Game anti-plug-in Ai algorithm ESP protection mechanism
Through the ESP protection mechanism of the game anti-plug-in AI algorithm, combined with data encryption, AI behavior detection and multi-dimensional protection, the problems of insufficient data encryption and single behavior detection in the existing technology are solved, and the security protection of game data and effective defense of plug-in are achieved.
Patent Information
- Application Number
- CN202510463717.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-14
AI Technical Summary
The existing game anti-plug-up technology has problems such as insufficient data encryption strength, lagging vulnerability repair, and single behavior detection, which is difficult to effectively prevent plug-ins from modifying game data and behavior.
The ESP protection mechanism of the game anti-plug-in AI algorithm is adopted, and through data encryption, AI behavior detection, vulnerability repair and expansion, speed blocking and exception handling, multi-dimensional protection control, combined with SDK and DLL embedded loading, it realizes the encryption of game key data and real-time identification and processing of abnormal behavior.
Effectively prevent plug-ins from modifying and intruding game clients, protecting game data security and integrity, improving the difficulty of plug-ins attacks, and ensuring the fairness and stability of gameplay.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of game security, and more specifically, to an anti-cheat AI algorithm ESP protection mechanism for games. Background Art
[0002] Current game anti-cheat technologies mainly focus on the following aspects:
[0003] Memory scanning and signature detection: By monitoring the memory of the game process, matching the signature codes or data patterns of known cheats, and intercepting suspicious operations. However, such methods rely on the real-time update of the cheat signature library and are difficult to cope with new types of cheats with dynamic changes.
[0004] Data verification and encryption: Simple encryption or verification is performed on key game data (such as health points, equipment attributes) to prevent direct memory tampering. However, the existing encryption algorithms are not strong enough, and cheats can bypass the protection through memory breakpoints and debugging tools. Especially for scenarios that require dynamic expansion of numerical values such as "infinite health bar" and "infinite equipment", traditional encryption methods cannot support the secure expansion of data.
[0005] Behavior pattern recognition: Based on a rule engine or simple machine learning algorithms, detecting abnormal behaviors of player operations (such as speeding up movement, frequent clicking). However, such methods lack self-learning ability, have insufficient detection accuracy for complex cheating behaviors (such as simulating mouse and keyboard operations, graphic color hanging), and are prone to false positives.
[0006] Engine vulnerability patching: Patching known vulnerabilities of the game engine, but cheats can achieve illegal breakthroughs in game logic by exploiting unpublicized vulnerabilities or limitations of engine extension interfaces (such as fixed health point value ranges).
[0007] In view of the problems of insufficient data encryption strength, lagging vulnerability patching, and single behavior detection in the prior art, the anti-cheat AI algorithm ESP protection mechanism for games proposed by the present invention can encrypt the health bars of characters and monsters to prevent cheats from modifying them, encrypt and draw independent infinite health bars, as well as encrypt infinite equipment expansion, game speed encryption, and encryption of the game mouse movement trajectory. Combined with AI behavior recognition, it can effectively prevent game cheating behaviors. Summary of the Invention
[0008] In view of this, the present invention provides an anti-cheat AI algorithm ESP protection mechanism for games.
[0009] To achieve the above object, the present invention provides the following technical solutions, mainly including: a loading and initialization module, a data encryption protection module, an AI behavior detection module, a vulnerability patching and extension module, a speed limiting and exception handling module, and a multi-dimensional protection control module;
[0010] The loading and initialization module: Loads the ESP protection unit in an embedded manner through the SDK and DLL. The unit file name is ESP-X32.DLL. After loading, it triggers the ESP-B version gateway protection mechanism and establishes a connection between the game client and the anti-cheat gateway Gameofesp.
[0011] The data encryption and protection module: Encrypts the key data in the game, including game speed data, blood volume values, equipment data, and mouse movement trajectory data. Among them, the blood volume value uses an independently drawn infinite health bar encryption technology, and the equipment data uses an infinite expansion encryption technology.
[0012] The AI behavior detection module: Introduces AI behavior simulation detection technology to analyze the player's operation behavior in the game in real time and identify abnormal behavior patterns. The AI behavior simulation detection technology is based on the AI large model visual nervous system and has the ability of self-learning.
[0013] The vulnerability repair and expansion module: Automatically detects and repairs the vulnerabilities existing in the game engine client, and at the same time supports the expansion of game data, including blood volume value expansion and equipment value expansion, to resist the modification attacks of cheats.
[0014] The speed limit and exception handling module: Detects the movement speed and attack speed in the game through the gateway speed limit system, sets the exception accumulation value and handling strategy, and when speed anomalies are detected, disconnects the connection and prompts the player.
[0015] The multi-dimensional protection control module: Includes an anti-simulated keyboard and mouse detection unit, a multi-opening control unit, a virtual machine detection unit, and a graphic color protection unit. Among them, the anti-simulated keyboard and mouse detection unit identifies the driver-level mouse simulation, the multi-opening control unit limits the number of game clients that can be logged in simultaneously according to the account or machine code, the virtual machine detection unit judges whether it is a virtual machine environment through features such as CPU model, hard disk size, and shared folder, and the graphic color protection unit interferes with and detects graphic color-based hanging behaviors in the game.
[0016] Preferably, in the AI behavior detection, the abnormal behavior patterns include but are not limited to high-frequency clicks within a short period of time, unnatural movement trajectories, speed values exceeding the game set range, etc. The AI algorithm establishes a behavior model by learning the behavior data of normal players and compares and judges the real-time operation data.
[0017] Preferably, the gateway speed limit system includes movement speed detection and attack speed detection.
[0018] Preferably, the anti-simulation keyboard and mouse detection includes detection of driver-level mouse simulation software such as Key Wizard and Big Model Plug-in, supports setting a keyboard and mouse protection whitelist, performs compatibility settings for remote control software such as ToDesk and Sunflower, and enters a prohibited attack time period by default.
[0019] Preferably, the multiple opening control function supports limiting the number of multiple openings based on the ESP account or machine code as an identifier, setting a time interval and a threshold for the number of multiple openings. When the set number is exceeded, new client logins are prohibited and the player is prompted.
[0020] Preferably, the virtual machine detection options include common options, robust options and brute force options. The common options detect virtual machines through CPU model names and shared folders, the robust options use CPUID+hard disk detection and network card MAC detection, and the brute force options use CPUID detection and hard disk size detection (less than or equal to 99GB) to determine the virtual machine environment, and also support adding a machine code whitelist to reduce false positives.
[0021] Preferably, the image color protection options include detecting image color binding, character name style protection, NPC name style protection, monster name style protection and underground item name style protection, turning on the function of preventing foreground image color from going offline, performing black screen processing on some software screenshot games, and supporting the setting of effective maps and machine code whitelists.
[0022] It can be seen from the above technical solutions that, compared with the prior art, the game anti-cheating Ai algorithm ESP protection mechanism provided by the present invention can effectively prevent the modification and invasion of the game client by the cheating, and protect the security and integrity of the game data. AI behavior detection technology can identify abnormal behavior in real time. Functions such as the speed blocking system and anti-simulation keyboard and mouse further increase the difficulty of the cheating attack. Measures such as multi-opening control and virtual machine detection reduce the use scenarios of the cheating. The image and color protection function effectively combats the image and color hanging behavior. The entire protection mechanism combines data encryption, AI algorithm and multi-dimensional protection control to form a complete set of game anti-cheating solutions, which provides a strong guarantee for the fairness and stability of the game. DETAILED DESCRIPTION
[0023] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0024] An anti-cheat AI algorithm ESP protection mechanism disclosed by the present invention mainly includes: a loading and initialization module, a data encryption protection module, an AI behavior detection module, a vulnerability repair and extension module, a speed limiting and exception handling module, and a multi-dimensional protection control module;
[0025] The loading and initialization module: Loads the ESP protection unit in an embedded manner through the SDK and DLL. The unit file name is ESP-X32.DLL. After loading, it triggers the ESP-B version gateway protection mechanism and establishes a connection between the game client and the anti-cheat gateway Gameofesp;
[0026] The data encryption protection module: Encrypts the key data in the game, including game speed data, blood volume values, equipment data, and mouse movement trajectory data. Among them, the blood volume value adopts an independent drawing infinite blood bar encryption technology, and the equipment data adopts an infinite expansion encryption technology;
[0027] The AI behavior detection module: Introduces AI behavior simulation detection technology to analyze the operation behavior of players in the game in real time and identify abnormal behavior patterns. The AI behavior simulation detection technology is based on the AI large model visual nervous system and has the ability of self-learning;
[0028] The vulnerability repair and extension module: Automatically detects and repairs the vulnerabilities existing in the game engine client, and at the same time supports the expansion of game data, including the expansion of blood volume values and equipment numerical values, to resist the modification attacks of cheats;
[0029] The speed limiting and exception handling module: Detects the movement speed and attack speed in the game through the gateway speed limiting system, sets the abnormal accumulation value and handling strategy, and when the speed abnormality is detected, disconnects the connection and prompts the player;
[0030] The multi-dimensional protection control module: Includes an anti-simulated keyboard and mouse detection unit, a multi-opening control unit, a virtual machine detection unit, and a graphic color protection unit. Among them, the anti-simulated keyboard and mouse detection unit identifies the driver-level mouse simulation, the multi-opening control unit limits the number of game clients that can be logged in simultaneously according to the account or machine code, the virtual machine detection unit judges whether it is a virtual machine environment through features such as CPU model, hard disk size, and shared folder, and the graphic color protection unit interferes with and detects the graphic color-based hanging behavior in the game.
[0031] When the game engine starts, the loading and initialization module loads the ESP-X32.DLL file in the form of SDK and DLL embedding. During the loading process, the ESP-B version gateway protection mechanism is triggered, and the anti-cheat gateway Gameofesp starts and establishes a communication connection with the game client. When initializing the gateway, the authorization information and protection policies in the configuration file are read to ensure the normal operation of the protection module. For example, in the MirServer / Mir200 directory on the server side, there are files such as esp.dll and ESP-X32.dll, and the initialization settings are carried out through the esp configuration in the configuration file and esp authorization verification.
[0032] Blood volume and equipment encryption in the data encryption and protection module: Encrypt the blood bar values of game characters and monsters, and use an independent encryption algorithm to generate encrypted blood volume values to prevent cheats from directly obtaining and modifying blood volume data by modifying memory. At the same time, the infinite blood bar expansion function is realized. The blood volume value is expanded to a larger numerical range through the encryption algorithm. Even if the cheat tries to modify it, it will fail because the value exceeds the expected range. The equipment data is also encrypted, and information such as the attributes and quantities of the equipment is encrypted, supporting infinite equipment expansion to ensure the security of equipment data.
[0033] Furthermore, speed and mouse trajectory encryption: The game speed data (including movement speed and attack speed) is encrypted during transmission to prevent cheats from accelerating by modifying speed parameters. The coordinates, speed, acceleration and other parameters of the mouse movement trajectory are collected and encrypted in real time to generate a unique trajectory feature code for subsequent AI behavior detection and anti-simulation mouse and keyboard detection.
[0034] The AI behavior detection module is based on the visual nervous system of the AI large model. By collecting a large amount of operation data of normal players, a normal behavior model is trained and established. At the same time, during the game operation, the operation data of players is collected in real time, including the mouse click position, movement trajectory, key press frequency, skill release interval, etc. These data are input into the AI algorithm for analysis and compared with the normal behavior model. When abnormal behavior patterns (such as high-frequency clicks in a short time, unnatural movement trajectories, etc.) are detected, the warning mechanism is triggered, and corresponding protection measures are further taken, such as recording logs, restricting operations or disconnecting the connection.
[0035] The vulnerability repair and expansion module is used to regularly scan the game engine client for vulnerabilities, identify potential security vulnerabilities, such as memory vulnerabilities and network protocol vulnerabilities. Once a vulnerability is found, the corresponding repair program is automatically loaded to repair the vulnerability to prevent cheats from using the vulnerability for attacks. At the same time, it supports the expansion of game data. For example, by modifying the code and data structure of the game client, the blood volume value and equipment value are expanded to provide a larger numerical range for the game and enhance the resistance to cheat modification.
[0036] The movement speed detection: Enable the movement speed detection function and set the abnormal accumulation value to 20 (which can be adjusted according to the actual situation). Adopt an enhanced movement speed calculation algorithm to intelligently judge whether the player's movement speed is normal. When the player is in a non-moving state, the abnormal accumulation value is 5; when in a moving state, the abnormal accumulation value is 2; when moving normally, it is 1. When the detected movement speed is abnormal (exceeding the set threshold), perform a disconnection operation and send a prompt message to the player: "Your movement speed is abnormal. Do not use programs such as speed-changing gears!"
[0037] The attack speed detection: Also adopt an enhanced attack speed calculation algorithm, enable the attack speed detection, and set the abnormal accumulation value to 20. When the detected attack speed is abnormal, perform a disconnection and prompt the player "Your attack speed is abnormal. Do not use programs such as speed-changing gears!" To avoid misjudgment caused by overly strict detection, it supports adjusting parameters such as filling -16 in the global compensation.
[0038] The anti-simulation mouse and keyboard detection unit is used to enable the anti-mouse and keyboard protection function and detect common driver-level mouse simulation software on the market (such as Button Sprite, Big Model Plugin). In the advanced options, it supports setting the strictest detection mechanism and enabling enhanced protection for the mouse pointer. At the same time, to be compatible with remote control software such as ToDesk and Sunflower, the default setting is to enter the prohibited attack time period when operating these software to avoid misjudgment. Players can perform exception handling for specific accounts by setting a whitelist of character names.
[0039] According to the game operation requirements, set the multi-opening control strategy. You can choose to use the ESP account as an identifier to limit the number of multi-openings, set the time interval (such as from 0:00 to 23:00 every day) and the threshold of the number of multi-openings (such as at most allowing 3 clients to log in simultaneously). When the number of clients that the player attempts to log in exceeds the set value, prohibit new login requests and prompt the player "The current account has reached the multi-opening limit". At the same time, it supports compatibility settings for multiple versions of logins and adding a whitelist of machine codes to perform exception handling for specific devices.
[0040] Furthermore, the virtual machine detection unit provides multiple virtual machine detection options, including common options, robust options, and violent options. Specifically, the common option judges whether it is a virtual machine environment by detecting the CPU model name and shared folders; the robust option adopts CPUID + hard disk detection and network card MAC detection to improve the detection accuracy; the violent option strictly judges the virtual machine through CPUID detection and hard disk size detection (less than or equal to 99GB), with strong detection ability but possible misjudgment. Players can select appropriate detection options according to the actual situation and add a whitelist of machine codes to reduce misjudgment situations.
[0041] Furthermore, the graphic color protection unit is used to enable the graphic color protection function to interfere with and detect graphic color-based afk farming behaviors in the game. It includes detecting the styles of graphic color bindings, protecting the names of characters, NPCs, monsters, and underground items, preventing cheats from automatically afk farming by identifying graphic color information. It enables the anti-front desk graphic color offline function to black out the game screen for some software screenshot games, making it impossible to obtain game screen information. It supports setting the effective maps to enable graphic color protection only within specific maps, and adding a machine code whitelist to disable the anti-screenshot function for specific devices.
[0042] Through the above specific implementation manners, the present invention can effectively prevent cheats from modifying and invading the game client, protecting the security and integrity of game data. The AI behavior detection technology can identify abnormal behaviors in real time. Functions such as the speed limit system and anti-simulated mouse and keyboard further increase the difficulty of attacking by cheats. Measures such as multi-opening control and virtual machine detection reduce the usage scenarios of cheats, and the graphic color protection function effectively combats graphic color-based afk farming behaviors. The entire protection mechanism combines data encryption, AI algorithms, and multi-dimensional protection control to form a complete game anti-cheat solution, providing a strong guarantee for the fairness and stability of the game.
[0043] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An anti-cheat AI algorithm ESP protection mechanism for games, characterized in that, Mainly include: Loading and initialization module, data encryption protection module, AI behavior detection module, vulnerability patching and expansion module, speed blocking and exception handling module, multi-dimensional protection control module; The loading and initialization module: loads the ESP protection unit through SDK and DLL embedded mode. The unit file is named ESP-X32.DLL. After loading, the ESP-B version gateway protection mechanism is triggered to establish a connection between the game client and the anti-hang gateway Gameofesp; The data encryption protection module: encrypts key data in the game, including game speed data, health value, equipment data and mouse movement trajectory data, where the health value adopts the independent drawing infinite health bar encryption technology, and the equipment data adopts the infinite expansion encryption technology; The AI behavior detection module: introduces AI behavior simulation detection technology to analyze the player's operation behavior in the game in real time and identify abnormal behavior patterns. The AI behavior simulation detection technology is based on the AI large model visual nervous system and has self-learning ability; The vulnerability patching and expansion module: automatically detects and patches the vulnerabilities existing in the game engine client, and supports the expansion of game data, including health value expansion and equipment value expansion, to resist modification attacks by plug-ins; The speed blocking and exception handling module: detects the movement speed and attack speed in the game through the gateway speed blocking system, sets the abnormal accumulation value and handling strategy, and disconnects and prompts the player when the speed abnormality is detected; The multi-dimensional protection control module includes an anti-simulation keyboard and mouse detection unit, a multi-opening control unit, a virtual machine detection unit and a graphic color protection unit, wherein the anti-simulation keyboard and mouse detection unit identifies the driver-level mouse simulation, the multi-opening control unit limits the number of game clients logged in at the same time according to the account or machine code, the virtual machine detection unit determines whether it is a virtual machine environment through features such as CPU model, hard disk size, and shared folders, and the graphic color protection unit interferes with and detects graphic color-related idle behaviors in the game.
2. The anti-cheat AI algorithm ESP protection mechanism for games according to claim 1, characterized in that, In the AI behavior detection, abnormal behavior patterns include but are not limited to high-frequency clicks in a short period of time, unnatural movement trajectories, speed values beyond the game setting range, etc. The AI algorithm learns the behavior data of normal players, establishes a behavior model, and compares and judges the real-time operation data.
3. The anti-cheat AI algorithm ESP protection mechanism for games according to claim 1, characterized in that The gateway speed blocking system includes movement speed detection and attack speed detection.
4. The anti-cheat AI algorithm ESP protection mechanism for games according to claim 1, characterized in that, The anti-simulation keyboard and mouse detection includes the detection of driver-level mouse simulation software such as Key Wizard and Big Model Plug-in, supports the setting of keyboard and mouse protection whitelist, and performs compatibility settings for remote control software such as ToDesk and Sunflower, and enters the prohibited attack time period by default.
5. The game anti-cheat AI algorithm ESP protection mechanism according to claim 1, characterized in that, The multiple opening control function supports limiting the number of multiple openings based on the ESP account or machine code as an identifier, setting a time interval and a threshold for the number of multiple openings. When the set number is exceeded, new clients are prohibited from logging in and the player is prompted.
6. The game anti-cheat AI algorithm ESP protection mechanism according to claim 1, characterized in that, The virtual machine detection options include common options, robust options, and brute-force options. The common options detect virtual machines through the CPU model name and shared folders. The robust options use CPUID + hard disk detection and network card MAC detection. The brute-force options judge the virtual machine environment through CPUID detection and hard disk size detection (less than or equal to 99GB), and at the same time support adding a machine code whitelist to reduce false positives.
7. The anti-cheat AI algorithm ESP protection mechanism for games according to claim 1, characterized in that, The graphic protection options include detecting graphic bindings, protecting the styles of character names, NPC names, monster names, and the names of underground items. The anti-foreground graphic offline function is enabled to black out the screenshots of some software games, and it supports setting the effective maps and machine code whitelists.
Citation Information
Patent Citations
Active anti-plug-in online game system and anti-plug-in method thereof
CN102158367A
System and method for client terminal plug-in detection and automatic closure
CN107096220A
Game plug-in detection method and device, storage medium and computer device
CN112090087A
Game plug-in behavior detection method and device and computer equipment
CN117959728A
Cited By
Cloud game vulnerability analyzing and monitoring system based on cloud computing
CN121167735A