Abnormal behavior detection method and device, equipment, medium and computer program product

By receiving the embedded data of the target terminal, determining and matching the client type sequence, the problem of insufficient coverage of cross-platform abnormal behavior detection is solved, and efficient cross-client abnormal behavior detection is achieved.

CN120654227APending Publication Date: 2025-09-16TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410297548.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-14
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively detect abnormal behaviors across multiple platforms, resulting in insufficient coverage and poor results in abnormal behavior detection.

Method used

By receiving the tracking data sent sequentially by the target terminal based on the tracking reporting mechanism, the operation client type sequence of the target terminal is determined and matched with the preset operation client type sequence indicating abnormal behavior, thereby realizing cross-client abnormal behavior detection.

Benefits of technology

The coverage of abnormal behavior detection is improved, the abnormal behavior detection effect is improved, and abnormal behavior across multiple clients can be discovered in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120654227A_ABST
    Figure CN120654227A_ABST
Patent Text Reader

Abstract

The invention relates to an abnormal behavior detection method and device, computer equipment, a storage medium and a computer program product. The embodiment of the invention can be applied to various scenes such as cloud technology, artificial intelligence, intelligent traffic, auxiliary driving and the like. The method relates to an artificial intelligence technology. The method comprises the following steps: receiving multiple pieces of burying point data sequentially sent by a target terminal based on a burying point reporting mechanism; determining an operation client type sequence corresponding to the target terminal according to client types corresponding to the client identifiers in the sequentially received burying point data; obtaining a preset operation client type sequence for indicating the abnormal behavior; and when the operation client type sequence corresponding to the target terminal is matched with the operation client type sequence indicating the abnormal behavior, an abnormal behavior detection result indicating that the abnormal behavior occurs on the target terminal is obtained, and the abnormal behavior detection effect is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an abnormal behavior detection method, apparatus, computer equipment, storage medium, and computer program product. Background Art

[0002] The rapid development of computer and Internet technologies has led to tremendous progress in many fields, such as e-commerce and social media. At the same time, these technologies have also spawned a series of abnormal behaviors, such as those involving fake interactions. These abnormal behaviors have brought huge risks to people and damaged their interests.

[0003] To prevent abnormal behavior from negatively impacting users, related technologies often use models like content models and account graph relationships to detect interaction data within the platform to determine whether abnormal behavior has occurred. However, this closed-loop detection approach for a single platform lacks coverage, resulting in poor abnormal behavior detection results. Summary of the Invention

[0004] Based on this, it is necessary to provide an abnormal behavior detection method, device, computer equipment, computer-readable storage medium and computer program product that can improve the abnormal behavior detection effect in response to the above technical problems.

[0005] In a first aspect, the present application provides a method for detecting abnormal behavior. The method comprises:

[0006] Receive multiple buried point data sent sequentially by a target terminal based on a buried point reporting mechanism, where the buried point data is sent by the target terminal when a preset operation is triggered on a client on the target terminal, and each buried point data includes at least a client identifier of the client that triggered the preset operation;

[0007] Determining an operation client type sequence corresponding to the target terminal according to the client types corresponding to the client identifiers in the tracking data received in sequence;

[0008] Obtaining a preset sequence of operation client types indicating abnormal behavior, wherein the sequence of operation client types indicating abnormal behavior is a sequence formed by sequentially arranging client types involved in the abnormal behavior, and there are multiple client types involved in the abnormal behavior;

[0009] When the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result for the target terminal is obtained, and the abnormal behavior detection result indicates that abnormal behavior occurs on the target terminal.

[0010] In a second aspect, the present application also provides an abnormal behavior detection device. The device includes:

[0011] A data receiving module is configured to receive a plurality of buried point data sequentially sent by a target terminal based on a buried point reporting mechanism, wherein the buried point data is sent by the target terminal when a preset operation is triggered on a client on the target terminal, and each buried point data includes at least a client identifier of the client that triggered the preset operation;

[0012] A sequence determination module, configured to determine an operation client type sequence corresponding to the target terminal according to the client types corresponding to the client identifiers in the buried data received in sequence;

[0013] A sequence acquisition module, configured to acquire a preset sequence of operation client types indicating abnormal behavior, wherein the sequence of operation client types indicating abnormal behavior is a sequence formed by sequentially arranging client types involved in abnormal behavior, and there are multiple client types involved in abnormal behavior;

[0014] A sequence matching module is used to obtain an abnormal behavior detection result about the target terminal when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, wherein the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal.

[0015] In some embodiments, the device also includes a client type determination module, which is used to obtain client installation timing texts corresponding to each of the multiple sample devices; using the client installation timing text as a sentence and the client identifier in the client installation timing text as a word, obtaining a word vector corresponding to each word based on the sentence through a word vector model; clustering the corresponding client identifiers based on the word vector corresponding to each word; according to the clustering results, obtaining a cluster corresponding to the client type involved in abnormal behavior, and determining the client represented by each client identifier in the cluster as the client type involved in abnormal behavior.

[0016] In some embodiments, the client type determination module is used to obtain the installation flow data of each client on the sample device; obtain the installation sequence of each client on the same sample device based on the installation flow data; sort the client identifiers of the corresponding clients in sequence according to the installation sequence to obtain the client installation timing text corresponding to the sample device.

[0017] In some embodiments, the client type determination module is used to use the word vectors corresponding to m client identifiers randomly selected from multiple client identifiers as cluster centers, where m is an integer greater than 1; assign each client identifier to the cluster cluster where the nearest cluster center is located according to the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers; update the cluster centers of each cluster cluster according to the word vectors corresponding to the client identifiers contained in each cluster cluster to obtain the updated m cluster centers, return the step of assigning each client identifier to the cluster cluster where the nearest cluster center is located according to the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers, and continue to execute until the clustering stop condition is met to obtain the clustering result.

[0018] In some embodiments, the sequence determination module is used to parse each buried point data received in sequence to obtain the client identifier of the client that triggers the preset operation; match the parsed client identifier of the client that triggers the preset operation with the client identifier set corresponding to the client type involved in abnormal behavior to obtain the client type of the client that triggers the preset operation; and sort the corresponding client types of the client that triggers the preset operation in sequence according to the order in which each of the buried point data is received to obtain the operation client type sequence corresponding to the target terminal.

[0019] In some embodiments, the sequence determination module is used to verify, for each client identifier of a client that triggers a preset operation, whether the client identifier belongs to a client identifier set corresponding to a client type involving abnormal behavior; if it belongs to a client identifier set corresponding to a client type involving abnormal behavior, the client type corresponding to the client identifier set is used as the client type of the client that triggers the preset operation; if it does not belong to a client identifier set corresponding to a client type involving abnormal behavior, the client type of the client that triggers the preset operation is determined to be a preset specified type, and the preset specified type is a client type that does not involve abnormal behavior.

[0020] In some embodiments, the sequence acquisition module is further used to obtain multiple preset operation client type sequences, each of the preset operation client type sequences is a preset sequence formed by arranging client types suspected of being involved in abnormal behavior in sequence, and the client operation time intervals corresponding to the multiple preset operation client type sequences are different; obtain the total number of terminals that hit each of the preset operation client type sequences; for any of the preset operation client type sequences, determine the abnormal behavior hit rate corresponding to each of the preset operation client type sequences based on the total number of terminals that hit the preset operation client type sequence and the number of abnormal behaviors that occur when hitting the preset operation client type sequence; and determine the operation client type sequence indicating abnormal behavior from the multiple preset operation client type sequences based on the abnormal behavior hit rate.

[0021] In some embodiments, the sequence matching module is used to determine that the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior if the operation client type sequence corresponding to the target terminal includes the operation client type sequence indicating abnormal behavior; if the operation client type sequence corresponding to the target terminal does not include the operation client type sequence indicating abnormal behavior, determine that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

[0022] In some embodiments, the apparatus further comprises a message sending module, wherein the message sending module is configured to send a reminder message to the target terminal when the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal.

[0023] In some embodiments, the client type involved in the abnormal behavior includes at least a payment type and a social type, and the preset operation triggered by the client includes a client installation operation or a client startup operation.

[0024] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the abnormal behavior detection method described above when executing the computer program.

[0025] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-mentioned abnormal behavior detection method.

[0026] In a fifth aspect, the present application further provides a computer program product, which includes a computer program that implements the steps of the above abnormal behavior detection method when executed by a processor.

[0027] The above-mentioned abnormal behavior detection method, device, computer device, storage medium and computer program product receive multiple buried point data sent in sequence by the target terminal based on the buried point reporting mechanism. The buried point data is automatically sent by the target terminal when a preset operation is triggered on the client on the target terminal. Each buried point data includes at least the client identifier of the client that triggered the preset operation. According to the client type corresponding to the client identifier in the buried point data received in sequence, the operation client type sequence corresponding to the target terminal is determined; the preset operation client type sequence indicating abnormal behavior is obtained. Since the operation client type sequence indicating abnormal behavior is a sequence formed by arranging the client types of the operation clients involved in the abnormal behavior, and there are multiple client types involved in the abnormal behavior, that is, the operation client type sequence indicating abnormal behavior reflects the abnormal behavior across clients. Therefore, by matching the operation client type sequence corresponding to the target terminal with the operation client type sequence indicating abnormal behavior in real time, it is possible to detect whether the target terminal has abnormal behavior across multiple clients. In this way, when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result indicating that abnormal behavior has occurred on the target terminal is obtained in a timely manner. Based on this, cross-client abnormal behavior detection is achieved, the coverage of abnormal behavior detection is improved, and the abnormal behavior detection effect is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 A diagram of an application environment of an abnormal behavior detection method in one embodiment;

[0029] Figure 2 1 is a flow chart of an abnormal behavior detection method according to an embodiment;

[0030] Figure 3 A schematic diagram of clustering results in one embodiment;

[0031] Figure 4 A schematic diagram of a process for determining a client type in one embodiment;

[0032] Figure 5 A schematic flow chart of steps for determining the type of operation client corresponding to a target terminal in one embodiment;

[0033] Figure 6 A flowchart illustrating steps for determining a sequence of types of operating clients indicating abnormal behavior in one embodiment;

[0034] Figure 7 A schematic diagram of key steps of abnormal behavior in one embodiment;

[0035] Figure 8A schematic diagram of a process for determining a sequence of operation client types indicating abnormal behavior in one embodiment;

[0036] Figure 9 is a schematic diagram of an abnormal behavior detection architecture in one embodiment;

[0037] Figure 10 1 is a flow chart of an abnormal behavior detection method according to another embodiment;

[0038] Figure 11 is a structural block diagram of an abnormal behavior detection device in one embodiment;

[0039] Figure 12 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0041] The abnormal behavior detection method provided in the embodiments of the present application involves artificial intelligence (AI) technology. Artificial intelligence is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new type of intelligent machine that can respond in a similar way to human intelligence. Artificial intelligence is to study the design principles and implementation methods of various intelligent machines, so that machines have the functions of perception, reasoning and decision-making.

[0042] Artificial intelligence technology is an interdisciplinary subject covering a wide range of fields, encompassing both hardware-level and software-level technologies. Basic AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing technology, pre-trained model technology, operating / interactive systems, and mechatronics. Pre-trained models, also known as large models or basic models, can be widely applied to downstream tasks in various AI fields after fine-tuning. AI software technologies primarily encompass computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning. The embodiments of this application specifically relate to machine learning technology in AI.

[0043] In related technologies, to prevent abnormal behavior from negatively impacting users, closed-loop detection is often performed within the platform (client) using models such as content models and account graphs to determine whether abnormal behavior has occurred. However, related technologies cannot accurately detect abnormal behavior across multiple platforms and their coverage is incomplete. The following will illustrate this using online interaction scenarios as an example:

[0044] Before that, let's first describe the abnormal behavior that occurs in this scenario: In the online interaction scenario, on a single platform (client), there is an abnormal task group used to publish or receive false interaction tasks. The initiator of the false interaction task usually publishes the false interaction task through the abnormal task group. After joining the group, the user obtains a small amount of money by completing the false interaction task to gain the user's trust. However, during multiple amount interactions, it is very easy for users to be defrauded of large amounts of money, which brings huge risks to users.

[0045] At this time, for abnormal task groups within a single platform, the initiator can be identified by using the content model in related technologies.

[0046] However, with the continuous updating of abnormal behavior scripts, new cross-platform abnormal behaviors have emerged. These new cross-platform abnormal behavior scripts include: attracting traffic, gaining trust, switching platforms, and repeatedly performing fake interactive tasks. For example, on Client 1, which has strong business risk control capabilities, User A proactively initiates a conversation with User B, informing User B that they can earn rewards by completing fake interactive tasks. The process is simple and the benefits are immediate. This is how User B is encouraged to start performing these fake interactive tasks. This is the first stage of attracting traffic. After completing this first stage, the second stage begins: gaining trust and switching platforms. For example, User A and User B continue chatting on Client 1, which has strong business risk control capabilities, to gain User B's trust. The user then asks User B if they can continue the conversation long-term. If so, User B is asked to download Client 2 (which has relatively weaker business risk control capabilities) and then switch to a client with weaker business risk control capabilities. The third stage begins: repeatedly performing fake interactive tasks. For example, User A sends tasks to User B, User C, and so on on Client 2, encouraging them to repeatedly perform these fake interactive tasks until they realize they have been scammed.

[0047] In the above abnormal behavior scenario, the implementation of abnormal behavior spans multiple platforms, which makes it difficult for related technologies to accurately detect abnormal behavior. That is, the coverage of abnormal behavior detection is insufficient, resulting in poor abnormal behavior detection results.

[0048] The abnormal behavior detection method provided by the embodiment of the present application receives multiple buried point data sent in sequence by the target terminal based on the buried point reporting mechanism. The buried point data is automatically sent by the target terminal when a preset operation is triggered on the client on the target terminal. Each buried point data includes at least the client identifier of the client that triggers the preset operation. According to the client type corresponding to the client identifier in the buried point data received in sequence, the operation client type sequence corresponding to the target terminal is determined; the preset operation client type sequence indicating abnormal behavior is obtained. Since the operation client type sequence indicating abnormal behavior is a sequence formed by arranging the client types of the operation clients involved in abnormal behavior, and there are multiple client types involved in abnormal behavior, that is, the operation client type sequence indicating abnormal behavior reflects abnormal behavior across clients. Therefore, by matching the operation client type sequence corresponding to the target terminal with the operation client type sequence indicating abnormal behavior in real time, it is possible to detect whether the target terminal has abnormal behavior across multiple clients. In this way, when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result indicating that abnormal behavior has occurred on the target terminal is obtained in a timely manner. Based on this, cross-client abnormal behavior detection is achieved, the coverage of abnormal behavior detection is improved, and the abnormal behavior detection effect is improved.

[0049] The abnormal behavior detection method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the target terminal 102 communicates with the server 104 via a network. The data storage system can store data that the server 104 needs to process. The data storage system can be integrated on the server 104 or placed on the cloud or other servers.

[0050] Optionally, the server 104 receives multiple buried point data sent in sequence by the target terminal 102 based on the buried point reporting mechanism. The buried point data is sent by the target terminal 102 when a preset operation is triggered on the client on the target terminal 102. Each buried point data includes at least the client identifier of the client that triggers the preset operation; according to the client type corresponding to the client identifier in the buried point data received in sequence, the operation client type sequence corresponding to the target terminal 102 is determined; a preset operation client type sequence indicating abnormal behavior is obtained, and the operation client type sequence indicating abnormal behavior is a sequence formed by arranging the client types involved in abnormal behavior in sequence, and there are multiple client types involved in abnormal behavior; when the operation client type sequence corresponding to the target terminal 102 matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result about the target terminal 102 is obtained, and the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal 102.

[0051] The target terminal 102 is a terminal, which may be, but is not limited to, various mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, aircraft, etc. The server 104 may be implemented as an independent server or a server cluster consisting of multiple servers.

[0052] In one embodiment, Figure 2 As shown, a method for detecting abnormal behavior is provided. Figure 1 Taking the server 104 in the example as an example, the following steps are included:

[0053] Step S202, receiving multiple buried point data sent in sequence by the target terminal based on the buried point reporting mechanism. The buried point data is sent by the target terminal when a preset operation is triggered on the client on the target terminal. Each buried point data includes at least the client identifier of the client that triggers the preset operation.

[0054] The target terminal is the terminal for which abnormal behavior detection is to be performed. Abnormal behavior refers to risky online interactions, such as fraudulent online interactions involving fake interactions. Another example is fraudulent investment fraud. The preset action triggered on the client on the target terminal can be launching the client or installing the client.

[0055] The point-of-sale reporting mechanism refers to the process of embedding some codes in the application to monitor specific data and sending these data to the designated server or cloud service for analysis and processing. In an embodiment of the present application, a mechanism is provided to enable the client to have the ability to report point-of-sale data by implanting a reporting code into the client when a preset operation is triggered on the client. Optionally, point-of-sale is performed in advance on the client of the type of client involved in abnormal behavior (such as a social client or a payment client) so that the client of the type of client involved in abnormal behavior has the ability to report point-of-sale data. Alternatively, point-of-sale is performed in advance on all clients involved in the target terminal of a terminal manufacturer so that all clients on the target terminal have the ability to report point-of-sale data. In this way, when a preset operation is triggered on the client on the target terminal, the client generates point-of-sale data and sends it to the server by the target terminal. Since there are multiple clients running on the target terminal, the server can receive multiple point-of-sale data sent sequentially by the target terminal based on the point-of-sale reporting mechanism.

[0056] In an embodiment of the present application, the tracking data sent by the target terminal includes at least the client identifier of the operated client. The client identifier can be represented by PCN data (P is the package name of the client, C is an integer of the client, and N is the client name). Exemplarily, the tracking data also includes the time when the preset operation is triggered on the client and the terminal identifier of the target terminal.

[0057] Optionally, the server receives a plurality of buried data reported by the target terminal within a preset time period. Each buried data is data generated by the target terminal based on the client identifier of the client after detecting that a preset operation is triggered on the client.

[0058] For example, when tracking is set only for clients of the client type involved in abnormal behavior, the server obtains multiple tracking data reported sequentially by the target terminal. The client type of the client identifier included in each tracking data is the client type involved in abnormal behavior.

[0059] For example, when all clients are tracked, when a preset operation is triggered on a client of the client type involved in abnormal behavior, the client of the client type involved in abnormal behavior will generate tracking data, and the target terminal obtains the tracking data generated by the client of the client type involved in abnormal behavior and reports the tracking data generated by the client to the server.

[0060] The target terminal designs trigger actions for tracking and reporting based on the client type involved in abnormal behavior, as shown in Table 1:

[0061] Table 1 Design of tracking point reporting action

[0062]

[0063] Step S204: Determine the operation client type sequence corresponding to the target terminal according to the client type corresponding to the client identifier in the buried data received in sequence.

[0064] The operation client type sequence represents the client types of the clients that trigger the above preset operations in sequence on the target terminal. The operation client type sequence is obtained by sorting the client types of the corresponding clients according to the time sequence of triggering the preset operations.

[0065] For example, within a preset period of time, client a belonging to client type 1, client b belonging to client type 2, and client c belonging to client type 3 in the target terminal trigger the client opening operation in sequence. Then, the operation client type sequence corresponding to the target terminal is:

[0066] Client Type 1 - Client Type 2 - Client Type 3.

[0067] For another example, within a preset period of time, client a belonging to client type 1, client b belonging to client type 2, client a belonging to client type 1, and client b belonging to client type 2 in the target terminal trigger the client open operation in sequence. Then, the operation client type sequence corresponding to the target terminal is:

[0068] Client Type 1 - Client Type 2 - Client Type 1 - Client Type 2.

[0069] Optionally, the server obtains multiple client identifiers and the trigger time corresponding to each client from multiple embedded data points, and determines the client type corresponding to each client identifier. The server sorts the corresponding client types in chronological order based on the trigger time corresponding to each client, and obtains a sequence of operation client types corresponding to the target terminal. The trigger time corresponding to the client is the time when the client triggers the preset operation.

[0070] It is understandable that, generally, the earlier the preset operation is triggered, the earlier the corresponding tracking data is sent. Therefore, the operation client type sequence can also be obtained by sorting each client type according to the order in which the client's respective tracking data is reported.

[0071] Optionally, after determining the client type corresponding to each client identifier, the server sorts the corresponding client types in chronological order according to the sending time of each buried data sent in sequence to obtain the operation client type sequence corresponding to the target terminal.

[0072] Step S206 , obtaining a preset sequence of operation client types indicating abnormal behavior. The sequence of operation client types indicating abnormal behavior is a sequence formed by sequentially arranging client types involved in abnormal behavior. There are multiple client types involved in abnormal behavior.

[0073] The client types involved in abnormal behavior refer to the client types related to the abnormal behavior. For different abnormal behaviors, the client types involved in the corresponding abnormal behavior can be the same or different. For example, with respect to abnormal behavior of false interactions, the client types involved in abnormal behavior generally include social types (such as instant messaging (IM)) and payment types. With respect to abnormal behavior of false investments, the client types involved in abnormal behavior generally include instant messaging types, payment types, and investment types.

[0074] Optionally, the preset sequence of operation client types indicating abnormal behavior can be a sequence of client types representing the clients operated in sequence by the abnormal behavior, which is set according to actual conditions or obtained through data analysis or semantic understanding. For example, when analyzing a new cross-platform abnormal behavior script, it can be found that the client types operated by the false interaction task (i.e., the abnormal behavior) include social type and payment type, and the client switches between these two types multiple times during the operation. Therefore, the operation client type sequence corresponding to the false interaction task can be determined as:

[0075] Social type-payment type-social type-payment type-social type-payment type…

[0076] Step S208 : When the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result on the target terminal is obtained, and the abnormal behavior detection result indicates that abnormal behavior occurs on the target terminal.

[0077] Wherein, if the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, it indicates that abnormal behavior has occurred on the target terminal.

[0078] Optionally, the server verifies whether the operation client type sequence corresponding to the target terminal is identical to the operation client type sequence indicating abnormal behavior. If so, the server obtains an abnormal behavior detection result for the target terminal, indicating that abnormal behavior has occurred on the target terminal. If not, the server determines that abnormal behavior has not occurred on the target terminal.

[0079] For example, the sequence of operation client types indicating abnormal behavior is: social type-payment type-social type-payment type-social type-payment type-social type-payment type;

[0080] The operation client type sequence corresponding to the target terminal is: social type-social type-social type-payment type-social type-payment type-social type-payment type-social type-payment type. It can be determined that there is a subsequence in the operation client type sequence corresponding to the target terminal that is exactly the same as the operation client type sequence indicating abnormal behavior. It can be considered that the operation client type sequence corresponding to the target terminal is the same as the operation client type sequence indicating abnormal behavior.

[0081] Optionally, the server verifies whether the operation client type sequence corresponding to the target terminal includes an operation client type sequence indicating abnormal behavior. If so, the server obtains an abnormal behavior detection result for the target terminal, the abnormal behavior detection result indicating that abnormal behavior has occurred on the target terminal. If not, the server determines that no abnormal behavior has occurred on the target terminal.

[0082] Specifically, the server can eliminate client types that do not involve abnormal behavior from the operation client type sequence corresponding to the target terminal, and check whether the operation client type subsequence composed of the remaining client types is the same as the operation client type sequence indicating abnormal behavior. If they are the same, an abnormal behavior detection result about the target terminal is obtained, and the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal.

[0083] For example, the sequence of operation client types indicating abnormal behavior is: social type-payment type-social type-payment type-social type-payment type-social type-payment type;

[0084] The operation client type sequence corresponding to the target terminal is: video type-social type-video type-payment type-shopping type-social type-payment type-social type-payment type-social type-payment type. Excluding client types that do not involve abnormal behavior, namely video type and shopping type, the obtained subsequence is: social type-payment type-social type-payment type-social type-payment type-social type-payment type. It can be determined that the operation client type sequence corresponding to the target terminal contains an operation client type sequence indicating abnormal behavior.

[0085] In some embodiments, the method further includes: sending a reminder message to the target terminal when the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal.

[0086] Exemplarily, when the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal, the server sends a reminder message to the target terminal to instruct the target terminal to display the reminder message.

[0087] Exemplarily, when the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal, the server generates a reminder message and sends the reminder message and the client identifier of the client type involved in the abnormal behavior to the target terminal. The target terminal will display the reminder message through the client corresponding to the client identifier to reduce the risk.

[0088] In this embodiment, when the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal, a reminder message is sent to the target terminal in real time, so that the target terminal can be alerted in time to reduce risks.

[0089] In the above-mentioned abnormal behavior detection method, by receiving multiple buried point data sent in sequence by the target terminal based on the buried point reporting mechanism, the buried point data is automatically sent by the target terminal when a preset operation is triggered on the client on the target terminal, and each buried point data includes at least the client identifier of the client that triggered the preset operation. According to the client type corresponding to the client identifier in the buried point data received in sequence, the operation client type sequence corresponding to the target terminal is determined; the preset operation client type sequence indicating abnormal behavior is obtained. Since the operation client type sequence indicating abnormal behavior is a sequence formed by arranging the client types of the operation clients involved in abnormal behavior, and there are multiple client types involved in abnormal behavior, that is, the operation client type sequence indicating abnormal behavior reflects abnormal behavior across clients. Therefore, by matching the operation client type sequence corresponding to the target terminal with the operation client type sequence indicating abnormal behavior in real time, it is possible to detect whether the target terminal has abnormal behavior across multiple clients. In this way, when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result indicating that abnormal behavior has occurred on the target terminal is obtained in a timely manner. Based on this, cross-client abnormal behavior detection is achieved, the coverage of abnormal behavior detection is improved, and the abnormal behavior detection effect is improved.

[0090] In some embodiments, the method also includes: obtaining client installation timing text corresponding to each of the multiple sample devices; using the client installation timing text as a sentence and the client identifier in the client installation timing text as a word, obtaining the word vector corresponding to each word based on the sentence through a word vector model; clustering the corresponding client identifiers based on the word vector corresponding to each word; according to the clustering results, obtaining the clustering cluster corresponding to the client type involved in the abnormal behavior, and determining the client represented by each client identifier in the clustering cluster as the client type involved in the abnormal behavior.

[0091] The sample devices include both terminals that have not yet experienced abnormal behavior and terminals that have experienced abnormal behavior. The client installation sequence text for each sample device is a text file that is generated by sequentially arranging the corresponding client identifiers based on the installation time of the client on the sample device. The client installation sequence text contains multiple client identifiers arranged in chronological order of installation time.

[0092] A word vector model is a model used to determine the vector of a word. For example, the word vector model can be a model built based on Glove (Global vectors for word representation) or a model built based on Word2vec (Word embeddings).

[0093] Specifically, the server obtains the client installation timing text corresponding to each sample device within a preset historical period, inputs each client installation timing text into a word vector model, and outputs the word vector corresponding to each client identifier included in multiple client installation timing texts.

[0094] In some embodiments, obtaining the client installation timing text corresponding to each of the multiple sample devices includes: obtaining the installation flow data of each client on the sample device; obtaining the installation sequence of each client on the same sample device based on the installation flow data; and sorting the client identifiers of the corresponding clients in sequence according to the installation sequence to obtain the client installation timing text corresponding to the sample device.

[0095] The installation flow data is the data obtained by recording the installation of the client on the sample device. The installation flow data at least includes the device identification of the sample device, the installation time of each client on the sample device, and the identification of each client. For example, the installation flow data is shown in Table 2:

[0096] Table 2 Installation flow data table

[0097]

[0098] Optionally, the server obtains the installation flow data of each sample device within a preset historical period. For each sample device, the server parses the client identifiers and the installation time of each client identifier from the corresponding installation flow data, sorts the client identifiers in chronological order of installation time, and obtains the client installation timing text corresponding to the sample device.

[0099] For example, the client installation timing text of each sample device is summarized as shown in Table 3:

[0100] Table 3 Client installation sequence text table for each sample device

[0101]

[0102] In this embodiment, the installation sequence of each client on the same sample device is parsed based on the installation flow data. The client identifiers of the corresponding clients are then sorted in this order to obtain the client installation sequence text corresponding to the sample device. In this way, the word embedding model uses each client in the client installation sequence text as a word and fully learns the relationship between adjacent words in the context. This ensures that the word embedding distances of similar clients are closer, thereby ensuring the accuracy and effectiveness of subsequent clustering results.

[0103] Clustering in this embodiment is the process of grouping similar client identifiers together. For example, clustering is performed based on the similarity between word vectors, resulting in multiple clusters. The similarity can be one of the cosine distance, Euclidean distance, and Manhattan distance between word vectors. The clustering results include multiple clusters, each corresponding to a client type, and each cluster containing multiple similar client identifiers belonging to the corresponding client type.

[0104] The server obtains the client identifier and the corresponding client type involved in the abnormal behavior. The server selects the cluster where the client identifier is located from each cluster in the clustering result, and uses the queried cluster as the cluster corresponding to the client type involved in the abnormal behavior, that is, the clients represented by each client identifier in the cluster all belong to the client type involved in the abnormal behavior.

[0105] Exemplarily, the server obtains client installation sequence texts 1, ..., and client installation sequence text m, wherein n client identifiers such as social client a, payment client b, and shopping client c are counted in the m client installation sequence texts. The m client installation sequence texts are input into a word vector model constructed based on word2vec, and the word vector corresponding to each client identifier with the same dimension is output. The word vector dimension is L, where L is a positive integer, as shown in Table 4:

[0106] Table 4 Word vector table corresponding to client identifier

[0107] Client Identification Word vector (L dimension) Social Client a [0.0034203744 0.0040682405…-0.0025722822] Payment client b [0.061663732 0.025000155…-0.038062602] Shopping client c [-0.014806328 -0.033496264…0.04651376] … …

[0108] It should be noted that the installation of a client involved in abnormal behavior is usually after or before the installation of another client involved in abnormal behavior. That is, the installation of multiple clients involved in abnormal behavior is adjacent. Therefore, the client installation time series text is used as a sentence, and the client identifier in the client installation time series text is used as a word. The word vector model can fully learn the relationship between adjacent words in the context environment during training, so that the word vector distance of similar clients is closer, thereby ensuring the accuracy and effectiveness of subsequent clustering results.

[0109] In some embodiments, based on the word vector corresponding to each word, the corresponding client identifiers are clustered, including: the word vectors corresponding to m client identifiers randomly selected from multiple client identifiers are all used as cluster centers, where m is an integer greater than 1; each client identifier is assigned to the cluster cluster where the nearest cluster center is located according to the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers; the cluster centers of each cluster cluster are updated according to the word vectors corresponding to the client identifiers contained in each cluster cluster to obtain the updated m cluster centers, and the step of assigning each client identifier to the cluster cluster where the nearest cluster center is located according to the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers is returned and continued until the clustering stop condition is met to obtain the clustering result.

[0110] For example, the server randomly selects m client identifiers from multiple client identifiers and uses the word vectors of the randomly selected client identifiers as cluster centers. The server calculates the distance between the word vector of each client identifier and each distance center, and for each word vector of the client identifier, the word vector is assigned to the cluster cluster with the closest cluster center.

[0111] For each cluster, the server calculates the mean of the word vectors in the cluster and updates the cluster center based on the mean to obtain the updated cluster center. The server returns and calculates the distance from each client's word vector to each distance center, and continues to execute until the m cluster centers are no longer changing.

[0112] In this embodiment, each client identifier is clustered through each word vector to group similar client identifiers into a cluster. Subsequently, based on the clustering results, the cluster corresponding to the client type involved in abnormal behavior can be accurately determined. In this way, the client represented by each client identifier in the cluster can be directly determined as the client type involved in abnormal behavior.

[0113] For example, Figure 3As shown, it is a schematic diagram of the clustering results in one embodiment. Clustering is performed based on the word vectors corresponding to each client identifier in Table 4, and three clusters are obtained: cluster 1, cluster 2 and cluster 3. Among them, cluster 1 includes App1 of the social type involving abnormal behavior, then the other client identifiers (App2, App3, App4) included in cluster 1 can be identified as social type client identifiers; cluster 2 includes App5 of the payment type involving abnormal behavior, then the other types of client identifiers (App6, App7) included in cluster 2 can be identified as payment type client identifiers. Cluster 3 includes client identifiers of client types that do not involve abnormal behavior, such as, cluster 3 includes customer identifiers (App8 and App9) belonging to the shopping type, and the shopping type is a client type that does not involve abnormal behavior.

[0114] Table 5 Client types and corresponding PCN data

[0115]

[0116] For the sake of distinction, all client types that do not involve abnormal behavior can be regarded as other types (or preset specified types), that is, the shopping types in Table 5 can be classified as other types.

[0117] In this embodiment, by obtaining the client installation sequence text corresponding to each of the multiple sample devices, more clients can be clustered, and subsequently more clients belonging to the client type involved in abnormal behavior can be found. In this way, when actually performing abnormal behavior detection, the detection range can be expanded and the detection coverage rate can be improved. In addition, using the client installation sequence text as a sentence and the client identifier in the client installation sequence text as a word, the word vector model is combined with the context to learn the association between words and accurately identify the word vector corresponding to each word. Based on the word vector corresponding to each word, the corresponding client identifier is clustered to ensure the accuracy and effectiveness of the clustering. According to the clustering results, the cluster cluster corresponding to the client type involved in abnormal behavior is accurately determined. In this way, the client represented by each client identifier in the cluster cluster can be directly determined as the client type involved in abnormal behavior.

[0118] In some embodiments, as Figure 4 FIG. 1 is a flow chart of the steps for determining the client type in one embodiment. The specific steps are as follows:

[0119] Step S402: The server obtains the client installation flow data of each sample device.

[0120] Exemplarily, the server obtains the installation data sent by each terminal manufacturer, wherein the installation data sent by each terminal manufacturer includes the client installation flow data of multiple sample devices belonging to the terminal manufacturer.

[0121] Step S404: The server obtains the installation sequence of each client on the same sample device according to the installation flow data; sorts the client identifiers of the corresponding clients in order according to the installation sequence to obtain the client installation sequence text corresponding to the sample device.

[0122] Step S406: The server inputs the installation sequence texts of each client into a word vector model to obtain a word vector of each client identifier involved in the multiple client installation sequences.

[0123] Step S408: The server clusters each word vector to obtain a clustering result.

[0124] Step S410: The server obtains a cluster corresponding to the client type involved in abnormal behavior based on the clustering result, and determines the client represented by each client identifier in the cluster as the client type involved in abnormal behavior.

[0125] Optionally, the server determines the client identifier and the corresponding client type involved in the abnormal behavior, and filters out the cluster cluster where the client identifier is located from the clustering results, and uses the filtered cluster cluster as the cluster cluster corresponding to the client type involved in the abnormal behavior. All clients identified by the client identifiers included in the filtered cluster cluster belong to the client type involved in the abnormal behavior.

[0126] It should be noted that due to the increasing diversification of user needs, new clients are constantly being developed. To ensure the accuracy and coverage of abnormal behavior detection and avoid missing new clients, steps S402 to S410 are performed every target time period to update the clusters of client types involved in abnormal behavior. In other words, clustering is performed every target time period to continuously expand the clusters of client types involved in abnormal behavior.

[0127] In this embodiment, by obtaining the client installation time-series text corresponding to multiple sample devices, more clients can be clustered. Subsequently, more clients belonging to the client type involved in abnormal behavior can be found. This expands the detection scope and improves the detection coverage during actual abnormal behavior detection. Furthermore, by using the client identifiers in each client installation time-series text as words, a word vector model is combined with context to learn the associations between words, accurately identify the word vector corresponding to each word, and perform clustering, thereby accurately determining the client type of each client identifier.

[0128] In some embodiments, as Figure 5 The figure is a flow chart of the steps for determining the operation client type corresponding to the target terminal in one embodiment. According to the client type corresponding to the client identifier in the buried data sent in sequence, the operation client type sequence corresponding to the target terminal is determined, including:

[0129] Step S502: For each buried point data received in sequence, parse the buried point data to obtain the client identifier of the client that triggers the preset operation.

[0130] Step S504 : Match the parsed client identifier of the client that triggers the preset operation with the client identifier set corresponding to the client type involved in the abnormal behavior to obtain the client type of the client that triggers the preset operation.

[0131] The client identifier set corresponding to the client type involved in abnormal behavior is the aforementioned cluster corresponding to the client type involved in abnormal behavior.

[0132] Optionally, the server determines whether the parsed client identifier matches a set of client identifiers corresponding to the client type involved in abnormal behavior, and obtains a corresponding matching result. If the matching result indicates that no client identifier set corresponding to the client type involved in abnormal behavior matches the client identifier, the client type of the parsed client segment identifier is determined to be a client type not involved in abnormal behavior. If the matching result indicates that a client identifier set corresponding to the client type involved in abnormal behavior matches the client identifier, the client type involved in abnormal behavior corresponding to the matched client identifier set is used as the client type of the client identifier.

[0133] For example, there are two client identifier sets corresponding to client types involved in abnormal behavior: a payment type client identifier set and a social type client identifier set. If a client identifier matches the payment type client identifier set, the client type of the client identifier is a payment type. If the client identifier matches neither the payment type client identifier set nor the social type client identifier set, the client type of the client identifier is not involved in abnormal behavior and can be classified as other types.

[0134] In some embodiments, the parsed client identifier of the client that triggers the preset operation is matched with the client identifier set corresponding to the client type involved in abnormal behavior to obtain the client type of the client that triggers the preset operation, including: for each parsed client identifier of the client that triggers the preset operation, verifying whether the client identifier belongs to the client identifier set corresponding to the client type involved in abnormal behavior; if it belongs to the client identifier set corresponding to the client type involved in abnormal behavior, then the client type corresponding to the client identifier set is used as the client type of the client that triggers the preset operation; if it does not belong to the client identifier set corresponding to the client type involved in abnormal behavior, then determining that the client type of the client that triggers the preset operation is a preset specified type, and the preset specified type is a client type that does not involve abnormal behavior.

[0135] Exemplarily, after determining the client identifiers of the respective clients that trigger the preset operation on the target terminal, the server selects, from all client identifier sets, a client identifier set corresponding to the client type involved in the abnormal behavior.

[0136] For each client identifier, the server checks whether the client identifier is included in a client identifier set corresponding to a client type involved in abnormal behavior.

[0137] If so, the client type involved in the abnormal behavior corresponding to the client identifier set is used as the client type of the client represented by the client identifier.

[0138] If not, the server determines that the client represented by the client identifier belongs to a client type that does not involve abnormal behavior, for example, the client represented by the client identifier belongs to a preset specified type (other type).

[0139] In this embodiment, for each parsed client identifier, it is not necessary to traverse all client identifier sets. Instead, it is only necessary to traverse the client identifier set corresponding to the client type involved in the abnormal behavior to verify whether there is a client identifier set corresponding to the client type involved in the abnormal behavior that includes the client identifier. This simplifies the client type determination step and ensures the accuracy of the client type determination, thereby improving the efficiency of client type determination.

[0140] Step S506 , according to the order in which each buried point data is received, the client types of the corresponding clients that trigger the preset operation are sorted in sequence to obtain an operation client type sequence corresponding to the target terminal.

[0141] For example, the client identifiers corresponding to each tracking data point are: social client a, payment client b, social client a, payment client b, social client a, payment client b, social client a, payment client b. The operation client type sequence corresponding to the target terminal is: social type-payment type-social type-payment type-social type-payment type-social type-payment type.

[0142] For example, social client a, payment client b, social client h, payment client 1, social client j, payment client k, social client m, and payment client n. The target terminal corresponds to the following sequence of operation client types: social type - payment type - social type - payment type - social type - payment type - social type - payment type.

[0143] In this embodiment, the client identifiers that trigger preset operations on the target terminal are first parsed. Then, by matching the client identifiers with the set of client identifiers corresponding to the client types involved in abnormal behavior, the client types of the client identifiers can be promptly and accurately determined. Finally, the client types of the client identifiers are sorted sequentially according to the order of the embedded data, which allows the target terminal to quickly obtain the corresponding operation client type sequence, improving the efficiency of determining the operation client type sequence on the target terminal side.

[0144] In some embodiments, as Figure 6 FIG. 1 is a flow chart of steps for determining a sequence of client operation types indicating abnormal behavior in one embodiment. The steps for determining a sequence of client operation types indicating abnormal behavior include:

[0145] Step S602 : obtaining a plurality of preset operation client type sequences, each of which is a preset sequence formed by sequentially arranging client types suspected of being involved in abnormal behavior, and the client operation time intervals corresponding to the plurality of preset operation client type sequences are different.

[0146] The plurality of preset operation client type sequences are sequences related to the same abnormal behavior, and each preset operation client type sequence includes a plurality of client types suspected of being involved in the abnormal behavior.

[0147] A client operation refers to a preset operation, such as a client installation operation or a client startup operation. The client operation interval refers to the time interval between any two clients triggering a client operation. For example, if client 1 triggers a client operation at time t1, and client 2, which is later than client 1, triggers a client operation at time t2, then the client operation interval is t2-t1. Within the same preset operation client type sequence, the client operation interval between two adjacent client types suspected of engaging in abnormal behavior is the same. Each preset operation client type sequence has a corresponding client operation interval.

[0148] Different preset operation client type sequences correspond to different client operation time intervals.

[0149] For example, the preset operation client type sequence 1 is: social type-payment type-social type-payment type-social type-payment type-social type-payment type, and the client operation time interval corresponding to the preset operation client type sequence 1 is 1 minute. The preset operation client type sequence 2 is: social type-payment type-social type-payment type-social type-payment type-social type-payment type, and the client operation time interval corresponding to the preset operation client type sequence 2 is 2 minutes. The preset operation client type sequence 3 is: social type-payment type-social type-payment type-social type-payment type-social type-payment type, and the client operation time interval corresponding to the preset operation client type sequence 2 is 3 minutes.

[0150] Optionally, the server determines multiple client types suspected of being involved in abnormal behaviors and an arrangement order of the client types suspected of being involved in abnormal behaviors that are related to the abnormal-related behaviors.

[0151] The server obtains multiple preset client operation time intervals, and the step of determining the preset operation client type sequence corresponding to each client operation time interval includes: the server arranges the multiple client types suspected of being involved in abnormal behavior in sequence according to the client operation time interval and the arrangement order of each client type suspected of being involved in abnormal behavior, to obtain the preset operation client type sequence corresponding to the client operation time interval.

[0152] Different abnormal behaviors have corresponding behavioral characteristics. For example, in online interaction scenarios, abnormal behaviors related to fake interactions are repetitive. Another example is abnormal behaviors related to fake investments.

[0153] For example, consider the case of abnormal behavior involving fake interactions: The client types involved in this abnormal behavior include social and payment clients. As previously mentioned, opening the social client followed by the payment client constitutes a unit sequence. The repetitive nature of this abnormal behavior refers to the repetition of this unit sequence multiple times.

[0154] Based on this, in other embodiments, the step of determining a preset operation client type sequence corresponding to each client operation time interval includes: the server determining a target number of repetitions corresponding to the abnormal behavior, and, based on the client operation time interval, sequentially arranging multiple client types suspected of being involved in the abnormal behavior in the order of arrangement of the client types suspected of being involved in the abnormal behavior to determine a corresponding unit sequence. The unit sequence is repeatedly spliced ​​according to the target number of repetitions to obtain the corresponding preset operation client type sequence.

[0155] For example, the target number of repetitions of the abnormal behavior regarding false interaction is 4 times, and the client operation time interval is 1 minute. The specific form of the preset operation client type sequence corresponding to the client operation time interval is: open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type.

[0156] In other embodiments, the step of determining the preset operation client type sequence corresponding to each client operation time interval includes: the server obtains a preset multiple repetition times, and after determining the unit sequence, for each repetition time, the server repeatedly splices the unit sequence according to the repetition time to obtain the preset operation client type sequence corresponding to the client operation time interval and the repetition time.

[0157] For example, after determining that the client operation time interval is 1 minute, the preset number of repetitions is determined to be 3 and 4. Therefore, there are two preset operation client type sequences corresponding to the client operation time interval, namely Sequence 1 and Sequence 2. Sequence 1: Open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type; Sequence 2: Open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type - open social type - interval within 1 minute, open payment type.

[0158] Step S604: Obtain the total number of terminals matching each preset operation client type sequence.

[0159] Optionally, after determining each preset operation client type sequence, the server receives multiple buried point data reported by each terminal within a specific time period, and determines the operation client type sequence corresponding to each terminal based on the multiple buried point data corresponding to each terminal. For each preset operation client type sequence, the server counts the number of terminals that match the preset operation client type in the operation client type sequences corresponding to each of the multiple terminals, and determines this number as the total number of terminals that hit the preset operation client type sequence.

[0160] For example, let's assume that the specific form of preset operation client type sequence 1 is: open social type - 20 minute interval, open payment type - open social type - 20 minute interval, open payment type - open social type - 20 minute interval, open payment type - open social type - 20 minute interval, open payment type. Within a specific time period, the number of terminals that hit this preset operation client type sequence 1 is 1000.

[0161] Step S606 : For any preset operation client type sequence, determine the abnormal behavior hit rate corresponding to each preset operation client type sequence according to the total number of terminals that hit the preset operation client type sequence and the number of abnormal behaviors that occur when hitting the preset operation client type sequence.

[0162] Optionally, for each preset operation client type sequence, the server determines the number of times abnormal behavior occurs in the terminals that hit the preset operation client type sequence, and calculates the ratio of the number to the total number of terminals that hit the preset operation client type sequence to obtain the abnormal behavior hit rate corresponding to the preset operation client type sequence.

[0163] Among them, the higher the abnormal behavior hit rate, the higher the probability that the corresponding preset operation client type sequence will have abnormal behavior.

[0164] For example, if it is determined that 50 of the 1000 terminals that hit the preset operation client type sequence 1 have abnormal behaviors, then the abnormal behavior hit rate of the preset operation client type sequence 1 is 5%.

[0165] Step S608 : determining an operation client type sequence indicating abnormal behavior from a plurality of preset operation client type sequences according to the abnormal behavior hit rate.

[0166] Exemplarily, the server obtains the abnormal behavior hit rate corresponding to each preset operation client type sequence, and based on each abnormal behavior hit rate, screens out the preset operation client type sequence corresponding to the highest abnormal behavior hit rate from multiple preset operation client type sequences, and determines it as the operation client type sequence indicating abnormal behavior.

[0167] The server uses the client type suspected of having abnormal behavior in the pre-selected sequence of client types as the client type involved in abnormal behavior. The corresponding client operation time interval is the target time interval, and the corresponding number of repetitions is the target number of repetitions.

[0168] For example, when the preset client operation time intervals are 20 minutes, 10 minutes, and 3 minutes, respectively, and the target number of repetitions is 4, there are preset operation client type sequence 1 (client operation time interval is 20 minutes, target number of repetitions is 4), preset operation client type sequence 3 (client operation time interval is 10 minutes, target number of repetitions is 4), and preset operation client type sequence 3 (client operation time interval is 3 minutes, target number of repetitions is 4). For details, see the following Table 6, where social payment terminal a in Table 6 is a social type client, and payment client b is a payment type client:

[0169] Table 6 Summary of preset operation client type sequences

[0170]

[0171] As shown in Table 6, the third preset operation client type sequence has the highest abnormal behavior hit rate and is determined to be the operation client type sequence indicating abnormal behavior.

[0172] In this embodiment, after obtaining various preset client type sequences with different client operation time intervals, the total number of terminals that hit each preset client type sequence is determined. For any preset client type sequence, the abnormal behavior hit rate for each preset client type sequence is accurately estimated based on the total number of hits and the number of abnormal behaviors occurring in the hit terminals. This allows for rapid and accurate screening of abnormal behavior-matching client type sequences based on the abnormal behavior hit rates, improving the effectiveness of determining abnormal behavior-indicating client type sequences.

[0173] In some embodiments, the step of determining the type of client suspected of being involved in abnormal behavior related to abnormal behavior includes: obtaining an abnormal behavior script related to the abnormal behavior, performing semantic understanding on the abnormal behavior script, and determining the type of client suspected of being involved in abnormal behavior related to the abnormal behavior.

[0174] Optionally, after the server obtains the abnormal behavior script related to the abnormal behavior, it obtains a large language model and prompt corpus, where the prompt corpus includes prompt questions and prompt answers, and the prompt answers are used to reply to the client types involved in the prompt questions; the prompt corpus and the obtained abnormal behavior script are input into the large language model, and the client types suspected of being involved in the abnormal behavior are output.

[0175] For example, after obtaining the abnormal behavior script related to the abnormal behavior, the abnormal behavior script is analyzed to determine the key steps related to the abnormal behavior, and the description text and prompt corpus related to the key steps are input into the large language model to obtain the client type suspected of being involved in the abnormal behavior.

[0176] For example, take the abnormal behavior regarding fake interactions, e.g. Figure 7 The figure shows a schematic diagram of the key steps of abnormal behavior in one embodiment. Step 1: diversion, that is, diversion through various channels (such as web pages, groups, short videos, etc.); Step 2: Gain trust, that is, first add friends to chat on software A (such as a client with strong business risk control capabilities), and gain the trust of the target user through small fake interactive tasks on software A. Step 3: Transfer platform, that is, guide the target user to download another software B (such as a social client with weak risk control capabilities), and pull the task group into the software B. Step 4: Repeatedly perform fake interactive tasks, that is, receive tasks in software B, and switch to payment software C, and repeat this cycle many times. The key step is determined to be step 4 from the abnormal behavior script. At this time, the description text related to step 4 can be directly input into the large language model, and the client types suspected of being involved in abnormal behavior are payment type and social type respectively.

[0177] In this embodiment, by performing semantic understanding on abnormal behavior scripts related to abnormal behavior, the client types suspected of being involved in abnormal behavior related to abnormal behavior can be accurately located from the abnormal behavior scripts, which is beneficial to improving the accuracy of subsequent operation client type sequences indicating abnormal behavior.

[0178] In some embodiments, the method also includes: if the operation client type sequence corresponding to the target terminal includes an operation client type sequence indicating abnormal behavior, then determining that the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior; if the operation client type sequence corresponding to the target terminal does not include an operation client type sequence indicating abnormal behavior, then determining that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

[0179] Optionally, the server determines the client operation time interval corresponding to the operation client type sequence indicating abnormal behavior as the target time interval. If the operation client type sequence corresponding to the target terminal includes the operation client type sequence indicating abnormal behavior, it is checked whether the preset operation time intervals corresponding to two adjacent client types involved in abnormal behavior in the operation client type sequence corresponding to the target terminal are less than or equal to the target time interval. If so, it is determined that the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior.

[0180] If not, it is determined that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

[0181] If the operation client type sequence corresponding to the target terminal does not include the operation client type sequence indicating abnormal behavior, it is determined that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

[0182] For example, if the client types related to abnormal behavior include social type and payment type. Figure 8 FIG. 1 is a schematic diagram of a process for determining an operation client type sequence indicating abnormal behavior in one embodiment. Figure 8 The middle unit sequence is to open the social category and then open the payment category within 3 minutes. The target number of repetitions for the unit sequence is 4. Repeating the unit sequence 4 times will result in an operation client type sequence indicating abnormal behavior, namely: open the social category - within 3 minutes, open the payment category - open the social category - within 3 minutes, open the payment category - open the social category - within 3 minutes, open the payment category - open the social category - within 3 minutes, open the payment category - open the social category - within 3 minutes, open the payment category.

[0183] For example, the server obtains the operation client type sequence corresponding to each terminal, which are the operation client type sequence corresponding to terminal 1 and the operation client type sequence corresponding to terminal 2, as shown in Table 7 below:

[0184] Table 7 Operation client type sequence table corresponding to each terminal

[0185]

[0186] The other types in Table 7 are the preset specified types mentioned above. For Terminal 1 in Table 7, the corresponding operation client type sequence is: Open social type - interval within 3 minutes, open payment type - open social type - interval within 3 minutes, open payment type - open social type - interval within 3 minutes, open payment type - open social type - interval within 3 minutes, open payment type.

[0187] The operation client type sequence matches the operation client type sequence indicating abnormal behavior, and the social client a that reported for the first time and the payment client b that reported for the last time are the matching start point and the matching end point, respectively.

[0188] For terminal 2 in Table 7, shopping client c, video client d, travel client e, game client f, and news client g are all client types that do not involve abnormal behavior. In other words, they are all preset types. Therefore, the corresponding operation client type sequence is: open social type -> open preset type within 3 minutes. This operation client type sequence does not match the operation client type sequence that indicates abnormal behavior.

[0189] In this embodiment, by comparing whether the operation client type sequence corresponding to the target terminal contains an operation client type sequence indicating abnormal behavior, sequence matching can be completed quickly and accurately, thereby improving the detection efficiency of abnormal behavior detection.

[0190] In some embodiments, the client types involved in abnormal behavior include at least a payment type and a social type, and the preset operation triggered by the client includes a client installation operation or a client startup operation.

[0191] Considering the strength of a client's risk control capabilities (their ability to manage risk), clients with strong risk control capabilities are less likely to engage in abnormal behavior, while clients with weak risk control capabilities are more likely to engage in abnormal behavior. Therefore, the client types involved in abnormal behavior can include those with weak risk control capabilities. Alternatively, all client types have weak risk control capabilities.

[0192] For example, the payment type can be a payment type with weak risk control capability or a payment type with strong risk control capability, and the social type can be a social type with weak risk control capability or a social type with strong risk control capability, without specific limitation.

[0193] In this embodiment, the client types involved in abnormal behavior include at least payment and social types, and the preset operations triggered by the client include client installation or client startup. This allows accurate detection of the operation of the client types involved in abnormal behavior, timely completion of abnormal behavior detection, and improved efficiency of abnormal behavior detection.

[0194] The present application also provides an application scenario, which applies the above-mentioned abnormal behavior detection method. Specifically, the application of the abnormal behavior detection method in this application scenario is as follows: in an online interaction scenario, in order to be able to comprehensively and accurately detect abnormal behaviors related to false interactions, improve detection coverage, and improve detection effects. The abnormal behavior detection method provided by the present application can be used, specifically as follows: the server receives multiple buried point data sent in sequence by the target terminal based on the buried point reporting mechanism, the buried point data is sent by the target terminal when a preset operation is triggered on the client on the target terminal, and each buried point data includes at least the client identifier of the client that triggers the preset operation; according to the client type corresponding to the client identifier in the buried point data received in sequence, the operation client type sequence corresponding to the target terminal is determined; a preset operation client type sequence indicating abnormal behavior is obtained, the operation client type sequence indicating abnormal behavior is a sequence formed by sequentially arranging the client types involved in abnormal behavior, and there are multiple client types involved in abnormal behavior; when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result about the target terminal is obtained, and the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal. Among them, the client types involved in abnormal behavior in this scenario include social type and payment type.

[0195] Of course, it is not limited to this. The abnormal behavior detection method provided in this application can also be applied in other application scenarios. For example, in an online investment scenario, the abnormal behavior detection method provided in this application can be used to detect abnormal behaviors related to false investments. The client types involved in abnormal behaviors in this scenario include social type, payment type, and investment type.

[0196] The above application scenarios are merely illustrative. It should be understood that the application of the abnormal behavior detection methods provided in the embodiments of the present application is not limited to the above scenarios.

[0197] In a specific embodiment, the present application provides an abnormal behavior detection method, which involves the interaction between the server and the target terminal. Figure 9 FIG. 1 is a schematic diagram of an abnormal behavior detection architecture in one embodiment. The target terminal can be any terminal to be detected.

[0198] The following combination Figure 9 The technical concept of the abnormal behavior detection method provided in the embodiments of this application is described. During the offline phase, the server updates the PCNS list by expanding and updating the client identifier set corresponding to the client type involved in abnormal behavior at target offline time intervals. This updated PCNS list includes updated PCNS data for the client type involved in abnormal behavior. The server then updates the updated PCNS data online.

[0199] In the online stage, the target terminal reports multiple buried data, which include the client identifier that triggered the preset operation, such as the client identifier of a social client.

[0200] After acquiring multiple tracking data, the server determines the client type corresponding to the client identifier in each tracking data according to the updated PCNS data. According to the client type corresponding to the client identifier in the tracking data sent in sequence, the server arranges the client types in the order of sending time to construct the operation client type sequence corresponding to the target terminal. Figure 9 In the example, from time t1 to time tn, the client types in this period are sorted by sending time to obtain the corresponding operation client type sequence: social type, ..., payment type.

[0201] The server obtains a preset operation client type sequence related to the abnormal behavior and indicating the abnormal behavior. The operation client type sequence indicating the abnormal behavior is a sequence formed by sequentially arranging client types involved in the abnormal behavior. There are multiple client types involved in the abnormal behavior.

[0202] The server matches the operation client type sequence corresponding to the target terminal with the operation client type sequence indicating abnormal behavior. When the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, it is determined that the target terminal has abnormal behavior and a reminder message is sent to the target terminal for timely alarm.

[0203] like Figure 10 FIG. 1 is a flow chart of an abnormal behavior detection method in another embodiment.

[0204] Step S1: The server determines the type of client suspected of being involved in the abnormal behavior based on the abnormal behavior scenario. Optionally, the server obtains sample examples of the abnormal behavior, along with a large language model and prompt corpus. The prompt corpus includes prompt questions and prompt answers, with the prompt answers used to respond to the client types mentioned in the prompt questions. The prompt corpus and the obtained sample examples are input into the large language model, which outputs the type of client suspected of being involved in the abnormal behavior.

[0205] Step S2: The server determines a sequence of operation client types indicating abnormal behavior based on multiple client types suspected of being involved in abnormal behavior.

[0206] Optionally, the server obtains multiple preset operation client type sequences, each preset operation client type sequence is a preset sequence formed by arranging client types suspected of involving abnormal behavior in sequence, and the client operation time intervals corresponding to the multiple preset operation client type sequences are different; the total number of terminals that hit each preset operation client type sequence is obtained; for any preset operation client type sequence, the abnormal behavior hit rate corresponding to each preset operation client type sequence is determined based on the total number of terminals that hit the preset operation client type sequence and the number of abnormal behaviors that occur when hitting the preset operation client type sequence; based on the abnormal behavior hit rate, the operation client type sequence indicating abnormal behavior is determined from the multiple preset operation client type sequences.

[0207] The server determines the client type suspected of being involved in the abnormal behavior in the determined sequence of client types indicating abnormal behavior as the client type involved in the abnormal behavior. The client type involved in the abnormal behavior includes at least a payment type and a social type, and the preset action triggered by the client includes a client installation operation or a client startup operation.

[0208] Step S3: The server determines a set of client identifiers corresponding to the client types involved in the abnormal behavior.

[0209] Optionally, the server executes steps S3.1 to S3.3 every target time period to update the client identifier set corresponding to the client type involved in abnormal behavior (update PCNS data).

[0210] Step S3.1: The server obtains the client installation sequence text corresponding to each of the multiple sample devices.

[0211] Optionally, the server obtains the installation flow data of each client on the sample device; obtains the installation sequence of each client on the same sample device based on the installation flow data; sorts the client identifiers of the corresponding clients in sequence according to the installation sequence to obtain the client installation timing text corresponding to the sample device.

[0212] Step S3.2: The server uses the client installation time sequence text as a sentence and the client identifier in the client installation time sequence text as a word, and obtains the word vector corresponding to each word based on the sentence through the word vector model.

[0213] Step S3.3: The server clusters the corresponding client identifiers based on the word vector corresponding to each word; according to the clustering results, a cluster corresponding to the client type involved in abnormal behavior is obtained, and the client represented by each client identifier in the cluster is determined as the client type involved in abnormal behavior.

[0214] Optionally, the server randomly selects m word vectors corresponding to client identifiers from the multiple client identifiers as cluster centers, where m is an integer greater than 1; assigns each client identifier to the cluster with the nearest cluster center based on the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers; updates the cluster centers of each cluster based on the word vectors corresponding to the client identifiers contained in each cluster, obtaining m updated cluster centers; and returns the step of assigning each client identifier to the cluster with the nearest cluster center based on the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers, and continues to execute the step until the clustering stop condition is met, thereby obtaining a clustering result. The clustering result includes clusters corresponding to each client type.

[0215] Step S3.3: The server selects the cluster where the client involved in the abnormal behavior is located from the clustering results, and determines a set of client identifiers corresponding to the type of the client involved in the abnormal behavior.

[0216] Step S4: The server obtains multiple buried data reported by the target terminal, and determines the operation client type sequence corresponding to the target terminal based on the buried data and the client identifier set belonging to the client type involved in abnormal behavior.

[0217] Step S4.1: For each buried point data received in sequence, the server parses the buried point data to obtain the client identifier of the client that triggers the preset operation.

[0218] Step S4.2: Match the parsed client identifier of the client that triggers the preset operation with the client identifier set corresponding to the client type involved in the abnormal behavior to obtain the client type of the client that triggers the preset operation.

[0219] Optionally, for each client identifier parsed out that triggers a preset operation, check whether the client identifier belongs to a client identifier set corresponding to a client type involved in abnormal behavior; if it belongs to a client identifier set corresponding to a client type involved in abnormal behavior, the client type corresponding to the client identifier set is used as the client type of the client that triggers the preset operation; if it does not belong to a client identifier set corresponding to a client type involved in abnormal behavior, determine that the client type of the client that triggers the preset operation is a preset specified type, and the preset specified type is a client type that does not involve abnormal behavior.

[0220] Step S4.3: According to the order in which the buried data are received, the client types of the corresponding clients that trigger the preset operation are sorted in sequence to obtain the operation client type sequence corresponding to the target terminal.

[0221] Step S5: Match the operation client type sequence corresponding to the target terminal with the operation client type sequence indicating abnormal behavior to obtain an abnormal behavior detection result.

[0222] Optionally, if the operation client type sequence corresponding to the target terminal includes an operation client type sequence indicating abnormal behavior, it is determined that the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior; if the operation client type sequence corresponding to the target terminal does not include an operation client type sequence indicating abnormal behavior, it is determined that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

[0223] When the abnormal behavior detection result indicates that abnormal behavior occurs on the target terminal, a reminder message is sent to the target terminal.

[0224] In this embodiment, by receiving multiple buried point data sent in sequence by the target terminal based on the buried point reporting mechanism, the buried point data is automatically sent by the target terminal when a preset operation is triggered on the client on the target terminal, and each buried point data includes at least the client identifier of the client that triggered the preset operation. According to the client type corresponding to the client identifier in the buried point data received in sequence, the operation client type sequence corresponding to the target terminal is determined; a preset operation client type sequence indicating abnormal behavior is obtained. Since the operation client type sequence indicating abnormal behavior is a sequence formed by arranging the client types of the operation clients involved in the abnormal behavior, and there are multiple client types involved in the abnormal behavior, that is, the operation client type sequence indicating abnormal behavior reflects abnormal behavior across clients. Therefore, by matching the operation client type sequence corresponding to the target terminal with the operation client type sequence indicating abnormal behavior in real time, it is possible to detect whether the target terminal has abnormal behavior across multiple clients. In this way, when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result indicating that abnormal behavior has occurred on the target terminal is obtained in a timely manner. Based on this, abnormal behavior detection across clients is achieved, the coverage rate of abnormal behavior detection is improved, and the abnormal behavior detection effect is improved.

[0225] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0226] Based on the same inventive concept, embodiments of the present application also provide an abnormal behavior detection device for implementing the aforementioned abnormal behavior detection method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations in one or more of the abnormal behavior detection device embodiments provided below can be found in the above-described limitations on the abnormal behavior detection method and will not be further elaborated here.

[0227] In one embodiment, Figure 11 As shown, an abnormal behavior detection device 1100 is provided, comprising: a data receiving module 1102, a sequence determination module 1104, a sequence acquisition module 1106 and a sequence matching module 1108, wherein:

[0228] The data receiving module 1102 is configured to receive a plurality of buried point data sequentially sent by the target terminal based on the buried point reporting mechanism. The buried point data is sent by the target terminal when a preset operation is triggered on a client on the target terminal. Each buried point data includes at least a client identifier of the client that triggered the preset operation.

[0229] The sequence determination module 1104 is configured to determine the operation client type sequence corresponding to the target terminal according to the client types corresponding to the client identifiers in the buried data received in sequence;

[0230] A sequence acquisition module 1106 is configured to acquire a preset sequence of operation client types indicating abnormal behavior. The sequence of operation client types indicating abnormal behavior is a sequence formed by sequentially arranging the client types involved in the abnormal behavior. There may be multiple client types involved in the abnormal behavior.

[0231] The sequence matching module 1108 is configured to obtain an abnormal behavior detection result on the target terminal when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, the abnormal behavior detection result indicating that abnormal behavior occurs on the target terminal.

[0232] In some embodiments, the device also includes a client type determination module, which is used to obtain client installation sequence texts corresponding to multiple sample devices; using the client installation sequence text as a sentence and the client identifier in the client installation sequence text as a word, obtaining the word vector corresponding to each word based on the sentence through a word vector model; clustering the corresponding client identifiers based on the word vector corresponding to each word; according to the clustering results, obtaining the clustering cluster corresponding to the client type involved in abnormal behavior, and determining the client represented by each client identifier in the clustering cluster as the client type involved in abnormal behavior.

[0233] In some embodiments, the client type determination module is used to obtain the installation flow data of each client on the sample device; obtain the installation sequence of each client on the same sample device based on the installation flow data; sort the client identifiers of the corresponding clients in sequence according to the installation sequence, and obtain the client installation timing text corresponding to the sample device.

[0234] In some embodiments, the client type determination module is used to use the word vectors corresponding to m client identifiers randomly selected from multiple client identifiers as cluster centers, where m is an integer greater than 1; assign each client identifier to the cluster cluster where the nearest cluster center is located according to the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers; update the cluster centers of each cluster cluster according to the word vectors corresponding to the client identifiers contained in each cluster cluster to obtain the updated m cluster centers, return the distance from the word vector corresponding to each client identifier in the multiple client identifiers to the m cluster centers, and continue to execute the step of assigning each client identifier to the cluster cluster where the nearest cluster center is located until the clustering stop condition is met to obtain the clustering result.

[0235] In some embodiments, the sequence determination module 1104 is used to parse the buried point data for each buried point data received in sequence to obtain the client identifier of the client that triggers the preset operation; match the parsed client identifier of the client that triggers the preset operation with the client identifier set corresponding to the client type involved in the abnormal behavior to obtain the client type of the client that triggers the preset operation; and sort the corresponding client types of the client that triggers the preset operation in sequence according to the order in which each buried point data is received to obtain the operation client type sequence corresponding to the target terminal.

[0236] In some embodiments, the sequence determination module 1104 is used to verify whether the client identifier of each client that triggers the preset operation belongs to the client identifier set corresponding to the client type involved in abnormal behavior; if it belongs to the client identifier set corresponding to the client type involved in abnormal behavior, the client type corresponding to the client identifier set is used as the client type of the client that triggers the preset operation; if it does not belong to the client identifier set corresponding to the client type involved in abnormal behavior, the client type of the client that triggers the preset operation is determined to be a preset specified type, and the preset specified type is a client type that does not involve abnormal behavior.

[0237] In some embodiments, the sequence acquisition module 1106 is further used to obtain multiple preset operation client type sequences, each preset operation client type sequence is a preset sequence formed by arranging client types suspected of involving abnormal behavior in sequence, and the client operation time intervals corresponding to the multiple preset operation client type sequences are different; obtain the total number of terminals that hit each preset operation client type sequence; for any preset operation client type sequence, determine the abnormal behavior hit rate corresponding to each preset operation client type sequence based on the total number of terminals that hit the preset operation client type sequence and the number of abnormal behaviors that occur when hitting the preset operation client type sequence; and determine the operation client type sequence indicating abnormal behavior from the multiple preset operation client type sequences based on the abnormal behavior hit rate.

[0238] In some embodiments, the sequence matching module 1108 is used to determine that the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior if the operation client type sequence corresponding to the target terminal includes an operation client type sequence indicating abnormal behavior; if the operation client type sequence corresponding to the target terminal does not include an operation client type sequence indicating abnormal behavior, determine that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

[0239] In some embodiments, the device further includes a message sending module, which is configured to send a reminder message to the target terminal when the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal.

[0240] In some embodiments, the client types involved in abnormal behavior include at least a payment type and a social type, and the preset operation triggered by the client includes a client installation operation or a client startup operation.

[0241] Each module in the abnormal behavior detection device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.

[0242] In one embodiment, a computer device is provided. The computer device may be a server or a terminal. The internal structure diagram thereof may be as follows: Figure 12 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an abnormal behavior detection method is implemented.

[0243] Those skilled in the art will understand that Figure 12 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0244] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0245] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0246] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0247] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0248] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0249] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0250] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for detecting abnormal behavior, characterized in that: The method comprises: Receive multiple buried point data sent sequentially by a target terminal based on a buried point reporting mechanism, where the buried point data is sent by the target terminal when a preset operation is triggered on a client on the target terminal, and each buried point data includes at least a client identifier of the client that triggered the preset operation; Determining an operation client type sequence corresponding to the target terminal according to the client types corresponding to the client identifiers in the tracking data received in sequence; Obtaining a preset sequence of operation client types indicating abnormal behavior, wherein the sequence of operation client types indicating abnormal behavior is a sequence formed by sequentially arranging client types involved in the abnormal behavior, and there are multiple client types involved in the abnormal behavior; When the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, an abnormal behavior detection result for the target terminal is obtained, and the abnormal behavior detection result indicates that abnormal behavior occurs on the target terminal.

2. The method according to claim 1, characterized in that The method further comprises: Obtain the client installation timing text corresponding to multiple sample devices; Taking the client installation time sequence text as a sentence and the client identifier in the client installation time sequence text as a word, obtaining a word vector corresponding to each word based on the sentence using a word vector model; Clustering the corresponding client identifiers based on the word vectors corresponding to each of the words; According to the clustering result, a cluster corresponding to the client type involved in abnormal behavior is obtained, and the client represented by each client identifier in the cluster is determined as the client type involved in abnormal behavior.

3. The method according to claim 2, characterized in that The step of obtaining the client installation timing text corresponding to each of the plurality of sample devices includes: Obtain installation flow data of each client on the sample device; Obtaining the installation sequence of each client on the same sample device according to the installation flow data; The client identifiers of the corresponding clients are sorted in sequence according to the installation sequence to obtain the client installation sequence text corresponding to the sample device.

4. The method according to claim 2, characterized in that Clustering the corresponding client identifiers based on the word vector corresponding to each word includes: The word vectors corresponding to m randomly selected client identifiers from multiple client identifiers are all used as cluster centers, where m is an integer greater than 1; According to the distances between the word vector corresponding to each client identifier in the multiple client identifiers and the m cluster centers, each client identifier is assigned to the cluster cluster where the nearest cluster center is located; According to the word vectors corresponding to the client identifiers contained in each of the clusters, the cluster centers of each cluster are updated respectively to obtain m updated cluster centers, and the distances from the word vectors corresponding to each client identifier in the multiple client identifiers to the m cluster centers are returned. The step of assigning each client identifier to the cluster cluster with the nearest cluster center is continued until the clustering stop condition is met to obtain a clustering result.

5. The method according to claim 1, wherein The determining, based on the client types corresponding to the client identifiers in the sequentially received tracking data, a sequence of operation client types corresponding to the target terminal includes: For each buried point data received in sequence, the buried point data is parsed to obtain the client identifier of the client that triggered the preset operation; Matching the parsed client identifier of the client that triggers the preset operation with a set of client identifiers corresponding to the client type involved in the abnormal behavior to obtain the client type of the client that triggers the preset operation; According to the order in which each of the buried point data is received, the client types of the corresponding clients that trigger the preset operation are sorted in sequence to obtain an operation client type sequence corresponding to the target terminal.

6. The method according to claim 5, characterized in that The step of matching the parsed client identifier of the client that triggers the preset operation with a client identifier set corresponding to the client type involved in the abnormal behavior to obtain the client type of the client that triggers the preset operation includes: For each client identifier of the client that triggers the preset operation, verify whether the client identifier belongs to the client identifier set corresponding to the client type involved in the abnormal behavior; If it belongs to the client identifier set corresponding to the client type involved in abnormal behavior, the client type corresponding to the client identifier set is used as the client type of the client that triggers the preset operation; If it does not belong to the client identifier set corresponding to the client type involving abnormal behavior, it is determined that the client type of the client triggering the preset operation is a preset specified type, and the preset specified type is a client type not involving abnormal behavior.

7. The method according to claim 1, characterized in that The step of determining a sequence of operation client types indicating abnormal behavior comprises: Acquire multiple preset operation client type sequences, each of the preset operation client type sequences being a preset sequence formed by sequentially arranging client types suspected of being involved in abnormal behavior, and the multiple preset operation client type sequences corresponding to different client operation time intervals; Obtaining the total number of terminals that hit each of the preset operation client type sequences; For any of the preset operation client type sequences, determining an abnormal behavior hit rate corresponding to each of the preset operation client type sequences according to the total number of terminals that hit the preset operation client type sequence and the number of abnormal behaviors that occur when hitting the preset operation client type sequence; An operation client type sequence indicating abnormal behavior is determined from the plurality of preset operation client type sequences according to the abnormal behavior hit rate.

8. The method according to claim 1, characterized in that The method further comprises: If the operation client type sequence corresponding to the target terminal includes the operation client type sequence indicating abnormal behavior, determining that the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior; If the operation client type sequence corresponding to the target terminal does not include the operation client type sequence indicating abnormal behavior, it is determined that the operation client type sequence corresponding to the target terminal does not match the operation client type sequence indicating abnormal behavior.

9. The method according to claim 1, characterized in that The method further comprises: When the abnormal behavior detection result indicates that abnormal behavior occurs on the target terminal, a reminder message is sent to the target terminal.

10. The method according to any one of claims 1 to 9, characterized in that The client types involved in abnormal behaviors include at least payment types and social types, and the preset operations triggered by the client include client installation operations or client startup operations.

11. An abnormal behavior detection device, characterized in that: The device comprises: A data receiving module is configured to receive a plurality of buried point data sequentially sent by a target terminal based on a buried point reporting mechanism, wherein the buried point data is sent by the target terminal when a preset operation is triggered on a client on the target terminal, and each buried point data includes at least a client identifier of the client that triggered the preset operation; A sequence determination module, configured to determine an operation client type sequence corresponding to the target terminal according to the client types corresponding to the client identifiers in the buried data received in sequence; A sequence acquisition module, configured to acquire a preset sequence of operation client types indicating abnormal behavior, wherein the sequence of operation client types indicating abnormal behavior is a sequence formed by sequentially arranging client types involved in abnormal behavior, and there are multiple client types involved in abnormal behavior; A sequence matching module is used to obtain an abnormal behavior detection result about the target terminal when the operation client type sequence corresponding to the target terminal matches the operation client type sequence indicating abnormal behavior, wherein the abnormal behavior detection result indicates that abnormal behavior has occurred on the target terminal.

12. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.