Stadium request analysis method and system based on multi-dimensional behavior analysis

Through multi-dimensional behavior analysis and combined with the business logic of the stadium, the offset distance of the ticket purchase path, the space-time abnormality and violation reservation indicators are calculated, which solves the problem of difficult to protect against abnormal behavior in the high-concurrent snap-up scenarios in the existing technology, and realizes accurate identification and protection of abnormal attacks.

CN120434644APending Publication Date: 2025-08-05SHENZHEN PAPA SPORTS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510557319.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

In the existing technology, in the stadium reservation scenario, when facing complex and changeable attack methods, there are problems such as single-dimensional detection blind spots, static rule lag and poor scene adaptability, and it is difficult to effectively protect against abnormal behaviors in high concurrent snap-up scenarios.

Method used

A multi-dimensional behavioral analysis method is adopted to obtain the basic behavior data of user ticket purchase requests, calculate the offset distance of ticket purchase path, temporal and spatial abnormal indicators, and make risk decisions to determine the processing method of ticket purchase requests.

Benefits of technology

It realizes accurate identification and protection of abnormal attacks, solves the problem of blind spots and insufficient adaptability of traditional solutions in high concurrent rush buying scenarios, and ensures the fairness and stability of the ticket purchase system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434644A_ABST
    Figure CN120434644A_ABST
Patent Text Reader

Abstract

The invention discloses a stadium request analysis method and system based on multi-dimensional behavior analysis. The method comprises the following steps: extracting basic behavior data of a user according to a ticket buying request initiated by the user for a specific site area in a target stadium; and according to the basic behavior data, calculating a ticket buying path offset distance, a plurality of space-time anomaly indexes and violation predetermined indexes, performing risk decision according to the indexes, and determining a processing mode of the ticket buying request according to a risk decision result. According to the method, the limitation of a single index is avoided through multi-dimensional behavior analysis of path offset, spatial-temporal characteristics, violation modes and the like. According to the method, multi-dimensional behavior analysis is closely combined with stadium service logic, normal behavior logic of a user in a reservation scene is deeply understood, and normal users and abnormal attacks are accurately distinguished. According to the method, risk decision is carried out based on multiple dynamic indexes calculated in real time, and the problems of detection blind areas and insufficient adaptability of a traditional scheme in a high-concurrency panic buying scene are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the intersection of Internet security and big data analysis, and in particular to a method and system for analyzing stadium requests based on multi-dimensional behavior analysis. Background Art

[0002] Currently, traditional systems for detecting abnormal behavior in stadium reservation scenarios rely primarily on single-dimensional detection of IP frequency or device fingerprints, as well as manually configured fixed rules. However, such solutions have significant drawbacks:

[0003] First, there are blind spots in single-dimensional detection. Traditional systems rely on single-dimensional detection of IP frequency or device fingerprints, which cannot identify distributed proxy pool attacks.

[0004] Second, static rules have a significant lag, and manually configured fixed rules are difficult to deal with new scalper attack patterns, such as attacks that combine dynamic IP switching with normal user behavior simulation.

[0005] Third, the existing solutions have poor adaptability to different scenarios. They lack an understanding of the unique business logic of sports venues, such as key features such as path dependence in venue selection and differences in popularity during different time periods.

[0006] It can be seen that traditional detection methods are difficult to effectively protect against complex and changing attack methods in high-concurrency rush-buying scenarios.

[0007] Therefore, the existing technology still needs to be improved and developed. Summary of the Invention

[0008] The technical problem to be solved by the present invention is to provide a sports venue request analysis method and system based on multi-dimensional behavior analysis in response to the above-mentioned defects of the existing technology, aiming to solve the problem that the existing abnormal behavior detection technology for sports venue reservation scenarios is difficult to effectively protect against complex and changeable attack methods in high-concurrency rush-buying scenarios.

[0009] The technical solutions adopted by the present invention to solve the problem are as follows:

[0010] In a first aspect, an embodiment of the present invention provides a method for analyzing stadium requests based on multi-dimensional behavior analysis, the method comprising:

[0011] Obtaining a ticket purchase request initiated by a user for a specific venue area within a target sports stadium, and extracting basic behavior data of the user based on the ticket purchase request;

[0012] Calculate the ticket purchase path deviation distance, several spatiotemporal anomaly indicators, and illegal reservation indicators based on the basic behavior data;

[0013] A risk decision is made based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the predetermined violation indicator, and a processing method for the ticket purchase request is determined based on the risk decision result.

[0014] In one embodiment, the method for calculating the ticket purchase path offset distance includes:

[0015] Performing interface dependency graph analysis based on the basic behavior data to obtain a ticket purchase path corresponding to the ticket purchase request;

[0016] Obtain a standard ticket purchasing path, compare the ticket purchasing path with the standard ticket purchasing path, and obtain the ticket purchasing path offset distance.

[0017] In one embodiment, each of the spatiotemporal anomaly indicators includes a geographic location anomaly indicator and a request time anomaly indicator; and a calculation method for each of the spatiotemporal anomaly indicators includes:

[0018] Obtaining the user location sequence and the frequency of request time during non-business hours based on the basic behavior data;

[0019] Calculating the geographic location anomaly index based on the user location sequence;

[0020] The request time anomaly index is calculated according to the frequency of the request time during non-business hours.

[0021] In one embodiment, calculating the geographic location anomaly index based on the user location sequence includes:

[0022] Calculating a moving speed according to the user position sequence, and calculating an abnormal transition index according to the moving speed;

[0023] Performing geo-fence verification based on the user location sequence and the movement speed to obtain an abnormal geographic behavior indicator; the abnormal geographic behavior indicator is used to reflect geographic location jump abnormalities and / or regional association abnormalities;

[0024] The geographic location anomaly index is determined according to the abnormal transition index and the abnormal geographic behavior index.

[0025] In one embodiment, geo-fence verification is performed based on the user location sequence and the movement speed to obtain an abnormal geographic behavior indicator, including:

[0026] determining a first-used IP address based on the user location sequence, and determining a geographic area fence based on the first-used IP address and the movement speed;

[0027] Performing spatial cluster analysis based on the user location sequence to obtain resident area identification information;

[0028] Calculating the geographic location jump anomaly index and / or the regional association anomaly index based on the resident area identification information and the geographic area fence;

[0029] The abnormal geographic behavior indicator is obtained according to the geographic location jump abnormality indicator and / or the regional association abnormality indicator.

[0030] In one embodiment, the method for calculating the predetermined violation index includes:

[0031] Obtaining a venue reservation strategy for the target sports venue;

[0032] According to the basic behavior data and the venue reservation strategy, it is determined whether the user has engaged in illegal reservation behavior, and the illegal reservation index is calculated according to the determination result.

[0033] In one embodiment, a risk decision is made based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the predetermined violation indicator, and a processing method of the ticket purchase request is determined based on the risk decision result, including:

[0034] Obtaining the risk value of the user by weighted fusion based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the violation reservation indicator;

[0035] The risk level of the user is determined according to the risk value, and the processing method of the ticket purchase request is determined according to the risk level; wherein, if the risk level is less than a preset level, the ticket purchase request is released.

[0036] In a second aspect, an embodiment of the present invention further provides a stadium request analysis system based on multi-dimensional behavior analysis, the system comprising:

[0037] A request acquisition module is used to acquire a ticket purchase request initiated by a user for a specific venue area in a target sports stadium, and extract basic behavior data of the user based on the ticket purchase request;

[0038] A behavior analysis module, configured to calculate the ticket purchase path deviation distance, several spatiotemporal anomaly indicators, and illegal reservation indicators based on the basic behavior data;

[0039] The risk decision module is used to make a risk decision based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators and the violation predetermined indicator, and determine the processing method of the ticket purchase request according to the risk decision result.

[0040] In a third aspect, an embodiment of the present invention further provides a terminal comprising a memory and one or more processors; the memory stores one or more programs; the programs include instructions for executing any of the above-described stadium request analysis methods based on multi-dimensional behavioral analysis; and the processor is used to execute the programs.

[0041] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium on which a plurality of instructions are stored, wherein the instructions are suitable for being loaded and executed by a processor to implement any of the steps of the above-mentioned stadium request analysis method based on multi-dimensional behavioral analysis.

[0042] Beneficial effects of the present invention: The embodiment of the present invention extracts the basic behavioral data of the user through the ticket purchase request initiated by the user for a specific venue area in the target sports stadium; calculates the ticket purchase path offset distance, several spatiotemporal anomaly indicators and violation reservation indicators based on the basic behavioral data, and makes risk decisions based on these indicators, and determines the processing method of the ticket purchase request based on the risk decision results. The present invention avoids the limitations of a single indicator through multi-dimensional behavioral analysis such as path offset, spatiotemporal characteristics, and violation patterns. The multi-dimensional behavioral analysis of the present invention is closely integrated with the business logic of the sports stadium, deeply understands the normal behavioral logic of users in the reservation scenario, and accurately distinguishes normal users from abnormal attacks. The present invention makes risk decisions based on a variety of dynamic indicators calculated in real time, which effectively solves the problems of detection blind spots and insufficient adaptability of traditional solutions in high-concurrency rush buying scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0044] Figure 1 It is a flow chart of a method for analyzing stadium requests based on multi-dimensional behavior analysis provided by an embodiment of the present invention.

[0045] Figure 2 This is a technical architecture diagram of a stadium request analysis method based on multi-dimensional behavior analysis provided by an embodiment of the present invention.

[0046] Figure 3 This is a logical diagram of the user behavior feature analysis provided by an embodiment of the present invention.

[0047] Figure 4 This is a logical diagram of the spatiotemporal trajectory analysis provided by an embodiment of the present invention.

[0048] Figure 5 It is a multi-dimensional decision-making flowchart provided by an embodiment of the present invention.

[0049] Figure 6 This is a module diagram of a sports venue request analysis system based on multi-dimensional behavior analysis provided by an embodiment of the present invention.

[0050] Figure 7 This is a principle block diagram of a terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0051] The present invention discloses a method and system for analyzing stadium requests based on multi-dimensional behavioral analysis. To make the objectives, technical solutions, and effects of the present invention more clear and explicit, the present invention is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific examples described herein are intended only to illustrate the present invention and are not intended to limit the present invention.

[0052] It will be understood by those skilled in the art that, unless expressly stated otherwise, the singular forms "a", "an", "said" and "the" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the description of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. In addition, "connected" or "coupled" as used herein may include wireless connections or wireless couplings. The term "and / or" used herein includes all or any units and all combinations of one or more associated listed items.

[0053] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art in the art to which the present invention belongs. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with their meanings in the context of the prior art and will not be interpreted in an idealized or overly formal sense unless specifically defined as herein.

[0054] To address the aforementioned shortcomings of the prior art, the present invention provides a stadium request analysis method based on multi-dimensional behavioral analysis. The method comprises: obtaining a user's ticket purchase request for a specific area within a target stadium; extracting the user's basic behavioral data based on the ticket purchase request; calculating the purchase path offset distance, several spatiotemporal anomaly indicators, and a pre-defined violation indicator based on the basic behavioral data; making a risk decision based on the purchase path offset distance, each of the spatiotemporal anomaly indicators, and the pre-defined violation indicator; and determining a handling method for the ticket purchase request based on the risk decision result. By analyzing multi-dimensional behavioral features such as path offset, spatiotemporal characteristics, and violation patterns, the present invention avoids the limitations of a single metric. Furthermore, the present invention's multi-dimensional behavioral analysis is closely integrated with the stadium's business logic, deeply understanding the normal user behavior logic in reservation scenarios, thereby accurately distinguishing between normal users and abnormal attacks. Furthermore, the present invention makes risk decisions based on multiple dynamic indicators calculated in real time, enabling rapid response to new scalper attack methods, effectively addressing the detection blind spots and insufficient adaptability of traditional solutions in high-concurrency rush-buying scenarios.

[0055] like Figure 1 As shown, the method specifically includes the following steps:

[0056] Step S100: Obtain a ticket purchase request initiated by a user for a specific venue area in a target sports stadium, and extract basic behavior data of the user based on the ticket purchase request.

[0057] Specifically, the target stadium in this embodiment can be any stadium that has a ticket purchasing system installed. The target stadium typically has multiple functional areas, such as a grandstand area, a VIP area, and a general area. In actual use, the system will receive one or more ticket purchase requests from a user and extract basic behavioral data from the user's ticket purchase process to subsequently analyze whether the user's ticket purchase request is normal.

[0058] Step S200: Calculate the ticket purchase path offset distance, several spatiotemporal anomaly indicators, and illegal reservation indicators based on the basic behavior data.

[0059] Specifically, this embodiment calculates multiple indicators based on basic behavioral data for collaborative subsequent risk decision-making. Among them, the ticket purchase path offset distance refers to: the degree of deviation between the user's actual ticket purchase operation path and the normal business logic path in the stadium reservation scenario. This type of indicator captures the behavioral characteristics of scalper scripts (such as bypassing the front-end page logic through the API interface). The spatiotemporal anomaly indicator refers to: quantifying the degree of deviation of user behavior from the normal pattern from the time dimension and the space dimension, including time anomaly indicators and space anomaly indicators. This type of indicator can effectively identify distributed proxy pool attacks (such as high-frequency access of multiple IPs across regions) and automated scripts (such as extremely short operation intervals) through the two dimensions of time and space. The illegal reservation indicator refers to: based on the stadium reservation business rules, quantifying the degree to which user behavior violates the preset business logic, such as purchase restrictions, reservation interval restrictions, etc. This type of indicator targets the behavioral characteristics of scalpers hoarding resources and batch operations, and combines business rules for accurate identification, thereby improving the system's scenario business understanding capabilities. Such as Figure 2 As shown in the figure, through the combined effect of the above three indicators, the system can more accurately identify abnormal ticket purchasing behavior.

[0060] In one implementation, the method for calculating the ticket purchase path offset distance includes:

[0061] Performing interface dependency graph analysis based on the basic behavior data to obtain a ticket purchase path corresponding to the ticket purchase request;

[0062] Obtain a standard ticket purchasing path, compare the ticket purchasing path with the standard ticket purchasing path, and obtain the ticket purchasing path offset distance.

[0063] Specifically, this embodiment pre-builds a dependency graph for venue service interfaces and defines a standard ticket purchase path. For example, a standard ticket purchase path sequentially includes the following steps: venue query, time slot selection, time slot lock, and payment confirmation. In actual application scenarios, the purchase path corresponding to the current user's ticket purchase request is analyzed and compared with the standard purchase path. The deviation between the two is calculated to obtain the purchase path offset distance. This offset distance is then used to detect abnormal purchase paths. For example, if the proportion of direct calls to the payment interface exceeds 85%, the path is considered abnormal and marked as high-risk.

[0064] For example, define a function called path_anomaly_detection that accepts a request sequence request_sequence (i.e., the purchase path corresponding to the current user's ticket purchase request) as input. Within this function, set the standard purchase path std_path, which includes the API paths corresponding to the venue query, time slot selection, time slot lock, and payment confirmation steps. Calculate the path offset between the input request sequence request_sequence and the standard purchase path std_path and store the result in the variable ed. Read the path offset threshold config['path_threshold'] from the configuration file. Check whether the calculated path offset ed exceeds this threshold. If so, the request sequence is deemed high risk and a high risk rating of RiskLevel.HIGH is returned. The path offset calculation logic is as follows: The purchase path is deducted from the standard purchase path based on factors such as missing steps, incorrect sequence, and excessive time difference between requests. The path offset is then determined based on the final score. For example, if any request is missing, the value is 0.1; if the order is wrong, the value is 0.1; if the time difference between two requests exceeds 600 seconds, the value is 0.5; and the rest are 1.

[0065] In one implementation, each of the spatiotemporal anomaly indicators includes a geographic location anomaly indicator and a request time anomaly indicator; and a calculation method for each of the spatiotemporal anomaly indicators includes:

[0066] Obtaining the user location sequence and the frequency of request time during non-business hours based on the basic behavior data;

[0067] Calculating the geographic location anomaly index based on the user location sequence;

[0068] The request time anomaly index is calculated according to the frequency of the request time during non-business hours.

[0069] Specifically, basic behavioral data includes location-related data, such as the user's location information (e.g., IP address location) when they initiate a ticket purchase request. Location information is extracted from each ticket purchase request and concatenated chronologically to form a user's location trajectory, resulting in a user location sequence containing a set of IP addresses associated with different requests. By analyzing the rationality of this user location sequence, a geolocation anomaly indicator is generated. For example, a normal user's location sequence should conform to human activity patterns (e.g., slow movement, reasonable location changes within a short period of time, and within the same city). However, an abnormal user's location sequence may involve short-term cross-city migration or frequent, irregular location changes. Secondly, basic behavioral data also includes time-related data, such as the timestamp of each request, which is used to determine whether the request time falls within the target stadium's off-hours. The target stadium's operating schedule is retrieved, and the user's request time is compared with the operating schedule. The total number of requests initiated by the user during off-hours is counted, and the frequency of requests during off-hours is calculated. By analyzing the rationality of the frequency of requests during off-hours, a request time anomaly indicator is generated. For example, a normal user may have a low request frequency during off-hours, while an abnormal user may have a high request frequency, consistent with the 24 / 7 operation of the automated script.

[0070] For example, the spatiotemporal feature anomaly detection is performed on basic behavioral data. The detection dimensions and logic are detailed in Table 1.

[0071] Table 1. Dimensions and logic of spatiotemporal feature anomaly detection

[0072]

[0073] Two requests refer to multiple requests within a ticket purchase, meaning a single ticket purchase may involve multiple requests. High request frequency and frequent switching between accounts may indicate scalpers using scripts to purchase tickets. These scripts typically request venues every second to check for available spots, with high frequency and consistent intervals (per second). Scalpers, driven by a desire to maximize profits, may frequently switch venues using a single account to purchase tickets.

[0074] In one implementation, calculating the geographic location anomaly index based on the user location sequence includes:

[0075] Calculating a moving speed according to the user position sequence, and calculating an abnormal transition index according to the moving speed;

[0076] Performing geo-fence verification based on the user location sequence and the movement speed to obtain an abnormal geographic behavior indicator; the abnormal geographic behavior indicator is used to reflect geographic location jump abnormalities and / or regional association abnormalities;

[0077] The geographic location anomaly index is determined according to the abnormal transition index and the abnormal geographic behavior index.

[0078] Specifically, the geographic location anomaly index in this embodiment includes two indicators: an abnormal transition index and an abnormal geographic behavior index.

[0079] Regarding the abnormal transition index: calculate the distance and time difference between two adjacent points in the user location sequence, and a moving speed can be calculated based on the calculated distance and time difference. The moving speed can be used to detect whether the user has exceeded the speed that cannot be achieved by conventional means of transportation. For example, a moving speed can be calculated from any two adjacent points in the user location sequence, and ultimately multiple moving speeds can be calculated. A speed threshold is set in advance, and the proportion of the number of times that multiple moving speeds exceed the speed threshold is counted. The higher the proportion, the larger the value of the abnormal transition index. Alternatively, the average speed of multiple moving speeds is calculated. The calculated speed average is compared with the historical average speed or the average speed of users of the same type. The greater the deviation, the larger the value of the abnormal transition index.

[0080] Targeting indicators of abnormal geographic behavior: Geofence verification identifies geographic location jump anomalies. For example, by combining user location sequences and movement speed, we check whether users cross geofence boundaries within a short period of time. If a user crosses a geofence when their normal movement speed shouldn't, but does, this is considered a location jump anomaly. Geofence verification can also identify regional association anomalies, such as the same account frequently switching between different city venues. This allows us to analyze whether the user's movement between different geographic regions conforms to normal logic.

[0081] In one implementation, performing geo-fence verification based on the user location sequence and the movement speed to obtain an abnormal geographic behavior indicator includes:

[0082] determining a first-used IP address based on the user location sequence, and determining a geographic area fence based on the first-used IP address and the movement speed;

[0083] Performing spatial cluster analysis based on the user location sequence to obtain resident area identification information;

[0084] Calculating the geographic location jump anomaly index and / or the regional association anomaly index based on the resident area identification information and the geographic area fence;

[0085] The abnormal geographic behavior indicator is obtained according to the geographic location jump abnormality indicator and / or the regional association abnormality indicator.

[0086] Specifically, the abnormal geographic behavior indicator in this embodiment integrates geographic location jump anomalies (such as teleportation) and regional association anomalies (such as the same account frequently switching between different city venues), reflecting the overall abnormality of the user's location behavior. Figure 4 As shown, the IP address used by the user when initiating the ticket purchase request for the first time is determined in the user location sequence, that is, the first-use IP address is obtained, which usually corresponds to the geographical location where the user initially accesses the network. Based on the geographical location corresponding to the first-use IP address and combined with the reasonable movement speed of the user, a reasonable activity range is delineated as a geographical fence. Secondly, a spatial clustering analysis is performed on the user location sequence to identify the resident areas where users frequently appear. By combining the resident areas with geographical fences, obviously unreasonable location jumps are screened out as the benchmark data for calculating the geographical location jump anomaly index; and abnormal regional associations are screened out as the benchmark data for calculating the regional association anomaly index. For example, the same account frequently switches between different city venues, or a combination of areas that normal users rarely visit at the same time (suddenly visiting stadiums in remote areas from stadiums in the city center).

[0087] For example, geofence verification can use the IP address to locate the geographic location of the request. The user's first IP address, combined with a reasonable travel speed, generates a prototype geofence. For example, if the IP address is first located in Guangzhou, a 300-kilometer geofence centered on Guangzhou within one hour is considered reasonable, while anything beyond the geofence is considered unreasonable. Based on the geofence verification results, a risk flag, or indicator of abnormal geographic behavior, is generated: a score of 1-0.1 is assigned based on distance, with further distances resulting in lower scores. Exceeding the range indicates high risk with a score of 0.

[0088] In one implementation, the method for calculating the predetermined violation index includes:

[0089] Obtaining a venue reservation strategy for the target sports venue;

[0090] According to the basic behavior data and the venue reservation strategy, it is determined whether the user has engaged in illegal reservation behavior, and the illegal reservation index is calculated according to the determination result.

[0091] Specifically, the venue reservation policy of the target sports stadium is a fixed business setting, which can be set by the operation staff to regulate user reservation behavior. The venue reservation policy is broken down into several types of quantifiable regulations, such as time rules, quantity restrictions, qualification restrictions, equipment / account restrictions, restrictions on the use of automated tools (the use of scripts or robot programs for reservations is prohibited), etc. For example, within a specified time range, only one venue can be snapped up and reserved. By comparing the user's basic behavior data with the various regulations in the venue reservation policy, the number of users violating the rules is counted, and the violation reservation index is calculated.

[0092] For example, Figure 3 As shown in the example, for a venue list query, association rule 1 is "Details View to Order Ratio < 1:5." The Details View to Order Ratio refers to the ratio of venue views to venue orders. Scalpers are known for their ability to view venues and then place an order. The detection dimension for Rule 1 is venue reservation strategy.

[0093] View venue details: Then proceed to the time slot availability check. Time slot availability check: Associate rule 2, "Time slot check interval < 200ms," with the exception of an abnormally high frequency of calls. The detection dimension for rule 2 is: geographic location jump.

[0094] Add to pre-selected list: Then enter the order submission stage. Submit order: Associate rule 3 "Non-open period order" and "Non-business hours call" situation. The corresponding detection dimension of rule 3 is: non-business operation.

[0095] Comprehensive characteristic indicator judgment: If "details / order ratio = 1:8.3", "time period inspection interval = 175ms", and "non-open time period accounts for 92%", it is determined to be a machine attack (typical abnormal pattern), identifying abnormal behaviors such as scalping ticket purchases, and enabling the stadium ticket purchasing system to accurately distinguish between normal users and abnormal attacks.

[0096] Step S300: Perform risk decision based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the predetermined violation indicator, and determine a processing method for the ticket purchase request based on the risk decision result.

[0097] Specifically, this embodiment uses the purchase path deviation distance, multiple spatiotemporal anomaly indicators, and illegal reservation indicators to make comprehensive risk decisions. If the path deviation is large, spatiotemporal anomalies are present, and there are illegal reservations, the purchase request may be directly blocked. If all indicators are normal or the risk is low, the purchase is allowed. This approach accurately distinguishes legitimate users from anomalous attacks, ensuring the fairness and stability of the ticket purchase system.

[0098] In one implementation, a risk decision is made based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the predetermined violation indicator, and a processing method for the ticket purchase request is determined based on the risk decision result, including:

[0099] Obtaining the risk value of the user by weighted fusion based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the violation reservation indicator;

[0100] The risk level of the user is determined according to the risk value, and the processing method of the ticket purchase request is determined according to the risk level; wherein, if the risk level is less than a preset level, the ticket purchase request is released.

[0101] Specifically, if Figure 5 As shown in the figure, after scoring the indicators of various dimensions, different weight values are assigned to the ticket purchase path offset distance, various spatiotemporal anomaly indicators, and illegal reservation indicators, and a comprehensive risk value is obtained through weighted calculation. In actual application scenarios, the risk level intervals can be pre-divided (for example, according to different numerical intervals, divided into low risk, medium risk, and high risk). According to the currently calculated risk value combined with the divided risk level intervals, the risk level corresponding to the current user is determined. Figure 2 As shown, if the risk level is less than the preset level (for example, the preset risk is medium, and the low risk meets the conditions), it is judged to be relatively safe, the ticket purchase request is released, and normal ticket purchase is allowed; if it is greater than or equal to the preset level (such as medium or high risk), interception and other restrictive measures are taken.

[0102] For example, a rule engine for multi-dimensional correlation warning is pre-built. The engine calculates the risk value through the algorithm in the decision matrix:

[0103] RiskScore=α·S_{path}+β·S_{geo}+γ·S_{time}+δ·S_{policy};

[0104] Among them, RiskScore is the risk value; S_{path} is the path deviation score (normalized to 0-1); S_{geo} is the geographical location anomaly index; S_{time} is the activity during non-business hours; S_{policy} is the degree of violation of venue policy (such as the maximum number of reservations for a single account); α, β, γ, and δ are weight values respectively.

[0105] Based on the above embodiments, the present invention also provides a stadium request analysis system based on multi-dimensional behavior analysis, such as Figure 6 As shown, the system includes:

[0106] Request acquisition module 01, used to obtain a ticket purchase request initiated by a user for a specific venue area in a target stadium, and extract the basic behavior data of the user based on the ticket purchase request;

[0107] Behavior analysis module 02, used to calculate the ticket purchase path deviation distance, several spatiotemporal anomaly indicators and illegal reservation indicators based on the basic behavior data;

[0108] The risk decision module 03 is used to make a risk decision based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators and the violation predetermined indicator, and determine the processing method of the ticket purchase request according to the risk decision result.

[0109] Based on the above embodiment, the present invention further provides a terminal, whose principle block diagram can be shown as follows: Figure 7As shown. The terminal includes a processor, memory, network interface, and display screen connected via a system bus. The processor of the terminal is used to provide computing and control capabilities. The memory of the terminal includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the terminal is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements a stadium request analysis method based on multi-dimensional behavior analysis. The display screen of the terminal can be a liquid crystal display or an electronic ink display.

[0110] Those skilled in the art will understand that Figure 7 The principle block diagram shown in the figure is only a block diagram of a partial structure related to the solution of the present invention, and does not constitute a limitation on the terminal to which the solution of the present invention is applied. The specific terminal may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0111] In one implementation, the terminal has one or more programs stored in its memory and is configured to be executed by one or more processors. The one or more programs include instructions for performing a stadium request analysis method based on multi-dimensional behavior analysis.

[0112] Those skilled in the art will appreciate that all or part of the processes in the above-described embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the above-described embodiments. Among them, any reference to memory, storage, database or other media used in the embodiments provided by the present invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct RAM bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM).

[0113] In summary, the present invention discloses a method and system for analyzing stadium requests based on multi-dimensional behavioral analysis. The method comprises: obtaining a ticket purchase request initiated by a user for a specific venue area within a target stadium, extracting the basic behavioral data of the user based on the ticket purchase request; calculating the ticket purchase path offset distance, several spatiotemporal anomaly indicators, and a predetermined violation indicator based on the basic behavioral data; making a risk decision based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the predetermined violation indicator, and determining the processing method of the ticket purchase request based on the risk decision result. The present invention avoids the limitations of a single indicator through multi-dimensional behavioral analysis such as path offset, spatiotemporal characteristics, and violation patterns. Moreover, the multi-dimensional behavioral analysis of the present invention is closely integrated with the business logic of the stadium, deeply understanding the normal behavioral logic of users in the reservation scenario, thereby accurately distinguishing normal users from abnormal attacks. In addition, the present invention makes risk decisions based on multiple dynamic indicators calculated in real time, which can quickly respond to new attack methods of scalpers, effectively solving the problems of detection blind spots and insufficient adaptability of traditional solutions in high-concurrency rush buying scenarios.

[0114] It should be understood that the application of the present invention is not limited to the above examples. For those skilled in the art, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.

Claims

1. A stadium request analysis method based on multi-dimensional behavior analysis, characterized in that: The method comprises: Obtaining a ticket purchase request initiated by a user for a specific venue area within a target sports stadium, and extracting basic behavior data of the user based on the ticket purchase request; Calculate the ticket purchase path deviation distance, several spatiotemporal anomaly indicators, and illegal reservation indicators based on the basic behavior data; A risk decision is made based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the predetermined violation indicator, and a processing method for the ticket purchase request is determined based on the risk decision result.

2. The stadium request analysis method based on multi-dimensional behavior analysis according to claim 1 is characterized in that: The method for calculating the ticket purchase path offset distance includes: Performing interface dependency graph analysis based on the basic behavior data to obtain a ticket purchase path corresponding to the ticket purchase request; Obtain a standard ticket purchasing path, compare the ticket purchasing path with the standard ticket purchasing path, and obtain the ticket purchasing path offset distance.

3. The stadium request analysis method based on multi-dimensional behavior analysis according to claim 1 is characterized in that: Each of the spatiotemporal anomaly indicators includes a geographic location anomaly indicator and a request time anomaly indicator; The calculation method of each of the spatiotemporal anomaly indicators includes: Obtaining the user location sequence and the frequency of request time during non-business hours based on the basic behavior data; Calculating the geographic location anomaly index based on the user location sequence; The request time anomaly index is calculated according to the frequency of the request time during non-business hours.

4. The method for analyzing stadium requests based on multi-dimensional behavior analysis according to claim 3 is characterized in that: Calculating the geographic location anomaly index according to the user location sequence includes: Calculating a moving speed according to the user position sequence, and calculating an abnormal transition index according to the moving speed; Performing geo-fence verification based on the user location sequence and the movement speed to obtain an abnormal geographic behavior indicator; the abnormal geographic behavior indicator is used to reflect geographic location jump abnormalities and / or regional association abnormalities; The geographic location anomaly index is determined according to the abnormal transition index and the abnormal geographic behavior index.

5. The method for analyzing stadium requests based on multi-dimensional behavior analysis according to claim 4 is characterized in that: Performing geo-fence verification based on the user location sequence and the movement speed to obtain abnormal geographic behavior indicators, including: determining a first-used IP address based on the user location sequence, and determining a geographic area fence based on the first-used IP address and the movement speed; Performing spatial cluster analysis based on the user location sequence to obtain resident area identification information; Calculating the geographic location jump anomaly index and / or the regional association anomaly index based on the resident area identification information and the geographic area fence; The abnormal geographic behavior indicator is obtained according to the geographic location jump abnormality indicator and / or the regional association abnormality indicator.

6. The method for analyzing stadium requests based on multi-dimensional behavior analysis according to claim 1, characterized in that: The calculation method of the predetermined violation index includes: Obtaining a venue reservation strategy for the target sports venue; According to the basic behavior data and the venue reservation strategy, it is determined whether the user has engaged in illegal reservation behavior, and the illegal reservation index is calculated according to the determination result.

7. The stadium request analysis method based on multi-dimensional behavior analysis according to claim 1 is characterized in that: Performing a risk decision based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the violation schedule indicator, and determining a processing method for the ticket purchase request based on the risk decision result, including: Obtaining the risk value of the user by weighted fusion based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators, and the violation reservation indicator; The risk level of the user is determined according to the risk value, and the processing method of the ticket purchase request is determined according to the risk level; wherein, if the risk level is less than a preset level, the ticket purchase request is released.

8. A stadium request analysis system based on multi-dimensional behavior analysis, characterized in that: The system comprises: A request acquisition module is used to acquire a ticket purchase request initiated by a user for a specific venue area in a target stadium, and extract the basic behavior data of the user based on the ticket purchase request; A behavior analysis module, configured to calculate the ticket purchase path offset distance, several spatiotemporal anomaly indicators, and illegal reservation indicators based on the basic behavior data; The risk decision module is used to make a risk decision based on the ticket purchase path offset distance, each of the spatiotemporal anomaly indicators and the violation predetermined indicator, and determine the processing method of the ticket purchase request according to the risk decision result.

9. A terminal, characterized in that: The terminal includes a memory and one or more processors; the memory stores one or more programs; the programs include instructions for executing the stadium request analysis method based on multi-dimensional behavioral analysis as described in any one of claims 1-7; and the processor is used to execute the programs.

10. A computer-readable storage medium having a plurality of instructions stored thereon, characterized in that: The instructions are suitable for being loaded and executed by a processor to implement the steps of the stadium request analysis method based on multi-dimensional behavior analysis as described in any one of claims 1-7.