Risk control confrontation detection method of risk control system

By installing Nat iveTest and Holmes tools on the target device, modifying hardware fingerprints and user behavior information, and simulating attack behavior for confrontation detection, the problem that traditional risk control systems are easily avoided is solved, and the detection capability of risk control systems and the security of financial applications are improved.

CN120372594APending Publication Date: 2025-07-25启朔(深圳)科技有限公司
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510262404.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Traditional risk control systems are easily evaded by advanced fraudulent means, and it is difficult to effectively identify fraudulent behaviors in equipment virtualization and simulate the environment, resulting in an increase in financial security threats.

Method used

Install the first tool (such as Nat iveTest) and the second tool (such as Holmes) on the target device, modify the hardware fingerprint and user behavior information through the detection function, simulate attack behavior, and use the risk control system to be tested for adversarial detection, collect adversarial detection results to evaluate the detection capabilities of the risk control system.

Benefits of technology

It significantly enhances the detection capabilities of the risk control system, can effectively prevent fraud in equipment virtualization and simulated environments, ensure user data security, improve the reliability and stability of financial applications, and adapt to changing fraudulent means.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372594A_ABST
    Figure CN120372594A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a risk control confrontation detection method for a risk control system, and the method comprises the steps: installing a first tool and a second tool on target equipment, then modifying the original hardware fingerprint information of the target equipment into preset hardware fingerprint information through the detection function of the first tool, and modifying the original hardware fingerprint information of the target equipment into preset hardware fingerprint information through the anti-detection function of the second tool. Modifying the original user behavior information of the target equipment into preset user behavior information, and finally performing confrontation detection on the target equipment by using the risk control system to be detected to obtain a confrontation detection result; according to the mode, the response efficiency of the risk control system when encountering virtual or simulation equipment can be tested, and the risk control detection capability of the risk control system for resisting equipment feature detection, behavior analysis and other security detection mechanisms can be remarkably enhanced, so that the performance of financial application in the aspects of risk monitoring and fraud prevention is improved; a firmer security defense line is constructed for financial application, and fraudulent behaviors of equipment virtualization and simulation environment are effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a risk control confrontation detection method for a risk control system. Background Art

[0002] In the field of network security, with the continuous evolution and upgrading of financial fraud means, the financial industry, especially the banking and payment fields, is facing increasingly severe risk control security challenges. To effectively resist fraud means such as device virtualization and simulation, many overseas banks and financial institutions have invested a large amount of resources and adopted a series of complex risk control detection technologies. These technologies deeply analyze various characteristics of devices, aiming to build an all-round security protection network.

[0003] However, traditional risk control systems still face the risk of being circumvented by advanced fraud means. This is because they often rely on static device fingerprints and basic behavior pattern analysis, but this information is relatively easy to be tampered with or forged by attackers through specific tools. Attackers can create virtual environments and simulate real user behaviors, thus easily bypassing risk control detections based on static features and posing a serious threat to the security of financial systems.

[0004] In view of this severe situation, how to test the response effectiveness of risk control systems when encountering virtual or simulated devices, so as to effectively improve the risk control detection ability of risk control systems, and ensure their sensitivity and accuracy when facing virtual or simulated devices, has become a key problem to be solved urgently. Summary of the Invention

[0005] Based on this, it is necessary to address the above problems and propose a risk control confrontation detection method for a risk control system, which can not only test the response effectiveness of the risk control system when encountering virtual or simulated devices, but also significantly enhance the risk control detection ability of the risk control system against device feature detection, behavior analysis and other security detection mechanisms, so as to improve the performance of financial applications in risk monitoring and fraud prevention, build a more solid security defense line for financial applications, effectively prevent fraud behaviors in device virtualization and simulation environments, ensure the absolute security of user data, and at the same time significantly improve the reliability and stability of financial applications.

[0006] To achieve the above object, in a first aspect, the present invention provides a risk control confrontation detection method for a risk control system, the method comprising:

[0007] Install a first tool and a second tool on a target device;

[0008] Use the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information, and modify the original user behavior information of the target device into preset user behavior information;

[0009] Use the risk control system to be tested to perform adversarial detection on the target device to obtain an adversarial detection result.

[0010] Optionally, the first tool is the NativeTest tool, and the second tool is the Holmes tool.

[0011] Optionally, using the detection function of the first tool and the anti-detection function of the second tool, modify the original hardware fingerprint information of the target device to preset hardware fingerprint information, including:

[0012] Run the first tool, start the detection function of the first tool, and obtain the original hardware fingerprint information of the target device;

[0013] Use a hardware fingerprint emulation tool to generate real-time hardware fingerprint emulation data according to preset hardware fingerprint emulation rules;

[0014] Use the real-time hardware fingerprint emulation data as the preset hardware fingerprint information;

[0015] Run the second tool, start the anti-detection function of the second tool, and modify the original hardware fingerprint information of the target device to the preset hardware fingerprint information.

[0016] Optionally, using the detection function of the first tool and the anti-detection function of the second tool, modify the original user behavior information of the target device to preset user behavior information, including:

[0017] Run the first tool, start the detection function of the first tool, and obtain the original user behavior information of the target device;

[0018] Use a user behavior emulation tool to generate real-time user behavior emulation data according to preset user behavior emulation rules;

[0019] Use the real-time user behavior emulation data as the preset user behavior information;

[0020] Run the second tool, start the anti-detection function of the second tool, and modify the original user behavior information of the target device to the preset user behavior information.

[0021] Optionally, the method further includes:

[0022] Run the first tool, start the detection function of the first tool, and obtain the application anti-debugging mechanism, application code execution flow, and system call information and debugging flags during runtime of the target device;

[0023] Run the second tool, activate the anti-detection function of the second tool, and modify the application anti-debugging mechanism, application code execution flow, as well as the system call information and debugging flag during runtime of the target device according to the preset combination modification rules.

[0024] Optionally, the using the risk control system under test to perform adversarial detection on the target device to obtain an adversarial detection result includes:

[0025] Use the risk control system under test to perform adversarial detection on the modified original hardware fingerprint information and original user behavior information of the target device according to the risk control detection rules of the risk control system under test to obtain the adversarial detection result.

[0026] Optionally, the method further includes:

[0027] Determine the security level of the risk control system under test according to the adversarial detection result;

[0028] Determine whether to update the risk control detection rules of the risk control system under test according to the adversarial detection result and / or the security level of the risk control system under test.

[0029] Optionally, the determining the security level of the risk control system under test according to the adversarial detection result includes:

[0030] When the adversarial detection result is that both the modified original hardware fingerprint information and original user behavior information of the target device satisfy the risk control detection rules of the risk control system under test, determine that the security level of the risk control system under test is risk level one;

[0031] When the adversarial detection result is that the modified original hardware fingerprint information of the target device does not satisfy the risk control detection rules of the risk control system under test, and the modified original user behavior information of the target device satisfies the risk control detection rules of the risk control system under test, determine that the security level of the risk control system under test is risk level two;

[0032] When the adversarial detection result is that the modified original hardware fingerprint information of the target device satisfies the risk control detection rules of the risk control system under test, and the modified original user behavior information of the target device does not satisfy the risk control detection rules of the risk control system under test, determine that the security level of the risk control system under test is risk level three;

[0033] When the adversarial detection result is that both the modified original hardware fingerprint information and original user behavior information of the target device do not satisfy the risk control detection rules of the risk control system under test, determine that the security level of the risk control system under test is risk level four.

[0034] Optionally, determining whether to update the risk control detection rules of the to-be-tested risk control system according to the adversarial detection result and / or the security level of the to-be-tested risk control system includes:

[0035] When the security level of the to-be-tested risk control system is not the first level of risk control, update the risk control detection rules of the to-be-tested risk control system according to the adversarial detection result and / or the security level of the to-be-tested risk control system to obtain an updated to-be-tested risk control system, and return to execute the steps of using the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information and modify the original user behavior information of the target device into preset user behavior information until the security level of the updated to-be-tested risk control system is the first level of risk control.

[0036] Optionally, the method further includes:

[0037] When the security level of the to-be-tested risk control system is the first level of risk control, update the preset hardware fingerprint simulation rules and the preset user behavior simulation rules according to the risk control detection rules of the to-be-tested risk control system, and return to execute the steps of using the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information and modify the original user behavior information of the target device into preset user behavior information;

[0038] When the security level of the updated to-be-tested risk control system is the first level of risk control, update the preset hardware fingerprint simulation rules and the preset user behavior simulation rules according to the risk control detection rules of the updated to-be-tested risk control system, or update the updated preset hardware fingerprint simulation rules and the updated preset user behavior simulation rules again, and return to execute the steps of using the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information and modify the original user behavior information of the target device into preset user behavior information until the sum of the number of times the security level of the to-be-tested risk control system is the first level of risk control and the number of times the security level of the updated to-be-tested risk control system is the first level of risk control is equal to the total number threshold.

[0039] To achieve the above object, the present invention provides a risk control adversarial detection device for a risk control system in a second aspect, and the device includes:

[0040] An installation module for installing a first tool and a second tool on a target device;

[0041] A tool modification module, configured to use the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information, and modify the original user behavior information of the target device into preset user behavior information;

[0042] An anti-detection module, configured to perform anti-detection on the target device using the risk control system to be tested, and obtain an anti-detection result.

[0043] To achieve the above object, in a third aspect of the present invention, there is provided a computer-readable storage medium storing a computer program, which when executed by a processor, causes the processor to execute the method according to any one of the first aspect.

[0044] To achieve the above object, in a fourth aspect of the present invention, there is provided a computer device including a memory and a processor, the memory storing a computer program, which when executed by the processor, causes the processor to execute the method according to any one of the first aspect.

[0045] Adopting the embodiments of the present invention has the following beneficial effects: By installing the first tool and the second tool on the target device, then using the detection function of the first tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information, and using the anti-detection function of the second tool to modify the original user behavior information of the target device into preset user behavior information, and finally performing anti-detection on the target device using the risk control system to be tested to obtain an anti-detection result; that is, by cleverly using the detection function of the first tool and the anti-detection function of the second tool, it efficiently and accurately simulates the fraudulent behavior of attackers to bypass risk control detection through device virtualization and simulation means. On this basis, the risk control system to be tested is used to perform anti-detection on the modified target device and collect the anti-detection results. According to these anti-detection results, overseas banks and financial institutions can accurately judge whether the existing risk control detection rules of the risk control system are effective, and then decide whether necessary updates are required. This method can not only test the response effectiveness of the risk control system when encountering virtual or simulated devices, but also significantly enhance the risk control detection ability of the risk control system against device feature detection, behavior analysis and other security detection mechanisms, so as to improve the performance of financial applications in risk monitoring and fraud prevention, build a more solid security defense line for financial applications, effectively prevent fraudulent behaviors in device virtualization and simulation environments, ensure the absolute security of user data, and at the same time significantly improve the reliability and stability of financial applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0047] Wherein:

[0048] Figure 1 It is a schematic diagram of a risk control confrontation detection method for a risk control system in an embodiment of the present application;

[0049] Figure 2 It is a schematic diagram of a risk control confrontation detection device for a risk control system in an embodiment of the present application;

[0050] Figure 3 It is an internal structure diagram of a computer device in some embodiments. Detailed implementation manners

[0051] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0052] In the field of network security, with the continuous evolution and upgrading of financial fraud means, the financial industry, especially the banking and payment fields, is facing increasingly severe risk control security challenges. To effectively resist fraud means such as device virtualization and simulation, many overseas banks and financial institutions have invested a large amount of resources and adopted a series of complex risk control detection technologies. These technologies deeply analyze various characteristics of devices, aiming to build an all-round security protection network.

[0053] However, traditional risk control systems still face the risk of being circumvented by advanced fraud means. This is because they often rely on static device fingerprints and basic behavior pattern analysis, but this information is relatively easy to be tampered with or forged by attackers through specific tools. Attackers can create virtual environments and simulate real user behaviors, thus easily bypassing risk control detections based on static characteristics and posing a serious threat to the security of the financial system.

[0054] In view of this severe situation, how to test the response effectiveness of the risk control system when encountering virtual or simulated devices, so as to effectively improve the risk control detection ability of the risk control system and ensure its sensitivity and accuracy when facing virtual or simulated devices, has become a key problem to be solved urgently.

[0055] In view of the above problems, the present application proposes a risk control and countermeasure detection method for a risk control system, which can not only test the response effectiveness of the risk control system when encountering virtual or simulated devices, but also significantly enhance the risk control detection ability of the risk control system against device feature detection, behavior analysis, and other security detection mechanisms, so as to improve the performance of financial applications in risk monitoring and fraud prevention, build a more solid security defense line for financial applications, effectively prevent fraud behaviors in device virtualization and simulation environments, ensure the absolute security of user data, and at the same time significantly improve the reliability and stability of financial applications. The specific implementation principle will be described in detail in the following embodiments.

[0056] In a first aspect, the present application provides a risk control and countermeasure detection method for a risk control system.

[0057] Please refer to Figure 1 , which is a schematic diagram of a risk control and countermeasure detection method for a risk control system in an embodiment of the present application. The method includes:

[0058] Step 110: Install a first tool and a second tool on the target device.

[0059] Among them, the target device refers to a terminal; the first tool and the second tool can be tools determined and selected by the operator in advance based on a large amount of experience, experiments, or statistics. Of course, they can also be selected by the operator in advance according to actual needs.

[0060] In some embodiments, the target device can be a terminal with an operating system; for example, the target device can be a smartphone or tablet with an Android, HarmonyOS, or iOS system, or a computer with a Windows, macOS, or Linux system.

[0061] In some embodiments, the first tool can be selected as a tool with a detection function, and the second tool can be selected as a tool with an anti-detection function; among them, the detection function means that various information of the target device can be detected, and the anti-detection function means that it can prevent the modification of various information of the target device from being detected. For example, in the present application, it is to prevent the modification of various information of the target device from being detected by the risk control system to be tested.

[0062] Step 120: Use the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information, and modify the original user behavior information of the target device into preset user behavior information.

[0063] Among them, the preset hardware fingerprint information and the preset user behavior information can both be obtained and set in advance by the operator based on a large amount of experience, experiments, or statistics. Of course, they can also be set in advance by the operator according to actual needs.

[0064] It should be noted that in this application, by using the detection function of the first tool, the original hardware fingerprint information and original user behavior information of the target device can be detected. Through the anti-detection function of the second tool, it can prevent various information such as the original hardware fingerprint information and original user behavior information of the target device from being detected by the risk control system to be tested, that is, prevent abnormal modifications from being detected by the risk control system to be tested.

[0065] In some embodiments, both the original hardware fingerprint information and the preset hardware fingerprint information include but are not limited to CPU information (such as architecture, model, etc.), memory information, screen characteristic information (such as resolution, pixel density, etc.), system information (such as version, brand, patches, etc.), and sensor data (such as accelerometer, gyroscope, etc.); both the original user behavior information and the preset user behavior information include but are not limited to application usage behaviors (such as login, transfer, etc.), application behavior patterns (such as click / slide / touch events, process startup, process stop, response time, startup speed, network requests (traffic, frequency, etc.)).

[0066] In some embodiments, the preset hardware fingerprint information and the preset user behavior information can be determined according to the risk control detection rules of the risk control system to be tested.

[0067] In some embodiments, various information in the preset hardware fingerprint information and the preset user behavior information can be dynamically updated by the operator to enhance the anti-detection ability during the risk control anti-detection process.

[0068] Step 130: Use the risk control system to be tested to perform anti-detection on the target device to obtain an anti-detection result.

[0069] Among them, the risk control system to be tested refers to the risk control system that needs to perform anti-detection.

[0070] In some embodiments, there is an adversarial relationship between the risk control system to be tested and the first tool and the second tool in the target device. The purpose of the risk control system to be tested is to detect whether various information of the target device has been abnormally modified, while the purpose of the first tool and the second tool is to prevent the risk control system to be tested from detecting that various information of the target device has been abnormally modified.

[0071] It should be noted that if the risk control system to be tested fails to detect that various information of the target device has been abnormally modified, it indicates that the detection function of the first tool and the anti-detection function of the second tool have bypassed the risk control detection through device virtualization and simulation means, and the risk control detection ability of the risk control system to be tested is insufficient, and the risk control system to be tested needs to be updated; if the risk control system to be tested detects that various information of the target device has been abnormally modified, it indicates that the detection function of the first tool and the anti-detection function of the second tool have failed to bypass the risk control detection through device virtualization and simulation means, and the risk control detection ability of the risk control system to be tested is relatively good, and the preset hardware fingerprint information and preset user behavior information need to be updated, and the method of this application needs to be re-executed for adversarial detection to further improve the risk control detection ability of the risk control system to be tested.

[0072] That is, in some embodiments, if the risk control system to be tested fails to detect that various information of the target device has been abnormally modified, the risk control detection rules of the risk control system to be tested are updated according to the preset hardware fingerprint information and preset user behavior information; if the risk control system to be tested detects that various information of the target device has been abnormally modified, the preset hardware fingerprint information and preset user behavior information are updated according to the risk control detection rules of the risk control system to be tested; and after the update, the method of this application is re-executed for adversarial detection, that is, by dynamically updating and re-performing adversarial detection, the risk control detection ability of the risk control system to be tested can be continuously improved.

[0073] In the embodiments of this application, by skillfully using the detection function of the first tool and the anti-detection function of the second tool, the fraudulent behavior of the attacker is efficiently and accurately simulated to bypass the risk control detection through device virtualization and simulation means. On this basis, the risk control system to be tested is used to perform adversarial detection on the modified target device, and the adversarial detection results are collected. According to these adversarial detection results, overseas banks and financial institutions can accurately judge whether the existing risk control detection rules of the risk control system are effective, and then decide whether necessary updates are required. This method can not only test the response effectiveness of the risk control system when encountering virtual or simulated devices, but also significantly enhance the risk control detection ability of the risk control system against device feature detection, behavior analysis and other security detection mechanisms, so as to improve the performance of financial applications in risk monitoring and fraud prevention, build a more solid security defense line for financial applications, effectively prevent fraudulent behavior in device virtualization and simulation environments, ensure the absolute security of user data, and at the same time significantly improve the reliability and stability of financial applications.

[0074] In addition, the method has the following advantages: by dynamically updating the preset hardware fingerprint information and preset user behavior information and re-performing adversarial detection, the risk control system can continuously adapt to new fraud means and device virtualization technologies. This adaptability enables the risk control system to maintain its effectiveness and accuracy when facing evolving financial fraud; by simulating the fraud behavior of attackers to comprehensively test the risk control system, this test not only covers known risk points but may also reveal potential security vulnerabilities. By promptly fixing these vulnerabilities, the robustness of the risk control system will be enhanced, enabling it to better resist various forms of attacks; through the adversarial detection results, financial institutions can deeply understand the performance of the risk control system when encountering virtual or simulated devices. These adversarial detection results can provide strong data support for formulating and optimizing risk control strategies, helping financial institutions more precisely identify and control risks; the adversarial detection proposed in this application encourages financial institutions and technical personnel to continuously explore new risk control technologies and means. Through continuous technological innovation and upgrading, financial institutions can build a more advanced and efficient risk control system, enhancing their competitiveness in the financial market; a powerful risk control system can effectively protect the data security and fund security of users. By implementing adversarial detection in this application, financial institutions can ensure the effectiveness of their risk control systems, thereby enhancing users' trust and satisfaction with financial institutions. This helps financial institutions establish more stable customer relationships and promote the sustainable development of their businesses; with the development of the financial industry, regulatory authorities have put forward increasingly high requirements for the risk control capabilities of financial institutions. By implementing adversarial detection, financial institutions can ensure that their risk control systems comply with regulatory requirements and avoid legal risks caused by compliance issues.

[0075] In a feasible implementation manner, the first tool in the above embodiment is the NativeTest tool, and the second tool is the Holmes tool.

[0076] It should be noted that the NativeTest tool is a tool for detection and can obtain various information of the target device by calling system functions, reading device information, etc.; the Holmes tool is a tool for anti-detection and can bypass risk control detection through virtualization and dynamic debugging technologies.

[0077] In the embodiment of this application, by preferably determining the first tool as the NativeTest tool and the second tool as the Holmes tool, not only can various information of the target device be comprehensively and accurately obtained, but also the information modification behavior can be effectively hidden, increasing the complexity and challenge of adversarial detection, thereby more comprehensively testing the risk control detection ability of the risk control system to be tested. At the same time, this way of combined use can also achieve the functions of dynamic update and re-detection, ensuring that the risk control system can continuously maintain its strong defense ability.

[0078] It is understandable that as a professional detection tool, the NaturalTest tool has powerful information collection capabilities and can go deep into the underlying system of the target device. By calling system functions, reading device information, etc., it can comprehensively and accurately obtain the original hardware fingerprint information and original user behavior information of the target device. The comprehensiveness and accuracy of this information acquisition provides a solid foundation for subsequent information modification and adversarial detection; the Holmes tool, as an anti-detection tool, has excellent anti-detection capabilities. It uses virtualization and dynamic debugging technology to effectively hide or disguise the information modification behavior of the target device, thereby avoiding detection by the risk control system to be tested. This anti-detection capability makes the attacker's fraudulent behavior more covert and difficult to detect, increases the complexity and challenge of adversarial detection, and thus can more comprehensively test the risk control detection capabilities of the risk control system to be tested.

[0079] In a feasible implementation, step 120 in the above embodiment, using the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device to the preset hardware fingerprint information, includes: running the first tool, starting the detection function of the first tool, and obtaining the original hardware fingerprint information of the target device; using the hardware fingerprint simulation tool to generate hardware fingerprint simulation real-time data according to preset hardware fingerprint simulation rules; using the hardware fingerprint simulation real-time data as the preset hardware fingerprint information; running the second tool, starting the anti-detection function of the second tool, and modifying the original hardware fingerprint information of the target device to the preset hardware fingerprint information.

[0080] The preset hardware fingerprint simulation rules may be obtained and set in advance by the operator based on a large amount of experience, experiments or statistics. Of course, they may also be set in advance by the operator based on actual needs.

[0081] In some embodiments, the hardware fingerprint simulation tool may be a simulation tool or simulation script pre-defined by an operator, or an existing simulation tool may be used, such as a device with a magic environment or a simulator provided by the target device.

[0082] In other embodiments, various historical information of the target device and various historical information of terminals similar to the target device may be analyzed to generate hardware fingerprint simulation real-time data by analyzing various historical information.

[0083] In the embodiments of the present application, by running the first tool (such as the NativeTest tool) and starting its detection function, and running the second tool (such as the Holmes tool) and starting its anti-detection function, the original hardware fingerprint information of the target device can be accurately obtained, the preset hardware fingerprint information that is real and reliable can be generated, and the original information can be modified into the preset information through the hidden anti-detection function, so as to comprehensively and efficiently test the risk control detection ability of the risk control system to be tested. This testing method not only improves the defense ability of the risk control system, but also provides strong data support for financial institutions to formulate and optimize risk control strategies.

[0084] It can be understood that by running the first tool and starting its detection function, the original hardware fingerprint information of the target device can be comprehensively and accurately obtained. This accurate information acquisition provides a solid foundation for subsequent information modification and anti-detection, ensuring the accuracy and reliability of the entire detection process; by using the hardware fingerprint simulation tool and generating real-time data of hardware fingerprint simulation according to the preset hardware fingerprint simulation rules, this process can simulate the hardware characteristics similar to or specific to the target device, making the generated preset hardware fingerprint information have high authenticity and credibility. This authenticity helps to more realistically simulate the fraudulent behavior of attackers, so as to more comprehensively test the risk control detection ability of the risk control system to be tested; by running the second tool and starting its anti-detection function, the original hardware fingerprint information of the target device can be modified into the preset hardware fingerprint information while avoiding being detected by the risk control system to be tested. This concealment increases the complexity and challenge of anti-detection, making the fraudulent behavior of attackers more difficult to detect, so as to be able to more deeply test the defense ability of the risk control system to be tested.

[0085] In a feasible implementation manner, step 120 in the above embodiment, using the detection function of the first tool and the anti-detection function of the second tool to modify the original user behavior information of the target device into the preset user behavior information, includes: running the first tool, starting the detection function of the first tool, and obtaining the original user behavior information of the target device; using the user behavior simulation tool to generate real-time data of user behavior simulation according to the preset user behavior simulation rules; using the real-time data of user behavior simulation as the preset user behavior information; running the second tool, starting the anti-detection function of the second tool, and modifying the original user behavior information of the target device into the preset user behavior information.

[0086] Among them, the preset user behavior simulation rules can be obtained and set in advance by the operator according to a large amount of experience, experiments or statistics. Of course, they can also be set in advance by the operator according to actual needs.

[0087] In some embodiments, the user behavior simulation tool can be a simulation tool or simulation script pre-customized by an operator, or an existing simulation tool can be adopted.

[0088] In other embodiments, real-time user behavior simulation data can also be generated by analyzing various historical information of the target device and various historical information of terminals similar to the target device, so as to generate real-time user behavior simulation data by analyzing various historical information.

[0089] In the embodiments of the present application, by running the first tool and starting its detection function, and running the second tool and starting its anti-detection function, user behavior can be accurately simulated, highly simulated preset user behavior information, concealed information modification, and subsequent risk control system optimization can be generated. This not only improves the defense ability of the risk control system, but also provides strong data support for financial institutions to formulate and optimize risk control strategies, and helps to enhance the competitiveness and user trust of financial institutions.

[0090] It can be understood that by running the first tool and starting its detection function, the original user behavior information of the target device can be obtained comprehensively and accurately. This step provides a true and reliable data basis for subsequent user behavior information modification and anti-detection, ensuring the accuracy and effectiveness of the test; by using the user behavior simulation tool and according to the preset user behavior simulation rules, highly simulated real-time user behavior simulation data can be generated. These data are not only similar to the user behavior characteristics of the target device, but also can be customized according to actual needs, so as to more realistically simulate the user behavior patterns that an attacker may adopt. This highly simulated preset user behavior information helps to more deeply test the risk control detection ability of the risk control system to be tested when facing complex user behaviors; by running the second tool and starting its anti-detection function, the original user behavior information of the target device can be modified into preset user behavior information, and at the same time, the modification process can be avoided being detected by the risk control system to be tested. This concealment increases the complexity and challenge of anti-detection, making it more difficult for the attacker's fraud behavior to be detected by the risk control system, so as to more comprehensively evaluate the defense ability of the risk control system to be tested.

[0091] In a feasible implementation manner, the method in the above embodiments further includes: running the first tool, starting the detection function of the first tool, and obtaining the application anti-debugging mechanism, application code execution flow, system call information and debugging identifier during runtime of the target device; running the second tool, starting the anti-detection function of the second tool, and modifying the application anti-debugging mechanism, application code execution flow, system call information and debugging identifier of the target device according to the preset combination modification rules.

[0092] The preset combination modification rules may be obtained and set in advance by the operator based on a large amount of experience, experiments or statistics. Of course, they may also be set in advance by the operator based on actual needs.

[0093] It should be noted that by modifying the target device's application anti-debugging mechanism, application code execution flow, and runtime system call information and debugging flags according to preset combination modification rules, it is possible to prevent the risk control system from detecting virtual devices or simulated behaviors in the application through reverse analysis or anti-debugging at the underlying level of the target device.

[0094] In the embodiments of the present application, by introducing the application anti-debugging mechanism of the target device, the application code execution flow, and the modification of the system call information and debugging flags at runtime, the complexity and challenge of risk control adversarial detection are further enhanced. This step not only enriches the content of adversarial detection, but also improves the defense capability of the risk control system in the face of advanced fraud methods, and provides strong support for financial institutions to formulate and optimize risk control strategies.

[0095] It is understandable that by running the first tool and starting its detection function, the anti-debugging mechanism, code execution flow, and system call information and debugging identification of the target device at the application level can be accurately obtained. This information is an important basis for evaluating the security of the target device and identifying potential risk points; by running the second tool and starting its anti-detection function, the relevant information of the target device is modified according to the preset combination modification rules. This step is intended to simulate the means that the attacker may take, and by tampering with or disguising this information, it is difficult for the risk control system to detect virtual devices or simulated behaviors in the application through conventional reverse analysis or anti-debugging means; this modification not only increases the complexity of adversarial detection, but also tests the risk control system's detection capabilities when faced with tampered or disguised information. It can more comprehensively evaluate the defense level of the risk control system, discover potential security vulnerabilities, and provide strong data support for subsequent risk control strategy optimization.

[0096] In a feasible implementation, step 130 in the above embodiment uses the risk control system to be tested to perform adversarial detection on the target device to obtain an adversarial detection result, including: using the risk control system to be tested, according to the risk control detection rules of the risk control system to be tested, to perform adversarial detection on the modified original hardware fingerprint information and original user behavior information of the target device to obtain the adversarial detection result.

[0097] In an embodiment of the present application, by directly using the risk control system to be tested and based on its built-in risk control detection rules, adversarial detection is performed on the target device processed by the first tool and the second tool (that is, its original hardware fingerprint information and original user behavior information have been modified to preset information). The actual performance of the risk control system to be tested when facing device virtualization and simulation means can be intuitively evaluated. This process not only verifies whether the risk control system can effectively identify tampered device information and user behavior, but also verifies the accuracy and effectiveness of its risk control detection rules.

[0098] It is understandable that the adversarial detection results can directly reflect the sensitivity and accuracy of the risk control system under test when dealing with virtual or simulated devices. If the risk control system fails to detect that the information of the target device has been abnormally modified, it means that its risk control detection capabilities are insufficient and it may be necessary to further optimize the risk control detection rules or improve the advancedness of the detection technology. On the contrary, if the risk control system successfully detects abnormal modifications, it means that it has certain defense capabilities, but it still needs to make targeted adjustments and optimizations based on the adversarial detection results to cope with ever-changing fraud methods.

[0099] In a feasible implementation, the method in the above embodiment also includes: determining the security level of the risk control system to be tested based on the adversarial detection result; determining whether to update the risk control detection rules of the risk control system to be tested based on the adversarial detection result and / or the security level of the risk control system to be tested.

[0100] In the embodiments of the present application, by introducing security level assessment and rule update decisions based on detection results, not only the security and adaptability of the risk control system are improved, but also strong data support and decision-making basis are provided for financial institutions to formulate and optimize risk control strategies. This helps financial institutions to enhance their competitiveness and user trust in the financial market while ensuring user data security and improving business reliability and stability.

[0101] It is understandable that by determining the security level of the risk control system to be tested based on the adversarial detection results, this step enables financial institutions to intuitively understand the defense capabilities of the risk control system when facing virtual or simulated devices. The division of security levels can be based on multiple dimensions of the adversarial detection results, such as detection accuracy, false alarm rate, missed alarm rate, etc. By comprehensively considering these indicators, the performance of the risk control system can be comprehensively evaluated; further, by determining whether to update the risk control detection rules of the risk control system to be tested based on the adversarial detection results and / or the security level of the risk control system to be tested, this decision-making process reflects the dynamic optimization and continuous improvement of the risk control system. If the adversarial detection results show that the risk control system has obvious security loopholes or insufficient defense capabilities, or the security level of the risk control system does not meet the expected standards, the financial institution should update the risk control detection rules in a timely manner to improve the defense capabilities and accuracy of the risk control system. This rule update strategy based on actual detection results helps to ensure that the risk control system is always in the best condition and effectively respond to evolving financial fraud methods.

[0102] In a feasible implementation, the security level of the risk control system to be tested is determined according to the adversarial detection result in the above embodiment, including: when the adversarial detection result is that the original hardware fingerprint information and the original user behavior information of the target device after modification both meet the risk control detection rules of the risk control system to be tested, determining that the security level of the risk control system to be tested is risk control level one; when the adversarial detection result is that the original hardware fingerprint information modified by the target device does not meet the wind control detection rules of the risk control system to be tested, and the original user behavior information modified by the target device meets the wind control detection rules of the risk control system to be tested, determining that the security level of the risk control system to be tested is risk control level two; when the adversarial detection result is that the original hardware fingerprint information modified by the target device meets the wind control detection rules of the risk control system to be tested, and the original user behavior information modified by the target device does not meet the wind control detection rules of the risk control system to be tested, determining that the security level of the risk control system to be tested is risk control level three; when the adversarial detection result is that the original hardware fingerprint information and the original user behavior information modified by the target device both do not meet the wind control detection rules of the risk control system to be tested, determining that the security level of the risk control system to be tested is risk control level four.

[0103] In the embodiments of the present application, by carefully dividing the security levels, the actual defense capability of the risk control system to be tested when facing virtual or simulated devices can be intuitively reflected. Level 1 risk control means that the risk control system performs well in both hardware fingerprint information and user behavior information, and can accurately identify and resist fraud. Level 2 and level 3 risk control respectively point out the deficiencies of the risk control system in detecting hardware fingerprint information or user behavior information. Level 4 risk control indicates that the risk control system has obvious loopholes in both aspects and urgently needs improvement.

[0104] In addition, this classification of security levels helps financial institutions formulate targeted risk control strategies. For different levels of security vulnerabilities, financial institutions can adopt different countermeasures, such as optimizing risk control detection rules, enhancing the advancement of detection technologies, strengthening employee training, etc., so as to more effectively enhance the overall defense ability of the risk control system.

[0105] In a feasible implementation manner, determining whether to update the risk control detection rules of the risk control system to be tested according to the adversarial detection result and / or the security level of the risk control system to be tested in the above embodiments includes: when the security level of the risk control system to be tested is not the first level of risk control, updating the risk control detection rules of the risk control system to be tested according to the adversarial detection result and / or the security level of the risk control system to be tested, obtaining the updated risk control system to be tested, and returning to execute the steps of using the detection function of the first tool and the anti-detection function of the second tool, modifying the original hardware fingerprint information of the target device into the preset hardware fingerprint information, and modifying the original user behavior information of the target device into the preset user behavior information, until the security level of the updated risk control system to be tested is the first level of risk control.

[0106] In the embodiments of the present application, by means of cyclic iteration, continuously updating the risk control detection rules according to the adversarial detection result and the security level assessment can ensure that the risk control system can continuously adapt to and resist new fraud means. This dynamic optimization process enables the risk control system to maintain its effectiveness and accuracy when facing the ever-changing financial fraud environment, thus providing a higher level of security protection for users.

[0107] In addition, by raising the security level of the risk control system to the first level of risk control, it means that the system performs excellently in both aspects of hardware fingerprint information and user behavior information, and can accurately identify and resist fraud behaviors. Such high standards not only help to enhance the security and adaptability of the risk control system, but also provide strong data support and decision-making basis for financial institutions to formulate and optimize risk control strategies. This is of great significance for financial institutions to enhance their competitiveness and user trust in the financial market while ensuring the security of user data and improving the reliability and stability of their services.

[0108] In a feasible implementation manner, the method in the above embodiment further includes: when the security level of the risk control system to be tested is at the first level of risk control, updating the preset hardware fingerprint simulation rule and the preset user behavior simulation rule according to the risk control detection rule of the risk control system to be tested, and returning to execute the detection function of the first tool and the anti-detection function of the second tool, modifying the original hardware fingerprint information of the target device into the preset hardware fingerprint information, and modifying the original user behavior information of the target device into the preset user behavior information; when the security level of the updated risk control system to be tested is at the first level of risk control, updating the preset hardware fingerprint simulation rule and the preset user behavior simulation rule according to the risk control detection rule of the updated risk control system to be tested, or updating the updated preset hardware fingerprint simulation rule and the updated preset user behavior simulation rule again, and returning to execute the detection function of the first tool and the anti-detection function of the second tool, modifying the original hardware fingerprint information of the target device into the preset hardware fingerprint information, and modifying the original user behavior information of the target device into the preset user behavior information, until the sum of the number of times that the security level of the risk control system to be tested is at the first level of risk control and the number of times that the security level of the updated risk control system to be tested is at the first level of risk control is equal to the total number threshold.

[0109] Among them, the total number threshold can be obtained and set in advance by the operator according to a large amount of experience, experiments or statistics. Of course, it can also be set in advance by the operator according to actual needs.

[0110] In the embodiment of the present application, by introducing an update mechanism for the preset hardware fingerprint simulation rule and the preset user behavior simulation rule, and combining a cyclic iterative test process, not only the adaptability and robustness of the risk control system are improved, but also strong data support and decision-making basis are provided for financial institutions to formulate and optimize risk control strategies, which is of great significance for financial institutions to enhance their competitiveness and user trust in the financial market while ensuring user data security and improving business reliability and stability.

[0111] It can be understood that when the security level of the risk control system to be tested reaches Risk Control Level 1, it not only indicates that the current risk control detection rules can effectively resist fraud behaviors, but also means that the preset hardware fingerprints and user behavior simulation rules have a certain degree of authenticity and challenge. At this time, by updating the preset simulation rules according to the risk control detection rules of the risk control system to be tested, more complex and concealed fraud means can be simulated, thereby further enhancing the detection ability of the risk control system. By continuously updating the preset simulation rules and combining with an iterative test process, the defense level of the risk control system can be continuously challenged and improved. This dynamic and highly adaptable testing method enables the risk control system to maintain its sensitivity and accuracy when facing constantly changing financial fraud means. At the same time, by setting a total number threshold, the sufficiency and effectiveness of the test process can be ensured, avoiding over-testing or under-testing situations.

[0112] In addition, this update mechanism helps financial institutions and technical personnel continuously explore new risk control technologies and means. As fraud means continue to evolve, traditional risk control detection rules may gradually become ineffective. By continuously updating the preset simulation rules and risk control detection rules, financial institutions can keep up with the development trend of fraud means and build a more advanced and efficient risk control system, thereby ensuring the security of user data and the stability of business operations.

[0113] In a second aspect of the present application, there is provided a risk control confrontation detection device for a risk control system.

[0114] Please refer to Figure 2 , which is a schematic diagram of a risk control confrontation detection device for a risk control system in an embodiment of the present application. The device 210 includes:

[0115] An installation module 211, configured to install a first tool and a second tool on a target device;

[0116] A tool modification module 212, configured to use the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information, and modify the original user behavior information of the target device into preset user behavior information;

[0117] A confrontation detection module 213, configured to perform confrontation detection on the target device using the risk control system to be tested to obtain a confrontation detection result.

[0118] In an embodiment of the present application, the relevant content of the above installation module 211, tool modification module 212, and confrontation detection module 213 can refer to the content in the embodiment shown in Figure 1 and will not be elaborated here.

[0119] It should be noted that the device 210 of the present application further includes some other modules. It can be understood that there is a one-to-one correspondence between the method and the device 210 of the present application. Therefore, some other modules of the device 210 of the present application are the corresponding content of the method of the present application in the above embodiments.

[0120] In the embodiments of the present application, by cleverly using the detection function of the first tool and the anti-detection function of the second tool, the fraudulent behavior of the attacker is efficiently and accurately simulated to bypass the risk control detection through device virtualization and simulation means. On this basis, the to-be-tested risk control system is used to perform adversarial detection on the modified target device, and the adversarial detection results are collected. According to these adversarial detection results, overseas banks and financial institutions can accurately judge whether the existing risk control detection rules of the risk control system are effective, and then decide whether necessary updates are required. This method can not only test the response efficiency of the risk control system when encountering virtual or simulated devices, but also significantly enhance the risk control detection ability of the risk control system against device feature detection, behavior analysis and other security detection mechanisms, so as to improve the performance of financial applications in risk monitoring and fraud prevention, build a more solid security defense line for financial applications, effectively prevent fraud behavior in device virtualization and simulation environments, ensure the absolute security of user data, and at the same time significantly improve the reliability and stability of financial applications.

[0121] In addition, the method has the following advantages: by dynamically updating the preset hardware fingerprint information and preset user behavior information and re-performing the adversarial detection, the risk control system can continuously adapt to new fraud means and device virtualization technologies. This adaptability enables the risk control system to maintain its effectiveness and accuracy in the face of evolving financial fraud; by simulating the fraud behavior of attackers to comprehensively test the risk control system, this test not only covers known risk points but may also reveal potential security vulnerabilities. By promptly fixing these vulnerabilities, the robustness of the risk control system will be enhanced, enabling it to better resist various forms of attacks; through the adversarial detection results, financial institutions can deeply understand the performance of the risk control system when encountering virtual or simulated devices. These adversarial detection results can provide strong data support for formulating and optimizing risk control strategies, helping financial institutions more accurately identify and control risks; the adversarial detection proposed in this application encourages financial institutions and technicians to continuously explore new risk control technologies and means. Through continuous technological innovation and upgrading, financial institutions can build more advanced and efficient risk control systems, enhancing their competitiveness in the financial market; a powerful risk control system can effectively protect the data security and fund security of users. By implementing the adversarial detection in this application, financial institutions can ensure the effectiveness of their risk control systems, thereby enhancing users' trust and satisfaction with financial institutions. This helps financial institutions establish more stable customer relationships and promote the continuous development of their businesses; with the development of the financial industry, regulatory agencies have put forward increasingly high requirements for the risk control capabilities of financial institutions. By implementing the adversarial detection, financial institutions can ensure that their risk control systems comply with regulatory requirements and avoid legal risks caused by compliance issues.

[0122] In a third aspect of the present application, there is also provided a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor is caused to execute a risk control adversarial detection method for a risk control system in the above method embodiment.

[0123] In a fourth aspect of the present application, there is also provided a computer device including a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute a risk control adversarial detection method for a risk control system in the above method embodiment.

[0124] Figure 3 The internal structure diagram of the computer device in some embodiments is shown. The computer device may specifically be a terminal, a server, or a gateway. As Figure 3 shown, the computer device includes a processor, a memory, and a network interface connected through a system bus.

[0125] Among them, the memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the computer device stores an operating system and may also store a computer program. When the computer program is executed by the processor, the processor can implement each step in the above method embodiments. The internal memory may also store a computer program. When the computer program is executed by the processor, the processor can execute each step in the above method embodiments. Those skilled in the art can understand that Figure 3 The structure shown in Figure 3 is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0126] Those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments.

[0127] Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0128] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0129] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A risk control and countermeasure detection method for a risk control system, characterized in that, The method includes: Install a first tool and a second tool on the target device; Use the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information, and modify the original user behavior information of the target device into preset user behavior information; Use the risk control system to be tested to perform adversarial detection on the target device to obtain an adversarial detection result.

2. The method according to claim 1, characterized in that The first tool is the NativeTest tool, and the second tool is the Holmes tool.

3. The method according to claim 1, wherein Using the detection function of the first tool and the anti-detection function of the second tool to modify the original hardware fingerprint information of the target device into preset hardware fingerprint information includes: Run the first tool, start the detection function of the first tool, and obtain the original hardware fingerprint information of the target device; Use a hardware fingerprint simulation tool to generate real-time hardware fingerprint simulation data according to preset hardware fingerprint simulation rules; Use the real-time hardware fingerprint simulation data as the preset hardware fingerprint information; Run the second tool, start the anti-detection function of the second tool, and modify the original hardware fingerprint information of the target device into the preset hardware fingerprint information.

4. The method according to claim 1, characterized in that Using the detection function of the first tool and the anti-detection function of the second tool to modify the original user behavior information of the target device into preset user behavior information includes: Run the first tool, start the detection function of the first tool, and obtain the original user behavior information of the target device; Use a user behavior simulation tool to generate real-time user behavior simulation data according to preset user behavior simulation rules; Use the real-time user behavior simulation data as the preset user behavior information; Run the second tool, start the anti-detection function of the second tool, and modify the original user behavior information of the target device into the preset user behavior information.

5. The method according to claim 1, characterized in that, The method further includes: Run the first tool, start the detection function of the first tool, and obtain the application anti-debugging mechanism, application code execution flow, and system call information and debugging flag during runtime of the target device; Run the second tool, start the anti-detection function of the second tool, and modify the application anti-debugging mechanism, application code execution flow, and system call information and debugging flag during runtime of the target device according to preset combination modification rules.

6. The method according to claim 1, characterized in that, The step of using the risk control system to be tested to perform adversarial detection on the target device to obtain an adversarial detection result includes: Use the risk control system to be tested to perform adversarial detection on the modified original hardware fingerprint information and original user behavior information of the target device according to the risk control detection rules of the risk control system to be tested to obtain the adversarial detection result.

7. The method according to claim 1, characterized in that, The method further includes: Determine the security level of the risk control system to be tested according to the adversarial detection result; Determine whether to update the risk control detection rules of the risk control system to be tested according to the adversarial detection result and / or the security level of the risk control system to be tested.

8. The method according to claim 7, wherein The step of determining the security level of the risk control system to be tested according to the adversarial detection result includes: When the anti-detection result shows that both the modified original hardware fingerprint information and the original user behavior information of the target device meet the risk control detection rules of the to-be-tested risk control system, determine that the security level of the to-be-tested risk control system is risk control level one; When the anti-detection result shows that the modified original hardware fingerprint information of the target device does not meet the risk control detection rules of the to-be-tested risk control system, and the modified original user behavior information of the target device meets the risk control detection rules of the to-be-tested risk control system, determine that the security level of the to-be-tested risk control system is risk control level two; When the anti-detection result shows that the modified original hardware fingerprint information of the target device meets the risk control detection rules of the to-be-tested risk control system, and the modified original user behavior information of the target device does not meet the risk control detection rules of the to-be-tested risk control system, determine that the security level of the to-be-tested risk control system is risk control level three; When the anti-detection result shows that both the modified original hardware fingerprint information and the original user behavior information of the target device do not meet the risk control detection rules of the to-be-tested risk control system, determine that the security level of the to-be-tested risk control system is risk control level four.

9. The method according to claim 7, wherein Determining whether to update the risk control detection rules of the to-be-tested risk control system according to the anti-detection result and / or the security level of the to-be-tested risk control system includes: When the security level of the to-be-tested risk control system is not risk control level one, update the risk control detection rules of the to-be-tested risk control system according to the anti-detection result and / or the security level of the to-be-tested risk control system to obtain an updated to-be-tested risk control system, and return to execute the steps of using the detection function of the first tool and the anti-detection function of the second tool, modifying the original hardware fingerprint information of the target device to preset hardware fingerprint information, and modifying the original user behavior information of the target device to preset user behavior information until the security level of the updated to-be-tested risk control system is risk control level one.

10. The method according to any one of claims 3, 4 or 9, characterized in that The method further includes: When the security level of the to-be-tested risk control system is risk control level one, update the preset hardware fingerprint simulation rules and the preset user behavior simulation rules according to the risk control detection rules of the to-be-tested risk control system, and return to execute the steps of using the detection function of the first tool and the anti-detection function of the second tool, modifying the original hardware fingerprint information of the target device to preset hardware fingerprint information, and modifying the original user behavior information of the target device to preset user behavior information; When the security level of the updated risk control system to be tested is at the first level of risk control, according to the risk control detection rules of the updated risk control system to be tested, update the preset hardware fingerprint simulation rules and the preset user behavior simulation rules, or update the updated preset hardware fingerprint simulation rules and the updated preset user behavior simulation rules again, and return to execute the detection function of the first tool and the anti-detection function of the second tool, modify the original hardware fingerprint information of the target device to the preset hardware fingerprint information, and modify the original user behavior information of the target device to the preset user behavior information, until the sum of the number of times the security level of the risk control system to be tested is at the first level of risk control and the number of times the security level of the updated risk control system to be tested is at the first level of risk control is equal to the total number threshold.

Citation Information

Patent Citations

  • Data analysis method and device, electronic device and storage medium

    CN110543506A

  • Method and device for determining risk behavior generation model

    CN110633989A

  • Attack and defense confrontation test method and device, medium and equipment

    CN116318799A

  • Grade protection safety evaluation method and system, terminal equipment and storage medium

    CN117273460A

  • Intelligent risk control method for cloud face scanning and computer readable storage medium

    CN117792653A