Internet e-commerce abnormal user detection method based on big data
By analyzing the transaction data and device fingerprint information of the e-commerce platform in real time, and dynamically adjusting the risk weight, the problem of device account association identification is solved, and accurate detection and risk management of abnormal users is realized.
Patent Information
- Application Number
- CN202510659296.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-29
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology cannot effectively integrate the device fingerprint and account information, and it is difficult to identify the complex account relationship hidden behind the device, and the lack of a dynamic adjustment mechanism, resulting in inaccurate detection of abnormal users.
By comparing the changes in the number of commodity transactions in real time, marking the transaction analysis period, calculating transaction doubt values based on the device fingerprint information and transaction information, dynamically adjusting the risk weight, and identifying abnormal devices and users.
Accurately filter out problematic products and abnormal users, improve the risk management and security monitoring capabilities of e-commerce platforms, and ensure transaction security and user trust.
Smart Images

Figure CN120563128A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet e-commerce, and in particular to a method for detecting abnormal users of Internet e-commerce based on big data. Background Art
[0002] With the rapid development of the internet e-commerce industry, e-commerce platforms have accumulated massive amounts of transaction data, which contains a wealth of business information and user behavior patterns. However, the challenge is how to effectively analyze this data to discover potential commercial value while also identifying and preventing abnormal user behavior, such as fraudulent transactions and malicious order manipulation. Traditional data analysis methods are unable to cope with such large-scale and complex data. Therefore, big data-based abnormal user detection methods have emerged.
[0003] In the daily operations of e-commerce platforms, managers often face various transaction anomalies. These issues may manifest as sudden surges or decreases in transaction volume, frequent returns or complaints for specific products, or the same device being associated with multiple user accounts for transactions within a short period of time. These abnormal behaviors not only disrupt the normal operations of e-commerce platforms but can also cause financial losses and reputational damage. With technological advancements, some detection solutions have begun to focus on device information, but these solutions are severely deficient in analyzing the associations between devices and users. Many anomalous users use the same device to register multiple accounts and conduct malicious fraudulent transactions. However, existing technologies are unable to effectively integrate device fingerprints with account information, making it difficult to identify the complex account associations hidden behind devices. This results in a large number of anomalous devices and their associated accounts remaining at large. Furthermore, existing detection technologies lack dynamic adjustment mechanisms and cannot promptly optimize detection strategies based on real-time data. This often results in normal users being misclassified as anomalous or genuine anomalous users being missed.
[0004] In response to the above problems, the present invention proposes a method for detecting abnormal users in Internet e-commerce based on big data. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for detecting abnormal users of Internet e-commerce based on big data to solve at least one of the above-mentioned problems in the prior art.
[0006] By comparing the changes in commodity trading volume in real time, mark the trading analysis period;
[0007] Based on the marked transaction analysis period, the device fingerprint information of the transaction user is analyzed, and combined with the transaction information of the product, the transaction doubt value of the product is calculated and the problematic products are screened and marked;
[0008] Analyze the number of users and traded items associated with the same device during historical trading periods, calculate period anomalies, mark these periods, dynamically adjust risk weights for these periods, calculate device anomalies based on period anomalies, and identify and mark abnormal and risky devices.
[0009] Based on marked abnormal devices and risky devices, abnormal users are detected by analyzing the transaction records of associated users.
[0010] Beneficial effects of the present invention:
[0011] 1. The present invention obtains records of e-commerce platform products during transaction periods, marks and analyzes the periods, and combines device fingerprint information with transaction information to calculate transaction suspicion values. This method can effectively identify transaction anomalies, accurately screen out problematic products, enhance the risk management capabilities of e-commerce platforms, ensure transaction security, optimize user experience, and promote the healthy development of the e-commerce ecosystem.
[0012] 2. The present invention analyzes the historical transaction records of users on the e-commerce platform, combines device-related information with the number of transaction items, calculates time period anomalies and dynamically adjusts risk weights. This method can accurately identify device behavior patterns, effectively distinguish abnormal devices, risky devices, and normal devices, and then accurately detect abnormal users based on the transaction records of associated users, significantly improving the security monitoring capabilities of the e-commerce platform, ensuring transaction integrity, maintaining platform order, and enhancing user trust. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0014] Figure 1 This is a flow chart of a method for detecting abnormal users of Internet e-commerce based on big data provided by an embodiment of the present invention;
[0015] Figure 2 This is a flow chart of the steps for obtaining the operating status of an evaluation device in a method for detecting abnormal users of an Internet e-commerce platform based on big data provided in the second embodiment of the present invention;
[0016] Figure 3 This is a structural diagram of an electronic device provided in Example 3 of the present invention. DETAILED DESCRIPTION
[0017] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0018] Example 1
[0019] like Figure 1 As shown, an embodiment of the present invention provides a method for detecting abnormal users of Internet e-commerce based on big data, which specifically includes the following steps:
[0020] Step 1: Obtain transaction records of products on the e-commerce platform during the commodity trading period, and mark the transaction analysis period by comparing the changes in the commodity transaction quantity;
[0021] In some embodiments, based on any product on the e-commerce platform, the transaction record of the product during the product transaction period is obtained, and the transaction record includes the transaction users and transaction quantity of the product in each monitoring period;
[0022] The commodity trading period is a period starting from the time when the commodity starts to be sold, consisting of several monitoring periods, and ending at the current time. The monitoring periods are all of equal length, and the end point of each monitoring period is marked as the detection node of the monitoring period. The detection node is also the starting point of the next monitoring period.
[0023] It should be noted that the user refers to a registered account on the e-commerce platform, not a real user. A real user can have multiple registered accounts, so multiple registered accounts may be associated with the same device.
[0024] Take a flag value, flag, and set it to 0. Obtain the difference between the transaction quantity of the product in the current monitoring period and the previous monitoring period to obtain the transaction change value of the product between the two monitoring periods. Take the absolute value of the transaction change value to obtain the absolute transaction change value. Compare the obtained absolute transaction change value with the transaction change threshold.
[0025] If the absolute value of the transaction change is less than or equal to the transaction change threshold, it means that the commodity transaction changes slowly;
[0026] If the absolute value of the transaction change is greater than the transaction change threshold and the transaction change value is greater than 0, it means that the number of commodity transactions has increased sharply, and the flag value is set to 1;
[0027] If the absolute value of the transaction change is greater than the transaction change threshold and the transaction change value is less than 0, it means that the commodity transaction volume has dropped sharply, and the flag value is set to 0;
[0028] Compare the duration that the flag value is continuously 1 with the duration threshold. If the duration that the flag value is continuously 1 is greater than or equal to the duration threshold, set the flag value to 0.
[0029] Mark the period when the flag value is continuously 1 as a trading analysis period;
[0030] Step 2: Based on the marked transaction analysis period, analyze the transaction user's device fingerprint information, combine it with the product's transaction information, calculate the product's transaction suspicion value within the transaction analysis period, and filter and mark problematic products based on the transaction suspicion value;
[0031] In some embodiments, based on the marked transaction analysis period, the transaction user composition within the transaction analysis period is analyzed;
[0032] Specifically, the device fingerprint information of the transaction user during the transaction analysis period is traced back. The device fingerprint information includes the transaction user's MAC address, IP address and device model. The device fingerprint information of any device is unique;
[0033] Based on any device fingerprint information, obtain the transaction count of all transaction users associated with the device fingerprint information within the transaction analysis period and sum them to obtain the device commodity transaction count, and compare the obtained device commodity transaction count with the abnormal quantity threshold;
[0034] If the number of device commodity transactions is less than or equal to the abnormal number threshold, it means that the device transaction situation is within the normal range;
[0035] If the number of device commodity transactions exceeds the abnormal number threshold, it indicates that there may be an abnormality in the device transaction situation, and the device corresponding to the device fingerprint information will be marked as a suspicious device;
[0036] Traverse the device fingerprint information and transaction volume of all transaction users during the transaction analysis period to obtain several suspicious devices;
[0037] Obtain the device commodity transaction quantity of the suspicious device and compare it with the total commodity transaction quantity during the transaction analysis period to obtain the suspicious transaction ratio. Obtain the suspicious transaction ratios of all suspicious devices during the transaction analysis period and sum and average them to obtain the average of the suspicious transaction ratios, which is marked as CJ.
[0038] Obtain the number of all suspicious devices during the transaction analysis period and compare it with the total number of all transaction users during the transaction analysis period to obtain the suspicious device ratio, which is marked as CS.
[0039] The obtained doubtful transaction ratio mean CJ and doubtful device ratio CS are imported into the linear weighted model for calculation to obtain the doubtful transaction value of the commodity during the transaction analysis period.
[0040] It should be noted that the calculation in the linear weighted model is positively correlated with the parameters. The purpose of the calculation is to determine the suspicious transactions of the commodity during the transaction analysis period by combining the proportion of the number of transactions of the suspicious device during the transaction analysis period with the proportion of the suspicious device among the transaction users. The higher the proportion of the number of transactions of the suspicious device during the transaction analysis period and the higher the proportion of the suspicious device among the transaction users, the higher the suspicious transaction value of the commodity during the transaction analysis period.
[0041] Compare the obtained transaction doubt value with the transaction doubt threshold;
[0042] If the product's suspicious transaction value during the transaction analysis period is less than the suspicious transaction threshold, it means that the change in the product's transaction volume is not related to abnormal users;
[0043] If the suspicious transaction value of a product during the transaction analysis period is greater than or equal to the suspicious transaction threshold, it indicates that the change in the product's transaction volume is caused by an abnormal user, and the product will be marked as a problematic product.
[0044] The technical solution of an embodiment of the present invention is: obtaining transaction records of goods on an e-commerce platform during a commodity trading period, marking the transaction analysis period by comparing changes in the number of commodity transactions, analyzing the device fingerprint information of the transaction user based on the marked transaction analysis period, combining the transaction information of the goods, calculating the transaction doubt value of the goods during the transaction analysis period, and screening and marking problematic goods based on the transaction doubt value.
[0045] Example 2
[0046] like Figure 1 As shown, the embodiment of the present invention provides a method for detecting abnormal users of Internet e-commerce based on big data, which specifically includes the following steps:
[0047] Step 3: Obtain transaction records of e-commerce platform users during historical trading periods, analyze the number of users and transaction items associated with the same device, perform data processing, calculate period anomalies, mark normal and abnormal transaction periods based on the period anomalies, dynamically adjust the risk weights for abnormal transaction periods, calculate device anomalies based on the period anomalies, evaluate device operation based on the device anomalies, and identify abnormal and risky devices;
[0048] like Figure 2 As shown, the steps for obtaining the operating status of the evaluation device are as follows:
[0049] In some embodiments, the transaction records of the e-commerce platform users in the historical transaction period are obtained, wherein the transaction records include the commodity information and quantity of the commodities traded by the users in each detection period;
[0050] The historical trading period represents a period starting from the time when the e-commerce platform was put into use, consisting of several detection periods, and ending at the current time. The detection periods are all of equal length, and the end point of each detection period is marked as the detection node of the detection period. The detection node is also the starting point of the next detection period.
[0051] Based on any detection period, traverse all users within the detection period, trace the device fingerprint information of all users within the detection period, and obtain the transaction records of users within the detection period;
[0052] Based on any device fingerprint information, obtain the number of users associated with the device fingerprint information during the detection period, and compare it with the number of associated devices to obtain the user number ratio, marked as YS;
[0053] It should be noted that the device associated with the same device fingerprint information is unique, so the number of associated devices is 1. The purpose of performing the ratio processing is only to remove the dimension to facilitate subsequent calculations.
[0054] Obtain the number of items traded by all users associated with the device fingerprint information during the detection period, and compare it with the abnormal quantity threshold to obtain the device transaction ratio, which is marked as SJ;
[0055] The obtained user quantity ratio YS and device transaction ratio SJ are processed to obtain the time period abnormal value SX of the device associated with the device fingerprint information within the detection period;
[0056] A transaction period evaluation model is established based on a convolutional neural network. The transaction period evaluation model is used to obtain abnormal values within the detection period of the device associated with the device fingerprint information.
[0057] Specifically:
[0058] Obtain sample data of the device associated with the device fingerprint information within the historical detection period. Combine T consecutive time periods (e.g., T = 10) into a sample. The input shape is (T, 2). 70% of the sample data is used as the training set, and 30% of the sample data is used as the validation set.
[0059] It should be noted that: if the sample data in the historical detection period totals 1000 periods and the window length T = 10, then 991 samples (1000-T+1) are generated;
[0060] The sample data for each detection period is (YS k 、SJ k) were subjected to Z-score standardization;
[0061] Use one-dimensional CNN to process time window sequences to process the trading session evaluation model;
[0062] Among them, YS k Indicates the ratio of the number of users in the kth detection period, SJ k represents the device transaction ratio in the kth detection period;
[0063] The user quantity ratio YS and the device transaction ratio SJ corresponding to the device fingerprint information associated device in the current detection period are input into the transaction period evaluation model, thereby outputting the period anomaly value SX of the device fingerprint information associated device in the detection period;
[0064] It should be noted that the role of the time period abnormal value is to determine the transaction abnormality of the device during the detection period by combining the number of users associated with the device and the number of goods traded by the device-associated users during the detection period. The more users associated with the device during the detection period and the larger the number of goods traded by the device-associated users, the larger the time period abnormal value.
[0065] Compare the obtained time period anomaly value with the time period anomaly value threshold;
[0066] If the device's time period abnormality value during the detection period is less than the time period abnormality threshold, it means that the device's transaction abnormality is low, and the detection period is marked as the device's normal transaction period;
[0067] If the device's time period abnormality value during the detection period is greater than or equal to the time period abnormality threshold, it indicates that the device's transaction abnormality is high, and the detection period is marked as the device's transaction abnormality period;
[0068] Traverse all detection periods within the user monitoring cycle, calculate and compare several normal transaction periods and abnormal transaction periods of the device associated with the device fingerprint information;
[0069] Based on the marked abnormal transaction period, obtain the commodity information of the device transaction during the abnormal transaction period, obtain the commodity quantity of the problematic commodities traded, and compare it with the commodity quantity traded by the device during the abnormal transaction period to obtain the problematic transaction ratio of the device, which is marked as WJ i , where i represents the chronological order of the abnormal trading period among all abnormal trading periods;
[0070] Combined with the obtained problem transaction ratio, the formula is: W i =W base (1+λ*WJ i ) Calculate the risk weight for abnormal trading periods, where W base It represents the basic risk weight during the abnormal trading period, Wbase =0.7, λ is the adjustment coefficient, λ=10;
[0071] It should be noted that the risk weight is adjusted based on the proportion of problematic products among the traded commodities during the abnormal trading period. The greater the proportion of problematic products among the traded commodities, the higher the risk weight for the abnormal trading period.
[0072] Data processing is performed on the abnormal values of the equipment during the historical trading period and the corresponding risk weights, using the formula: Calculate the device abnormal value SY of the device at the current detection node, where SX i It represents the abnormal value of the abnormal trading period with the time sequence number i among all abnormal trading periods. n represents the total number of abnormal trading periods in the historical trading period. If n is 0, the device abnormal value SY is also 0.
[0073] It should be noted that the device abnormal value is calculated by accumulating the abnormal value of each abnormal trading period in the historical trading period according to the risk weight of the abnormal trading period;
[0074] Compare the obtained device abnormality value with the device abnormality threshold;
[0075] If the device abnormality value of the device at the current detection node is greater than or equal to the device abnormality threshold, it means that the device has multiple or serious abnormal operations, and the device is marked as an abnormal device;
[0076] If the device abnormality value at the current detection node is less than the device abnormality threshold but not equal to 0, it indicates that the device may have abnormal operation but the degree is relatively minor. The device is marked as a risk device.
[0077] If the device abnormality value of the device at the current detection node is 0, it indicates that the device is operating normally and the device is marked as a normal device;
[0078] Step 4: Based on the marked abnormal devices and risky devices, analyze the transaction records of related users and detect abnormal users;
[0079] In some embodiments, users associated with marked risky devices are obtained, and based on any user associated with a risky device, transaction records of the user in a historical transaction period are obtained, and commodities traded by the user in an abnormal transaction period in the historical analysis period are marked as period risk commodities;
[0080] Specifically, based on any period risk commodity, if the period risk commodity is not a problem commodity;
[0081] Obtain the number of users associated with the risky device during the abnormal trading period and the risky commodity during the period, and compare it with the total number of users associated with the risky device during the abnormal trading period to obtain the risky user ratio of the risky commodity during the period;
[0082] Obtain the number of period risk commodities traded during the abnormal trading period, and compare it with the sum of the numbers of all period risk commodities traded during the abnormal trading period to obtain the risk quantity ratio of the period risk commodities;
[0083] Perform a weighted calculation on the obtained risk user ratio and risk quantity ratio to obtain the product's risk value within the time period;
[0084] Compare the obtained intra-period risk value with the intra-period risk threshold, and mark the commodities with intra-period risk value greater than or equal to the intra-period risk threshold as risky commodities;
[0085] Traverse all abnormal trading periods of the user during the historical analysis period to obtain several risky products. Obtain the sum of the number of risky products and problematic products traded by the user during the historical analysis period, and compare this sum with the total number of products traded by the user during the historical analysis period to obtain the user's user abnormal value. Compare the obtained user abnormal value with the user abnormal threshold.
[0086] If the user's user abnormality value is less than the user abnormality threshold, it means that the user operation is normal;
[0087] If the user's user abnormality value is greater than or equal to the user abnormality threshold, it indicates that there is a problem with the user's operation and the user is marked as an abnormal user;
[0088] Obtain users associated with the marked abnormal device, and mark all users associated with the abnormal device during the abnormal transaction period as abnormal users;
[0089] The technical solution of an embodiment of the present invention is: obtaining transaction records of e-commerce platform users during historical transaction periods, analyzing the number of users and transaction items associated with the same device and performing data processing, calculating time period anomalies, marking normal transaction periods and abnormal transaction periods according to the time period anomalies, dynamically adjusting the risk weights of abnormal transaction periods, calculating device anomalies based on the time period anomalies, marking devices as abnormal devices, risky devices, or normal devices according to the device anomaly values, analyzing the transaction records of associated users based on the marked abnormal devices and risky devices, and realizing the detection of abnormal users.
[0090] Example 3
[0091] Reference Figure 3, an embodiment of the present invention further provides a computer device 3, comprising: a memory 302 and a processor 301 and a computer program 303 stored in the memory 302. When the computer program 303 is executed on the processor 301, it implements a method for detecting abnormal users of Internet e-commerce based on big data as described in any one of the above methods.
[0092] The computer device 3 may be a desktop computer, a notebook computer, a PDA, a cloud server or other computing devices. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art will understand that Figure 3 This is merely an example of the computer device 3 and does not constitute a limitation on the computer device 3 . The computer device 3 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device 3 may also include input and output devices, network access devices, etc.
[0093] The processor 301 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.
[0094] In some embodiments, the memory 302 may be an internal storage unit of the computer device 3, such as a hard disk or memory of the computer device 3. In other embodiments, the memory 302 may also be an external storage device of the computer device 3, such as a plug-in hard disk, a SmartMediaCard (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device 3. Furthermore, the memory 302 may include both an internal storage unit of the computer device 3 and an external storage device. The memory 302 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 302 may also be used to temporarily store data that has been output or is about to be output.
[0095] Example 4
[0096] An embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements a method for detecting abnormal users of Internet e-commerce based on big data as described in any one of the above methods.
[0097] In this embodiment, if the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process of the above-mentioned method embodiment by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can at least include: any entity or device capable of carrying computer program code to the camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, mobile hard drive, magnetic disk, or optical disk. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.
[0098] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0099] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0100] In the embodiments disclosed in the present application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are merely schematic. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0101] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0102] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.
[0103] The above is a detailed description of an embodiment of the present invention. However, the content described is only a preferred embodiment of the present invention and should not be considered to limit the scope of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.
Claims
1. A method for detecting abnormal users of Internet e-commerce based on big data, characterized in that: The following steps are involved: By comparing the changes in commodity trading volume in real time, mark the trading analysis period; Based on the marked transaction analysis period, the device fingerprint information of the transaction user is analyzed, and combined with the transaction information of the product, the transaction doubt value of the product is calculated and the problematic products are screened and marked; Analyze the number of users and traded items associated with the same device during historical trading periods, calculate period anomalies, mark abnormal trading periods, dynamically adjust risk weights for abnormal trading periods, calculate device anomalies based on period anomalies, and identify and mark abnormal and risky devices. Based on marked abnormal devices and risky devices, abnormal users are detected by analyzing the transaction records of associated users.
2. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 1 is characterized in that: The method of the trading analysis period is: Take a flag value flag and set it to 0, obtain the transaction quantity of the product in the current monitoring period and the previous monitoring period, perform data processing to obtain the transaction change value and the absolute value of the transaction change, and if the absolute value of the transaction change is greater than the transaction change threshold and the transaction change value is greater than 0, set the flag value to 1; If the absolute value of the transaction change is greater than the transaction change threshold and the transaction change value is less than 0, or the duration of the fl ag value being 1 is greater than or equal to the duration threshold, the fl ag value is set to 0; The period when the fl ag value is continuously 1 is marked as a trading analysis period.
3. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 1, characterized in that: The method for obtaining the problematic products is to mark the products whose transaction doubt value is greater than or equal to the transaction doubt threshold during the transaction analysis period as problematic products.
4. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 3 is characterized in that: The method for obtaining the transaction doubt value is as follows: The number of questionable devices and the number of device-commodity transactions during the transaction analysis period are obtained and processed to obtain the average questionable transaction ratio and the questionable device ratio. The questionable transaction value of the commodity during the transaction analysis period is calculated using a formula.
5. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 4 is characterized in that: The method for obtaining the suspected device is: Obtain the transaction counts of all transaction users associated with the same device fingerprint information within the transaction analysis period and sum them up to obtain the device commodity transaction count. Mark the corresponding device whose device commodity transaction count is greater than the abnormal quantity threshold as a suspicious device.
6. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 1, characterized in that: The method for obtaining abnormal devices and risky devices is as follows: Devices whose device abnormality values at the current detection node are greater than or equal to the device abnormality threshold are marked as abnormal devices, and devices whose device abnormality values at the current detection node are less than the device abnormality threshold but not 0 are marked as risk devices.
7. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 6 is characterized in that: The method for obtaining the device abnormal value is as follows: Obtain the number of problematic items traded on the device during the abnormal trading period and process the data to obtain the device's problematic transaction ratio. Dynamically adjust the risk weight for the abnormal trading period using a formula. Data processing is performed on the device's period abnormal values and corresponding risk weights during the historical trading period, and the device abnormal value of the device at the current detection node is cumulatively calculated. If there is no abnormal trading period during the historical trading period, the device abnormal value is 0.
8. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 7 is characterized in that: The method for obtaining the abnormal transaction period is as follows: The number of users associated with the device fingerprint information and the number of goods traded during the detection period are obtained for data processing to obtain the user number ratio and the device transaction ratio, and a weighted calculation is performed to obtain the time period anomaly value of the device associated with the device fingerprint information during the detection period. The detection period in which the device's time period anomaly value is greater than or equal to the time period anomaly threshold is marked as the device's transaction anomaly period.
9. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 1, characterized in that: The abnormal user is obtained as follows: All users who are associated with risky devices during the abnormal transaction period, whose user abnormality values are greater than or equal to the user abnormality threshold, and who are associated with abnormal devices during the abnormal transaction period are marked as abnormal users.
10. The method for detecting abnormal users of Internet e-commerce based on big data according to claim 1, characterized in that: The method for obtaining the user abnormal value is: The commodities traded by users during the abnormal transaction period are marked as period risk commodities. If the period risk commodities are not problem commodities, the number of associated users who traded the period risk commodities and the number of commodities traded during the abnormal transaction period are obtained for data processing to obtain the risk user ratio and the risk quantity ratio, and weighted calculation is performed to obtain the risk value within the period. Commodities with an intra-period risk value greater than or equal to the intra-period risk threshold are marked as risk commodities. Data processing is performed on the number of risk commodities and problem commodities traded by users during the historical analysis period to obtain the user anomaly value of the user.