Data monitoring method and device in game, electronic equipment and storage medium
By obtaining transaction order information and behavioral data, calculating the anomaly scores of virtual props and virtual characters, and comprehensively evaluating the degree of transaction anomaly, the problem of inaccurate transaction anomaly judgment in existing technologies is solved, and the accuracy of game data monitoring and the stability of the economic system are improved.
Patent Information
- Application Number
- CN202510943011.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-09
- Publication Date
- 2025-10-21
AI Technical Summary
In the existing technology, determining whether a transaction is abnormal is inaccurate based solely on transaction data comparison results, which negatively impacts the game economic system and makes it impossible to effectively identify and combat the gold-stealing behavior of illegal players.
By obtaining the order information of the transaction order to be evaluated, the reference value of the transaction abnormality of the target virtual props and virtual characters is determined, the abnormality score is calculated based on the transaction information and transaction behavior data, and the abnormality degree of the transaction order is comprehensively evaluated.
It improves the accuracy of monitoring abnormal game transaction data, can evaluate the degree of transaction abnormality from multiple dimensions, avoids misjudgment caused by single price comparison, and ensures the stable operation of the game economic system.
Smart Images

Figure CN120815344A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, device, electronic device, and storage medium for monitoring data in a game. Background Art
[0002] In Massive Multiplayer Online Role-Playing Games (MMORPGs), players can engage in relatively free trade with one another. This mechanism is exploited by some players or game studios, who create multiple accounts and transfer resources from their smaller accounts to their larger accounts in bulk. This behavior has a serious negative impact on the game's economy, easily leading to currency devaluation and shortening the game's lifespan. Therefore, maintaining a healthy and stable in-game economy is crucial for the long-term success of MMORPGs. To enhance the game's vitality and competitiveness, stabilize the exchange rate of in-game currency, ensure fairness, and guarantee a positive experience for paying players, it is essential to accurately identify and crack down on illegal players engaging in fraudulent activities.
[0003] However, the existing technology usually compares the transaction data of the current transaction with a threshold, and then determines whether the current transaction is an abnormal transaction based on the comparison result. However, it is inaccurate to determine whether a transaction is abnormal based solely on the transaction data comparison result. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a data monitoring method, device, electronic device and storage medium in a game to overcome at least one of the above-mentioned defects.
[0005] In a first aspect, an embodiment of the present application provides a method for monitoring data in a game, comprising:
[0006] Obtaining a transaction order to be evaluated for a target virtual item in a specified type of transaction, and determining, based on order information of the transaction order to be evaluated, a first reference value for measuring a degree of transaction anomaly for the target virtual item and a second reference value for measuring a degree of transaction anomaly for a virtual character participating in the transaction, wherein the order information includes transaction information for the target virtual item;
[0007] Determining a first abnormality score for characterizing a degree of abnormality in the transaction of the target virtual item based on the transaction information and the first reference value;
[0008] Determining, based on the transaction behavior data of the virtual character participating in the transaction and the second reference value, a second abnormality score for characterizing the degree of abnormality in the transaction of the virtual character;
[0009] The abnormality degree of the transaction order to be evaluated is determined based on the first abnormality score and the second abnormality score.
[0010] In a second aspect, an embodiment of the present application further provides a data monitoring device in a game, the device comprising:
[0011] a reference value determination module for obtaining a transaction order to be evaluated for a target virtual item in a specified type of transaction, and determining, based on order information of the transaction order to be evaluated, a first reference value for measuring the degree of transaction anomaly of the target virtual item and a second reference value for measuring the degree of transaction anomaly of the virtual character participating in the transaction, wherein the order information includes transaction information of the target virtual item;
[0012] A first scoring module is configured to determine, based on the transaction information and the first reference value, a first anomaly score for characterizing the degree of anomaly in the transaction of the target virtual item;
[0013] A second scoring module is configured to determine a second abnormality score for characterizing a degree of abnormality in a transaction of a virtual character based on the transaction behavior data of the virtual character participating in the transaction and a second reference value;
[0014] The anomaly evaluation module is used to determine the degree of anomaly of the transaction order to be evaluated based on the first anomaly score and the second anomaly score.
[0015] In a third aspect, an embodiment of the present application further provides an electronic device comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the data monitoring method in the game as described above are performed.
[0016] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the data monitoring method in the game as described above are executed.
[0017] The embodiments of the present application bring the following beneficial effects:
[0018] The embodiments of the present application provide a method, device, electronic device, and storage medium for in-game data monitoring, which can evaluate the degree of abnormality of transaction orders based on two dimensions: the degree of abnormality of transactions of target virtual props and the degree of abnormality of transactions of virtual characters. This avoids the problem of low data monitoring accuracy caused by directly determining whether a transaction is abnormal based on the comparison results of order prices. Compared with the data monitoring methods in games in the prior art, the accuracy of data monitoring for abnormal transactions in games is improved.
[0019] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0021] Figure 1 A flowchart of a data monitoring method for a game provided by an embodiment of the present application is shown;
[0022] Figure 2 A flowchart showing the steps of determining the first reference value provided in an embodiment of the present application is shown;
[0023] Figure 3 A flowchart showing steps for determining a second reference value provided in an embodiment of the present application is shown;
[0024] Figure 4 A flowchart showing the steps of determining the first anomaly score provided in an embodiment of the present application is shown;
[0025] Figure 5 A flowchart showing the steps of determining the second anomaly score provided in an embodiment of the present application is shown;
[0026] Figure 6 A flowchart showing the steps for constructing an abnormal role queue provided in an embodiment of the present application is shown;
[0027] Figure 7 A schematic diagram showing a transaction behavior topology diagram provided in an embodiment of the present application is shown;
[0028] Figure 8 A flowchart showing the steps for determining transaction health provided by an embodiment of the present application;
[0029] Figure 9 A schematic diagram showing the structure of a data monitoring device in a game provided by an embodiment of the present application is shown;
[0030] Figure 10 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0031] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application for which protection is claimed, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, each other embodiment obtained by those skilled in the art without making creative work falls within the scope of protection of the present application.
[0032] It is worth noting that prior to the filing of this application, players in Massive Multiplayer Online Role Playing Games (MMORPGs) were able to engage in relatively free transactions with each other. This mechanism was exploited by some players or game studios, who opened multiple accounts and transferred resources from their secondary accounts to their primary accounts in bulk. This behavior had a serious negative impact on the game's economic system, easily leading to the devaluation of in-game currency and, in turn, shortening the game's lifecycle. Therefore, maintaining the healthy and stable operation of the in-game economic system has become crucial for the long-term and stable operation of MMORPGs. To enhance the vitality and competitiveness of the game, stabilize the exchange rate of in-game currency, ensure fairness and justice, and protect a positive experience for paying players, it is necessary to accurately identify and severely crack down on illegal players' money-swindling behavior. However, existing technologies typically compare the current transaction's transaction data with a threshold and then determine whether the current transaction is abnormal based on the comparison results. However, determining whether a transaction is abnormal based solely on the transaction data comparison results is inaccurate.
[0033] For example, transaction data includes transaction prices. The current transaction price is compared with a price threshold. If the transaction price exceeds the price threshold, the current transaction is considered abnormal. However, the current transaction price exceeding the price threshold may be due to a decrease in the output of virtual props in the current game system. Therefore, it is clearly inaccurate to determine whether the current transaction is a fraudulent activity based solely on the price comparison result.
[0034] Another example is using a boxplot model to identify abnormal player trades. In this case, the upper and lower quartiles of the trade price are calculated based on historical data, and the upper and lower quartiles are used to determine whether the trade order is abnormal.
[0035] The terms involved in the embodiments of this application are explained below.
[0036] Graphical User Interface:
[0037] It is an interface display format for communication between people and computers. It allows users to manipulate icons, logos or menu options on the screen using input devices such as a mouse or keyboard. It also allows users to manipulate icons or menu options on the screen by performing touch operations on the touch screen of a touch terminal to select commands, start programs or perform other tasks.
[0038] Game scene:
[0039] A game scene is a virtual scene displayed (or provided) when an application is running on a terminal device or server, i.e., the scene used during normal game play. In other words, a game scene refers to the virtual game controls that host virtual objects during game play. Within this virtual scene, virtual objects can perform actions such as movement and skill releases in response to commands issued by the user (i.e., player) to the terminal device. Optionally, the game scene can be a simulation of the real world, a virtual environment that is partially simulated and partially fictional, or a purely fictional virtual environment. A game scene can be any of two-dimensional, two-and-a-half-dimensional, and three-dimensional virtual scenes. The virtual environment can include the sky, land, ocean, etc., where the land includes environmental elements such as deserts and cities. A game scene is a scene where users control the complete game logic of virtual objects. Optionally, a game scene can also be used for virtual environment battles between at least two virtual objects, with virtual resources available for use by at least two virtual objects. Exemplarily, a game scene can include any one or more of the following elements: game background elements, game avatar elements, game prop elements, etc.
[0040] In an optional implementation, the in-game data monitoring method in one embodiment of the present disclosure can be run on a local terminal device or a server. When the in-game data monitoring method is run on a server, the method can be implemented and executed based on a cloud interaction system, wherein the cloud interaction system includes a server and a client device.
[0041] In an optional embodiment, various cloud applications can be run under the cloud interaction system, such as cloud games. Taking cloud games as an example, cloud games refer to a gaming method based on cloud computing. In the cloud game operation mode, the operating body of the game program and the main body of the game screen presentation are separated. The storage and operation of the game loading method are completed on the cloud game server. The role of the client device is to receive and send data and present the game screen. For example, the client device can be a display device with data transmission function close to the user side, such as a mobile terminal, TV, computer, PDA, etc.; but the cloud game server in the cloud is responsible for information processing. When playing the game, the player operates the client device to send operation instructions to the cloud game server. The cloud game server runs the game according to the operation instructions, encodes and compresses the game screen and other data, and returns it to the client device through the network. Finally, the client device decodes and outputs the game screen.
[0042] In an optional embodiment, taking a game as an example, a local terminal device stores a game program and is used to present the game screen. The local terminal device is used to interact with the player through a graphical user interface, that is, conventionally downloading and installing the game program through an electronic device and running it. The local terminal device can provide the graphical user interface to the player in a variety of ways, for example, it can be rendered and displayed on the terminal's display screen, or provided to the player through holographic projection. For example, the local terminal device may include a display screen and a processor, the display screen is used to present the graphical user interface, the graphical user interface includes the game screen, and the processor is used to run the game, generate the graphical user interface, and control the display of the graphical user interface on the display screen.
[0043] In one possible implementation, an embodiment of the present invention provides a data monitoring method for a game, providing a graphical user interface through a terminal device, wherein the terminal device can be the local terminal device mentioned above, or the client device in the cloud interactive system mentioned above.
[0044] Based on this, an embodiment of the present application provides a data monitoring method in a game to improve the accuracy of monitoring abnormal transaction data in the game.
[0045] See also Figure 1 , Figure 1 This is a flow chart of a data monitoring method for a game provided by an embodiment of the present application. Figure 1 As shown, the data monitoring method in the game provided by the embodiment of the present application includes:
[0046] Step S101: obtaining a transaction order to be evaluated for a target virtual item in a specified type of transaction, and determining, based on order information of the transaction order to be evaluated, a first reference value for measuring the degree of transaction anomaly of the target virtual item and a second reference value for measuring the degree of transaction anomaly of the virtual character participating in the transaction;
[0047] Step S102: determining a first abnormality score for characterizing the degree of abnormality in the transaction of the target virtual item based on the transaction information and the first reference value;
[0048] Step S103, determining a second abnormality score for characterizing the degree of abnormality of the transaction of the virtual character based on the transaction behavior data of the virtual character participating in the transaction and the second reference value;
[0049] Step S104: Determine the abnormality level of the transaction order to be evaluated based on the first abnormality score and the second abnormality score.
[0050] The order information includes transaction information of the target virtual item.
[0051] The in-game data monitoring method provided by the embodiment of the present application can evaluate the abnormality of the transaction order to be evaluated from two dimensions: the abnormality of the transaction of the target virtual props and the abnormality of the transaction of the virtual character. This avoids the problem of low data monitoring accuracy caused by directly determining whether the transaction is abnormal based on the comparison results of the order prices, and improves the accuracy of data monitoring for abnormal transactions in the game.
[0052] To facilitate understanding of this embodiment, the following takes the application of the information processing method in the game provided in the embodiment of the present application to a game server as an example to illustrate each of the above exemplary steps provided in the embodiment of the present application.
[0053] In step S101, a transaction order to be evaluated for a target virtual item in a specified type of transaction is obtained, and based on the order information of the transaction order to be evaluated, a first reference value for measuring the degree of transaction abnormality of the target virtual item and a second reference value for measuring the degree of transaction abnormality of the virtual character participating in the transaction are determined.
[0054] In this step, the designated type of transaction may refer to a transaction between virtual characters that can transfer game virtual currency in the transaction chain of converting game virtual assets into real economic benefits. As an example, the designated type of transaction may refer to setting up a stall in the game, where users can sell target virtual props to each other in exchange for virtual gold coins.
[0055] A pending transaction order refers to an order generated by a user participating in a specific type of transaction. Order information includes the transaction details of the target virtual item and virtual character. The order information also includes the transaction time and the estimated price of the item.
[0056] The transaction information is used to describe the transaction volume and transaction amount of the target virtual item in the transaction order to be evaluated. The transaction information includes the item identifier, item type, transaction quantity and transaction amount of the target virtual item being traded.
[0057] Virtual characters are used to describe the buyers and sellers involved in a transaction. Buyers and sellers refer to the seller and the buyer. Both buyers and sellers are controlled virtual characters. One of the two controlled virtual characters is the seller, and the other of the two controlled virtual characters is the buyer.
[0058] The method of obtaining the transaction order to be evaluated includes at least one of the following:
[0059] In one case, when a transaction is completed, the transaction order to be evaluated is immediately obtained to determine the abnormality of the transaction order to be evaluated.
[0060] In another case, a transaction order to be evaluated is obtained in response to an order monitoring instruction. For example, when a game developer needs to determine the degree of abnormality of an order for a target virtual item, an order monitoring instruction is generated based on a triggering operation of the game developer.
[0061] The first reference value may refer to the reference value used when judging the degree of abnormality of a transaction order from the dimension of the degree of abnormality of the transaction of the target virtual item. The first reference value includes a transaction quantity reference value and a transaction amount reference value. The transaction quantity reference value includes the transaction quantity mean and the transaction quantity standard deviation. The transaction amount reference value includes the transaction amount mean and the transaction amount standard deviation.
[0062] The second reference value may refer to a reference value used to judge the degree of abnormality of the transaction order to be evaluated from the dimension of the degree of transaction abnormality of the virtual characters participating in the transaction. The second reference value includes but is not limited to: the frequency mean and the frequency standard deviation. The frequency mean and the frequency standard deviation are determined based on the number of transactions of each group of designated characters within the first preset time period.
[0063] In order to accurately judge the degree of transaction abnormality of the target virtual item, it is necessary to determine a first reference value.
[0064] Refer to the following Figure 2 Let's introduce the process of determining the first reference value.
[0065] Figure 2 A flowchart showing the steps of determining the first reference value provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the step of determining the first reference value includes:
[0066] Step S1011: Acquire multiple first transaction orders for determining normal transaction information of the target virtual item according to the target virtual item identifier in the order information.
[0067] For example, multiple first transaction orders matching the target virtual item's identifier are searched for in historical transaction orders. The target virtual item's transaction information during normal trading periods is determined using these first transaction orders. This information is then used to determine the degree of abnormality in the target virtual item's trading. Each first transaction order is generated during normal trading.
[0068] Among them, since the transaction information of the same virtual props in different time periods varies greatly, in order to ensure the accuracy of the first reference value, multiple first transaction orders can be obtained from the historical transaction orders of the past month.
[0069] Step S1012: determining a first reference value based on the transaction information and transaction times corresponding to the plurality of first transaction orders.
[0070] For example, the total transaction quantity of the target virtual props under all first transaction orders is counted. The total transaction quantity is recorded as: Q, and the transaction quantity of the target virtual props under the i-th first transaction order is recorded as: q i ; Count the total transaction amount under all first transaction orders, the total transaction amount is recorded as: M, the transaction amount of the target virtual prop under the i-th first transaction order is recorded as: m i Count the number of transactions corresponding to all first transaction orders. The number of transactions is recorded as: N, where the number of transactions can refer to the number of times a single transaction is successfully completed. The number of transactions corresponds to the number of transaction orders. For each transaction order formed, the number of transactions increases by one. The average number of transactions is recorded as: AVE q , the standard deviation of transaction quantity is recorded as: ST q ; The average transaction amount is recorded as: AVE m , the standard deviation of transaction amount is recorded as: ST m .
[0071] Determine the average transaction amount AVE based on the ratio of the total transaction amount to the number of transactions q ,AVE q =Q / N. Determine the sum of the squares of the differences between the transaction quantity of each first transaction order and the mean transaction quantity, and use the ratio of this sum of squares to the difference corresponding to the number of transactions to determine the standard deviation of the transaction quantity ST. q .ST q The calculation formula is:
[0072]
[0073] Determine the average transaction amount AVE based on the ratio of the total transaction amount M to the number of transactions N m ,AVE m=M / N. Determine the sum of the squares of the difference between the transaction amount of each first transaction order and the mean transaction amount, and the ratio of the sum of squares to the difference corresponding to the number of transactions to determine the standard deviation of the transaction amount ST m .ST m The calculation formula is:
[0074]
[0075] Refer to the following Figure 3 Next, we will introduce the process of determining the second reference value.
[0076] Figure 3 A flowchart showing the steps for determining the second reference value provided in an embodiment of the present application is shown in FIG. Figure 3 As shown, the step of determining the second reference value includes:
[0077] Step S1013: determining, based on the role information of the virtual role participating in the transaction, a plurality of groups of designated roles corresponding to the virtual role participating in the transaction.
[0078] Character information may refer to information associated with a virtual character, and a virtual character may refer to a controlled virtual character participating in this transaction. As an example, character information includes but is not limited to: the level of the controlled virtual character, the combat power of the controlled virtual character, the level of the pet carried, the combat power of the pet carried, the VIP level, and the IP address of the login terminal device.
[0079] In order to more accurately define the degree of abnormality in the transactions of the virtual characters, designated characters participating in normal transactions may be selected, and the transaction information of the designated characters participating in normal transactions may be used to evaluate the degree of abnormality in the transactions of the virtual characters.
[0080] For example: multiple groups of designated roles that match the role information are selected, and the designated roles may refer to designated controlled virtual roles that meet the screening conditions. Each group of designated roles includes a seller and a buyer. The normal transaction orders of each group of designated roles are obtained, and the transaction information of the normal transaction orders of each group of designated roles is used to determine the second reference value.
[0081] Among them, the screening conditions include at least one of the following items: the level difference between the seller of each group of specified characters and the seller in the transaction order is within the first preset range, the level difference between the buyer of each group of specified characters and the buyer in the transaction order is within the first preset range, the combat power difference between the seller of each group of specified characters and the seller in the transaction order is within the second preset range, the combat power difference between the buyer of each group of specified characters and the buyer in the transaction order is within the second preset range, the VIP level difference between the seller of each group of specified characters and the seller in the transaction order is within the third preset range, and the VIP level difference between the buyer of each group of specified characters and the buyer in the transaction order is within the third preset range.
[0082] Step S1014 , determining a second reference value according to the number of transactions of the multiple groups of designated roles within the first preset time period and the number of groups of designated roles.
[0083] For example, consider counting the number of transactions per group of designated roles over the past month. The transaction frequency for each group of designated roles is determined by the ratio of the number of transactions per day. The mean frequency is then calculated by the ratio of the sum of the transaction frequencies for all groups of designated roles to the number of groups of designated roles. For example, if the sum of the transaction frequencies for 100 groups of designated roles over a given month is 1000, the mean frequency is 10.
[0084] Determine the sum of squares of the difference between the transaction frequency of each group of specified roles and the frequency mean, and the ratio of the sum of squares to the difference corresponding to the number of groups to determine the frequency standard deviation ST f The mean frequency is recorded as: AVE f , the frequency standard deviation is recorded as: ST f , the number of groups of the specified role is recorded as: G, the default value is 1, then ST f The calculation formula is:
[0085]
[0086] In step S102, based on the transaction information and the first reference value, a first abnormality score is determined to characterize the degree of abnormality in the transaction of the target virtual item.
[0087] In this step, the first anomaly score includes a transaction volume anomaly score and a transaction amount anomaly score.
[0088] Refer to the following Figure 4 Let's introduce the steps for determining the first anomaly score.
[0089] Figure 4 A flowchart showing the steps for determining the first abnormality score provided in an embodiment of the present application is shown in FIG. Figure 4 As shown, the step of determining the first abnormality score includes:
[0090] Step S1021: Determine a transaction volume anomaly score based on the transaction volume and the transaction volume reference value.
[0091] For example, the transaction volume reference value includes the mean transaction volume and the standard deviation of the transaction volume. The absolute value of the difference between the transaction volume in the transaction order and the mean transaction volume is calculated, and the ratio of the absolute value to the standard deviation of the transaction volume is determined as the transaction volume anomaly score.
[0092] Step S1022: Determine a transaction amount abnormality score based on the transaction amount and the transaction amount reference value.
[0093] For example, the transaction amount reference value includes the mean transaction amount and the standard deviation of the transaction amount. The absolute value of the difference between the transaction amount in the transaction order and the mean transaction amount is calculated, and the ratio of this absolute value to the standard deviation of the transaction amount is used to determine the transaction amount anomaly score. The transaction quantity reference value and transaction amount reference value are determined based on the transaction information and number of transactions corresponding to the first transaction order.
[0094] In step S103 , based on the transaction behavior data of the virtual character involved in the transaction and the second reference value, a second abnormality score for characterizing the degree of abnormality in the transaction of the virtual character is determined.
[0095] In this step, the transaction behavior data includes but is not limited to: the transaction frequency of the virtual character in the second preset time period and the abnormality of the transaction behavior of the virtual character.
[0096] The abnormality degree is used to evaluate the abnormality of the virtual character's trading behavior. The abnormality degree is determined based on the number and ranking of the virtual characters in the abnormal character queue. The abnormal character queue is used to record virtual characters with abnormal trading behavior and / or illegal trading behavior.
[0097] The transaction frequency of the virtual character may refer to the frequency of recent transactions between the seller and the buyer of the virtual character. The transaction frequency of the virtual character is determined based on the ratio of the number of recent transactions between the seller and the buyer of the virtual character to the number of recent days.
[0098] Refer to the following Figure 5 Let's introduce the steps for determining the second anomaly score.
[0099] Figure 5 A flowchart showing the steps for determining the second abnormality score provided in an embodiment of the present application is shown in FIG. Figure 5 As shown, the step of determining the second abnormality score includes:
[0100] Step S1031: Determine a frequency ratio based on the transaction frequency and the second reference value.
[0101] For example: based on the difference between the transaction frequency of the virtual character and the frequency mean, the frequency difference is determined; based on the ratio of the frequency difference to the frequency standard deviation, the frequency ratio is determined.
[0102] Step S1032: Correct the frequency ratio using the abnormality degree to determine a second abnormality score.
[0103] Here, since the frequency ratio can only reflect the degree of transaction anomaly based on the most recent transaction frequency, it cannot fully reflect the degree of transaction anomaly of the virtual character. Therefore, this application modifies the second anomaly score by the degree of anomaly. For example, the product of the degree of anomaly and the frequency ratio is determined as the second anomaly score.
[0104] In one example, if the seller and the buyer in the virtual character are both in the abnormal character queue, the abnormality is determined based on the first preset basic score, the abnormality score coefficient corresponding to the seller's ranking, and the abnormality score coefficient corresponding to the buyer's ranking.
[0105] For example: the first preset basic score is 1, and the ranking of each abnormal role queue corresponds to an abnormal scoring coefficient. If the seller's ranking is 10, its corresponding abnormal scoring coefficient is 0.1, and the seller's weight is 0.65; the buyer's ranking is 5, its corresponding abnormal scoring coefficient is 0.2, and the buyer's weight is 0.35. Then first calculate the sum of the weights of the two abnormal scoring coefficients as: 0.1×0.65+0.2×0.35=0.135, and determine the abnormality degree by adding the sum of the weights and the first preset basic score. At this time, the abnormality degree is 1.135.
[0106] If the seller or the buyer is in the abnormal role queue, the abnormality degree is determined based on the second preset basic score and the abnormality score coefficient corresponding to the ranking of the target virtual role in the abnormal role queue.
[0107] For example: the second preset basic score is 0.6, the seller is in the abnormal role queue, if the seller is ranked 9, its corresponding abnormal score coefficient is 0.12, and the seller's weight is 0.65, then first calculate the sum of the weights of the two abnormal score coefficients: 0.12×0.65=0.078, and determine the sum of the weights and the sum of the second preset basic score as the abnormality degree. At this time, the abnormality degree is 0.678.
[0108] Refer to the following Figure 6 To introduce the construction process of the abnormal role queue.
[0109] Figure 6 A flowchart showing the steps for constructing an abnormal role queue provided in an embodiment of the present application is shown in FIG. Figure 6 As shown, the steps for building the abnormal role queue include:
[0110] Step S1034 , obtaining candidate virtual characters that have participated in transactions of the specified type, using the candidate virtual characters as nodes, establishing a directed edge between every two candidate virtual characters, and constructing a transaction behavior topology graph.
[0111] Here, the candidate virtual characters in the transaction behavior topology graph include a first virtual character who has participated in abnormal transactions and a second virtual character who has not participated in abnormal transactions, and the first virtual character and the second virtual character are displayed in the transaction behavior topology graph in different presentation forms.
[0112] A directed edge is an edge with an arrow pointing from the seller to the buyer. Directed edges are used to indicate the flow of goods. Each directed edge has a weight, which is determined based on the transaction information between the two candidate virtual characters corresponding to the directed edge. For example, if a transaction is conducted between two nodes, the order information in the transaction order can be used to determine the number of virtual props traded and the estimated value of the virtual props. The estimated amount of the transaction is calculated by multiplying the estimated value by the number of virtual props. The weight of the transaction is determined based on the estimated amount, and the weight of the transaction is added to the previous weight of this directed edge based on the preset weight. The preset weight of each latest transaction is always greater than the preset weight of the previous weight of this directed edge.
[0113] Step S1035 : For each first virtual character, determine the abnormal transaction link corresponding to the first virtual character, and determine the abnormal transaction participation degree of the first virtual character based on the sum of the weights of the directed edges under the abnormal transaction link.
[0114] Here, the abnormal transaction link is used to represent the transaction relationship between the first virtual characters.
[0115] Refer to the following Figure 7 Let’s introduce the abnormal transaction link.
[0116] Figure 7 A schematic diagram of a transaction behavior topology diagram provided in an embodiment of the present application is shown as follows: Figure 7 As shown, the transaction behavior topology graph includes nodes A, B, C, D, and E corresponding to the first virtual character, and node G corresponding to the second virtual character. The transaction behavior topology graph includes directed edge 201 from node G to node A, directed edge 211 from node A to node B, directed edge 213 from node B to node C, directed edge 212 from node B to node D, directed edge 214 from node D to node E, directed edge 221 from node C to node B, and directed edge 222 from node B to node A. Thus, the abnormal transaction links corresponding to node A include abnormal transaction link ABC corresponding to directed edges 211 and 213, abnormal transaction links ABDE corresponding to directed edges 211, 212, and 214, and abnormal transaction link CBA corresponding to directed edges 221 and 222, for a total of three abnormal transaction links.
[0117] First, calculate the weight of each abnormal transaction link corresponding to node A. Taking abnormal transaction link ABDE as an example, the sum of the weights of directed edge 211, directed edge 212, and directed edge 214 under abnormal transaction link ABDE is used as the weight of abnormal transaction link ABDE. Similarly, the weight of each abnormal transaction link corresponding to node A can be determined.
[0118] Then, according to the directions of the abnormal transaction links, the weights of the three abnormal transaction links are weightedly summed to determine the abnormal transaction participation degree of the first virtual character.
[0119] For example, if the direction is from node A to another node, it means that the gold is flowing to node A, and the corresponding weight of the abnormal transaction link is 0.7. If the direction is from another node to node A, it means that the gold is flowing to another node, and the corresponding weight of the abnormal transaction link is 0.3. In this way, the weights of abnormal transaction links ABC and ABDE are 0.7, and the weight of abnormal transaction link CBA is 0.3. If the weights of abnormal transaction links ABC and ABDE are 10, and the weight of abnormal transaction link CBA is 5, the abnormal transaction participation rate is 10×0.7+10×0.7+5×0.3=15.5.
[0120] Step S1036: sort the first virtual characters according to the degree of participation in abnormal transactions to construct an abnormal character queue.
[0121] According to the calculation method of the abnormal transaction degree of node A, the abnormal transaction participation degree of the node corresponding to each first virtual character in the transaction behavior topology diagram can be determined, and then the first virtual characters are sorted in order from large to small according to the abnormal transaction participation degree, and the abnormal scoring coefficient is set according to the abnormal transaction participation degree, thereby constructing an abnormal role queue.
[0122] The abnormality scoring coefficient is positively correlated with the degree of abnormal transaction participation. When setting the abnormality scoring coefficient, the specific value of the abnormality scoring coefficient can be set by combining the number of illegal transactions of the first virtual character and the degree of abnormal transaction participation. The number of illegal transactions can be obtained through manual marking.
[0123] In step S104, the abnormality degree of the transaction order to be evaluated is determined based on the first abnormality score and the second abnormality score.
[0124] In this step, the degree of anomaly reflects the likelihood that the transaction order being evaluated is an abnormal order. A comprehensive anomaly score can be determined based on the first and second anomaly scores. The comprehensive anomaly score can be calculated by taking the root mean square of the transaction volume anomaly score, the transaction amount anomaly score, and the second anomaly score. The degree of anomaly is then determined based on the target score range within which the comprehensive anomaly score falls.
[0125] For example, the comprehensive anomaly score is divided into four intervals, each corresponding to a degree of abnormality. The degrees of abnormality include extremely mild abnormality, mild abnormality, normal abnormality, and severe abnormality. The scoring interval for extremely mild abnormality is (0, 0.5), the scoring interval for mild abnormality is (0.5, 0.7), the scoring interval for normal abnormality is (0.7, 0.9), and the scoring interval for severe abnormality is (0.9, 1). For example, if the comprehensive anomaly score is 0.6, the target scoring interval is (0.5, 0.7), and the degree of abnormality is mild.
[0126] If the degree of abnormality is slight abnormality, ordinary abnormality or severe abnormality, the transaction order to be evaluated is determined to be an abnormal order. If it is an abnormal order, the transaction order to be evaluated is marked as abnormal and an abnormal alert is sent.
[0127] In one example, after determining the abnormality level of each transaction order to be evaluated, the transaction health of the target virtual item may also be determined. The transaction health of the target virtual item includes transaction volume health and transaction amount health.
[0128] Refer to the following Figure 8 Let’s introduce the process of determining transaction health.
[0129] Figure 8 A flowchart showing the steps for determining transaction health provided by an embodiment of the present application is shown as follows: Figure 8 As shown, the steps for determining transaction health include:
[0130] Step S1041: Acquire multiple historical transaction orders corresponding to the target virtual item, and determine abnormal orders among the multiple historical transaction orders based on the abnormality level of each historical transaction order.
[0131] Obtain multiple historical transaction orders corresponding to the target virtual item, and refer to the above-mentioned method for determining the abnormality level of the transaction order to be evaluated to determine the abnormality level of each historical transaction order for the target virtual item, and select abnormal orders with a slight abnormality, a normal abnormality, or a severe abnormality level from the multiple historical transaction orders.
[0132] Step S1042: Determine the transaction health of the target virtual item based on the abnormality level and transaction information of the abnormal order.
[0133] Regarding the health of trading volume, the number of transactions at different levels of abnormality in abnormal orders and the total number of transactions of the target virtual props in multiple historical transaction orders are determined. The health of trading volume is determined based on the ratio of the sum of the weights of the number of transactions at different levels of abnormality to the total number of transactions.
[0134] The formula for calculating trading volume health is: (1 - (number of orders with minor anomalies × w1 + number of orders with normal anomalies × w2 + number of orders with severe anomalies × w3)) / total number of transactions. w1, w2, and w3 represent the weighting coefficients for trading volume health at different levels of anomaly, respectively.
[0135] For example, there are 120 abnormal orders among 5,000 historical trading orders. Among these 120 abnormal orders, 70 are slightly abnormal, 40 are generally abnormal, and 10 are seriously abnormal. A total of 10,000 target virtual items were traded in these 5,000 historical trading orders. The ratio of the sum of the weights of the number of transactions at different levels of abnormality to the total number of transactions is: (70×w1+40×w2+10×w3) / 10,000.
[0136] Regarding the health of the transaction amount, the total transaction amount of the abnormal order and the total transaction amount of multiple historical transaction orders are determined. The health of the transaction amount is determined based on the ratio of the square of the total transaction amount of the abnormal order to the square of the total transaction amount of multiple historical transaction orders.
[0137] For example, the calculation formula for transaction amount health is: Among them, Am represents the total transaction amount of abnormal orders, and Hm represents the total transaction amount of multiple historical transaction orders.
[0138] In one example, an abnormal order evaluation model can be constructed, the input of the abnormal order evaluation model is the order information of the transaction order to be evaluated, and the output of the abnormal order evaluation model is the abnormality degree of the transaction order to be evaluated. The data monitoring method in the game provided in this application can be handled by the constructed abnormal order evaluation model, which can be a LightGBM model or other neural network models. When using the abnormal order evaluation model to determine the abnormality degree of the transaction order to be evaluated, the order information of the transaction order to be evaluated can be input into the abnormal order evaluation model, and the abnormal order evaluation model will output the abnormality degree of the transaction order to be evaluated.
[0139] For example: the abnormal order evaluation model will execute steps S101 to S104 to determine a first reference value for measuring the degree of transaction abnormality of the target virtual item and a second reference value for measuring the degree of transaction abnormality of the virtual character participating in the transaction based on the order information of the transaction order to be evaluated, where the order information includes the transaction information of the target virtual item; based on the transaction information and the first reference value, a first abnormality score for characterizing the degree of transaction abnormality of the target virtual item is determined; based on the transaction behavior data of the virtual character participating in the transaction and the second reference value, a second abnormality score for characterizing the degree of transaction abnormality of the virtual character is determined; based on the first abnormality score and the second abnormality score, the degree of abnormality of the transaction order to be evaluated is determined.
[0140] Based on the same inventive concept, the embodiments of the present application also provide a data monitoring device in the game corresponding to the data monitoring method in the game. Since the principle of solving the problem by the device in the embodiments of the present application is similar to the data monitoring method in the above-mentioned game in the embodiments of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0141] See also Figure 9 , Figure 9 This is a schematic diagram of the structure of a data monitoring device in a game provided by an embodiment of the present application. Figure 9 As shown in , the data monitoring device 200 in the game includes:
[0142] Reference value determination module 201 is configured to obtain a transaction order to be evaluated for a target virtual item in a specified type of transaction, and determine, based on order information of the transaction order to be evaluated, a first reference value for measuring the degree of transaction anomaly of the target virtual item and a second reference value for measuring the degree of transaction anomaly of the virtual character involved in the transaction, wherein the order information includes transaction information of the target virtual item;
[0143] A first scoring module 202 is configured to determine a first abnormality score for characterizing the degree of abnormality in the transaction of the target virtual item based on the transaction information and the first reference value;
[0144] A second scoring module 203 is configured to determine a second abnormality score for characterizing a degree of abnormality in a transaction of a virtual character based on the transaction behavior data of the virtual character participating in the transaction and a second reference value;
[0145] The abnormality evaluation module 204 is configured to determine the abnormality level of the transaction order to be evaluated based on the first abnormality score and the second abnormality score.
[0146] In a feasible embodiment of the present application, the reference value determination module 201 is specifically used to: obtain multiple first transaction orders for determining normal transaction information of the target virtual item based on the target virtual item identifier in the order information; and determine the first reference value based on the transaction information and transaction times corresponding to the multiple first transaction orders.
[0147] In a feasible embodiment of the present application, the reference value determination module 201 is further specifically used to: determine multiple groups of designated roles corresponding to the virtual characters participating in the transaction based on the role information of the virtual characters participating in the transaction; and determine the second reference value based on the number of transactions of the multiple groups of designated roles within the first preset time period and the number of groups of designated roles.
[0148] In a feasible embodiment of the present application, the data monitoring device 200 in the game also includes an alarm module, which is used to: determine whether the transaction order to be evaluated is an abnormal order based on the degree of abnormality; if it is an abnormal order, mark the transaction order to be evaluated as abnormal and send an abnormal alarm.
[0149] In a feasible embodiment of the present application, the transaction behavior data includes the transaction frequency of the virtual character in the second preset time period and the abnormality of the virtual character's transaction behavior. The second scoring module 203 includes a frequency ratio determination module and an abnormality score determination module. The frequency ratio determination module is used to: determine the frequency ratio based on the transaction frequency and the second reference value; the abnormality score determination module is used to: use the abnormality to correct the frequency ratio and determine the second abnormality score. The abnormality is determined based on the number and ranking of the virtual character in the abnormal character queue. The abnormal character queue is used to record virtual characters that have participated in abnormal transactions.
[0150] In a feasible embodiment of the present application, the virtual characters include the seller and the buyer in the transaction order to be evaluated, and the data monitoring device 200 in the game also includes an abnormality determination module, which is used to: if the seller and the buyer are both in the abnormal character queue, then the abnormality is determined based on the first preset basic score, the abnormality score coefficient corresponding to the seller's ranking, and the abnormality score coefficient corresponding to the buyer's ranking; if the seller or the buyer is in the abnormal role queue, then the abnormality is determined based on the second preset basic score and the abnormality score coefficient corresponding to the ranking of the target virtual character in the abnormal role queue.
[0151] In a feasible embodiment of the present application, the data monitoring device 200 in the game also includes a queue construction module, which is used to: obtain candidate virtual characters that have participated in transactions of a specified type; using the candidate virtual characters as nodes, establish a directed edge between every two candidate virtual characters to construct a transaction behavior topology graph, and the weight of each directed edge is determined based on the transaction information between the two candidate virtual characters corresponding to the directed edge, and the candidate virtual characters include first virtual characters participating in abnormal transactions; for each first virtual character, determine the abnormal transaction link corresponding to the first virtual character, and determine the abnormal transaction participation degree of the first virtual character based on the sum of the weights of the directed edges under the abnormal transaction link, and the abnormal transaction link is used to characterize the transaction relationship between the first virtual characters; sort the first virtual characters according to the size of the abnormal transaction participation degree to construct an abnormal role queue.
[0152] In a feasible embodiment of the present application, the second reference value includes a frequency mean and a frequency standard deviation determined based on the number of transactions of each group of designated roles within the first preset time period, and the frequency ratio determination module is specifically used to: determine the frequency difference based on the difference between the transaction frequency and the frequency mean; determine the frequency ratio based on the ratio of the frequency difference to the frequency standard deviation.
[0153] In a feasible embodiment of the present application, the first reference value includes a transaction quantity reference value and a transaction amount reference value determined based on the transaction information and transaction number corresponding to the first transaction order, the transaction information includes the transaction quantity and the transaction amount, the first anomaly score includes the transaction volume anomaly score and the transaction amount anomaly score, and the first scoring module 202 is specifically used to: determine the transaction volume anomaly score based on the transaction quantity and the transaction quantity reference value; determine the transaction amount anomaly score based on the transaction amount and the transaction amount reference value.
[0154] In a feasible embodiment of the present application, the data monitoring device 200 in the game also includes a health determination module, which is used to: obtain multiple historical transaction orders corresponding to the target virtual props, and determine abnormal orders among the multiple historical transaction orders based on the abnormality level of each historical transaction order; determine the transaction health of the target virtual props based on the abnormality level and transaction information of the abnormal orders.
[0155] In a feasible embodiment of the present application, the transaction information includes the number of transactions, the transaction health includes the transaction volume health, the health determination module includes the transaction volume health determination module, and the transaction volume health determination module is used to: determine the transaction number of abnormal orders at different abnormality levels and the total transaction number of target virtual props in multiple historical transaction orders; determine the transaction volume health based on the ratio of the sum of the weights of the transaction numbers at different abnormality levels to the total transaction number.
[0156] In a feasible embodiment of the present application, the transaction information includes the transaction amount, the transaction health includes the transaction amount health, the health determination module includes the transaction amount health determination module, and the transaction amount health determination module is used to: determine the total transaction amount of the abnormal order and the total transaction amount of multiple historical transaction orders; determine the transaction amount health based on the ratio of the square of the total transaction amount of the abnormal order to the square of the total transaction amount of multiple historical transaction orders.
[0157] In a feasible embodiment of the present application, the data monitoring device 200 in the game also includes a model building module, which is used to: build an abnormal order evaluation model, the input of the abnormal order evaluation model is the order information of the transaction order to be evaluated, and the output of the abnormal order evaluation model is the degree of abnormality; the abnormal order evaluation model determines the degree of abnormality in the following manner: based on the order information of the transaction order to be evaluated, determining a first reference value for measuring the degree of transaction abnormality of the target virtual prop and a second reference value for measuring the degree of transaction abnormality of the virtual character participating in the transaction, the order information includes the transaction information of the target virtual prop; based on the transaction information and the first reference value, determining a first abnormality score for characterizing the degree of transaction abnormality of the target virtual prop; based on the transaction behavior data of the virtual character participating in the transaction and the second reference value, determining a second abnormality score for characterizing the degree of transaction abnormality of the virtual character; based on the first abnormality score and the second abnormality score, determining the degree of abnormality of the transaction order to be evaluated.
[0158] The in-game data monitoring device provided by the embodiment of the present application can evaluate the abnormality of an order from two dimensions: the abnormality of the transaction of the target virtual props and the abnormality of the transaction of the virtual character. This avoids the problem of low data monitoring accuracy caused by directly determining whether a transaction is abnormal based on the comparison results of the order prices, and improves the accuracy of data monitoring for abnormal transactions in the game.
[0159] See also Figure 10 , Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 10 As shown in FIG, the electronic device 300 includes a processor 310 , a memory 320 and a bus 330 .
[0160] The memory 320 stores machine-readable instructions executable by the processor 310. When the electronic device 300 is running, the processor 310 communicates with the memory 320 via the bus 330. When the machine-readable instructions are executed by the processor 310, the above-mentioned Figure 1 The steps of the data monitoring method in the game in the method embodiment are specifically implemented as follows:
[0161] Obtain a transaction order to be evaluated for a target virtual item in a specified type of transaction, determine a first reference value for measuring the degree of transaction abnormality of the target virtual item and a second reference value for measuring the degree of transaction abnormality of a virtual character participating in the transaction based on order information of the transaction order to be evaluated, wherein the order information includes transaction information of the target virtual item; determine a first abnormality score for characterizing the degree of transaction abnormality of the target virtual item based on the transaction information and the first reference value; determine a second abnormality score for characterizing the degree of transaction abnormality of the virtual character based on transaction behavior data of the virtual character participating in the transaction and the second reference value; and determine the degree of abnormality of the transaction order to be evaluated based on the first abnormality score and the second abnormality score.
[0162] The electronic device in the game provided by the embodiment of the present application can evaluate the abnormality of the transaction order to be evaluated based on two dimensions: the abnormality of the transaction of the target virtual props and the abnormality of the transaction of the virtual character. This avoids the problem of low data monitoring accuracy caused by directly determining whether the transaction is abnormal based on the comparison results of the order prices, and improves the accuracy of data monitoring for abnormal transactions in the game.
[0163] The embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the computer program can execute the above-mentioned Figure 1 The steps of the data monitoring method in the game in the method embodiment are specifically implemented as follows:
[0164] Obtain a transaction order to be evaluated for a target virtual item in a specified type of transaction, determine a first reference value for measuring the degree of transaction abnormality of the target virtual item and a second reference value for measuring the degree of transaction abnormality of a virtual character participating in the transaction based on order information of the transaction order to be evaluated, wherein the order information includes transaction information of the target virtual item; determine a first abnormality score for characterizing the degree of transaction abnormality of the target virtual item based on the transaction information and the first reference value; determine a second abnormality score for characterizing the degree of transaction abnormality of the virtual character based on transaction behavior data of the virtual character participating in the transaction and the second reference value; and determine the degree of abnormality of the transaction order to be evaluated based on the first abnormality score and the second abnormality score.
[0165] The computer-readable storage medium provided in the embodiment of the present application can evaluate the degree of abnormality of the transaction order to be evaluated based on two dimensions: the degree of abnormality of the transaction of the target virtual props and the degree of abnormality of the transaction of the virtual character. This avoids the problem of low data monitoring accuracy caused by directly determining whether the transaction is abnormal based on the comparison results of the order prices, and improves the accuracy of data monitoring for abnormal game transactions.
[0166] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0167] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. There may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be through some communication interface, indirect coupling or communication connection of devices or units, which may be electrical, mechanical or other forms.
[0168] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0169] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0170] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0171] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The scope of protection of the present application is not limited thereto. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-mentioned embodiments within the technical scope disclosed in the present application, or perform equivalent replacements for some of the technical features thereof. These modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A data monitoring method in a game, characterized in that: include: Obtaining a transaction order to be evaluated for a target virtual item in a specified type of transaction, and determining, based on order information of the transaction order to be evaluated, a first reference value for measuring a degree of transaction anomaly for the target virtual item and a second reference value for measuring a degree of transaction anomaly for a virtual character participating in the transaction, wherein the order information includes transaction information for the target virtual item; Determining, based on the transaction information and the first reference value, a first anomaly score for characterizing the degree of anomaly in the transaction of the target virtual item; Determining, based on the transaction behavior data of the virtual character participating in the transaction and the second reference value, a second abnormality score for characterizing a degree of abnormality in the transaction of the virtual character; The abnormality degree of the transaction order to be evaluated is determined based on the first abnormality score and the second abnormality score.
2. The method according to claim 1, characterized in that The first reference value is determined by: Acquire, according to the target virtual item identifier in the order information, a plurality of first transaction orders for determining normal transaction information of the target virtual item; A first reference value is determined based on the transaction information and transaction times corresponding to the multiple first transaction orders.
3. The method according to claim 1, characterized in that The second reference value is determined by: Determining, based on the role information of the virtual role participating in the transaction, a plurality of groups of designated roles corresponding to the virtual role participating in the transaction; A second reference value is determined according to the number of transactions of the multiple groups of designated roles within the first preset time period and the number of groups of designated roles.
4. The method according to claim 1, wherein The method further comprises: Determining whether the transaction order to be evaluated is an abnormal order based on the abnormality degree; If it is an abnormal order, the transaction order to be evaluated will be marked as abnormal and an abnormal alert will be sent.
5. The method according to claim 3, characterized in that The transaction behavior data includes the transaction frequency of the virtual character in a second preset time period and the abnormality of the transaction behavior of the virtual character. A second abnormality score for characterizing the degree of abnormality of the transaction of the virtual character is determined by: determining a frequency ratio based on the transaction frequency and the second reference value; The frequency ratio is corrected using an abnormality degree to determine a second abnormality score, wherein the abnormality degree is determined based on the number and ranking of the virtual characters in an abnormal character queue, wherein the abnormal character queue is used to record virtual characters that have participated in abnormal transactions.
6. The method according to claim 5, characterized in that The virtual characters include the seller and the buyer in the transaction order to be evaluated, and the abnormality is determined by the following method: If both the seller and the buyer are in the abnormal role queue, determining the abnormality degree based on the first preset basic score, the abnormality score coefficient corresponding to the seller's ranking, and the abnormality score coefficient corresponding to the buyer's ranking; If the seller or the buyer is in the abnormal role queue, the abnormality degree is determined based on the second preset basic score and the abnormality score coefficient corresponding to the ranking of the target virtual role in the abnormal role queue.
7. The method according to claim 5, characterized in that Construct the exception role queue in the following way: Obtain candidate virtual characters that have participated in transactions of the specified type; A transaction behavior topology graph is constructed by establishing a directed edge between each two candidate virtual characters using the candidate virtual characters as nodes, wherein the weight of each directed edge is determined based on transaction information between the two candidate virtual characters corresponding to the directed edge, wherein the candidate virtual characters include the first virtual character that has participated in the abnormal transaction; For each first virtual character, determining an abnormal transaction link corresponding to the first virtual character, and determining the abnormal transaction participation degree of the first virtual character based on the sum of the weights of the directed edges under the abnormal transaction link, wherein the abnormal transaction link is used to represent the transaction relationship between the first virtual characters; The first virtual characters are sorted according to the degree of participation in the abnormal transaction to construct the abnormal character queue.
8. The method according to claim 5, characterized in that The second reference value includes a frequency mean and a frequency standard deviation determined based on the number of transactions of each group of designated roles within a first preset time period. Determining the frequency ratio based on the transaction frequency and the second reference value includes: determining a frequency difference based on a difference between the transaction frequency and the frequency mean; A frequency ratio is determined based on a ratio of the frequency difference to the frequency standard deviation.
9. The method according to claim 2, characterized in that The first reference value includes a transaction quantity reference value and a transaction amount reference value determined based on the transaction information and transaction number corresponding to the first transaction order, the transaction information includes the transaction quantity and transaction amount, and the first anomaly score includes a transaction volume anomaly score and a transaction amount anomaly score. The first anomaly score for characterizing the degree of anomaly of the transaction indicator of the order is determined by: Determining a transaction volume anomaly score based on the transaction volume and the transaction volume reference value; A transaction amount abnormality score is determined based on the transaction amount and the transaction amount reference value.
10. The method according to claim 1, characterized in that The method further comprises: Acquire multiple historical transaction orders corresponding to the target virtual item, and determine abnormal orders among the multiple historical transaction orders based on the abnormality level of each historical transaction order; Based on the abnormality degree and transaction information of the abnormal order, the transaction health of the target virtual item is determined.
11. The method according to claim 10, characterized in that The transaction information includes the transaction quantity, and the transaction health includes the transaction volume health. The transaction volume health of the target virtual item is determined by: Determining the transaction quantity of the abnormal order at different abnormality levels and the total transaction quantity of the target virtual item in the multiple historical transaction orders; The transaction volume healthiness is determined based on the ratio of the sum of the weights of the transaction quantities at different abnormality levels to the total number of transactions.
12. The method according to claim 10, characterized in that The transaction information includes the transaction amount, and the transaction health includes the transaction amount health. The transaction amount health of the target virtual item is determined by: Determining the total transaction amount of the abnormal order and the total transaction amount of the multiple historical transaction orders; The transaction amount healthiness is determined based on a ratio of the square of the total transaction amount of the abnormal order to the square of the total transaction amount of the multiple historical transaction orders.
13. The method according to claim 1, wherein The method further comprises: Constructing an abnormal order evaluation model, wherein the input of the abnormal order evaluation model is the order information of the transaction order to be evaluated, and the output of the abnormal order evaluation model is the degree of abnormality; The abnormal order evaluation model determines the degree of abnormality in the following way: Determining, based on order information of the transaction order to be evaluated, a first reference value for measuring a degree of abnormality in the transaction of the target virtual item and a second reference value for measuring a degree of abnormality in the transaction of the virtual character involved in the transaction, wherein the order information includes transaction information of the target virtual item; Determining, based on the transaction information and the first reference value, a first anomaly score for characterizing the degree of anomaly in the transaction of the target virtual item; Determining, based on the transaction behavior data of the virtual character participating in the transaction and the second reference value, a second abnormality score for characterizing a degree of abnormality in the transaction of the virtual character; The abnormality degree of the transaction order to be evaluated is determined based on the first abnormality score and the second abnormality score.
14. A data monitoring device in a game, characterized in that: include: a reference value determination module, configured to obtain a transaction order to be evaluated for a target virtual item in a specified type of transaction, and determine, based on order information of the transaction order to be evaluated, a first reference value for measuring a degree of abnormality in the transaction of the target virtual item and a second reference value for measuring a degree of abnormality in the transaction of the virtual character, wherein the order information includes transaction information of the target virtual item; a first scoring module, configured to determine, based on the transaction information and the first reference value, a first anomaly score for characterizing the degree of anomaly in the transaction of the target virtual item; a second scoring module, configured to determine, based on the transaction behavior data of the virtual character participating in the transaction and the second reference value, a second anomaly score for characterizing a degree of transaction anomaly of the virtual character; An abnormality evaluation module is used to determine the abnormality level of the transaction order to be evaluated based on the first abnormality score and the second abnormality score.
15. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate via the bus, and the processor executes the machine-readable instructions to perform the steps of the data monitoring method in the game as described in any one of claims 1 to 13.
16. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, performs the steps of the data monitoring method in a game according to any one of claims 1 to 13.