A marketing risk control system based on big data
By combining hardware rendering unique identification and behavioral timing modeling, with device unique identification and dynamic noise injection, the problem of easy tampering of device identification in existing marketing risk control systems is solved, high-precision user identification and cheating detection are achieved, and the system's anti-bypass capability and user experience are improved.
Patent Information
- Application Number
- CN202510795777.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-06-16
AI Technical Summary
In existing marketing risk control systems, device identification relies on hardware information that is easily tampered with or forged, affecting recognition accuracy, and virtualization technology makes it difficult to effectively intercept fraud detection.
Through hardware rendering unique identification and behavior timing modeling, combined with device unique identification, behavior risk probability model and dynamic noise injection, user operation characteristics can be identified and anti-bypass capabilities can be enhanced.
It achieves high-precision user identification and cheating detection, improves the accuracy of device identification and anti-bypass capabilities, protects the fairness and security of marketing activities, and reduces accidental harm to normal users.
Smart Images

Figure CN120338881B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer software technology, and in particular to a marketing risk control system based on big data. Background Art
[0002] With the rapid development of Internet technology, marketing activities are becoming increasingly digital and networked, and various online marketing methods are emerging one after another, which has harmed the interests of merchants and consumers. In order to effectively combat these cheating behaviors and ensure the fairness and security of marketing activities, marketing risk control technology has come into being.
[0003] For example, Chinese patent application No. 202210079401.5 discloses a marketing anti-cheating system based on big data, which is applied to
[0004] Marketing anti-fraud, the system includes a cloud server and a user terminal; when the system is in operation, the marketing anti-fraud function is implemented through the following steps: when a user performs marketing activity-related operations on the user terminal, a risk identification request is sent to the cloud server. After receiving the request, the cloud server calls the data collection module to send a data collection instruction to the user terminal; the user terminal responds to the data collection instruction, and after receiving the data, the cloud server calls the risk identification control module to perform risk judgment using a blacklist and whitelist database comparison and a risk model judgment method; the cloud server receives the risk judgment instruction; the cloud server transmits the risk judgment instruction to the user terminal as a response to the risk identification request, and the user terminal approves or rejects the user operation based on the risk judgment instruction.
[0005] Existing patented marketing risk control systems rely primarily on device hardware information, such as MAC addresses and IMEI numbers, for device identification. However, this hardware information is easily tampered with or forged, severely impacting device identification accuracy. Furthermore, with the development of virtualization and simulators, fraudsters can leverage these technologies to simulate real-world device environments, further circumventing device identification. Therefore, improving device identification accuracy and preventing bypasses has become a significant challenge for marketing risk control technology. Summary of the Invention
[0006] This application provides a marketing risk control system based on big data, which achieves high-precision user identification and cheating detection through hardware rendering unique identification and behavior timing modeling, thereby protecting the fairness and security of marketing activities.
[0007] The present application provides a marketing risk control system based on big data, which includes a server module, a client integration module, and a device identification module. The server module and the client integration module implement the marketing risk control function through the following steps:
[0008] S101, build the server and client;
[0009] S102: The server generates data, and the client generates a fingerprint after receiving the data. Based on the fingerprint and data, the server generates a unique device identifier;
[0010] S103, obtaining the user's operation time, generating a time series based on the operation time, extracting the characteristics of the time series, and constructing a behavior risk probability model based on the characteristics of the time series;
[0011] S104, calculating a risk value based on the unique identifier of the device;
[0012] S105: Add random disturbance data to the server and identify cheating clients by detecting client information.
[0013] Preferably, the time series features include time series behavior features and interactive biometric features. For time series behavior features, the client integration module is used to monitor the user's operation events and their timestamps, and the acquired user operation time is sequentially generated into a time series; for interactive biometric features, the interactive behavior features are extracted through the mean mouse movement acceleration and touch pressure entropy.
[0014] Preferably, the average mouse movement acceleration is used to measure the dynamic characteristics of the user's mouse movement. The average mouse movement acceleration is calculated by the velocity vector, and the formula is: ,in, represents the average value of acceleration, Indicates the number of acceleration values, because the acceleration is calculated from the second velocity vector, there are M-1 acceleration values in total. represents the index of the acceleration vector, Indicates acceleration.
[0015] Preferably, the touch pressure entropy is used to measure the randomness of the user's touch pressure distribution. The touch pressure entropy is calculated according to the probability distribution of the interval. The formula is: ,in, Represents the touch pressure entropy, K represents the number of intervals into which the pressure value is divided, The index representing the pressure value interval, represents the probability that the pressure value falls within the kth interval, express The logarithm of .
[0016] Preferably, the risk value is calculated based on the unique identifier of the device, and the formula is: ,in, is the comprehensive risk value, The number of times the current device has been claimed. is the maximum number of withdrawals allowed by the platform, and ≠0, The probability of user cheating, is the IP address risk score, and its value range is [0,1]. 、 is the weight coefficient and satisfies + =1.
[0017] Preferably, the method for compensating for differences between different browsers in the client integration module is:
[0018] S201, setting standardized generated content according to the client software;
[0019] S202, placing the set standardized generated content in the center of the visual area;
[0020] S203, using software to perform off-screen rendering;
[0021] S204: Compensate for the differences in color rendering between different browsers.
[0022] Preferably, the coordinates of the normalized generated content in the visual area are calculated based on the width and height of the visual area and the width and height of the rendered content, using the formula: , ,in, and Represents the coordinates of the normalized generated content in the visual area. Indicates the width of the visible area. Indicates the height of the visible area. Indicates the width of the rendered content. Indicates the height of the rendered content.
[0023] Preferably, the device identification module identifies the device in the following manner:
[0024] S301, measuring the first frame rendering time, classifying the performance of the devices according to the first frame rendering time, and dynamically grading the devices according to their performance;
[0025] S302, extracting multi-dimensional features;
[0026] S303, generating a dynamic ID based on the device load, detecting the visualization area, and identifying the virtual environment through the physical GPU characteristics;
[0027] S304 , identifying the device through multi-dimensional features, dynamic ID, detecting the visualization area, and identifying the virtual environment.
[0028] Preferably, the performance of the devices is divided according to the first frame rendering time, and a first threshold and a second threshold are set. Devices with a first frame rendering time less than the first threshold are regarded as high-performance devices, devices with a first frame rendering time greater than or equal to the first threshold and less than the second threshold are regarded as balanced devices, and devices with a first frame rendering time greater than or equal to the second threshold are regarded as low-performance devices.
[0029] Preferably, the devices are divided into different load levels according to their current load conditions, and different device IDs are generated according to their load levels. By embedding the load level information in the device's unique identifier, the same device generates different IDs at different load levels, but the IDs generated multiple times at the same load level remain consistent.
[0030] One or more technical solutions provided in this application have at least the following technical effects or advantages: Through hardware-rendered unique identifiers and behavioral time series modeling, high-precision user identification and fraud detection are achieved, protecting the fairness and security of marketing activities. The device-level uniqueness error rate is reduced, the detection rate of behavioral anomalies is improved, and fraudulent behavior is effectively intercepted while reducing accidental harm to normal users. By combining device-rendered unique identifiers and behavioral time series modeling, higher user identification accuracy and fraud detection rates are provided. Anti-bypass enhancements such as dynamic noise injection and virtualized environment detection are introduced to continuously combat new attack methods. By reducing accidental harm to normal users, the solution improves user experience and platform reputation.
[0031] Eliminate interference from browser differences, ensuring that the same device generates consistent features across different browsers, maintaining high uniqueness. Accurately identify hardware differences in a cross-browser environment and avoid misjudgments. Through standardized content generation parameters, off-screen rendering and center positioning, and browser difference compensation, cross-browser consistency is significantly improved, reducing the misjudgment rate caused by browser differences. Off-screen rendering and center positioning isolate the rendering environment, making it unaffected by page layout and improving the system's anti-interference capabilities.
[0032] Through dynamic load grading, multi-benchmark collaboration and privacy-security balance design, stable hardware identification across devices and resolutions is achieved, while privacy protection and anti-attack capabilities are enhanced. Through physical GPU verification, the discrimination and security of hardware identification are significantly improved. Dynamic rendering complexity grading ensures a good user experience on devices with different performance. Anti-virtualization reinforcement measures effectively block virtualization attacks, improve the security of hardware identification, and achieve high-discrimination, low-performance cross-device hardware identification, enhance the recognition ability of virtualized environments, and improve the security and accuracy of hardware identification. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 This is a block diagram of a marketing risk control system based on big data in the present invention;
[0034] Figure 2 A flow chart showing the implementation of marketing risk control functions by the server module and the client integration module of the present invention;
[0035] Figure 3 Schematic diagram of the process of compensating for differences between different browsers in the client integration module of the present invention;
[0036] Figure 4 This is a schematic diagram of the process of device identification module of the present invention identifying a device. DETAILED DESCRIPTION
[0037] To facilitate understanding of the present invention, the present application will be described more comprehensively below with reference to the relevant drawings; the drawings show preferred embodiments of the present invention, but the present invention can be implemented in many different forms and is not limited to the embodiments described herein; on the contrary, the purpose of providing these embodiments is to enable a more thorough and comprehensive understanding of the disclosed content of the present invention.
[0038] It should be noted that the terms “vertical”, “horizontal”, “up”, “down”, “left”, “right” and similar expressions used in this document are for illustrative purposes only and do not represent the only implementation method.
[0039] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this invention pertains; the terms used herein in the specification of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention; the term "and / or" used herein includes any and all combinations of one or more of the associated listed items.
[0040] Example 1: Figure 2 This is a flowchart of a marketing risk control system based on big data according to an embodiment of the present invention, which is applied to marketing risk control, such as Figure 1 As shown, the system includes a server module, a client integration module and a device identification module. The server module is connected to the client integration module, and both the server module and the client integration module are connected to the device identification module. When the system is working, the marketing risk control function is realized through the following steps:
[0041] S101, building the server and client sides of marketing risk control;
[0042] Specifically, for the server-side module, the marketing risk control server uses the cloud service Alibaba Cloud and uses MySQL to install the database system. The MySQL is suitable for storing structured data, such as device unique ID, user information, transaction records, etc. MySQL has high performance, reliability and ease of use, and is suitable for processing large amounts of transactional data. The database is configured and optimized according to business needs, including index design, partitioning strategy, read-write separation, etc., to improve data access speed and system stability; for the client integration module, the software development kit (SDK) is integrated into the client. The SDK includes functional modules such as WebGL rendering, feature extraction, hash generation, behavior monitoring and risk assessment.
[0043] S102: The server generates data, and the client generates a fingerprint after receiving the data. Based on the fingerprint and data, the server generates a unique device identifier;
[0044] Furthermore, the server generates data as rendering data based on the task space, and the rendering data includes shape category, color gradient, rotation angle and graphics complexity. For shape category, the shape category is the geometric shape of the specified rendering graphic, which is randomly selected from a predefined shape set. For color gradient, the color gradient is to define the color change range of the rendering graphic, and the RGB values of the starting color and the ending color are randomly generated. The value of each channel is between 0 and 255. For rotation angle, the rotation angle is the rotation angle of the specified graphic around the center point, and an angle value is randomly generated from the specified range. For graphics complexity, the graphics complexity is the complexity of controlling the graphics. For polygons, the number of vertices is randomly generated, and for curves, the number of control points or the order is randomly generated. The client receives the generated rendering data through the communication interface with the server. Using the received rendering data, the client starts the rendering engine to generate the corresponding image.
[0045] The client integration module generates anti-aliasing fingerprints and floating-point precision fingerprints based on the rendered image. For anti-aliasing fingerprints, the pixel data of the rendered image is obtained, the pixel data is defined as a matrix, and the edge detection algorithm Sobel operator is used to identify edge pixels in the image. Another pixel is selected in the neighborhood of the edge pixel with a small offset for comparison. The small offset is a very small displacement, usually one or several pixel units. The color value difference between the edge pixel and the offset pixel on the same color channel is calculated. The color value difference is calculated by the absolute value. The color difference of all edge pixels and all color channels is summed to obtain the total. Then, the total is divided by the total number of edge pixels to obtain the average color difference. This average is the anti-aliasing edge feature vector. The obtained feature vector is hashed to generate the anti-aliasing fingerprint. For WebGL floating-point precision fingerprints, in WebGL In the shader, the vertex position is slightly perturbed to reflect the difference in floating-point operation precision of the hardware. The perturbed vertex position is obtained according to the original vertex position. The deviation between the perturbed vertex position and the original vertex position is used to form a deviation matrix. The deviation matrix is transposed, and the deviation matrix is multiplied by the transposed deviation matrix. The multiplied matrix is eigendecomposed, and the maximum and minimum eigenvalues are extracted from the result of the eigendecomposition. The eigenvalues are hashed to generate a floating-point precision fingerprint.
[0046] Record the time required for the client to complete the rendering task, splice the anti-aliasing hash value, floating-point precision hash value and rendering time, and hash the spliced data string to generate a fixed-length hash value, which is the device's unique identifier. The splicing is to connect these feature values in a certain order into a long data string. The hashing is an algorithm that converts input data of any length into a fixed-length output (hash value), and it is almost impossible for different input data to produce the same hash value.
[0047] S103, obtaining the user's operation time, generating a time series based on the operation time, extracting the characteristics of the time series, and constructing a behavior risk probability model based on the characteristics of the time series;
[0048] Specifically, time series features include temporal behavior features and interactive biometric features. For temporal behavior features, the client application is used to monitor and record user operation events (such as clicks, slides, inputs, etc.) and their timestamps. The acquired user operation time is sequentially generated into a time series. The time difference between adjacent operation events is calculated based on the time series, and the variance of the operation time interval is calculated based on the time difference. For interactive biometric features, the interactive behavior features are extracted through the mean mouse movement acceleration and touch pressure entropy. The mean mouse movement acceleration is used to measure the dynamic characteristics of the user's mouse movement and reflect the speed and amplitude of the user's mouse operation. In the client application, the speed vector of the mouse movement is monitored and recorded. The speed vector is calculated by recording the change in the mouse position and the time interval. The speed vector is stored as a sequence in chronological order. The mean mouse movement acceleration is calculated through the speed vector. The formula is: ,in, represents the average value of acceleration, Indicates the number of acceleration values, because the acceleration is calculated from the second velocity vector, there are M-1 acceleration values in total. represents the index of the acceleration vector, represents acceleration. The touch pressure entropy is used to measure the randomness of the user's touch pressure distribution, reflecting the diversity and uncertainty of the user's touch pressure. According to the range and distribution of pressure values, the pressure value intervals are divided, and the probability distribution of the intervals is calculated. The touch pressure entropy is calculated based on the probability distribution of the intervals. The formula is: ,in, represents the touch pressure entropy, which is used to measure the randomness of the user's touch pressure distribution. K represents the number of intervals into which the pressure value is divided, that is, the entire range of pressure values is divided into K non-overlapping sub-intervals. The index representing the pressure value interval, represents the probability that the pressure value falls within the kth interval, that is, the ratio of the number of pressure values in the kth interval to the total number of pressure values. express The logarithm of .
[0049] A behavioral risk probability model is constructed based on the variance of the operation time interval, the mean of the mouse movement acceleration, and the touch pressure entropy. The formula in the risk probability model is: ,in, The probability of user cheating, is the operation time interval variance, represents the average value of acceleration, represents the touch pressure entropy, 、 、 and The model coefficient is obtained through training data. The behavioral risk probability model is trained and tested. According to the behavioral data of new users, the time series behavioral features are extracted. The extracted features are input into the trained behavioral risk probability model, and the model outputs the probability of user cheating.
[0050] S104, calculating a risk value based on the device identifier, the probability of user cheating, and the user behavior;
[0051] Furthermore, the number of times the current device has been claimed is collected from the server database or real-time log, and the risk value is calculated based on the device identifier, the probability of user cheating, and the user behavior. The formula is: ,in, It is a comprehensive risk value used to measure the risk level of the user. The number of times the current device has received rewards or discounts, indicating the number of times the device has received rewards or discounts on the platform. is the maximum number of withdrawals allowed by the platform, and ≠0 is a threshold set by the platform to limit the number of times a device can receive rewards or discounts. The probability of user cheating, The IP address risk score ranges from [0,1] and is calculated based on historical cheating records to measure the risk level of the IP address. 0 means no risk, 1 means high risk, 、 is the weight coefficient, which is used to adjust the contribution of each factor in the comprehensive risk value and meets the following requirements: + =1, set dynamic hierarchical interception according to the calculated risk value, and set hierarchical interception thresholds based on business needs and risk control strategies. When R<0.3, the user risk is considered low and the user request is directly allowed; when 0.3≤R<0.7, the user risk is considered medium and additional verification steps (such as SMS verification, face recognition, etc.) are required before deciding whether to allow the user request; when R≥0.7, the user risk is considered high and the user request is directly intercepted.
[0052] S105, adding random perturbation data to the data generated by the server, and identifying cheating clients running in the virtualized environment by detecting client information;
[0053] Specifically, random perturbations are introduced into the rotation angle data to generate uniformly distributed random numbers, which are then added to the original angle to obtain new rotation angle data. By introducing random noise, the result of the rendering task becomes uncertain, which increases the difficulty for cheaters to predict or simulate the rendering results. Due to the randomness of the noise, it is difficult for cheaters to bypass the system's detection through fixed patterns or algorithms, thereby improving the system's anti-bypass capability. When the client is running, the GPU driver information is obtained. By detecting the GPU driver information, the client running in a virtualized environment can be accurately identified. For the identified client running in a virtualized environment, the system will reject its request or implement other restrictive measures, thereby effectively preventing the occurrence of cheating.
[0054] The technical solutions in the above-mentioned embodiments of the present application have at least the following technical effects or advantages: through hardware rendering unique identification and behavior timing modeling, high-precision user identification and cheating detection are achieved, the fairness and security of marketing activities are protected, the device-level uniqueness error rate is reduced, the behavior anomaly detection rate is improved, cheating behavior is effectively intercepted, and at the same time, accidental harm to normal users is reduced. By combining device rendering unique identification and behavior timing modeling, higher user identification accuracy and cheating detection rate are provided, and anti-bypass enhancement designs such as dynamic noise injection and virtualized environment detection are introduced, which can continuously fight against new attack methods. By reducing accidental harm to normal users, the solution improves user experience and platform reputation.
[0055] Example 2: Based on Example 1, this example selects the location and compensates for the differences between different browsers to make the generated content render consistently in different browsers, thereby reducing the stability of device fingerprints. Figure 3 shown.
[0056] S201, setting standardized generated content according to the client software;
[0057] Furthermore, the standardized generation content includes geometric standardization, dynamic effect standardization and rendering environment isolation. For geometric standardization, basic shapes (circles, squares) are used, and complex curves (such as Bezier curves) are avoided to reduce shape inconsistencies caused by differences in browser rendering engines. Dimensions are defined in pixels, and dimension values are even numbers to reduce edge blur or differences caused by anti-aliasing processing, ensuring that graphics have the same size and appearance on different browsers and devices. sRGB standard color values are used, and the browser's color management function is disabled during rendering to ensure that color values are applied directly without any conversion, so that colors appear consistent on different browsers and devices, avoiding color deviations caused by color management. For dynamic effect standardization, the animation frame rate is set to 60FPS to ensure that the animation has the same smoothness on different devices, and the rotation angle increment for each frame is 1° to ensure Maintain consistency in rotation speed. By setting CSS properties, browsers are prevented from making unnecessary optimizations on animations, which would affect the consistency of animations. This ensures that rotation animations have the same rotation speed and smoothness on different browsers and devices. The linear gradient direction is fixed to horizontal or vertical. Avoid using diagonal gradients, as diagonal gradients result in inconsistent rendering due to differences in coordinate systems. This ensures that gradient effects are consistent across different browsers and devices. For rendering environment isolation, set forced use of high-precision floating-point operations in the WebGL configuration to reduce rendering problems caused by differences in floating-point precision. This ensures that graphics have the same rendering accuracy and detail on different browsers and devices. Set a retained rendering buffer in the WebGL configuration so that the rendering results can be reread or modified when needed. This provides additional control over the rendering results and ensures that the rendering buffer can be accessed and modified consistently across different browsers and devices.
[0058] S202, placing the set standardized generated content in the center of the visual area;
[0059] Specifically, JavaScript is used to obtain the width and height of the visible area of the current browser window. The width and height of the visible area represent the area inside the browser window that can be used to display content. The width and height of the content to be rendered are pre-set. The coordinates of the standardized generated content in the visible area are calculated based on the width and height of the visible area and the width and height of the rendered content. The formula is: , ,in, and Represents the coordinates of the normalized generated content in the visual area. Indicates the width of the visible area. Indicates the height of the visible area. Indicates the width of the rendered content. Indicates the height of the content being rendered. Use Canvas to draw the calculated x and y coordinates applied to the content to be rendered.
[0060] S203, using software to perform off-screen rendering;
[0061] Furthermore, use the software JavaScript constructor to create an off-screen Canvas object with a width of 100 pixels and a height of 100 pixels, and use the WebGL rendering method to obtain the rendering context of the off-screen Canvas. This context will be used to perform actual drawing operations in the background thread, including drawing graphics, applying styles, etc. Create a script file and define the rendering logic in it. The script file will not block the execution of the main thread. In the script file, receive the off-screen Canvas reference passed by the main thread, and use the obtained rendering context to perform drawing operations. These operations are performed completely in the background thread and are not affected by factors such as CSS styles and page scaling in the main thread. After the drawing is completed, the script file sends the image data back to the main thread, converts the image data into an image and displays it on the page.
[0062] S204, compensating for differences in color rendering between different browsers;
[0063] Specifically, a standard checkerboard pattern consisting of black and white squares is drawn on the page. This checkerboard pattern is used as a reference for benchmarking and is used to compare the rendering results of different browsers. Canvas is used to obtain pixel data of specific areas in the checkerboard pattern (such as white squares or black squares), and the color values of the three channels of red (R), green (G), and blue (B) are extracted, that is, the actual measured color values. The standard color value is set. The standard color value represents the color of the squares in the checkerboard pattern under ideal conditions. The difference between the actual measured color value and the standard color value is calculated, and the color compensation matrix is calculated based on the color difference. The matrix is in the following form: ,in, represents the color compensation matrix, ΔR represents the color difference of the red channel, ΔG represents the color difference of the green channel, and ΔB represents the color difference of the blue channel. Represent the standard color values of the red, green, and blue channels respectively, obtain the browser type, version and other information, set up a compensation library, which contains compensation parameters for different browser types and versions, and query the corresponding compensation parameters in the compensation library according to the browser type and version number. Dynamically adjust the rendering data based on the queried compensation parameters and color compensation matrix.
[0064] The technical solutions in the above-mentioned embodiments of the present application have at least the following technical effects or advantages: eliminating interference from browser differences, ensuring that the same device generates consistent features in different browsers, maintaining high uniqueness, and accurately identifying hardware differences in a cross-browser environment to avoid misjudgment. By standardizing content generation parameters, off-screen rendering and center positioning, and browser difference compensation, cross-browser consistency is significantly improved, and the misjudgment rate caused by browser differences is reduced. Off-screen rendering and center positioning achieve isolation of the rendering environment, are not affected by page layout, and improve the system's anti-interference ability.
[0065] Example 3: Based on the above example 2, fixed rendering data may cause lag and blurring of the effect on devices with different performance. This example ensures a good user experience on devices with different performance by dynamically grading the rendering complexity, such as Figure 4 shown.
[0066] S301, measuring the first frame rendering time, classifying the performance of the devices according to the first frame rendering time, and dynamically grading the devices according to their performance;
[0067] Furthermore, the first frame rendering time is measured, and the device types are divided according to the first frame rendering time. A first threshold and a second threshold are set. Devices with a first frame rendering time less than the first threshold are regarded as high-performance devices, devices with a first frame rendering time greater than or equal to the first threshold and less than the second threshold are regarded as balanced devices, and devices with a first frame rendering time greater than or equal to the second threshold are regarded as low-performance devices. Dynamic grading is performed according to the performance type of the device. For high-performance devices, the highest number of fractal iterations and particles are set, and the anti-aliasing level is set to 8 times. For balanced devices, the number of fractal iterations and particles are reduced on the basis of high-performance devices, and the anti-aliasing level is set to 4 times. For low-performance devices, the number of fractal iterations and particles are further reduced on the basis of balanced devices, and the anti-aliasing level is not set. The rendering time is remeasured every 5 seconds. If the rendering time is detected to exceed the current mode threshold for 3 consecutive times, it will switch to the next level mode.
[0068] S302, extracting multi-dimensional features;
[0069] The multi-dimensional features include spatial features, temporal features, and browser rendering strategies. For spatial features, the original gradient value of the edge area is extracted from the rendered graphics. The gradient value reflects the severity of the change in pixel value in the image. The original gradient value is normalized according to the different performance of the device, and the normalized gradient value is used to perform anti-aliasing processing on the edge of the graphics. Then, the edge area is measured, and the attenuation characteristics of the edge area are analyzed based on the measurement results. The ESI value is calculated based on the attenuation data. The ESI value is inversely proportional to the degree of edge attenuation, that is, the sharper the edge (the slower the attenuation), the higher the ESI value. The calculated ESI value is stored. For temporal features, the current frame rate during the rendering process is recorded, the variance is calculated based on the frame rate, and the calculated variance is stored. In high-performance devices, the WebGL timer function is used to record the start and end times of the GPU and CPU. Based on the recorded time, the collaboration delay between the GPU and CPU is calculated. The delay difference = GPU completion time - CPU start time, and the delay difference is stored. The browser rendering strategy has been described in the above embodiment 2 and will not be repeated in this embodiment.
[0070] S303, generating a dynamic ID based on the device load, detecting the visualization area, and identifying the virtual environment through the physical GPU characteristics;
[0071] Specifically, according to the current load of the device (such as CPU usage, memory occupancy, etc.), the device is divided into different load levels (such as low load, medium load, and high load). Different device IDs are generated according to the load level of the device. This is achieved by embedding load level information in the device identifier or using different hash algorithms to ensure that the device IDs generated at different load levels are unique and stable. That is, the same device should generate different IDs at different load levels, but the IDs generated multiple times at the same load level remain consistent. The dynamic ID generation mechanism can ensure that unique and stable device identifications can be generated in different modes; when the device is initialized or the user visits for the first time, Calculate the hash value of the visualization area (such as based on parameters such as the size and resolution of the visualization area). Recalculate the hash value of the visualization area upon each request, compare the recalculated hash value with the initial hash value, and calculate the deviation. If the deviation exceeds the threshold, a risk flag is triggered, indicating that the visualization area size has been tampered with. Run the same sphere collision detection multiple times on the physical GPU, and calculate the mean and standard deviation of the collision point coordinates as the expected result. Run the same ray tracing simulation calculation on the device to be verified to obtain the simulation result. Calculate the difference between the simulation result and the expected result. If the difference is greater than the preset threshold, it is marked as a virtual environment. Otherwise, it is not a virtual environment.
[0072] S304 , identifying the device through multi-dimensional features, dynamic ID, detecting the visualization area, and identifying the virtual environment.
[0073] The technical solutions in the above-mentioned embodiments of the present application have at least the following technical effects or advantages: through dynamic load grading, multi-benchmark collaboration and privacy-security balance design, stable hardware identification across devices and resolutions is achieved, while enhancing privacy protection and anti-attack capabilities. Through physical GPU verification, the discrimination and security of hardware identification are significantly improved. Dynamic rendering complexity grading ensures a good user experience on devices with different performance. Anti-virtualization reinforcement measures effectively intercept virtualization attacks, improve the security of hardware identification, and achieve high-discrimination, low-performance cross-device hardware identification. The ability to recognize virtualized environments is enhanced, and the security and accuracy of hardware identification are improved.
[0074] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Various modifications and variations are readily apparent to those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A marketing risk control system based on big data, characterized by: The marketing risk control system includes a server module, a client integration module, and a device identification module; the server module and the client integration module implement the marketing risk control function through the following steps: S101, build the server and client; S102: The server generates data, and the client generates a fingerprint after receiving the data. Based on the fingerprint and data, the server generates a unique device identifier; S103, obtaining the user's operation time, generating a time series based on the operation time, extracting the characteristics of the time series, and constructing a behavior risk probability model based on the characteristics of the time series; S104, calculating a risk value based on the unique identifier of the device; S105, adding random perturbation data to the server to detect the client's information and identify the cheating client; The method for compensating for differences between different browsers in the client integration module is: S201, setting standardized generated content according to the client software; S202, placing the set standardized generated content in the center of the visual area; S203, using software to perform off-screen rendering; S204: Compensate for the differences in color rendering between different browsers.
2. A marketing risk control system based on big data according to claim 1, characterized in that: Time series features include temporal behavior features and interactive biometric features. For temporal behavior features, the client integration module monitors the user's operation events and their timestamps, and generates a time series in sequence based on the acquired user operation time; for interactive biometric features, the interactive behavior features are extracted through the mean mouse movement acceleration and touch pressure entropy.
3. A marketing risk control system based on big data as claimed in claim 2, characterized in that: The average mouse movement acceleration is used to measure the dynamic characteristics of the user's mouse movement. The average mouse movement acceleration is calculated by the velocity vector. The formula is: ,in, represents the average value of acceleration, Indicates the number of acceleration values, because the acceleration is calculated starting from the second velocity vector, there are M−1 acceleration values in total. represents the index of the acceleration vector, Indicates acceleration.
4. A marketing risk control system based on big data as claimed in claim 2, characterized in that: The touch pressure entropy is used to measure the randomness of the user's touch pressure distribution. The touch pressure entropy is calculated based on the probability distribution of the interval. The formula is: ,in, Represents the touch pressure entropy, K represents the number of intervals into which the pressure value is divided, The index representing the pressure value interval, represents the probability that the pressure value falls within the kth interval, express The logarithm of .
5. The marketing risk control system based on big data according to claim 1, characterized in that: The risk value is calculated based on the unique identifier of the device. The formula is: ,in, is the comprehensive risk value, The number of times the current device has been claimed. is the maximum number of withdrawals allowed by the platform, and ≠0, The probability of user cheating, is the IP address risk score, and its value range is [0,1]. 、 is the weight coefficient and satisfies + =1.
6. The marketing risk control system based on big data according to claim 1, characterized in that: The coordinates of the generated content in the visual area are calculated based on the width and height of the visual area and the width and height of the rendered content. The formula is: , ,in, and Represents the coordinates of the normalized generated content in the visual area. Indicates the width of the visible area. Indicates the height of the visible area. Indicates the width of the rendered content. Indicates the height of the rendered content.
7. The marketing risk control system based on big data according to claim 1, characterized in that: The method by which the device identification module identifies the device is as follows: S301, measuring the first frame rendering time, classifying the performance of the devices according to the first frame rendering time, and dynamically grading the devices according to their performance; S302, extracting multi-dimensional features; S303, generating a dynamic ID based on the device load, detecting the visualization area, and identifying the virtual environment through the physical GPU characteristics; S304 , identifying the device through multi-dimensional features, dynamic ID, detecting the visualization area, and identifying the virtual environment.
8. The marketing risk control system based on big data according to claim 7, characterized in that: The performance of the devices is divided according to the first frame rendering time, and a first threshold and a second threshold are set. Devices with a first frame rendering time less than the first threshold are classified as high-performance devices, devices with a first frame rendering time greater than or equal to the first threshold and less than the second threshold are classified as balanced devices, and devices with a first frame rendering time greater than or equal to the second threshold are classified as low-performance devices.
9. The marketing risk control system based on big data according to claim 7, characterized in that: According to the current load condition of the device, the device is divided into different load levels. Different device IDs are generated according to the load level of the device. By embedding the load level information in the device unique identifier, the same device generates different IDs at different load levels, but the IDs generated multiple times at the same load level remain consistent.
Citation Information
Patent Citations
A marketing anti-fraud system based on big data
CN114119037B
Marketing anti-cheating system based on big data
CN114119037A
Cloud mobile phone end-to-end performance tracking method and related equipment
CN120151231A