Risk control method, device, equipment, medium and program product

By generating risk behavior sequence templates at the application layer gateway and performing matching degree analysis on incremental traffic, the problem of insufficient risk control coverage and accuracy in existing technologies is solved, achieving more reliable risk identification and control.

CN121151145BActive Publication Date: 2026-03-27ZHEJIANG E COMMERCE BANK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-19
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing online business risk control solutions rely on a single data dimension and manually set rules and strategies, resulting in insufficient coverage and accuracy of risk control.

Method used

By generating risk behavior sequence templates based on historical traffic behavior sequences from application layer gateways, and performing matching degree analysis on incremental traffic, risk control methods are constructed. These methods include obtaining historical traffic behavior sequences from multiple confirmed risk cases, filtering high-risk call interfaces, generating risk behavior sequence templates, calculating matching degree, and performing risk control operations.

Benefits of technology

It improves the accuracy and coverage of risk control, enables the full collection of user behavior data and accurate identification of risk patterns, and enhances the reliability of risk control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151145B_ABST
    Figure CN121151145B_ABST
Patent Text Reader

Abstract

Embodiments of the present specification disclose a risk control method, device, equipment, medium and program product. The method comprises: obtaining a historical traffic behavior sequence associated with each of a plurality of confirmed risk cases based on historical application layer traffic passing through an application layer gateway; generating a risk behavior sequence template based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases; and performing risk control on incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template. The risk control method can effectively improve the accuracy and coverage of risk control, thereby effectively improving the reliability of risk control.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present specification relates to the technical field of information security, and in particular, to a risk control method, device, equipment, medium and program product. BACKGROUND

[0002] At present, the risk control of online business mainly depends on data collection triggered by security events and risk identification of preset rule strategies. In the related technology, when detecting a security event triggered by a user performing registration, login, transfer and the like, static metadata (such as user identification, device fingerprint, action type, etc.) related to the event is collected, and based on the collected static metadata and the pre-set rule strategy, it is judged whether the business subject exists risks such as account buying and selling, fraud, etc.

[0003] However, the current risk control scheme relies on a single data dimension, and the risk identification mechanism relies on artificially set rule strategies, which leads to insufficient coverage and accuracy of risk control, and a more reliable risk control method needs to be provided. SUMMARY

[0004] The embodiments of the present specification provide a risk control method, device, equipment, medium and program product, which can improve the coverage and accuracy of risk control, and further improve the reliability of risk control.

[0005] In a first aspect, the embodiments of the present specification provide a risk control method, comprising:

[0006] Based on the historical application layer traffic passing through the application layer gateway, a plurality of historical traffic behavior sequences respectively associated with a plurality of confirmed risk cases are obtained;

[0007] Based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, a risk behavior sequence template is generated;

[0008] Based on the risk behavior sequence template, incremental application layer traffic passing through the application layer gateway is controlled.

[0009] In a possible implementation manner, based on the historical application layer traffic passing through the application layer gateway, the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases are obtained, comprising:

[0010] Based on the historical application layer traffic passing through the application layer gateway, a historical traffic behavior sequence in the subject dimension is constructed;

[0011] According to the case data respectively corresponding to the plurality of confirmed risk cases, the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases are filtered out from the historical traffic behavior sequence in the subject dimension.

[0012] In a possible implementation, the case data includes a subject involved and a time stamp of the case involved;

[0013] According to the case data corresponding to each of the plurality of confirmed risk cases, a historical traffic behavior sequence associated with each of the plurality of confirmed risk cases is filtered from the historical traffic behavior sequence in the subject dimension, including:

[0014] According to the subject involved corresponding to each of the plurality of confirmed risk cases, a historical traffic behavior sequence corresponding to the subject involved of the plurality of confirmed risk cases is filtered from the historical traffic behavior sequence in the subject dimension;

[0015] According to the time stamp of the case involved corresponding to each of the plurality of confirmed risk cases, a sequence before and after the time point of the case involved is intercepted from the historical traffic behavior sequence corresponding to the subject involved of the plurality of confirmed risk cases, as the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases.

[0016] In a possible implementation, based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, a risk behavior sequence template is generated, including:

[0017] Based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence are obtained;

[0018] According to the at least one high-risk historical traffic behavior sequence, a calling sequence of the at least one high-risk calling interface is determined;

[0019] According to the calling sequence, the high-risk calling interface is combined into a risk behavior sequence template.

[0020] In a possible implementation, based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence are obtained, including:

[0021] The sequence aggregation feature corresponding to the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases is obtained;

[0022] Based on the sequence aggregation feature, at least one high-risk historical traffic behavior sequence is filtered from the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases;

[0023] The interface aggregation feature corresponding to the calling interface in the at least one high-risk historical traffic behavior sequence is obtained;

[0024] Based on the interface aggregation feature, at least one high-risk calling interface is filtered from the at least one high-risk historical traffic behavior sequence.

[0025] In a possible implementation, the sequence aggregation feature includes sequence occurrence frequency and sequence occurrence frequency; and the interface aggregation feature includes interface call frequency and interface call frequency.

[0026] Based on the sequence aggregation feature, at least one high-risk historical traffic behavior sequence is filtered from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, including:

[0027] A historical traffic behavior sequence with sequence occurrence frequency reaching a first preset frequency threshold and sequence occurrence frequency reaching a first preset frequency threshold is filtered from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases as the at least one high-risk historical traffic behavior sequence.

[0028] Based on the interface aggregation feature, at least one high-risk calling interface is filtered from the at least one high-risk historical traffic behavior sequence, including:

[0029] A calling interface with interface call frequency reaching a second preset frequency threshold and interface call frequency reaching a second preset frequency threshold is filtered from the at least one high-risk historical traffic sequence as the at least one high-risk calling interface.

[0030] In a possible implementation, before the risk control is performed on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template, the method further includes:

[0031] Based on the incremental application layer traffic passing through the application layer gateway, an incremental traffic behavior sequence of the subject dimension is constructed.

[0032] The risk control is performed on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template, including:

[0033] A matching degree between the risk behavior sequence template and the incremental traffic behavior sequence of the subject dimension corresponding to the incremental application layer traffic is calculated.

[0034] The incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold is determined as a suspicious incremental traffic behavior sequence.

[0035] The subject of the suspicious incremental traffic behavior sequence is compared and verified with the subject of the potential risk case.

[0036] The subject of the suspicious incremental traffic behavior sequence that passes the verification is subjected to a risk control operation.

[0037] In a second aspect, an embodiment of the present specification provides a risk control device, including:

[0038] The acquisition module is configured to acquire a historical traffic behavior sequence associated with each of a plurality of confirmed risk cases based on historical application layer traffic passing through the application layer gateway.

[0039] The generation module is configured to generate a risk behavior sequence template based on the historical traffic behavior sequences associated with the plurality of confirmed risk cases.

[0040] The control module is configured to perform risk control on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template.

[0041] In a third aspect, an electronic device is provided, including a processor and a memory. The memory stores a computer program, and the computer program is executed by the processor to implement the method steps provided in the first aspect of the embodiments of the present specification.

[0042] In a fourth aspect, a computer storage medium is provided, which stores a plurality of instructions. The instructions are adapted to be loaded by a processor and executed to implement the method steps provided in the first aspect of the embodiments of the present specification.

[0043] In a fifth aspect, a computer program product is provided, including a computer program. The computer program is executed by a processor to implement the method steps provided in the first aspect of the embodiments of the present specification.

[0044] The risk control method, device, equipment, medium and program product described above, in the offline analysis stage, based on the historical application layer traffic passing through the application layer gateway, acquire the historical traffic behavior sequences associated with each of a plurality of confirmed risk cases, and based on the historical traffic behavior sequences associated with each of the plurality of confirmed risk cases, generate a risk behavior sequence template, which helps to trace the complete behavior trajectory of the user before and after the occurrence of the plurality of confirmed risk cases, thereby more accurately identifying the risk pattern and improving the accuracy of risk control; in the online processing stage, based on the risk behavior sequence template, the incremental application layer traffic passing through the application layer gateway is controlled, which helps to obtain the full behavior data of the user from the incremental application layer traffic from the traffic entrance, thereby improving the coverage of risk control. The entire risk control process is based on the application layer traffic collected by the point embedding on the application layer gateway, realizes the construction of the black sample template and the online risk decision, effectively improves the accuracy and coverage of risk control, and further improves the reliability of risk control. BRIEF DESCRIPTION OF DRAWINGS

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present specification, the drawings required to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description only constitute some embodiments of the present specification, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0046] Figure 1 An application environment schematic diagram of a risk control method provided by an exemplary embodiment of the present specification is shown in the figure.

[0047] Figure 2 A flowchart of a risk control method provided by an exemplary embodiment of the present specification is shown in the figure.

[0048] Figure 3 A flowchart of another risk control method provided by an exemplary embodiment of the present specification is shown in the figure.

[0049] Figure 4 A flowchart of still another risk control method provided by an exemplary embodiment of the present specification is shown in the figure.

[0050] Figure 5 A structural schematic diagram of a risk control device provided by an exemplary embodiment of the present specification is shown in the figure.

[0051] Figure 6 A structural schematic diagram of an electronic device provided by an exemplary embodiment of the present specification is shown in the figure. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical solutions and advantages of the present specification more clear and explicit, the present specification will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present specification, and cannot be used to limit the present specification.

[0053] In the description of the present specification, it should be understood that the terms "first", "second" and the like are only for the purpose of description, and cannot be understood as indicating or implying relative importance. For those skilled in the art, the specific meanings of the above terms in the present specification can be understood according to the specific circumstances. In addition, in the description of the present specification, unless otherwise specified, "multiple" means two or more. "And / or", the association relationship between the associated objects, means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone. The character " / " generally represents that the associated objects before and after are in an "or" relationship.

[0054] The risk control method provided by the embodiments of the present specification can be applied to, for example, Figure 1The application environment shown. Among them, the terminal 10 communicates with the server 20 through the network. The data storage system can store the data required by the server 20 to process. The data storage system can be integrated on the server 20, or placed on the cloud or other network servers.

[0055] In some possible implementations, the risk control personnel can initiate an offline analysis instruction to the server 20 through the terminal 10. The server 20 responds to the offline analysis instruction, obtains a plurality of historical traffic behavior sequences respectively associated with a plurality of confirmed risk cases based on historical application layer traffic passing through the application layer gateway; based on the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, generates a risk behavior sequence template, and sends the risk behavior sequence template to the terminal 10, so that the terminal 10 displays the risk behavior sequence template for the risk control personnel to confirm. After confirming the template generated by the server 20, the risk control personnel can also initiate an online processing instruction to the server 20 through the terminal 10, triggering the server 20 to perform risk control on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template.

[0056] It is worth noting that the above process of triggering the server 20 to complete risk control by the terminal 10 is only described as an optional implementation, and in actual application, the offline analysis process and the online processing process in the above risk control scheme can also be automatically and periodically executed by the server 20 according to a preset strategy, and the embodiments of the present application do not limit this.

[0057] It can be understood that the terminal 10 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The server 20 can be implemented by an independent server or a server cluster composed of multiple servers.

[0058] In one embodiment, as Figure 2 shown, a risk control method is provided, and the method is applied to the server 20 in Figure 1 for example, and includes the following steps:

[0059] S202: Based on historical application layer traffic passing through the application layer gateway, a plurality of historical traffic behavior sequences respectively associated with a plurality of confirmed risk cases are obtained.

[0060] Among them, the application layer gateway is a software and hardware facility for processing application layer protocols in network communication, which is used as a unified entrance of business traffic, and is used for parsing, forwarding and processing application layer traffic such as HTTP and HTTPS. The historical application layer traffic is the seven-layer network traffic passing through the above-mentioned application layer gateway in a preset historical time period. The plurality of confirmed risk cases are the reported risk cases obtained by the server 20 from the data storage system.

[0061] Optionally, a collection agent is deployed at the application layer gateway of the business system to collect the traffic passing through the application layer gateway. The collection agent has traffic mirroring capability and is configured to receive the application layer traffic mirrored by the application layer gateway and forward the application layer traffic to the server 20 for processing. The server 20 receives the application layer traffic sent by the collection agent, obtains historical application layer traffic passing through the application layer gateway in a first preset time period from the application layer traffic, and obtains case data corresponding to each of a plurality of confirmed risk cases with timestamps in a second preset time period from the data storage system. Then, based on the case data and the historical application layer traffic, the server 20 obtains a historical traffic behavior sequence associated with each of the plurality of confirmed risk cases.

[0062] It can be understood that the case data corresponding to each of the plurality of confirmed risk cases includes, but is not limited to, a subject identifier (such as a user account involved, a device number involved) corresponding to each of the plurality of confirmed risk cases, a bank card number involved, a case, a timestamp involved, and the like. The start time of the first preset time period is earlier than the start time of the second preset time period, and the end time of the first preset time period is later than the end time of the second preset time period, so as to ensure that the application layer traffic passing through the application layer gateway before and after the plurality of confirmed risk cases can be used to trace back the complete behavior track of the user before and after the case, so as to more accurately identify the risk pattern in the subsequent process.

[0063] S204: generating a risk behavior sequence template based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases.

[0064] The risk behavior sequence template is a template for abstracting common business risk behaviors obtained by analyzing and refining the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases. The risk behavior sequence template includes a plurality of high-risk calling interfaces arranged in a specific calling order, which is used to represent a typical operation path for completing a certain type of risk activity.

[0065] Optionally, the server 20 first screens at least one high-risk historical traffic behavior sequence from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases according to the sequence aggregation features corresponding to the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; then screens at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence according to the interface aggregation features corresponding to the calling interfaces in the at least one high-risk historical traffic behavior sequence; then determines the calling sequence of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence; and finally combines the high-risk calling interfaces into a risk behavior sequence template in the interface dimension according to the calling sequence. Exemplarily, the risk behavior sequence template is an ordered list composed of risk interface identifiers, for example, it can be [risk interface A, risk interface A, risk interface A, risk interface B, risk interface B, risk interface C,...].

[0066] In the embodiment, in the offline analysis stage, the server obtains the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases based on the historical application layer traffic passing through the application layer gateway, and generates the risk behavior sequence template based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, which helps to trace the complete behavior track of the user before and after the occurrence of the plurality of confirmed risk cases, thereby more accurately identifying the risk pattern and improving the accuracy of risk control.

[0067] S206: performing risk control on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template.

[0068] Optionally, the server 20 calculates the matching degree between the risk behavior sequence template and the incremental traffic behavior sequence corresponding to the incremental application layer traffic passing through the application layer gateway in a preset time period, determines the incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold as a suspicious incremental traffic behavior sequence, and thereby performs risk control on the incremental application layer traffic passing through the application layer gateway.

[0069] The preset time period is a processing period set by a person, for example, it can be set to 1 hour, and can also be adjusted according to actual needs, for example, to half an hour, 2 hours, etc. The smaller the preset time period is set, the higher the processing frequency of the incremental application layer traffic is, and the stronger the timeliness of risk control is. However, if the preset time period is set too small, the data processing amount of the server 20 in implementing online risk control will be too large, and thereby the computing resources and computing cost consumed by the server 20 in implementing business risk control will be high.

[0070] In the embodiment, in the online processing stage, the server performs risk control on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template, which helps to obtain complete behavior data of the user from the incremental application layer traffic from the traffic entrance, and improves the coverage of risk control.

[0071] In the above risk control method, in the offline analysis stage, the server obtains historical traffic behavior sequences respectively associated with a plurality of confirmed risk cases based on historical application layer traffic passing through the application layer gateway, and generates a risk behavior sequence template based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, which helps to trace the complete behavior track of the user before and after the plurality of confirmed risk cases, thereby more accurately identifying the risk pattern and improving the accuracy of risk control; in the online processing stage, the server performs risk control on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template, which helps to obtain complete behavior data of the user from the incremental application layer traffic from the traffic entrance, and improves the coverage of risk control. The entire risk control process is based on the application layer traffic collected by the application layer gateway, realizes the construction of the black sample template and the online risk decision, effectively improves the accuracy and coverage of risk control, and further improves the reliability of risk control.

[0072] In one embodiment, as shown in Figure 3 , another risk control method is provided, which is applied to the server 20 in Figure 1 as an example, including the following steps:

[0073] S302: Construct a historical traffic behavior sequence of a subject dimension based on historical application layer traffic passing through the application layer gateway.

[0074] The historical traffic behavior sequence of the subject dimension can be, but is not limited to, a historical traffic behavior sequence of a user account dimension, a historical traffic behavior sequence of a device number dimension, etc. The following takes the historical traffic behavior sequence of the subject dimension as the historical traffic behavior sequence of the user account dimension as an example for description.

[0075] Optionally, the server 20 receives the application layer traffic sent by the collection probe deployed at the application layer gateway, parses and cleans the application layer traffic, obtains historical application layer traffic passing through the application layer gateway in a first preset time period, and then constructs a historical traffic behavior sequence of a user account dimension based on the historical application layer traffic. It can be understood that the historical traffic behavior sequence of the user account dimension is structured data sequence formed by arranging and aggregating all application layer network access behaviors generated by the user in the first preset time period in chronological order, with the user account as the unique identifier. Specifically, the server 20 extracts the user account, timestamp, and calling interface from the historical application layer traffic passing through the application layer gateway in the first preset time period, aggregates them with the user account as the primary key, and sorts all behaviors of the user according to the timestamp, to finally form the historical traffic behavior sequence of the user account dimension.

[0076] S304: According to the case data corresponding to each of the plurality of confirmed risk cases, a historical traffic behavior sequence associated with each of the plurality of confirmed risk cases is selected from the historical traffic behavior sequence of the subject dimension.

[0077] Optionally, the server 20 obtains, from the data storage system, case data corresponding to each of the plurality of confirmed risk cases within a second preset time period; wherein the start time of the second preset time period is later than the start time of the first preset time period, and the end time of the second preset time period is earlier than the end time of the first preset time period. Then the server 20 selects, from the historical traffic behavior sequence of the subject dimension, a historical traffic behavior sequence associated with each of the plurality of confirmed risk cases according to the subject identifier and the case time stamp corresponding to each of the plurality of confirmed risk cases.

[0078] In this embodiment, the server 20 constructs the historical traffic behavior sequence of the subject dimension based on the historical application layer traffic passing through the application layer gateway, which can collect full behavior data of the user at the traffic entrance; according to the case data corresponding to each of the plurality of confirmed risk cases, a historical traffic behavior sequence associated with each of the plurality of confirmed risk cases is selected from the historical traffic behavior sequence of the subject dimension, which helps to discover potential risk behavior patterns and improves the accuracy of risk control.

[0079] S306: Based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence are obtained.

[0080] Optionally, the server 20 analyzes the aggregated features of the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases according to the case types of the confirmed risk cases, and obtains at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence according to the aggregated features of the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases.

[0081] In one embodiment, the obtaining of the at least one high-risk historical traffic behavior sequence and the at least one high-risk calling interface in the high-risk historical traffic behavior sequence based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases comprises: obtaining sequence aggregated features corresponding to the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; screening at least one high-risk historical traffic behavior sequence from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases based on the sequence aggregated features; obtaining interface aggregated features corresponding to the calling interfaces in the at least one high-risk historical traffic behavior sequence; and screening at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence based on the interface aggregated features.

[0082] In one embodiment, the sequence aggregated features comprise sequence occurrence frequency and sequence occurrence frequency, and the interface aggregated features comprise interface calling frequency and interface calling frequency. Optionally, the server 20 obtains the sequence occurrence frequency and the sequence occurrence frequency corresponding to the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, and screens sequences with higher sequence occurrence frequency and sequence occurrence frequency from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases as the at least one high-risk historical traffic behavior sequence. Then the server 20 obtains the interface calling frequency and the interface calling frequency corresponding to the calling interfaces in the at least one high-risk historical traffic behavior sequence, and screens interfaces with higher interface calling frequency and interface calling frequency from the calling interfaces of the high-risk historical traffic behavior sequences as the at least one high-risk calling interface.

[0083] In this embodiment, the server screens at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface from the historical traffic behavior sequences by analyzing the sequence aggregated features corresponding to the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, which helps to subsequently construct a risk behavior sequence template according to the at least one high-risk historical traffic behavior sequence and the at least one high-risk calling interface, so as to mine potential risk behavior patterns and improve the accuracy of risk control.

[0084] S308: Determine the calling order of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence.

[0085] It can be understood that a plurality of interface identifiers arranged in the calling order are included in the high-risk historical traffic behavior sequence, and the server 20 determines the calling order of each group of high-risk calling interfaces corresponding to each high-risk historical traffic behavior sequence according to the calling order of the interface identifiers in each high-risk historical traffic behavior sequence.

[0086] S310: Combine the high-risk calling interfaces into a risk behavior sequence template according to the calling order.

[0087] Optionally, the server 20 combines at least one high-risk calling interface into each risk behavior sequence template according to the calling order of each group of high-risk calling interfaces, which can be, for example, [risk interface A, risk interface A, risk interface A, risk interface B, risk interface B, risk interface C,...].

[0088] In this embodiment, the server obtains at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, and combines each risk behavior sequence template from the at least one high-risk historical traffic behavior sequence and the at least one high-risk calling interface, which can effectively mine potential risk behavior patterns and improve the accuracy of risk control.

[0089] S312: Construct a subject dimension incremental traffic behavior sequence based on the incremental application layer traffic passing through the application layer gateway.

[0090] The subject dimension incremental traffic behavior sequence can be, but is not limited to, a user account dimension incremental traffic behavior sequence, a device number dimension incremental traffic behavior sequence, etc. The following will be described taking the subject dimension incremental traffic behavior sequence as an example.

[0091] Optionally, the server 20 periodically analyzes and cleanses the incremental application layer traffic passing through the application layer gateway in a preset time period to construct the user account dimension incremental traffic behavior sequence. It can be understood that the user account dimension incremental traffic behavior sequence is a structured data sequence formed by arranging and aggregating all application layer network access behaviors of a user in a preset time window in chronological order, taking the user account as the unique identifier. Specifically, the server 20 extracts the user account, timestamp, calling interface and other key fields from the incremental application layer traffic passing through the application layer gateway in the preset time window, then aggregates them by taking the user account as the primary key, and sorts all behaviors of the user according to the timestamp, and finally forms the user account dimension incremental traffic behavior sequence.

[0092] S314: Calculate the matching degree between the risk behavior sequence template and the subject dimension incremental traffic behavior sequence corresponding to the incremental application layer traffic.

[0093] Optionally, the server 20 calculates the matching degree between the risk behavior sequence template and the incremental application layer traffic corresponding to the subject dimension of the incremental traffic behavior sequence according to the longest common subsequence between the risk behavior sequence template and the incremental traffic behavior sequence of the subject dimension (such as the user account dimension). Specifically, the server 20 determines the matching degree between the two based on the ratio of the length of the longest common subsequence to the length of the risk behavior sequence template.

[0094] For example, the risk behavior sequence template is [risk interface A, risk interface A, risk interface B], and the incremental traffic behavior sequence of the subject dimension is [risk interface A, risk interface X, risk interface A, risk interface Y, risk interface B, risk interface Z]. At this time, the longest common subsequence between the risk behavior sequence template and the incremental traffic behavior sequence of the subject dimension is [risk interface A, risk interface A, risk interface B], the length of the risk behavior sequence template is 3, and the matching degree between the risk behavior sequence template and the incremental application layer traffic corresponding to the subject dimension of the incremental traffic behavior sequence is 100%.

[0095] In this embodiment, the server 20 calculates the matching degree between the risk behavior sequence template and the incremental traffic behavior sequence of the subject dimension by determining the longest common subsequence between the two, which can effectively exclude general call interfaces in the incremental traffic behavior sequence and only focus on the frequency and order of high-risk call interfaces, effectively improving the accuracy and rationality of the matching calculation, and further improving the accuracy of risk control.

[0096] S316: Determine the incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold as a suspicious incremental traffic behavior sequence.

[0097] The preset matching degree threshold is a pre-set similarity threshold, which can be set to 90%, for example, and can also be adjusted according to actual needs, such as 80%, 100%, etc. The higher the matching degree threshold is set, the higher the similarity between the suspicious incremental traffic behavior sequence and the risk behavior sequence template is, but at the same time, the fault tolerance is weaker. Optionally, the server 20 determines the incremental traffic behavior sequence with a matching degree reaching 90% as a suspicious incremental traffic behavior sequence.

[0098] S318: Compare and verify the subject of the suspicious incremental traffic behavior sequence with the subject of a potential risk case.

[0099] The potential risk case is a case that is identified as having risks based on pre-set rule strategies, but has not been reported yet.

[0100] Optionally, the server 20 collects multi-dimensional metadata of the device and behavior of the user during registration, login, and transfer based on the active card points of the security event, and identifies the risk level of the case based on the pre-set rule strategy, such as whether the number of login failures of a user exceeds the pre-set threshold, whether the transfer frequency of the user exceeds the pre-set frequency threshold, and the like. The case with a risk level exceeding the pre-set level threshold and not reported is regarded as a potential risk case. The subject identification (such as the user account, the device number, the bank card number, the case, the time stamp, and the like) of the potential risk case is stored in the data storage system. After determining the suspicious incremental traffic behavior sequence in the incremental application layer traffic, the subject of the suspicious incremental traffic behavior sequence is compared and verified with the subject of the potential risk case, so as to determine whether the suspicious incremental traffic behavior sequence is accurate. Specifically, when the server 20 determines that the subject of any suspicious incremental traffic behavior sequence does not belong to the subjects corresponding to the plurality of potential risk cases in the data storage system, it is determined that the verification result of the any suspicious incremental traffic behavior sequence is not passed. When the server 20 determines that the subject of any suspicious incremental traffic behavior sequence belongs to the subjects corresponding to the plurality of potential risk cases in the data storage system, it is determined that the verification result of the any suspicious incremental traffic behavior sequence is passed.

[0101] S320: performing a risk control operation on the subject of the suspicious incremental traffic behavior sequence that passes the verification.

[0102] Optionally, the server 20 performs a risk control operation on the subject of the suspicious incremental traffic behavior sequence that passes the verification, and reports the risk information to the data storage system. Specifically, the risk control operation performed by the server 20 on the subject of the suspicious incremental traffic behavior sequence that passes the verification includes but is not limited to controlling the use permission of the user account of the subject, controlling the transfer limit of the bank card of the subject, and sending a security warning information to the subject.

[0103] In this embodiment, the server 20 constructs the subject-dimension incremental traffic behavior sequence based on the incremental application layer traffic from the traffic entrance, calculates the matching degree between the incremental traffic behavior sequence and the risk behavior sequence template, effectively quantifies the risk degree of the user behavior, and improves the comprehensiveness and accuracy of the risk control. By comparing and verifying the suspicious subject with the potential risk case, a risk case review link is added based on the suspicious incremental traffic behavior sequence, which effectively improves the reliability of the risk control. By performing a risk control operation on the subject that passes the verification, an automatic closed loop from risk identification to risk disposal is formed, and the reliability of the risk control is effectively improved throughout the process.

[0104] In the risk control method, in the offline analysis stage, the server constructs a historical traffic behavior sequence of a subject dimension based on historical application layer traffic passing through the application layer gateway, screens historical traffic behavior sequences respectively associated with a plurality of confirmed risk cases from the historical traffic behavior sequence of the subject dimension according to case data respectively corresponding to the plurality of confirmed risk cases, obtains at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, determines a calling sequence of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence, and combines the high-risk calling interfaces into a risk behavior sequence template according to the calling sequence. The risk control method can mine potential risk behavior patterns according to full behavior data of a user at a traffic entrance, and improves the accuracy of risk control. In the online processing stage, the server constructs an incremental traffic behavior sequence of a subject dimension based on incremental application layer traffic passing through the application layer gateway, calculates a matching degree between the risk behavior sequence template and the incremental traffic behavior sequence of the subject dimension corresponding to the incremental application layer traffic, and determines an incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold as a suspicious incremental traffic behavior sequence. The risk control method can effectively quantify the risk degree of user behavior based on the incremental application layer traffic from the traffic entrance and the risk behavior sequence template, and improves the coverage and accuracy of risk control. The risk control method effectively improves the accuracy and coverage of risk control, and further improves the reliability of risk control.

[0105] In one embodiment, as shown in FIG. 1, Figure 4 Another risk control method is provided, which is applied to the server 20 in FIG. 1 as an example and includes the following steps. Figure 1

[0106] S402: Construct a historical traffic behavior sequence of a subject dimension based on historical application layer traffic passing through the application layer gateway.

[0107] The historical traffic behavior sequence of the subject dimension can be, but is not limited to, a historical traffic behavior sequence of a user account dimension, a historical traffic behavior sequence of a device number dimension, etc.

[0108] Specifically, S402 is consistent with S302, which will not be described here.

[0109] S404: Screen historical traffic behavior sequences corresponding to involved subjects of a plurality of confirmed risk cases from the historical traffic behavior sequence of the subject dimension according to involved subject identifiers respectively corresponding to the plurality of confirmed risk cases.

[0110] ​It can be understood that the subject involved identification can be the user account involved identification, and can also be the user account involved identification. Specifically, in the case of the historical traffic behavior sequence of the subject dimension constructed in S402 being the historical traffic behavior sequence of the user account dimension, the subject involved identification is the user account involved identification; in the case of the historical traffic behavior sequence of the subject dimension constructed in S402 being the historical traffic behavior sequence of the device number dimension, the subject involved identification is the device number involved identification.

[0111] Optionally, the server 20 screens the historical traffic behavior sequence corresponding to the user account involved from the historical traffic behavior sequence of the user account dimension according to the user account involved identification corresponding to each of the multiple confirmed risk cases.

[0112] S406: According to the involved time stamp corresponding to each of the multiple confirmed risk cases, the sequence before and after the involved time point is intercepted from the historical traffic behavior sequence corresponding to the subject involved in the multiple confirmed risk cases as the historical traffic behavior sequence associated with each of the multiple confirmed risk cases.

[0113] Optionally, the server screens the sequence of the user account involved within a period of time before and after the involved time point from the historical traffic behavior sequence corresponding to the user account involved according to the involved time stamp corresponding to each of the multiple confirmed risk cases, as the historical traffic behavior sequence associated with each of the multiple confirmed risk cases.

[0114] In this embodiment, the server screens the historical traffic behavior sequence associated with each of the multiple confirmed risk cases from the historical traffic behavior sequence of the subject dimension through the subject involved and the involved time stamp corresponding to each of the multiple confirmed risk cases, which can completely capture the dynamic behavior context of the user before and after the risk case occurs, provides a reliable data basis for subsequent mining of risk behavior patterns, ensures the reliability of the generated risk behavior sequence template, and further ensures the reliability of risk control.

[0115] S408: Obtain the sequence aggregation feature corresponding to the historical traffic behavior sequence associated with each of the multiple confirmed risk cases; wherein the sequence aggregation feature includes sequence appearance frequency and sequence appearance frequency.

[0116] Optionally, the server 20 counts the sequence aggregation features corresponding to the historical traffic behavior sequences associated with the plurality of confirmed risk cases, including sequence occurrence frequency corresponding to each historical traffic behavior sequence and sequence occurrence frequency corresponding to the historical traffic behavior sequence. The sequence occurrence frequency refers to the proportion of the occurrence of a certain sequence pattern in the historical traffic behavior sequences associated with different confirmed risk cases, and the sequence occurrence frequency can be calculated by dividing the number of sequences in which the sequence pattern occurs by the total number of historical traffic behavior sequences associated with the confirmed risk cases. The sequence occurrence frequency refers to the total number of occurrences of a certain sequence pattern in all historical traffic behavior sequences associated with the confirmed risk cases, and the sequence occurrence frequency is the total number of occurrences of a certain sequence pattern.

[0117] S410: From the historical traffic behavior sequences associated with the plurality of confirmed risk cases, the historical traffic behavior sequences with sequence occurrence frequency higher than a first preset frequency threshold and sequence occurrence frequency higher than a first preset frequency threshold are selected as at least one high-risk historical traffic behavior sequence.

[0118] Optionally, the server 20 compares the occurrence frequency and occurrence frequency of each sequence pattern with the preset frequency threshold and frequency threshold, and only when a certain sequence pattern meets the conditions of occurrence frequency higher than the first preset frequency threshold and occurrence frequency higher than the first preset frequency threshold, it is determined as a high-risk historical traffic behavior sequence.

[0119] S412: Obtain the interface aggregation features corresponding to the called interfaces in the at least one high-risk historical traffic behavior sequence; wherein the interface aggregation features include interface call frequency and interface call frequency.

[0120] Optionally, the server 20 counts the interface aggregation features corresponding to the called interfaces in the at least one high-risk historical traffic behavior sequence, including the interface call frequency of each called interface in each high-risk historical traffic behavior sequence and the interface call frequency of each called interface. The interface call frequency refers to the proportion of the occurrence of a certain called interface in its corresponding high-risk historical traffic behavior sequence, and the interface call frequency can be calculated by dividing the number of occurrences of the called interface by the total number of interfaces in the corresponding high-risk historical traffic behavior sequence. The interface call frequency refers to the number of occurrences of a certain called interface in its corresponding high-risk historical traffic behavior sequence.

[0121] S414: From the at least one high-risk historical traffic sequence, the called interface with interface call frequency higher than a second preset frequency threshold and interface call frequency higher than a second preset frequency threshold is selected as at least one high-risk called interface.

[0122] Optionally, the server 20 compares the call frequency and call frequency of each calling interface in each high-risk historical traffic behavior sequence with the preset frequency threshold and frequency threshold respectively, and only when a calling interface simultaneously meets the conditions of: the occurrence frequency is higher than the second preset frequency threshold, and the occurrence frequency is higher than the second preset frequency threshold, it is determined as a high-risk calling interface.

[0123] In this embodiment, the server locks the common risk behavior sequence of the risk case by the occurrence frequency and occurrence frequency of the historical traffic behavior sequence associated with each confirmed risk case. On the basis of the screened high-risk behavior sequence, the high-risk calling interface in each high-risk behavior sequence is further screened out by the interface call frequency and interface call frequency, which is helpful to subsequent construction of a risk behavior sequence template according to the screened high-risk behavior sequence and high-risk calling interface, and effectively improves the reliability of risk control.

[0124] S416: Determine the call order of at least one high-risk calling interface according to at least one high-risk historical traffic behavior sequence.

[0125] Specifically, S416 is consistent with S308, which will not be repeated here.

[0126] S418: Combine the high-risk calling interface into a risk behavior sequence template according to the call order.

[0127] Specifically, S418 is consistent with S310, which will not be repeated here.

[0128] S420: Construct a subject dimension incremental traffic behavior sequence based on the incremental application layer traffic passing through the application layer gateway.

[0129] Specifically, S420 is consistent with S310, which will not be repeated here.

[0130] S422: Calculate the matching degree between the risk behavior sequence template and the subject dimension incremental traffic behavior sequence corresponding to the incremental application layer traffic.

[0131] Specifically, S420 is consistent with S310, which will not be repeated here.

[0132] S424: Determine the incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold as a suspicious incremental traffic behavior sequence.

[0133] Specifically, S424 is consistent with S316, which will not be repeated here.

[0134] S426: Compare and verify the subject of the suspicious incremental traffic behavior sequence with the subject of the potential risk case.

[0135] Specifically, S426 is consistent with S318, which will not be repeated here.

[0136] S428: performing a risk control operation on the subject of the suspicious incremental traffic behavior sequence that passes the verification.

[0137] Specifically, S428 is consistent with S320, which will not be repeated here.

[0138] In the above risk control method, in the offline analysis stage, the server constructs a subject-dimension historical traffic behavior sequence based on historical application layer traffic passing through the application layer gateway, screens a historical traffic behavior sequence associated with each of a plurality of confirmed risk cases from the subject-dimension historical traffic behavior sequence according to case data corresponding to each of the plurality of confirmed risk cases, obtains at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, determines a calling order of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence, and combines the high-risk calling interfaces into a risk behavior sequence template according to the calling order. The method can mine potential risk behavior patterns from the full behavior data of the user at the traffic entrance, thereby improving the accuracy of risk control. In the online processing stage, the server constructs a subject-dimension incremental traffic behavior sequence based on incremental application layer traffic passing through the application layer gateway, calculates a matching degree between the risk behavior sequence template and the subject-dimension incremental traffic behavior sequence corresponding to the incremental application layer traffic, and determines an incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold as a suspicious incremental traffic behavior sequence. The method can effectively quantify the risk degree of user behavior based on the incremental application layer traffic from the traffic entrance and the risk behavior sequence template, thereby improving the coverage and accuracy of risk control. The above method effectively improves the accuracy and coverage of risk control, thereby improving the reliability of risk control.

[0139] To specifically describe the technical solutions of the risk control method in the embodiments of the present specification, the following will use specific application examples to describe the entire processing process, which specifically includes the following steps:

[0140] First stage: offline analysis stage

[0141] 1. The server parses and cleans the application layer traffic sent by the collection probe (Agent) deployed in the application layer gateway to obtain historical application layer traffic passing through the application layer gateway in a first preset time period.

[0142] 2. The server obtains, from the data storage system, case data corresponding to each of the plurality of confirmed risk cases with timestamps within a second preset time period, including a plurality of confirmed risk cases corresponding to each of the case data, a case user account number, a case bank card number, a case, a case timestamp, etc.; wherein the starting time of the second preset time period is later than the starting time of the first preset time period, and the ending time of the second preset time period is earlier than the ending time of the first preset time period.

[0143] 3. The server obtains a plurality of historical traffic behavior sequences associated with each of the plurality of confirmed risk cases based on historical application layer traffic through the application layer gateway. The specific process is as follows:

[0144] A) The server constructs a historical traffic behavior sequence in the user account dimension based on the historical application layer traffic through the application layer gateway.

[0145] B) The server filters the historical traffic behavior sequence corresponding to the case user account number of the plurality of confirmed risk cases from the historical traffic behavior sequence in the user account dimension according to the case user account number corresponding to each of the plurality of confirmed risk cases.

[0146] C) The server extracts the sequence before and after the case time point from the historical traffic behavior sequence corresponding to the case user account number of the plurality of confirmed risk cases according to the case timestamp corresponding to each of the plurality of confirmed risk cases, as the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases.

[0147] 4. The server generates a risk behavior sequence template based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases. The specific process is as follows:

[0148] A) The server obtains sequence aggregation features corresponding to the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, including sequence appearance frequency and sequence appearance frequency.

[0149] B) The server filters the historical traffic behavior sequence with a sequence appearance frequency higher than a first preset frequency threshold and a sequence appearance frequency higher than a first preset frequency threshold from the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases, as at least one high-risk historical traffic behavior sequence.

[0150] C) The server obtains interface aggregation features corresponding to the interface call in the at least one high-risk historical traffic behavior sequence, including interface call frequency and interface call frequency.

[0151] D) The server filters the call interface with an interface call frequency higher than a second preset frequency threshold and an interface call frequency higher than a second preset frequency threshold from the at least one high-risk historical traffic sequence, as at least one high-risk call interface.

[0152] E) The server determines the calling sequence of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence.

[0153] F) The server combines the high-risk calling interfaces into a risk behavior sequence template according to the calling sequence, which can be, for example, [risk interface A, risk interface A, risk interface A, risk interface B, risk interface B, risk interface C,...].

[0154] Second stage: online processing stage

[0155] 1. The server periodically analyzes and cleanses the incremental application layer traffic passing through the application layer gateway in a preset time period, and constructs the incremental traffic behavior sequence of the user account dimension.

[0156] 2. The server obtains case data corresponding to each of the plurality of potential risk cases in the data storage system from the data storage system, including the user account involved in each of the plurality of potential risk cases.

[0157] 3. The server calculates the matching degree between the risk behavior sequence template generated in the offline analysis stage and the incremental traffic behavior sequence of the user account dimension.

[0158] 4. The server determines the incremental traffic behavior sequence that reaches the preset matching degree threshold as a suspicious incremental traffic behavior sequence.

[0159] 5. The server compares and verifies the user account corresponding to the suspicious incremental traffic behavior sequence with the user account corresponding to the potential risk case, which is specifically processed as follows:

[0160] A) After determining that the user account corresponding to any suspicious incremental traffic behavior sequence does not belong to the user accounts corresponding to the plurality of potential risk cases in the data storage system, the server determines that the verification result of the any suspicious incremental traffic behavior sequence is not verified.

[0161] B) After determining that the user account corresponding to any suspicious incremental traffic behavior sequence belongs to the user accounts corresponding to the plurality of potential risk cases in the data storage system, the server determines that the verification result of the any suspicious incremental traffic behavior sequence is verified.

[0162] 6. The server performs risk control operations on the user account corresponding to the suspicious incremental traffic behavior sequence that passes the verification, such as controlling the use permission of the user account, controlling the bank card transfer limit of the user account, sending a security warning message to the user account, etc., and reports the risk information to the data storage system.

[0163] It should be understood that although the steps in the flowcharts involved in the embodiments described above are shown in sequence according to the arrows, the steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, the execution of the steps is not strictly limited in sequence, and the steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the embodiments described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of the steps or stages is not necessarily sequential, but can be alternately or alternately executed with at least part of other steps or steps or stages in other steps.

[0164] Based on the above risk control method, the application concept is shown as Figure 5 The embodiments of the present specification also provide a risk control device 500 for implementing the above-mentioned risk control method. The risk control device 500 comprises:

[0165] The acquisition module 501 is configured to acquire a historical traffic behavior sequence associated with each of a plurality of confirmed risk cases based on historical application layer traffic passing through the application layer gateway.

[0166] The generation module 502 is configured to generate a risk behavior sequence template based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases.

[0167] The control module 503 is configured to perform risk control on the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template.

[0168] In a possible implementation, the acquisition module 501 is specifically configured to construct a historical traffic behavior sequence of a subject dimension based on the historical application layer traffic passing through the application layer gateway; and filter the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases from the historical traffic behavior sequence of the subject dimension according to case data corresponding to each of the plurality of confirmed risk cases.

[0169] In a possible implementation, the case data includes a case subject identifier and a case time stamp; and the acquisition module 501 is specifically configured to filter the historical traffic behavior sequence corresponding to the case subject of the plurality of confirmed risk cases from the historical traffic behavior sequence of the subject dimension according to the case subject identifier corresponding to each of the plurality of confirmed risk cases; and intercept the sequence before and after the case time point from the historical traffic behavior sequence corresponding to the case subject of the plurality of confirmed risk cases as the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases according to the case time stamp corresponding to each of the plurality of confirmed risk cases.

[0170] In one possible implementation, the generation module 502 is specifically used to: obtain at least one high-risk historical traffic behavior sequence and at least one high-risk call interface in the high-risk historical traffic behavior sequence based on the historical traffic behavior sequences associated with each of the multiple confirmed risk cases; determine the calling order of at least one high-risk call interface according to the at least one high-risk historical traffic behavior sequence; and combine the high-risk call interfaces into a risk behavior sequence template according to the calling order.

[0171] In one possible implementation, the generation module 502 is specifically used to: obtain the sequence clustering features corresponding to the historical traffic behavior sequences associated with each of the multiple confirmed risk cases; based on the sequence clustering features, select at least one high-risk historical traffic behavior sequence from the historical traffic behavior sequences associated with each of the multiple confirmed risk cases; obtain the interface clustering features corresponding to the calling interfaces in the at least one high-risk historical traffic behavior sequence; and based on the interface clustering features, select at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence.

[0172] In one possible implementation, the sequence clustering feature includes sequence occurrence frequency and sequence occurrence count; the interface clustering feature includes interface call frequency and interface call count; the generation module 502 is specifically used to: select historical traffic behavior sequences with a sequence occurrence frequency higher than a first preset frequency threshold and a sequence occurrence count higher than the first preset frequency threshold from the historical traffic behavior sequences associated with multiple confirmed risk cases, as at least one high-risk historical traffic behavior sequence; and select calling interfaces with an interface call frequency higher than a second preset frequency threshold and an interface call count higher than the second preset frequency threshold from the at least one high-risk historical traffic sequence, as at least one high-risk calling interface.

[0173] In one possible implementation, the risk control device 500 further includes a sequence construction module for constructing an incremental traffic behavior sequence at the subject level based on the incremental application layer traffic passing through the application layer gateway; and a control module 503 for calculating the matching degree between the risk behavior sequence template and the incremental traffic behavior sequence at the subject level corresponding to the incremental application layer traffic; identifying incremental traffic behavior sequences with a matching degree higher than a preset matching degree threshold as suspicious incremental traffic behavior sequences; comparing and verifying the subject of the suspicious incremental traffic behavior sequence with the subject of a potential risk case; and performing risk control operations on the subject of the verified suspicious incremental traffic behavior sequence.

[0174] The various modules in the risk control apparatus 500 described above can be implemented in whole or in part by software, hardware, and combinations thereof. The various modules described above can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in a computer device in software form, so as to be invoked by a processor to perform the operations corresponding to the various modules.

[0175] The embodiments of the present specification also provide an electronic device, which can be a server, and an internal structure diagram of the electronic device can be as shown in Figure 6 The electronic device includes a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the electronic device is configured to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The application database of the electronic device is configured to store confirmed risk case data, potential risk case data, and the like. The input / output interface of the electronic device is configured to exchange information between the processor and external devices. The communication interface of the electronic device is configured to communicate with external terminals through network connection. The processor of the electronic device executes the computer program to implement a risk control method.

[0176] Those skilled in the art can understand that Figure 6 The structure shown in the above description is only a block diagram of part of the structure related to the scheme of the present specification, and does not constitute a limitation on the electronic device to which the scheme of the present specification is applied. Specifically, the electronic device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0177] In one possible implementation, an electronic device is provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the following steps:

[0178] Based on the historical application layer traffic passing through the application layer gateway, a plurality of historical traffic behavior sequences respectively associated with the confirmed risk cases are obtained;

[0179] Based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, a risk behavior sequence template is generated;

[0180] Based on the risk behavior sequence template, incremental application layer traffic passing through the application layer gateway is controlled.

[0181] In a possible implementation, when the processor executes the computer program, the following steps are further implemented: constructing a historical traffic behavior sequence of the subject dimension based on historical application layer traffic passing through the application layer gateway; and screening a historical traffic behavior sequence associated with each of the plurality of confirmed risk cases from the historical traffic behavior sequence of the subject dimension according to case data corresponding to each of the plurality of confirmed risk cases.

[0182] In a possible implementation, the case data includes a subject involved identifier and a time stamp of the case involved; when the processor executes the computer program, the following steps are further implemented: screening a historical traffic behavior sequence corresponding to a subject involved in the plurality of confirmed risk cases from the historical traffic behavior sequence of the subject dimension according to the subject involved identifier corresponding to each of the plurality of confirmed risk cases; and intercepting a sequence before and after a time point of the case involved from the historical traffic behavior sequence corresponding to the subject involved in the plurality of confirmed risk cases as the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases according to the time stamp of the case involved corresponding to each of the plurality of confirmed risk cases.

[0183] In a possible implementation, when the processor executes the computer program, the following steps are further implemented: obtaining at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence based on the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases; determining a calling sequence of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence; and combining the high-risk calling interface into a risk behavior sequence template according to the calling sequence.

[0184] In a possible implementation, when the processor executes the computer program, the following steps are further implemented: obtaining a sequence aggregation feature corresponding to the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases; screening at least one high-risk historical traffic behavior sequence from the historical traffic behavior sequence associated with each of the plurality of confirmed risk cases based on the sequence aggregation feature; obtaining an interface aggregation feature corresponding to a calling interface in the at least one high-risk historical traffic behavior sequence; and screening at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence based on the interface aggregation feature.

[0185] In a possible implementation, the sequence aggregation feature includes sequence occurrence frequency and sequence occurrence frequency; the interface aggregation feature includes interface calling frequency and interface calling frequency; and the processor, when executing the computer program, further implements the following steps: filtering, from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, historical traffic behavior sequences with sequence occurrence frequency higher than a first preset frequency threshold and sequence occurrence frequency higher than a first preset frequency threshold, as at least one high-risk historical traffic behavior sequence; and filtering, from the at least one high-risk historical traffic sequence, calling interfaces with interface calling frequency higher than a second preset frequency threshold and interface calling frequency higher than a second preset frequency threshold, as at least one high-risk calling interface.

[0186] In a possible implementation, the processor, when executing the computer program, further implements the following steps: constructing a subject-dimension incremental traffic behavior sequence based on the incremental application layer traffic passing through the application layer gateway; calculating a matching degree between the risk behavior sequence template and the subject-dimension incremental traffic behavior sequence corresponding to the incremental application layer traffic; determining, as a suspicious incremental traffic behavior sequence, the incremental traffic behavior sequence with a matching degree higher than a preset matching degree threshold; comparing and verifying the subject of the suspicious incremental traffic behavior sequence with the subject of the potential risk case; and performing a risk control operation on the subject of the suspicious incremental traffic behavior sequence that passes the verification.

[0187] The embodiments of the present specification further provide a computer storage medium, which stores instructions. When the instructions are run on a computer or a processor, the computer or the processor executes one or more steps of the above-described embodiments. When the constituent modules of the above-described electronic device are implemented in the form of software function units and sold or used as independent products, the constituent modules can be stored in the above-described computer storage medium.

[0188] The embodiments of the present specification further provide a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in the above-described method embodiments are implemented.

[0189] In the above embodiments, all or part of the methods can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the methods can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the specification are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted by the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through a wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital versatile disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)) and the like.

[0190] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by a computer program instructing related hardware, which can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments. The storage medium includes ROM, RAM, magnetic or optical discs, and various media that can store program codes. In the case of no conflict, the technical features in the embodiments and the embodiments can be combined arbitrarily.

[0191] The above-described embodiments are merely described as preferred embodiments of the specification, and do not limit the scope of the specification. Without departing from the design spirit of the specification, various modifications and improvements of the technical solutions of the specification made by those of ordinary skill in the art shall fall within the protection scope determined by the claims.

[0192] It should be noted that the information, data and signals involved in the embodiments of the specification are authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0193] The above described embodiments of the present description have been described. Other embodiments are within the scope of the following claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve desirable results. In certain implementations, multitasking and parallel processing can be advantageous.

Claims

1. A risk control method, the method comprising: obtaining a plurality of historical traffic behavior sequences respectively associated with a plurality of confirmed risk cases based on historical application layer traffic passing through an application layer gateway; generating a risk behavior sequence template based on the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; performing risk control on incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template; wherein the generating of the risk behavior sequence template based on the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases comprises: obtaining at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence based on the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; determining a calling sequence of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence; combining the high-risk calling interfaces into the risk behavior sequence template according to the calling sequence; wherein the obtaining of the at least one high-risk historical traffic behavior sequence and the at least one high-risk calling interface in the high-risk historical traffic behavior sequence based on the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases comprises: obtaining sequence aggregation features corresponding to the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; screening at least one high-risk historical traffic behavior sequence from the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases based on the sequence aggregation features; obtaining interface aggregation features corresponding to calling interfaces in the at least one high-risk historical traffic behavior sequence; screening at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence based on the interface aggregation features; wherein the sequence aggregation features comprise sequence occurrence frequency and sequence occurrence frequency, and the interface aggregation features comprise interface calling frequency and interface calling frequency.

2. The method of claim 1, wherein the obtaining of the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases based on historical application layer traffic passing through an application layer gateway comprises: constructing subject-dimension historical traffic behavior sequences based on historical application layer traffic passing through an application layer gateway; screening the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases from the subject-dimension historical traffic behavior sequences according to case data respectively corresponding to the plurality of confirmed risk cases.

3. The method of claim 2, wherein the case data comprises implicated subject identifier and implicated timestamp; the screening of the plurality of historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases from the subject-dimension historical traffic behavior sequences according to case data respectively corresponding to the plurality of confirmed risk cases comprises: screening historical traffic behavior sequences corresponding to implicated subjects of the plurality of confirmed risk cases from the subject-dimension historical traffic behavior sequences according to implicated subject identifiers respectively corresponding to the plurality of confirmed risk cases. According to the time stamps corresponding to each of the plurality of confirmed risk cases, sequences before and after the time stamps are intercepted from the historical traffic behavior sequences corresponding to the subjects of the plurality of confirmed risk cases, as the historical traffic behavior sequences associated with each of the plurality of confirmed risk cases.

4. The method of claim 1, wherein the filtering, based on the sequence aggregation feature, of at least one high-risk historical traffic behavior sequence from the historical traffic behavior sequences associated with each of the plurality of confirmed risk cases comprises: filtering, from the historical traffic behavior sequences associated with each of the plurality of confirmed risk cases, a historical traffic behavior sequence with a sequence occurrence frequency reaching a first preset frequency threshold and a sequence occurrence frequency reaching a first preset frequency threshold, as the at least one high-risk historical traffic behavior sequence; wherein the filtering, based on the interface aggregation feature, of at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence comprises: filtering, from the at least one high-risk historical traffic sequence, a calling interface with an interface calling frequency reaching a second preset frequency threshold and an interface calling frequency reaching a second preset frequency threshold, as the at least one high-risk calling interface.

5. The method of claim 1, wherein before the risk control of the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template, the method further comprises: constructing a subject-dimension incremental traffic behavior sequence based on the incremental application layer traffic passing through the application layer gateway; wherein the risk control of the incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template comprises: calculating a matching degree between the risk behavior sequence template and a subject-dimension incremental traffic behavior sequence corresponding to the incremental application layer traffic; determining an incremental traffic behavior sequence with a matching degree reaching a preset matching degree threshold as a suspicious incremental traffic behavior sequence; comparing and verifying a subject of the suspicious incremental traffic behavior sequence with a subject of a potential risk case; performing a risk control operation on the subject of the suspicious incremental traffic behavior sequence that passes the verification.

6. A risk control device, comprising: an acquisition module configured to acquire, based on historical application layer traffic passing through an application layer gateway, a plurality of historical traffic behavior sequences associated with each of a plurality of confirmed risk cases; a generation module configured to generate, based on the historical traffic behavior sequences associated with each of the plurality of confirmed risk cases, a risk behavior sequence template; a control module configured to perform risk control on incremental application layer traffic passing through the application layer gateway based on the risk behavior sequence template. The generating module is specifically configured to: based on the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases, acquire at least one high-risk historical traffic behavior sequence and at least one high-risk calling interface in the high-risk historical traffic behavior sequence; determine a calling sequence of the at least one high-risk calling interface according to the at least one high-risk historical traffic behavior sequence; and combine the high-risk calling interfaces into the risk behavior sequence template according to the calling sequence. The generating module is specifically configured to: acquire sequence aggregation features corresponding to the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; based on the sequence aggregation features, screen at least one high-risk historical traffic behavior sequence from the historical traffic behavior sequences respectively associated with the plurality of confirmed risk cases; acquire interface aggregation features corresponding to calling interfaces in the at least one high-risk historical traffic behavior sequence; and based on the interface aggregation features, screen at least one high-risk calling interface from the at least one high-risk historical traffic behavior sequence. The sequence aggregation features include sequence occurrence frequency and sequence occurrence frequency, and the interface aggregation features include interface calling frequency and interface calling frequency.

7. An electronic device, comprising: A processor and a memory; The memory stores a computer program, and the processor implements the method steps of any one of claims 1-5 when executing the computer program.

8. A computer storage medium, the computer storage medium storing a plurality of instructions, the instructions being adapted to be loaded and executed by a processor to implement the method steps of any one of claims 1-5.

9. A computer program product, comprising a computer program, the computer program being executed by a processor to implement the method steps of any one of claims 1-5.

Citation Information

Patent Citations

  • Financial risk control method, financial risk control device and electronic device

    CN110796542A

  • Risk management and control method and system based on real-time behavior analysis

    CN120896706A