Abnormal area identification method and device, equipment, medium and product
By acquiring target abnormal communication information and historical abnormal area location information, and utilizing an abnormal behavior and area recognition model trained by federated learning, the problem of difficulty in identifying abnormal areas in existing technologies is solved, and efficient and accurate abnormal area recognition is achieved.
Patent Information
- Application Number
- CN202511642728.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-11
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies struggle to accurately identify anomalous areas, especially in complex network environments, making it difficult to track and combat abnormal targets.
By acquiring target abnormal communication information and historical abnormal area location information, a target abnormal behavior type identification model is trained using federated learning. The target abnormal communication information and historical abnormal area location information are then input into the target abnormal area identification model to identify the location of abnormal areas.
It significantly improves the accuracy and efficiency of abnormal area identification, providing strong technical support for combating abnormal behavior.
Smart Images

Figure CN121508947A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to an abnormal region identification method, apparatus, device, medium and product. Background Technology
[0002] With the advancement of technology and the widespread use of the internet, anomalous entities are leveraging modern communication technologies and the convenience of the internet to construct more covert and complex networks. These anomalous entities are individuals or groups who, with the intent to illegally possess property, defraud others of substantial amounts of public or private funds by fabricating facts and concealing the truth. These anomalous entities often congregate in physical locations or virtual spaces hidden in residential areas, commercial buildings, or even overseas, operating through virtual identities and encrypted communication, making tracking and prosecution exceptionally difficult.
[0003] Therefore, identifying abnormal areas has become an urgent problem to be solved. Summary of the Invention
[0004] This invention provides an abnormal region identification method, apparatus, device, medium, and product that can accurately identify abnormal regions.
[0005] According to one aspect of the present invention, an abnormal region identification method is provided, comprising:
[0006] Acquire abnormal communication information of the target and historical abnormal area location information;
[0007] The target abnormal communication information is input into the target abnormal behavior type identification model to obtain the target abnormal behavior type;
[0008] The target abnormal communication information, target abnormal behavior type, and historical abnormal area location information are input into the target abnormal area identification model to obtain the location information of the abnormal area corresponding to the target abnormal communication information.
[0009] According to another aspect of the present invention, an abnormal region identification device is provided, the abnormal region identification device comprising:
[0010] The acquisition module is used to acquire abnormal communication information of the target and location information of historical abnormal areas;
[0011] The target abnormal behavior type determination module is used to input the target abnormal communication information into the target abnormal behavior type recognition model to obtain the target abnormal behavior type.
[0012] The location information determination module for the abnormal area corresponding to the abnormal communication information of the target is used to input the abnormal communication information of the target, the type of abnormal behavior of the target, and the location information of the historical abnormal area into the target abnormal area identification model to obtain the location information of the abnormal area corresponding to the abnormal communication information of the target.
[0013] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0014] At least one processor; and
[0015] A memory communicatively connected to the at least one processor; wherein,
[0016] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the abnormal region identification method according to any embodiment of the present invention.
[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the abnormal region identification method according to any embodiment of the present invention.
[0018] According to another aspect of the present invention, a computer program product is provided, which, when executed by a processor, implements the abnormal region identification method as described in any of the embodiments of the present invention.
[0019] This invention improves the accuracy of abnormal region identification by acquiring target abnormal communication information and historical abnormal region location information; inputting the target abnormal communication information into a target abnormal behavior type identification model to obtain the target abnormal behavior type; and inputting the target abnormal communication information, target abnormal behavior type, and historical abnormal region location information into a target abnormal region identification model to obtain the location information of the abnormal region corresponding to the target abnormal communication information.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0021] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart of an abnormal region identification method in an embodiment of the present invention;
[0023] Figure 2 This is a schematic diagram of the structure of an abnormal area identification device according to an embodiment of the present invention;
[0024] Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0027] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0028] Example 1
[0029] Figure 1 This is a flowchart illustrating an abnormal region identification method provided in an embodiment of the present invention. This embodiment is applicable to the identification of abnormal regions. The method can be executed by the abnormal region identification device in this embodiment, which can be implemented in software and / or hardware, such as... Figure 1 As shown, the method specifically includes the following steps:
[0030] S110, acquire target abnormal communication information and historical abnormal area location information.
[0031] In this embodiment, the target abnormal communication information includes: a target abnormal communication identifier and the communication content corresponding to the target abnormal communication identifier. The historical abnormal area location information is the location information of historically marked abnormal areas.
[0032] In this embodiment, the server obtains the target abnormal communication information and the location information of historical abnormal areas.
[0033] S120, input the target abnormal communication information into the target abnormal behavior type identification model to obtain the target abnormal behavior type.
[0034] In this embodiment, the target abnormal behavior type identification model can be obtained through federated learning training.
[0035] Optionally, the training process of the target abnormal behavior type identification model includes:
[0036] The initial abnormal behavior type identification model is sent to multiple clients so that each client can train the initial abnormal behavior type identification model based on local abnormal data, thereby obtaining its own trained abnormal behavior type identification model.
[0037] The local abnormal data of each client includes: historical abnormal communication information, historical abnormal account information, abnormal object information related to historical abnormal communication information, abnormal server and abnormal application, at least one of the following.
[0038] In this embodiment, the server sends the initial abnormal behavior type identification model to multiple clients in advance, so that each client can train the initial abnormal behavior type identification model based on local abnormal data to obtain its own trained abnormal behavior type identification model.
[0039] In this embodiment, the initial abnormal behavior type identification model can be a BI-LSTM model. It is trained using a federated learning framework. By introducing federated learning, abnormal data is collected and stored on multiple clients to perform model training. The model is then progressively optimized through interaction between the client and the server to identify the abnormal behavior type.
[0040] It should be noted that, due to the limited number of training samples, training samples can be generated first using adversarial neural networks, and then an abnormal behavior type recognition model can be trained based on cross-platform multi-source data from federated learning.
[0041] Based on the trained abnormal behavior type recognition model sent by each client, determine the target abnormal behavior type recognition model.
[0042] In this embodiment, the server determines the weight of each client based on the client's data volume and data quality (such as the accuracy of anomaly sample labeling). Clients with larger data volumes and higher sample quality have higher model weights. The trained anomaly behavior type recognition models sent by each client are weighted and summed according to their respective weights to obtain the target anomaly behavior type recognition model.
[0043] It should be noted that after receiving the trained abnormal behavior type identification models sent by each client, the server can perform a weighted summation of the trained abnormal behavior type identification models sent by each client to obtain a first abnormal behavior type identification model. The first abnormal behavior type identification model is then sent to multiple clients so that each client can train the first abnormal behavior type identification model based on its local abnormal data to obtain its own trained abnormal behavior type identification model. The above process is iteratively executed until the server performs a weighted summation of the trained abnormal behavior type identification models sent by each client according to the weights of each client. The resulting model satisfies the iteration termination condition, and the target abnormal behavior type identification model is obtained.
[0044] Optionally, the multiple clients are designated as a first client, a second client, a third client, and a fourth client. The local abnormal data of the first client includes: historical abnormal communication information, which includes: abnormal communication identifiers and communication content corresponding to the abnormal communication identifiers. The local abnormal data of the second client includes: historical abnormal account information, which includes: abnormal ownership migration account identifiers and login abnormal account identifiers. The local abnormal data of the third client includes: abnormal object information related to historical abnormal communication information. The local abnormal data of the fourth client includes: abnormal servers and / or abnormal applications.
[0045] In this embodiment, the abnormal ownership transfer account identifiers include: unauthorized ownership transfer account identifiers and ownership transfer account identifiers where the transaction amount exceeds a transaction amount threshold.
[0046] S130, the target abnormal communication information, target abnormal behavior type and historical abnormal area location information are input into the target abnormal area identification model to obtain the location information of the abnormal area corresponding to the target abnormal communication information.
[0047] In this embodiment, the target anomaly region identification model is a model obtained after training a large model.
[0048] Optionally, the training process for the target anomaly region identification model includes:
[0049] Obtain a training sample set, wherein the training sample set includes: input samples and location information of the abnormal regions corresponding to the input samples, wherein the input samples include: abnormal communication information samples, abnormal behavior type samples corresponding to the abnormal communication information samples, and historical abnormal region location information;
[0050] Input samples from the training sample set into a large model to obtain the location information of the predicted anomaly region;
[0051] The parameters of the large model are trained based on the difference between the location information of the predicted abnormal region and the location information of the abnormal region corresponding to the input sample, so as to obtain the target abnormal region identification model.
[0052] In this embodiment, if the number of training samples in the training sample set is less than the number threshold, training samples can be generated by an adversarial generative network to expand the training sample set.
[0053] Optionally, obtain the training sample set, including:
[0054] Obtain samples of abnormal communication information;
[0055] Input the abnormal communication information sample into the target abnormal behavior type identification model to obtain the abnormal behavior type sample corresponding to the abnormal communication information sample.
[0056] Optionally, after inputting the target anomalous communication information, target anomalous behavior type, and historical anomalous area location information into the target anomalous area identification model to obtain the location information of the anomalous area corresponding to the target anomalous communication information, the method further includes:
[0057] The location information of the abnormal area corresponding to the abnormal communication information of the target is sent to the target client.
[0058] In this embodiment, the target client can be a client corresponding to the system of an administrative unit.
[0059] In a specific example, in the field of anomaly area identification, data collection mainly relies on a single data source from the telecommunications industry. However, this single-data-source-based approach has significant limitations; it cannot comprehensively capture and analyze the diversity and complexity of abnormal behavior, resulting in limited identification accuracy and difficulty in accurately locating abnormal areas. To address these issues, this invention proposes an anomaly area identification method based on multi-source data fusion technology. In this embodiment, data is collected from the telecommunications industry, the financial industry, government agency systems, and information security centers. To ensure data security across different data sources, a federated training method is used to train an anomaly behavior type identification model. The model analyzes the behavioral characteristics in the dataset and performs cluster analysis to identify the types of abnormal behavior. Then, by combining the abnormal behavior type, abnormal communication information, and known historical anomaly area location information, the large model is enhanced with industry-specific training to establish a target anomaly area identification model, thereby predicting potential anomaly areas. Once the prediction model identifies a potential anomaly area, the system automatically triggers an alert, notifying relevant departments for investigation and handling. Furthermore, this method emphasizes the importance of real-time data processing and dynamic model updates to ensure the system can adapt to the continuous evolution of fraud methods. This approach can significantly improve the accuracy and efficiency of identifying abnormal areas, providing strong technical support for combating abnormal behavior.
[0060] This invention proposes an abnormal area identification system. The system includes a data acquisition module, a data fusion module, a feature clustering module, a large-scale model training module, and an early warning module. Specifically, the data acquisition module collects relevant data from multiple channels, including the telecommunications industry, the financial industry, institutional systems, and information security centers. The data fusion module uses federated modeling to train a model from data from different channels, ensuring data security across different data sources. The feature clustering module analyzes behavioral characteristics and performs clustering analysis to identify abnormal behavior types. The large-scale model training module uses abnormal communication information, the corresponding abnormal behavior types, and historical abnormal area location information to enhance the training of a general large-scale model, establishing a target abnormal area identification model to predict potential abnormal areas. Finally, the early warning module uses a real-time monitoring and dynamic update mechanism to promptly issue early warning signals to relevant departments, enabling rapid response and effective crackdown on abnormal areas.
[0061] The data acquisition module integrates resources from the telecommunications industry, the financial industry, government agencies, and information security centers to comprehensively collect information related to abnormal communication behavior. In the telecommunications industry, it can obtain abnormal communication identifiers, corresponding communication content, and transmission patterns; in the financial industry, it provides detailed data on abnormal transaction records and account anomalies; government agencies share investigation details and information on individuals involved in abnormal communication behavior; and the information security center monitors and records abnormal servers and / or applications, such as data from phishing websites, malware, and other cyberattacks.
[0062] Data collection from the telecommunications industry: The telecommunications industry is a significant source of abnormal communication behavior. The data acquisition module can capture a large number of abnormal communication identifiers and their corresponding communication content. The communication content corresponding to the abnormal communication identifiers includes key information such as the call time and duration of the abnormal entity.
[0063] Data collected from the financial industry: The financial industry provides abnormal transaction data closely related to unusual communication behavior. This data includes, but is not limited to, unauthorized fund transfers, unusually large transactions, and frequent account login attempts. By monitoring and analyzing these abnormal behaviors, potential financial fraud can be detected in a timely manner, protecting users' assets. In addition, the financial industry also records account information and transaction paths involved in abnormal communication behavior.
[0064] Data is collected from government agency systems, which are the primary providers of information on abnormal communication behavior. The data collection module can obtain detailed investigation reports on abnormal communication behavior, information on individuals involved, and more. This information not only helps in understanding the development trends and characteristics of abnormal communication behavior but also provides a basis for developing targeted preventative measures. The data from government agency systems also includes historical location information for abnormal areas.
[0065] Data collected from the Information Security Center: The Information Security Center provides monitoring data on abnormal communication behavior, including various forms such as phishing websites, malware, and phishing attacks. Analysis of this data can identify the targets and propagation paths of these abnormal communication behaviors. The Information Security Center's data also includes response records for cybersecurity incidents, which play a crucial role in improving cybersecurity protection capabilities and reducing losses from abnormal communication behavior.
[0066] In summary, the data acquisition module collects data related to abnormal communication behavior from multiple channels, including the telecommunications industry, the financial industry, government agency systems, and information security centers.
[0067] Data fusion module: It optimizes the training process of federated learning through adversarial neural networks, reduces the interaction frequency between the server and the client, and improves fusion efficiency; it realizes the organic fusion of cross-platform multi-source data and improves model training efficiency.
[0068] In the feature clustering module, the data collected by the data acquisition module is first subjected to feature extraction using two methods: Principal Component Analysis (PCA) and Independent Component Analysis (ICA). These two methods effectively reduce the dimensionality of the data while retaining key information. PCA transforms the original data into a set of linearly independent representations to extract the main feature components; while ICA aims to find a set of statistically independent source signals, thereby revealing the underlying structure in the data. For the clustering algorithm, the K-means algorithm is used. The K-means algorithm divides the data points into K clusters through an iterative optimization process, with the center of each cluster being the mean of all points within that cluster. It has the advantages of high computational efficiency and ease of implementation. In the key stages of clustering result analysis and optimization, evaluation metrics such as the silhouette coefficient and the Davidson-Burding index are used to assess the clustering effect. The silhouette coefficient measures the compactness of samples within a cluster and the separation of samples between clusters; a value closer to 1 indicates a better clustering effect. The Davidson-Burding index evaluates the ratio of intra-cluster distance to inter-cluster distance; a smaller value indicates a better clustering effect. To further optimize the clustering results, iterative relocation and genetic algorithms were employed. Iterative relocation continuously adjusts the assignments of data points to find better clustering schemes; genetic algorithms simulate natural selection and genetic mechanisms, exploring the global optimum through crossover and mutation operations. The application of these optimization strategies significantly improved the accuracy and stability of the clustering results.
[0069] In the large model training module, the dataset from the data fusion module is first preprocessed. Then, a general large model is selected as the foundation. This model should have sufficient parameters and computational power to handle complex pattern recognition tasks. The general large model is trained using abnormal communication information samples, abnormal behavior type samples corresponding to the abnormal communication information samples, and historical abnormal area location information to obtain the target abnormal area recognition model.
[0070] In the data preprocessing stage, the first step is data cleaning, which removes duplicate records, corrects erroneous data, and fills in missing values to ensure data integrity. Next, non-numerical data (such as text) is transformed into numerical form through transformation operations, commonly using methods such as one-hot encoding or word embedding techniques. Subsequently, normalization or standardization is performed to scale the numerical data to a uniform range or convert it to a standard distribution to reduce scale differences between different features. Finally, the cleaned and transformed dataset is divided into training, validation, and test sets to evaluate performance and make necessary adjustments and optimizations during model training.
[0071] When building a large-scale model for anomaly region identification, a general-purpose model should be chosen. First, based on the evaluation requirements, determine the complexity and data volume the model needs to handle. If the dataset contains 1 million records, each with 100 features, a model capable of processing this scale of data is required. Next, consider the model's flexibility and choose a model architecture that can adapt to various data types and patterns; here, the Transformer model is chosen. This model can handle sequence data as well as various types of data such as images and audio. Finally, consider computational resources, ensuring sufficient resources are available to train the selected model. If computational resources are limited, a smaller-scale Transformer model can be chosen, such as a lightweight BERT model based on knowledge distillation, which has fewer parameters and can be trained in a shorter time.
[0072] The training process of the target anomaly region identification model includes: inputting anomalous communication information samples, corresponding anomalous behavior type samples, and historical anomalous region location information into a general large-scale pre-trained model, and performing a refined augmentation training process. This process aims to construct a highly optimized target anomaly region identification model. During this process, hyperparameter tuning techniques such as grid search or random search are used to systematically adjust and optimize hyperparameters to ensure that the model not only accurately captures the unique characteristics of anomalous communication behavior but also maximizes its classification performance and generalization ability, thus providing a solid technical foundation for effectively identifying and preventing anomalous regions.
[0073] In the prediction phase, the target anomaly area identification model is deployed to practical applications to analyze data streams in real time to identify potential abnormal communication behaviors. Risk assessment is then conducted based on the probability distribution output by the target anomaly area identification model, thereby effectively enabling early warning and prevention of anomaly areas.
[0074] Early warning module: The early warning module uses a real-time monitoring and dynamic update mechanism to promptly issue early warning signals to relevant departments, enabling rapid response and effective crackdown on abnormal areas.
[0075] The technical solution of this embodiment improves the accuracy of abnormal area identification by acquiring target abnormal communication information and historical abnormal area location information; inputting the target abnormal communication information into a target abnormal behavior type identification model to obtain the target abnormal behavior type; and inputting the target abnormal communication information, target abnormal behavior type, and historical abnormal area location information into a target abnormal area identification model to obtain the location information of the abnormal area corresponding to the target abnormal communication information.
[0076] Example 2
[0077] Figure 2This is a schematic diagram of an abnormal region identification device provided in an embodiment of the present invention. This embodiment is applicable to cases involving abnormal region identification. The device can be implemented using software and / or hardware methods and can be integrated into any device that provides abnormal region identification functionality, such as… Figure 2 As shown, the abnormal area identification device specifically includes: an acquisition module 210, a target abnormal behavior type determination module 220, and a location information determination module 230 for the abnormal area corresponding to the target abnormal communication information.
[0078] The acquisition module is used to acquire target abnormal communication information and historical abnormal area location information;
[0079] The target abnormal behavior type determination module is used to input the target abnormal communication information into the target abnormal behavior type recognition model to obtain the target abnormal behavior type.
[0080] The location information determination module for the abnormal area corresponding to the abnormal communication information of the target is used to input the abnormal communication information of the target, the type of abnormal behavior of the target, and the location information of the historical abnormal area into the target abnormal area identification model to obtain the location information of the abnormal area corresponding to the abnormal communication information of the target.
[0081] The above-described products can perform the methods provided in any embodiment of the present invention, and have the corresponding functional modules and beneficial effects for performing the methods.
[0082] Example 3
[0083] Figure 3 A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0084] like Figure 3As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0085] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0086] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as anomaly region identification methods.
[0087] In some embodiments, the anomaly region identification method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the anomaly region identification method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the anomaly region identification method by any other suitable means (e.g., by means of firmware).
[0088] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0089] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0090] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0091] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0092] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0093] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0094] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0095] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the abnormal region identification method according to any embodiment of the invention.
[0096] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0097] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for identifying abnormal regions, characterized in that, The abnormal region identification method includes: Acquire abnormal communication information of the target and historical abnormal area location information; The target abnormal communication information is input into the target abnormal behavior type identification model to obtain the target abnormal behavior type; The target abnormal communication information, target abnormal behavior type, and historical abnormal area location information are input into the target abnormal area identification model to obtain the location information of the abnormal area corresponding to the target abnormal communication information.
2. The method according to claim 1, characterized in that, The training process of the target abnormal behavior type identification model includes: An initial abnormal behavior type identification model is sent to multiple clients so that each client can train the initial abnormal behavior type identification model based on local abnormal data to obtain its own trained abnormal behavior type identification model. The local abnormal data of each client includes at least one of the following: historical abnormal communication information, historical abnormal account information, abnormal object information related to historical abnormal communication information, abnormal server, and abnormal application. Based on the trained abnormal behavior type recognition model sent by each client, determine the target abnormal behavior type recognition model.
3. The method according to claim 1, characterized in that, The training process of the target anomaly region identification model includes: Obtain a training sample set, wherein the training sample set includes: input samples and location information of the abnormal regions corresponding to the input samples, wherein the input samples include: abnormal communication information samples, abnormal behavior type samples corresponding to the abnormal communication information samples, and historical abnormal region location information; Input samples from the training sample set into a large model to obtain the location information of the predicted anomaly region; The parameters of the large model are trained based on the difference between the location information of the predicted abnormal region and the location information of the abnormal region corresponding to the input sample, so as to obtain the target abnormal region identification model.
4. The method according to claim 3, characterized in that, Obtain the training sample set, including: Obtain samples of abnormal communication information; Input the abnormal communication information sample into the target abnormal behavior type identification model to obtain the abnormal behavior type sample corresponding to the abnormal communication information sample.
5. The method according to claim 1, characterized in that, After inputting the target anomalous communication information, target anomalous behavior type, and historical anomalous area location information into the target anomalous area identification model to obtain the location information of the anomalous area corresponding to the target anomalous communication information, the method further includes: The location information of the abnormal area corresponding to the abnormal communication information of the target is sent to the target client.
6. The method according to claim 2, characterized in that, The multiple clients are designated as a first client, a second client, a third client, and a fourth client. The local abnormal data of the first client includes: historical abnormal communication information, which includes: abnormal communication identifiers and communication content corresponding to the abnormal communication identifiers. The local abnormal data of the second client includes: historical abnormal account information, which includes: abnormal ownership migration account identifiers and login abnormal account identifiers. The local abnormal data of the third client includes: abnormal object information related to historical abnormal communication information. The local abnormal data of the fourth client includes: abnormal servers and / or abnormal applications.
7. An abnormal area identification device, characterized in that, The abnormal region identification device includes: The acquisition module is used to acquire abnormal communication information of the target and location information of historical abnormal areas; The target abnormal behavior type determination module is used to input the target abnormal communication information into the target abnormal behavior type recognition model to obtain the target abnormal behavior type. The location information determination module for the abnormal area corresponding to the abnormal communication information of the target is used to input the abnormal communication information of the target, the type of abnormal behavior of the target, and the location information of the historical abnormal area into the target abnormal area identification model to obtain the location information of the abnormal area corresponding to the abnormal communication information of the target.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the abnormal region identification method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the abnormal region identification method according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the abnormal region identification method according to any one of claims 1-6.