Method and device for recalling target account, equipment, storage medium and program product

Through community discovery algorithms and login information features, black market accounts are identified and recalled from the account behavior heterogeneous graph, solving the threat to network security posed by the proliferation of black market accounts and achieving efficient and low-cost black market account identification and recall.

CN120804439APending Publication Date: 2025-10-17BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511040413.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

How to efficiently identify and recall black market accounts to ensure the security of the network environment and prevent illegal activities and threats to user privacy.

Method used

Through the community discovery algorithm, communities are identified from the account behavior heterogeneous graph, community characteristics are analyzed, and login information features are used to recall target accounts from the account database.

Benefits of technology

It realizes the active and automatic mining of the characteristics of black market accounts in graph structure data, and recalls other black market accounts efficiently and at low cost, thereby improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120804439A_ABST
    Figure CN120804439A_ABST
Patent Text Reader

Abstract

The invention provides a method, device and equipment for recalling a target account, a storage medium and a program product, and relates to the technical field of artificial intelligence such as graph structure data processing, network security and collaborative recall. The method comprises the steps that at least one community is determined from an account behavior heterogeneous graph through a community discovery algorithm, vertexes in the account behavior heterogeneous graph are constructed based on login information of an account, and edges connecting different vertexes are constructed based on the incidence relation between the login information; determining community features of the communities, and determining a target community from the at least one community based on the community features; determining a login information feature from the target community; and recalling the target account from the account library by using the login information features. Therefore, the characteristics of the account information of the target type can be actively and automatically mined in the graph structure data by utilizing the community algorithm, and other accounts belonging to the target type are recalled and mined efficiently and at low cost by further utilizing the characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, in particular to the technical field of artificial intelligence such as graph structure data processing, network security, collaborative recall, and more particularly to a method and device for recalling target accounts, an electronic device, a computer readable storage medium, and a computer program product. BACKGROUND

[0002] With the rapid development of Internet technology, network platforms and online services have increasingly become an indispensable part of users' daily life.

[0003] However, the rampant black industry chain (referred to as "black production") accounts pose a serious challenge to network security. Black production accounts refer to accounts that are obtained, sold or manipulated through illegal means, or maliciously attack and manipulate the account system of the platform through false identities, automated tools and other means. These black production accounts are often used for illegal activities such as online fraud, data theft, spam dissemination, and false transactions, which seriously endanger the normal operation of the platform and the privacy security of users.

[0004] Therefore, how to more efficiently identify and recall black production accounts to more effectively protect the safety of the network environment is a concern and an urgent need. SUMMARY

[0005] The present disclosure provides a method and device for recalling target accounts, an electronic device, a computer readable storage medium, and a computer program product.

[0006] In a first aspect, the present disclosure provides a method for recalling target accounts, comprising: determining at least one community from an account behavior heterogeneous graph through a community discovery algorithm, wherein the vertices in the account behavior heterogeneous graph are constructed based on login information of accounts, and the edges connecting different vertices in the account behavior heterogeneous graph are constructed based on the association relationship between the login information; determining the community features of the community, and determining the target community from the at least one community based on the community features; determining the login information features from the target community; and recalling the target accounts from the account library using the login information features.

[0007] In a second aspect, the embodiments of the present disclosure provide a device for recalling target accounts, comprising: a community determining unit configured to determine at least one community from an account behavior heterogeneous graph by a community discovery algorithm, wherein vertices in the account behavior heterogeneous graph are constructed based on login information of accounts, and edges connecting different vertices in the account behavior heterogeneous graph are constructed based on an association relationship between the login information; a community screening unit configured to determine community features of the community, and determine a target community from the at least one community based on the community features; a login information feature determining unit configured to determine login information features from the target community; and an account recalling unit configured to recall target accounts from an account library by using the login information features.

[0008] In a third aspect, the embodiments of the present disclosure provide an electronic device, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to implement the method for recalling target accounts as described in any implementation manner of the first aspect.

[0009] In a fourth aspect, the embodiments of the present disclosure provide a non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to enable a computer to implement the method for recalling target accounts as described in any implementation manner of the first aspect.

[0010] In a fifth aspect, the embodiments of the present disclosure provide a computer program product comprising a computer program, and the computer program is executed by a processor to enable the method for recalling target accounts as described in any implementation manner of the first aspect.

[0011] The method, device, electronic device, computer-readable storage medium and computer program product for recalling target accounts provided by the embodiments of the present disclosure can determine at least one community from an account behavior heterogeneous graph by a community discovery algorithm, wherein vertices in the account behavior heterogeneous graph are constructed based on login information of accounts, and edges connecting different vertices in the account behavior heterogeneous graph are constructed based on an association relationship between the login information; determine community features of the community, and determine a target community from the at least one community based on the community features; determine login information features from the target community; and recall target accounts from an account library by using the login information features.

[0012] The present disclosure can use a community algorithm to actively and automatically mine features of account information of a target type in graph structure data, and further use the features to efficiently and low-costly recall and mine other accounts belonging to the target type.

[0013] It should be understood that the contents described in this part are not intended to identify key or important features of the embodiments of the present disclosure, nor to limit the scope of the present disclosure. Other features of the present disclosure will become apparent through the following description. BRIEF DESCRIPTION OF DRAWINGS

[0014] Other features, objects, and advantages of the present disclosure will become more apparent from the following detailed description of non-limiting embodiments made with reference to the drawings: Figure 1 is an exemplary system architecture to which the present disclosure can be applied; Figure 2 A flowchart of a process for recalling target accounts provided by an embodiment of the present disclosure; Figure 3 A flowchart of a process for determining login information features provided by an embodiment of the present disclosure; Figure 4 A flowchart of a process for recalling target accounts implemented in an application scenario provided by an embodiment of the present disclosure; Figure 5 A structural block diagram of an apparatus for recalling target accounts provided by an embodiment of the present disclosure; Figure 6 A structural diagram of an electronic device suitable for executing a method for recalling target accounts provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0015] Exemplary embodiments of the present disclosure are described below with reference to the accompanying drawings, which include various details of the embodiments of the present disclosure to assist in understanding, which should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Also, descriptions of well-known functions and structures are omitted in the following description for clarity and conciseness. It should be noted that the embodiments in the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0016] In addition, the technical solutions involved in the present disclosure involve the acquisition, storage, use, processing, transportation, provision and disclosure of user personal information (such as login information involved in the present disclosure, the association between login information, etc.), which comply with relevant laws and regulations and do not violate public order and good customs.

[0017] Figure 1 An exemplary system architecture 100 is shown, which can apply embodiments of the method, apparatus, electronic device and computer readable storage medium for recalling target accounts of the present disclosure.

[0018] As Figure 1As shown, the system architecture 100 can include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.

[0019] A user can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. The terminal devices 101, 102, 103 and the server 105 can be installed with various applications for realizing information communication between them, such as security management applications, attack protection applications, instant messaging applications, etc.

[0020] The terminal devices 101, 102, 103 and the server 105 can be hardware or software. When the terminal devices 101, 102, 103 are hardware, they can be various electronic devices with display screens, including but not limited to smartphones, tablet computers, laptop computers, and desktop computers, etc. When the terminal devices 101, 102, 103 are software, they can be installed in the above-mentioned electronic devices, and can be implemented as multiple software or software modules, or as a single software or software module, which is not specifically limited here. When the server 105 is hardware, it can be implemented as a distributed server cluster composed of multiple servers, or as a single server. When the server 105 is software, it can be implemented as multiple software or software modules, or as a single software or software module, which is not specifically limited here.

[0021] The server 105 can provide various services through various built-in applications. Taking a security management application for providing login management and application access security protection services as an example, the server 105 can achieve the following effects when running the security management application: First, the server 105 can provide corresponding services for the terminal devices 101, 102, 103 through the network 104. For example, online services such as online socializing and online shopping. In this process, the server 105 can record the login information used by each terminal device 101, 102, 103 when logging into the application, and construct and maintain an account behavior heterogeneous graph based on the login information. The vertices in the account behavior heterogeneous graph are constructed based on the login information of the account, and the edges connecting different vertices in the account behavior heterogeneous graph are constructed based on the association relationship between the login information.

[0022] In such a case, the server 105 can determine at least one community from the account behavior heterogeneous graph through a community discovery algorithm. Next, the server 105 determines community features of the community, and determines a target community from the at least one community based on the community features. Next, the server 105 determines login information features from the target community. Finally, the target account is recalled from the account library by using the login information features.

[0023] It should be noted that the account behavior heterogeneous graph can be constructed and maintained in advance based on historical interaction behaviors and account usage behaviors. In such a case, the server 105 can directly obtain the account behavior heterogeneous graph in the case that the account behavior heterogeneous graph has been obtained, and determine at least one community from the account behavior heterogeneous graph through a community discovery algorithm. Accordingly, in such a case, the exemplary system architecture 100 can also not include the terminal devices 101, 102, and 103 and the network 104.

[0024] Since the actions of determining a community and determining community features may often require more computing resources and stronger computing power, the method for recalling a target account provided in each of the subsequent embodiments of the present disclosure is generally executed by the server 105 with stronger computing power and more computing resources, and accordingly, the device for recalling a target account is generally arranged in the server 105. However, it should also be noted that when the terminal devices 101, 102, and 103 also have computing power and computing resources that meet the requirements, the terminal devices 101, 102, and 103 can also complete the above-mentioned operations by the server 105 through the security management application installed thereon, and then output the same results as the server 105. Especially in the case that there are multiple terminal devices with different computing powers, but the security management application judges that the terminal device has stronger computing power and more remaining computing resources, the terminal device can be allowed to execute the above-mentioned operations, so as to appropriately reduce the computing pressure of the server 105, and accordingly, the device for recalling a target account can also be arranged in the terminal devices 101, 102, and 103. In such a case, the exemplary system architecture 100 can also not include the server 105 and the network 104.

[0025] It should be understood that Figure 1 the number of terminal devices, networks, and servers in may be only illustrative. Any number of terminal devices, networks, and servers can be provided according to implementation needs.

[0026] Reference can be made to Figure 2 , Figure 2 a flowchart of a process for recalling a target account provided by an embodiment of the present disclosure, which includes the process 200.

[0027] The process 200 specifically includes the following steps: Step 201: determining at least one community from the account behavior heterogeneous graph by a community discovery algorithm; In an embodiment of the present disclosure, the execution subject (e.g. Figure 1 The server 105 shown) can obtain the account behavior heterogeneous graph to determine at least one community from the account behavior heterogeneous graph by a community discovery algorithm.

[0028] The vertices in the account behavior heterogeneous graph are constructed based on login information of accounts, and the edges connecting different vertices in the account behavior heterogeneous graph are constructed based on the association relationship between the login information. As the vertex, the login information can be related to the login behavior of the account of the user, or can be other accounts, other information, etc. corresponding to the account of the user. For example, the login information can be a mobile phone number (e.g. a mobile phone number used for quick login of the account). For another example, the login information can be an identifier of the user in different databases corresponding to the same account. For example, the login information can be a Customer Unique Identifier (abbreviated as UUID), or a user identifier in a specific system, etc.

[0029] In some scenarios, the login information can also be associated with a hardware device used by the user when logging into the account. For example, the login information can be an (unique) identification of the device used when logging into the account.

[0030] In some scenarios, the login information can also be associated with other accounts associated with the account in other service platforms or systems, for example, the login information can be a resource extraction account (e.g. a resource management party other than the management party of the account, but associated with the associated account managed by the other management party) associated with the account and having a binding relationship, etc.

[0031] Correspondingly, the edge in the account behavior heterogeneous graph can be determined and constructed based on whether the login information has an association relationship. In other words, the edge of the account behavior heterogeneous graph can be used to indicate the association relationship between different login information.

[0032] In some optional implementations of the present embodiment, the association relationship can be a co-occurrence relationship, that is, for two different login information, if they have appeared on, for example, a network address, for example, an Internet Protocol Address (abbreviated as IP address), a JA3 fingerprint, or the same device, it can be considered that the two login information has an association relationship. Correspondingly, the two login information has an "edge" in the account behavior heterogeneous graph.

[0033] For the convenience of understanding, a specific scenario can be used as an example. For example, for two different device identification marks as vertices, if both devices are used to extract resources from the resource extraction account, there can be an "edge" between the two vertices in the account behavior heterogeneous graph.

[0034] In some embodiments, in combination with different scenarios and requirements, the addition criteria of the "edge" can also be more granularly based on the co-occurrence of two "vertices" in a certain functional link. For example, such a function can be closely related to black production behavior, or a function that is not easy to be imitated and tampered with by black production. For example, the "edge" is determined based on the "co-occurrence" of two login information in the login function, and the "edge" is determined based on the "co-occurrence" of two login information in the resource extraction link.

[0035] Therefore, through such a standard determination method of the edge, it is possible to avoid dilution of the correlation between login information due to black production and tampering of part of the functional link.

[0036] It should be understood that, whether for the above login information or for the association relationship between the above login information, the execution subject will prompt the user (i.e., the user of the account) before obtaining these contents. For example, the execution subject can inform the corresponding user through a pop-up window or the like that it will collect and obtain such login information. And in the process of the pop-up window, the execution subject will also prompt the user with the processing process and purpose of the login information, so that the user can know and understand the role of the information collected by the execution subject and the subsequent operation performed.

[0037] Correspondingly, if the user authorizes at least part of the operation based on the pop-up window, the execution subject will obtain and process these contents according to the authorized content within the scope authorized by the user, according to the processing purpose and processing action previously prompted and informed to the user, so that the acquisition and processing action that may involve the user's personal information are both informed and allowed by the user.

[0038] It should be pointed out that the account behavior heterogeneous graph can be obtained directly by the above execution subject from the local storage device, or from a non-local storage device (for example Figure 1The local storage device can be a data storage module arranged in the above execution subject, for example, a server hard disk, in which case the account behavior heterogeneous graph can be determined locally quickly; the non-local storage device can also be any other electronic device arranged for storing data, such as some user terminals, etc., in which case the execution subject can obtain the required account behavior heterogeneous graph by sending an acquisition command to the electronic device.

[0039] In this step, after obtaining the account behavior heterogeneous graph, the execution subject can determine at least one community from the account behavior heterogeneous graph through a community discovery algorithm.

[0040] The community discovery algorithm can identify subsets or subgraphs of nodes in the graph that are closely related to each other (usually, the vertices included in the subsets or subgraphs have similarities and commonalities in certain characteristics or behaviors), and determine these subsets or subgraphs as "communities".

[0041] For example, the execution subject can determine at least one community from the account behavior heterogeneous graph through a community discovery algorithm such as a modularity optimization algorithm, spectral clustering, random walk optimization algorithm (e.g., Louvain algorithm), etc. In the community, the accounts corresponding to the "vertices" included therein can be (frequently) logged in using the same network address, the same device, or these accounts can frequently perform similar behavior operations, or these accounts can share the same "associated account" extraction resources, etc.

[0042] Step 202: Determine the community features of the community, and determine the target community from the at least one community based on the community features; In embodiments of the present disclosure, based on step 201, the execution subject can determine the community features of the "communities" determined in step 201, respectively, and use the community features to determine the target community that can correspond to, with high probability, "black production" accounts (groups).

[0043] That is, after the execution subject identifies at least one community with strong internal correlation from the account behavior heterogeneous graph through a community discovery algorithm, it can determine whether the community corresponds to, with high probability, "black production" accounts (groups) by analyzing the community features of the community.

[0044] In some embodiments, the execution subject can determine the community features of the community by statistically analyzing the results of each vertex in the community in a statistical dimension. The statistical dimension is at least one of: account dimension, device dimension, network dimension.

[0045] For example, the execution subject can obtain a statistical result corresponding to the community by counting each vertex in the community from at least one of the following statistical dimensions: an account dimension, a device dimension, and a network dimension.

[0046] For example, for the account dimension, the execution subject can count the number of accounts registered with the same information, the registration time, the mobile phone number, and the like. For example, the execution subject can cluster accounts registered with the same information, and then associate the corresponding vertices (i.e., those vertices corresponding to the accounts) based on the clustered accounts. Then, by counting the total number of the vertices as a statistical result, the community feature can be determined (for example, the community feature can be used to represent that the accounts in the community can belong to only a few specific users). For another example, for the account dimension, the execution subject can also take the proportion of virtual accounts included in the community as a statistical result, so that the community feature can be used to indicate whether the community is composed of virtual accounts. For another example, for the account dimension, the execution subject can also choose to count the number of accounts using the same "associated account" to obtain a statistical result.

[0047] For another example, for the device dimension, the execution subject can count the number of accounts logged in through the same historical device, and take the statistical result as a community feature. For another example, for the device dimension, the execution subject can also count the usage frequency of the devices involved in the community, and take the proportion of devices with low usage frequency as a statistical result to determine the community feature (such a community feature can be used to represent whether the accounts in the community are concentrated on certain devices, and whether the devices are repeatedly used by the accounts in a short period of time).

[0048] For another example, for the network dimension, the execution subject can count the number of accounts logged in through the same network address, and take the statistical result as a community feature.

[0049] Therefore, the execution subject can determine the community features of the community in different statistical dimensions by counting the login information of the "vertices" in the account behavior heterogeneous graph in different statistical dimensions. Therefore, the type of the account (group) that the community can be associated with can be more accurately determined, so as to more accurately determine and mine the target community that can correspond to the "black production" account (group) in the future.

[0050] Accordingly, after obtaining community characteristics, the executing entity can determine whether each community is a target community based on the corresponding community characteristics, thereby screening and determining the target community from the previously determined communities. For example, when directly using statistical results as community characteristics, the executing entity can choose to determine whether the statistical results exceed a corresponding statistical threshold (e.g., a threshold for the proportion of virtual accounts) to determine whether the community is determined to be a target community. Accordingly, if the statistical results corresponding to the community exceed the corresponding statistical threshold, the executing entity can determine that group as the target community.

[0051] In some embodiments, the execution entity may also use multiple community features to determine whether a community is a target community by weighting the scores corresponding to each community feature, for example, by assigning points to different community features (for example, under the corresponding community feature dimension, if the corresponding feature content and feature value can more reliably point to the community as a black market community, then the community feature may be assigned a higher "score"). In this way, by utilizing multiple community features, the target community can be more comprehensively and accurately identified and determined.

[0052] In some embodiments, in the process of determining the target community from previously determined communities based on community features, the execution entity may further choose to process the community features through an integrated learning algorithm to determine the target community from at least one community.

[0053] An ensemble learning algorithm combines multiple base learners (such as decision trees, neural networks, and support vector machines) to improve overall predictive performance. By combining multiple weak models (those with slightly lower performance) into a strong model (one with better performance), processing and recognition tasks can be completed more efficiently and effectively. For example, the executor can implement this ensemble learning algorithm using the XGBoost (Extreme Gradient Boosting) model.

[0054] For example, the execution entity can construct a binary classification problem based on whether it belongs to the target community, and use the XGBoost model to judge and determine whether each community belongs to the target community based on community characteristics, and then further determine the target community from (at least one) community determined in the above steps.

[0055] Accordingly, through integrated learning, the execution subject can process different types of login information and community characteristics with more generalization capabilities, so that the execution subject can more stably and accurately determine and identify those target communities from at least one community.

[0056] In some embodiments, in order to more accurately determine whether the community is the target community, the execution subject can also determine the trusted vertex for each community using (pre-maintained) whitelist information before determining whether the community belongs to the target community. Then, the trusted vertex and the edges associated with the trusted vertex are removed from the community to obtain the corresponding updated community.

[0057] Correspondingly, in the process of determining the community features of the community and determining the target community based on the community features by the subsequent execution subject, the community features (i.e., the community features of the updated community) can be further determined based on only the "vertices" included in the updated community, and the target community is determined based on the community features.

[0058] The whitelist information can be pre-maintained based on the dimensions of the account or the login information corresponding to the account, to indicate those accounts (or login information corresponding to the accounts) that are trusted and reliable (not "black production" accounts). Correspondingly, the execution subject can use the whitelist information to remove the "vertices" in the community that have been excluded as black production, to reduce the amount of calculation of the subsequent community features, and to avoid the interference of these "non-black production vertices" on the subsequent community features in the form of vertex statistical features, and to avoid the influence of these "non-black production vertices" on the identification and determination quality of the target community.

[0059] Step 203: determining the login information features in the target community based on the target community; In the embodiments of the present disclosure, after determining the target community in the above step 202, the execution subject can analyze and determine the login information features in the target community based on this.

[0060] The login information features can include applications, network addresses, devices, resource extraction accounts, etc. that are repeatedly used or commonly used by each "account" in the target community. That is, the execution subject can determine the target community based on more fine-grained actions and interaction conditions between the target community, to mine "login information features" (e.g., whether the same application has been commonly used by the accounts, whether the same device has been used, whether the same resource extraction account has been used, etc.) that may be associated with black production behaviors and activities.

[0061] Step 204: recalling the target account from the account library using the login information features.

[0062] In embodiments of the present disclosure, after the login information features are determined based on step 203 described above, the performing subject can use these login information features to recall target accounts (i.e., those accounts with high probability of being "black production accounts") from the (pre-maintained) account library that also have these login feature information. For example, the account library can maintain a plurality of accounts managed by the performing subject (e.g., accounts used by users who can interact with the performing subject).

[0063] In this way, the performing subject can mine target communities (i.e., black production communities) through login information, and then actively discover "login information features" (e.g., logging into black production accounts "intermediately" through the same application, logging into black production accounts based on the same network address, logging into black production accounts using the same device, extracting resources from black production accounts using the same "associated accounts", etc.) that can be used for black production behavior or associated with black production behavior by further and more granular feature mining in the black production community.

[0064] The method for recalling target accounts provided by embodiments of the present disclosure determines at least one community from the account behavior heterogeneous graph by a community discovery algorithm, wherein the vertices in the account behavior heterogeneous graph are constructed based on login information of accounts, and the edges connecting different vertices in the account behavior heterogeneous graph are constructed based on the association relationship between the login information; determines community features of the community, and determines a target community from the at least one community based on the community features; determines login information features from the target community; and recalls target accounts from an account library using the login information features. In this way, the community algorithm can be used to actively and automatically mine features of account information of a target type in graph structure data, and further use the features to efficiently and cost-effectively recall and mine other accounts of the target type.

[0065] In some embodiments, if the performing subject chooses to determine which of the at least one community determined in advance is the target community by an ensemble learning algorithm, in such a case, the performing subject can also obtain the reference degree of different community features in the processing process of the ensemble learning algorithm (e.g., an ensemble learning algorithm implemented based on an XGBoost model). For example, the performing subject can determine the reference degree of different community features in the processing process of the XGBoost model by obtaining the importance of each community feature used in the feature importance evaluation link of the XGBoost model.

[0066] For example, the performing subject can instruct the XGBoost model to provide the importance of each community feature by calling a visual feature importance function, and determine the reference degree of each community feature based on the provision result of the XGBoost model.

[0067] After obtaining the reference degree, the execution entity can sort the community features based on the reference degree to obtain a sorting result (for example, in descending order), and then select a preset number (for example, the community features with the highest reference degree) as the target community features.

[0068] Then, the execution entity can communicate the target community characteristics to the target device based on the pre-configured communication path. The target device can be, for example, a device used by an administrator who has management and processing authority over the black market account.

[0069] Accordingly, in this way, the executive body can actively explore those (target) community characteristics that are more obvious and important in the process of determining the target group, and then actively feed them back to the management personnel so that the management personnel can formulate corresponding protection strategies for these target community characteristics in a timely manner.

[0070] In such a case, the executing entity can also interact with the administrator to determine the login feature information that may be more important, more valuable for reference, and more needed, and recall the target accounts that are needed and paid more attention to by the administrator in a more appropriate way to meet the needs of the administrator.

[0071] For this situation, you can also refer to Figure 3 . Figure 3 A flowchart of a process for determining login information features provided by an embodiment of the present disclosure includes process 300.

[0072] The process 300 specifically includes the following steps: Step 301: Determine target community characteristics by sorting the reference degrees of different community characteristics in the process of determining a target community from at least one community using an ensemble learning algorithm; Step 302: Communicate the target community features to the target device based on the pre-configured communication path; Regarding steps 301 and 302, as discussed above, after obtaining the reference degree, the execution entity can sort the community characteristics based on the reference degree and use the sorting results to determine the target community characteristics. The target community results are then provided to a target device used by, for example, a manager. This description will not be repeated here.

[0073] Step 303: In response to the target device returning a selection result for the target community feature, determining the feature type to which the login information feature belongs based on the selection result; Specifically, after the target social group features are provided by the execution subject, the administrator can also make a selection from the target social group features, and return the selection result to the execution subject through the target device, to instruct the execution subject that the login information features can be determined according to which feature types in the future, and the target users are recalled by using the login information features.

[0074] For example, if the target social group features selected by the user are specifically device features (for example, the social group features determined by using the statistical results under the device dimension), the execution subject can determine that the feature type is “device” based on the device features. Accordingly, in the process of analyzing the target social group and determining the login information features, the execution subject can take the device identifier of the reused device, for example, associated with the device, as the “login information feature” to recall those account numbers that have logged in by using the “reused device” as the target account numbers.

[0075] Similarly, if the feature type is determined to be “network address” or “associated account number for extracting resources”, the execution subject can correspondingly take the network address reused by the target social group and the “associated account number” as the login information features to recall the target account numbers (for example, the target account numbers also log in by using the “reused network address”).

[0076] Step 304, determining the login information features from the target social group based on the feature types.

[0077] Specifically, if the execution subject receives the selection result of the target social group features returned by the target device, the execution subject can determine the feature type to which the login information features belong based on the selection result in response. Then, the login information features are determined from the target social group based on the feature type, and the target account numbers are recalled by using the login information features.

[0078] In some embodiments, the login information features can be continuously and long-term mined by continuously updating the account behavior heterogeneous graph as described above. For example, new “vertices” and “edges” can be periodically added to the behavior heterogeneous graph, or those “vertices” and “edges” that have become obsolete can be deleted. For another example, after the execution subject completes the recall of the target account numbers, the execution subject can take the login information associated with the target account numbers as new vertices, and update the account behavior heterogeneous graph based on the association relationship between the vertices and other vertices already maintained in the account behavior heterogeneous graph.

[0079] Accordingly, if the execution subject receives the update data of the account behavior heterogeneous graph, the execution subject can update the account behavior heterogeneous graph based on the updated login information and / or updated association relationship included in the update data to obtain an updated account behavior heterogeneous graph in response.

[0080] For example, the execution entity can update the account behavior heterogeneous graph by updating the login information as a new vertex and updating the association relationship as a new edge.

[0081] After the update, the execution entity can detect the number of target vertices in the updated account behavior heterogeneous graph that cannot be classified as existing communities (for example, these target vertices may not be classified into at least one community because the existing updated account behavior heterogeneous graph lacks corresponding "communities"). If the number of target vertices in the updated account behavior heterogeneous graph that cannot be classified as (existing) communities is greater than or equal to a (predetermined) threshold, the execution entity can re-determine communities from the updated account behavior heterogeneous graph using the above-mentioned community discovery algorithm.

[0082] Therefore, in case a new type of black market group (i.e., target community) may appear in the account behavior heterogeneous graph, the situation of the "community" included in the previously determined account behavior heterogeneous graph is readjusted to ensure the use value of the account behavior heterogeneous graph.

[0083] In some embodiments, after each update of the account behavior heterogeneous graph (regardless of whether the community is re-determined or not), even if the community is not re-determined through the community discovery algorithm, new login information features may appear in the existing target community due to the addition and changes of vertices and edges. Therefore, as long as the account behavior heterogeneous graph is updated, the execution entity can correspondingly re-determine the login information features from the current target community, so as to follow the changes in the target community and try to explore those login information features that may be newly emerged as much as possible, so as to recall the target account as much as possible and ensure network security.

[0084] Based on any of the above embodiments, the execution entity may also proactively feedback these target accounts to, for example, management personnel, so that management personnel can access and manage them more promptly and efficiently, thereby ensuring network security as efficiently and comprehensively as possible.

[0085] That is, if the executing entity recalls the target account, the executing entity can also choose to communicate the target account to the target device based on a pre-configured communication path, so that the management personnel can obtain and understand these target accounts in a timely manner, and select the target accounts that need to be blocked according to the actual management policy.

[0086] Accordingly, if the target account needs to be blocked, the administrator can feedback a blocking instruction for the target device to the execution entity through the target device.

[0087] Correspondingly, if the execution subject receives the shielding instruction fed back by the target device, the target account can be shielded correspondingly. For example, the target account is refused to be continuously used, and the access request of the target account to the corresponding application is refused.

[0088] In such a case, in order to improve the management efficiency, the execution subject can also execute the security policy differently based on the application to which the account belongs. For example, for different types of applications, different identification accuracies of the target account can be configured, so that the execution subject can select to interact with the management personnel to determine whether it needs to be shielded for those applications with high identification accuracy (for example, greater than or equal to a predetermined accuracy threshold), so as to reduce the "false sealing" and "false shielding" caused by inaccurate identification.

[0089] And for those applications with low identification accuracy (for example, less than the above-mentioned accuracy threshold), the black production risk can be cut off as soon as possible by directly shielding.

[0090] For example, for those applications with high identification accuracy (for example, greater than or equal to a predetermined accuracy threshold), they can be referred to as first applications. And for the target account, if it belongs to the first application or is associated with the first application, the execution subject can respond to this by communicating the target account to the target device based on the pre-configured communication path. Correspondingly, if the execution subject receives the shielding instruction fed back by the target device, the target account is shielded from the access request of the first application.

[0091] And for those applications with low identification accuracy (that is, the identification accuracy is less than the above-mentioned accuracy threshold), they can be referred to as second applications. For such second applications, if the target account belongs to the second application or is associated with the second application, the execution subject can respond to this by directly selecting to shield the target account from the access request of the second application. In this way, not only can the security management of various applications be effectively performed, but also the management personnel can focus more on the target account in the first application with high requirements.

[0092] In some embodiments, for the target account, the execution subject can also similarly utilize the white list information to determine the trusted account from the target account after recalling the target account. Then, the trusted account is removed from the target account. In this way, the false sealing, false shielding and the like caused by identification errors and the like are avoided, and the overall reliability of the system is improved.

[0093] In order to deepen the understanding, the present disclosure also gives a specific implementation process of recalling the target account in combination with a specific application scenario. For this, please refer to Figure 4 , Figure 4A flowchart of a process of recalling target accounts in an application scenario is provided for the embodiments of the present disclosure, which includes process 400. For example, the process 400 can also be completed by the "execution subject" described above (for example, the server 105).

[0094] In the process 400, the execution subject can select to perform S401 to determine the social groups 420 and 430 from the account behavior heterogeneous graph 410 through a social group algorithm.

[0095] It should be understood that, for the convenience of understanding, only four forms of vertices (and edges for connection) such as UUID, mobile phone number, network address and device identification are exemplarily shown in the account behavior heterogeneous graph 410, which is not intended to limit the content of the specific "vertices" included in the account behavior heterogeneous graph 410 (that is, in different scenarios, the account behavior heterogeneous graph 410 can also include "vertices" in the form and content such as the "associated account" described above).

[0096] Exemplarily, in S401, the execution subject determines the social groups 420 and 430.

[0097] Next, the execution subject can determine the respective social group features of the social groups 420 and 430 by performing S402, and determine whether the two are target social groups based on the features.

[0098] Exemplarily, the execution subject can determine the social group feature 421 from the social group 420, and determine the social group feature 431 from the social group 430, and determine that the target social group is the social group 430 based on the social group feature 421 and the social group feature 431 (for example, determine that the social group feature 431 is a "target social group" based on an XGBoost model).

[0099] Next, the execution subject can determine the login information feature 431 in the social group 430 by performing S403.

[0100] Then, the execution subject can recall the target accounts from the account library 440 by performing S404 using the login information feature 431. For example, the execution subject can use the login information feature 431 to call the target accounts with the "login information feature 431" from the account library 440. For example, the target account 441, the target account 442, …, the target account 44N (where N is a positive integer) can be recalled. Accordingly, the execution subject can subsequently provide these target accounts 441, 442, …, 44N as references to the target device or directly shield at least part of the target accounts, which will not be repeated here.

[0101] Further reference is made to Figure 5As an implementation of the method shown in the above figures, the present disclosure provides an embodiment of a device for recalling target accounts, which corresponds to the method embodiment shown in Figure 2 The device can be applied in various electronic devices.

[0102] As shown in Figure 5 The device 500 for recalling target accounts in this embodiment can include a community determining unit 501, a community screening unit 502, a login information feature determining unit 503, and an account recalling unit 504. The community determining unit 501 is configured to determine at least one community from an account behavior heterogeneous graph by a community discovery algorithm, wherein the vertices in the account behavior heterogeneous graph are constructed based on the login information of accounts, and the edges connecting different vertices in the account behavior heterogeneous graph are constructed based on the association between the login information; the community screening unit 502 is configured to determine the community features of the community and determine the target community from the at least one community based on the community features; the login information feature determining unit 503 is configured to determine the login information features from the target community; and the account recalling unit 504 is configured to recall the target accounts from the account library by using the login information features.

[0103] In this embodiment, the specific processing of the community determining unit 501, the community screening unit 502, the login information feature determining unit 503, and the account recalling unit 504 in the device 500 for recalling target accounts and the technical effects brought by the same can be respectively referred to the related descriptions of steps 201-204 in the corresponding embodiments, which will not be repeated here. Figure 2

[0104] In some optional implementations of this embodiment, determining the community features of the community includes determining the community features of the community by the statistical results of each vertex in the community under a statistical dimension, wherein the statistical dimension is at least one of the following: account dimension, device dimension, and network dimension.

[0105] In some optional implementations of this embodiment, determining the target community from the at least one community based on the community features includes determining the target community from the at least one community by processing the community features by an ensemble learning algorithm.

[0106] In some optional implementations of this embodiment, the device 500 further includes a target community feature determining unit configured to determine the target community features by the ranking results of the reference degrees of different community features in the process of determining the target community from the at least one community by the ensemble learning algorithm; and a target community feature communication unit configured to communicate the target community features to the target device based on a preconfigured communication path.

[0107] ​In some optional implementation forms of the embodiment, the apparatus 500 further includes a feature type determination unit configured to determine, in response to the target device returning a selection result for the target social group feature, a feature type to which the login information feature belongs based on the selection result; and a login information feature determination unit configured to determine the login information feature from the target social group based on the feature type.

[0108] In some optional implementation forms of the embodiment, the apparatus 500 further includes a trusted vertex determination unit configured to determine a trusted vertex from the social group by using the white list information; a social group updating unit configured to remove the trusted vertex and an edge associated with the trusted vertex from the social group to obtain an updated social group; and the social group screening unit 502 is further configured to determine a social group feature of the updated social group, and determine the target social group based on the social group feature.

[0109] In some optional implementation forms of the embodiment, the apparatus 500 further includes a heterogeneous graph updating unit configured to, in response to receiving update data for the account behavior heterogeneous graph, update the account behavior heterogeneous graph based on updated login information and / or updated association relationship included in the update data to obtain an updated account behavior heterogeneous graph; and a social group updating unit configured to, in response to a number of target vertices in the updated account behavior heterogeneous graph that fail to be classified as a social group being greater than or equal to a number threshold, determine a social group from the updated account behavior heterogeneous graph by using a social group discovery algorithm.

[0110] In some optional implementation forms of the embodiment, the apparatus 500 further includes a target account communication unit configured to, in response to the target account having an association with a first application, communicate the target account to the target device based on a preconfigured communication path, where an identification accuracy of the first application for the target account is greater than or equal to an accuracy threshold; and a first target account shielding unit configured to, in response to receiving a shielding instruction fed back by the target device, shield an access request of the target account for the first application.

[0111] In some optional implementation forms of the embodiment, the apparatus 500 further includes a second target account shielding unit configured to, in response to the target account having an association with a second application, shield an access request of the target account for the second application, where an identification accuracy of the second application for the target account is less than the accuracy threshold.

[0112] In some optional implementation forms of the embodiment, the apparatus 500 further includes a target account screening unit configured to determine a trusted account from the target account by using the white list information; and a trusted account removing unit configured to remove the trusted account from the target account.

[0113] Corresponding to the method embodiment, the device embodiment is provided. The device for recalling a target account provided by the embodiment determines at least one community from an account behavior heterogeneous graph through a community discovery algorithm. The vertices in the account behavior heterogeneous graph are constructed based on login information of an account. The edges connecting different vertices in the account behavior heterogeneous graph are constructed based on an association relationship between the login information. The community features of the community are determined, and the target community is determined from the at least one community based on the community features. The login information features are determined from the target community. The target account is recalled from an account library by using the login information features. Thus, the community algorithm can be used to actively and automatically mine the features of the account information of the target type in the graph structure data, and the features are further used to efficiently and low-costly recall and mine other accounts belonging to the target type.

[0114] According to embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.

[0115] Figure 6 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the present disclosure described and / or claimed in this document.

[0116] As shown in Figure 6 The device 600 includes a computing unit 601 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. Various programs and data required for the operation of the device 600 can also be stored in the RAM 603. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0117] A number of components in the device 600 are connected to the I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, a magneto-optical disk, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows the device 600 to exchange information / data with other devices over a computer network, such as the Internet, and / or various telecommunication networks.

[0118] The computing unit 601 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 601 performs various methods and processes described above, such as the method of recalling target accounts. For example, in some embodiments, the method of recalling target accounts can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded onto the RAM 603 and executed by the computing unit 601, one or more steps of the method of recalling target accounts described above can be performed. Alternatively, in other embodiments, the computing unit 601 can be configured to perform the method of recalling target accounts by any other appropriate means, such as by means of firmware.

[0119] The various implementations of the systems and techniques described above herein can be realized in a digital electronic circuit system, an integrated circuit system, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), an application specific standard product (ASSP), a system on a chip system (SOC), a complex programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0120] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces the functions / operations specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package, or entirely on a remote machine or server.

[0121] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0122] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0123] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0124] A computer system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a host product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosts and virtual private server (VPS) services. Servers can also be classified as distributed system servers or servers integrated with blockchain.

[0125] According to the technical solution of the embodiment of the present disclosure, at least one community is determined from the account behavior heterogeneous graph through a community discovery algorithm, the vertices in the account behavior heterogeneous graph are constructed based on the login information of the account, and the edges connecting different vertices in the account behavior heterogeneous graph are constructed based on the association relationship between the login information; the community characteristics of the community are determined, and based on the community characteristics, a target community is determined from at least one community; the login information characteristics are determined from the target community; and the login information characteristics are used to recall the target account from the account library. In this way, the community algorithm can be used to actively and automatically mine the characteristics of the target type of account information in the graph structure data, and further use the characteristics to efficiently and cost-effectively recall and mine other accounts belonging to the target type.

[0126] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions provided by this disclosure can be achieved. This is not limited herein.

[0127] The above detailed description does not limit the scope of the disclosure. Various modifications, combinations, sub-combinations and alternatives can be made to the detailed description. Any modification, equivalent replacement and improvement etc. made within the spirit and principle of the disclosure shall be included in the scope of the disclosure.

Claims

1. A method for recalling a target account, comprising: Determining at least one community from an account behavior heterogeneous graph using a community discovery algorithm, wherein vertices in the account behavior heterogeneous graph are constructed based on account login information, and edges connecting different vertices in the account behavior heterogeneous graph are constructed based on associations between the login information; determining community characteristics of the communities, and determining a target community from at least one of the communities based on the community characteristics; Determining login information characteristics from the target community; The target account is retrieved from the account database using the login information features.

2. The method according to claim 1, wherein Determine the community characteristics of the community, including: The community characteristics of the community are determined by statistical results of each vertex in the community under statistical dimensions, wherein the statistical dimensions include at least one of: account dimension, device dimension, and network dimension.

3. The method according to claim 2, wherein: Determining a target community from at least one of the communities based on the community characteristics includes: The community features are processed by an ensemble learning algorithm to determine a target community from at least one of the communities.

4. The method according to claim 3, further comprising: determining the target community characteristics by sorting the reference degrees of different community characteristics in the process of determining the target community from at least one community using the ensemble learning algorithm; Based on a preconfigured communication path, the target community feature is communicated to the target device.

5. The method according to claim 4, further comprising: In response to the target device returning a selection result for the target community feature, determining, based on the selection result, a feature type to which the login information feature belongs; Based on the feature type, the login information feature is determined from the target community.

6. The method according to claim 1, further comprising: Determining trusted vertices from the community using the whitelist information; removing the trusted vertex and the edges associated with the trusted vertex from the community to obtain an updated community; as well as The determining of the community characteristics of the community and determining the target community based on the community characteristics includes: The community characteristics of the updated community are determined, and a target community is determined based on the community characteristics.

7. The method according to claim 1, further comprising: In response to receiving update data for the account behavior heterogeneous graph, updating the account behavior heterogeneous graph based on updated login information and / or updated association relationships included in the update data to obtain an updated account behavior heterogeneous graph; In response to the number of target vertices in the updated account behavior heterogeneous graph that are not classified as the community being greater than or equal to a quantity threshold, the community is re-determined from the updated account behavior heterogeneous graph by using the community discovery algorithm.

8. The method according to claim 1, further comprising: In response to the target account being associated with the first application, communicating the target account to the target device based on a preconfigured communication path, wherein the first application has an identification accuracy for the target account that is greater than or equal to an accuracy threshold; In response to receiving the blocking instruction fed back by the target device, blocking the access request of the target account to the first application.

9. The method according to claim 8, further comprising: In response to the target account being associated with a second application, shielding the target account's access request to the second application, wherein the second application's recognition accuracy of the target account is less than the accuracy threshold.

10. The method according to claim 8 or 9, further comprising: Determining a trusted account from the target account using the whitelist information; The trusted account is removed from the target account.

11. A device for recalling a target account, comprising: a community determining unit configured to determine at least one community from an account behavior heterogeneous graph using a community discovery algorithm, wherein vertices in the account behavior heterogeneous graph are constructed based on account login information, and edges connecting different vertices in the account behavior heterogeneous graph are constructed based on associations between the login information; a community screening unit configured to determine community characteristics of the community, and determine a target community from at least one of the communities based on the community characteristics; a login information feature determination unit, configured to determine login information features from the target community; The account recall unit is configured to recall the target account from the account database using the login information feature.

12. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method for recalling a target account according to any one of claims 1 to 10.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method for recalling a target account according to any one of claims 1 to 10.

14. A computer program product, comprising a computer program, wherein when executed by a processor, the computer program implements the method for recalling a target account according to any one of claims 1 to 10.