Risk management and control method and device, storage medium and computer equipment
By obtaining asynchronous data of the target application and performing policy link processing, combining user profiles and risk control rules, differentiated control of high-risk users is solved, and the problems of high manual control costs and illegal missed in the existing technology are solved, achieving efficient risk control and immediate disposal.
Patent Information
- Application Number
- CN202510588651.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, when risk control of high-risk, high-exposure, frequent and multiple violations, people mainly rely on manual methods, resulting in high control costs and prone to missed violations.
By obtaining asynchronous data in the target application, determining the policy link for processing, and when the patrol conditions for active patrol tasks are met, the target user is comprehensively evaluated and punished, and differentiated processing is carried out in combination with user portraits and risk control rules.
It improves the efficiency of risk control, improves user experience, ensures effective handling of illegal content and subject behavior, avoids the missed illegality, and realizes instant capture and governance.
Smart Images

Figure CN120455077A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of risk control and security technology, and in particular to a risk control method, apparatus, storage medium, and computer equipment. Background Art
[0002] With the rapid development of the internet, the number and gameplay of social voice apps are increasing. As the volume of these apps grows, so too are the user groups prone to generating illegal information. These high-risk, highly exposed, and frequent offenders not only impact the experience of regular platform users but can also lead to the loss of high-paying, high-value users, further impacting the platform's ecological security. Therefore, platforms need to identify these high-risk, highly exposed, and frequent offenders and take appropriate action to maintain the platform's ecological security and enhance the user experience.
[0003] At present, risk control for high-risk, highly exposed, and frequently violating groups is mainly achieved through manual control, and the control method is relatively simple, which leads to high control costs and the possibility of violations being missed. Summary of the Invention
[0004] The purpose of this application is to solve at least one of the above-mentioned technical defects, especially the technical defects that in the existing technology, when risk control is carried out on people with high risks, high exposure, and frequent violations, it is mainly achieved through manual control, and the control method is relatively simple, which leads to high control costs and the possibility of violations being missed.
[0005] This application provides a risk management method, which includes:
[0006] Obtain asynchronous data generated by a target user in at least one risk control list of a target application in the target application;
[0007] Determining a policy link corresponding to the asynchronous data, and processing the asynchronous data according to the policy link to obtain a data processing result;
[0008] When the asynchronous data and / or the data processing result meets the inspection conditions configured for the active inspection task being executed, a comprehensive evaluation is performed on the relevant information of the target user, and when it is determined that the target user has violated the rules based on the comprehensive evaluation result, the target user is punished.
[0009] Optionally, before obtaining the asynchronous data generated by the target user in the risk control list of the target application in the target application, the method further includes:
[0010] Obtain historical data generated by each user in the target application within a preset time period;
[0011] Based on the historical data of each user, target users who meet the risk control conditions are screened out from each user, and a risk control list corresponding to the target users is formed.
[0012] Optionally, the method of screening target users that meet risk control conditions from various users based on historical data of various users and forming a risk control list corresponding to the target users includes:
[0013] Generate user profiles for each user based on their historical data;
[0014] The user profile of each user is matched with a pre-configured risk control rule set, and a risk control list is determined based on a first matching result, wherein the risk control rule set includes user attribute rules, user behavior rules, and behavior sequence rules.
[0015] Optionally, each user's historical data includes record tables of multiple dimensions;
[0016] Generating a user profile of each user based on the historical data of each user includes:
[0017] For each user:
[0018] Clean the record tables of each dimension of the user according to the pre-configured meta-event table and event attribute table to form an event table corresponding to the user;
[0019] Determine the user attribute corresponding to the user according to the pre-configured user attribute table;
[0020] Generate a user profile for the user based on the user's event table and user attributes.
[0021] Optionally, determining a policy link corresponding to the asynchronous data, and processing the asynchronous data according to the policy link to obtain a data processing result includes:
[0022] Determining a target policy corresponding to the asynchronous data and a plurality of policy condition groups pre-configured in the target policy;
[0023] Matching the asynchronous data with each policy condition group respectively, and determining a target condition group corresponding to the asynchronous data according to the second matching result;
[0024] The asynchronous data is processed according to the policy link of the target condition group to obtain a data processing result.
[0025] Optionally, determining a target policy corresponding to the asynchronous data and a plurality of policy condition groups preconfigured in the target policy includes:
[0026] The asynchronous data is matched with a plurality of enabled and approved policies pre-configured in a policy center, and a target policy corresponding to the asynchronous data and a plurality of policy condition groups pre-configured in the target policy are determined according to a third matching result.
[0027] Optionally, the determining whether the asynchronous data and / or the data processing result meets the inspection condition configured for the active inspection task being executed includes:
[0028] Determining an active patrol strategy associated with the active patrol task being executed, and determining patrol conditions configured for the active patrol strategy;
[0029] The asynchronous data and / or the data processing result are matched with the inspection condition, and it is determined whether the asynchronous data and / or the data processing result meet the inspection condition according to a fourth matching result.
[0030] Optionally, the relevant information includes at least subject information, real-time interactive content, and subject attributes of the target user;
[0031] The comprehensive evaluation of the relevant information of the target user to obtain a comprehensive evaluation result includes:
[0032] The subject information, real-time interactive content and subject attributes of the target user are evaluated respectively through a plurality of pre-set risk assessment mechanisms, and the comprehensive assessment results are obtained after reviewing the assessment results.
[0033] This application also provides a risk management device, including:
[0034] A data acquisition module, configured to acquire asynchronous data generated by a target user in at least one risk control list of a target application in the target application;
[0035] a data processing module, configured to determine a policy link corresponding to the asynchronous data, and process the asynchronous data according to the policy link to obtain a data processing result;
[0036] The violation penalty module is used to conduct a comprehensive evaluation of the relevant information of the target user when the asynchronous data and / or the data processing results meet the inspection conditions configured for the active inspection task being executed, and to punish the target user when it is determined that the target user has violated the regulations based on the comprehensive evaluation results.
[0037] The present application also provides a computer-readable storage medium, which stores computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the risk management method described in any of the above embodiments.
[0038] The present application also provides a computer device, comprising: one or more processors, and a memory;
[0039] The memory stores computer-readable instructions, and when the computer-readable instructions are executed by the one or more processors, the steps of the risk management method described in any one of the above embodiments are performed.
[0040] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0041] The risk management method, device, storage medium and computer equipment provided by the present application, when obtaining asynchronous data generated by a target user in at least one risk control list of the target application in the target application, can first determine the policy link corresponding to the asynchronous data, and then process the asynchronous data according to the policy link to obtain the data processing result; in this process, the present application sets differentiated processing strategies for different asynchronous data, so that it can improve the risk management efficiency while improving the user experience, and the present application also decouples the timing dependency by processing asynchronous data, thereby further optimizing the risk management efficiency; in addition, when the asynchronous data and / or data processing results in the present application meet the inspection conditions configured for the active inspection task being executed, the relevant information of the target user can also be comprehensively evaluated, and when it is determined that the target user has violated the rules based on the comprehensive evaluation results, the target user is punished, so that it can ensure that the illegal content generated by the subject and the illegal behavior of the subject itself can be effectively dealt with, thereby effectively preventing the illegal content and the illegal subject from being exposed, realizing the real-time capture and governance of the subject's risk behavior, and avoiding the omission of violations. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0043] Figure 1 A flow chart of a risk management method provided in an embodiment of the present application;
[0044] Figure 2 A diagram showing the configuration page of the risk control rule set provided in an embodiment of the present application;
[0045] Figure 3 A schematic diagram of the historical data cleaning process provided in an embodiment of the present application;
[0046] Figure 4 A schematic diagram of the user portrait calculation process provided in an embodiment of the present application;
[0047] Figure 5 This is a diagram showing the meta-event configuration page provided in the embodiment of the present application;
[0048] Figure 6 This is a diagram showing the event attribute configuration page provided in the embodiment of the present application;
[0049] Figure 7 This is a diagram showing the user attribute configuration page provided in the embodiment of the present application;
[0050] Figure 8 User portrait-business architecture diagram provided for the embodiment of this application;
[0051] Figure 9 Schematic diagram of the policy management page provided in this embodiment of the application;
[0052] Figure 10 This is a diagram showing one of the policy configuration pages provided in an embodiment of the present application;
[0053] Figure 11 Another policy configuration page display diagram provided in an embodiment of the present application;
[0054] Figure 12 A schematic diagram of the configuration page for the active inspection task provided in an embodiment of the present application;
[0055] Figure 13 A diagram showing the inspection condition configuration page provided in an embodiment of the present application;
[0056] Figure 14 This is a page display diagram of the active inspection workbench provided in an embodiment of the present application;
[0057] Figure 15 A schematic diagram of the structure of a risk management device provided in an embodiment of the present application;
[0058] Figure 16 A schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0059] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0060] In one embodiment, Figure 1 As shown, Figure 1 A schematic diagram of a risk management method provided in an embodiment of the present application; the present application provides a risk management method, which may include:
[0061] S110: Acquire asynchronous data generated in a target application by a target user in at least one risk control list of the target application.
[0062] In this step, when risk control is performed on the high-risk, high-exposure, and frequent and multiple-violation groups in the target application, the risk control list of the target application can be obtained. Since the group portrait corresponding to the user group in the risk control list is a subject portrait covering various characteristics formed after multi-dimensional data evaluation, the target users in the risk control list are one or more of the above-mentioned high-risk, high-exposure, and frequent and multiple-violation groups. This application can monitor the data generated by the target users in the risk control list and the target user subjects, thereby ensuring that the illegal content generated by the subjects and the illegal behavior of the subjects themselves can be effectively handled.
[0063] Furthermore, the target application's risk control list in this application can be one or more lists, with the target users on each list corresponding to one or more categories of people with high-risk characteristics, such as user attributes, user behaviors, and behavior sequences that meet violation criteria. Therefore, after obtaining at least one risk control list for a target application, this application can obtain the asynchronous data generated by the target users on that list in the target application, allowing for appropriate processing of the target users and the asynchronous data generated by them.
[0064] Furthermore, in order to decouple timing dependencies and further optimize risk management efficiency, this application can obtain asynchronous data when acquiring relevant data generated by the target user in the target application. The core feature of this asynchronous data is non-blocking: the sender does not need to wait for the receiver's response after sending the data, and can continue to perform other tasks, while the receiver processes the data when it is ready. Among them, the asynchronous data acquired by this application mainly refers to the data content generated by the subject in the target application, such as the user's nickname, user signature, user avatar, user album, square posting, or the room's public screen message, room name, room welcome, room topic, room topic content, etc. The specific data content acquired and the data generation period can be set according to the actual situation and are not restricted here.
[0065] S120: Determine a policy link corresponding to the asynchronous data, and process the asynchronous data according to the policy link to obtain a data processing result.
[0066] In this step, after obtaining the asynchronous data generated by the target user in at least one risk control list of the target application in the target application through S110, the present application can also determine the policy link corresponding to the asynchronous data, and process the asynchronous data according to the policy link to obtain the final data processing result.
[0067] It is understandable that in order to carry out differentiated treatment of asynchronous data generated by different target users, this application can pre-set different policy links for different business scenarios. The policy link refers to the data processing flow when processing the asynchronous data. Different asynchronous data corresponds to different policy links, which can be set according to application, subject type, audit scenario, policy type, risk control list and other conditions. After the setting is completed, the platform will carry out layered treatment with different intensities for different applications, different scenarios, different risk control list users, and set conditions. For example, when it is identified that the message sent by the user on the risk control list A in the voice live broadcast platform hits a certain violation label in the room, the room message of this user can be checked according to the corresponding policy link.
[0068] Furthermore, when different asynchronous data in this application are processed according to the corresponding policy links, the data processing results obtained may be the same or different. Among them, the data processing results of this application include but are not limited to machine review passed, machine review failed, assigned human review, simulated human review and marking, suspected risk, simulated human review passed, retrieval, human review passed, human review marked, etc. Specifically, "machine review passed" and "human review passed" refer to sending a "PASS" result to the business application, indicating that the content can be released; "machine review failed" refers to sending a "REJECT" result to the business application, indicating that the content is blocked and cannot be released; "human review assignment" refers to assigning the content to a reviewer for review, and selecting the corresponding review round, review mode, and corresponding review role. When there are multiple review roles, the assigned weight ratio can be configured, and multi-role weight ratio allocation is supported; "simulated human review labeling" refers to selecting the human review label configuration, the system simulates human review labeling, and sends the human review labeling results to the business application, which then blocks the content; "human review labeling" refers to labeling the data by the reviewer and sending it to the business application, which then blocks the content; "suspected risk" refers to sending a "REVIEW" result to the business application, which blocks the content and cannot be released; "simulated human review passed" refers to sending the human review pass result to the business application, which then releases the content; "recall" refers to querying the data that has passed the machine review but not pushed for human review in the specified scenario based on the ID of the risk control list and the business scenario, and then recalling it for human review. This application processes different asynchronous data differently and outputs the same or different data processing results, which can not only improve the accuracy of data processing but also avoid illegal omissions.
[0069] S130: When the asynchronous data and / or data processing results meet the inspection conditions configured for the active inspection task being executed, a comprehensive evaluation is performed on the relevant information of the target user, and when it is determined that the target user has violated the regulations based on the comprehensive evaluation results, the target user is punished.
[0070] In this step, the policy link corresponding to the asynchronous data is determined through S120, and the asynchronous data is processed according to the policy link. After obtaining the data processing result, it can also be judged whether the asynchronous data and / or the data processing result meet the inspection conditions configured for the active inspection task being executed. If so, the relevant information of the target user can be comprehensively evaluated, and when it is determined that the target user has violated the rules based on the comprehensive evaluation results, the target user will be punished.
[0071] Specifically, this application can not only perform differentiated processing on the asynchronous data of the target user, but also create active patrol tasks and set the task execution time of the active patrol tasks. In this way, when the platform monitors the active patrol task being executed, it can compare the asynchronous data and / or data processing results of the target user with the patrol conditions configured for the active patrol task. If the asynchronous data and / or data processing results meet the patrol conditions configured for the active patrol task being executed, the relevant information of the target user can be obtained and the relevant information can be comprehensively evaluated to determine whether the target user has violated the rules. If it is determined that the target user has violated the rules, the target user can be punished to ensure that the illegal content generated by the subject and the illegal behavior of the subject itself can be effectively dealt with.
[0072] It is understandable that in order to improve the control and management strength and scope of users who violate regulations, this application can pre-create active patrol tasks and configure the execution time and patrol conditions of active patrol tasks. The patrol conditions can be set with risk control lists, subject types, review scenarios, asynchronous text keywords, historical machine review violations, historical human review violations and other conditions. Active patrol tasks can set tasks for specified time periods and cyclic periods to facilitate dealing with various situations. For example, this application can set an active patrol task that is executed on May 17, 2025. If a user who meets the risk control list A sends a message in the room and hits the patrol conditions configured by the active patrol task, the subject can be patrolled and monitored. If there is a violation, it will be dealt with, so as to achieve real-time capture and governance of the subject's risky behavior.
[0073] In the above embodiment, when the asynchronous data generated by the target user in at least one risk control list of the target application in the target application is obtained, the policy link corresponding to the asynchronous data can be determined first, and then the asynchronous data can be processed according to the policy link to obtain the data processing result; in this process, the present application sets differentiated processing strategies for different asynchronous data, so that it can improve the risk control efficiency while improving the user experience, and the present application also decouples the timing dependency by processing asynchronous data, thereby further optimizing the risk control efficiency; in addition, when the asynchronous data and / or data processing results in the present application meet the inspection conditions configured for the active inspection task being executed, the relevant information of the target user can also be comprehensively evaluated, and when it is determined that the target user has violated the rules based on the comprehensive evaluation results, the target user can be punished, so that it can ensure that the illegal content generated by the subject and the illegal behavior of the subject itself can be effectively dealt with, thereby effectively preventing the illegal content and the illegal subject from being exposed, realizing the real-time capture and governance of the subject's risky behavior, and avoiding the omission of violations.
[0074] In one embodiment, before obtaining the asynchronous data generated by the target user in the risk control list of the target application in S110, the following steps may also be included:
[0075] S101: Acquire historical data generated by each user in a target application within a preset time period.
[0076] S102: Based on the historical data of each user, target users that meet the risk control conditions are screened out from each user, and a risk control list corresponding to the target users is formed.
[0077] In this embodiment, before obtaining the asynchronous data generated by the target users in the risk control list of the target application in the target application, the present application can also obtain the historical data generated by each user in the target application within a preset time period, and based on the historical data generated by each user, screen out the target users who meet the risk control conditions from each user, and form a risk control list corresponding to the risk control conditions in turn.
[0078] Among them, when obtaining the historical data generated by each user in the target application within a preset time period, the present application can collect various behavioral data generated by the subject in the target application, such as user entry into the room, user microphone, user recharge, user nickname modification and other behavioral data, and can also collect content data generated by the subject, such as room public screen messages sent by users, IM chat data, modified specific nickname content, modified room name content, etc. After the present application collects the historical data generated by each user, it can clean and calculate the collected historical data according to certain rules, and use users who meet the risk control conditions as target users. For example, the present application can classify user groups that meet the pre-configured set of rules for user attributes, user behaviors, and behavior sequences, and generate corresponding user group portraits, so that users who meet the user group portrait among the users whose historical data are collected can be used as target users in the risk control list.
[0079] In one embodiment, in S102, based on the historical data of each user, target users meeting the risk control conditions are screened out from each user, and a risk control list corresponding to the target users is formed, which may include:
[0080] S1021: Generate a user profile for each user based on the historical data of each user.
[0081] S1022: Match the user profile of each user with a pre-configured risk control rule set, and determine a risk control list based on a first matching result, wherein the risk control rule set includes user attribute rules, user behavior rules, and behavior sequence rules.
[0082] In this embodiment, when constructing a risk control list based on the historical data of each user, a user portrait of each user can be generated based on the historical data of each user, and then the user portrait of each user can be matched with a pre-configured risk control rule set, and the risk control list can be determined based on the first matching result. The target users in the risk control list are the user groups that meet the risk control rule set.
[0083] Specifically, this application can generate a corresponding user portrait based on the historical data of each user. The user portrait is a single user portrait. Then, this application can also generate a corresponding user group portrait based on a pre-configured risk control rule set, so that the single user portrait can be matched with the user group portrait. If the single user portrait matches the user group portrait, it means that the user corresponding to the single user portrait is the target user in the risk control list.
[0084] Schematically, as Figure 2 As shown, Figure 2 This is a diagram showing the configuration page of the risk control rule set provided in the embodiment of this application, Figure 2 It can be seen that the risk control rule set of this application may include user attribute rules, user behavior rules, and behavior sequence rules. Among them, the user attribute rules of this application refer to the attribute information corresponding to the users entering the risk control list, and the attribute information includes but is not limited to user ID, membership level, account status (active / silent / churned), IP address, place of residence, gender, age, etc.; the user behavior rules of this application refer to the behavior corresponding to the users entering the risk control list, and the behavior includes but is not limited to the number of penalties imposed on the subject, the number of historical violations, the level of historical violations, etc.; the behavior sequence rules of this application refer to the behavior sequence corresponding to the users entering the risk control list, and the behavior sequence includes but is not limited to the time period of the subject penalty, the time period of historical violations, etc., which can be set according to the actual situation and are not limited here.
[0085] In one embodiment, the historical data of each user includes a record table of multiple dimensions; generating a user profile of each user based on the historical data of each user in S1021 may include:
[0086] For each user:
[0087] S10211: Clean the record tables of each dimension of the user according to the pre-configured meta-event table and event attribute table to form an event table corresponding to the user.
[0088] S10212: Determine the user attributes corresponding to the user according to the pre-configured user attribute table.
[0089] S10213: Generate a user profile of the user based on the event table and user attributes of the user.
[0090] In this embodiment, when generating a user portrait of each user, the historical data of each user may be cleaned first, and then the cleaned historical data may be calculated to generate a user portrait corresponding to each user.
[0091] Schematically, as Figure 3 As shown, Figure 3 A schematic diagram of the historical data cleaning process provided in an embodiment of the present application; Figure 3 In this application, the historical data of each user can be in the form of a record table of multiple dimensions, which includes but is not limited to human review records, machine review records, user microphone entry and exit records, user room entry and exit records, etc. This application can clean the record table of each dimension of the user according to the pre-configured meta-event table and event attribute table, thereby generating corresponding configured meta-events and event attributes. This application can aggregate these meta-events and event attributes into an event table sorted according to user dimensions and time dimensions, which can facilitate the classification and management of data, and also improve the readability and operability of the data.
[0092] Further, if Figure 4 As shown, Figure 4 Schematic diagram of the calculation process of the user portrait provided in the embodiment of this application; this application is as follows Figure 3 After the cleaning process shown cleans the historical data, an event table corresponding to the user's behavior and behavior attributes can be obtained. Then, the present application can determine the user attributes corresponding to the user based on the pre-configured user attribute table, so that a user profile of the user can be generated based on the user's event table and user attributes.
[0093] Among them, such as Figure 5 、 6 ,7, Figure 5 This is a diagram showing the meta-event configuration page provided in the embodiment of this application. Figure 6 This is a diagram showing the event attribute configuration page provided in the embodiment of this application. Figure 7 This is a diagram showing the user attribute configuration page provided in the embodiment of the present application; Figure 5 In this application, the meta-event can be configured according to the application, subject type, event display name, event name, triggering time, and binding corresponding event attributes, and form a meta-event table together with other meta-events. Then, according to the meta-event configured on the page, the data that meets the rules is cleaned from the historical data and stored in the event table corresponding to the record. Figure 6 In this application, the event attributes can be configured according to the application, subject type, attribute display name, attribute name, data type, whether it is set as a public attribute, unit / format, and associated with the corresponding meta-event. Figure 7In this application, the user attributes can also be configured according to the application, subject type, attribute display name, attribute name, data type, whether it is set as a public attribute, and unit / format, and a corresponding user attribute table is formed to determine the user attributes of each user.
[0094] Furthermore, the present application can be Figure 8 The business architecture diagram shown above is used to realize the generation process of the above user portraits. Figure 8 The overall architecture of this application can be divided into five layers, as follows:
[0095] 1. Access layer: This layer receives raw data and processes it, including using Kafka, Tidb, Clickhouse, files, etc.
[0096] 2. Computing layer: This layer uses Flink as the real-time computing framework to clean and correlate real-time data.
[0097] 3. Storage layer: After cleaning, this layer stores the data in different storage media, including Redis, ES, Tidb, Clickhouse, Mongo, etc., to support the construction of real-time user portrait models and data query requirements for multiple application scenarios.
[0098] 4. Service layer: This layer provides unified data query services and supports multi-dimensional calculations from underlying detailed data to aggregated layer data, so that external users can quickly obtain the required data information.
[0099] 5. Application layer: This layer uses unified query services to support the data needs of various business lines, mainly including user individual profiles, user group profiles, user grouping and other data.
[0100] Through the above-mentioned business architecture, this application can quickly clean and calculate historical data, and form corresponding user individual portraits and user group portraits, and then quickly form a corresponding risk control list.
[0101] In one embodiment, determining the policy link corresponding to the asynchronous data in S120 and processing the asynchronous data according to the policy link to obtain a data processing result may include:
[0102] S121: Determine a target policy corresponding to the asynchronous data and a plurality of policy condition groups pre-configured in the target policy.
[0103] S122: Match the asynchronous data with each policy condition group respectively, and determine a target condition group corresponding to the asynchronous data according to the second matching result.
[0104] S123: Process the asynchronous data according to the policy link of the target condition group to obtain a data processing result.
[0105] In this embodiment, when determining the policy link corresponding to asynchronous data, the present application can first determine the target policy corresponding to the asynchronous data and multiple policy condition groups pre-configured in the target policy, so that the asynchronous data can be matched with each policy condition group, and the target condition group corresponding to the asynchronous data can be determined based on the second matching result. Then, the present application can process the asynchronous data according to the policy link of the target condition group to obtain the corresponding data processing result.
[0106] Schematically, as Figure 9 As shown, Figure 9 Schematic diagram of the policy management page provided in the embodiment of this application; Figure 9 It can be seen that this application can pre-configure multiple policies by adding, deleting, modifying, copying, etc. Each policy includes but is not limited to the policy name, policy ID, policy attributes, policy type, application to which it belongs, subject type, audit scenario, etc. Moreover, in the process of configuring policies, each time a policy is modified, a new version of the policy will be added. At this point, this application can obtain policies of multiple types and different versions of each type. When asynchronous data needs to be processed, the asynchronous data can be matched with multiple policies to determine the target policy that matches the asynchronous data.
[0107] Furthermore, the present application can also configure a corresponding policy condition group for each policy, each policy includes at least two policy condition groups, and each policy condition group corresponds to the same or different policy links, so that the asynchronous data can be further matched with each policy condition group under the target policy, and the target condition group corresponding to the asynchronous data is determined based on the second matching result, and the asynchronous data is processed according to the policy link of the target condition group, and finally the corresponding data processing result can be obtained. The present application performs differentiated processing on different asynchronous data and outputs the same or different data processing results, which can not only improve the accuracy of data processing, but also avoid the phenomenon of illegal omissions.
[0108] In one embodiment, determining the target policy corresponding to the asynchronous data and the plurality of policy condition groups pre-configured in the target policy in S121 may include:
[0109] S1211: Match the asynchronous data with multiple enabled and approved policies pre-configured in the policy center, and determine the target policy corresponding to the asynchronous data and multiple policy condition groups pre-configured in the target policy based on the third matching result.
[0110] In this embodiment, since a new version of the policy will be added to the policy center every time the user modifies a policy, when there are too many policies configured in this application, this application can enable or delete different versions of policies according to actual needs. At the same time, this application can also approve the enabled policies, so as to ensure that there are no abnormalities in the policy configuration process, and after approval at all levels, the security of production configuration can also be guaranteed.
[0111] Based on this, when this application obtains the asynchronous data generated by the target user in the target application, it can match the asynchronous data with multiple enabled and approved policies pre-configured in the policy center, and obtain a third matching result. The third matching result indicates that the policy currently matching the asynchronous data is the target policy. Since this application pre-configures the corresponding policy condition group for each policy, when this application determines the target policy, it can determine multiple policy condition groups corresponding to the target policy. In this way, the policy condition group can be used to determine the policy link corresponding to the asynchronous data, and the policy link can be used to process the asynchronous data, thereby achieving differentiated handling.
[0112] Schematically, as Figure 10 、 11 As shown, Figure 10 This is a diagram showing one of the policy configuration pages provided in the embodiment of this application. Figure 11 Another policy configuration page display diagram provided in the embodiment of the present application; Figure 10 and Figure 11 As can be seen, the policy condition groups of this application can include a default group and at least one condition group. Each condition group contains at least one policy condition, including but not limited to user ID, room ID, guild ID, group ID, historical violation level, historical violation tag, room tab, vest package, room gameplay, user attributes, room type, risk control list (user profile), etc. When a condition group sets multiple policy conditions, each policy condition must be met before the policy link corresponding to the condition group will be executed.
[0113] It is understandable that the purpose of setting up conditional groups in this application is to enrich the flexibility of the policy, meet the policy requirements of special processing logic for review work orders with the same content but different conditions, and achieve independent isolation of events for the review of special processing logic, so as to meet the diverse and complex business scenarios without interfering with the default group, and support the provision of policy configuration to combat risk response capabilities.
[0114] In addition, when configuring a policy, this application can configure basic policy information, such as the policy name and policy type, which are divided into scenario policies and general policies (universal for all applications), the application to which it belongs, the audit business, the subject type, the audit scenario, and policy attributes, which are divided into machine review policies and human review policies. Therefore, the policy attributes of the target policy of this application also include machine review policies and human review policies. Among them, machine review policies refer to policies for data review by machines, and human review policies refer to policies for data review by humans, so that different data scenarios can be met.
[0115] In one embodiment, determining whether the asynchronous data and / or the data processing result satisfies the inspection condition configured for the active inspection task being executed in S130 may include:
[0116] S131: Determine an active patrol strategy associated with the active patrol task being executed, and determine patrol conditions configured for the active patrol strategy.
[0117] S132: Match the asynchronous data and / or the data processing result with the inspection condition, and determine whether the asynchronous data and / or the data processing result meets the inspection condition according to a fourth matching result.
[0118] In this embodiment, when determining whether the asynchronous data and / or data processing results meet the inspection conditions configured for the active inspection task being executed, the active inspection strategy associated with the active inspection task being executed can be determined first, and the inspection conditions configured for the active inspection strategy can be determined. Then, the asynchronous data and / or data processing results are matched with the inspection conditions to obtain a fourth matching result. Then, the present application can determine whether the asynchronous data and / or data processing results meet the inspection conditions based on the fourth matching result.
[0119] It is understandable that when setting an active inspection task, the application can configure the inspection time of the active inspection task, such as Figure 12 As shown, Figure 12 A schematic diagram of the configuration page for the active inspection task provided in an embodiment of the present application; Figure 12 In the task configuration page, you can configure the task name, task type, execution strategy, and execution frequency. The execution frequency can be a specified period or a recurring period, and the task type can be a scheduled task or a real-time task. Therefore, when this application configures an active patrol task, it can be executed in the corresponding period based on the execution frequency of the active patrol task.
[0120] Furthermore, this application can also configure inspection conditions corresponding to the active inspection strategy. The inspection conditions include but are not limited to subject status, audit scenario, machine review results, human review results, machine review labels, human review labels, number of people in the room, historical events, recent days, historical number of human review violations, historical number of machine review violations, user ID, asynchronous text keywords, risk control, and list (user portrait). If risk control and list are configured, the user ID that hits the list will be included in the active patrol monitoring list. The above-mentioned inspection conditions correspond to the types of asynchronous data obtained and the types of data processing results. Therefore, when the inspection conditions of the active inspection policy set by the user are only related to abnormal data, only the abnormal data can be matched with the inspection conditions. When the inspection conditions set by the user are only related to the data processing results, only the data processing results can be matched with the inspection conditions. When the inspection conditions set by the user are related to both abnormal data and data processing results, the abnormal data and data processing results can be matched with the inspection conditions together, and whether the inspection conditions are met can be determined based on the fourth matching result. When the inspection conditions are met, the corresponding subjects can be monitored to promptly clean up the illegal content and illegal subjects.
[0121] In a specific implementation, when determining whether the asynchronous data and / or data processing result meets the inspection condition according to the fourth matching result, the present application may first determine the inspection condition configured by the active inspection strategy. Figure 13 As shown, Figure 13 This is a diagram showing the inspection condition configuration page provided in the embodiment of the present application; Figure 13 It can be seen that the configuration information of the active patrol strategy of this application includes basic information and policy configuration, among which the basic information includes policy name, policy type, patrol time range, application and subject type, and the policy configuration includes policy condition group, policy condition item and satisfaction condition, among which, in order to distinguish the policy condition group of machine review strategy and human review strategy, the policy condition group here refers to the patrol condition group. This application can set one or more patrol condition groups for each active patrol strategy, and one or more patrol conditions can be set in each patrol condition group. The policy condition item can configure more detailed features for the corresponding patrol conditions, such as configuring the specific scenario of the patrol condition of the audit scenario, configuring the specific keywords under the patrol condition of asynchronous text keywords, etc. The specific settings can be made according to the actual situation and are not restricted here.
[0122] Furthermore, when there is one inspection condition group in this application, and the fourth matching result is that the asynchronous data and / or data processing result matches all the inspection conditions in the inspection condition group, it means that the asynchronous data and / or data processing result meets the inspection conditions; when there are multiple inspection condition groups in this application, it is necessary to jointly determine whether the asynchronous data and / or data processing results meet the inspection conditions based on the satisfaction conditions of the inspection condition group and the fourth matching result, so that a variety of business scenarios can be met.
[0123] In one embodiment, the relevant information includes at least the subject information, real-time interactive content, and subject attributes of the target user.
[0124] In S130, comprehensive evaluation is performed on the relevant information of the target user to obtain a comprehensive evaluation result, which may include:
[0125] The subject information, real-time interactive content and subject attributes of the target user are evaluated respectively through a plurality of pre-set risk assessment mechanisms, and the comprehensive assessment results are obtained after reviewing the assessment results.
[0126] In this embodiment, when the asynchronous data and / or data processing results meet the inspection conditions, relevant information of the target user can be obtained and comprehensively evaluated to confirm whether the target user has violated the regulations based on the comprehensive evaluation results.
[0127] Among them, the relevant information obtained by this application includes but is not limited to the subject information, real-time interactive content and subject attributes of the target user. This application can evaluate the subject information, real-time interactive content and subject attributes of the target user respectively through a plurality of pre-set risk assessment mechanisms, and obtain a comprehensive assessment result after reviewing the assessment results.
[0128] In a specific implementation, Figure 14 As shown, Figure 14 This is a page display diagram of the active inspection workbench provided in an embodiment of this application. In this application, when a user subject is included in the ledger due to triggering an inspection condition, the auditor must "check in" at the workbench, that is, log in to the system and then mark the start of processing the task. This operation ensures the allocation of audit responsibilities (such as designated processing personnel), records the audit time, and allows the auditor to retrieve relevant information about the subject (such as historical records, real-time data, etc.) for verification. The audit content includes but is not limited to: subject information, real-time interactive content (such as voice on the microphone, IM messages, ASR on the microphone, etc.), and the user's recent violations.
[0129] Next, this application can use the three-layer mechanism of "rules + machine review + manual" to determine whether the target user has violated the rules, as follows:
[0130] 1. Preset rule base: clearly define violation criteria, for example:
[0131] Content rules: including banned words, external link advertisements, etc.
[0132] Behavioral rules: Frequent private chats, screen swiping, abnormal logins and other high-risk operations;
[0133] 2. Machine-assisted identification:
[0134] Natural Language Processing (NLP): identifying semantic violations (e.g., cryptic insults, homophonic words);
[0135] User behavior risk identification: Detects historical behaviors of the subject (such as multiple reports, multiple illegal content sent, abnormal behavior within the terminal, etc.), and increases the judgment weight based on the subject's historical behavior;
[0136] 3. Manual review and judgment: Suspicious cases marked by the system are ultimately confirmed by auditors, especially for gray area content (such as ambiguous sentences that depend on the context).
[0137] For example, when this application determines whether the subject information of the target user violates the regulations, it can make a judgment through static data (such as the latest subject information records and historical subject information violation records); when determining whether real-time audio information violates the regulations, it can convert the voice into text through voice recognition technology (ASR), and combine semantic analysis to detect sensitive content (such as insults, advertisements); when determining whether IM messages violate the regulations, it can scan the text chat content in real time, use keyword filtering and spam models to identify and mark illegal text (such as screen swiping, inducing transactions); when determining whether the ASR information on the microphone violates the regulations, it can dynamically analyze the real-time translated text in the voice interaction to capture the intention of violation (such as violation hints, etc.); when determining whether the subject attributes violate the regulations, it can combine user type (such as ordinary user / anchor), behavior pattern (such as high-frequency speech) and other attributes to assess the subject risk by calling the risk control platform (machine review).
[0138] After judging through the above identification capabilities, various risks can be marked on the workbench, and then reviewed and determined by manual reviewers, and finally dealt with accordingly based on the risk level of the violation.
[0139] The risk management and control device provided in an embodiment of the present application is described below. The risk management and control device described below and the risk management and control method described above can be referenced to each other.
[0140] In one embodiment, Figure 15 As shown, Figure 15 This is a schematic diagram of the structure of a risk management device provided in an embodiment of the present application. The present application also provides a risk management device, which may include a data acquisition module 210, a data processing module 220, and a violation penalty module 230, specifically including the following:
[0141] The data acquisition module 210 is configured to acquire asynchronous data generated by a target user in at least one risk control list of a target application in the target application.
[0142] The data processing module 220 is configured to determine a policy link corresponding to the asynchronous data, and process the asynchronous data according to the policy link to obtain a data processing result.
[0143] The violation penalty module 230 is used to comprehensively evaluate the relevant information of the target user when the asynchronous data and / or the data processing results meet the inspection conditions configured for the active inspection task being executed, and to punish the target user when it is determined that the target user has violated the regulations based on the comprehensive evaluation results.
[0144] In the above embodiment, when the asynchronous data generated by the target user in at least one risk control list of the target application in the target application is obtained, the policy link corresponding to the asynchronous data can be determined first, and then the asynchronous data can be processed according to the policy link to obtain the data processing result; in this process, the present application sets differentiated processing strategies for different asynchronous data, so that it can improve the risk control efficiency while improving the user experience, and the present application also decouples the timing dependency by processing asynchronous data, thereby further optimizing the risk control efficiency; in addition, when the asynchronous data and / or data processing results in the present application meet the inspection conditions configured for the active inspection task being executed, the relevant information of the target user can also be comprehensively evaluated, and when it is determined that the target user has violated the rules based on the comprehensive evaluation results, the target user can be punished, so that it can ensure that the illegal content generated by the subject and the illegal behavior of the subject itself can be effectively dealt with, thereby effectively preventing the illegal content and the illegal subject from being exposed, realizing the real-time capture and governance of the subject's risky behavior, and avoiding the omission of violations.
[0145] In one embodiment, the present application also provides a computer-readable storage medium, which stores computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the risk management method described in any of the above embodiments.
[0146] In one embodiment, the present application further provides a computer device, including: one or more processors, and a memory.
[0147] The memory stores computer-readable instructions, and when the computer-readable instructions are executed by the one or more processors, the steps of the risk management method described in any one of the above embodiments are performed.
[0148] Schematically, as Figure 16 As shown, Figure 16 This is a schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. The computer device 300 can be provided as a server. Figure 16 Computer device 300 includes a processing component 302, which further includes one or more processors, and memory resources represented by memory 301 for storing instructions executable by processing component 302, such as applications. The applications stored in memory 301 may include one or more modules, each corresponding to a set of instructions. Furthermore, processing component 302 is configured to execute the instructions to perform the risk management method of any of the above-described embodiments.
[0149] The computer device 300 may further include a power supply component 303 configured to perform power management of the computer device 300, a wired or wireless network interface 304 configured to connect the computer device 300 to a network, and an input / output (I / O) interface 305. The computer device 300 may operate based on an operating system stored in the memory 301, such as Windows Server™, Mac OS X™, Unix™, Linux™, Free BSD™, or the like.
[0150] Those skilled in the art will understand that Figure 16 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0151] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0152] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The various embodiments can be combined as needed, and the same or similar parts can be referenced to each other.
[0153] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A risk management method, characterized in that: The method comprises: Obtain asynchronous data generated by a target user in at least one risk control list of a target application in the target application; Determining a policy link corresponding to the asynchronous data, and processing the asynchronous data according to the policy link to obtain a data processing result; When the asynchronous data and / or the data processing result meets the inspection conditions configured for the active inspection task being executed, a comprehensive evaluation is performed on the relevant information of the target user, and when it is determined that the target user has violated the rules based on the comprehensive evaluation result, the target user is punished.
2. The risk management method according to claim 1, characterized in that: Before obtaining asynchronous data generated by a target user in the risk control list of the target application in the target application, the method further includes: Obtain historical data generated by each user in the target application within a preset time period; Based on the historical data of each user, target users who meet the risk control conditions are screened out from each user, and a risk control list corresponding to the target users is formed.
3. The risk management method according to claim 2, characterized in that: The target users who meet the risk control conditions are screened out from the users based on the historical data of each user, and a risk control list corresponding to the target users is formed, including: Generate user profiles for each user based on their historical data; The user profile of each user is matched with a pre-configured risk control rule set, and a risk control list is determined based on a first matching result, wherein the risk control rule set includes user attribute rules, user behavior rules, and behavior sequence rules.
4. The risk management method according to claim 3, characterized in that: Each user's historical data includes record tables of multiple dimensions; Generating a user profile of each user based on the historical data of each user includes: For each user: Clean the record tables of each dimension of the user according to the pre-configured meta-event table and event attribute table to form an event table corresponding to the user; Determine the user attribute corresponding to the user according to the pre-configured user attribute table; Generate a user profile for the user based on the user's event table and user attributes.
5. The risk management method according to any one of claims 1 to 4, characterized in that: The determining of a policy link corresponding to the asynchronous data and processing the asynchronous data according to the policy link to obtain a data processing result includes: Determining a target policy corresponding to the asynchronous data and a plurality of policy condition groups pre-configured in the target policy; Matching the asynchronous data with each policy condition group respectively, and determining a target condition group corresponding to the asynchronous data according to the second matching result; The asynchronous data is processed according to the policy link of the target condition group to obtain a data processing result.
6. The risk management method according to claim 5, characterized in that: The determining of a target policy corresponding to the asynchronous data and a plurality of policy condition groups pre-configured in the target policy includes: The asynchronous data is matched with a plurality of enabled and approved policies pre-configured in a policy center, and a target policy corresponding to the asynchronous data and a plurality of policy condition groups pre-configured in the target policy are determined according to a third matching result.
7. The risk management method according to any one of claims 1 to 4 and 6, characterized in that: The determining whether the asynchronous data and / or the data processing result meets the inspection conditions configured for the active inspection task being executed includes: Determining an active patrol strategy associated with the active patrol task being executed, and determining patrol conditions configured for the active patrol strategy; The asynchronous data and / or the data processing result are matched with the inspection condition, and it is determined whether the asynchronous data and / or the data processing result meet the inspection condition according to a fourth matching result.
8. The risk management method according to any one of claims 1 to 4 and 6, characterized in that: The relevant information includes at least the subject information, real-time interactive content and subject attributes of the target user; The comprehensive evaluation of the relevant information of the target user to obtain a comprehensive evaluation result includes: The subject information, real-time interactive content and subject attributes of the target user are evaluated respectively through a plurality of pre-set risk assessment mechanisms, and the comprehensive assessment results are obtained after reviewing the assessment results.
9. A risk management device, characterized in that: include: A data acquisition module, configured to acquire asynchronous data generated by a target user in at least one risk control list of a target application in the target application; a data processing module, configured to determine a policy link corresponding to the asynchronous data, and process the asynchronous data according to the policy link to obtain a data processing result; The violation penalty module is used to conduct a comprehensive evaluation of the relevant information of the target user when the asynchronous data and / or the data processing results meet the inspection conditions configured for the active inspection task being executed, and to punish the target user when it is determined that the target user has violated the regulations based on the comprehensive evaluation results.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the risk management method according to any one of claims 1 to 8.
11. A computer device, characterized in that: include: one or more processors, and memory; The memory stores computer-readable instructions, which, when executed by the one or more processors, execute the steps of the risk management method according to any one of claims 1 to 8.