Information processing method and device, equipment, storage medium and program product

By associating devices within a multicast group to detect malicious accounts across multiple devices, the method enhances the detection of restricted accounts, addressing the limitations of existing methods that rely solely on device-specific identifiers.

CN120316751APending Publication Date: 2025-07-15TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410061060.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-15
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

In the prior art, malicious accounts are easily hidden in multiple devices, resulting in the inability to accurately identify the blacklist accounts, affecting the security of the platform.

Method used

By obtaining the account list of the first device, determining the second device with which it has a communication-related relationship, and according to the operation of the account on the second device, assisting in determining whether the second account is a restricted account, diffusion detection is performed using the multicast group form to obtain a more comprehensive account list.

Benefits of technology

It has increased the detection of restricted accounts, enhanced the security of the platform, and avoided the hidden dangers caused by malicious behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120316751A_ABST
    Figure CN120316751A_ABST
Patent Text Reader

Abstract

The invention discloses an information processing method and device, equipment, a storage medium and a program product, and relates to the technical field of computers. The method comprises the following steps: acquiring a first account list; in response to the condition that the at least one restricted account comprises the first account, determining a second device having a communication association relationship with the first device; under the condition that the account state corresponding to the second account meets the account adding condition, a second account list is obtained, and the account state is used for representing the account operation condition of the second account on the second equipment; the second account list is an updated list obtained after the second account is added into the first account list. Through the above mode, the first device can be used as a device for detecting the restricted account number, whether the second account number is the restricted account number is judged in an auxiliary mode according to the account number operation condition of the second account number on the second device, and the detection strength of the restricted account number is improved. The method can be applied to various scenes such as cloud technology, artificial intelligence and intelligent transportation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of computer technologies, and in particular, to an information processing method, apparatus, device, storage medium, and program product. Background Art

[0002] With the development of computer technologies, there are some malicious entities that perform malicious acts such as stealing video resources and modifying data parameters. Therefore, in order to prevent malicious entities from performing malicious acts through accounts, it is necessary to search for accounts that perform malicious acts as comprehensively as possible, so as to add the found malicious accounts to the blacklist accounts.

[0003] In related technologies, usually when there is one application installed on one device, a malicious entity may illegally log in to multiple accounts within the application. Therefore, after identifying multiple accounts, the multiple accounts can be used as blacklist accounts to restrict or prohibit the account behaviors of the multiple accounts.

[0004] In the above process, one device corresponds to one device identifier (IDentity, ID). The process of searching for multiple blacklist accounts strongly depends on the process that multiple accounts correspond to one device ID. If only one account is logged in on one device, even if the account performs malicious acts, it is easy to hide among numerous devices, thus making it impossible to accurately identify blacklist accounts. Summary of the Invention

[0005] Embodiments of the present application provide an information processing method, apparatus, device, storage medium, and program product, which can use a first device as a device for detecting restricted accounts, and assist in determining whether a second account is a restricted account according to the account running status of the second account on a second device, thereby improving the detection strength for restricted accounts. The technical solution is as follows.

[0006] On the one hand, an information processing method is provided, and the method includes:

[0007] Obtain a first account list, where the first account list includes at least one restricted account;

[0008] In response to the first account being included in the at least one restricted account, determine a second device having a communication association relationship with a first device, where the first account is an account logged in on the first device, and the communication association relationship is used to represent that the first device and the second device are in the same multicast group, and the second device is logged in with a second account;

[0009] When the account status corresponding to the second account meets the account joining conditions, obtain a second account list, where the account status is used to characterize the account running situation of the second account on the second device; the second account list is an updated list obtained by adding the second account to the first account list.

[0010] On the other hand, an information processing device is provided, and the device includes:

[0011] A first acquisition module, configured to acquire a first account list, where the first account list includes at least one restricted account, and the restricted account is an account whose account behavior is restricted;

[0012] A device determination module, configured to, in response to the first account being included in the at least one restricted account, determine a second device having a communication association relationship with the first device, where the first account is an account logged in on the first device, and the communication association relationship is used to characterize that the first device and the second device are located in the same multicast group, and the second device logs in a second account;

[0013] A second acquisition module, configured to acquire a second account list when the account status corresponding to the second account meets the account joining conditions, where the account status is used to characterize the account running situation of the second account on the second device; the second account list is an updated list obtained by adding the second account to the first account list.

[0014] On the other hand, a computer device is provided, and the computer device includes a processor and a memory. At least one program is stored in the memory, and the at least one program is loaded and executed by the processor to implement the information processing method according to any one of the foregoing embodiments of the present application.

[0015] On the other hand, a computer-readable storage medium is provided, and at least one program is stored in the storage medium. The at least one program is loaded and executed by a processor to implement the information processing method according to any one of the foregoing embodiments of the present application.

[0016] On the other hand, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the information processing method according to any one of the foregoing embodiments.

[0017] The beneficial effects brought by the technical solutions provided in the embodiments of the present application at least include:

[0018] Obtain a first account list including at least one restricted account; when at least one restricted account includes a first account logged in to a first device, determine a second device located in the same multicast group as the first device; if the account running status of the second account logged in to the second device meets the account joining condition, a second account list obtained by updating after adding the second account to the first account list can be obtained. Under the condition that the first account is known to be a restricted account, the first device can be used as a device for detecting restricted accounts to perform account detection on the second device belonging to the same multicast group, so as to assist in determining whether the second account is a restricted account based on the account running status of the second account on the second device, avoiding the problem that a single account is logged in to the device and account determination cannot be performed, realizing the diffusion detection process of the device in the form of a multicast group, improving the detection intensity of restricted accounts, facilitating the acquisition of a more comprehensive second account list, and thus helping to maintain platform security by restricting restricted accounts and avoiding potential hazards caused by malicious behaviors. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1 is a schematic diagram of an implementation environment provided by an exemplary embodiment of the present application;

[0021] Figure 2 is a flowchart of an information processing method provided by an exemplary embodiment of the present application;

[0022] Figure 3 is a flowchart of an information processing method provided by another exemplary embodiment of the present application;

[0023] Figure 4 is a flowchart of an information processing method provided by still another exemplary embodiment of the present application;

[0024] Figure 5 is a comparison schematic diagram of unicast, broadcast, and multicast provided by an exemplary embodiment of the present application;

[0025] Figure 6 is a schematic diagram of detecting a preset multicast port provided by an exemplary embodiment of the present application;

[0026] Figure 7 is a flowchart of obtaining a first account list provided by an exemplary embodiment of the present application;

[0027] Figure 8It is a flowchart for performing account detection provided by an exemplary embodiment of the present application;

[0028] Figure 9 It is a schematic diagram of account detection provided by an exemplary embodiment of the present application;

[0029] Figure 10 It is a schematic diagram of performing an information processing method within a local area network provided by an exemplary embodiment of the present application;

[0030] Figure 11 It is a structural block diagram of an information processing device provided by an exemplary embodiment of the present application;

[0031] Figure 12 It is a structural block diagram of a server provided by an exemplary embodiment of the present application. Detailed implementation manners

[0032] To make the objectives, technical solutions, and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0033] In the related art, usually when an application program is installed on a device, malicious objects may illegally log in to multiple accounts within the application program. Therefore, after identifying multiple accounts, the multiple accounts can be used as blacklist accounts to restrict or prohibit the account behaviors of the multiple accounts. In the above process, one device corresponds to one device ID. The process of searching for multiple blacklist accounts strongly depends on the process that multiple accounts correspond to one device ID. If only one account is logged in on a device, even if the account performs malicious behaviors, it is easy to hide among numerous devices, thus making it impossible to accurately identify blacklist accounts.

[0034] In the embodiments of the present application, an information processing method is introduced. The first device can be used as a device for detecting restricted accounts. According to the account running situation of the second account on the second device, it is assisted in determining whether the second account is a restricted account, improving the detection intensity of restricted accounts. Furthermore, based on the restricted accounts detected in a more comprehensive second account list, the platform security is maintained by restricting or prohibiting the account behaviors of the restricted accounts, avoiding potential hazards caused by malicious behaviors. This information processing method can be applied to multiple scenarios such as network security scenarios, social media scenarios, e-commerce scenarios, game application scenarios, communication service scenarios, traffic scenarios, etc., which are not limited here.

[0035] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions. For example, the account list, restricted accounts, etc. involved in this application are obtained under full authorization.

[0036] Secondly, the implementation environment involved in the embodiments of this application is described. The information processing method provided in the embodiments of this application can be implemented by the terminal alone, or by the server, or by the terminal and the server through data interaction. The embodiments of this application do not limit this. Optionally, taking the joint execution of the information processing method by the terminal and the server as an example for description.

[0037] Schematically, please refer to Figure 1 , in this implementation environment, the first device 110 and at least one second device 120 are involved. The first device 110 can jointly execute the information processing method with the help of the server 130. Optionally, both the first device 110 and the second device 120 can be implemented as terminals.

[0038] In some embodiments, a first account is logged in on the first device 110. The first account is a system account logged in on the first device 110; or, an application program capable of logging in to an account is installed in the first device 110, such as a video application program, a social application program, etc., and the first account is a program account logged in on the application program installed in the first device 110, etc.

[0039] In some embodiments, the first device 110 obtains a first account list, and the first account list includes at least one restricted account.

[0040] Optionally, the first device 110 is connected to the server 130 through a communication network, and the server 130 can timely count and determine the first account list for the first device 110. Schematically, the server 130 is the background server of the application program, and the first account list sent by the server 130 to the first device 110 is the list content determined after counting multiple devices installed with the application program.

[0041] In some embodiments, in response to the first account being included in at least one restricted account, the first device 110 determines the second device 120 having a communication association relationship with the first device.

[0042] Among them, the communication association relationship is used to represent that the first device 110 and the second device 120 are located in the same multicast group, and the second device logs in to the second account.

[0043] Schematically, the first device 110 and at least one second device 120 are in the same multicast group. The multicast group is the basis for supporting multicast communication, allowing data to be transmitted one-to-many among multiple devices in the multicast group. For example, the first device 110 and the second device 120 join the same multicast group through the multicast protocol.

[0044] In some embodiments, when the account status corresponding to the second device 120 meets the account joining condition, the first device 110 obtains the second account list.

[0045] Among them, the account status is used to characterize the account operation situation of the second account on the second device 120, and the second account list is the updated list obtained after adding the second account to the first account list.

[0046] Schematically, after being detected by the first device 110, the second device 120 determines the account operation situation of the second account on the second device 120, so that the second device 120 counts the current account status.

[0047] Optionally, the second device 120 is also connected to the server 130 through a communication network. The server 130 can count the account status of the second device, thereby determining the account operation situation of the second account on the second device 120 based on the account status, and then determining whether the account status meets the account joining condition. If the account status meets the account joining condition, the server 130 will use the second account logged in on the second device 120 as a restricted account, such as adding the second account to the first account list to obtain the second account list.

[0048] Optionally, the server 130 sends the second account list to the first device 110 through the communication network, so that the first device 110 can obtain the second account list when the account status of the second device 120 meets the account joining condition.

[0049] It should be noted that the above terminals include but are not limited to mobile phones, tablets, portable laptops, desktop computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, etc.; the above server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.

[0050] Among them, cloud technology refers to a hosting technology that unifies a series of resources such as hardware, application programs, and networks within a wide area network or a local area network to achieve the calculation, storage, processing, and sharing of data. Cloud technology is the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model. It can form a resource pool, be used on demand, and is flexible and convenient.

[0051] In some embodiments, the above server can also be implemented as a node in a blockchain system.

[0052] Combined with the above noun introduction and application scenarios, the information analysis method provided in this application will be described. Taking the application of this method to the first device as an example, as Figure 2 shown, this method includes the following steps 210 to step 230.

[0053] Step 210, obtain the first account list.

[0054] Optionally, the information processing method is executed by the first device, and the first device can be implemented as a terminal in the form of, for example, a mobile phone, a tablet computer, a desktop computer, etc.

[0055] In some embodiments, the first device is communicatively connected to the server, and the first device obtains the first account list from the server. Among them, the first account list includes at least one restricted account.

[0056] Among them, a restricted account is an account whose account behavior is restricted, and can also be called a blacklist account. That is: a restricted account refers to an object account that is included in the blacklist by the system (server), usually because the user of the object violates the regulations or terms, resulting in restrictions or prohibitions on specific behaviors in the system.

[0057] For example: if the user uses a certain object account to violate the regulations and record video content that has not been fully made public, the object account that performs the screen recording behavior can be determined as a restricted account; or, if the user uses a certain object account to violate the regulations and modify some system parameters to maliciously obtain information or maliciously attack the system, the object account that performs the parameter modification can be determined as a restricted account; or, when multiple accounts are logged in on one device, the multiple accounts can be used as restricted accounts, etc.

[0058] Optionally, the first device is logged in with the first account, that is: the first account is the system account logged in on the first device; the server that sends the first account list to the first device is the server that assists the first device in communicating with other devices for device - to - device communication.

[0059] Optionally, the first device is installed with an application. Log in to the first account within the application, that is: the first account is a program account logged in on the application through the first device; the server that sends the first account list to the first device is the background server corresponding to the application, which is used to overall manage and allocate the program running statuses respectively corresponding to multiple devices installed with the application.

[0060] Illustratively, the application is implemented as at least one of multiple types of applications such as a video application, a music application, a social application, a news application, a shopping application, etc. The first device can install the application and then log in to the first account within the application. The application corresponds to a background server. The background server can not only obtain the program running data of the first device during the running of the application based on authorization, but also obtain the program running data of other devices during the running of the application based on the authorization of the user object for other devices, etc., so that the background server can analyze the program running statuses when multiple devices run the application respectively.

[0061] Optionally, the first device is installed with an application. Log in to the first account within the application. The application can also embed at least one mini-program based on the operations of the user object. The mini-program uses the first account as the operation account corresponding to the mini-program based on the authorization of the user object, that is: the first account is both a program account logged in on the application through the first device and a mini-program account (operation account) logged in on the mini-program based on the authorization process; the server that sends the first account list to the first device is the background server corresponding to the mini-program during the running of the mini-program, which is used to overall manage and allocate the mini-program running statuses respectively corresponding to multiple devices embedded with the mini-program, etc.

[0062] It should be noted that the above are only illustrative examples, and the embodiments of the present application are not limited thereto.

[0063] Illustratively, the server determines at least one restricted account based on the account operation status of the object account during the running of the device or application where it is logged in, forms the first account list, and then sends the first account list to the first device, so that the first device obtains the first account list.

[0064] Optionally, the first device periodically receives the account list to obtain the first account list. For example: the first device receives the account list every preset time period (such as: 1 minute, 2 hours, etc.), and the account list received at the current moment is called the first account list.

[0065] Optionally, the first device receives the account list in real time to obtain the first account list. For example, when the first device is communicatively connected to the server, it obtains the account list sent by the server in real time, and refers to the account list received at the current moment as the first account list, etc.

[0066] Step 220, in response to the first account being included in at least one restricted account, determine a second device that has a communication association relationship with the first device.

[0067] Illustratively, after the first device receives the first account list, based on the fact that the first account list includes at least one restricted account, the first device searches the at least one restricted account to find out whether the first account logged in to the first device exists therein.

[0068] Optionally, when the first account is included in at least one restricted account, the first device will determine a second device that has a communication association relationship with it.

[0069] Among them, the communication association relationship is used to represent that the first device and the second device are in the same multicast group.

[0070] Illustratively, a multicast group is a concept in a computer network, usually representing a group established by multiple devices based on multicast, and each device is regarded as a node in the multicast group. Optionally, multiple devices join the same multicast group based on a preset multicast protocol; or, multiple devices join the same multicast group based on being configured with a preset multicast component, etc.

[0071] Among them, the multicast group is assigned a unique multicast address, and the multicast group can be uniquely identified by the multicast address; in addition, the multicast group can correspond to at least one multicast port, and multiple devices can perform one-to-one or even one-to-many multicast communication through the multicast port. That is: the multicast group is the basis for supporting multicast communication between multiple devices, thus allowing data to be communicated more efficiently within the multicast group.

[0072] In some embodiments, multiple devices have a pre-established multicast group. Based on the condition that the first account is a restricted account, the first device will determine at least one other device in the same multicast group as it, that is, determine a second device that has a communication association relationship with it.

[0073] Illustratively, Device 1, Device 2, and Device 3 are in the same multicast group. Taking the first device as Device 1 as an example, when Device 1 determines that the first account logged in to Device 1 is one of the at least one restricted accounts, then Device 1 will determine the second device in the same multicast group as it, that is, the second device is Device 2 and Device 3.

[0074] Among them, the second device logs in to the second account.

[0075] Schematically, a second account is logged in on the second device. The second account is similar to the first account logged in on the first device and is an object account that can perform account operations through the first device.

[0076] For example: Application A is installed on the first device, and the first account is logged in to Application A installed on the first device; Application A is also installed on the second device, and the second account is logged in to Application A installed on the second device.

[0077] Step 230: When the account status corresponding to the second account meets the account joining condition, obtain a list of second accounts.

[0078] Optionally, during the process of the first device determining at least one second device, a detection process is performed on the second device; in response to the detection process of the first device, the second device determines the account running status of the second account on the second device, that is, the second device can determine the account status corresponding to the second account.

[0079] The account status is used to characterize the account running status of the second account on the second device.

[0080] Schematically, the second account is an account logged in to the video application installed on the second device, and the account status indicates that the second account is watching a video through the second device; or, the account status indicates that the second account is recording the screen through the second device; or, the account status indicates that the second account is taking a screenshot, etc.

[0081] In some embodiments, the account status is written into data logs. The data logs are used to indicate data files generated by a device or an application. The data files contain information about various events, statuses, and operations that occur during the operation of the device or the application.

[0082] In some embodiments, the data logs are sent to a server. The server determines the status corresponding to the second account based on the data logs and determines whether the account status meets the account joining condition.

[0083] Optionally, the account joining condition is used to represent the condition for adding the second account as a restricted account to the first account list.

[0084] Schematically, the account joining condition is a pre-set condition and is a condition for qualifying an account as a restricted account. For example: The account joining condition is used to characterize that the account performs a screen recording behavior; and / or, the account joining condition is used to characterize that the account modifies background parameters; and / or, the account joining condition is used to characterize that the account has posted illegal content; and / or, the account joining condition is used to characterize that the account has carried out a network attack, etc.

[0085] In some embodiments, the account login is on the application installed on the first device, and the account joining condition is determined based on the type of the application.

[0086] Illustratively, the account login is on a video application, and the account joining condition corresponding to the video application is used to characterize the account's screen recording behavior. For example, when the second account performs a screen recording behavior through the second device, the second account can be regarded as a restricted account, etc.

[0087] Illustratively, the account login is on a social application, and the account joining condition corresponding to the social application is used to characterize that the account has posted illegal content. For example, when the second account sends illegal content through the second device in a square, a social group, or to a specific object, the second account can be regarded as a restricted account, etc.

[0088] In some embodiments, either one account joining condition can be set as the condition for a restricted account, or multiple account joining conditions can be set.

[0089] Optionally, when multiple account joining conditions are set, the account can be regarded as a restricted account when any one of the account joining conditions is met; the account can also be regarded as a restricted account when the account meets multiple account joining conditions simultaneously; the account can also be regarded as a restricted account when the account meets at least two of the multiple account joining conditions simultaneously, etc.

[0090] In an alternative embodiment, the server executes the matching process between the account status and the account joining conditions, so that the second account that meets the account joining conditions can be regarded as a restricted account in real time.

[0091] In some embodiments, the second device sends the account status corresponding to the second account to the server through a data log, and the server matches the account status with the account joining conditions to determine whether the account status meets the account joining conditions.

[0092] Optionally, when the account status meets the account joining conditions, the server can regard the second account as a restricted account to add the second account to the first account list, thereby realizing the update of the first account list to obtain the second account list.

[0093] That is to say, the second account list is an updated list obtained by adding the second account to the first account list.

[0094] Optionally, the server sends the second account list to the first device, so that the first device can determine more comprehensive restricted accounts based on the second account list.

[0095] In summary, obtain a first account list including at least one restricted account; when at least one of the restricted accounts includes a first account logged in to a first device, determine a second device located in the same multicast group as the first device; if the account running status of the second account logged in to the second device meets the account joining condition, a second account list obtained by updating after adding the second account to the first account list can be obtained. Under the condition that the first account is known to be a restricted account, the first device can be used as a device for detecting restricted accounts to perform account detection on the second devices belonging to the same multicast group, so as to assist in determining whether the second account is a restricted account based on the account running status of the second account on the second device, avoiding the problem that a single account is logged in to the device and account determination cannot be performed, realizing the diffusion detection process of the device in the form of a multicast group, improving the detection intensity of restricted accounts, facilitating the acquisition of a more comprehensive second account list, and thus contributing to maintaining platform security by restricting restricted accounts and avoiding potential hazards caused by malicious behaviors.

[0096] In an alternative embodiment, the communication association relationship between the first device and the second device is implemented as being located in the same multicast group. By means of multicast communication, the first device can perform a detection and determination process on other second devices by sending a multicast detection message to a preset multicast address corresponding to the multicast group. Schematically, as Figure 3 shown, the above Figure 2 embodiment shown can also be implemented as the following steps 310 to 340; the above Figure 2 step 220 shown can also be implemented as the following steps 320 to 330.

[0097] Step 310, obtain a first account list.

[0098] Among them, the first account list includes at least one restricted account, and a restricted account is an account whose account behavior is restricted.

[0099] In an alternative embodiment, when the first device runs a preset application program, detect a preset multicast port corresponding to the multicast group.

[0100] Schematically, the preset application program is an application program installed on the first device, and the first device joins the multicast group based on the multicast protocol and becomes a device node in the multicast group.

[0101] Optionally, a multicast group corresponds to at least one multicast port. A multicast port is a mechanism for identifying a specific service or application program in multicast communication; there is a corresponding relationship between the multicast port and the multicast group joined by the first device. Usually, data packets related to the multicast group are transmitted through the multicast port, so that device nodes in the multicast group can simultaneously receive the same multicast data through the multicast port.

[0102] Schematically, the preset multicast port is a pre-determined multicast port among at least one multicast port, and this preset multicast port is used to transfer the first account list collected by the program background of the preset application to the first device, that is: the preset multicast port is used to transmit multicast data including the first account list, so the first device can obtain the first account list based on the preset multicast port.

[0103] Schematically, the program background of the preset application is the server responsible for managing the preset application. For example: the preset application is a game application, and the program background is the game server responsible for managing this game application, etc.; or, the preset application is a film and television application, and the program background is the film and television platform server responsible for managing this film and television application, etc.

[0104] Among them, the preset application is used to log in to the first account on the first device. Based on the running process of the preset application on multiple devices, the program background can obtain various log data generated during the running process, and analyze the log data corresponding to each of the multiple devices.

[0105] Schematically, when the program background detects that the account behavior performed by the account logged in to a certain device violates the regulations, the account logged in to this device can be used as a restricted account. For example: multiple accounts are logged in to the preset application installed on a device, and all the multiple accounts are used as restricted accounts; or, the account behavior performed by the account logged in to the preset application installed on a device meets the above account joining conditions, and this account is used as a restricted account, etc. Based on the determination of the restricted accounts, the program background can initially determine a certain number of restricted accounts and form the first account list.

[0106] In some embodiments, a communication connection is maintained between the preset multicast port and the program background.

[0107] Schematically, the multicast port is a number used to identify an application program or service that performs multicast communication in a computer network. When an application program needs to use multicast communication, this application program will be bound to a specific multicast port so as to be able to receive and send multicast data. The multicast port bound to the preset application is the preset multicast port. Based on the fact that the program background is the background of the preset application, there is a multicast communication relationship between the preset multicast port and the program background.

[0108] Optionally, in the program background of the preset application, if multicast communication needs to be implemented, the following steps generally need to be performed.

[0109] (1) Multicast port binding: The preset application selects an unoccupied multicast port as the preset multicast port and binds to this port when the application starts. This process can be completed through the application programming interface (API) provided by the underlying network library or framework.

[0110] (2) Joining a multicast group: The preset application needs to join a specific multicast group. This process can be implemented by using protocols such as the Internet Group Management Protocol (IGMP). By joining the multicast group, the preset application can receive the data of this multicast group.

[0111] (3) Data transmission and reception: In the program background, after the multicast port binding and joining the multicast group are implemented, the preset application can use the corresponding API or library to send and receive multicast data; the multicast data can be transmitted through the Internet Protocol (IP) address and multicast port of the multicast group, ensuring that only the preset applications installed on the device nodes that have joined this multicast group can receive the multicast data.

[0112] Schematically, various applications such as video stream services (film and television applications), online games (game applications), real-time data (social applications, shopping applications, etc.) may use multicast communication. By using the multicast port in the program background of the corresponding application, the same information can be effectively transmitted to multiple device nodes, thereby reducing the network burden.

[0113] Among them, the preset multicast port is used to transfer the first account list collected by the program background of the preset application to the first device. That is: based on the process of the first device detecting the preset multicast port, the first device can receive the first account list sent by the preset multicast port.

[0114] Schematically, the first account list is a form of the multicast data transmitted by the program background through the preset multicast port. This process enables multiple devices including the first device within the multicast group to receive the first account list in the form of multicast communication.

[0115] In an alternative embodiment, a multicast association component is deployed inside the preset application.

[0116] Schematically, the preset application is an application installed on the first device. A multicast association component is deployed inside the preset application, and the multicast association component is used to establish a communication association relationship between the first device and the second device within the local area network.

[0117] Schematically, the communication association relationship between the first device and the second device is established based on the multicast association component. For example, under the condition that the first device deploys the multicast association component, the first device determines the local area network it is in, and then searches for other devices that deploy the multicast association component within the local area network. Based on the fact that both deploy the multicast association component for establishing multicast communication, the first device can establish a communication association relationship with other devices, and the other devices are the second devices that have a communication association relationship with the first device.

[0118] Among them, a local area network (LAN) refers to a relatively small geographical area such as inside a single building, campus, or office, where computers and network devices are interconnected through network technologies. This network is usually supported by a set of local area network technologies and protocols, allowing data exchange and resource sharing between connected devices. The local area network has characteristics such as limited geographical scope, high bandwidth, privacy, low cost, and high performance.

[0119] Considering that restricted accounts are usually used by malicious teams when performing malicious acts, and malicious teams usually concentrate on implementing malicious acts in one or more regions, it is possible to comprehensively determine whether the accounts logged in on other devices are restricted accounts by leveraging the geographical location limitation of the local area network under the condition that one or more restricted accounts are known as the first accounts, combined with the characteristics of the local area network.

[0120] Optionally, in the case of local area network technology combined with multicast communication, under the condition that multicast communication allows a one-to-many communication mode, compared with the unicast situation of the one-to-one communication mode within the local area network, it can improve network bandwidth, reduce network traffic, and reduce the risk of network congestion; this can enable multiple devices within the local area network to share the same data stream such as real-time video streams, audio streams, or other multicast data through multicast communication.

[0121] In some embodiments, both the first device and the second device are under a local area network. The first device can join the multicast group and become a device node in the multicast group because the preset application installed includes a multicast association component; similarly, the second device can join the multicast group and become another device node in the multicast group because the preset application installed includes a multicast association component, etc.

[0122] Optionally, the device nodes within the multicast group implement the multicast communication process through the multicast association component deployed in the preset application. The multicast association component correspondingly detects at least one multicast port, and the preset multicast port is a pre-determined one among the at least one multicast port.

[0123] In some embodiments, when a preset application is installed on the first device, a multicast association component is called to detect a preset multicast port corresponding to the multicast group.

[0124] Illustratively, the first device has a preset multicast component in the installed preset application, and the preset multicast component can detect the preset multicast port. Therefore, the first device can call the multicast association component deployed in the preset application while running the preset application, and obtain the first account list through the preset multicast port.

[0125] It is worth noting that the above are merely illustrative examples and are not limited to the embodiments of the present application.

[0126] Step 320: In response to at least one restricted account including the first account, a multicast detection message is sent to a preset multicast address corresponding to the multicast group.

[0127] Schematically, a multicast address is a special IP address used for multicast communication. Each multicast group has a unique multicast address. Through the multicast address, the sender in the multicast group can transmit data to all the receivers that have joined the multicast group, where the sender and the receiver are device nodes in the multicast group.

[0128] With the help of multicast addresses, a device node is allowed to send data to a multicast group, which can not only realize one-to-one (one device node sends to a single device node) data transmission, but also one-to-many (one device node sends to a multicast address, and then broadcasts to multiple device nodes in the multicast group) data transmission; it can also achieve the purpose of delivering data to specific receivers in the multicast group instead of all devices. Multicast communication is very useful in application scenarios such as streaming media, online meetings, and real-time communication. Multicast addresses can help deliver the same data stream to multiple device nodes in the multicast group at the same time.

[0129] Among them, the preset multicast address is the multicast address corresponding to the multicast group joined by the first device. If the first device determines that at least one restricted account includes the first account after receiving the first account list, the first device can send a multicast detection message to the preset multicast address of the multicast group to which it belongs.

[0130] The multicast detection message is used to obtain device information of devices in the multicast group, and the device information includes account information corresponding to the device.

[0131] Illustratively, the device information includes device attributes related to the device itself, such as device identification and device model, and also includes at least one of the account information related to the account logged in and running on the device, such as account identification, account status, and account usage period.

[0132] Optionally, the first device sends a multicast probe message to a preset multicast address, so as to broadcast the multicast probe message to the second devices within the multicast group by means of the multicast communication function corresponding to the preset multicast address.

[0133] That is: the preset multicast address is used to broadcast the multicast probe message to multiple devices within the multicast group. Among them, the second device located in the multicast group receives the multicast probe message based on the preset multicast address.

[0134] Illustratively, the multicast group includes the first device as device 1, and also includes device 2 and device 3. Device 2 and device 3 are referred to as the above-mentioned second devices; if the first account logged in by device 1 is a restricted account, a multicast probe message is generated and sent to the multicast address corresponding to this multicast group; the multicast address sends the multicast probe message to device 2 and device 3 to obtain the device information corresponding to device 2 and device 3 respectively; or, the multicast address sends the multicast probe message to device 1, device 2 and device 3 to obtain the device information corresponding to device 1, device 2 and device 3 respectively, etc.

[0135] Step 330, based on the reception of the multicast probe message by the devices within the multicast group, determine the second device having a communication association relationship with the first device.

[0136] Illustratively, the multicast group includes multiple devices. It is possible that some devices are in the running state and some devices are in the non-running state.

[0137] For example: regarding the device startup state as being in the running state and the device shutdown state as being in the non-running state; or, regarding the state of the device running a preset application program as being in the running state and the state of the device not running the preset application program as being in the non-running state, etc.

[0138] Optionally, in the case where the devices in the multicast group are in the running state, receive the feedback information respectively sent by multiple devices within the multicast group.

[0139] Among them, the feedback information is used to characterize the reception situation of the device for the multicast probe message.

[0140] Illustratively, the feedback message is implemented in binary form. For example: if the device receives the multicast probe message, it sends "1" to indicate successful reception; if the device does not receive the multicast probe message, it sends "0" to indicate reception failure after a preset duration.

[0141] Or, the feedback message is implemented as device information. For example: if the device receives the multicast probe message, it sends the device information, representing the process of the device collecting and sending device information based on the multicast probe message; if the device does not receive the multicast probe message, there is no message received from this device after a preset duration.

[0142] Optionally, determine, from multiple devices, a device that receives the multicast probe message as the second device having a communication association relationship with the first device based on the feedback information indicating the device that receives the multicast probe message.

[0143] Illustratively, the multicast group includes Device 1, Device 2, and Device 3. Taking the first device as Device 1 as an example, Device 2 is in an operating state and can receive the multicast probe message; Device 3 is in a non-operating state and cannot receive the multicast probe message. Then, Device 2 is regarded as the second device.

[0144] Step 340: Obtain a second account list when the account status corresponding to the second account meets the account joining condition.

[0145] Herein, the account status is used to represent the account operation situation of the second account on the second device; the second account list is an updated list obtained by adding the second account to the first account list.

[0146] In an optional embodiment, obtain the second account list when the account status represents that the second account is in the process of screen recording through the second device.

[0147] Herein, the screen recording process is a process that meets the account joining condition.

[0148] Illustratively, in some preset situations, video recording by an account is prohibited. If certain restricted accounts perform malicious screen recording behavior, under the condition that the first account is a restricted account, the second account can be determined through the local area network and multicast communication for targeted analysis; then, based on the behavior of the second account on the second device, such as triggering a specific area of the screen, the account status corresponding to the second account is determined, so as to determine whether the second account is determined as a restricted account, etc.

[0149] When the account status represents that the second account is in the process of screen recording through the second device in ways such as clicking on a specific area of the screen or modifying the screen recording path, the second account is regarded as a restricted account, and the second account can be added to the first account list to obtain the second account list.

[0150] In an optional embodiment, obtain the second account list when the account status represents that the video played by the second account through the second device is a screen recording video.

[0151] Herein, the screen recording video is a video obtained by a restricted account through the screen recording process.

[0152] In some embodiments, obtain the second account list when the account status represents that the account watermark on the video is not the second account identifier.

[0153] Herein, the account watermark is used to represent the account identifier corresponding to the restricted account that records the screen recording video.

[0154] Optionally, the first device corresponds to a first device identifier, and the second device corresponds to a second device identifier. The device identifier is used to uniquely represent the device. If the device uses an account for the video recording process, an account identifier representing the account will be left on the video as the account watermark content.

[0155] For example: During the process of the first device logging in to the first account, the video recording process is carried out through the first account, and the recorded video includes the first account identifier as a watermark, and this watermark can be in a visible state or an invisible state.

[0156] Optionally, taking the restricted account implemented as the first account as an example, if the second device plays the screencast video recorded by the first account when logging in to the second account, that is, plays the video with the first account identifier as the watermark; the second device can send the second account identifier corresponding to the second account and the watermark of the currently played video to the server. If the server detects that the first account identifier of the watermark of the played video is different from the second account identifier, it means that the account status corresponding to the second account matches the account joining condition, and the second account can be used as the restricted account, etc.

[0157] In an optional embodiment, when the account status indicates that the second account tampers with the data reception parameter through the second device, a second account list is obtained based on the second account.

[0158] Among them, the data reception parameter is a parameter used to receive data during the data transmission process, and the data includes at least one of multimedia data and text data.

[0159] In summary, under the condition that the first account is known to be a restricted account, the first device can be used as a device for detecting restricted accounts to perform account detection on the second device belonging to the same multicast group. Thus, based on the account operation situation of the second account on the second device, it is assisted to determine whether the second account is a restricted account, avoiding the problem that the device cannot perform account determination when logging in to a single account, realizing the diffusion detection process of the device in the form of a multicast group, improving the detection intensity of restricted accounts, facilitating the acquisition of a more comprehensive second account list, and thus helping to maintain platform security by restricting restricted accounts and avoiding potential hazards caused by malicious behaviors.

[0160] In the embodiments of the present application, a multicast communication process for device detection through a multicast group is introduced. As a device in the multicast group, the first device can send a multicast detection message to a preset multicast address corresponding to the multicast group on the condition that at least one restricted account includes the first account, so as to detect the second device in the multicast group through the preset multicast address. Thus, when the second device feeds back device information based on the multicast detection message, the second account list obtained after adding the second account to the first account list can be received under the condition that the account status corresponding to the second account meets the account joining condition, improving the acquisition strength of restricted accounts. By using the first account list with a small number of restricted accounts to detect other devices in the multicast group to obtain the second account list, it is convenient to improve the restriction intensity of restricted accounts with the help of the second account list.

[0161] In an alternative embodiment, the account management platform is used to analyze the account status corresponding to the second account, and then the account management platform decides whether to add the second account to the first account list to implement the list update process. Schematically, as Figure 4 shown, the above Figure 2 shown embodiment can also be implemented as the following steps 410 to step 442; the above Figure 2 shown step 230 can also be implemented as the following steps 431 to step 433 or steps 441 to step 442.

[0162] Step 410, obtain the first account list.

[0163] Among them, the first account list includes at least one restricted account, and a restricted account is an account whose account behavior is restricted.

[0164] In some embodiments, the first device is logged in with the first account, and the first account is assisted in management by the account management platform.

[0165] Schematically, the first account is an account logged in to a preset application installed on the first device, and the account management platform is the program background corresponding to the preset application; or, the first account is a system account logged in to the first device, and the account management platform is the device management platform corresponding to the device model, etc.

[0166] In some embodiments, after the first device logs in to the first account, the first account list is obtained through the account management platform. Among them, the first account list includes at least one restricted account.

[0167] Step 420, in response to the first account being included in at least one restricted account, determine the second device having a communication association relationship with the first device.

[0168] Schematically, after the first device receives the first account list, and based on the fact that the first account list includes at least one restricted account, the first device searches among the at least one restricted account to find out whether there is a first account logged in on the first device.

[0169] Optionally, when the at least one restricted account includes the first account, the first device will determine a second device that has a communication association relationship with it.

[0170] Among them, the communication association relationship is used to characterize that the first device and the second device are in the same multicast group, and the second device is logged in with a second account.

[0171] Schematically, the second account logged in on the second device is also assisted in management by the account management platform.

[0172] In an alternative embodiment, when matching the account status and the account joining conditions through the account management platform, the following steps 431 to 433 are executed; when matching the account status and the account joining conditions through the first device, the following steps 441 to 442 are executed.

[0173] Step 431, under the condition that the first device and the second device are both in an online state, receive the second account identifier sent by the second device.

[0174] Among them, the second account identifier is used to uniquely indicate the second account, and the second account identifier belongs to the device information corresponding to the second device.

[0175] Schematically, when the first device detects the second device, the second device sends the second account identifier corresponding to the second account logged in on the second device to the first device.

[0176] Optionally, the second account identifier is used to uniquely identify the second account. For example: the second account identifier is a string of numbers; or, the second account identifier is a section of letters; or, the second account identifier is a combination of numbers and letters, etc.

[0177] Step 432, send the second account identifier to the account management platform.

[0178] Among them, the account management platform is a platform for managing multiple accounts, and the multiple accounts include the first account and the second account. The account management platform is used to query the account status corresponding to the second account based on the second account identifier and match the account status with the account joining conditions.

[0179] Schematically, since the account management platform is used to manage multiple accounts including the second account, the account management platform can find the second account based on the second account identifier and determine the account status corresponding to the second account.

[0180] Optionally, the account management platform can receive various log data generated when the second account runs on the second device, and thus query the account status corresponding to the second account from the log data based on the second account identifier.

[0181] Step 433, when the account management platform determines that the account status meets the account joining conditions, receive the second account list sent by the account management platform.

[0182] Among them, when the account status meets the account joining conditions, the account management platform adds the second account to the first account list.

[0183] Schematically, the account management platform stores account joining conditions correspondingly to determine whether an account is determined as a restricted account. Schematically, the account management platform matches the account status with the account joining conditions. When it is determined that the account status corresponding to the second account matches the account joining conditions, the second account is determined as a restricted account and added to the first account list, so as to update and obtain the second account list.

[0184] Step 441, when the first device determines that the account status meets the account joining conditions, send a list update message to the account management platform.

[0185] Among them, the list update message is used to instruct the account management platform to add the second account to the first account list. The account management platform is a platform that manages multiple accounts, and the multiple accounts include the first account and the second account.

[0186] Schematically, the first account is an account logged in to the preset application installed on the first device; the second account is an account logged in to the preset application installed on the second device; the account management platform is the program background corresponding to the preset application, etc.

[0187] Optionally, the account status is the situation where the second account runs on the second device. After the first device detects the second device, the second device can send the account status to the first device. The first device compares the account status with the account joining conditions, and when the account status meets the account joining conditions, sends a list update message to the account management platform.

[0188] Step 442, receive the second account list sent by the account management platform.

[0189] Among them, the second account list is used to increase the number of restricted accounts that perform account restriction behaviors.

[0190] Schematically, after obtaining the second account list, the account management platform can send the updated second account list to the first device when the first device receives the account list subsequently, so that the first device can determine restricted accounts based on the second account list. Even if the second account logs in to the first device later, the first device can also determine the updated restricted account situation in the second account list in a timely manner, so as to increase the number of accounts for which account restriction actions are performed and avoid malicious actions of restricted accounts such as screen recording and data tampering.

[0191] Schematically, for restricted accounts, the device can implement a series of account restriction actions to enhance security, guard against potential threats, and reduce the risks posed by restricted accounts to the system. The account restriction actions include at least one of the following forms.

[0192] (1) Access restriction: Restrict the access rights of the accounts in the second account list to the minimum range, or completely prohibit their access to sensitive information, system resources, or services. This process can be achieved by adjusting the Access Control List (ACL), permission settings, or firewall rules.

[0193] (2) Login attempt limit: To prevent brute-force attacks, the number of login attempts allowed for each account within a certain period of time can be restricted. When the number of attempts exceeds the set threshold, the system can temporarily lock or delay the login attempt of the account.

[0194] (3) IP blocking: If the malicious behavior of the restricted account comes from a specific IP address, IP blocking measures can be taken to prohibit access from that IP address. This helps guard against attacks from specific geographical locations or network sources.

[0195] (4) Account locking: When suspicious activities are detected, the restricted account can be temporarily locked to prevent further malicious behavior. The locking can be permanent or temporary for a period of time.

[0196] The above account restriction actions are usually implemented as part of a comprehensive security policy to minimize the potential threats posed by restricted accounts to the device.

[0197] In some embodiments, the account is an account logged in to a preset application, and the account restriction actions are behavior contents closely related to the preset application.

[0198] Schematically, the preset application is a video application, and the account restriction behavior is to prohibit the account from performing some behaviors such as video viewing and video recording during the operation of the video application, but the account can perform behaviors such as video evaluation and video search; or, the account restriction behavior is to prohibit the account from performing all operations during the operation of the video application, etc.

[0199] It should be noted that the above is only a schematic example, and the embodiments of the present application do not limit this.

[0200] In summary, under the condition that the first account is known to be a restricted account, the first device can be used as a device for detecting restricted accounts to detect the second account of the same multicast group, so as to assist in determining whether the second account is a restricted account based on the account running status of the second account on the second device, avoiding the problem that a single account cannot be determined when logging in to the device, realizing the diffusion detection process of the device in the form of a multicast group, improving the detection intensity of restricted accounts, facilitating the acquisition of a more comprehensive second account list, and thus contributing to maintaining platform security by restricting restricted accounts and avoiding potential hazards caused by malicious behaviors.

[0201] In the embodiments of the present application, the content of analyzing the account status through the account management platform and determining whether to use the second account as a restricted account is introduced. The account management platform can add the second account to the first account list when the account status corresponding to the second account meets the account joining conditions, so as to fully exert the ability of overall account management, and can also reduce the data processing burden of the first device to a certain extent, and then obtain a more complete second account list covering restricted accounts, which is beneficial to improving the management efficiency of accounts with the help of the account management platform and also facilitating the improvement of the security of account login on the device.

[0202] In an optional embodiment, the above information processing method is called "a method for discovering black production teams based on the multicast protocol". A black production team is a team that implements malicious behaviors. The purpose of discovering black production teams is to discover as comprehensively as possible the black production accounts that implement malicious behaviors, that is, to discover as comprehensively as possible the blacklist accounts, that is, the above-mentioned restricted accounts.

[0203] Optionally, the above information processing method can be applied to various applications, such as: video applications, game applications, etc.; by deploying a multicast association component inside the application, the process of establishing a multicast group and performing multicast communication is realized.

[0204] Schematically, such as Figure 5As shown, it is a schematic diagram of unicast, broadcast, and multicast. If the server 510 sends data to a single device (such as device 521), the unicast process is realized; if the server 510 sends data to multiple devices (such as device 522 and device 523), the multicast process is realized; if the server 510 sends data to all devices (such as device 521, device 522, device 523, and device 524), the broadcast process is realized. That is: Multicast can not only achieve one-to-many communication, but also achieve many-to-many communication.

[0205] In some embodiments, taking the example of discovering whether the account logged in to the video application is a blacklist account, a multicast association component is installed in the application. When the application runs on the device, the multicast association component enters the startup state and detects a preset multicast port jointly associated with the multicast group and the application.

[0206] As Figure 6 shown, it is a schematic diagram of multiple devices detecting the preset multicast port.

[0207] Among them, the multiple devices can be implemented as at least one type of terminal such as mobile phones, tablets, portable laptops, desktop computers, intelligent voice interaction devices, smart home appliances (such as smart TVs, smart speakers, etc.), vehicle terminals, etc. For example: The multiple devices include at least one mobile phone; or, the multiple devices include at least one mobile phone and at least one computer (tablet, portable laptop or desktop computer), etc. Taking the multiple devices as the desktop computer 610, smart TV (Television, TV) 620, and mobile phone 630 as an example, the desktop computer 610, smart TV 620, and mobile phone 630 are in a multicast group together, and the desktop computer 610, smart TV 620, and mobile phone 630 jointly detect the preset multicast port 640.

[0208] Optionally, the video applications installed on the multiple devices in the multicast group are respectively deployed with the multicast association component. When the multicast association component of the video application starts, it can detect the preset multicast port 640. Schematically, this detection process is realized as a real-time detection process.

[0209] Optionally, in addition to detecting a default preset multicast port, the multicast association component can also detect the preset multicast address corresponding to the multicast group to which the current device belongs, so as to comprehensively perform the account detection process of the application by means of the preset multicast port and the preset multicast address.

[0210] Schematically, the current device (such as the first device) regularly reads whether the first account logged in to it is a blacklist account. As Figure 7As shown, taking a desktop computer 710 as the first device as an example, there is communication between the desktop computer 710 and the program background 720 of the application; the desktop computer 710 regularly pulls the first account list sent by the program background 720 through the getvinfo interface, so that the desktop computer 710 can know whether the currently logged-in account is a blacklist account based on the search of the first account list.

[0211] Optionally, when the first device determines that the first account currently logged in is a blacklist account, an account detection process needs to be performed.

[0212] Schematically, if the multicast association component installed on any device detects that the account logged in to the current device is a blacklist account, the multicast association component sends an instruction to the current device, so that the device to which the account belongs regularly sends information for detecting other devices.

[0213] Optionally, the first device sends the multicast detection message representing the account detection to a preset multicast address, and the preset multicast address broadcasts the multicast detection message to the second devices within the multicast group.

[0214] Schematically, if the first device receives the account information sent by other devices based on the multicast detection message, it will report the account information; if the discovered party (the detected device) knows that it has been detected by the first-layer blacklist account (the first account), it will also start detection for the second-round detection.

[0215] As Figure 8 shown, it is a timing relationship flowchart of the account detection process.

[0216] Among them, taking the first device as the desktop computer 810, one second device as the smart TV 820, another second device as the mobile phone 830, and the program background as the data reporting platform 840 as an example for illustration.

[0217] The desktop computer 810 regularly pulls the first account list. If it determines that the first account currently logged in exists in the first account list, it determines that the first account is a blacklist account; similarly, the smart TV 820 will also regularly pull the first account list to determine whether the currently logged-in account is a blacklist account, and the mobile phone 830 will also perform this account judgment process, which is not elaborated here.

[0218] Schematically, if the desktop computer 810 determines that the first account is a blacklist account, it will regularly detect other devices that are online at the same time as the desktop computer 810. If the smart TV 820 is online at the same time as the desktop computer 810, the desktop computer 810 will perform timed detection on the smart TV 820. If it broadcasts the multicast detection message through the preset multicast address and successfully broadcasts the multicast detection message to the smart TV 820 because the smart TV 820 is online.

[0219] Optionally, based on the successful detection process, the smart TV 820 will send the account identifier of the second account logged in on the smart TV 820 to the desktop computer 810 as device information feedback to the desktop computer 810.

[0220] Optionally, the desktop computer 810 performs a log reporting and local area network detection process to add information such as the account information of the first account and the account identifier of the second account logged in on the desktop computer 810 to the log data and report it to the data reporting platform 840; in addition, the desktop computer 810 also sends a local area network detection request to the data reporting platform 840 to request to determine other devices in the same multicast group.

[0221] In addition, to avoid the problem of incomplete or inaccurate messages uploaded by the desktop computer 810, the smart TV 820 will also perform a log reporting and local area network detection process similar to that of the desktop computer 810.

[0222] Schematically, as a device detected by the desktop computer, the smart TV will also start an account detection process for a second round of detection, such as performing timed detection on the mobile phone 830 and subsequent operations.

[0223] Such as Figure 9 As shown, if there is an AB watermark (i.e., the account mark for playing the video is different from the watermark mark of the video) and the account for which the screen recording is discovered, a group ID (multicast group identifier - uniquely representing the multicast group) is sent to it through the background. A timed detection model is deployed on the desktop computer 910. Since the smart TV 920 is online, it can detect the smart TV 920; in addition, the smart TV 920 needs to detect other devices such as mobile phones and tablets.

[0224] In the above process, multiple devices in the multicast group are in the same local area network. The following briefly introduces the local area network.

[0225] Among them, if the account logged in by the device is a blacklist account, the account information corresponding to the account can be retained locally, and then the device periodically sends multicast information (multicast detection messages) to detect information about the video application on each device. Since the account information may be dynamically updated, for example, during the playback process, it is determined in real time that the video played by the account through the device is a screen recording, etc., then the account can be set as a blacklist account in real time. That is: reading whether the current account can be determined as a blacklist account can be determined by playing the video or reading it regularly, etc.

[0226] Schematically, in the local area network, class A addresses are usually assigned to specific institutions; class B addresses are usually assigned to medium-sized companies; class C addresses are usually assigned to any object that needs to form a local area network, such as a home network is usually a class C address.

[0227] Optionally, when performing account detection, the detection is defaultly performed on Class C addresses, and the detection range can be updated by means of configuration distribution. If the black production team uses Class B addresses, it needs to be dynamically configured and updated. For example, the detection range can be configured for regions, IPs, etc. to achieve a more flexible detection process.

[0228] In some embodiments, it is assumed that the usage objects include smart TVs, desktop computers, mobile phones, and tablets. If screen recording is performed through a desktop computer, it can be found that the account logged in to the desktop computer is a blacklist account. Then the desktop computer regularly reads the blacklist information and starts detection. If it immediately discovers that the online smart TV is the first team, at this time the desktop computer will report its own account information and the other party's account information. The smart TV, as the detected party, will also report its own IP information, etc. for problem positioning. At the same time, the smart TV, as the second-level detector, continues to detect. After the usage object shuts down the desktop computer, if screen recording needs to be performed using a tablet computer, when the tablet computer is powered on, it will also be detected by the smart TV, thereby restricting the account.

[0229] Optionally, the maximum detection level can also be limited here. For example, the maximum detection is 6 times. If it is identified as a blacklist account during the second-level detection, the detection level can also be updated to the first level.

[0230] Therefore, as long as there are two devices logged in with accounts running, that is, two accounts are online at the same time, the above process can be used to continuously detect each other's accounts. At the same time, the detailed information passed through the router can be reported through traceroute.

[0231] Generally, the network of a local area network is relatively simple and there are relatively few routers. Therefore, when performing multicast detection, the Time to Live (TtL) in the network can be set to 2, so as to achieve the detection of only the devices passing through one router in the middle.

[0232] Among them, TtL is a mechanism used in computer networks to limit the transmission time or number of hops of data packets in the network, which can prevent data packets from circulating forever in the network and limit the transmission time of data packets in the network to avoid endless circulation of data packets caused by network problems.

[0233] Generally speaking, devices such as smart TVs and desktop computers are less likely to move, so it is sufficient to detect the interface under Wireless Fidelity (WiFi). For mobile devices such as mobile phones, it may be necessary to limit the detection time period because the user may be out. For example, detect the account at night or when the IP address remains the same as the previous one. At the same time, it is necessary to keep the device alive, that is, the detection can continue even when the application is in the background.

[0234] In some embodiments, when reporting the device information corresponding to the detecting party and the detected party respectively, the device information includes at least one of various IP information such as network card IP, external network IP, CDN IP, device model, User-agent, etc., so as to make subsequent judgments and avoid situations such as company networks or large-scale bans. For scenarios such as Internet cafes and companies, the issue of the scale of the object needs to be considered. If the detection range is large, abnormal cases need to be considered.

[0235] As Figure 10 shown, it is a schematic diagram of executing the above information processing method in a local area network.

[0236] The local area network 1010 includes multiple devices, such as some devices with relatively fixed positions: desktop computers, smart TVs, World Wide Web (WEB), etc.; and also includes some devices with more flexible mobility, such as: tablet computers, portable laptops, mobile phones, etc.; multiple devices are connected to the Internet through a router 1020. That is: the information processing method provided by the embodiments of the present application can be applied to scenarios where the device location is relatively fixed, and can also be applied to scenarios where the device location is relatively flexible. Thus, considering the situation where devices logged in with multiple blacklist accounts are concentrated in a relatively fixed place, the local area network is used to flexibly analyze other devices that move to this place, improving the detection strength of blacklist accounts logged in on devices, facilitating obtaining a more comprehensive second account list, and thus helping to maintain platform security by restricting blacklist accounts and avoiding potential hazards caused by malicious behaviors.

[0237] It should be noted that the above are only illustrative examples, and the embodiments of the present application are not limited thereto.

[0238] In summary, under the condition that the first account is known to be a blacklist account, the first device can be used as a device for detecting blacklist accounts to detect the account of the second device belonging to the same multicast group. Thus, based on the account running situation of the second account on the second device, it is assisted to determine whether the second account is a blacklist account, avoiding the problem that a single account is logged in on the device and the account cannot be determined. The diffusion detection process of the device is realized in the form of a multicast group, improving the detection strength of blacklist accounts, facilitating obtaining a more comprehensive second account list, and thus helping to maintain platform security by restricting blacklist accounts and avoiding potential hazards caused by malicious behaviors.

[0239] Figure 11 It is a structural block diagram of an information processing device provided by an exemplary embodiment of the present application. As Figure 11 shown, the device includes the following parts:

[0240] A first acquisition module 1110, configured to acquire a first account list, where the first account list includes at least one restricted account, and the restricted account is an account whose account behavior is restricted;

[0241] A device determination module 1120, configured to, in response to the first account being included in the at least one restricted account, determine a second device having a communication association relationship with the first device, where the first account is an account logged in to the first device, and the communication association relationship is used to indicate that the first device and the second device are located in the same multicast group, and the second device logs in to a second account;

[0242] A second acquisition module 1130, configured to acquire a second account list when the account status corresponding to the second account meets the account joining condition, where the account status is used to indicate the account running situation of the second account on the second device; the second account list is an updated list obtained by adding the second account to the first account list.

[0243] In an optional embodiment, the device determination module 1120 is further configured to, in response to the first account being included in the at least one restricted account, send a multicast probe message to a preset multicast address corresponding to the multicast group, where the multicast probe message is used to acquire device information of devices located in the multicast group, the preset multicast address is used to broadcast the multicast probe message to multiple devices in the multicast group, and the device information includes account information of an account logged in to the device; based on the reception of the multicast probe message by devices in the multicast group, determine the second device having the communication association relationship with the first device.

[0244] In an optional embodiment, the device determination module 1120 is further configured to, when devices in the multicast group are in an operating state, receive feedback information respectively sent by multiple devices in the multicast group, where the feedback information is used to indicate the reception situation of the multicast probe message by the device; determine, from the multiple devices, the device for which the feedback information indicates reception of the multicast probe message as the second device having the communication association relationship with the first device.

[0245] In an optional embodiment, the second obtaining module 1130 is further configured to, when the first device and the second device are both in an online state, receive a second account identifier sent by the second device, where the second account identifier is used to uniquely indicate the second account, and the second account identifier belongs to the device information corresponding to the second device; send the second account identifier to an account management platform, where the account management platform is a platform for managing multiple accounts, and the multiple accounts include the first account and the second account; the account management platform is configured to query the account status corresponding to the second account based on the second account identifier, and match the account status with the account joining condition; when the account management platform determines that the account status meets the account joining condition, receive the second account list sent by the account management platform; where the account management platform adds the second account to the first account list when the account status meets the account joining condition.

[0246] In an optional embodiment, the second obtaining module 1130 is further configured to, when the first device determines that the account status meets the account joining condition, send a list update message to the account management platform, where the list update message is used to instruct the account management platform to add the second account to the account list; receive the second account list sent by the account management platform, where the second account list is used to increase the number of restricted accounts for performing account restriction actions.

[0247] In an optional embodiment, the second obtaining module 1130 is further configured to, when the first device and the second device are both in an online state, receive the device information sent by the second device, where the device information includes the account status; match the account status with the account joining condition; when the first device determines that the account status meets the account joining condition, send the list update message to the account management platform.

[0248] In an optional embodiment, the second obtaining module 1130 is further configured to, when the account status indicates that the second account is in a screen recording process through the second device, obtain the second account list, where the screen recording process is a process that meets the account joining condition.

[0249] In an optional embodiment, the second obtaining module 1130 is further configured to, when the account status indicates that the video played by the second account through the second device is a screen recording video, obtain the second account list; where the screen recording video is a video obtained by the restricted account through a screen recording process.

[0250] In an optional embodiment, the second obtaining module 1130 is further configured to obtain the second account list when the account status indicates that the account watermark on the video is not the second account identifier; wherein, the account watermark is used to represent the account identifier corresponding to the restricted account that records the screen recording video.

[0251] In an optional embodiment, the first obtaining module 1110 is further configured to detect a preset multicast port corresponding to the multicast group when the first device runs a preset application, where the preset application is used to log in to the first account in the first device, and the preset multicast port is used to transfer the first account list collected by the program background of the preset application to the first device; and receive the first account list sent by the preset multicast port.

[0252] In an optional embodiment, a multicast association component is deployed inside the preset application;

[0253] The first obtaining module 1110 is further configured to call the multicast association component to detect the preset multicast port corresponding to the multicast group when the first device runs the preset application; wherein, the multicast association component is used to establish a communication association relationship between the first device and the second device within a local area network.

[0254] In summary, under the condition that the first account is known to be a restricted account, the first device can be used as a device for detecting restricted accounts to perform account detection on the second device belonging to the same multicast group, so as to assist in determining whether the second account is a restricted account based on the account running situation of the second account on the second device, avoiding the problem that a single account cannot be determined when the device logs in, realizing the diffusion detection process of the device in the form of a multicast group, improving the detection intensity of restricted accounts, facilitating the acquisition of a more comprehensive second account list, and thus helping to maintain platform security by restricting restricted accounts and avoiding potential hazards caused by malicious behaviors.

[0255] It should be noted that: the information processing device provided in the above embodiment is only illustrated by dividing the above functional modules. In actual application, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the information processing device provided in the above embodiment and the information processing method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0256] In an optional embodiment, the above information processing method is executed by a computer device, and the computer device can be implemented as a terminal or a server.

[0257] In some embodiments, a computer device that executes an information processing method is taken as an example of a server for illustration. As Figure 12 shown, it is a schematic structural diagram of a server provided for an exemplary embodiment. The server 1200 includes a Central Processing Unit (CPU) 1201, a system memory 1204 including a Random Access Memory (RAM) 1202 and a Read Only Memory (ROM) 1203, and a system bus 1205 connecting the system memory 1204 and the central processing unit 1201. The server 1200 also includes a mass storage device 1206 for storing an operating system 1213, application programs 1214, and other program modules 1215.

[0258] The mass storage device 1206 is connected to the central processing unit 1201 through a mass storage controller (not shown) connected to the system bus 1205. The mass storage device 1206 and its associated computer-readable medium provide non-volatile storage for the server 1200. That is to say, the mass storage device 1206 may include a computer-readable medium (not shown) such as a hard disk or a Compact Disc Read Only Memory (CD-ROM) drive.

[0259] Without loss of generality, computer-readable media may include computer storage media and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. The above-mentioned system memory 1204 and mass storage device 1206 may be collectively referred to as memory.

[0260] According to various embodiments of the present application, the server 1200 may also run on a remote computer on the network through a network such as the Internet. That is, the server 1200 may be connected to the network 1212 through a network interface unit 1211 connected to the system bus 1205, or in other words, the network interface unit 1211 may also be used to connect to other types of networks or remote computer systems (not shown).

[0261] The above-mentioned memory further includes one or more programs, and one or more programs are stored in the memory and are configured to be executed by the CPU.

[0262] An embodiment of the present application also provides a computer device, which includes a processor and a memory. At least one program is stored in the memory, and the at least one program is loaded and executed by the processor to implement the information processing method provided by each of the above method embodiments.

[0263] An embodiment of the present application also provides a computer-readable storage medium, on which at least one program is stored. The at least one program is loaded and executed by the processor to implement the information processing method provided by each of the above method embodiments.

[0264] An embodiment of the present application also provides a computer program product or a computer program, which includes computer instructions. The computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the information processing method described in any one of the above embodiments.

[0265] The foregoing are only optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. An information processing method, characterized in that, The method includes: Obtaining a first account list, where the first account list includes at least one restricted account, and the restricted account is an account whose account behavior is restricted; In response to the first account being included in the at least one restricted account, determining a second device that has a communication association relationship with the first device, where the first account is an account logged in on the first device, and the communication association relationship is used to represent that the first device and the second device are in the same multicast group, and the second device is logged in with a second account; When the account status corresponding to the second account meets the account joining condition, obtaining a second account list, where the account status is used to represent the account running situation of the second account on the second device; the second account list is an updated list obtained by adding the second account to the first account list.

2. The method according to claim 1, characterized in that, The determining, in response to the first account being included in the at least one restricted account, a second device that has a communication association relationship with the first device includes: In response to the first account being included in the at least one restricted account, sending a multicast probe message to a preset multicast address corresponding to the multicast group, where the multicast probe message is used to obtain device information of devices in the multicast group, the preset multicast address is used to broadcast the multicast probe message to multiple devices in the multicast group, and the device information includes account information of the account logged in on the device; Based on the reception of the multicast probe message by the devices in the multicast group, determining the second device that has the communication association relationship with the first device.

3. The method according to claim 2, wherein The determining, based on the reception of the multicast probe message by the devices in the multicast group, a second device that has the communication association relationship with the first device includes: When the devices in the multicast group are in an operating state, receiving feedback information respectively sent by multiple devices in the multicast group, where the feedback information is used to represent the reception situation of the multicast probe message by the device; Determining, from the multiple devices, the device whose feedback information indicates that the multicast probe message has been received as the second device that has the communication association relationship with the first device.

4. The method according to any one of claims 1 to 3, characterized in that, When the account status corresponding to the second account meets the account joining condition, obtaining a second account list includes: Under the condition that the first device and the second device are both in an online state, receiving a second account identifier sent by the second device, where the second account identifier is used to uniquely indicate the second account, and the second account identifier belongs to the device information corresponding to the second device; Sending the second account identifier to an account management platform, where the account management platform is a platform for managing multiple accounts, and the multiple accounts include the first account and the second account; the account management platform is used to query the account status corresponding to the second account based on the second account identifier and match the account status with the account joining condition. When it is determined that the account status meets the account joining conditions on the account management platform, receive the second account list sent by the account management platform; wherein, the account management platform adds the second account to the first account list when the account status meets the account joining conditions.

5. The method according to any one of claims 1 to 3, characterized in that, The obtaining the second account list when the account status corresponding to the second account meets the account joining conditions includes: When it is determined that the account status meets the account joining conditions on the first device, send a list update message to the account management platform, where the list update message is used to instruct the account management platform to add the second account to the account list; Receive the second account list sent by the account management platform, where the second account list is used to increase the number of restricted accounts for performing account restriction actions.

6. The method according to claim 5, characterized in that, The sending a list update message to the account management platform when it is determined that the account status meets the account joining conditions on the first device includes: Under the condition that the first device and the second device are both in an online state, receive the device information sent by the second device, where the device information includes the account status; Match the account status with the account joining conditions; When it is determined that the account status meets the account joining conditions on the first device, send the list update message to the account management platform.

7. The method according to any one of claims 1 to 3, characterized in that The obtaining the second account list when the account status corresponding to the second account meets the account joining conditions includes: When the account status indicates that the second account is in a screen recording process through the second device, obtain the second account list, where the screen recording process is a process that meets the account joining conditions.

8. The method according to any one of claims 1 to 3, characterized in that The obtaining the second account list when the account status corresponding to the second account meets the account joining conditions includes: When the account status indicates that the video played by the second account through the second device is a screen recording video, obtain the second account list; Wherein, the screen recording video is a video obtained by the restricted account through a screen recording process.

9. The method according to claim 8, characterized in that, The obtaining the second account list when the account status indicates that the video played by the second account through the second device is a screen recording video includes: When the account status indicates that the account watermark on the video played by the second device is not the second account identifier, obtain the second account list; Wherein, the account watermark is used to represent the account identifier corresponding to the restricted account that recorded the screen recording video.

10. The method according to any one of claims 1 to 3, characterized in that, The obtaining the first account list includes: When the first device runs a preset application, detect the preset multicast port corresponding to the multicast group, where the preset application is used to log in the first account on the first device, and the preset multicast port is used to transfer the first account list collected by the program background of the preset application to the first device; Receive the first account list sent by the preset multicast port.

11. The method according to claim 10, wherein The preset application has a multicast association component deployed inside; When the first device runs a preset application program, detecting a preset multicast port corresponding to the multicast group includes: When the first device runs the preset application program, invoking the multicast association component to detect the preset multicast port corresponding to the multicast group; wherein the multicast association component is used to establish a communication association relationship between the first device and the second device within a local area network.

12. An information processing apparatus, characterized in that, The apparatus includes: A first acquisition module, configured to acquire a first account list, where the first account list includes at least one restricted account, and the restricted account is an account whose account behavior is restricted; A device determination module, configured to, in response to the first account being included in the at least one restricted account, determine a second device having a communication association relationship with the first device, where the first account is an account logged in to the first device, and the communication association relationship is used to represent that the first device and the second device are in the same multicast group, and the second device logs in to a second account; A second acquisition module, configured to, when the account status corresponding to the second account meets the account joining condition, acquire a second account list, where the account status is used to represent the account running condition of the second account on the second device; the second account list is an updated list obtained by adding the second account to the first account list.

13. A computer device, characterized in that, The computer device includes a processor and a memory, and at least one program is stored in the memory, and the at least one program is loaded and executed by the processor to implement the information processing method according to any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that, At least one program is stored in the storage medium, and the at least one program is loaded and executed by a processor to implement the information processing method according to any one of claims 1 to 11.

15. A computer program product, characterized in that, Including computer instructions, which implement the information processing method according to any one of claims 1 to 11 when executed by a processor.