Big Data-Based Abnormal User Analysis System

By analyzing user behavior data from multiple dimensions on the gaming platform, abnormal users can be identified and dealt with, solving the problem that the existing system cannot adapt to dynamic changes and improving the fairness of the gaming environment and player satisfaction.

CN120324913BActive Publication Date: 2025-10-31HANGZHOU KAIKAI NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510488869.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-10-31
Estimated Expiration
2045-04-18

AI Technical Summary

Technical Problem

Existing big data-based abnormal user analysis systems are unable to deeply explore user behavior patterns and underlying logic, and cannot adapt to the dynamic changes in the game environment and user behavior, resulting in reduced accuracy in abnormal user identification.

Method used

By acquiring behavioral characteristic data of game platform users, we can perform multi-dimensional segmentation and collection, calculate the deviation between user behavior and normal behavior, and assess and determine whether the user is in an abnormal state. This includes analysis of various aspects such as login time patterns, game duration, game operation frequency, recharge amount and recharge frequency.

Benefits of technology

It enables timely identification and handling of abnormal users, maintains the fairness and normal order of the game, enhances player trust and satisfaction, ensures that players play in a fair environment, and improves the game experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120324913B_ABST
    Figure CN120324913B_ABST
Patent Text Reader

Abstract

This invention discloses an abnormal user analysis system based on big data, belonging to the field of big data technology. Its key technical solution includes a segmentation module: acquiring behavioral characteristic data of game platform users; classifying game platform users according to the degree of abnormality in the behavioral characteristic data to obtain a user category segmentation result set; collecting behavioral data from the second category of users in the user category segmentation result set according to different monitoring dimensions to obtain a first behavior dataset, a second behavior dataset, and a third behavior dataset; extracting the abnormal deviation between the user behavior and normal behavior of the second category of users under different monitoring dimensions to obtain a first risk dataset, a second risk dataset, and a third risk dataset, respectively; the effect is that by effectively identifying and handling abnormal users, the fairness and normal order of the game are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of big data technology, and more specifically, to an anomaly user analysis system based on big data. Background Technology

[0002] In today's digital age, the gaming industry is booming, and the number of users on gaming platforms is experiencing explosive growth. As the player base continues to expand, gaming platforms face a series of management and operational challenges, among which the identification and handling of abnormal user behavior has become a critical issue that urgently needs to be addressed.

[0003] With the rise of big data technology, some gaming platforms have begun to explore using data statistical analysis to identify anomalous users. However, existing big data-based anomalous user analysis systems often focus only on surface-level user behavior data, such as login frequency and spending amounts, lacking in-depth analysis of user behavior patterns and underlying logic. Moreover, these analyses are mostly static and cannot adapt to the dynamic changes in the gaming environment and user behavior. For example, during game promotional events, user spending behavior and game duration may change, but traditional static analysis methods cannot adjust their judgment criteria in a timely manner, leading to reduced accuracy in identifying anomalous users. Summary of the Invention

[0004] In view of the shortcomings of existing technologies, the purpose of this invention is to provide an abnormal user analysis system based on big data.

[0005] To achieve the above objectives, the present invention provides the following technical solution:

[0006] A big data-based abnormal user analysis system includes:

[0007] Segmentation Module: Acquires behavioral characteristic data of game platform users, and classifies game platform users into categories based on the degree of anomaly in the behavioral characteristic data to obtain a user category segmentation result set;

[0008] Data collection module: Collects behavioral data from the second category of users in the user category division result set according to different monitoring dimensions to obtain the first behavioral dataset, the second behavioral dataset, and the third behavioral dataset;

[0009] Acquisition module: Extract the abnormal deviation between the user behavior and normal behavior of the second type of users under different monitoring dimensions to obtain the first risk dataset, the second risk dataset, and the third risk dataset, respectively;

[0010] Evaluation module: Based on the first row dataset, the second row dataset, the third row dataset, the first risk dataset, the second risk dataset, and the third risk dataset, evaluate the abnormal situations of the second type of users in the user category classification result set to obtain the first unprocessed evaluation result set, the second unprocessed evaluation result set, and the third unprocessed evaluation result set;

[0011] Judgment Module: Based on the first set of pending evaluation results, the second set of pending evaluation results, and the third set of pending evaluation results, determine whether the second category of users in the user category classification result set is in an abnormal state.

[0012] Preferably, the behavioral characteristic data of the game platform users includes the login time pattern, game duration, game operation frequency, recharge amount, and recharge frequency of the game platform users.

[0013] Preferably, the user classification result set is obtained by classifying game platform users based on the degree of anomaly in behavioral feature data, specifically including the following steps:

[0014] Set corresponding normal range thresholds based on different behavioral characteristic data;

[0015] Users whose behavioral characteristics are all within the normal range threshold are classified as the first category of users;

[0016] Users whose behavioral characteristics fall within the normal range threshold are classified as second-category users.

[0017] Users whose behavioral characteristics data are all outside the normal range threshold are classified as third category users;

[0018] The first category of users, the second category of users, and the third category of users are combined to form the user category classification result set.

[0019] Preferably, the acquisition module specifically includes the following steps:

[0020] For the data monitoring and collection of the second type of users, a first monitoring and collection dimension, a second monitoring and collection dimension, and a third monitoring and collection dimension are set.

[0021] The first behavior dataset is obtained by collecting data on the game social behavior and item usage of the second type of users based on the first monitoring and collection dimension. The second behavior dataset is obtained by collecting data on the game battle results and opponent matching of the second type of users based on the second monitoring and collection dimension. The third behavior dataset is obtained by collecting data on the login status and IP address changes of the second type of users based on the third monitoring and collection dimension.

[0022] Preferably, the acquisition module specifically includes the following steps:

[0023] The deviation between the user behavior and normal behavior of the second type of users is calculated under the first monitoring and collection dimension, the second monitoring and collection dimension, and the third monitoring and collection dimension respectively to obtain the first deviation dataset, the second deviation dataset, and the third deviation dataset;

[0024] The first risk dataset is obtained by predicting the risk of abnormal user behavior of the second type of users based on the first deviation dataset.

[0025] The second risk dataset is obtained by predicting the risk of abnormal user behavior of the second type of users based on the second deviation dataset.

[0026] The abnormal deviation of each user behavior from normal behavior in the third monitoring and collection dimension is extracted to obtain the third risk dataset.

[0027] Preferably, the evaluation module specifically includes the following steps:

[0028] Based on the first risk dataset and the first behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the first evaluation result set to be processed;

[0029] Based on the second risk dataset and the second behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the second evaluation result set to be processed;

[0030] The third set of evaluation results is obtained by processing and evaluating the first row dataset, the second row dataset, the third deviation dataset, and the third row dataset.

[0031] Preferably, the third evaluation result set is obtained by processing and evaluating the first row dataset, the second row dataset, the third deviation dataset, and the third row dataset, specifically including the following steps:

[0032] The first and second time datasets of key nodes in the normal operation behavior pattern of the second type of users were collected based on the first and second behavior datasets.

[0033] The third time dataset is collected based on the third behavior dataset and the key nodes of the second category of user operation behavior information set.

[0034] The time difference dataset is obtained by calculating the difference in arrival time of the key node among the first time dataset, the second time dataset, and the third time dataset;

[0035] Based on the time difference dataset and the third deviation dataset, the risk of abnormal internal behavior of the second category of users is determined, and the third risk dataset is obtained.

[0036] Based on the third risk dataset and the third behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the third evaluation result set to be processed.

[0037] Preferably, the determination module specifically includes the following steps:

[0038] The first verification difference set is obtained by calculating the difference between the data in the first set of evaluation results to be processed and the corresponding data in the standard evaluation set.

[0039] The second verification difference set is obtained by performing difference processing on the data in the second set of evaluation results to be processed and the corresponding data in the standard evaluation set;

[0040] The third verification difference set is obtained by calculating the difference between the data in the third set of evaluation results to be processed and the corresponding data in the standard evaluation set.

[0041] The average value of the verification difference is obtained by calculating the average value of the first verification difference set, the second verification difference set, and the third verification difference set;

[0042] The second category of users in the user category division result set is determined by comparing the average difference between the verification values ​​and the preset verification threshold.

[0043] Preferably, determining whether the second category of users in the user category classification result set is in an abnormal state by comparing the average verification difference with a preset verification threshold specifically includes the following steps:

[0044] If the average verification difference is less than or equal to the preset verification threshold, then the second type of user in the user category division result set is in a normal state.

[0045] If the average verification difference is greater than the preset verification threshold, then the second type of user in the user category division result set is in an abnormal state.

[0046] Compared with the prior art, the present invention has the following beneficial effects:

[0047] This application utilizes user behavior data from multiple dimensions, including login time patterns, game duration, game operation frequency, recharge amount, and recharge frequency. This comprehensive application of multi-dimensional data avoids the one-sidedness of judging anomalies based on only one or a few dimensions. It calculates the deviation between user behavior and normal behavior under different monitoring dimensions and predicts the risk of abnormal behavior accordingly. By analyzing data such as game battle results and opponent matching, it can promptly detect whether players are using cheats, exploiting game vulnerabilities, or engaging in other cheating behaviors. If such abnormal users are found, the operator can take timely measures such as banning accounts and restricting game functions to effectively maintain a fair competitive environment in the game. This ensures that all players can play the game in a fair environment, increasing player trust and satisfaction. By effectively identifying and handling abnormal users, the system guarantees the fairness and normal order of the game, creating a healthy game ecosystem for players. In such an environment, players can focus more on the game itself, enjoy the fun of the game, and enhance their gaming experience. Attached Figure Description

[0048] Figure 1 This is a schematic diagram of the modules of the abnormal user analysis system based on big data proposed in this invention;

[0049] Figure 2 This invention provides a schematic diagram illustrating the steps of the acquisition module in a big data-based abnormal user analysis system.

[0050] Figure 3 This invention presents a schematic diagram illustrating the steps of the evaluation module in a big data-based abnormal user analysis system. Detailed Implementation

[0051] Reference Figures 1 to 3 As shown.

[0052] The embodiments further illustrate the abnormal user analysis system based on big data proposed in this invention.

[0053] A big data-based abnormal user analysis system includes:

[0054] Segmentation Module: Acquires behavioral characteristic data of game platform users, and classifies game platform users into categories based on the degree of anomaly in the behavioral characteristic data to obtain a user category segmentation result set;

[0055] Data collection module: Collects behavioral data from the second category of users in the user category division result set according to different monitoring dimensions to obtain the first behavioral dataset, the second behavioral dataset, and the third behavioral dataset;

[0056] Acquisition module: Extract the abnormal deviation between the user behavior and normal behavior of the second type of users under different monitoring dimensions to obtain the first risk dataset, the second risk dataset, and the third risk dataset, respectively;

[0057] Evaluation module: Based on the first row dataset, the second row dataset, the third row dataset, the first risk dataset, the second risk dataset, and the third risk dataset, evaluate the abnormal situations of the second type of users in the user category classification result set to obtain the first unprocessed evaluation result set, the second unprocessed evaluation result set, and the third unprocessed evaluation result set;

[0058] Judgment Module: Based on the first set of pending evaluation results, the second set of pending evaluation results, and the third set of pending evaluation results, determine whether the second category of users in the user category classification result set is in an abnormal state.

[0059] The game platform of this application obtains user behavior data in real time through background logs and other means, covering login time patterns, game duration, game operation frequency, recharge amount and recharge frequency, etc.

[0060] Users whose behavioral characteristics are all within the normal threshold range are classified as Category 1 users, i.e., normal users, such as player A mentioned above. All data meet the set threshold range, so they can be classified as Category 1 users. Users whose behavioral characteristics are partially within the normal threshold range are classified as Category 2 users, i.e., suspected abnormal users, such as player C. Their login time and game time are normal, but their recharge amount suddenly exceeds 1,000 yuan for three consecutive months, far exceeding the normal threshold range. Other data such as operation frequency are normal, so player C belongs to Category 2 users. Users whose behavioral characteristics are all outside the normal threshold range are classified as Category 3 users, i.e., abnormal users, such as player D. Their login time is chaotic, their game time is extremely short or extremely long, their operation frequency is extremely low, and their recharge amount and frequency are seriously beyond the normal range, so they can be classified as Category 3 users. These three categories of users are combined to form the user category classification result set.

[0061] For data monitoring and collection of the second type of users, the following three dimensions are set: first monitoring and collection dimension (game social behavior and item usage), second monitoring and collection dimension (game battle results and opponent matching), and third monitoring and collection dimension (login status and IP address changes).

[0062] The deviation of user behavior from normal behavior for the second type of users is calculated under the first, second, and third monitoring and data collection dimensions, respectively. For example, under the first monitoring and data collection dimension, the deviation of player E's friend-adding frequency and chat frequency is calculated by comparing data such as the average frequency of adding friends and the number of chats of normal users to obtain the first deviation dataset; similarly, the deviation of player F's win rate and opponent level is calculated under the second monitoring and data collection dimension to obtain the second deviation dataset; and the deviation of player G's login device change frequency and IP address change is calculated under the third monitoring and data collection dimension to obtain the third deviation dataset.

[0063] The first risk dataset is obtained by predicting the risk of abnormal user behavior for the second type of users based on the first deviation dataset. For example, the probability of player E using cheats or engaging in game cheating social behavior is predicted based on the first deviation dataset. Similarly, the second risk dataset is obtained by predicting the risk of abnormal behavior for player F based on the second deviation dataset, and the third risk dataset is obtained by extracting the abnormal deviation of player G's various user behaviors from normal behavior based on the third deviation dataset.

[0064] The first set of evaluation results to be processed is obtained by evaluating the anomalies of the second category of users in the user category division result set based on the first risk dataset and the first behavior dataset. For example, for player E, the anomaly evaluation result in terms of game social interaction and item usage is obtained by weighting the predicted risk probability of cheating social behavior in the first risk dataset and combining it with the specific social behavior and item usage in the first behavior dataset.

[0065] The second set of evaluation results is obtained by assessing the abnormal situations of the second type of users based on the second risk dataset and the second behavior dataset. For example, player F is evaluated and scored based on the abnormal battle risk probability in the second risk dataset, combined with the battle results and matched opponents in the second behavior dataset, to obtain the abnormal situation evaluation result of his game battle.

[0066] Based on the first and second behavior datasets, key nodes of the normal operational behavior patterns of the second type of users were collected, including first-time datasets and second-time datasets. For example, the time points when player E uses certain key items, and the key time points when player F wins a battle.

[0067] The third time dataset is a key node of the second category of user operation behavior information set collected based on the third behavior dataset, such as the time when player G changed login device.

[0068] Based on the third risk dataset and the third behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the third evaluation result set to be processed.

[0069] The first verification difference set is obtained by calculating the difference between the data in the first set of evaluation results to be processed and the corresponding data in the standard evaluation set. Then, the relevant data of the first verification difference set is obtained by calculating the difference. Similarly, the same operation is performed on the second and third sets of evaluation results to be processed to obtain the second and third verification difference sets, respectively.

[0070] The average of the first, second, and third verification difference sets is calculated to obtain the verification average difference.

[0071] Behavioral characteristics data of game platform users include login time patterns, game duration, game operation frequency, recharge amount, and recharge frequency.

[0072] The user classification result set is obtained by classifying game platform users based on the degree of anomaly in behavioral feature data, specifically including the following steps:

[0073] Set corresponding normal range thresholds based on different behavioral characteristic data;

[0074] Users whose behavioral characteristics are all within the normal range threshold are classified as the first category of users;

[0075] Users whose behavioral characteristics fall within the normal range threshold are classified as second-category users.

[0076] Users whose behavioral characteristics data are all outside the normal range threshold are classified as third category users;

[0077] The user category results set consists of the first category of users, the second category of users, and the third category of users.

[0078] This application uses a large amount of historical login data from gaming platforms to determine the distribution pattern of login times for most normal users. For example, if a mobile game's statistics show that 70% of users habitually log in between 7 PM and 10 PM, and the login time fluctuates within ±1 hour, then the threshold for the normal login time range is set as 6 PM to 11 PM.

[0079] Based on game type and player activity statistics, for example, in a role-playing game, the average player plays for 2-4 hours per day. Considering individual differences among players and special circumstances such as weekends, the normal range threshold for game time is set to 1-6 hours per day.

[0080] The game counts and statistics various operations. For example, in an action game, a normal player performs about 40-60 operations such as skill release and movement per hour. Therefore, the normal range threshold for game operation frequency is set to 30-70 times per hour.

[0081] By analyzing in-game spending and player spending power, if the in-game item prices are set such that the average player spends between 50 and 300 yuan per month, the normal spending range threshold can be set to 0-500 yuan per month (0 yuan represents players who do not spend money).

[0082] Statistically analyze the time intervals and frequency of player recharges. If most players recharge 1-3 times per month, then set the threshold for the normal range of recharge frequency to 0-5 times per month.

[0083] First category of users: For example, player Xiao Li logs into the game around 8 PM every night, plays for about 3 hours, performs about 50 actions per hour, and spends 200 yuan per month, recharging twice a month. All of Xiao Li's behavioral characteristics—login time, game time, action frequency, recharge amount, and recharge frequency—are within the aforementioned normal threshold range. Therefore, Xiao Li is classified as a first category user, i.e., a normal user. This type of user exhibits stable behavior, conforms to the game's normal ecosystem, and represents the core active group of the game platform.

[0084] The second category of users is categorized as follows: For example, player Zhang's login time, game duration, and game operation frequency are all within the normal range. However, his recharge amount suddenly reached 800 yuan in the past month, far exceeding the normal range threshold of 0-500 yuan per month, while other behavioral characteristics are normal. Because some of Zhang's behavioral characteristics are within the normal range threshold, he is classified as a second category user, namely a suspected abnormal user. These users may have some special circumstances or be beginning to show a trend of deviating from normal behavior, requiring further monitoring and analysis.

[0085] The third category of users is categorized as follows: For example, player Xiao Zhao's login times are completely irregular, sometimes logging in at midnight and sometimes during the day, far exceeding the normal range of 6 PM to 11 PM; his game time is either only a few minutes or as long as 8 hours or more, not within the normal range of 1-6 hours; his game operation frequency is extremely low, less than 20 times per hour, and also not within the range of 30-70 times; moreover, his recharge amount and frequency are almost zero, completely outside the normal threshold. All of Xiao Zhao's behavioral characteristics are outside the normal threshold, therefore he is classified as a third category user, i.e., identified as an abnormal user. This type of user may engage in malicious data manipulation, use cheats, or other behaviors that seriously damage the game ecosystem.

[0086] The data acquisition module specifically includes the following steps:

[0087] For the data monitoring and collection of the second type of users, a first monitoring and collection dimension, a second monitoring and collection dimension, and a third monitoring and collection dimension are set.

[0088] The first behavior dataset is obtained by collecting data on the game social behavior and item usage of the second type of users based on the first monitoring and collection dimension. The second behavior dataset is obtained by collecting data on the game battle results and opponent matching of the second type of users based on the second monitoring and collection dimension. The third behavior dataset is obtained by collecting data on the login status and IP address changes of the second type of users based on the third monitoring and collection dimension.

[0089] The second monitoring and data collection dimension focuses on in-game social behavior and item usage. In-game social behavior encompasses actions such as adding friends, forming teams, and chatting among players; item usage includes information such as the frequency, timing, and type of items used. For example, in a massively multiplayer online role-playing game (MMORPG), where player social interactions are frequent and the item system is rich and diverse, this dimension can effectively capture players' behavioral characteristics in terms of social interaction and item usage.

[0090] The second monitoring and data collection dimension primarily focuses on game battle results and opponent matching. Game battle results include data such as wins / losses, scores, and kills; opponent matching involves information such as the opponent's level, rank, and win rate. Taking competitive games as an example, battles are the core gameplay, and this dimension can accurately obtain information on player performance and opponent-related details during battles.

[0091] The third monitoring and data collection dimension focuses on login activity and IP address changes. Login activity includes login time, login device, and login location; IP address changes record the frequency and origin of player IP address changes during login. Regardless of the game, player login is a fundamental behavior, and this dimension tracks various dynamics related to player logins.

[0092] First-order behavior dataset collection: Taking player Xiao Wang as an example, he belongs to the second type of user. According to the first monitoring and collection dimension, the game system records the number of friends Xiao Wang adds each day through the social module. For example, the number of friends added per month was originally 5-10, but recently it suddenly increased to 30 per month; it records the frequency of Xiao Wang teaming up with other players. In the past, he teamed up 2-3 times a week, but now it has reached 5-6 times a week; at the same time, it monitors the number of times Xiao Wang speaks in the game chat channel and the content tendency, and finds that he has recently been frequently asking about game cheat information. In terms of item usage, it counts the frequency of Xiao Wang using high-level equipment items. Originally, he used them once every two weeks, but recently he has used them 2-3 times a week. These data on game social behavior and item usage are summarized to constitute Xiao Wang's first-order behavior dataset.

[0093] The second behavioral dataset collection: Continuing with player Xiao Wang as an example, in the game's battle mode, according to the second monitoring dimension, the game server records Xiao Wang's recent battle results. His win rate was originally maintained at 40%-50%, but in the past week, it has surged to 80%. Simultaneously, the data on Xiao Wang's matched opponents is recorded. It was found that previously, most of his opponents were players of similar level with win rates between 40%-60%, while now, a large number of his opponents are significantly lower level and have win rates below 20%. This data on battle results and opponent matching forms Xiao Wang's second behavioral dataset.

[0094] The third-line dataset collection: Continuing with player Xiao Wang as an example, based on the third monitoring dimension, the game login system records that Xiao Wang previously used the same mobile phone to log in to the game in his city of residence. However, recently, he has begun frequently changing login devices, using tablets and different models of mobile phones; the login location has also changed from the previously fixed city of residence to multiple different cities, and the corresponding IP addresses are also highly dispersed, frequently changing between different provinces and even different countries. This collection of login and IP address changes constitutes Xiao Wang's third-line dataset.

[0095] The specific steps for obtaining the module are as follows:

[0096] The deviation between the user behavior and normal behavior of the second type of users is calculated under the first monitoring and collection dimension, the second monitoring and collection dimension, and the third monitoring and collection dimension respectively to obtain the first deviation dataset, the second deviation dataset, and the third deviation dataset;

[0097] The first risk dataset is obtained by predicting the risk of abnormal user behavior of the second type of users based on the first deviation dataset.

[0098] The second risk dataset is obtained by predicting the risk of abnormal user behavior of the second type of users based on the second deviation dataset.

[0099] The abnormal deviation of each user behavior from normal behavior in the third monitoring and collection dimension is extracted to obtain the third risk dataset.

[0100] The deviation calculation for the first monitoring dimension of this application is as follows: Regarding game social behavior, the average number of friends added by normal players is 8 per month, while player Xiao Wang has recently added 30 friends per month. The deviation is calculated using the formula (here, the formula is assumed to be: Deviation = (Actual Value - Average) ÷ Standard Deviation; the specific formula depends on the actual statistical method). Assuming the standard deviation of the number of friends added by normal players is 2, then Xiao Wang's deviation in adding friends is (30-8) ÷ 2 = 11. Regarding chat interaction, normal players speak 5 times per day in the game chat channel, while Xiao Wang has recently spoken 20 times per day. If the standard deviation of the normal speaking frequency is 3, his chat speaking deviation is (20-5) ÷ 3 = 5. Combining these data, the relevant content of the first deviation dataset for Xiao Wang's game social behavior is obtained.

[0101] Regarding item usage, a normal player uses high-level equipment items once every two weeks, while Xiao Wang uses them 2-3 times per week. Assuming the standard deviation of high-level item usage frequency is 0.5, taking twice-weekly usage as an example, the deviation is calculated as (2-0.5)÷0.5=3. Integrating this item usage deviation data with the social behavior deviation data forms the complete first deviation dataset.

[0102] The deviation calculation under the second monitoring and collection dimension: In terms of game battle results, Xiao Wang's win rate was originally maintained at 40%-50%, but recently it has soared to 80%. Assuming that the standard deviation of a normal player's win rate is 5%, the deviation is calculated using the formula (deviation = (actual win rate - average win rate) ÷ standard deviation). Xiao Wang's win rate deviation = (80% - 45%) ÷ 5% = 7. In terms of battle score, the average score per game was originally 50 points, but recently it has reached 80 points per game. If the standard deviation of the score is 10 points, the score deviation = (80 - 50) ÷ 10 = 3.

[0103] Regarding the opponent matching, under normal circumstances, the average level of the opponents Xiao Wang is matched with is similar to his, with a level difference of ±5 levels. However, the average level of the opponents he has been matched with recently is 20 levels lower than his. Assuming the standard deviation of the opponent level difference is 3 levels, the deviation of his opponent level is approximately (20) ÷ 3 ≈ 6.67. Combining these battle results and the deviation data of the opponent matching, the second deviation dataset is obtained.

[0104] Deviation calculation under the third monitoring and collection dimension: Regarding login status, Xiao Wang has always used the same mobile phone to log in to the game in his city of residence. Recently, he has frequently changed login devices, having used 3 different devices. Normal players change devices on average every six months. Assuming the standard deviation of device change frequency is 0.5 times / six months, the deviation of his login device change is calculated as (3-0.5)÷0.5=5, taking six months as the time period.

[0105] Regarding IP address changes, Xiao Wang's original login IP addresses all originated from his city of residence. Recently, his IP addresses have changed frequently, originating from 5 different provinces. A normal user's IP address changes no more than once per quarter. Assuming a standard deviation of 0.3 times per quarter, and using a quarterly time period, his IP address change deviation is calculated as (5 - 0.5) ÷ 0.3 ≈ 15. Integrating this data yields the third deviation dataset.

[0106] Based on the second deviation dataset, the deviation data of game social behavior and item usage from the first deviation dataset are input into a pre-trained machine learning model. This model has learned a large amount of data features of normal and abnormal players in these dimensions. Based on the model's output, it is predicted that Xiao Wang has a risk of abnormal behavior in game social interactions and item usage, such as potentially trying to use cheat items to attract other players to add him as a friend or engaging in inappropriate social interactions. This results in the first risk dataset, which records information such as the predicted risk type and probability. For example, the predicted probability of Xiao Wang using cheat items is 80%.

[0107] Based on the second deviation dataset, the deviation data of game results and opponent matching in the second deviation dataset are input into a deep learning model specifically designed for analyzing game behavior. This model has learned a large amount of data features of normal and abnormal players in these dimensions. The model predicts that Xiao Wang may engage in cheating behavior during game battles, such as using cheat programs to increase his win rate or matching with low-level opponents to gain an unfair advantage. This results in a second risk dataset, which includes the types of cheating risks and their corresponding probabilities. For example, the predicted probability of Xiao Wang cheating is 75%.

[0108] Extract risk data from the third monitoring and collection dimension: Extract information on Xiao Wang's frequent changes in login devices and abnormal changes in IP addresses from the third deviation dataset. Combine this with historical data on account theft and malicious login to determine whether Xiao Wang's account may be at risk of being stolen or whether he himself may be performing abnormal login operations, such as trying to bypass the game's security detection mechanism through different IP addresses. Obtain the third risk dataset and record the relevant risk information.

[0109] The evaluation module specifically includes the following steps:

[0110] Based on the first risk dataset and the first behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the first evaluation result set to be processed;

[0111] Based on the second risk dataset and the second behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the second evaluation result set to be processed;

[0112] The third set of evaluation results is obtained by processing and evaluating the first row dataset, the second row dataset, the third deviation dataset, and the third row dataset.

[0113] The first set of assessment results to be processed is generated: The first risk dataset for Xiao Wang predicts abnormal behavior risks in game social interactions and item usage, such as an 80% probability of using cheat items. The first behavior dataset collected by the data acquisition module records information such as Xiao Wang adding 30 friends per month (normal players average 8 per month), speaking in the game chat channel 20 times per day (normal players speak 5 times per day), and using high-level equipment items 2-3 times per week (normal players use them once every two weeks). These two datasets are integrated and evaluated using a weighted scoring method. Assuming the weight for abnormal social behavior is 0.6 and the weight for abnormal item usage is 0.4. For social behavior, a scoring standard is set based on the degree of deviation: a high deviation in friend additions scores 8 points, a high deviation in chat speech scores 7 points, and the overall social behavior score is (8 × 0.6 + 7 × 0.4) = 7.6 points. For item usage, a deviation score of 9 points is given based on usage frequency, multiplied by a weight of 0.4 to obtain 3.6 points. Adding the two together, we get a comprehensive score of 11.2 for Xiao Wang in terms of game social interaction and item usage in the first pending assessment result set. The above comprehensive score, along with related behavioral data, risk probability and other information, are compiled into the first pending assessment result set, which clearly records the assessment conclusion of Xiao Wang's abnormal situation in the dimensions of game social interaction and item usage, such as "Game player Xiao Wang has a high abnormal risk in terms of game social interaction and item usage, with a comprehensive score of 11.2 and a risk probability of using cheat items of 80%".

[0114] A second set of assessment results to be processed is generated: The second risk dataset predicts that Xiao Wang may have cheated in the game, with a cheating risk probability of 75%. The second behavior dataset shows that Xiao Wang's win rate has recently soared to 80% (originally 40%-50%), his average score per game has increased from 50 to 80 points, and the average level of his matched opponents is 20 levels lower than his. First, the weights of the game results and the matched opponents in the game anomaly assessment are determined, assuming a weight of 0.7 for the game results and 0.3 for the matched opponents. In the game results, a high win rate deviation scores 9 points, and a high score deviation scores 8 points, for a total game result score of (9 × 0.7 + 8 × 0.3) = 8.7 points; the matched opponents score 7 points based on level deviation, which, multiplied by a weight of 0.3, yields 2.1 points. Adding the two together, we get Xiao Wang's overall score for game battles as 10.8. The overall score, behavioral data, and risk probability are compiled into the second set of assessment results to be processed, which records the assessment conclusions of Xiao Wang's abnormal situation in the game battle dimension, such as "Game player Xiao Wang has a high risk of abnormality in game battles, with an overall score of 10.8 and a probability of cheating in battles of 75%".

[0115] A third set of evaluation results to be processed is generated: The first set of datasets collects the time points when Xiao Wang uses key items, such as using a high-level buff item 5 minutes before a specific dungeon opens; the second set of datasets collects the key moments when Xiao Wang wins a battle, such as achieving a crucial kill with 10 seconds remaining in a key battle. These constitute the first and second time sets. The third set of datasets collects the key moments when Xiao Wang changes his login device and IP address, such as immediately changing devices after a game update and switching his IP address from domestic to international within a short period. The differences in arrival times of these key moments are calculated between the first, second, and third time sets. For example, the difference between the time Xiao Wang uses a high-level item and the time he wins a battle, as well as the differences between these times and the times when his login device and IP address change, are calculated to obtain a time difference dataset.

[0116] Using the third deviation dataset (Xiao Wang's deviation is 5 for changing login devices and 15 for changing IP addresses), a decision tree model was used to assess the risk of abnormal internal behavior. The model, trained on historical data, can identify abnormal behavior based on features such as time difference and deviation. It was determined that Xiao Wang poses a risk of gaining illicit benefits through abnormal login behavior combined with key in-game actions, thus obtaining the third risk dataset.

[0117] Anomalies related to login and account security for Xiao Wang were assessed based on the third risk dataset and the third behavior dataset. A fuzzy comprehensive evaluation method was used, considering multiple factors such as login device changes and IP address variations. Different weights were assigned to these factors, resulting in a final comprehensive score of 9 points. The relevant information was compiled into a third set of pending evaluation results, recording "Game player Xiao Wang has a high risk of anomalies in login and account security, with a comprehensive score of 9 points."

[0118] The third evaluation result set is obtained by processing and evaluating the first row dataset, the second row dataset, the third deviation dataset, and the third row dataset. The specific steps include:

[0119] The first and second time datasets of key nodes in the normal operation behavior pattern of the second type of users were collected based on the first and second behavior datasets.

[0120] The third time dataset is collected based on the third behavior dataset and the key nodes of the second category of user operation behavior information set.

[0121] The time difference dataset is obtained by calculating the difference in arrival times of key nodes among the first time dataset, the second time dataset, and the third time dataset;

[0122] Based on the time difference dataset and the third deviation dataset, the risk of abnormal internal behavior of the second category of users is determined, and the third risk dataset is obtained.

[0123] Based on the third risk dataset and the third behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the third evaluation result set to be processed.

[0124] Taking game player Xiao Wang as an example, the first action dataset records his social and item usage behaviors in the game. Suppose that using a key item in a game can greatly enhance the hero's ability. Xiao Wang used the item 3 minutes before the start of an important team fight. This usage time point becomes a key node in the normal operation behavior pattern and is collected in the first action dataset.

[0125] The second row of the dataset covers game results and opponent matching. In one game, at the 15-minute mark, Xiao Wang's team launched a crucial attack and won. This winning moment was captured in the second time dataset.

[0126] The third row of the dataset mainly concerns Xiao Wang's login activity and IP address changes. Xiao Wang had been consistently logging into the game locally using a fixed device around 8 PM. However, recently, at 7:50 PM one evening, just before a major game event was about to begin, he suddenly switched devices and logged in from an unfamiliar IP address. This login time and related changes were collected in the third-time dataset.

[0127] The time differences for reaching key nodes are calculated in the first, second, and third time datasets. For example, the time difference between Xiao Wang using the key item (first time dataset) and winning the battle (second time dataset) is 12 minutes; the time difference between Xiao Wang's abnormal login time (third time dataset) and using the "Winning Orb" is -10 minutes. These time differences are then compiled and recorded to obtain the time difference dataset.

[0128] The risk of abnormal behavior is judged based on the time difference dataset and the third deviation dataset (Xiao Wang's login device change deviation is high, and the IP address change deviation is also high). The judgment is made by combining the performance of normal players and abnormal players in these dimensions in historical data and using machine learning algorithms (such as support vector machines).

[0129] The analysis revealed that Xiao Wang used key items and won a match shortly after logging in abnormally. This behavior pattern differed significantly from that of normal players. It was determined that Xiao Wang was at risk of using abnormal login behavior in conjunction with key in-game operations to gain an unfair advantage. For example, he might have bypassed the game's anti-cheat detection by changing devices and IP addresses. This led to the creation of a third risk dataset, which records information such as the types and probabilities of his abnormal behavior.

[0130] Generate a third set of pending assessment results: Assuming that based on a comprehensive score of 10 points, Xiao Wang's final score is 8 points. This score, along with relevant behavioral data and risk descriptions, is compiled to generate a third set of pending assessment results, recording that "Game player Xiao Wang has a high risk of abnormal behavior in login and related game activities, with a score of 8 points, and may be using abnormal login to bypass anti-cheating mechanisms."

[0131] The judgment module specifically includes the following steps:

[0132] The first verification difference set is obtained by calculating the difference between the data in the first set of evaluation results to be processed and the corresponding data in the standard evaluation set.

[0133] The second verification difference set is obtained by performing difference processing on the data in the second set of evaluation results to be processed and the corresponding data in the standard evaluation set;

[0134] The third verification difference set is obtained by calculating the difference between the data in the third set of evaluation results to be processed and the corresponding data in the standard evaluation set.

[0135] The average of the first, second, and third verification difference sets is calculated to obtain the verification average difference.

[0136] The second category of users in the user category division result set is determined by comparing the average difference between the verification values ​​and the preset verification threshold.

[0137] The calculation of the first verification difference set in this application is as follows: In the first set of evaluation results to be processed, Xiao Wang's overall score for game social interaction and item usage is 11.2. In the standard evaluation set, for players with normal game social interaction and item usage behavior, the overall score range is 6-8. The average score of 7 is taken as the standard value. The difference is calculated as 11.2 - 7 = 4.2. This difference and related evaluation dimension information are recorded to obtain the relevant data for the first verification difference set. If there are other sub-item data in the first set of evaluation results to be processed, such as abnormal scores for adding friends in social behavior or abnormal scores for item usage frequency, these are also compared with the standard values ​​of the corresponding sub-items in the standard evaluation set and included in the first verification difference set.

[0138] The second verification difference set is calculated as follows: In the second set of evaluation results to be processed, Xiao Wang's overall score in game combat is 10.8. In the standard evaluation set, the overall score range for players with normal game combat behavior is 5-7. Taking the average of 6 as the standard value, the difference is calculated as 10.8-6=4.8. This difference and the corresponding evaluation dimension information are recorded to construct the second verification difference set. If sub-items such as win rate and score in the combat results are involved, they are also differed from the standard value in this way and included in the second verification difference set.

[0139] The third verification difference set is calculated as follows: In the third set of pending evaluation results, Xiao Wang's score for login and account security is 8 points. In the standard evaluation set, the comprehensive score range for players with normal login and account security behavior is 4-6 points. Taking the average of 5 points as the standard value, the calculated difference is 8-5=3. This difference and related information are recorded to form the third verification difference set. If it includes sub-items such as login device change frequency and IP address changes, these are also subtracted from the standard value and integrated into the third verification difference set.

[0140] Calculate the average of the first, second, and third validation difference sets. The data for the first validation difference set is 4.2, the data for the second validation difference set is 4.8, and the data for the third validation difference set is 3. Therefore, the validation average difference is (4.2 + 4.8 + 3) ÷ 3 = 4.

[0141] The determination of whether the second category of users in the user category division result set is in an abnormal state is based on a comparison between the average verification difference and a preset verification threshold. The specific steps include:

[0142] If the average verification difference is less than or equal to the preset verification threshold, then the second type of user in the user category division result set is in a normal state.

[0143] If the average verification difference is greater than the preset verification threshold, then the second type of user in the user category division result set is in an abnormal state.

[0144] Assume the preset verification threshold is 3 (this threshold can be set comprehensively based on the actual situation of the game platform, historical data, and operational needs). Since the calculated average verification difference of 4 is greater than the preset verification threshold of 3, according to the judgment rules, it can be determined that game player Xiao Wang is in an abnormal state.

[0145] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0146] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0147] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An abnormal user analysis system based on big data, characterized in that, include: Segmentation Module: This module acquires behavioral characteristic data of game platform users and categorizes them based on the degree of anomaly in the behavioral characteristic data to obtain a user segmentation result set. Specifically, it includes the following steps: Set corresponding normal range thresholds based on different behavioral characteristic data; Users whose behavioral characteristics are all within the normal range threshold are classified as the first category of users; Users whose behavioral characteristics fall within the normal range threshold are classified as second-category users. Users whose behavioral characteristics data are all outside the normal range threshold are classified as third category users; Among them, the first category of users, the second category of users, and the third category of users are combined to form a user category classification result set; The data collection module: Collects behavioral data from the second category of users in the user category division result set according to different monitoring dimensions to obtain the first behavioral dataset, the second behavioral dataset, and the third behavioral dataset. Specifically, this includes the following steps: For the data monitoring and collection of the second type of users, a first monitoring and collection dimension, a second monitoring and collection dimension, and a third monitoring and collection dimension are set. The first behavior dataset is obtained by collecting data on the game social behavior and item usage of the second type of users based on the first monitoring and collection dimension; the second behavior dataset is obtained by collecting data on the game battle results and matchmaking of the second type of users based on the second monitoring and collection dimension; and the third behavior dataset is obtained by collecting data on the login status and IP address changes of the second type of users based on the third monitoring and collection dimension. Acquisition Module: Extracting the abnormal deviations between the user behavior and normal behavior of the second type of users from different monitoring dimensions to obtain the first risk dataset, the second risk dataset, and the third risk dataset, specifically including the following steps: The deviation between the user behavior and normal behavior of the second type of users is calculated under the first monitoring and collection dimension, the second monitoring and collection dimension, and the third monitoring and collection dimension respectively to obtain the first deviation dataset, the second deviation dataset, and the third deviation dataset; The first risk dataset is obtained by predicting the risk of abnormal user behavior of the second type of users based on the first deviation dataset. The second risk dataset is obtained by predicting the risk of abnormal user behavior of the second type of users based on the second deviation dataset. The abnormal deviation between each user behavior and normal behavior in the third monitoring and collection dimension is extracted to obtain the third risk data; Evaluation module: Based on the first risk dataset and the first behavior dataset, evaluate the abnormal situations of the second type of users in the user category classification result set to obtain the first evaluation result set to be processed; Based on the second risk dataset and the second behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the second evaluation result set to be processed; The third set of evaluation results to be processed is obtained by processing and evaluating the first row dataset, the second row dataset, the third deviation dataset, and the third row dataset. Judgment Module: Based on the first set of pending evaluation results, the second set of pending evaluation results, and the third set of pending evaluation results, determine whether the second category of users in the user category classification result set is in an abnormal state.

2. The abnormal user analysis system based on big data according to claim 1, characterized in that, The behavioral characteristic data of the game platform users includes the login time pattern, game duration, game operation frequency, recharge amount and recharge frequency of the game platform users.

3. The abnormal user analysis system based on big data according to claim 1, characterized in that, The third evaluation result set is obtained by processing and evaluating the first row dataset, the second row dataset, the third deviation dataset, and the third row dataset. The specific steps include: The first and second time datasets of key nodes in the normal operation behavior pattern of the second type of users were collected based on the first and second behavior datasets. The third time dataset is collected based on the third behavior dataset and the key nodes of the second category of user operation behavior information set. The time difference dataset is obtained by calculating the difference in arrival time of the key node among the first time dataset, the second time dataset, and the third time dataset; Based on the time difference dataset and the third deviation dataset, the risk of abnormal internal behavior of the second category of users is determined, and the third risk dataset is obtained. Based on the third risk dataset and the third behavior dataset, the abnormal situations of the second type of users in the user category classification result set are evaluated to obtain the third evaluation result set to be processed.

4. The abnormal user analysis system based on big data according to claim 1, characterized in that, The judgment module specifically includes the following steps: The first verification difference set is obtained by calculating the difference between the data in the first set of evaluation results to be processed and the corresponding data in the standard evaluation set. The second verification difference set is obtained by performing difference processing on the data in the second set of evaluation results to be processed and the corresponding data in the standard evaluation set; The third verification difference set is obtained by calculating the difference between the data in the third set of evaluation results to be processed and the corresponding data in the standard evaluation set. The average value of the verification difference is obtained by calculating the average value of the first verification difference set, the second verification difference set, and the third verification difference set; The second category of users in the user category division result set is determined by comparing the average difference between the verification values ​​and the preset verification threshold.

5. The abnormal user analysis system based on big data according to claim 4, characterized in that, The determination of whether the second category of users in the user category division result set is in an abnormal state is based on a comparison between the average verification difference and a preset verification threshold. The specific steps include: If the average verification difference is less than or equal to the preset verification threshold, then the second type of user in the user category division result set is in a normal state. If the average verification difference is greater than the preset verification threshold, then the second type of users in the user category division result set is in an abnormal state.

Citation Information

Patent Citations

  • Abnormal account identification method and device, computer equipment and storage medium

    CN112329811A

  • User account risk control method and device

    CN112370793A