Transaction security management method, device and equipment and readable storage medium
By building transaction resource flow information and multi-dimensional analysis, the problem of low transaction security management accuracy in existing technologies has been solved, and higher detection accuracy has been achieved.
Patent Information
- Application Number
- CN202410362530.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-26
- Publication Date
- 2025-09-26
AI Technical Summary
In the existing technology, when unsafe transaction behaviors are detected through expert rules, the detection features are single, resulting in low accuracy of transaction security management.
By obtaining the transaction information of the target object, constructing transaction resource flow information, and combining account information and transaction feature information, calculating transaction security information, and using multi-dimensional analysis to improve detection accuracy.
It improves the accuracy of transaction security management and ensures the accuracy of detection of unsafe transactions.
Smart Images

Figure CN120707135A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a transaction security management method, apparatus, device, and readable storage medium. Background Art
[0002] Mobile payment is a digital payment method that allows users to conduct financial transactions through mobile devices such as smartphones and tablets. However, in actual payment scenarios, there are some unsafe transaction behaviors, so these transaction behaviors need to be detected.
[0003] In related technologies, detecting unsafe transactions often involves analyzing past cases to identify characteristics of these behaviors and developing expert rules to prevent them. However, using expert rules to detect unsafe transactions can fail to accurately identify transaction security due to the limited number of features detected, resulting in low accuracy in transaction security management.
[0004] Therefore, how to improve the accuracy of transaction security management is an urgent problem to be solved. Summary of the Invention
[0005] To solve the above technical problems, embodiments of the present application provide a transaction security management method, apparatus, device, and computer-readable storage medium.
[0006] Among them, the technical solutions adopted in this application are:
[0007] A transaction security management method, comprising:
[0008] Obtain transaction information of the target object within a preset time period;
[0009] Acquire other objects associated with the target object based on the transaction information of the target object, and construct transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects;
[0010] Calculating transaction security information of the target object based on the transaction resource flow information, the target object's account information, transaction feature information between the target object and the other objects, preset transaction resource flow information, preset account information, and preset transaction feature information;
[0011] The transaction triggered by the target object is securely managed based on the transaction security information.
[0012] A transaction security management device, comprising:
[0013] An acquisition unit, configured to acquire transaction information of a target object within a preset time period;
[0014] a processing unit configured to detect other objects associated with the target object based on the transaction information of the target object, and construct transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects;
[0015] a calculation unit, configured to calculate the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature information between the target object and the other objects, the preset transaction resource flow information, the preset account information, and the preset transaction feature information;
[0016] The processing unit is further configured to perform security management on the transaction triggered by the target object based on the transaction security information.
[0017] In one embodiment of the present application, based on the aforementioned scheme, the other objects include at least one of a first object and a second object; the processing unit is further used to construct transaction resource flow information corresponding to the target object based on a second object associated with at least one of the target object and the first object if it is detected that there are transferred transaction resources between the target object and the first object.
[0018] In one embodiment of the present application, based on the aforementioned scheme, the processing unit is further used to construct transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the second object and the target object, if there is a second object associated with the target object, and the second object and the first object are not associated with each other.
[0019] In one embodiment of the present application, based on the aforementioned scheme, the processing unit is further used to construct transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, the transaction resource transfer direction between the second object and the target object, and the transaction resource transfer direction between the first object and the second object, if there is a second object associated with both the target object and the first object.
[0020] In one embodiment of the present application, based on the aforementioned scheme, the acquisition unit is further used to obtain the preset account information, and the preset account information includes account information whose transaction security is lower than a preset security threshold; the calculation unit is further used to calculate the account similarity between the account information of the target object and the preset account information; and calculate the transaction security information of the target object based on the transaction resource flow information, the account similarity, the transaction feature information between the target object and the other objects, the preset transaction resource flow information and the preset transaction feature information.
[0021] In one embodiment of the present application, based on the aforementioned scheme, the calculation unit is further configured to, if the account information of the target object includes the identification information of the target object, perform similarity calculation on the identification information of the target object and the preset identification information contained in the preset account information to obtain a first similarity; if the account information of the target object includes the transaction behavior information of the target object, perform similarity calculation on the transaction behavior information of the target object and the preset transaction behavior information contained in the preset account information to obtain a second similarity; if the account information of the target object includes the transaction resource storage entity information of the target object, perform similarity calculation on the transaction resource storage entity information of the target object and the preset transaction resource storage entity information contained in the preset account information to obtain a third similarity; and calculate the account similarity based on the first similarity, the second similarity and the third similarity.
[0022] In one embodiment of the present application, based on the aforementioned scheme, the acquisition unit is further used to obtain the preset transaction feature information, wherein the preset transaction feature information includes transaction feature information between a preset object and other objects associated with the preset object, and the transaction security of the account information of the preset object is lower than a preset security threshold; the calculation unit is further used to calculate the transaction feature similarity between the transaction feature information between the target object and the other objects and the preset transaction feature information; and calculate the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature similarity, the preset transaction resource flow information and the preset account information.
[0023] In one embodiment of the present application, based on the aforementioned scheme, the transaction security information includes an abnormal transaction indicator of the target object; an output unit is used to output a prompt message of transaction failure to the target object if the abnormal transaction indicator is greater than a first preset abnormal transaction indicator and the target object is detected to trigger a transaction; if the abnormal transaction indicator is less than the first preset abnormal transaction indicator and greater than a second preset abnormal transaction indicator, and the target object is detected to trigger a transaction, output a prompt message of pending identification verification to the target object.
[0024] In one embodiment of the present application, based on the aforementioned scheme, after outputting the prompt information for identity authentication to the target object, the processing unit is further used to update the abnormal transaction indicator if identification information sent by the target object is received and the identification information is verified, so that the updated abnormal transaction indicator is less than the second preset abnormal transaction indicator.
[0025] A transaction security management device includes a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the transaction security management method described above is implemented.
[0026] A computer-readable storage medium stores computer-readable instructions, which, when executed by a processor of a computer, enable the computer to execute the transaction security management method as described above.
[0027] A computer program product includes computer-readable instructions, which implement the above transaction security management method when executed by a processor.
[0028] In the above technical solution:
[0029] After obtaining the target object's transaction information within a preset time period, it is necessary to obtain other objects associated with the target object to construct the transaction resource flow information corresponding to the target object. This transaction resource flow information can represent the transfer of transaction resources triggered by the target object within the preset time period. Next, based on the target object's transaction resource flow information, account information, and transaction feature information between other objects, as well as the corresponding preset transaction resource flow information, preset account information, and preset transaction feature information, the target object's transaction security information can be calculated to perform transaction security management.
[0030] In this method, the target object's account information also includes at least one of identification information, transaction behavior information, and transaction resource storage entity information. Combined with transaction resource flow information and transaction characteristics between the target object and other objects, this method calculates the target object's transaction security information across multiple dimensions, comprehensively considering all dimensions of the resource transaction scenario. Furthermore, by combining information from each dimension with its corresponding preset information to calculate transaction security information, the accuracy of transaction security calculation is improved, ensuring the precise detection of unsafe transactions and enhancing the accuracy of transaction security management.
[0031] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The accompanying drawings are incorporated into and constitute a part of the specification, illustrating embodiments consistent with the present application and, together with the specification, serving to explain the principles of the present application. It is obvious that the drawings described below are merely some embodiments of the present application, and a person of ordinary skill in the art can derive other drawings based on these drawings without inventive effort. In the drawings:
[0033] Figure 1 It is a schematic diagram of an implementation environment involved in this application;
[0034] Figure 2 This is a schematic diagram of transaction resource flow information constructed using motif paradigm features, which is part of this application;
[0035] Figure 3 This is a flow chart of transaction security management performed by a server according to an embodiment of the present application;
[0036] Figure 4 This is a schematic diagram of the structure of various transaction resource flow information involved in the embodiments of the present application;
[0037] Figure 5 is a flow chart showing a transaction security management method according to an exemplary embodiment;
[0038] Figure 6 is a flow chart showing a transaction security management method according to another exemplary embodiment;
[0039] Figure 7 is a flow chart showing a transaction security management method according to another exemplary embodiment;
[0040] Figure 8 is a flow chart showing a transaction security management method according to another exemplary embodiment;
[0041] Figure 9 is a flow chart showing a transaction security management method according to another exemplary embodiment;
[0042] Figure 10 This is a schematic diagram of an interface for transaction security management involved in this application;
[0043] Figure 11 is a block diagram of a transaction security management device according to an exemplary embodiment;
[0044] Figure 12 The figure is a structural diagram of a computer system of a transaction security management device according to an exemplary embodiment. DETAILED DESCRIPTION
[0045] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments applicable to the present application. Rather, they are merely examples of apparatus and methods applicable to certain aspects of the present application, as detailed in the appended claims.
[0046] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically separate entities. That is, these functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0047] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be integrated or partially integrated. Therefore, the actual execution order may vary depending on the actual situation.
[0048] It should be noted that the term "plurality" used in this application refers to two or more. "And / or" describes the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. The character " / " generally indicates that the associated objects are in an "or" relationship.
[0049] It should be noted that in the specific implementation of this application, when user-related data is involved, when the embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. At the same time, the formulas involved in the embodiments of this application can be flexibly adjusted, such as adding or reducing corresponding parameters.
[0050] Before introducing the technical solutions of the embodiments of the present application, the technical terms involved in the embodiments of the present application are first introduced here.
[0051] Mobile payments are digital payment methods that allow users to conduct financial transactions using mobile devices such as smartphones or tablets. Mobile payments, which rely on wireless network technology, allow users to transfer funds and purchase goods and services without the use of cash, checks, or physical debit cards. Mobile payments can be made using a variety of technologies, including near-field communication (NFC), QR code scanning, mobile payment apps, and SMS messaging. They offer convenience and flexibility, enabling users to conduct transactions anytime, anywhere, while also increasing transaction security by protecting users' financial information through encryption and other security measures.
[0052] The area under the curve (AUC) is the area under the receiver operating characteristic curve (ROC curve). It is an indicator for evaluating the performance of a classification model and is used to evaluate a binary classification model. AUC measures the ability of the model to correctly distinguish between positive and negative classes under all possible classification thresholds. The AUC value ranges from 0 to 1. The AUC of an ideal classification model is 1, indicating that it has 100% sensitivity (no missed detections) and specificity (no false positives). The higher the AUC value, the better the classification performance of the model, and the more effective it is in distinguishing instances of different categories. In the embodiment of the present application, AUC can be used to represent the weight of a model among multiple models.
[0053] Weight of Evidence (WOE) is a common technique used in financial risk assessment and statistical modeling to evaluate the predictive power of a variable for a target event. The WOE is calculated by taking the natural logarithm of the distribution ratio of "good" to "bad" outcomes for a given feature class. The WOE value provides a quantitative measure of the importance of a feature class for predicting the target event. Positive values indicate a stronger correlation with "good" outcomes, while negative values indicate a stronger correlation with "bad" outcomes.
[0054] In the embodiments of the present application, the WOE transformation can convert a categorical variable into a continuous variable that can be used in statistical models such as logistic regression, while maintaining the variable's predictive power and providing an intuitive understanding of the direction and intensity of the variable's impact on the target variable (such as default risk). The following transformation formula can be used:
[0055] WOE = ln (percentage of good customers / percentage of bad customers) × 100%
[0056] In this formula, the WOE value reflects the proportion of response events in a specific group relative to the overall proportion. If the response ratio in a group is large, then the WOE value for that group is large; conversely, if the response ratio is small, then the WOE value is small.
[0057] A scorecard is a tool used in credit risk assessment that aims to predict default risk by collecting and analyzing financial and other relevant information about individuals or businesses. The scorecard model assesses default risk by assigning a score to each relevant feature and then aggregating these scores into a total score. A higher total score indicates a lower default risk; a lower total score indicates a higher default risk. Scorecards are typically developed based on historical data, using statistical methods to determine the weights and scores of each feature. In an embodiment of the present application, a scorecard can be used to score a user's transaction behavior to obtain transaction security information. A higher score for the transaction security information indicates that the user's transaction behavior is less secure.
[0058] When developing a scorecard, the WOE transformation can preprocess data and convert categorical variables into a form that matches the model. By converting variables to WOE values, technicians can intuitively assess the impact of each variable on the target event (such as unsafe trading behavior). This information can then be used to create a scorecard. In the scorecard, the WOE value of each feature is assigned a score based on its predictive ability for the target event.
[0059] The WOE transform often involves binning during its application. Binning is a data preprocessing technique used to convert continuous variables into categorical variables, or to regroup categorical variables with multiple categories. This process involves dividing the variable's value range into several "bins," each representing a range of values. The purpose of binning is to simplify the model's complexity, enhance its generalization capabilities, and improve the prediction of unsafe trading behavior characteristics.
[0060] In complex network analysis, motifs refer to recurring, structurally specific subgraph patterns within a network. The server can identify and analyze typical transaction behaviors within a transaction network, such as circular transactions, convergent transactions, and resale transactions. Leveraging these motifs, it can construct information about the flow of transaction resources involved in a particular transaction. The application of motifs allows for a clearer visualization of the paths and convergence nodes of transaction resources within the network.
[0061] Feature engineering refers to the processing and transformation of raw data in machine learning and data analysis tasks to extract useful features or create new features to improve model performance. Feature engineering includes steps such as data cleaning, data transformation, feature selection, and feature construction. Through feature engineering, potential patterns and regularities can be discovered from the raw data, making the model easier to learn and generalize. In the embodiments of the present application, feature engineering can be used to extract feature vectors of the data to be reviewed.
[0062] Machine learning (ML) is a multidisciplinary field that encompasses probability theory, statistics, approximation theory, convex analysis, and algorithmic complexity theory. It specifically studies how computers can simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is at the core of artificial intelligence and the fundamental way to make computers intelligent. Its applications span all areas of AI. Machine learning and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and self-learning.
[0063] In related technologies, detecting unsafe transactions often involves analyzing past cases to identify characteristics of these behaviors and developing expert rules to prevent them. However, using expert rules to detect unsafe transactions can fail to accurately identify transaction security due to the limited number of features detected, resulting in low accuracy in transaction security management.
[0064] Based on this, the embodiments of the present application respectively provide a transaction security management method, a transaction security management apparatus, a transaction security management device, a computer-readable storage medium, and a computer program product. In these embodiments, after obtaining the transaction information of a target object within a preset time period, it is necessary to obtain other objects associated with the target object to construct transaction resource flow information corresponding to the target object. This transaction resource flow information can represent the transfer of transaction resources triggered by the target object within the preset time period. Next, the target object's transaction security information can be calculated based on the target object's transaction resource flow information, account information, and transaction feature information between other objects, as well as the corresponding preset transaction resource flow information, preset account information, and preset transaction feature information, to perform transaction security management. In this method, the target object's account information also includes at least one of identification information, transaction behavior information, and transaction resource storage entity information. Combined with the transaction resource flow information and transaction feature information between the target object and other objects, the method can calculate the target object's transaction security information across multiple dimensions, comprehensively considering all dimensions in the resource transaction scenario. In addition, the information of each dimension is combined with its corresponding preset information to calculate the transaction security information, which improves the accuracy of the transaction security information calculation, ensures the accuracy of the detection of unsafe transactions, and improves the accuracy of transaction security management.
[0065] See also Figure 1 , Figure 1 It is a schematic diagram of an implementation environment involved in this application.
[0066] Figure 1 The illustrated implementation environment includes a target object 110 , other objects 121 , other objects 122 , other objects 123 , and a server 140 .
[0067] Each object can use the terminal device to conduct transactions with other objects. For example, target object 110 receives transaction information 131 sent by other object 121, target object 110 sends transaction information 132 to other object 122, target object 110 sends transaction information 133 to other object 123, and other object 123 sends transaction information 134 to other object 121. Figure 1 In the example, the number of other objects may be less than 3 or more than 3. Here, the example in which the number of other objects is 3 is used for explanation.
[0068] The transaction information in the embodiments of the present application may include a transaction order, which may indicate the transaction initiator, the transaction recipient, the amount of transaction resources, and the transfer direction of the transaction resources. The transaction resources may be currencies, such as US dollars, RMB, British pounds, etc. For example, if other object 121 transfers 1,000 yuan to target object 110, then the transaction initiator included in transaction information 131 is other object 121, the transaction recipient is target object 110, the amount of transaction resources is 1,000 yuan, and the transfer direction of the transaction resources is from other object 121 to target object 110.
[0069] In this embodiment of the present application, server 140 can obtain transaction information of target object 110 within a preset time period. The preset time period can be set by a person skilled in the art, for example, the time period of the past week, the past day, or the past two days. Based on the transaction information of target object 110 within the preset time period, the server can construct transaction resource flow information corresponding to target object 110.
[0070] The transaction resource flow information may include the flow of transaction resources in the relationship network corresponding to the target object. Since an object may involve a large number of transaction information and there may be differences between different transaction information, the server 140 may use machine learning methods to analyze whether there is a relationship between the objects involved in each transaction information. For example, Figure 1 In the example, other object 121 and other object 123 are both associated with target object 110. Therefore, server 140 can detect whether there is an association relationship between other object 121 and other object 123. Transaction information 134 exists between other object 121 and other object 123. Therefore, server 140 can determine that there is an association relationship between other object 121 and other object 123.
[0071] When the server 140 constructs the transaction resource flow information of the target object 110 based on the transaction information of the target object 110, the motif paradigm feature can be used. Figure 2 Shown is a schematic diagram of transaction resource flow information constructed using motif paradigm features. Figure 2 In the diagram, black dots represent the target object, and white dots represent other objects associated with the target object. Transaction resource flow information with the physical meaning of "receiving payment" represents the transfer of transaction resources from other objects to the target object. Transaction resource flow information with the physical meaning of "one-way capital loop" represents the transfer of transaction resources from the target object to other object 1, which then transfers transaction resources to other object 2, and finally, other object 2 transfers the transaction resources to the target object. Similarly, different transaction resource flow information can be constructed based on the different transaction information involved in the target object.
[0072] It should be noted that the terminal device in the embodiment of the present application can be a mobile phone, a tablet computer, a laptop computer, a PDA, a mobile Internet device (MID), a vehicle-mounted device, an aircraft, a wearable device (such as a smart watch, a smart bracelet, a pedometer, etc.), a virtual reality device (such as a VR (Virtual Reality) device, an AR (Augmented Reality) device), etc.
[0073] Optionally, the server in the embodiment of the present application can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0074] See also Figure 3 , Figure 3 This is a flow chart of transaction security management performed by a server involved in this application.
[0075] In the embodiment of the present application, the process of the server processing the transaction information of the transaction object is divided into a model construction process and a process of processing the transaction information of the transaction object using the constructed model.
[0076] During the model building process, the server can obtain transaction information of multiple transaction objects to build a processing strategy, and use the policy engine to build each sub-model for these transaction information. In the embodiment of the present application, the model that comprehensively scores the transaction security information of the transaction information can be called a transaction security detection model. The transaction security detection model also includes multiple sub-models, such as the identification information scoring model (denoted as M1), the transaction behavior information scoring model (denoted as M2), the transaction resource storage entity scoring model (denoted as M3), the transaction resource flow information scoring model (denoted as M4) and the transaction feature scoring model (denoted as M5). The scores of these sub-models correspond to Figure 3 P1 to P5 in the.
[0077] When building a transaction security detection model, the server can obtain a portion of positive samples and a portion of negative samples (i.e., extracting data variables for feature processing). Positive samples refer to transaction information determined to be unsafe, while negative samples refer to transaction information determined to be safe. Positive samples can be obtained by authoritatively identifying unsafe transactions. Negative samples can be obtained by performing stratified sampling within the transaction information database, extracting transaction information from different tiers and time periods.
[0078] Optionally, the ratio of the number of positive samples to negative samples may be 1:20.
[0079] Next, the server performs feature engineering on each sample (i.e., each transaction information) and derives features using different sliding time windows to obtain the feature engineering information corresponding to each sample. Next, the server uses a logistic regression model to bin each sample's feature engineering information, transform the feature's evidence weight, and perform parameter training and performance evaluation on each sub-model, ultimately resulting in a successfully constructed sub-model.
[0080] In the process of using the constructed model to process the transaction information of the transaction object, the server can input the test sample (the test sample refers to the transaction information of the transaction object to be tested, such as the transaction information of the target object) into each sub-model, and obtain the results output by each sub-model (respectively denoted as P1, P2, P3, P4 and P5), and then perform a weighted fusion operation on the output results of these five sub-models.
[0081] Specifically, the server can calculate the AUC metric corresponding to each sub-model from the output of each sub-model, denoted as A1, A2, A3, A4, and A5, respectively. Using the AUC metric, the server calculates the final test result (denoted as P) corresponding to the test sample. This final test result is the comprehensive transaction security information score corresponding to the test sample. Finally, the server can perform transaction security management based on the total transaction security information score P corresponding to each transaction object.
[0082] See also Figure 4 ,like Figure 4 The figure shows the structure diagram of the flow information of various transaction resources involved in this application. Figure 4 In the article, 33 types of transaction resource flow information are enumerated. The following is a summary of these 33 types of transaction resource flow information according to their Figure 4 The serial number in the table is introduced in detail. It should be noted that Figure 4 The black dots in the figure are target objects, and the white dots are other objects. When a transaction resource transfer information contains three objects, in addition to the target object, the remaining two objects are named other object 1 and other object 2.
[0083] 1. The target object transfers transaction resources to other objects;
[0084] 2. The target object receives the transaction resources transferred by other objects;
[0085] 3. Other object 1 transfers transaction resources to other object 2, and other object 2 then transfers the transaction resources to the target object, completing the second-level collection.
[0086] 4. Other object 1 transfers the transaction resources to the target object, and the target object then transfers the transaction resources to other object 2, completing the transfer of the transaction resources.
[0087] 5. The target object transfers the transaction resources to other object 1, which then transfers the transaction resources to other object 2, completing the second-order payment.
[0088] 6. The target object will transfer transaction resources to other object 1 and other object 2 respectively.
[0089] 7. Other object 1 transfers transaction resources to the target object and other object 2 respectively.
[0090] 8. Other objects 1 and 2 transfer transaction resources to the target object respectively.
[0091] 9. The target object and other object 2 transfer transaction resources to other object 1 respectively.
[0092] 10. The target object transfers transaction resources to other object 1, other object 1 transfers transaction resources to other object 2, and other object 2 transfers transaction resources to the target object, forming a one-way capital loop.
[0093] 11. The target object transfers transaction resources to other object 1 and other object 2 respectively, and other object 2 also transfers transaction resources to other object 1.
[0094] 12. Other object 1 transfers transaction resources to the target object and other object 2 respectively, and other object 2 also transfers transaction resources to the target object.
[0095] 13. Other object 1 transfers transaction resources to the target object and other object 2 respectively, and the target object also transfers transaction resources to other object 2.
[0096] 14. Multiple transaction resource transfers are carried out between the target object and other objects.
[0097] 15. Multiple transaction resource transfers are performed between the target object and other object 1, and other object 2 transfers transaction resources to other object 1.
[0098] 16. Multiple transaction resource transfers are performed between the target object and other object 1, and other object 2 transfers transaction resources to the target object.
[0099] 17. Multiple transaction resource transfers are performed between other object 1 and other object 2, and the target object transfers transaction resources to other object 1.
[0100] 18. Multiple transaction resource transfers are performed between the target object and other object 1, and other object 1 transfers transaction resources to other object 2.
[0101] 19. Multiple transaction resource transfers are performed between the target object and other object 1, and the target object transfers transaction resources to other object 2.
[0102] 20. Multiple transaction resource transfers are performed between other object 1 and other object 2, and other object 1 transfers transaction resources to the target object.
[0103] 21. Multiple transaction resource transfers are performed between the target object and other object 1, and multiple transaction resource transfers are performed between the target object and other object 2.
[0104] 22. Multiple transaction resource transfers are performed between the target object and other object 1, and multiple transaction resource transfers are performed between other object 1 and other object 2.
[0105] 23. Other object 1 and other object 2 transfer transaction resources to the target object respectively, and multiple transaction resource transfers are performed between other object 1 and other object 2.
[0106] 24. The target object and other object 2 transfer transaction resources to other object 1 respectively, and multiple transaction resource transfers are performed between the target object and other object 2.
[0107] 25. The target object transfers transaction resources to other object 1 and other object 2 respectively, and multiple transaction resource transfers are performed between other object 1 and other object 2.
[0108] 26. Other object 1 transfers transaction resources to the target object and other object 2 respectively, and multiple transaction resource transfers are performed between the target object and other object 2.
[0109] 27. Other object 2 performs a second-order transfer of transaction resources to the target object through other object 1, and multiple transaction resource transfers are performed between the target object and other object 2.
[0110] 28. Other object 2 performs a second-order transfer of transaction resources to other object 1 through the target object, and multiple transaction resource transfers are performed between other object 1 and other object 2.
[0111] 29. The target object performs a second-order transfer of transaction resources from other object 1 to other object 2, and multiple transaction resource transfers are performed between the target object and other object 2.
[0112] 30. Other object 1 performs multiple transaction resource transfers with the target object and other object 2, and other object 2 transfers transaction resources to the target object.
[0113] 31. The target object performs multiple transaction resource transfers with other object 1 and other object 2, and other object 2 transfers transaction resources to other object 1.
[0114] 32. Other object 1 performs multiple transaction resource transfers with the target object and other object 2, and the target object transfers transaction resources to other object 2.
[0115] 33. The target object, other object 1, and other object 2 perform multiple transaction resource transfers with each other.
[0116] It should be noted that multiple transaction resource transfers can refer to two or more transaction transfers, with both parties to the transaction needing to transfer transaction resources to each other. The 33 types of transaction resource flow information described above are merely examples. Those skilled in the art may reasonably add other types of transaction flow information based on the needs of actual application scenarios. For example, transaction flow information could be expanded from three transaction object dimensions to four or five transaction objects, allowing the transaction resource flow information to more comprehensively display the transaction resource transfers involving the target object, thereby enabling the detection of various unsafe transaction behaviors and improving the accuracy of unsafe transaction behavior detection.
[0117] See also Figure 5 , Figure 5 This is a flow chart of a transaction security management method according to an exemplary embodiment. Figure 1 The implementation environment shown in FIG. 1 is specifically executed by the server. Of course, the method can also be applied to other implementation environments, and the execution subject of the method is not limited here.
[0118] The following will use the server as an exemplary execution subject to elaborate on the transaction security management method. Figure 5 As shown, in an exemplary embodiment, the method includes at least the following steps:
[0119] S510, obtaining transaction information of a target object within a preset time period.
[0120] The preset time period refers to a specific time interval, and the specific interval can be set by those skilled in the art, for example, it can be the time period of the past week, the past day, or the past two days.
[0121] Optionally, the server may obtain all transaction information of the target object within a preset time period.
[0122] Optionally, the server can obtain partial transaction information of the target object within a preset time period. This partial transaction information can be obtained by random sampling or by stratified sampling according to time, which can reduce the processing pressure of the server.
[0123] S520 , acquiring other objects associated with the target object based on the transaction information of the target object, and constructing transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects.
[0124] The target object may have multiple transaction records corresponding to the preset time period. Each transaction record may represent other objects associated with the target object, specifically identifying information about the other objects. The server detects each transaction record of the target object within the preset time period and can detect the flow of resources for each transaction, thereby establishing relationships between different transaction objects associated with the target object.
[0125] In an embodiment of the present application, if there are transferred transaction resources between the first object and the target object, and the server has not detected the second object associated with at least one of the target object and the first object, the transaction resource flow information corresponding to the target object can be constructed based on the transaction resource transfer direction between the first object and the target object.
[0126] In an embodiment of the present application, if there are transferred transaction resources between the first object and the target object, and the server detects a second object associated with the target object, but the second object and the first object are not associated with each other, then based on the transaction resource transfer direction between the first object and the target object, and the transaction transfer direction between the second object and the target object, the transaction resource flow information corresponding to the target object can be constructed.
[0127] In an embodiment of the present application, if there are transferred transaction resources between the first object and the target object, and the server detects a second object associated with both the target object and the first object, based on the transaction resource transfer direction between the first object and the target object, the transaction resource transfer direction between the second object and the target object, and the transaction resource transfer direction between the first object and the second object, the transaction resource flow information corresponding to the target object is constructed.
[0128] S530 , calculating the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature information between the target object and other objects, the preset transaction resource flow information, the preset account information and the preset transaction feature information.
[0129] The target object's account information includes at least one of identification information, transaction behavior information, and transaction resource storage entity information.
[0130] The identification information can be used to describe the attributes of the target object, including at least the target object's body shape information, age information, residence information, and occupation information.
[0131] Transaction behavior information can be used to analyze whether the target object has any related actions of unsafe transaction behavior in the payment scenario. The transaction behavior information of the target object can be calculated from the actions reflected by the target object in transaction resource recharge, transaction resource withdrawal, etc.
[0132] Transaction resource storage entity information refers to the storage entity information required by the target party to transfer transaction resources. This storage entity can be a bank card, passbook, credit card, or other entity. Transaction resource storage entity information can indicate whether the target party encounters any abnormalities in using the transaction resource storage entity during payment.
[0133] The target object may have multiple transaction resource flow information, each of which is based on multiple transaction information of the target object within a preset time period. Each transaction resource flow information can represent the transfer direction of the transaction resources. The transaction resource flow information reflects the local topological characteristics of the resource transaction network. Therefore, in the embodiment of the present application, the transaction resource flow information formed between up to three transaction objects is used for illustration. The server can also count the frequency of occurrence of transaction resource flow information of the same pattern in the transaction resource flow information of the target object. The higher the frequency of occurrence, the closer the purpose of the resource transaction corresponding to the target object is to the purpose corresponding to the transaction resource flow information.
[0134] The transaction feature information between the target object and other objects comprehensively considers the characteristics of the payer and the recipient, including the length of time the two parties have added each other as friends, the registered mobile phone numbers and real-name ID ownership of the two parties, the location information where the order transaction occurred, etc.
[0135] In an embodiment of the present application, the preset account information may include preset identification information, preset transaction behavior information, and preset transaction resource storage entity information. When calculating the transaction security information of the target object, the server may perform a similarity calculation between the target object's identification information and the preset identification information to obtain a similarity score P1; perform a similarity calculation between the target object's transaction behavior information and the preset transaction behavior information to obtain a similarity score P2; perform a similarity calculation between the target object's transaction resource storage entity information and the preset transaction resource storage entity information to obtain a similarity score P3; perform a similarity calculation between the target object's transaction resource flow information and the preset transaction resource flow information to obtain a similarity score P4; and perform a similarity calculation between the target object's transaction feature information and the preset transaction feature information to obtain a similarity score P5.
[0136] Optionally, when calculating the transaction security information of the target object, the server can input all the transaction information corresponding to the target object into the constructed transaction security detection model, so that each sub-model outputs corresponding results, which respectively represent the scores of the target object's transaction information in the identification information scoring model, transaction behavior information scoring model, transaction resource storage entity scoring model, transaction resource flow information scoring model and transaction feature scoring model, namely P1, P2, P3, P4 and P5.
[0137] The server can calculate the AUC index corresponding to each score of each dimension, which are recorded as A1, A2, A3, A4 and A5 respectively. The AUC index is used to calculate the final detection result corresponding to the test sample (which can be recorded as P). The specific calculation formula can be:
[0138]
[0139] The final test result is the comprehensive score of the transaction security information corresponding to the test sample. Based on the comprehensive score of the transaction security information, the server can calculate the probability that the target object has engaged in unsafe transaction behavior.
[0140] S540: Perform security management on the transaction triggered by the target object based on the transaction security information.
[0141] Finally, the server can perform transaction security management based on the comprehensive transaction security score P corresponding to each transaction object. This management method can be to intercept the transaction triggered by the target object when the comprehensive transaction security score P of the target object is too high, and output a transaction failure prompt message to the target object.
[0142] Through this method, after obtaining the transaction information of a target object within a preset time period, the server needs to obtain other objects associated with the target object to construct the transaction resource flow information corresponding to the target object. This transaction resource flow information can represent the transfer of transaction resources triggered by the target object within the preset time period. Next, the server can calculate the target object's transaction security information based on the target object's transaction resource flow information, account information, and transaction feature information with other objects, as well as the corresponding preset transaction resource flow information, preset account information, and preset transaction feature information, to perform transaction security management.
[0143] In this method, the target object's account information also includes at least one of identification information, transaction behavior information, and transaction resource storage entity information. Combined with transaction resource flow information and transaction characteristics between the target object and other objects, this method calculates the target object's transaction security information across multiple dimensions, comprehensively considering all dimensions of the resource transaction scenario. Furthermore, by combining information from each dimension with its corresponding preset information to calculate transaction security information, the accuracy of transaction security calculation is improved, ensuring the precise detection of unsafe transactions and enhancing the accuracy of transaction security management.
[0144] In one embodiment of the present application, another transaction security management method is provided, which can be executed by a server. Figure 6As shown, the transaction security management method may include S510, S610 and S530 to S540. That is, S610 is Figure 5 The specific implementation method of S520 is shown.
[0145] In the embodiment of the present application, the other objects include at least one of a first object and a second object.
[0146] The following describes S610:
[0147] S610: If it is detected that there are transferred transaction resources between the target object and the first object, construct transaction resource flow information corresponding to the target object based on a second object associated with at least one of the target object and the first object.
[0148] In one embodiment of the present application, for a transaction information, if there is no second object associated with either the target object or the first object, the target object's transaction resource flow information can be directly constructed based on the transaction resource transfer direction between the first object and the target object. In other words, the transaction resource pointed to by this transaction information is only traded between the first object and the target object, and no other objects participate in the transaction of this transaction resource. For example, the first object transfers a transaction resource of 1,000 yuan to the target object, and after the target object receives the 1,000 yuan, it does not transfer the transaction resource to the second object. In this case, the target object's transaction resource flow information is composed of two transaction objects, and based on the transaction resource transfer direction, the target object's transaction resource flow information can be constructed. As Figure 4 Patterns 1, 2, and 14 in the figure can be considered as transaction resource flow information in this case.
[0149] In the embodiment of the present application, S610 may further specifically include S611 to S612.
[0150] S611 to S612 are described below:
[0151] S611, if it is detected that there are transferred transaction resources between the target object and the first object, there is a second object associated with the target object, and the second object and the first object are not associated with each other, then based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the second object and the target object, construct the transaction resource flow information corresponding to the target object.
[0152] For transaction information between a first object and a target object, there is a second object associated with the target object, but the second object and the first object are not associated with each other. Then the server can construct the transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the second object and the target object.
[0153] For example, the first object transfers 1,000 yuan of transaction resources to the target object, and after receiving the 1,000 yuan, the target object transfers it to the second object. In addition, the server also detects that there is no association relationship between the first object and the second object, that is, there is no record of transaction resource transfer between them. Then, based on the direction of transaction resource transfer from the first object to the target object and the direction of transaction resource transfer from the target object to the second object, the transaction resource flow information corresponding to the target object can be constructed.
[0154] In this case, the Figure 4 The various modes in the may include the 4th, 6th, 8th, 16th, 19th and 21st types of transaction resource flow information.
[0155] It should be noted that the transaction resource transfer amounts corresponding to two related transaction information may be different, but relatively close, such as 1,000 yuan and 1,100 yuan, 1,000 yuan and 800 yuan. In this case, the server can also identify the correlation between the two.
[0156] S612: If there is a second object associated with both the target object and the first object, construct transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, the transaction resource transfer direction between the second object and the target object, and the transaction resource transfer direction between the first object and the second object.
[0157] For transaction information between a first object and a target object, there is a second object associated with the target object, and the second object is also associated with the first object. Then the server can construct the transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, the transaction resource transfer direction between the second object and the target object, and the transaction resource transfer direction between the first object and the second object.
[0158] For example, the first object transfers 1,000 yuan of transaction resources to the target object, the target object transfers the 1,000 yuan to the second object, and the second object transfers the 1,000 yuan to the first object. Then, based on the direction of the transaction resource transfer from the first object to the target object, the direction of the transaction resource transfer from the target object to the second object, and the direction of the transaction resource transfer from the second object to the first object, the transaction resource flow information corresponding to the target object can be constructed.
[0159] In this case, the Figure 4 The respective modes may include the 10th to 13th, and the 23rd to 33rd types of transaction resource flow information.
[0160] In addition to S611 and S612, S610 may also include S613:
[0161] S613: If it is detected that there are transferred transaction resources between the target object and the first object, there is a second object associated with the first object, and the second object and the target object are not associated with each other, then based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the first object and the second object, construct transaction resource flow information corresponding to the target object.
[0162] For transaction information between a first object and a target object, there is a second object associated with the first object, but the second object and the target object are not associated with each other. Then the server can construct the transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the first object and the second object.
[0163] For example, the target object transfers 1,000 yuan of transaction resources to the first object, and after receiving the 1,000 yuan, the first object transfers it to the second object. In addition, the server also detects that there is no association between the second object and the target object, that is, there is no record of transaction resource transfer between them. Then, based on the direction of transaction resource transfer from the target object to the first object and the direction of transaction resource transfer from the first object to the second object, the transaction resource flow information corresponding to the target object can be constructed.
[0164] In this case, the Figure 4 The various modes in the data may include the 3rd, 5th, 7th, 9th, 15th, 17th, 18th, 20th and 22nd types of transaction resource flow information.
[0165] After obtaining the target object's transaction resource flow information, the server can calculate the target object's score based on this dimension. Specifically, the server can obtain preset transaction resource flow information, which includes transaction resource flow information for transaction objects that have engaged in unsafe transactions. This preset transaction resource flow information can indicate which transaction resource flow patterns, with the highest frequency of occurrence, are more likely to be involved in unsafe transactions. Therefore, the server can calculate the similarity between the target object's transaction resource flow information and the preset transaction resource flow information to determine the target object's score based on this information.
[0166] Through this method, the server can accurately construct the transaction resource flow information corresponding to the target object, making the server's scoring of the transaction resource flow information more accurate, improving the calculation accuracy of the target object's transaction security information, and thus improving the accuracy of transaction security management.
[0167] In one embodiment of the present application, another transaction security management method is provided, which can be executed by a server. Figure 7 As shown, the transaction security management method may include S510 to S520, S710 to S730 and S540. That is, S710 to S730 are Figure 5 The specific implementation method of S530 is shown.
[0168] S710 to S730 are described below:
[0169] S710: Obtain preset account information, where the preset account information includes account information whose transaction security is lower than a preset security threshold.
[0170] The preset account information is obtained by the server through machine learning training on multiple samples of multiple transaction objects, indicating that the transaction security is lower than the preset security threshold. The preset security threshold can be set by those skilled in the art and is not limited here.
[0171] S720: Calculate the account similarity between the target object's account information and the preset account information.
[0172] Specifically, S720 may include S721 to S724.
[0173] S721 to S724 are described below:
[0174] S721: If the account information of the target object includes identification information of the target object, similarity calculation is performed between the identification information of the target object and preset identification information included in the preset account information to obtain a first similarity.
[0175] The preset identification information includes the attributes of the transaction object that has engaged in unsafe transaction behavior, such as body shape information, age information, residence information, and occupation information.
[0176] S722: If the target object's account information includes the target object's transaction behavior information, similarity calculation is performed between the target object's transaction behavior information and the preset transaction behavior information included in the preset account information to obtain a second similarity.
[0177] The preset transaction behavior information includes the transaction behavior of the transaction object that has engaged in unsafe transaction behavior, such as transaction resource recharge information and transaction resource withdrawal information.
[0178] S723: If the target object's account information includes the target object's transaction resource storage entity information, similarity calculation is performed between the target object's transaction resource storage entity information and the preset transaction resource storage entity information included in the preset account information to obtain a third similarity.
[0179] The preset transaction resource storage entity information includes the transaction resource storage entity information of the transaction object that has engaged in unsafe transaction behavior, such as bank cards, passbooks, credit cards, etc.
[0180] S724 , calculating the account similarity based on the first similarity, the second similarity, and the third similarity.
[0181] The server can directly use the first similarity, the second similarity, and the third similarity as the similarity in three dimensions between the target object's account information and the preset account information, and use the first similarity, the second similarity, and the third similarity as the scores of the target object's transaction information in the identification information dimension, the transaction behavior information dimension, and the transaction resource storage entity information dimension, respectively.
[0182] Optionally, the server may perform a weighted operation on the first similarity, the second similarity, and the third similarity to obtain the account similarity between the account information of the target object and the preset account information.
[0183] S730 , calculating transaction security information of the target object based on the transaction resource flow information, account similarity, transaction feature information between the target object and other objects, preset transaction resource flow information, and preset transaction feature information.
[0184] The server can perform weighted summation processing on the transaction information of the target object based on the score of the transaction resource flow information, the transaction information identification information dimension, the transaction behavior information dimension, the transaction resource storage entity information dimension, and the transaction feature information between other objects to obtain the transaction security information of the target object.
[0185] Through this method, the server can accurately calculate the score of the target object's account information in the transaction information identification information dimension, transaction behavior information dimension and transaction resource storage entity information dimension, which can improve the calculation accuracy of the target object's transaction security information, thereby improving the accuracy of transaction security management.
[0186] In one embodiment of the present application, another transaction security management method is provided, which can be executed by a server. Figure 8 As shown, the transaction security management method may include S510 to S520, S810 to S830 and S540. That is, S810 to S830 are Figure 5 The specific implementation method of S530 is shown.
[0187] S810 to S830 are described below:
[0188] S810, obtaining preset transaction feature information, where the preset transaction feature information includes transaction feature information between a preset object and other objects associated with the preset object, and transaction security of the account information of the preset object is lower than a preset security threshold.
[0189] Each transaction involves two parties. Therefore, for transactions corresponding to unsafe transactions, the server can detect the transaction characteristics between the two parties. This preset transaction characteristics are obtained by the server through machine learning, using the transaction characteristics of the two parties in each transaction.
[0190] S820, calculating transaction feature similarity between transaction feature information between the target object and other objects and preset transaction feature information.
[0191] Based on the target object's multiple transaction information, the server can directly calculate the transaction feature information between the target object and other objects, and the transaction feature similarity between the target object and the preset transaction feature information. This transaction feature similarity can be used as a score for the target object's transaction information in the transaction feature information dimension.
[0192] S830 , calculating the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature similarity, the preset transaction resource flow information, and the preset account information.
[0193] The server can perform weighted summation processing on the transaction information of the target object based on the score of the transaction resource flow information, the transaction information identification information dimension, the transaction behavior information dimension, the transaction resource storage entity information dimension, and the transaction feature information between other objects to obtain the transaction security information of the target object.
[0194] Through this method, the server can accurately calculate the score of the target object's transaction information in the transaction feature information dimension, which can improve the calculation accuracy of the target object's transaction security information, thereby improving the accuracy of transaction security management.
[0195] In one embodiment of the present application, another transaction security management method is provided, which can be executed by a server. Figure 9 As shown, the transaction security management method may include S510 to S530 and S910 to S920. That is, S910 to S920 are Figure 5 The specific implementation method of S540 is shown.
[0196] In an embodiment of the present application, the transaction security information includes abnormal transaction indicators of the target object.
[0197] S910 to S920 are described below:
[0198] S910: If the abnormal transaction index is greater than a first preset abnormal transaction index and it is detected that the target object triggers a transaction, a prompt message indicating that the transaction failed is output to the target object.
[0199] The target subject's abnormal transaction index is the aforementioned comprehensive score of the target subject's transaction security information. If the abnormal transaction index is greater than the first preset abnormal transaction index, it indicates that the target subject is a highly abnormal transaction subject. If the target subject is detected to trigger a transaction again, the transaction will be intercepted and a transaction failure prompt will be output to the target subject. The value of the first preset abnormal transaction index can be set by those skilled in the art, for example, 90 points.
[0200] like Figure 10 The figure shows a schematic diagram of an interface for transaction security management involved in an embodiment of the present application. Figure 10 In the process, if the target object triggers a transaction, the server obtains the total transaction security information score corresponding to the target object (i.e., the abnormal transaction index). If it is detected that the abnormal transaction index is greater than the first preset abnormal transaction index, a prompt message indicating that the transaction failed will be displayed. In addition, the server can also inform the target object how to access the transaction restrictions, such as contacting manual customer service.
[0201] S920: If the abnormal transaction indicator is smaller than the first preset abnormal transaction indicator and larger than the second preset abnormal transaction indicator, and the target object is detected to have triggered the transaction, a prompt message indicating that identification verification is to be performed is output to the target object.
[0202] If the abnormal transaction indicator is less than the first preset abnormal transaction indicator but greater than the second preset abnormal transaction indicator, the target party is currently classified as a medium-to-high abnormal transaction party. When the target party triggers a transaction, the server will temporarily intercept the transaction and display a prompt message to the target party, indicating that identity verification is pending. In other words, the target party must complete identity verification before the transaction can be successfully completed.
[0203] like Figure 10 As shown, if the target object triggers a transaction, and the server detects that its abnormal transaction index is less than the first preset abnormal transaction index but greater than the second preset abnormal transaction index, a prompt message for pending identification verification will be displayed.
[0204] If the server receives the identification information sent by the target object and verifies the identification information, it updates the abnormal transaction index so that the updated abnormal transaction index is less than the second preset abnormal transaction index. That is, if the identification information of the target object is verified, the server can release the transaction restrictions on the target object and reduce its corresponding abnormal transaction index so that the abnormal transaction index after taking effect is less than the second preset abnormal transaction index. For example, assuming that the score of the second preset abnormal transaction index is 80 points, the abnormal transaction index corresponding to the target object is 85 points. After the target object triggers a transaction, the server requires the target object to perform identification verification. If the identification verification of the target object is passed, the 85 points can be reduced to 75 points. The specific reduced score can be set by those skilled in the art and is not limited in the embodiments of the present application.
[0205] Through this method, the server can perform transaction security management based on the comprehensive score of the target object's transaction security information. By performing transaction security management through scoring, the probability of misidentification can be reduced and the accuracy of transaction security management can be improved.
[0206] Figure 11 FIG is a block diagram of a transaction security management device according to an embodiment of the present application. Figure 11 As shown, the transaction security management device can be applied to a computer, and the device includes:
[0207] A transaction security management device, comprising:
[0208] An acquisition unit 1110 is configured to acquire transaction information of a target object within a preset time period;
[0209] The processing unit 1120 is configured to detect other objects associated with the target object based on the transaction information of the target object, and construct transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects;
[0210] A calculation unit 1130 is configured to calculate transaction security information of the target object based on the transaction resource flow information, the target object's account information, transaction feature information between the target object and other objects, preset transaction resource flow information, preset account information, and preset transaction feature information;
[0211] The processing unit 1120 is further configured to perform security management on the transaction triggered by the target object based on the transaction security information.
[0212] In one embodiment of the present application, based on the aforementioned scheme, the other objects include at least one of a first object and a second object; the processing unit 1120 is further used to construct transaction resource flow information corresponding to the target object based on the second object associated with at least one of the target object and the first object if it is detected that there are transferred transaction resources between the target object and the first object.
[0213] In one embodiment of the present application, based on the aforementioned scheme, the processing unit 1120 is further used to construct transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the second object and the target object, if there is a second object associated with the target object and the second object is not associated with the first object.
[0214] In one embodiment of the present application, based on the aforementioned scheme, the processing unit 1120 is further used to construct transaction resource flow information corresponding to the target object based on the transaction resource transfer direction between the first object and the target object, the transaction resource transfer direction between the second object and the target object, and the transaction resource transfer direction between the first object and the second object, if there is a second object associated with both the target object and the first object.
[0215] In one embodiment of the present application, based on the aforementioned scheme, the acquisition unit 1110 is further used to obtain preset account information, which includes account information whose transaction security is lower than a preset security threshold; the calculation unit 1130 is further used to calculate the account similarity between the account information of the target object and the preset account information; and calculate the transaction security information of the target object based on the transaction resource flow information, the account similarity, the transaction feature information between the target object and other objects, the preset transaction resource flow information and the preset transaction feature information.
[0216] In one embodiment of the present application, based on the aforementioned scheme, the calculation unit 1130 is further configured to: if the account information of the target object includes identification information of the target object, perform similarity calculation on the identification information of the target object and the preset identification information contained in the preset account information to obtain a first similarity; if the account information of the target object includes transaction behavior information of the target object, perform similarity calculation on the transaction behavior information of the target object and the preset transaction behavior information contained in the preset account information to obtain a second similarity; if the account information of the target object includes transaction resource storage entity information of the target object, perform similarity calculation on the transaction resource storage entity information of the target object and the preset transaction resource storage entity information contained in the preset account information to obtain a third similarity; and calculate the account similarity based on the first similarity, the second similarity, and the third similarity.
[0217] In one embodiment of the present application, based on the aforementioned scheme, the acquisition unit 1110 is further used to obtain preset transaction feature information, the preset transaction feature information includes transaction feature information between a preset object and other objects associated with the preset object, and the transaction security of the account information of the preset object is lower than the preset security threshold; the calculation unit 1130 is further used to calculate the transaction feature similarity between the transaction feature information between the target object and other objects and the preset transaction feature information; and calculate the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature similarity, the preset transaction resource flow information and the preset account information.
[0218] In one embodiment of the present application, based on the aforementioned scheme, the transaction security information includes an abnormal transaction indicator of the target object; the output unit 1140 is used to output a prompt message of transaction failure to the target object if the abnormal transaction indicator is greater than a first preset abnormal transaction indicator and the target object is detected to trigger a transaction; if the abnormal transaction indicator is less than the first preset abnormal transaction indicator and greater than a second preset abnormal transaction indicator, and the target object is detected to trigger a transaction, output a prompt message of pending identification verification to the target object.
[0219] In one embodiment of the present application, based on the aforementioned scheme, after outputting prompt information for identity authentication to the target object, the processing unit 1120 is further used to update the abnormal transaction indicator if identification information sent by the target object is received and the identification information is verified, so that the updated abnormal transaction indicator is less than the second preset abnormal transaction indicator.
[0220] It should be noted that the apparatus provided in the aforementioned embodiment and the method provided in the aforementioned embodiment belong to the same concept, wherein the specific manner in which each module and unit performs operations has been described in detail in the method embodiment.
[0221] An embodiment of the present application also provides a transaction security management device, including: one or more processors; a memory for storing one or more programs, which, when executed by one or more processors, enables the electronic device to implement the transaction security management method as described above.
[0222] Figure 12 It is a structural diagram of a computer system suitable for implementing the transaction security management device of the embodiment of the present application.
[0223] It should be noted that Figure 12 The computer system 1200 of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0224] like Figure 12 As shown, the computer system 1200 includes a central processing unit (CPU) 1201, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1202 or the program loaded from the storage part 1208 into the random access memory (RAM) 1203, such as executing the method in the above embodiment. Various programs and data required for system operation are also stored in the RAM 1203. The CPU 1201, ROM 1202 and RAM 1203 are connected to each other via a bus 1204. An input / output (I / O) interface 1205 is also connected to the bus 1204.
[0225] The following components are connected to the I / O interface 1205: an input section 1206 including a keyboard, a mouse, and the like; an output section 1207 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 1208 including a hard disk; and a communication section 1209 including a network interface card such as a LAN (Local Area Network) card or a modem. The communication section 1209 performs communication processing via a network such as the Internet. A drive 1210 is also connected to the I / O interface 1205 as needed. Removable media 1211, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 1210 as needed, so that computer programs read from the removable media can be installed in the storage section 1208 as needed.
[0226] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1209, and / or installed from a removable medium 1211. When the computer program is executed by the central processing unit (CPU) 1201, the various functions defined in the system of the present application are executed.
[0227] It should be noted that the computer-readable medium shown in the embodiments of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable computer program. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. A computer program embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0228] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. Among them, each box in the flowchart or block diagram can represent a module, program segment, or part of the code, and the above-mentioned module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0229] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. In some cases, the names of these units do not constitute limitations on the units themselves.
[0230] Another aspect of the present application provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the transaction security management method described above. The computer-readable medium may be included in the electronic device described in the above embodiments, or may exist independently and not be incorporated into the electronic device.
[0231] Another aspect of the present application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable medium. A processor of a computer device reads the computer instructions from the computer-readable medium and executes the computer instructions, causing the computer device to perform the transaction security management method provided in each of the above embodiments.
[0232] The above content is only a preferred exemplary embodiment of the present application and is not intended to limit the implementation scheme of the present application. Ordinary technicians in this field can easily make corresponding changes or modifications based on the main ideas and spirit of the present application. Therefore, the scope of protection of the present application shall be based on the scope of protection required by the claims.
Claims
1. A transaction security management method, characterized in that: include: Obtain transaction information of the target object within a preset time period; Acquire other objects associated with the target object based on the transaction information of the target object, and construct transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects; Calculating transaction security information of the target object based on the transaction resource flow information, the target object's account information, transaction feature information between the target object and the other objects, preset transaction resource flow information, preset account information, and preset transaction feature information; The transaction triggered by the target object is securely managed based on the transaction security information.
2. The method according to claim 1, characterized in that The other objects include at least one of a first object and a second object; The acquiring other objects associated with the target object based on the transaction information of the target object, and constructing transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects, includes: If it is detected that the transferred transaction resources exist between the target object and the first object, transaction resource flow information corresponding to the target object is constructed based on a second object associated with at least one of the target object and the first object.
3. The method according to claim 2, characterized in that The constructing transaction resource flow information corresponding to the target object based on a second object associated with at least one of the target object and the first object includes: If there is a second object associated with the target object, and the second object is not associated with the first object, then based on the transaction resource transfer direction between the first object and the target object, and the transaction resource transfer direction between the second object and the target object, the transaction resource flow information corresponding to the target object is constructed.
4. The method according to claim 2, characterized in that The constructing transaction resource flow information corresponding to the target object based on a second object associated with at least one of the target object and the first object includes: If there is a second object associated with both the target object and the first object, transaction resource flow information corresponding to the target object is constructed based on the transaction resource transfer direction between the first object and the target object, the transaction resource transfer direction between the second object and the target object, and the transaction resource transfer direction between the first object and the second object.
5. The method according to claim 1, wherein The calculating of the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature information between the target object and the other objects, the preset transaction resource flow information, the preset account information, and the preset transaction feature information includes: Acquiring the preset account information, wherein the preset account information includes account information whose transaction security is lower than a preset security threshold; Calculating the account similarity between the target object's account information and the preset account information; The transaction security information of the target object is calculated based on the transaction resource flow information, the account similarity, the transaction feature information between the target object and the other objects, the preset transaction resource flow information and the preset transaction feature information.
6. The method according to claim 5, characterized in that The calculating the account similarity between the target object's account information and the preset account information includes: If the target object's account information includes the target object's identification information, performing similarity calculation between the target object's identification information and the preset identification information included in the preset account information to obtain a first similarity; If the target object's account information includes the target object's transaction behavior information, performing similarity calculation on the target object's transaction behavior information and the preset transaction behavior information included in the preset account information to obtain a second similarity; If the target object's account information includes the target object's transaction resource storage entity information, performing similarity calculation on the target object's transaction resource storage entity information and the preset transaction resource storage entity information included in the preset account information to obtain a third similarity; The account similarity is calculated based on the first similarity, the second similarity, and the third similarity.
7. The method according to claim 1, characterized in that The calculating of the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature information between the target object and the other objects, the preset transaction resource flow information, the preset account information, and the preset transaction feature information includes: Acquiring the preset transaction characteristic information, the preset transaction characteristic information including transaction characteristic information between a preset object and other objects associated with the preset object, wherein transaction security of the account information of the preset object is lower than a preset security threshold; Calculating transaction feature similarity between the transaction feature information between the target object and the other objects and the preset transaction feature information; The transaction security information of the target object is calculated based on the transaction resource flow information, the account information of the target object, the transaction feature similarity, the preset transaction resource flow information and the preset account information.
8. The method according to claim 1, characterized in that The transaction security information includes abnormal transaction indicators of the target object; The performing security management on the transaction triggered by the target object based on the transaction security information includes: If the abnormal transaction index is greater than a first preset abnormal transaction index and the target object is detected to have triggered a transaction, a prompt message indicating that the transaction has failed is output to the target object; If the abnormal transaction indicator is smaller than the first preset abnormal transaction indicator and larger than the second preset abnormal transaction indicator, and the target object is detected to trigger a transaction, prompt information for pending identification verification is output to the target object.
9. The method according to claim 8, characterized in that After outputting prompt information for identity authentication to the target object, the method further includes: If the identification information sent by the target object is received and the identification information is verified, the abnormal transaction index is updated so that the updated abnormal transaction index is smaller than the second preset abnormal transaction index.
10. A transaction security management device, characterized in that: include: An acquisition unit, configured to acquire transaction information of a target object within a preset time period; a processing unit configured to detect other objects associated with the target object based on the transaction information of the target object, and construct transaction resource flow information corresponding to the target object based on the transaction information between the target object and the other objects; a calculation unit, configured to calculate the transaction security information of the target object based on the transaction resource flow information, the account information of the target object, the transaction feature information between the target object and the other objects, the preset transaction resource flow information, the preset account information, and the preset transaction feature information; The processing unit is further configured to perform security management on the transaction triggered by the target object based on the transaction security information.
11. A transaction security management device, characterized in that: include: a memory storing computer-readable instructions; A processor reads the computer-readable instructions stored in the memory to execute the method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that Computer-readable instructions are stored thereon, and when the computer-readable instructions are executed by a processor of a computer, the computer is caused to execute the method according to any one of claims 1 to 9.