Abnormal advertisement processing method and device, equipment and medium
By monitoring the duration of ad jumps and combining it with user feedback, the problem of untimely identification of abnormal ads in existing technologies is solved, active defense and accurate identification of malicious ads are achieved, and user experience and device security are improved.
Patent Information
- Application Number
- CN202510855786.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-10-10
AI Technical Summary
Existing technologies are unable to detect and handle abnormal advertisements in a timely manner, which affects user experience and device security. Rule matching technology is not updated in a timely manner, is highly dependent on user feedback, and has low recognition accuracy.
By monitoring the duration of ad jumps and exiting the site and combining it with user feedback, we can determine whether the ad behavior is abnormal. We use the background control module to trigger user feedback when the duration of the jumps and exits exceeds the threshold, and identify malicious ads through comprehensive rule matching and user feedback.
It achieves active defense against abnormal advertisements, improves the timeliness and accuracy of identification, reduces misjudgments and missed judgments, and enhances user experience and security.
Smart Images

Figure CN120768580A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security, and in particular to a method for processing abnormal advertisements and its apparatus, equipment, and medium. Background Art
[0002] Application providers often load advertising interfaces into their applications or load websites, such as online stores, which often also load advertising interfaces within their pages. Advertising, as a common monetization method, is beneficial for the operation of applications and online stores. However, with the development of advertising technology, the problem of malicious advertising has become increasingly prominent. Malicious ads not only consume system resources and affect the user experience, but may also contain malicious code, posing a threat to the security of user devices. Therefore, how to effectively monitor and address the security of advertising interfaces has become a pressing technical challenge.
[0003] Traditional ad monitoring technology relies primarily on rule matching and user complaints. Rule matching technology identifies and blocks ads by pre-setting a series of rules, such as specific domain names, URL features, tags, class names, styles, DOM structures, and the size and position of ads. While this method can identify known malicious ads to a certain extent, it has obvious limitations. First, rules need to be constantly updated to adapt to new ad formats. However, ad formats and delivery strategies are constantly changing, and new ad links are constantly emerging. Rule updates often cannot keep up with the speed of ad changes, resulting in some malicious ads not being effectively blocked. Second, rule matching technology has limited recognition and blocking effectiveness for dynamically loaded ad content, as rules can typically only match static page elements. In addition, overly strict rules may lead to false blocking, misidentifying some normal content as ads and blocking them, affecting users' access to normal content.
[0004] User complaint technology relies on users proactively providing feedback and filing complaints after encountering malicious ads. Developers then analyze and process relevant links based on this user feedback, such as blacklisting them for blocking. However, this approach also presents numerous issues. First, most malicious ads draw users away from the original application, preventing them from providing timely feedback on malicious ads they encounter, and their willingness to provide feedback is low, preventing developers from promptly identifying and addressing anomalous links. Second, due to the limitations of user feedback, only anomalous links reported by users can be identified and addressed; anomalous links that have not received user feedback remain undetected and unblocked. Finally, relying solely on user feedback to identify anomalous links lacks in-depth analysis of the link's characteristics and behavior, resulting in low recognition accuracy.
[0005] In actual applications, after users click on an ad link, they are often directed to an external webpage or application, making it difficult for them to return to the original application. In this case, even if users want to provide feedback, it is difficult to find the feedback entry point, resulting in uncertainty about the timeliness and accuracy of user feedback. Furthermore, even if users can return to the original application, the feedback process can be cumbersome, further reducing their willingness to provide feedback. These issues lead to significant deficiencies in existing technologies for ad monitoring and processing, making it impossible to detect abnormal ads in a timely manner and unable to provide proactive defense, thus affecting user experience and device security.
[0006] From this, we can see that existing technologies are unable to detect specific types of abnormal advertisements in a timely manner and cannot play a proactive defense role, thereby affecting user experience and device security. Therefore, improvement is urgently needed. Summary of the Invention
[0007] The purpose of the present application is to solve at least one of the above problems and provide a method for processing abnormal advertisements and its corresponding apparatus, device, non-volatile readable storage medium, and computer program product.
[0008] According to one aspect of the present application, a method for processing abnormal advertisements is provided, comprising:
[0009] In response to a touch event on an advertisement entry in the current page, determining whether a target link of the advertisement entry hits a malicious advertisement link library, and if so, prohibiting a jump to the advertisement page corresponding to the advertisement entry;
[0010] If no hit occurs, the background control module is called to start calculating the jump-off duration, and jump to the target link to load the advertisement page;
[0011] When the jump-off duration exceeds a preset duration threshold, it is determined that the advertising behavior of the target link constitutes an abnormal advertisement, and a notification event for collecting user feedback information is triggered through the background control module;
[0012] Based on the user feedback information submitted in response to the notification event and the jump exit duration, it is determined whether the target link is of a malicious type, and feature data of the target link of the malicious type is updated to the malicious advertisement link library.
[0013] According to another aspect of the present application, there is provided an abnormal advertisement processing device, comprising:
[0014] A hit control module is configured to respond to a touch event acting on an advertisement entry in the current page, determine whether a target link of the advertisement entry hits a malicious advertisement link library, and when a hit occurs, prohibit jumping to the advertisement page corresponding to the advertisement entry;
[0015] The jump monitoring module is configured to call the background control module to start calculating the jump exit duration when a hit is not received, and jump to the target link to load the advertisement page;
[0016] an abnormality identification module configured to determine that the advertising behavior of the target link constitutes an abnormal advertisement when the jump-off duration exceeds a preset duration threshold, and trigger a notification event for collecting user feedback information through the background control module;
[0017] The feedback confirmation module is configured to determine whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit time, and update the feature data of the target link that is malicious to the malicious advertising link library.
[0018] According to another aspect of the present application, an abnormal advertisement processing device is provided, comprising a central processing unit and a memory, wherein the central processing unit is configured to call and run a computer program stored in the memory to execute the steps of the method described in the present application.
[0019] According to another aspect of the present application, a non-volatile readable storage medium is provided, which stores a computer program implemented according to the abnormal advertisement processing method in the form of computer-readable instructions. When the computer program is called and executed by a computer, the steps included in the method are executed.
[0020] According to another aspect of the present application, a computer program product is provided, comprising a computer program / instruction, which implements the steps of the method when executed by a processor.
[0021] Compared with traditional technologies, this application realizes active defense and accurate identification of abnormal advertisements by combining jump-off time monitoring with user feedback mechanism. On the one hand, the background control module is introduced to monitor user jump behavior in real time. When the time of leaving the application exceeds the threshold, the feedback notification is triggered actively. Even if the user is taken away from the original application, user feedback can be obtained in time, which makes up for the deficiency of traditional technology relying on users to actively return feedback, and effectively improves the timeliness of abnormal advertisement discovery. On the other hand, the rule matching and user feedback are organically combined, which not only uses rules to quickly identify known malicious advertisements, but also uses user feedback to expand the recognition range and cover newly emerging malicious advertisements, significantly enhancing the comprehensiveness of malicious advertisement identification. At the same time, the objective technical parameter of jump-off time and the subjective evaluation of user feedback are comprehensively considered, and advertisements are evaluated from both subjective and objective dimensions, which greatly improves the accuracy of abnormal advertisement identification, reduces misjudgment and missed judgment, provides users with a safer and smoother user experience, and strongly promotes the progress of advertisement monitoring technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1This is an exemplary network architecture for this application;
[0023] Figure 2 This is a flowchart of an embodiment of the abnormal advertisement processing method of the present application;
[0024] Figure 3 This is a principle block diagram of the abnormal advertisement processing device of this application;
[0025] Figure 4 This is a structural diagram of an abnormal advertisement processing device used in this application. DETAILED DESCRIPTION
[0026] This application proposes an innovative abnormal advertisement processing method and its corresponding apparatus, equipment and medium, aiming to enhance the application's ability to proactively, comprehensively and accurately identify and process abnormal advertisements through advanced technical means.
[0027] like Figure 1 As shown, the exemplary network architecture of the present application mainly includes a data server 81 and a terminal device 80. The terminal device 80 is an interface for direct user interaction. By running the application according to the present application, which is a computer program product implemented according to the abnormal advertisement processing method of the present application, it can load internal or external website pages and allow these pages to load advertisement interfaces. These advertisement interfaces will load corresponding advertisement content for users to browse. These advertisement contents can come from a third-party server 82. The application can identify the security of these advertisement contents and make corresponding processing. The data server 81 is used to assist the application of the terminal device in identifying the security of advertisement content. For example, it can update and provide a malicious advertisement link library for it to provide a basis for identifying whether the advertisement content belongs to known malicious advertisements. For example, the data server 81 can provide an interface for the terminal device to call so that the application can upload relevant data to the data server 81, so that the data server 81 can update the malicious advertisement link library, determine whether the advertisement behavior of the relevant target link constitutes abnormal advertisement, train and update various models used in this application, etc.
[0028] In an exemplary application scenario, a user is browsing an online store page using an application, and the page loads multiple advertising interfaces. When the user clicks on one of the advertising interfaces, the application first determines whether the target link of the advertising interface matches a malicious advertising link library. If so, the application prevents redirection to the advertising page, thereby protecting the user from malicious ads. If not, the application calls the backend control module to begin calculating the jump-out duration and redirects to the target link to load the advertising page. If the user stays on the advertising page for a period of time and then returns to the original application, the application records the jump-out duration. If the jump-out duration exceeds a preset threshold, the application determines that the advertising behavior of the target link constitutes an abnormal advertisement and triggers a notification event through the backend control module to collect user feedback. The user can submit feedback through the feedback interface. The application then determines whether the advertising behavior of the target link is malicious based on the user feedback and updates the malicious advertising link library with the signature data indicating malicious behavior. In this way, the present application not only detects and handles abnormal ads in a timely manner, but also continuously optimizes the accuracy and timeliness of malicious ad identification through user feedback, providing users with a safer and smoother user experience.
[0029] See also Figure 2 According to the abnormal advertisement processing method provided by the present application, a computer program product can be installed and run on a server to implement a data collection system. In some embodiments, the method includes the following steps:
[0030] Step S3100: In response to a touch event on an advertisement entry in the current page, determining whether a target link of the advertisement entry hits a malicious advertisement link library; if so, prohibiting a jump to the advertisement page corresponding to the advertisement entry;
[0031] The application of this application contains multiple pages that users can switch and interact with. These pages can be provided by the application's own internal site or by external sites. The page the user is browsing is called the current page. When the user interacts with the advertising entrance on the current page, for example, by clicking on the advertising entrance through a touch operation, the application will respond to this touch event and perform a series of judgment and processing operations.
[0032] Specifically, the application determines whether the target link of the ad entry hits the malicious ad link library. The malicious ad link library of this application is a database containing multiple known malicious ad link feature data. These feature data are diverse and may include, for example, specific domain names, URL structures, keywords, HTTP header information, etc. The malicious ad link library can be updated and maintained by the data server and updated from the data server when the application is started to ensure that it contains the latest malicious ad link information.
[0033] The ad portal in this application refers to the area on the application page that displays advertising content. Users can trigger the action of jumping to the ad page through touch operations such as clicking. The target link in this application refers to the URL link of the ad page that the application is going to jump to after the user touches the ad portal.
[0034] Determining whether the target link of an ad entry matches a malicious ad link library can be done in a variety of ways. For example, a simple string matching approach can be used to check whether the target link's URL contains specific domain names or keywords recorded in the malicious ad link library. Alternatively, more complex pattern matching algorithms, such as regular expression matching, can be used to identify malicious links with specific patterns. Furthermore, machine learning models can be combined to make a comprehensive judgment based on multiple link characteristics to improve the accuracy and reliability of the judgment.
[0035] If the result indicates that the target link of an ad entry hits a malicious ad link library, meaning the link is identified as a known malicious ad link, the application will prevent the user from being redirected to the ad page corresponding to the ad entry. This measure effectively prevents users from being directed to malicious ad pages, thereby protecting users from malicious ads and potential security threats. For example, if a user clicks an ad link whose target link hits a malicious ad link library, the application will prevent the user from being redirected to the ad page and may display a warning message to inform the user that the ad link may contain malicious content.
[0036] For example, suppose the malicious ad link library stores the signature information "example.com / ad." When a user taps an ad entry, the application retrieves the target link "http: / / example.com / ad?param=123." Using a string matching algorithm, the application detects that the target link contains the signature "example.com / ad" from the malicious ad link library. Therefore, the application determines that the target link matches the malicious ad link library and immediately disables the redirect, preventing the user from reaching the malicious ad page.
[0037] Step S3200: If no hit occurs, the background control module is called to start calculating the jump-off duration, and jump to the target link to load the advertisement page;
[0038] If the malicious ad link library is not hit, meaning the target link of the ad entry is not identified as a known malicious ad link, the application will call the background control module to perform further operations. The background control module is pre-installed in the application and is responsible for monitoring user behavior after jumping from the current page to the target link, calculating the length of time the user stays on the target link page (jump exit time), and performing subsequent processing.
[0039] In one embodiment, the background control module can be implemented through page code. Specifically, when the application loads the advertising page, it can embed a script in the page code to record the timestamps of the user entering and leaving the advertising page. When the user clicks on the advertising entrance and jumps to the target link, the script starts timing; when the user returns to the original application or closes the advertising page, the script stops timing and calculates the jump-out duration. For example, assuming that the user clicks on a target link and is released, the application program loads the advertising page corresponding to the target link. When the user enters the advertising page, the application records the time the user enters the page as the jump-out duration through the script in the page code. When the user returns to the original application after browsing for a period of time, or when the application is cleared by the operating system background, the calculation of the jump-out duration stops. If the duration exceeds the preset duration threshold, the application will determine that the advertising behavior of the target link constitutes an abnormal advertisement.
[0040] In another embodiment, the background control module can be implemented based on the mechanism of the operating system. Many modern operating systems provide background task management functions, allowing applications to run some lightweight tasks in the background. Applications can use these functions to start a timing task in the background to calculate the length of time the user stays on the target link page. For example, in the Android operating system, applications can use the Service component to implement background timing tasks; in the iOS operating system, the Background Tasks API can be used to implement similar functions. When the user clicks on the advertisement entrance and jumps to the target link, the background task starts timing to record the jump-out time in real time; when the user returns to the original application, closes the advertisement page, or the application is cleared by the operating system background, the background task stops timing. If the duration exceeds the preset duration threshold, the application will determine that the advertising behavior of the target link constitutes an abnormal advertisement.
[0041] Both implementations effectively monitor the duration of a user's stay after redirecting to a target link, and use a preset duration threshold as objective data to determine whether advertising behavior constitutes anomalies. Through the monitoring capabilities of the backend control module, the application can still collect user behavior data even when the user is unable to return to the original application, providing objective evidence for subsequent identification and handling of anomalous ads.
[0042] Step S3300: When the jump-out duration exceeds a preset duration threshold, it is determined that the advertising behavior of the target link constitutes an abnormal advertisement, and a notification event for collecting user feedback information is triggered through the background control module;
[0043] When the jump-out duration exceeds the preset duration threshold, the application will determine that the advertising behavior of the target link constitutes abnormal advertising, and trigger a notification event to collect user feedback information through the background control module, so as to further confirm the nature of the advertising behavior through user feedback, thereby improving the accuracy and reliability of abnormal advertising identification.
[0044] In practice, the backend control module can immediately initiate a notification mechanism upon detecting that the duration of a page transition exceeds a preset threshold. This notification mechanism can be implemented in a variety of ways, such as through the application's internal messaging system, the operating system's notification service, or an external browser plug-in. These notifications will guide users to evaluate the ad page they just viewed and provide feedback.
[0045] User feedback can be collected by displaying a user feedback interface when the user handles the notification event. This interface can be a pop-up window within the application or a plug-in interface in an external browser. The user feedback interface asks the user for their subjective evaluation of the ad page, such as whether the ad is misleading, contains malicious content, or affects the user experience. Users can submit their evaluation by selecting pre-set options or entering customized feedback.
[0046] It's important to note that abnormal advertising refers to a suspected situation; while the presence of an abnormal link in a target link doesn't necessarily constitute malicious advertising, determining whether the target link constitutes malicious advertising can be determined in subsequent steps after the user submits feedback. This is done by conducting a comprehensive analysis based on subjective and objective information, either locally implemented in the application or via a remote interface that calls into the data server's business logic.
[0047] Step S3400: Determine whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit duration, and update the feature data of the target link that is malicious to the malicious advertisement link library.
[0048] The notification event sent by the background monitoring module will guide the user to the user feedback interface. For example, in different embodiments, if the notification event is delivered through a system message, or through the application's own internal message system, the user can quickly enter the user feedback interface of the application of this application by touching the corresponding message. If the notification event is delivered through a plug-in pre-installed in an external browser, the plug-in can display a feedback control above the advertising page the user is browsing, and the user can enter the corresponding user feedback page after touching the feedback control. After the user enters the user feedback page, he can submit his evaluation information as disclosed above, providing subjective evaluation data for identifying whether the target link is malicious.
[0049] Specifically, when a user responds to a notification event and enters the user feedback interface, the user can submit a subjective evaluation of the advertising page. These evaluations may include, but are not limited to, whether the advertisement is misleading, whether it contains malicious content, whether it affects the user experience, etc. User feedback information is one of the important bases for judging the nature of the target link advertising behavior, but it contains subjectivity and therefore cannot be used as a sufficient condition. For example, if a user feedback advertisement page contains malicious code or misleading content, this will serve as an important reference for judging that the advertising behavior may be malicious. However, in this application, the objective premise that the jump-out time exceeds the preset threshold must also be considered.
[0050] Therefore, after receiving user feedback information, the application combines previously collected objective data such as the jump exit time to conduct a further comprehensive analysis of the advertising behavior of the target link. When the comprehensive analysis results show that the advertising behavior of the target link is of a malicious type, the application can perform an update operation on the malicious advertising link library based on the target link. Specifically, the application can extract advertising type labeling information representing the user's subjective evaluation from the user feedback information. This advertising type labeling information can be the type information that requests the user to make a preliminary judgment in the user feedback interface. For example, the user can mark the target link as "malicious type" or other more vague similar expressions through the user feedback interface, thereby generating this advertising type labeling information. The application constructs the entire user feedback letter information and the corresponding target link and jump exit time into link access data. Then, the preset link classification model is called, and the model determines whether the target link is of a malicious type based on the link access data. If the link classification model again determines that the target link is of a malicious type, and this determination result is consistent with the semantics of the advertisement type annotation information submitted by the user, the application can finally confirm that the target link is of a malicious type. Based on this, feature data can be extracted from the target link and added to the malicious advertisement database to achieve incremental updates to the malicious advertisement database.
[0051] The above process first uses the jump exit duration as an objective evaluation premise, and then relies on user feedback information for subjective evaluation. It also combines objective data such as the jump exit duration to make a comprehensive judgment through the link classification model. The results obtained by the model are then cross-checked with the user's ad type annotation information. Based on the cross-checking results, the target link that constitutes a malicious type is confirmed, ensuring the accuracy and reliability of malicious ad identification.
[0052] For confirmed malicious target links, feature data can be extracted and promptly added to the malicious ad link library. For example, in the example mentioned above, if a user reports that the ad page of the link "http: / / example.com / ad?param=123" contains malicious code and the jump time exceeds the preset threshold, the link classification model also determines that the link is malicious, and after mutual confirmation with the user's subjective evaluation, the application can extract the feature data of the link, such as the specific domain name "example.com", URL parameter "ad", etc., and update this feature data to the malicious ad link library. In this way, when the user subsequently touches a similar link again, the application can more quickly and accurately identify and prevent the jump, thereby effectively protecting the user from the interference of malicious ads and potential security threats.
[0053] Since the malicious advertisement link library can be centrally maintained by a data server, this step can also be implemented by the data server, and the data server can update the malicious advertisement link library in a timely manner, and each application can update it locally.
[0054] This application effectively addresses the shortcomings of existing technologies in monitoring and processing abnormal advertisements through innovative technical solutions, achieving significant technical advantages and beneficial effects, including but not limited to:
[0055] First, the present application realizes an active defense mechanism that can be executed efficiently in the dynamic identification of abnormal advertisements. In the existing technology, advertisement monitoring mainly relies on rule matching and user complaints, and both methods have obvious limitations. Rule matching technology needs to be constantly updated to adapt to new advertisement formats, and has limited effect on the identification of dynamically loaded advertisement content; user complaint technology relies on active feedback from users, and the timeliness and accuracy of feedback cannot be guaranteed. The present application can monitor the user's behavior in real time through the background control module after the user clicks on the advertisement link, even if the user is taken away from the original application, and actively trigger the user feedback mechanism when the jump-off time exceeds the preset threshold. This active defense mechanism can not only detect abnormal advertisements in a timely manner, but also effectively collect user feedback when the user cannot return to the original application, thereby realizing the dynamic identification and processing of abnormal advertisements.
[0056] Secondly, this application organically combines rule matching technology with user complaint technology to improve the ability to comprehensively identify malicious advertisements. In the existing technology, although rule matching technology can identify known malicious advertisements to a certain extent, its recognition effect is limited for new advertisement formats and dynamically loaded advertisement content. User complaint technology relies on active feedback from users, and the timeliness and accuracy of the feedback cannot be guaranteed. By combining rule matching technology with user complaint technology, this application not only uses rule matching technology to quickly identify and block known malicious advertisements, but also identifies and processes unknown malicious advertisements through user feedback information. This combination not only improves the comprehensiveness of malicious advertisement identification, but also can promptly discover and process newly emerging malicious advertisements, thereby improving the overall malicious advertisement identification capability.
[0057] Finally, this application integrates both subjective and objective information to improve the accuracy of identifying abnormal advertisements. In the existing technology, rule matching technology mainly relies on preset rules and lacks in-depth analysis of advertising content and user behavior; user complaint technology relies entirely on users' subjective feedback and lacks the support of objective data. This application not only objectively analyzes the behavioral characteristics of advertisements from a technical perspective by comprehensively considering the jump exit time and user feedback information, but also subjectively evaluates the nature of advertisements from the user's perspective. This method of integrating subjective and objective information not only improves the accuracy of abnormal advertisement identification, but also effectively reduces misjudgments and missed judgments, thereby providing users with a safer and smoother user experience.
[0058] Based on any embodiment of the method of the present application, before determining whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit duration, the method includes:
[0059] Step S1110: Based on the notification event, the background control module sends a plug-in assistance notification to the external browser used to open the target link, driving the plug-in pre-installed in the external browser to pop up a user feedback interface based on the configuration information provided in the plug-in assistance notification;
[0060] The backend control module can be flexibly implemented to adapt to the method of opening the target link. In this embodiment, when the user touches the advertisement entrance, the browser default to the operating system or the browser selected by the user opens the corresponding target link and loads the corresponding advertisement page. This browser constitutes an external browser for the application where the current page is located.
[0061] Applications have relatively limited control over external browsers. In this case, the application can pre-install a corresponding plug-in in the external browser to cooperate with the application to collect user feedback information at runtime. The backend control module sends a plug-in assistance notification to the external browser used to open the target link, providing important subjective evaluation data for subsequent malicious ad identification.
[0062] Specifically, after detecting that the duration of a redirection exceeds a preset threshold, the backend control module triggers a notification event. This notification event contains sufficient information for the application to identify the target link requiring user feedback. The backend control module then uses this notification event to send a plug-in assistance notification to the external browser. This notification is specifically designed to communicate with the pre-installed plug-in in the external browser and contains the necessary configuration information to instruct the plug-in on how to pop up the user feedback interface and submit user feedback information.
[0063] Configuration information may include, but is not limited to, the style, location, and prompts of the feedback interface to ensure that users clearly understand how to provide feedback. For example, configuration information may specify whether the feedback interface should be displayed at the top, bottom, or sidebar of the browser window, and what types of feedback options the feedback interface should include, such as "malicious ads," "normal ads," "misleading content," and other descriptive information.
[0064] When the external browser receives a plugin assistance notification, the pre-installed plugin will pop up a user feedback interface based on the configuration information in the notification. This interface serves as a bridge for users to interact with the application, allowing them to submit their subjective evaluation of the target link's advertising behavior. For example, if a user discovers malicious code or misleading content after viewing an ad page, they can submit relevant feedback through the feedback interface.
[0065] In one embodiment, the configuration information can first drive the plug-in to display a control on an external browser. When the user touches the control, the user feedback interface is displayed and the feedback page preset in the configuration information is loaded. When the user enters relevant user feedback information in the user feedback interface, a submit event is triggered, and the user feedback information can be returned to the background control module.
[0066] Step S1120: The preset plug-in obtains user feedback information submitted by the user through the user feedback interface, where the user feedback information includes advertisement type labeling information and advertisement problem description information submitted by the user.
[0067] The user feedback interface can be displayed at the top, bottom or sidebar of the browser window, and the specific location is specified by the configuration information. According to the configuration information sent by the background control module, the feedback interface can include a variety of feedback options, such as "malicious ads", "normal ads", "misleading content", etc. These options have the function of representing the type of ads subjectively selected by the user, and therefore constitute ad type labeling information. In addition, the feedback interface can also allow users to submit other ad problem description information, allowing users to use natural language to describe richer problem content in order to provide a more comprehensive subjective evaluation. Users can submit their subjective evaluation by selecting these options or entering customized feedback, and the corresponding user feedback information can be returned to the background control module for subsequent determination of whether the target link is of a malicious type.
[0068] Through the above embodiments, the present application can effectively solve the problem of how to obtain user feedback information after the user is taken away from the original application by the target link. After the jump exit time expires, the background control module sends a plug-in assistance notification to the external browser according to the notification event, and drives the preset plug-in to pop up the user feedback interface, ensuring that even if the user leaves the original application, user feedback can be obtained through the plug-in in the external browser. Further, the user feedback information submitted by the user is obtained through the preset plug-in, including advertising type labeling information and other descriptive information. This information provides important subjective evaluation data for subsequent determination of whether the target link is of a malicious type. This mechanism not only improves the efficiency of obtaining user feedback, but also enhances the accuracy and reliability of abnormal advertising identification, so that the present application can still effectively collect user feedback when the user cannot directly return to the original application, providing strong support for the identification and processing of abnormal advertisements.
[0069] Based on any embodiment of the method of the present application, before determining whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit duration, the method includes:
[0070] Step S1210: Requesting the operating system to send a system message through the background control module according to the notification event, and associating the system message as an entrance to the user feedback interface;
[0071] In this embodiment, the user is taken away from the original application and may jump to a third-party application or a browser that does not pre-install the plug-in of this application. In this case, it is impossible to obtain user feedback information by pre-installing the plug-in of this application. Therefore, this embodiment is based on system messages to achieve the purpose of obtaining user feedback information, so as to provide important subjective evaluation data for subsequent malicious advertising identification.
[0072] Similarly, the backend control module triggers a notification event after detecting that the duration of the jump to the exit exceeds a preset threshold. This notification event contains sufficient information for the application to identify the target link requiring user feedback. The backend control module then uses this notification event to request a system message from the operating system and associates this system message with the entry point for the user feedback interface built into the application, allowing users to access the feedback interface through the system message.
[0073] System messages can be presented to users in a variety of forms supported by the operating system, such as notification bar messages, pop-up messages, etc. These system messages can contain links or buttons pointing to the user feedback interface. Users can directly enter the user feedback interface built into the application of this application by clicking these links or buttons. The advantage of this mechanism is that it directly provides users with access to the user feedback interface through the operating system's notification system, which is not affected by the destination of the target link, thereby improving the efficiency of obtaining user feedback.
[0074] In practice, the content and format of system messages can be tailored to different operating systems and user devices. For example, on Android, notification messages can be displayed; users can click on them to directly access the user feedback interface of the application. On iOS, local or remote notifications can be used; users can click on them to access the user feedback interface built into the application. These system messages can include concise and clear prompts, informing users that the message is related to the ad page they previously viewed and guiding them to provide feedback.
[0075] Step S1220: When the user accesses the system message, the user feedback interface pops up, and user feedback information is obtained through the user feedback interface. The user feedback information includes advertisement type labeling information and advertisement problem description information submitted by the user.
[0076] When a user accesses the system message sent by the backend control module, a user feedback interface built into the application of this application will pop up. This user feedback interface serves as a bridge for user interaction with the application, allowing users to submit subjective evaluations of the target link's advertising behavior. Similar to the previous embodiment, user feedback information includes user-submitted ad type annotations and ad problem descriptions, providing important subjective evaluation data for subsequent determination of whether the target link is malicious.
[0077] Since the user feedback interface of this embodiment is provided by the application of this application, when the user accesses the system message, he actually returns to the application. The application can also continue to use this user feedback information to determine whether the target link is malicious.
[0078] This embodiment effectively solves the problem of how to obtain user feedback information after the user is taken away from the original application by the target link by utilizing the system message mechanism. The system message is triggered by the background control module and associated with it as the entrance to the user feedback interface, ensuring that even if the user jumps to a third-party application or a browser without pre-installed plug-ins, it can quickly return to the original application through the system message and provide feedback. This mechanism is not affected by the destination of the target link, improves the efficiency of obtaining user feedback, and enhances the accuracy and reliability of abnormal advertising identification. At the same time, since the user feedback interface is provided by the original application, the application can continue to use this user feedback information more quickly to determine whether the target link is of a malicious type, providing strong support for the identification and processing of abnormal advertisements.
[0079] Based on any embodiment of the method of the present application, determining whether the target link is malicious based on user feedback information submitted in response to the notification event and the jump exit duration, and if so, updating the feature data of the target link to the malicious advertisement link library, including:
[0080] Step S3410: Construct the target link and its corresponding user feedback information and jump exit duration into link access data, wherein the user feedback information includes the advertisement type labeling information and advertisement problem description information submitted by the user;
[0081] To facilitate the use of the link classification model in this embodiment to infer whether a target link is malicious, this embodiment first constructs the input data for the link classification model, namely, link access data. Link access data includes the target link to be identified, user feedback information submitted by the user for the target link, and the duration of the application's exit after the user is redirected to the target link.
[0082] As disclosed above, the user feedback information collected by the application of the present application covers the user's subjective evaluation of advertising behavior, specifically including the advertisement type labeling information and advertisement problem description information submitted by the user.
[0083] Ad type labels represent users' initial judgments on the nature of ads, such as "malicious ad," "normal ad," or "misleading content." In practice, users often base their decisions on whether an ad is offensive to them based on their emotions, without considering factors like platform efficiency and technical principles. Consequently, user-generated ad type labels are subjective and unstable. This subjective instability indicates that ad type labels cannot be used blindly and require effective technical implementation.
[0084] Ad problem descriptions are detailed texts written by users in natural language. Users use these descriptions to describe their problems in detail, providing richer details for subsequent analysis. Therefore, ad problem descriptions are more helpful in technically identifying whether a target link is malicious. However, because users use different words and descriptions to describe their problems, the depth of their descriptions varies. Using ad problem descriptions directly as a basis for identification is not only unreliable, but also difficult to obtain highly confident results due to semantic ambiguity.
[0085] Therefore, in this embodiment, the collected user feedback information includes two parts: advertisement type labeling information and advertisement problem description information, which helps to comprehensively consider the user's multi-angle subjective evaluation information. After subsequent reasoning using the model, more reliable analysis results can be obtained.
[0086] The jump-out duration, as objective data, records the time between a user clicking the ad corresponding to the target link and returning to the original application. If this duration exceeds a preset threshold, it indicates that the user may have spent an extended period of time on the ad page. This may be due to unusual content or misleading information on the ad page, making it difficult for the user to quickly return. Since the user leaves the original application, it cannot necessarily be inferred that the target link has engaged in malicious advertising activities. Therefore, the jump-out duration can only serve as a key reference for identifying whether the target link is malicious.
[0087] Although user feedback and the duration of the jump to the exit link each contribute unequally to the purpose of identifying whether a target link is malicious, by combining these two data sets, we can present both subjective and objective evaluation information. Based on this combined information, we can determine with high confidence whether a target link is malicious. Therefore, we construct the target link, user feedback, and the duration of the jump to the exit link into link access data, which serves as the model input for the link classification model of this application.
[0088] Step S3420: calling a preset link classification model to determine whether the target link is malicious based on the link access data;
[0089] This application prepares a link classification model. Through pre-training or fine-tuning, it is able to initially determine whether the target link contained in the link access data constructed by this application is malicious. The link classification model accurately classifies the target link by integrating multiple dimensions such as user feedback information, jump exit time, and the target link itself.
[0090] In one embodiment, the link classification model is implemented using a traditional machine learning model, such as a support vector machine (SVM) or a random forest. These models can identify patterns and features in the data by learning from a large amount of labeled data, thereby classifying new data. During the training phase, the model receives training data containing user feedback information, jump exit time, and target link features, and adjusts the model parameters through an optimization algorithm to minimize classification errors. For example, SVM distinguishes data points of different categories by finding the best hyperplane, while random forest improves the accuracy and stability of classification by constructing multiple decision trees. In practical applications, these models can quickly process the input link access data and give a judgment result on whether the target link is of a malicious type.
[0091] In another embodiment, the link classification model adopts a deep learning model, such as a convolutional neural network (CNN) or a recurrent neural network (RNN). The deep learning model has a powerful feature extraction capability and can automatically learn complex feature representations from raw data. For example, CNN extracts spatial features of data through convolutional layers and pooling layers, and is suitable for processing image and text data; RNN and its variants, long short-term memory networks (LSTM) and gated recurrent units (GRU), can process sequence data and are suitable for analyzing text sequences in user feedback information. During the training process, the deep learning model continuously adjusts the weights between neurons through the backpropagation algorithm to optimize the model performance. These models can process large-scale data sets and perform well in complex scenarios, providing a more accurate basis for determining whether the target link is malicious.
[0092] In another embodiment, the link classification model adopts a large language model, such as a model based on the Transformer architecture. The large language model can understand the semantics and contextual relationships of natural language by pre-training a large amount of text data. Then, by fine-tuning the large language model using link access data and advertisement type labels constructed corresponding to different types of links, it can adapt to specific malicious advertisement identification tasks. The model can learn specific vocabulary and semantic patterns related to malicious advertisements from user feedback information of the link access data, and can conduct a comprehensive analysis of user feedback information, jump exit time, and the characteristics of the target link itself, thereby making a judgment on whether the relevant link is of a malicious type. In actual use, the link access data can be put into a preset prompt template and then input into the large language model. The model can analyze and classify the text based on its pre-trained knowledge and semantic understanding ability, thereby more accurately judging whether the target link is of a malicious type.
[0093] Through the above-mentioned different types of link classification models, this application can more accurately determine whether a target link is malicious based on multi-dimensional data such as the target link in the link access data, user feedback information, and jump-off time. It should be noted that although the jump-off time and the ad classification labeling information and ad problem description information in the user feedback information are each insufficient in determining whether a target link is malicious, after integrating these data, the model, based on its acquired capabilities during training, can more accurately determine whether a target link is malicious by using various key information in these data and the relationships between these key information.
[0094] Step S3430: Although the link classification model can obtain relatively accurate ad type information based on link access data, in actual testing, the confidence level of this result still rarely reaches above 95%, and misjudgments still occur. The main reason for this is that the model itself suffers from machine hallucinations, and the ad problem description information in user feedback information can sometimes interfere with the model's accurate semantic understanding. To address this problem, the present application cleverly improves upon this issue. When the link classification model determines that the target link is malicious, it continues to calculate semantic similarity between this result and the ad type annotation information corresponding to the target link in the user feedback information. If the similarity between these two exceeds a preset confidence threshold, the type result given by the model is considered consistent with the type result given in the ad type annotation information. In other words, the ad type annotation information serves as one of the input data for the link classification model, providing a reference for the model's overall reasoning based on link access data, but the model is not necessarily affected by the ad type annotation information. It also serves to verify the output results of the link classification model based on this input data, so as to examine whether the final classification result is highly consistent with the user's understanding. Only when they are consistent is the target link confirmed to be malicious. Obviously, the advertisement type annotation information plays a role in verifying the model classification results. After confirming that the target link is malicious, feature data can be extracted from the target link and added to the malicious advertisement database.
[0095] This embodiment verifies the determination result of the link classification model through an innovative approach, ensuring that the determination of whether the target link is malicious has higher accuracy and confidence.
[0096] Although the link classification model can perform a comprehensive analysis based on link access data (including target links, user feedback information, and jump exit duration) and provide a judgment result, in actual application, due to the limitations of the model itself and the complexity of user feedback information, especially the description of ad problems, the confidence level of this result may not reach above 90%, which may lead to misjudgment. To address this problem, this embodiment introduces a cross-verification mechanism.
[0097] Specifically, when the link classification model determines that a target link is malicious, the present application further calculates semantic similarity between this result and the ad type annotation information in the user feedback information. Since the model output is a classification label, the type text corresponding to the classification label, such as "malicious type," can be obtained to calculate similarity with the ad type annotation information, such as "malicious ad." The ad type annotation information represents the user's initial judgment of the nature of the ad, such as "malicious ad," "normal ad," or "misleading content." By calculating the semantic similarity between the model's judgment result and the user's ad type annotation information, it is possible to verify whether the model's output is highly consistent with the user's understanding. If the similarity between them exceeds a preset confidence threshold, the model's classification result is considered consistent with the user's classification result, thus confirming that the target link is malicious. In practice, the preset confidence threshold can be set flexibly and relatively low, for example, greater than or equal to 60%. When the model output and the user's predicted result have a similarity of more than 60%, it indicates that the two are substantially consistent, and there is no abnormal situation where the user's prediction is contrary to the model output. In this case, the model output is trustworthy and can be directly used.
[0098] The key to this cross-verification mechanism lies in the fact that ad type annotations not only serve as input to the link classification model, serving as a reference for overall reasoning rather than a decisive factor, but also serve to verify the accuracy of the model's output. This approach effectively leverages user subjective evaluation data, cross-verifying the model's judgment process both before and after the fact, thereby improving its accuracy and reliability.
[0099] After confirming that the target link is of a malicious type, this application extracts feature data from the target link and adds these feature data to the malicious advertisement database, enriching the content of the malicious advertisement database and providing more feature data for subsequent malicious advertisement identification, so as to further improve the accuracy and timeliness of malicious advertisement identification by the terminal device.
[0100] The above embodiments significantly improve the accuracy and confidence of determining whether a target link is malicious by introducing a cross-verification mechanism. Specifically, to address the problem of unstable information value in user feedback, which leads to unstable confidence in the link classification model's inference results and easily leads to misjudgments, the model further incorporates the ad type annotation information in the user feedback information and calculates semantic similarity with the model's inference results. This not only utilizes user subjective evaluation data as a reference for model inference, but also effectively reduces the possibility of misjudgments by verifying the consistency of the model's output results with the user's understanding.
[0101] Through this cross-examination mechanism, the embodiment ensures that the model's determination result is highly consistent with the user's subjective evaluation, thereby improving the reliability and accuracy of the determination result. This method effectively utilizes the user's subjective evaluation data and cross-examines the model's determination process before and after, thereby improving the accuracy and reliability of the determination. After confirming that the target link is of a malicious type, the embodiment extracts feature data from the target link and adds these feature data to the malicious advertisement database. This process not only enriches the content of the malicious advertisement database, but also provides more feature data for subsequent malicious advertisement identification, further improving the accuracy and timeliness of malicious advertisement identification.
[0102] Overall, the embodiment significantly improves the accuracy and confidence of determining whether a target link is of a malicious type by integrating multi-dimensional data such as user feedback information and jump-off duration, and ingeniously introducing a cross-examination mechanism. This method not only considers the output of the model, but also combines the user's subjective evaluation, verifies the model's determination result through semantic similarity calculation, and ensures the accuracy and reliability of the final determination result.
[0103] On the basis of any embodiment of the method of the present application, after determining that the advertising behavior of the target link constitutes an abnormal advertisement, the method comprises:
[0104] Step S4110, count the number of abnormal determinations corresponding to the plurality of target links determined to be abnormal advertisements, and determine the median determination number based on the number of abnormal determinations of each target link;
[0105] In this embodiment, the application program on the terminal device records each target link determined to be an abnormal advertisement, forming relevant log data, and then uploads these log data to the data server, realizing the collection of relevant information of abnormal advertisements through the terminal device and the transmission of the information to the data server for further analysis and processing.
[0106] Specifically, when the application program on the terminal device determines that the advertising behavior of a target link constitutes an abnormal advertisement, the application program will record the relevant information of the target link, including but not limited to the URL of the target link, user feedback information, the number of jump-off durations, etc. These information are organized into log data and uploaded to the data server for storage.
[0107] After receiving the log data, the data server can identify whether the target link is of a malicious type based on the log data in a statistical manner. To this end, the data server will count the number of abnormal determinations corresponding to the plurality of target links determined to be abnormal advertisements, and determine the median determination number based on the number of abnormal determinations of each target link.
[0108] Specifically, after receiving this log data, the data server first counts the number of abnormality determinations for each target link. This refers to the number of times a target link was identified as an abnormal advertisement within a specific period of time. By counting these counts, the data server can understand how often each target link was identified as an abnormal advertisement.
[0109] Next, the data server determines the median determination number based on these anomaly determination times. The median determination number refers to the value in the middle position after the anomaly determination times of all target links are arranged in order of size. If the number of target links is an odd number, the median determination number is the middle value; if the number of target links is an even number, the median determination number is the average of the two middle values. For example, if there are 5 target links and their anomaly determination times are 3, 5, 7, 9, and 11 respectively, then the median determination number is 7. If the number of target links is an even number, such as 6 target links, and their anomaly determination times are 3, 5, 7, 9, 11, and 13 respectively, then the median determination number is (7+9) / 2=8. The determination of the median determination number provides an important reference benchmark for subsequent abnormal link screening.
[0110] Step S4120: Compare the abnormality determination times of each target link with the median determination times, determine the target link whose abnormality determination times exceed the median determination times as a malicious type, and update the feature data of the target link belonging to the malicious type to the malicious advertisement link library.
[0111] After determining the median number of detections, the data server compares the number of abnormal detections for each target link with the median number. If the number of abnormal detections for a target link exceeds the median number, the target link is determined to be malicious. For example, if the median number of detections is 7 and the number of abnormal detections for a target link is 10, the target link is determined to be malicious. The characteristic data of these malicious target links is extracted and updated in the malicious ad link library to facilitate subsequent malicious ad identification and processing.
[0112] In the above embodiments, terminal devices collect log data related to abnormal advertisements and upload it to a data server. The data server uses a statistical method to determine the median number of judgments as a reference benchmark, and then selects target links with abnormal judgments exceeding the median number, classifying them as malicious and updating them to the malicious advertisement link library. This method can effectively fill gaps when other identification methods fail, accurately identifying malicious links based on the principle of balance, improving the accuracy and reliability of malicious advertisement identification, promptly discovering malicious links missed by other methods, enriching the malicious advertisement database, and ensuring user safety and experience.
[0113] Based on any embodiment of the method of the present application, after determining that the advertising behavior of the target link constitutes an abnormal advertisement, the method further includes:
[0114] Step S4210: Obtain the jump source information of the target link, wherein the jump source information includes multiple browsing behavior data of the user in the application;
[0115] The target link's redirect source information includes multiple browsing behavior data of the user in the application. By obtaining this redirect source information, we can gain a deeper understanding of how the user interacts with the target link in the application, providing richer context for subsequent malicious ad identification.
[0116] Specifically, jump source information refers to the series of page paths and behavioral data involved in a user's navigation from one page to a target link within an application. This data may include the links clicked, the page content viewed, and the duration of the user's stay. By collecting this data, the application can construct the user's browsing path within the application and determine how the user was guided to the target link.
[0117] During implementation, applications can obtain this redirect source information in a variety of ways. For example, the application can record the time each page is visited, the user's actions on the page (such as clicks and swipes), and the specific path the user takes from one page to another. This data can be stored in local log files or uploaded to a data server for centralized analysis.
[0118] By obtaining redirect source information, applications can gain a more comprehensive understanding of user behavior patterns, which is crucial for identifying malicious ads. For example, if a target link is accessed through a complex series of redirect paths, this may indicate that the link is misleading or hidden, increasing the likelihood of it being identified as malicious. By analyzing this redirect source information, applications can more accurately identify and address malicious ads, thereby improving user experience and device security.
[0119] Step S4220: Based on the plurality of browsing behavior data in the jump source information, extract the path of the pages that led the user to open the target link, and determine the page depth of the path of the pages;
[0120] By analyzing multiple browsing behavior data points within the redirect source information, the application can extract the path of pages that led the user to the target link. The path of pages refers to the sequence of pages the user browsed before reaching the target link. For example, if a user clicks a link from the homepage to a product page, and then clicks an ad link from the product page to the target link, the path of pages is homepage -> product page -> target link.
[0121] Furthermore, the application needs to determine the page depth of the path. Page depth refers to the number of pages a user browses before reaching the target link. For example, if a user clicks an ad link directly from the homepage to the target link, the page depth is 1; if the user enters a product page from the homepage and then clicks an ad link from the product page to the target link, the page depth is 2. Page depth reflects the complexity of the path the user took to reach the target link. A higher page depth often indicates that the target link is misleading or hidden, increasing the likelihood of it being identified as malicious advertising.
[0122] Step S4230: When the page depth exceeds a preset depth threshold, it is determined that the target link is of a malicious type, and feature data of the target link of the malicious type is updated to the malicious advertisement link library.
[0123] In order to identify malicious advertisements through page depth, the application of this application uses a preset depth threshold for identification. Specifically, if the page depth exceeds the preset depth threshold, the application will determine that the target link is of a malicious type and update its feature data to the malicious advertisement link library. The depth threshold can be flexibly set according to the actual situation. For example, the depth threshold is set to 5 levels. If a path of a page contains a page depth of more than 5 levels, then the corresponding target link can be determined to be a malicious type. Because in general, each site hopes to provide users with full site information with fewer nodes of the path of the page. Deliberately burying the access level to which the advertisement entrance belongs can be used as one of the bases for identifying malicious advertisements.
[0124] Through the above examples, applications can effectively identify malicious advertising links that lead users through complex paths. This method not only considers user behavior patterns but also uses the quantitative metric of page depth to provide a clear judgment standard for identifying malicious ads and help fill gaps. By updating the feature data of malicious target links to the malicious advertising link library, applications can continuously optimize their ability to identify malicious ads, improving user experience and device security.
[0125] Based on any embodiment of the method of the present application, after determining that the advertising behavior of the target link constitutes an abnormal advertisement, the method further includes:
[0126] Step S4310: Count the number of abnormality determinations of the target link within a preset time. If the number of abnormality determinations exceeds a preset threshold, mark the target link as a high-risk link.
[0127] By analyzing the historical data of target links being judged as abnormal behaviors, we can statistically determine the number of abnormal judgments of the target link within a preset time, which is used to assess the risk level of the link. By identifying those links that are frequently judged as abnormal advertisements, high-risk links can be marked.
[0128] Specifically, the preset time period can be a fixed period of time, such as 24 hours, a week, or a month, depending on the specific needs and design of the application. During this period, the application will record the log data of each target link that is judged to be an abnormal advertisement and submit it to the data server. The data server then counts the number of abnormality judgments for each target link based on the corresponding log data within the preset period.
[0129] The number of abnormality checks for each target link is then compared to a preset threshold. If a target link's abnormality count exceeds the threshold, the link is marked as high-risk. Similarly, the threshold is a value determined based on experience or data analysis to distinguish between normal links and potentially problematic links.
[0130] For example, if the preset threshold is 50 times, and a target link is judged as an abnormal advertisement 500 times within 24 hours, then the link will be marked as a high-risk link.
[0131] The application requests the data server to execute the above process by calling the remote interface preset by the data server, and confirms whether the target link being processed is a high-risk link based on the judgment result of the data server.
[0132] Step S4320: Obtain the page content of the high-risk link and input it into a preset page judgment model to determine whether the high-risk link is malicious;
[0133] To identify the target link type, the application further retrieves the page content marked as high-risk and feeds it into a pre-set page judgment model to determine whether these high-risk links are malicious. This is based on further analysis of the high-risk links, using the characteristics of the page content to determine whether the corresponding target link is malicious.
[0134] Specifically, when a target link is marked as high-risk, the application analyzes the page content of the high-risk target link. Page content can include various elements such as text, images, videos, and scripts, which together constitute the page's characteristics. Using pre-defined data cleaning methods, a feature data package corresponding to the target link's page content is constructed and input into the page judgment model for inference.
[0135] In this application, the page determination model is a pre-trained model that can determine whether a page is malicious based on the characteristics of the page content. For example, the model can check whether the page contains malicious code, misleading content, false information, and other characteristics, and directly determine whether it is malicious.
[0136] During implementation, applications can obtain page content associated with high-risk links through a variety of methods. For example, applications can use web crawler technology to capture page content, or obtain page content through interaction with data servers. The obtained page content is then input into a page determination model for analysis. Page determination models can be implemented in a variety of ways, such as machine learning-based classification models, deep learning models, or rule-based models. By learning from large amounts of annotated data, these models can identify malicious features in page content and determine whether the page content is malicious.
[0137] For example, in one embodiment, the page determination model is a deep learning-based convolutional neural network (CNN) that analyzes the page's text content, image features, and other information to determine whether the page is malicious. The model outputs a confidence score, indicating the probability that the page is malicious. If the confidence score exceeds a preset threshold, the model determines that the page is malicious.
[0138] Step S4330: When the link is of a malicious type, the feature data of the high-risk link is updated to the malicious advertisement link library.
[0139] When the page identification model determines that a high-risk link is malicious based on its page content characteristics, the application can extract feature data from the link. This feature data may include, but is not limited to, the link URL, page content text features, image features, and script features. This feature data is organized into a structured format and updated to the malicious ad link library, enabling iterative improvement of the application's ability to identify malicious ads based on the malicious ad link library.
[0140] The above embodiment marks high-risk links by counting the number of abnormal judgments of the target link within a preset time, and further analyzes the page content of these high-risk links to determine whether they are of the malicious type. It can effectively identify links that are frequently judged as abnormal advertisements, and conduct in-depth analysis through the characteristics of the page content, thereby improving the accuracy and reliability of malicious advertisement identification. Updating the feature data of high-risk links that are of malicious type to the malicious advertisement link library not only enriches the content of the malicious advertisement database, but also provides more feature data for subsequent malicious advertisement identification, further improving the efficiency and accuracy of malicious advertisement identification. Through this mechanism, the application can promptly discover and handle newly emerging malicious advertisement links, providing users with a safer and smoother user experience, while helping developers better understand and respond to the threat of malicious advertisements, and improving the security and reliability of applications.
[0141] See also Figure 3 According to one aspect of the present application, an abnormal advertisement processing device is provided, including a hit control module 3100, a jump monitoring module 3200, an abnormality identification module 3300, and a feedback confirmation module 3400, wherein the hit control module 3100 is configured to respond to a touch event acting on an advertisement entrance in the current page, determine whether the target link of the advertisement entrance hits a malicious advertisement link library, and when it hits, prohibit jumping to the advertisement page corresponding to the advertisement entrance; the jump monitoring module 3200 is configured to call the background control module to start calculating the jump distance when it does not hit. The jump-off duration is determined by the user, and the target link is jumped to load the advertising page; the abnormality identification module 3300 is configured to determine that the advertising behavior of the target link constitutes an abnormal advertisement when the jump-off duration exceeds a preset duration threshold, and trigger a notification event for collecting user feedback information through the background control module; the feedback confirmation module 3400 is configured to determine whether the target link is of a malicious type based on the user feedback information submitted in response to the notification event and the jump-off duration, and update the characteristic data of the target link of the malicious type to the malicious advertising link library.
[0142] On the basis of any embodiment of the device of the present application, prior to the feedback confirmation module 3400, the device also includes: a plug-in entry notification module, which is configured to send a plug-in assistance notification to the external browser used to open the target link through the background control module according to the notification event, and drive the plug-in preset in the external browser to pop up a user feedback interface according to the configuration information provided by the plug-in assistance notification; a plug-in entry feedback module, which is configured to obtain user feedback information submitted by the user through the user feedback interface by the preset plug-in, and the user feedback information includes advertising type labeling information and advertising problem description information submitted by the user.
[0143] On the basis of any embodiment of the device of the present application, prior to the feedback confirmation module 3400, the device also includes: a system message notification module, which is configured to request the operating system to send a system message through the background control module according to the notification event, and associate the system message as the entrance to the user feedback interface; a system entrance feedback module, which is configured to pop up the user feedback interface when the user accesses the system message, and obtain user feedback information through the user feedback interface, wherein the user feedback information includes the advertisement type labeling information and advertisement problem description information submitted by the user.
[0144] Based on any embodiment of the device of the present application, the feedback confirmation module 3400 includes: a data construction module, configured to construct the target link and its corresponding user feedback information and jump exit time into link access data, wherein the user feedback information includes the advertisement type labeling information and advertisement problem description information submitted by the user; a link classification module, configured to call a preset link classification model to determine whether the target link therein is of a malicious type based on the link access data; a cross-validation module, configured to extract feature data from the target link and add it to the malicious advertisement database when the link classification model determines that the target link is of a malicious type and is semantically consistent with the advertisement type labeling information corresponding to the target link.
[0145] On the basis of any embodiment of the device of the present application, after the feedback confirmation module 3400, the device further includes: a median determination module, configured to count the number of abnormal determinations corresponding to multiple target links determined to be abnormal advertisements, and determine the median determination number based on the number of abnormal determinations of each target link; an abnormality identification module 3300, configured to compare the number of abnormal determinations of each target link with the median determination number, determine the target link whose number of abnormal determinations exceeds the median determination number as belonging to a malicious type, and update the feature data of the target link belonging to the malicious type to the malicious advertisement link library.
[0146] On the basis of any embodiment of the device of the present application, after the feedback confirmation module 3400, the device also includes: a source confirmation module, configured to obtain the jump source information of the target link, and the jump source information includes multiple browsing behavior data of the user in the application; a path analysis module, configured to extract the path of the passing page that guides the user to open the target link based on the multiple browsing behavior data in the jump source information, and determine the page depth of the passing page path; a depth judgment module, configured to determine that the target link is of a malicious type when the page depth exceeds a preset depth threshold, and update the feature data of the target link of the malicious type to the malicious advertising link library.
[0147] On the basis of any embodiment of the device of the present application, after the feedback confirmation module 3400, the device further includes: a frequency analysis module, configured to count the number of abnormality determinations of the target link within a preset time, and if the number of abnormality determinations exceeds a preset threshold, mark the target link as a high-risk link; a page analysis module, configured to obtain the page content of the high-risk link and input it into a preset page determination model to determine whether the high-risk link is of a malicious type; a determination processing module, configured to update the feature data of the high-risk link to the malicious advertising link library when it is of a malicious type.
[0148] Another embodiment of the present application also provides an abnormal advertisement processing device. Figure 4 Figure 1 shows a schematic diagram of the internal structure of an abnormal advertisement processing device. The abnormal advertisement processing device includes a processor, a computer-readable storage medium, a memory, and a network interface connected via a system bus. The computer-readable, non-volatile storage medium of the abnormal advertisement processing device stores an operating system, a database, and computer-readable instructions. The database may store an information sequence. When the computer-readable instructions are executed by the processor, the processor implements an abnormal advertisement processing method.
[0149] The processor of the abnormal advertisement processing device is used to provide computing and control capabilities to support the operation of the entire abnormal advertisement processing device. The memory of the abnormal advertisement processing device may store computer-readable instructions, which, when executed by the processor, may cause the processor to execute the abnormal advertisement processing method of the present application. The network interface of the abnormal advertisement processing device is used to connect and communicate with the terminal.
[0150] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the abnormal advertisement processing device to which the solution of the present application is applied. The specific abnormal advertisement processing device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0151] In this embodiment, the processor is used to execute Figure 3 The memory stores the program code and various data required to execute the modules or submodules. The network interface is used to implement data transmission between user terminals or servers. The non-volatile readable storage medium in this embodiment stores the program code and data required to execute all modules in the abnormal advertisement processing device of this application. The server can call the server's program code and data to execute the functions of all modules.
[0152] The present application also provides a non-volatile readable storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the abnormal advertisement processing method of any embodiment of the present application.
[0153] The present application also provides a computer program product, comprising a computer program / instruction, which implements the steps of the method described in any embodiment of the present application when executed by one or more processors.
[0154] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments of the present application can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments of the method. The aforementioned storage medium can be a computer-readable storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0155] In summary, this application effectively addresses the shortcomings of existing technologies in monitoring and handling abnormal advertisements through innovative technical means, achieving significant technical advantages and beneficial effects. This application not only efficiently implements active defense mechanisms to promptly detect and handle abnormal advertisements, but also improves the accuracy of identifying abnormal advertisements by integrating both subjective and objective information, providing users with a safer and smoother user experience.
Claims
1. A method for handling abnormal advertisements, characterized in that: include: In response to a touch event on an advertisement entry in the current page, determining whether a target link of the advertisement entry hits a malicious advertisement link library, and if so, prohibiting a jump to the advertisement page corresponding to the advertisement entry; If no hit occurs, the background control module is called to start calculating the jump-off duration, and jump to the target link to load the advertisement page; When the jump-off duration exceeds a preset duration threshold, it is determined that the advertising behavior of the target link constitutes an abnormal advertisement, and a notification event for collecting user feedback information is triggered through the background control module; Based on the user feedback information submitted in response to the notification event and the jump exit duration, it is determined whether the target link is of a malicious type, and feature data of the target link of the malicious type is updated to the malicious advertisement link library.
2. The abnormal advertisement processing method according to claim 1, characterized in that: Before determining whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit duration, the method includes: According to the notification event, the background control module sends a plug-in assistance notification to the external browser used to open the target link, and drives the plug-in pre-installed in the external browser to pop up a user feedback interface according to the configuration information provided by the plug-in assistance notification; The preset plug-in obtains user feedback information submitted by the user through the user feedback interface, where the user feedback information includes advertisement type labeling information and advertisement problem description information submitted by the user.
3. The abnormal advertisement processing method according to claim 1, characterized in that: Before determining whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit duration, the method includes: According to the notification event, the background control module requests the operating system to send a system message, and associates the system message as an entrance to the user feedback interface; When a user accesses the system message, the user feedback interface pops up, and user feedback information is obtained through the user feedback interface. The user feedback information includes advertisement type labeling information and advertisement problem description information submitted by the user.
4. The abnormal advertisement processing method according to claim 1, characterized in that: Determining whether the target link is malicious based on user feedback information submitted in response to the notification event and the jump exit duration, and if so, updating feature data of the target link to the malicious advertisement link library, including: Constructing the target link and its corresponding user feedback information and jump exit duration into link access data, wherein the user feedback information includes advertisement type labeling information and advertisement problem description information submitted by the user; Invoking a preset link classification model to determine whether a target link is malicious based on the link access data; When the link classification model determines that the target link is of a malicious type and the semantics are consistent with the advertisement type annotation information corresponding to the target link, feature data is extracted from the target link and added to the malicious advertisement database.
5. The abnormal advertisement processing method according to any one of claims 1 to 4, characterized in that: After determining that the advertising behavior of the target link constitutes abnormal advertising, the following procedures are performed: Counting the number of abnormality determinations corresponding to a plurality of target links determined to be abnormal advertisements, and determining a median number of abnormality determinations based on the number of abnormality determinations for each target link; The abnormality determination times of each target link are compared with the median determination times, and the target link whose abnormality determination times exceed the median determination times is determined to be malicious type, and the feature data of the target link belonging to the malicious type is updated to the malicious advertisement link library.
6. The abnormal advertisement processing method according to any one of claims 1 to 4, characterized in that: After determining that the advertising behavior of the target link constitutes abnormal advertising, the following also applies: Obtaining jump source information of the target link, wherein the jump source information includes multiple browsing behavior data of the user in the application; Extracting the path of the pages that led the user to open the target link based on the multiple browsing behavior data in the jump source information, and determining the page depth of the path of the pages; When the page depth exceeds a preset depth threshold, it is determined that the target link is of a malicious type, and feature data of the target link of the malicious type is updated to the malicious advertisement link library.
7. The abnormal advertisement processing method according to any one of claims 1 to 4, characterized in that: After determining that the advertising behavior of the target link constitutes abnormal advertising, the following also applies: Counting the number of abnormality determinations of the target link within a preset time, and if the number of abnormality determinations exceeds a preset threshold, marking the target link as a high-risk link; Obtaining the page content of the high-risk link and inputting it into a preset page judgment model to determine whether the high-risk link is malicious; When it is of a malicious type, the feature data of the high-risk link is updated to the malicious advertisement link library.
8. An abnormal advertisement processing device, characterized in that: include: A hit control module is configured to respond to a touch event acting on an advertisement entry in the current page, determine whether a target link of the advertisement entry hits a malicious advertisement link library, and when a hit occurs, prohibit jumping to the advertisement page corresponding to the advertisement entry; The jump monitoring module is configured to call the background control module to start calculating the jump exit duration when a hit is not received, and jump to the target link to load the advertisement page; an abnormality identification module configured to determine that the advertising behavior of the target link constitutes an abnormal advertisement when the jump-off duration exceeds a preset duration threshold, and trigger a notification event for collecting user feedback information through the background control module; The feedback confirmation module is configured to determine whether the target link is malicious based on the user feedback information submitted in response to the notification event and the jump exit time, and update the feature data of the target link that is malicious to the malicious advertising link library.
9. An abnormal advertisement processing device, comprising a central processing unit and a memory, characterized in that: The central processing unit is configured to call and run a computer program stored in the memory to execute the steps of the method according to any one of claims 1 to 7.
10. A non-volatile readable storage medium, characterized in that: It stores a computer program implemented according to the method described in any one of claims 1 to 7 in the form of computer-readable instructions, and when the computer program is called and executed by a computer, the steps included in the corresponding method are executed.