Malicious behavior identification method and device for Internet platform
By generating strategies and performing factor analysis and score calculation on an internet platform, malicious behavior can be dynamically identified and dealt with, solving the problem that existing technologies cannot respond to new attack patterns in real time, and achieving the effect of real-time response and efficient prevention of malicious behavior.
Patent Information
- Application Number
- CN202511111898.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-07
AI Technical Summary
Existing internet platforms are unable to respond to new attack patterns in real time when preventing malicious behavior, and policy updates require manual intervention or system shutdown for maintenance.
By obtaining behavior recognition requests from internet platforms, generating strategies based on event tracking information in business logic, parsing factors and calculating sub-scores, determining the total strategy score by combining factor weights, dynamically configuring strategy logic and thresholds, and identifying and handling malicious behavior in real time.
It enables real-time response and dynamic adaptation to malicious behavior, reduces the need for manual intervention, improves the real-time performance and accuracy of the system, and prevents malicious attacks on the platform.
Smart Images

Figure CN120915536A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information processing, in particular to a malicious behavior identification method and device for an Internet platform. BACKGROUND
[0002] Online platforms such as e-commerce, logistics, and finance cannot respond to new attack modes (such as second dial IP and automated scripts) in real time when preventing malicious behavior because they rely on fixed prevention methods, and policy updates require manual intervention or system downtime maintenance. SUMMARY
[0003] The main purpose of the present application is to provide a malicious behavior identification method and device for an Internet platform to solve the problems in the related art.
[0004] In order to achieve the above purpose, according to the first aspect of the present application, a malicious behavior identification method for an Internet platform is provided, which includes obtaining a behavior identification request from an Internet platform, wherein the behavior identification request is generated based on event embedding information in business logic; querying a strategy corresponding to the request from a strategy list; and analyzing the strategy to obtain the included factors; according to the type of the factor, different execution engines are called to calculate the sub-score according to the mode indicated by each factor, and the total score of the strategy is determined based on the calculated sub-score and the weight of each factor; based on the total score of the strategy and the threshold value associated with the strategy, it is determined whether the behavior corresponding to the event this time exists risk; if there is risk, the disposal mode associated with the strategy is executed.
[0005] Optionally, before querying the strategy corresponding to the request from the strategy list, the method further comprises defining factors, wherein the factors are obtained based on different business scenarios; dynamically configuring strategy logic using a rule engine to obtain multiple strategies, wherein the strategy logic is obtained based on the defined factor combination; associating the configured threshold value with the configured strategy, and associating the configured disposal mode.
[0006] Optionally, the method further comprises collecting multi-dimensional data, including: collecting hardware parameters of a login device from an Internet platform, and generating a unique identifier of the login device based on the hardware parameters; associating the user operation behavior information corresponding to the device with the unique identifier; and structuring data generated after the login account of the login device into a user portrait, wherein the data includes user information, account usage behavior data, and business behavior data.
[0007] Optionally, if there is risk, the disposal mode associated with the strategy is executed, including: based on the unique identifier, adding the device to a blacklist, and sending the hardware parameters corresponding to the unique identifier to a gateway for interception.
[0008] Optionally, when the time limit of being blacklisted reaches a preset value, it is re-judged whether the behavior corresponding to the event is risky; if not, the blacklist restriction is removed.
[0009] Optionally, the method further comprises adjusting the weights of the factors and the threshold associated with the strategy, wherein, when adjusting, real-time data sources are obtained from the Internet platform, and the adjustment is based on the behavior logs of the logged-in user in the real-time data sources and the records determined to be risky
[0010] According to the second aspect of the present application, an apparatus for identifying malicious behavior on an Internet platform is provided, comprising a request obtaining unit configured to obtain a behavior identification request from the Internet platform, wherein the behavior identification request is generated based on event tracking information in business logic; a processing unit configured to query a strategy corresponding to the request from a strategy list, and to parse the strategy to obtain included factors; to call different execution engines according to the types of the factors to perform sub-score calculation in the manners indicated by the factors, and to determine a total score of the strategy based on the calculated sub-scores and the weights of the factors; and an identification unit configured to determine whether the behavior corresponding to the event is risky based on the total score of the strategy and a threshold associated with the strategy; and if so, to execute a handling manner associated with the strategy.
[0011] According to the third aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for causing a computer to execute the method of any one of the first aspect.
[0012] According to the fourth aspect of the present application, an electronic device is provided, comprising at least one processor, and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to cause the at least one processor to execute the method of any one of the implementation manners of the first aspect.
[0013] According to the fifth aspect of the present application, a computer program product is provided, which, when executed by a processor, implements the method of any one of the implementation manners of the first aspect.
[0014] The embodiment is directed to an internet platform malicious behavior identification method and device, wherein the method comprises: obtaining a behavior identification request from an internet platform, wherein the behavior identification request is generated based on event embedding information in business logic; querying a strategy list to obtain a strategy corresponding to the request; and analyzing the strategy to obtain included factors; calling different execution engines according to the types of the factors to perform sub-score calculation in the manner indicated by each factor, and determining a total score of the strategy based on the calculated sub-scores and the weights of each factor; determining whether the behavior corresponding to the current event is at risk based on the total score of the strategy and the threshold value associated with the strategy; and if there is a risk, executing the disposal mode associated with the strategy. By configuring the strategy in a configurable manner, different risk behavior identification scenarios can be dynamically adapted, and the defects that fixed paradigms cannot respond to new attack modes in real time and strategy updates require manual intervention or system downtime maintenance are solved. BRIEF DESCRIPTION OF DRAWINGS
[0015] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the description of the specific embodiments or the prior art. Obviously, the drawings described below are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0016] Figure 1 It is a flowchart of the malicious behavior identification method of the internet platform according to the embodiment of the present application.
[0017] Figure 2 It is a schematic diagram of an electronic device according to the embodiment of the present application. DETAILED DESCRIPTION
[0018] In order to make the person skilled in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.
[0019] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and in the above drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0020] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.
[0021] According to an embodiment of the present application, a malicious behavior identification method for an Internet platform is provided, as shown in the figure, comprising the following steps 101 to 103: Figure 1
[0022] Step 101: Obtain a behavior identification request from the Internet platform, wherein the behavior identification request is generated based on event embedding information in business logic.
[0023] In this step, the user generates an identification request through a unified event parameter in the business logic corresponding to the event embedding, and sends the identification request to the server. The event parameter contains user information and embedding identification, which is a request parameter used to calculate the current score, and is understood as a parameter of the current real-time scene. The strategy calculation input is the event.
[0024] Step 102: Query the strategy corresponding to the request from the strategy list; and parse the strategy to obtain the included factors; according to the type of the factors, call different execution engines to calculate the sub-score according to the mode indicated by each factor, and determine the total score of the strategy based on the calculated sub-score and the weight of each factor.
[0025] In this step, when the request is received, the corresponding strategy associated with the event embedding information is queried from the strategy list. During the execution of the strategy, the factors used in the strategy are first parsed, and different factor execution engines are used for processing according to different factor types, such as sql query, druid data source query, three-party interface call, and business interface logic processing. For various sources and processing methods, the numerical results are finally returned uniformly, and the final strategy score is calculated through the numerical values of each factor according to the strategy logic.
[0026] In the calculation of the factor, the data source for calculating the factor calculation dependency is obtained, and multiple data source types can be flexibly extended by using mysql, a third-party function, apache druid. Fusion SQL query, real-time stream calculation (Apache Druid), third-party API call, flexible extension of data source, support for real-time aggregation of complex risk indicators (such as "same device login frequency"). Improve the efficiency and accuracy of the calculation, and meet the millisecond-level response demand of high-concurrency scenarios.
[0027] Step 103: determining whether the behavior corresponding to the event exists risk based on the policy total score and the threshold value associated with the policy; if there is risk, executing the disposal mode associated with the policy.
[0028] In this step, whether the policy hits is determined according to the corresponding scene policy, comparing the policy score with the configured threshold value. If the threshold value is exceeded, it is determined that the policy is hit, otherwise the policy is not hit. If the policy is not hit, the request is risk-free and the business logic of the request is continued. If the policy is hit, it means that the operation exists risk, according to the disposal mode configured by the policy, interrupting the subsequent behavior of the request, or performing the blacklisting operation on the user, the user will not be able to log in and continue to use the system function in the future.
[0029] As an optional implementation manner of the embodiment, before querying the policy corresponding to the request from the policy list, the method further comprises: defining factors, wherein the factors are obtained based on different business scenarios; obtaining multiple policies by using a rule engine to dynamically configure policy logic, wherein the policy logic is obtained based on the defined factors; associating the configured policy with the configured threshold value, and associating the configured disposal mode.
[0030] In the optional implementation manner, the factor is the smallest calculation unit of the policy, and a calculation factor can be an independent calculation logic such as a complete SQL expression. In principle, it is generally an aggregated calculation result, and can also return a direct result. The factor can also be a third-party API call, which is diversified. The index is shared, and different policies can refer to the same factor.
[0031] The strategy can be configured by a person in a visual configuration interface, and is a model encapsulation of risk judgment provided by the system to the outside. Different business scenarios need to call different strategy scenarios. For example, a single grabbing scenario involves factors including whether the driver and the consignor mobile phone numbers are consistent, the total number of orders completed by the driver, the proportion of orders of the current enterprise carried by the driver, the proportion of orders of the current consignor carried by the driver, whether the driver and the consignor login devices are the same, whether the order contact is the same as the driver mobile phone number, etc. The above factors are combined together through logical operation, and the threshold value and the score of the factor calculation result are set respectively. If the threshold value is exceeded, the score will be added up. Finally, the above score calculation logic is combined together through a groovy script, and the threshold value of the strategy score is set to form an executable strategy in the system. If the cumulative score exceeds the threshold value of the strategy, the risk control is hit. The above strategy prevents drivers and consignors from colluding to place false orders and infringe on the interests of the platform.
[0032] The embodiment can adapt to dynamic scenarios by adjusting and combining factors.
[0033] As an optional implementation manner of the embodiment, the method further includes collecting multi-dimensional data, including: collecting hardware parameters of a login device from an Internet platform, and generating a unique identifier of the login device based on the hardware parameters; associating user operation behavior information corresponding to the device with the unique identifier; and structuring data generated after a login account of the login device into a user portrait, wherein the data includes user information, account usage behavior data, and business behavior data.
[0034] In the optional implementation manner, the multi-dimensional data collection collects a user device fingerprint. When generating the user device fingerprint, the device hardware parameters (such as IMEI and MAC address) are collected to generate a unique device id through an encryption algorithm, and the device id and the user are associated together through user operation behavior.
[0035] Collecting a user risk portrait: integrating user information (mobile phone number and ID number), account behavior data (login frequency and associated device number), business behavior (consignor order placement, driver carrying, and freight settlement), etc. to build a user risk data source.
[0036] Calculating a strategy score based on the device fingerprint, the user portrait, and event information detected through a biological probe. The groovy strategy script score is calculated. Each strategy includes multiple factor logic units. Each such unit has a corresponding score configuration. The result of each factor is calculated through multi-dimensional data, and then the score of each factor logic unit is calculated. The cumulative score is the strategy score. If the threshold value is exceeded, the disposal (such as blocking the request or blacklisting the user) is triggered.
[0037] The related art only uses a single dimension such as IP, device or account for risk judgment, and black production can bypass detection by forging a single dimension (such as changing IP). The related art lacks multi-dimensional correlation analysis (such as IP + device + behavior characteristics), resulting in a high rate of missed or misjudged defects. The introduction of IP and account risk correlation analysis (such as the number of times an account frequently switches IP) dynamically bans high-frequency switching IP accounts, breaks the passive defense mode of traditional IP detection, and actively suppresses by increasing black production resource consumption (frequent device / IP changes). During the user login process, the ip information will be brought along, if a certain ip sensitive operation exceeds the threshold, or the number of ip switching of the account exceeds the threshold, the ip and user account will be blacklisted, and the user account operation will be prohibited. This can avoid the risk of persistent attacks by the same ip and frequent ip switching of the same account, and realize the second dial IP countermeasures mechanism.
[0038] The related art relies on basic hardware parameters (such as MAC address), which are easy to tamper with or fake, and cannot accurately distinguish between real devices and virtual machines. It does not combine biological probes (such as sensor data) to generate a unique device fingerprint, and the device uniqueness verification capability is insufficient.
[0039] As an optional implementation of the present embodiment, if there is a risk, the strategy associated disposal mode is executed, including: adding the device to the blacklist based on the unique identifier, and sending the hardware parameter corresponding to the unique identifier to the gateway for interception.
[0040] As an optional implementation of the present embodiment, when the time limit for being pulled into the blacklist reaches the preset value, it is re-judged whether the event corresponding behavior has a risk; if there is no risk, the blacklist restriction is removed.
[0041] In this optional implementation, the hit strategy will configure a corresponding disposal mode, such as supporting global blacklisting, while most scenarios can be disposed by the calling party. Exemplarily, multi-dimensional blacklisting can be performed, and blacklisting can be implemented according to the combination of user ID, mobile phone number, device ID, IP, etc. and synchronized to the gateway for interception.
[0042] For blacklisting behavior, a dynamic removal mechanism is set, which will remove the blacklist after a period of time, and the user can log in to the system again, but if the user continues to have risky operations, the user will be blacklisted again. For the calculation of risk factors, the user's operations in the recent period of time are counted, such as: 10 minutes, 30 minutes, 2 hours, 4 hours, 1 day, 15 days, etc. If the user hits the strategy for a period of time without risky behavior, the user behavior calculated by the above factors will also return to normal, and will not hit the strategy again. If abnormal risky behavior occurs again, the strategy will be triggered again to prevent the user's risky behavior.
[0043] Exemplarily, in the driver order grabbing scenario, the strategy factor can be configured in advance for the scenario, including mobile phone number similarity, same device login frequency, and abnormal number of driver-cargo association. The strategy score is calculated in real time based on the strategy factor, and if the threshold is exceeded, the order grabbing request is intercepted and the account is blacklisted. In the marketing activity anti-brushing scenario, after the strategy score calculation, the out-of-place login verification (SMS verification code) can be triggered, the high-risk account is marked and the participation qualification is limited.
[0044] As an optional implementation manner of the embodiment, the method further comprises adjusting the weight of the factor and the threshold of the strategy association, wherein, when adjusting, real-time data sources are obtained from the Internet platform, and the behavior log of the logged-in user in the real-time data sources and the record of determining the existence of risks are used for adjustment.
[0045] In the optional implementation manner, the real-time data sources can include business databases, log streams, etc., and the factor weight and the strategy threshold are manually adjusted by analyzing the hit records and the user behavior log, so as to improve the strategy accuracy. For example, in the SMS verification code scenario, the abnormal acquisition verification code frequency and the hit risk control record are observed, the factor hit threshold and the score in the strategy are adjusted, and the accuracy of intercepting black production and script acquisition of SMS verification code is improved.
[0046] The embodiment can also adapt to dynamic scenarios by adjusting the threshold. The factor weight and the strategy threshold are dynamically adjusted based on log analysis, and the risk release mechanism (such as blacklisting time limit) is combined to realize the self-iterative optimization of the model. The false positive rate is reduced, the system accuracy and operation and maintenance efficiency are improved, and the need for manual intervention is reduced. When dynamically adjusting, the factor weight and the strategy threshold are manually adjusted by analyzing the hit records and the user behavior log, so as to improve the strategy accuracy. For example, in the SMS verification code scenario, the abnormal acquisition verification code frequency and the hit risk control record, and the false blacklisting of the user feedback are observed, the calculation time interval, the hit threshold and the score of the factor in the strategy are adjusted, the normal user false blacklisting is avoided, and the malicious illegal request is prevented.
[0047] The embodiment can prevent users from maliciously registering new accounts, driver-cargo association fraud, and other ways to obtain non-legitimate income from the platform; and to prevent malicious access to system interfaces, obtain system information and waste system resources, the system intercepts and blacklists the above behaviors to protect the platform business and system security.
[0048] Through real-time data analysis and device fingerprint, and a flexible strategy configuration mechanism, the malicious behavior can be effectively identified and blocked, and the real-time, accuracy and adaptability of the system are improved.
[0049] The embodiment realizes dynamic programmable policy configuration: based on rule expression analysis, to parse the rule factors configured in the policy, and the expression composed by the rule factors through logical operation. Dynamic configuration of policy logic is supported, allowing online adjustment of factor combination, threshold and handling method without downtime or code reconstruction. Further, it can adapt to new attacks (such as second dial IP) in real time, and through the "policy-factor" decoupling design, realize the rapid expansion of business scenarios (such as order grabbing→marketing anti-brushing).
[0050] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown.
[0051] According to the embodiment of the present application, a device for identifying malicious behavior of an Internet platform is also provided, comprising a request acquisition unit configured to acquire a behavior identification request from the Internet platform, wherein the behavior identification request is generated based on event tracking information in business logic; a processing unit configured to query a policy corresponding to the request from a policy list, and parse the policy to obtain included factors; according to the type of the factors, different execution engines are called to perform sub-score calculation in the manner indicated by each factor, and a total score of the policy is determined based on the calculated sub-scores and the weights of each factor; and an identification unit configured to determine whether the behavior corresponding to the event this time has risks based on the total score of the policy and the threshold value associated with the policy; if there are risks, a handling method associated with the policy is executed.
[0052] According to the embodiment of the present application, the present application also provides an electronic device, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to implement the method described in any of the above embodiments when executed.
[0053] According to the embodiment of the present application, the present application also provides a readable storage medium, which stores computer instructions for enabling a computer to implement the method described in any of the above embodiments when executed.
[0054] According to the embodiment of the present application, the present application also provides a computer program product, which can implement the method described in any of the above embodiments when executed by a processor.
[0055] Figure 2A schematic block diagram of an example electronic device 300 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices, and other similar computing devices.
[0056] As shown in Figure 2 The electronic device 300 includes a computing unit 301 that can perform various appropriate actions and processes in accordance with a computer program stored in a read-only memory (ROM) 302 or a computer program loaded into a random access memory (RAM) 303 from a storage unit 308. Various programs and data required for the operation of the electronic device 300 can also be stored in the RAM 303. The computing unit 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0057] Various components in the electronic device 300 are connected to the I / O interface 305, including an input unit 306, such as a keyboard, a mouse, and the like, an output unit 307, such as various types of displays, speakers, and the like, a storage unit 308, such as a magnetic disk, an optical disk, and the like, and a communication unit 309, such as a network card, a modem, a wireless communication transceiver, and the like. The communication unit 309 allows the electronic device 300 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0058] The computing unit 301 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 301 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, and the like. The computing unit 301 performs various methods and processes described above, such as the object matching method. For example, in some embodiments, the object matching method can be implemented as a computer software program that is tangibly embodied in a machine-readable medium, such as the storage unit 308. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 300 via the ROM 302 and / or the communication unit 309. When the computer program is loaded into the RAM 303 and executed by the computing unit 301, one or more steps of the methods described above can be performed.
[0059] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0060] Program code for carrying out methods of the present application can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces a means for implementing the functions / acts specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, or entirely on a remote machine or server.
[0061] In the context of the present application, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium will include one or more lines of electrical connections, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
Claims
1. A method for identifying malicious behavior on internet platforms, characterized in that, The method comprises: obtaining a behavior identification request from an Internet platform, wherein the behavior identification request is generated based on event embedding information in business logic; querying a strategy corresponding to the request from a strategy list; and analyzing the strategy to obtain factors contained therein; calling different execution engines according to the types of the factors to perform sub-score calculation in the manner indicated by each factor, and determining a total score of the strategy based on the calculated sub-scores and the weights of each factor; determining whether the behavior corresponding to the event this time has risks based on the total score of the strategy and the threshold value associated with the strategy; and if there are risks, executing the disposal mode associated with the strategy.
2. The method according to claim 1, wherein the malicious behavior is identified with respect to an Internet platform. Characterized in that, before querying the strategy corresponding to the request from the strategy list, the method further comprises: defining factors, wherein the factors are obtained based on different business scenarios; dynamically configuring strategy logic by using a rule engine to obtain multiple strategies, wherein the strategy logic is obtained based on the defined factor combination; associating the configured strategy with the configured threshold value, and associating the configured disposal mode. 3.The method for identifying malicious behavior against an Internet platform according to claim 1, characterized in that, The method further comprises collecting multi-dimensional data, including: collecting hardware parameters of a login device from an Internet platform, and generating a unique identifier of the login device based on the hardware parameters; and associating user operation behavior information corresponding to the device with the unique identifier; Further comprising structuring data generated after the login account of the login device into a user portrait, wherein the data includes user information, account usage behavior data, and business behavior data.
4. The method of claim 3, wherein, If there are risks, executing the disposal mode associated with the strategy includes: adding the device to a blacklist based on the unique identifier, and sending the hardware parameters corresponding to the unique identifier to a gateway for interception. 5.The method for identifying malicious behavior on an Internet platform according to claim 4, characterized in that, When the time limit for being pulled into the blacklist reaches a preset value, it is determined again whether the behavior corresponding to the event has risks; If there are no risks, the blacklist restriction is removed.
6. The method of identifying malicious behavior against an Internet platform according to claim 1, wherein, The method further comprises adjusting the weights of the factors and the threshold value associated with the strategy, wherein, during the adjustment, real-time data sources are obtained from the Internet platform, and the behavior logs of the login users in the real-time data sources and the records determined to have risks are used for adjustment.
7. A malicious behavior identification device for internet platforms, characterized in that, The method comprises a request obtaining unit configured to obtain a behavior identification request from an Internet platform, wherein the behavior identification request is generated based on event embedding information in business logic; a processing unit configured to query a strategy corresponding to the request from a strategy list; and analyze the strategy to obtain factors contained therein; call different execution engines according to the types of the factors to perform sub-score calculation in the manner indicated by each factor, and determine a total score of the strategy based on the calculated sub-scores and the weights of each factor; an identification unit configured to determine whether the behavior corresponding to the event this time has risks based on the total score of the strategy and the threshold value associated with the strategy; and if there are risks, execute the disposal mode associated with the strategy.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing the computer to execute the method of any one of claims 1-6.
9. An electronic device, comprising: The method comprises: at least one processor; and a memory connected to the at least one processor in communication; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to cause the at least one processor to perform the method of any one of claims 1-6.
10. A computer program product, characterised in that, The computer program, when executed by the processor, implements the method of any one of claims 1-6.