User abnormal behavior detection method and device, electronic equipment and storage medium

By constructing individual and group user profiles and combining them with user login and order query log data for anomaly assessment, the problem of insufficient accuracy in detecting abnormal user behavior has been solved, achieving more efficient abnormal behavior detection and information security protection.

CN121940146APending Publication Date: 2026-04-28SF TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SF TECH CO LTD
Filing Date
2024-10-25
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

In existing technologies, the accuracy of detecting abnormal user behavior is insufficient, which easily leads to false alarms and prevents maintenance personnel from quickly handling real abnormal situations.

Method used

By constructing individual user profiles and group profiles of the target audience, and combining user login log data and transaction log data, anomaly assessment is conducted to filter out abnormal behavior data.

Benefits of technology

It improves the accuracy of detecting abnormal user behavior, reduces false alarms, facilitates timely protective measures by operations and maintenance personnel, and enhances information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940146A_ABST
    Figure CN121940146A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a user abnormal behavior detection method and device, electronic equipment and a storage medium, and belongs to the technical field of computers. The method comprises the steps of obtaining user log data of a target object and group login log data of a group where the target object is located; the user log data comprises user login log data and user check log data, and behaviors of the target object are similar to behaviors of other objects in the group where the target object is located; according to the user login log data and the user check log data, carrying out portrait construction to obtain a user personal portrait; performing portrait construction according to the group login log data to obtain a group portrait; acquiring current user behavior data of the target object; performing anomaly evaluation on the current user behavior data based on the user personal portrait and the group portrait to obtain anomaly evaluation data; and screening out abnormal behavior data from the current user behavior data according to the abnormal evaluation data. According to the embodiment of the invention, the accuracy of user abnormal behavior detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method and apparatus for detecting abnormal user behavior, an electronic device, and a storage medium. Background Technology

[0002] In the interaction of computer networks, abnormal user behavior affects information security. Therefore, accurately detecting abnormal user behavior and improving information security has become a key technology in computer networks. For example, in the logistics industry, logistics orders contain a large amount of sensitive information, such as sender and recipient contact information, names, and addresses. If abnormal user behavior indicates that a courier's account has been used by someone else, it affects information security. To address this issue, related technologies detect user behavior characteristics. If these characteristics exceed a preset threshold, an alarm is generated to alert logistics application maintenance personnel to take timely protective measures and reduce information leakage. However, relying solely on user behavior characteristics and preset thresholds cannot accurately detect abnormal user behavior and is prone to false alarms. Therefore, improving the accuracy of abnormal user behavior detection has become an urgent technical problem to be solved. Summary of the Invention

[0003] The main objective of this application is to provide a method, apparatus, electronic device, and storage medium for detecting abnormal user behavior, aiming to improve the accuracy of detecting abnormal user behavior.

[0004] To achieve the above objectives, a first aspect of this application proposes a method for detecting abnormal user behavior, the method comprising:

[0005] Obtain user log data of the target object and group login log data of the group to which the target object belongs; wherein, the user log data includes: user login log data and user query log data, and the behavior of the target object is similar to the behavior of other objects in the group;

[0006] A user profile is constructed based on the user login log data and the user query log data.

[0007] A profile is constructed based on the group login log data to obtain a group profile;

[0008] Obtain the current user behavior data of the target object;

[0009] Based on the individual user profile and the group profile, an anomaly assessment is performed on the current user behavior data to obtain anomaly assessment data.

[0010] Abnormal behavior data is filtered out from the current user behavior data based on the abnormality assessment data.

[0011] In some embodiments, the anomaly assessment of current user behavior data based on the individual user profile and the group profile, to obtain anomaly assessment data, includes:

[0012] Feature extraction is performed on the current user behavior data to obtain at least two user behavior features;

[0013] Based on the individual user profile and the group profile, feature evaluation is performed on each user behavior feature to obtain feature evaluation data;

[0014] The anomaly assessment data is obtained by concatenating at least two of the feature assessment data.

[0015] In some embodiments, the user behavior characteristics include: current login behavior characteristics and current order inquiry behavior characteristics; the individual user profile includes: user login behavior profile and user order inquiry behavior profile; the group profile includes: group login behavior profile;

[0016] The feature evaluation is performed on each user behavior feature based on the individual user profile and the group profile to obtain feature evaluation data, including:

[0017] Based on the user login behavior profile and the group login behavior profile, the current login behavior characteristics are evaluated to obtain login evaluation data.

[0018] Based on the user's query behavior profile, the current query behavior characteristics are evaluated to obtain query evaluation data.

[0019] The feature evaluation data is constructed based on the login evaluation data and the order query evaluation data.

[0020] In some embodiments, the current login behavior characteristics include: current login address characteristics, current login component characteristics, current login device characteristics, and current login system characteristics; the user login behavior profile includes: historical login address characteristics, historical login component characteristics, historical login device characteristics, and historical login system characteristics; and the group login behavior profile includes: group login address characteristics and group login device characteristics.

[0021] The login feature evaluation is performed on the current login behavior features based on the user login behavior profile and the group login behavior profile to obtain login evaluation data, including:

[0022] Based on the historical login address characteristics and the group login address characteristics, the current login address characteristics are evaluated to obtain login address evaluation data.

[0023] Based on the historical login component characteristics, the current login component characteristics are evaluated to obtain login component evaluation data;

[0024] Based on the historical login device characteristics and the group login device characteristics, the current login device characteristics are evaluated to obtain login device evaluation data.

[0025] Based on the historical login system characteristics, the current login system characteristics are evaluated to obtain login system evaluation data;

[0026] The login evaluation data is constructed based on the login address evaluation data, the login component evaluation data, the login device evaluation data, and the login system evaluation data.

[0027] In some embodiments, the current order tracking behavior characteristics include: current out-of-period order tracking characteristics, current total order tracking volume characteristics, current out-of-period order tracking volume characteristics, historical waybill characteristics for shipments not picked up or delivered by the user, and current cross-regional order tracking characteristics; the user order tracking behavior profile includes: out-of-period order tracking rules, historical total order tracking volume characteristics, historical out-of-period order tracking volume characteristics, rules for shipments not picked up or delivered by the user, and historical cross-regional order tracking characteristics;

[0028] Based on the user's order inquiry behavior profile, the current order inquiry behavior characteristics are evaluated to obtain order inquiry evaluation data, including:

[0029] Based on the rules for checking orders outside the delivery period, the current characteristics of checking orders outside the delivery period are evaluated to obtain evaluation data for checking orders outside the delivery period.

[0030] Based on the historical total query volume characteristics, the current total query volume characteristics are evaluated to obtain total query volume evaluation data;

[0031] Based on the historical out-of-period order inquiry volume characteristics, the current out-of-period order inquiry volume characteristics are evaluated to obtain out-of-period order inquiry evaluation data.

[0032] Based on the rules for non-owner-received delivery and pickup waybills, the characteristics of the historical delivery and pickup waybills of non-owner-received delivery and pickup are evaluated to obtain non-owner-received waybill characteristic evaluation data.

[0033] Based on the historical cross-regional query characteristics, the current cross-regional query characteristics are evaluated to obtain cross-regional query evaluation data.

[0034] The order inquiry assessment data is constructed based on the order inquiry assessment data outside the collection and delivery period, the total order inquiry volume assessment data, the order inquiry assessment data outside the collection and delivery period, the non-owner's waybill characteristic assessment data, and the cross-regional order inquiry assessment data.

[0035] In some embodiments, filtering abnormal behavior data from the current user behavior data based on the abnormality assessment data includes:

[0036] The current user behavior data is sorted based on the anomaly assessment data to obtain a behavior sequence number;

[0037] Target numbers are selected from the behavior numbers according to a preset number;

[0038] Abnormal behavior data is filtered from the current user behavior data based on the target sequence number.

[0039] In some embodiments, after filtering out abnormal behavior data from the current user behavior data based on the abnormality assessment data, the method further includes:

[0040] Feature extraction is performed on the abnormal behavior data to obtain abnormal behavior features;

[0041] Warning information is generated based on preset warning rules and the abnormal behavior characteristics, resulting in warning prompts.

[0042] To achieve the above objectives, a second aspect of this application provides a user abnormal behavior detection device, the device comprising:

[0043] The log data acquisition module is used to acquire user log data of the target object and group login log data of the group to which the target object belongs; wherein, the user log data includes: user login log data and user query log data, and the behavior of the target object is similar to the behavior of other objects in the group;

[0044] The personal profile building module is used to build a profile based on the user login log data and the user query log data to obtain a user personal profile.

[0045] The group profile building module is used to build a profile based on the group login log data to obtain a group profile.

[0046] The behavior data acquisition module is used to acquire the current user behavior data of the target object;

[0047] Anomaly assessment module is used to assess the current user behavior data based on the user's individual profile and the group profile, and obtain anomaly assessment data;

[0048] The data filtering module is used to filter out abnormal behavior data from the current user behavior data based on the abnormality assessment data.

[0049] To achieve the above objectives, a third aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described in the first aspect.

[0050] To achieve the above objectives, a fourth aspect of the present application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the first aspect.

[0051] The user abnormal behavior detection method, device, electronic device, and storage medium proposed in this application construct individual user profiles and group profiles of the target user's group, and evaluate user behavior data based on the individual user profiles and group profiles. Abnormal behavior data is then filtered out based on the abnormal evaluation data. This not only improves the accuracy of abnormal behavior detection but also facilitates maintenance personnel to take timely protective measures based on abnormal behavior data, thereby improving the security of the information managed by the target user. Attached Figure Description

[0052] Figure 1 This is a flowchart of the user abnormal behavior detection method provided in the embodiments of this application;

[0053] Figure 2 yes Figure 1 The flowchart of step S105 in the process;

[0054] Figure 3 yes Figure 2 The flowchart of step S202 in the text;

[0055] Figure 4 yes Figure 3 The flowchart of step S301 in the process;

[0056] Figure 5 yes Figure 3 The flowchart of step S302 in the text;

[0057] Figure 6 yes Figure 1 The flowchart of step S106 in the process;

[0058] Figure 7 This is a flowchart of a user abnormal behavior detection method provided in another embodiment of this application;

[0059] Figure 8 This is a schematic diagram of the user abnormal behavior detection device provided in the embodiments of this application;

[0060] Figure 9 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0062] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0063] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0064] First, let's analyze some of the terms used in this application:

[0065] Personal profile: A description or analysis of a person's characteristics, personality, behavior, interests, etc.

[0066] Group profiling: refers to a general description of the characteristics, behaviors, preferences, and needs of a specific group.

[0067] Waybill collection and delivery period: refers to the time required for the entire process from receiving the waybill to completing the delivery in logistics or express delivery services.

[0068] Anomaly ranking algorithms are algorithms used in data analysis and machine learning to identify and rank outliers or abnormal patterns in a dataset. Outliers may represent data entry errors, measurement errors, or actual abnormal situations.

[0069] In the interaction process of computer networks, abnormal user behavior affects information security. Therefore, accurately detecting abnormal user behavior and improving information security has become a key technology in computer networks. For example, in the logistics industry, users check order information by querying decrypted package information within the system. This package information contains a large amount of sensitive information, such as the sender's and recipient's phone numbers, names, and addresses. Delivery personnel have their own employee accounts and need to log in to the logistics system through these accounts to query relevant information. If the delivery personnel's account information is leaked, security is compromised. Therefore, to protect customer information, it is necessary to detect abnormal user behavior and provide timely feedback when abnormal user behavior is detected, reducing the possibility of employee accounts being stolen.

[0070] In related technologies, abnormal user behavior detection mainly uses threshold rules for monitoring. When a user's behavior characteristics exceed a preset threshold, an alarm is generated to alert the user to the abnormal behavior. However, using threshold rules to detect abnormal user behavior tends to generate a large number of alarms and has a high false alarm rate, making it difficult for operations and maintenance personnel to quickly handle abnormal user behavior, resulting in the failure to detect and resolve genuine anomalies in a timely manner.

[0071] Based on this, embodiments of this application provide a method and apparatus for detecting abnormal user behavior, an electronic device, and a storage medium, aiming to improve the accuracy of detecting abnormal user behavior.

[0072] The user abnormal behavior detection method, device, electronic device and storage medium provided in the embodiments of this application are specifically described through the following embodiments. First, the user abnormal behavior detection method in the embodiments of this application is described.

[0073] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0074] Foundational technologies in artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.

[0075] The user abnormal behavior detection method provided in this application relates to the field of computer technology. This method can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the user abnormal behavior detection method, but is not limited to the above forms.

[0076] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0077] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.

[0078] Figure 1 This is an optional flowchart of the user abnormal behavior detection method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S106.

[0079] Step S101: Obtain user log data of the target object and group login log data of the group to which the target object belongs; wherein, the user log data includes: user login log data and user query log data, and the behavior of the target object is similar to the behavior of other objects in the group;

[0080] Step S102: Based on user login log data and user query log data, a profile is constructed to obtain a user's personal profile;

[0081] Step S103: Construct a profile based on the group login log data to obtain a group profile;

[0082] Step S104: Obtain the current user behavior data of the target object;

[0083] Step S105: Based on the user's individual profile and group profile, perform anomaly assessment on the current user behavior data to obtain anomaly assessment data;

[0084] Step S106: Filter out abnormal behavior data from the current user behavior data based on the abnormal assessment data.

[0085] Steps S101 to S106, as illustrated in this embodiment, involve constructing a user profile using the user login log data and user query log data of the target object, and then constructing a group profile using the group login log data of the target object's group. The constructed group profile and the user profile share a certain degree of similarity. Based on the user profile and group profile, anomaly assessment is performed on the current user behavior data to obtain accurate anomaly assessment data characterizing abnormal user behavior. Based on this anomaly assessment data, abnormal behavior data is then filtered from the current user behavior to achieve accurate detection of abnormal user behavior. Therefore, evaluating user behavior data using user profiles and group profiles, and then filtering out abnormal behavior data based on the anomaly assessment data, not only improves the accuracy of abnormal behavior detection but also facilitates timely protective measures by maintenance personnel based on abnormal behavior data, thereby enhancing the security of the information managed by the target object.

[0086] In step S101 of some embodiments, the user abnormal behavior detection method is mainly applicable to the field of user account theft detection. Specifically, the user abnormal behavior detection method can be applied to logistics management systems or online shopping platforms, and this embodiment does not impose specific limitations on the application scenarios of the user abnormal behavior detection method.

[0087] User log data is retrieved directly from the target user's account information. This data includes user login logs and user order query logs. Login logs represent the target user's login behavior, while order query logs represent their order query behavior. Group login logs are the log data of other users within the target user's group. By obtaining the target user's group information, the object log data of other users within the group is extracted and combined to form the group login log data. It's important to note that the target user and other users in their group exhibit similar behaviors, allowing the group's behavioral habits to be determined through group login log data. Group login log data, in particular, represents the login behavior habits of the target user's group. Therefore, combining both user log data and group login log data for analysis is more accurate and reduces false alarms.

[0088] In one application scenario, taking a logistics management system as an example, the target object is the accounts of delivery personnel. User anomaly detection primarily involves detecting account theft. For delivery personnel, group login log data aggregates the login logs of other delivery personnel within the same branch. Furthermore, delivery personnel within the same branch share similar operational habits due to their job responsibilities. Therefore, determining whether an individual delivery personnel's account has been stolen involves analyzing not only their own log data but also the log data of other delivery personnel within the same branch. This allows for accurate detection of abnormal account theft behavior, improving the security of customer information managed by delivery personnel.

[0089] As disclosed above, after collecting user log data and group login log data, the user log data and group login log data are cleaned to obtain structured user log data and group login log data. Then, the structured user log data and group login log data are stored in a big data cluster so that they can be extracted from the big data cluster when building user personal profiles and group profiles, which facilitates the detection of abnormal user behavior.

[0090] In step S102 of some embodiments, the user profile is used to characterize the user's login and order inquiry behavior habits. The user profile includes a user login behavior profile and a user order inquiry behavior profile. The user login behavior profile is constructed based on user login log data, and this profile characterizes the user's behavioral habits. The user order inquiry behavior profile is constructed based on user order inquiry log data.

[0091] Specifically, the user login log data includes: user login address information, user login component information, user login device information, and user login system information. The user login address information includes the address where the user logs in, and the address can be broken down to country, province, and city. This user login address information is obtained by resolving the target object's login IP address. The user login component information represents the components used during the login process, and includes the login component name, which is extracted from the component field in the user login log data. The user login device information represents the device used by the target object when logging in, including the login device name and model, determined by the login device field in the user login log data. The user login system information represents the operating system used by the target object when logging in, including the login system type. Traditional operating systems can include Windows, iOS, and Android, etc., but this embodiment does not impose specific limitations on the operating system.

[0092] Specifically, user order tracking log data includes: the percentage of time spent tracking orders outside the delivery / collection period, the percentage of time spent tracking orders across different branches, the percentage of time spent tracking orders across different departments, the percentage of time spent tracking orders across different regions, the number of branches involved in cross-branch tracking, the number of branches involved in cross-department tracking, the number of branches involved in cross-regional tracking, the average daily tracking volume, the standard deviation of the daily tracking volume, the average daily tracking volume outside the delivery / collection period, the standard deviation of the daily tracking volume outside the delivery / collection period, and the employee's order decryption operation time. It should be noted that tracking orders outside the delivery / collection period refers to the tracking behavior after the order has been received, and the percentage of time spent tracking orders outside the delivery / collection period = the number of days with tracking behavior outside the delivery / collection period / the number of days with tracking behavior. Cross-department tracking refers to the tracking behavior of querying a branch other than the user's service branch, and the percentage of time spent tracking orders across different branches = the number of days with cross-department tracking / the number of days with tracking behavior. Cross-regional order inquiries refer to inquiries made in regions other than the user's own service area. The percentage of time spent on cross-regional order inquiries equals the number of days with cross-regional order inquiries divided by the total number of days with order inquiries. The number of branches with cross-branch order inquiries represents the number of branches with cross-branch order inquiries in historical order inquiries. The number of branches with cross-department order inquiries represents the number of branches with cross-department order inquiries in historical order inquiries, and the number of branches with cross-regional order inquiries represents the number of regions with cross-regional order inquiries in historical order inquiries. The average daily order volume represents the historical daily order volume per employee; the average daily order volume per employee is calculated. The standard deviation of daily order inquiry volume represents the historical daily order inquiry volume and mean of employees, and the standard deviation of the daily order inquiry volume is calculated. The average daily order inquiry volume outside the collection and delivery period represents the historical daily order inquiry volume outside the collection and delivery period of employees, and the standard deviation of the daily order inquiry volume outside the collection and delivery period is calculated. The decryption time point in the employee's order decryption operation time represents the time point within the day when the employee has engaged in order inquiry and decryption behavior, calculated in hours. Therefore, by constructing a user order inquiry behavior profile based on the user order inquiry behavior log data above, a more detailed analysis of the target user's order inquiry behavior habits can be achieved.

[0093] In step S103 of some embodiments, the group login log data can characterize the login behavior habits of the group to which the target object belongs, so the generated group profile characterizes the login behavior habits of the group to which the target object belongs. The group login log data includes: group login address information and group login device information. The group login address information includes login addresses commonly used by other objects within the target object's group, specifying the login address down to the country, province, and city. The group login address information is obtained by parsing the IP addresses in the group login log data. The group login devices are login devices commonly used by other objects within the target object's group, and the commonly used login devices are counted on a group-by-group basis.

[0094] In step S104 of some embodiments, the current user behavior data is obtained from the current log data, and the user log data is historical log data. By comparing the current user behavior data and the user log data, the differences between the current user behavior and the previous user behavior are analyzed to achieve abnormal user behavior detection.

[0095] Please see Figure 2 In some embodiments, step S105 may include, but is not limited to, steps S201 to S203:

[0096] Step S201: Extract features from the current user behavior data to obtain at least two user behavior features;

[0097] Step S202: Based on the user's individual profile and group profile, perform feature evaluation on the behavioral characteristics of each user to obtain feature evaluation data;

[0098] Step S203: At least two feature evaluation data are spliced ​​together to obtain anomaly evaluation data.

[0099] In step S201 of some embodiments, user behavior features can characterize the user's current behavior. Therefore, anomaly analysis is used for user behavior features, eliminating the need to analyze the entire current user behavior data and reducing the computational load of anomaly analysis.

[0100] In step S202 of some embodiments, each user behavior feature is evaluated by combining the user's personal profile and group profile to obtain feature evaluation data for each user behavior feature, and the feature evaluation data represents the probability that the user behavior feature belongs to abnormal behavior feature.

[0101] In step S203 of some embodiments, at least two feature evaluation data are concatenated into anomaly evaluation data. The concatenation of at least two feature evaluation data can be achieved by weighted summation or by direct summation or averaging. This embodiment does not impose specific restrictions on the concatenation method.

[0102] In steps S201 to S203 of this embodiment, at least two user behavior features are extracted from the current user behavior data, and feature evaluation is performed on each user behavior feature to obtain feature evaluation data for each user behavior feature. Finally, the at least two feature evaluation data are concatenated to form anomaly evaluation data. Therefore, when performing anomaly evaluation on the current user behavior data, only user behavior features are evaluated, without needing to evaluate the entire current user behavior data, reducing the computational load during evaluation and improving the computational efficiency of anomaly evaluation data.

[0103] Please see Figure 3In some embodiments, user behavior characteristics include: current login behavior characteristics and current order inquiry behavior characteristics; individual user profiles include: user login behavior profiles and user order inquiry behavior profiles; group profiles include: group login behavior profiles. It should be noted that current login behavior characteristics represent the target object's current login behavior, and current order inquiry behavior characteristics represent the target object's current order inquiry behavior. Therefore, by analyzing current login behavior characteristics using user login behavior profiles and group login behavior profiles, it is possible to determine whether the current login behavior differs significantly from historical login behavior and group login behavior. If the difference is too large, it can be considered abnormal login behavior. Simultaneously, by analyzing current order inquiry behavior characteristics using user order inquiry behavior profiles, it is possible to determine whether the current order inquiry behavior differs significantly from historical order inquiry behavior, thereby detecting abnormal order inquiry behavior.

[0104] Please see Figure 3 In some embodiments, step S202 may include, but is not limited to, steps S301 to S303:

[0105] Step S301: Based on the user login behavior profile and the group login behavior profile, evaluate the current login behavior characteristics to obtain login evaluation data;

[0106] Step S302: Based on the user's query behavior profile, evaluate the current query behavior characteristics to obtain query evaluation data;

[0107] Step S303: Construct feature evaluation data based on login evaluation data and order query evaluation data.

[0108] In step S301 of some embodiments, the group login behavior profile and the user login behavior profile have certain similarities. The current login behavior characteristics of the target object are evaluated by combining the user login behavior profile and the group login behavior profile to obtain login evaluation data. It should be noted that the login evaluation data characterizes the probability that the target object's current login behavior is abnormal, in order to analyze whether the account may be stolen from the perspective of login behavior.

[0109] In step S302 of some embodiments, to further analyze account misuse and improve the accuracy of abnormal user behavior detection, a user order inquiry behavior profile is used to evaluate the current order inquiry behavior characteristics. This is to analyze whether the target's current order inquiry behavior is abnormal and obtain order inquiry evaluation data. It should be noted that the order inquiry evaluation data represents the probability that the current order inquiry behavior characteristics belong to abnormal order inquiry behavior characteristics. Based on the order inquiry evaluation data, further analysis of whether the account has been misused is conducted, thereby improving the accuracy of abnormal user behavior detection.

[0110] In step S303 of some embodiments, login evaluation data and order query evaluation data are used as feature evaluation data to analyze whether there are any abnormalities in the current behavior of the target object from the perspectives of the target object's current login behavior and order query behavior. This can quickly and accurately analyze abnormal user behavior, improve the accuracy of abnormal user behavior detection, facilitate maintenance personnel to quickly maintain the information or resources managed by the target object, and reduce the possibility of information leakage.

[0111] In steps S301 to S303 of this embodiment, the current login behavior characteristics of the target object are evaluated by combining the user login behavior profile and the group login behavior profile, and the current order query behavior characteristics of the target object are evaluated by using the user order query behavior profile. Therefore, determining whether the target object has abnormal behavior based on its current login behavior and order query behavior can improve the accuracy of abnormal user behavior detection.

[0112] In some embodiments, the current login behavior characteristics include: current login address characteristics, current login component characteristics, current login device characteristics, and current login system characteristics. The user login behavior profile includes: historical login address characteristics, historical login component characteristics, historical login device characteristics, and historical login system characteristics. The group login behavior profile includes: group login address characteristics and group login device characteristics. It should be noted that the current login address characteristic represents the target object's current login address; the current login component characteristic represents the component used by the target object for current login; the current login device characteristic represents the device used by the target object for current login; and the current login system characteristic represents the system used by the target object for current login. The historical login address characteristic represents the target object's historical login address; the historical login component characteristic represents the component used by the target object for historical login; the historical login device characteristic represents the device used by the target object for historical login; and the historical login system characteristic represents the system used by the target object for historical login. The group login address characteristic represents the login address commonly used by other objects in the target object's group; and the group login device characteristic represents the device commonly used by other objects in the target object's group for login.

[0113] Please see Figure 4 In some embodiments, step S301 may include, but is not limited to, steps S401 to S405:

[0114] Step S401: Evaluate the current login address based on historical login address features and group login address features to obtain login address evaluation data;

[0115] Step S402: Evaluate the current login component based on the characteristics of historical login components to obtain login component evaluation data;

[0116] Step S403: Based on the characteristics of historical login devices and the characteristics of group login devices, evaluate the characteristics of the current login device to obtain login device evaluation data;

[0117] Step S404: Evaluate the current login system based on historical login system characteristics to obtain login system evaluation data;

[0118] Step S405: Construct login evaluation data based on login address evaluation data, login component evaluation data, login device evaluation data, and login system evaluation data.

[0119] In step S401 of some embodiments, the current login address features are evaluated by combining historical login address features and group login address features. Specifically, the current login address features are analyzed to determine whether they are the same as historical login address features and group login address features, so as to obtain login address evaluation data.

[0120] Specifically, login address evaluation data is set as address feature values, and historical login address features can be divided into historical login country features, historical login province features, and historical login city features. Group login address features can be divided into group login country features, group login province features, and group login city features. The current login address feature is compared with the historical login city features, group login city features, historical login province features, group login province features, historical login country features, and group login country features. If the current login address feature is different from either the historical or group login city features, the address feature value is determined to be 1; if it is different from either the historical or group login province features, the address feature value is determined to be 2; if it is different from either the historical or group login country features, the address feature value is determined to be 3. If the current login address feature is the same as any one of the following features: historical login city features, group login city features, historical login province features, group login province features, historical or group login country features, and group login country features, the address feature value is determined to be 0. It should be noted that address feature values ​​are used to characterize abnormal login behavior of the target object. The higher the address feature value, the more abnormal the login behavior.

[0121] In step S402 of some embodiments, there may be multiple current login component features. The current login component features are compared with historical login component features to obtain the number of components whose current login component features do not exist in the historical login component features, and this number is used as login component evaluation data. Specifically, the login component evaluation data is the component feature value, and the number of components currently used by the target object that do not exist in the historical login component features is used as the component feature value. If all current login component features exist in the historical login component features, the component feature value is 0. Therefore, the component feature value is used to characterize the degree of abnormality of the target object's component usage behavior. The higher the component feature value, the more abnormal the component currently used by the target object is.

[0122] In step S403 of some embodiments, the number of devices whose current login device characteristics do not exist in the historical login device characteristics is obtained as the first device count, and the number of devices whose current login device characteristics do not exist in the group login device characteristics is obtained as the second device count. Login device evaluation data is determined based on the first and second device counts. Specifically, the login device evaluation data is determined as device feature values, the first device count is defined as person_count, and the second device count is defined as group_count. The formula for calculating the device feature values ​​is: F new_device =person_count * 0.4 + group_count. It should be noted that device characteristic values ​​indicate abnormal login activity using the target device. The larger the device characteristic value, the more suspicious the login activity using that device is.

[0123] In step S404 of some embodiments, the number of systems whose current login system characteristics do not exist in the historical login system characteristics is obtained, and this number is used as login system evaluation data. It should be noted that the login system evaluation data is a system feature value, and the number of systems whose current login system characteristics do not exist in the historical login system characteristics is used as the system feature value. Therefore, the larger the system feature value, the more abnormal the system currently used by the target object for login is.

[0124] In step S405 of some embodiments, the login address evaluation data is the address feature value, the login component evaluation data is the component feature value, the login device evaluation data is the device feature value, and the login system evaluation data is the system feature value. The login evaluation data composed of the address feature value, component feature value, device feature value and system feature value can be obtained by weighted summation, or by summation and averaging. In this embodiment, there are no specific restrictions on the calculation method of the login evaluation data.

[0125] In steps S401 to S405 of this embodiment, by evaluating whether the current login behavior of the target object is abnormal by considering the address, components, device, and system at the time of login, abnormal login behavior can be detected more accurately.

[0126] Please see Figure 5 In some embodiments, the current order tracking behavior characteristics include: current out-of-period order tracking characteristics, current total order tracking volume characteristics, current out-of-period order tracking volume characteristics, historical waybill characteristics for items not picked up or delivered by the user, and current cross-regional order tracking characteristics; the user order tracking behavior profile includes: out-of-period order tracking rules, historical total order tracking volume characteristics, historical out-of-period order tracking volume characteristics, rules for waybills picked up or delivered by non-users, and historical cross-regional order tracking characteristics. Step S302 may include, but is not limited to, steps S501 to S506:

[0127] Step S501: Evaluate the current out-of-period order query characteristics based on the out-of-period order query rules to obtain out-of-period order query evaluation data.

[0128] Step S502: Evaluate the current total order volume characteristics based on the historical total order volume characteristics to obtain total order volume evaluation data;

[0129] Step S503: Evaluate the current out-of-period order inquiry volume based on the historical out-of-period order inquiry volume characteristics to obtain out-of-period order inquiry evaluation data;

[0130] Step S504: Based on the rules for non-owner-received delivery and pickup waybills, evaluate the characteristics of historical waybills for non-owner-received delivery and pickup to obtain non-owner-received waybill characteristic evaluation data.

[0131] Step S505: Evaluate the current cross-regional query characteristics based on historical cross-regional query characteristics to obtain cross-regional query evaluation data;

[0132] Step S506: Construct order inquiry assessment data based on out-of-period order inquiry assessment data, total order inquiry volume assessment data, out-of-period order inquiry assessment data, non-owner order characteristic assessment data, and cross-regional order inquiry assessment data.

[0133] In step S501 of some embodiments, the out-of-collection and delivery order query rule is a pre-set query rule, and the responsibility for out-of-collection and delivery order query is defined as whether the currently queried waybill is outside the collection and delivery period. If the currently queried waybill is outside the collection and delivery period, the query feature value is determined to be 1; otherwise, the query feature value is 0. Therefore, the out-of-collection and delivery order query feature is evaluated, that is, it is determined whether the current out-of-collection and delivery order query feature exists. If it exists, the out-of-collection and delivery order query evaluation data is determined to be 1.

[0134] In step S502 of some embodiments, the historical total order volume characteristics include the historical daily order volume average and the historical daily order volume standard deviation, and the current total order volume is the order volume within one day. It should be noted that a deviation range is constructed based on the historical daily order volume standard deviation and a preset multiple. The difference between the current total order volume characteristics and the historical daily order volume average is calculated, and the total order volume evaluation data is determined based on the difference and the deviation range.

[0135] Specifically, in this embodiment, if the current total order volume characteristic is between the historical daily average order volume and (historical daily average order volume + 10 * historical daily average order volume standard deviation), then the order query characteristic value is 1; if the current total order volume characteristic is between the historical daily average order volume and (historical daily average order volume + 20 * historical daily average order volume standard deviation), then the order query characteristic value is 2; otherwise, the order query characteristic value is 0. Therefore, the order query characteristic value characterizes the degree of abnormality of the target object's current order query behavior, and the larger the order query characteristic value, the more abnormal the order query behavior.

[0136] In step S503 of some embodiments, in addition to the total number of order inquiries, it is also necessary to further analyze the number of order inquiries outside the delivery period. This is achieved by comparing the current characteristics of order inquiries outside the delivery period with historical characteristics, to obtain order inquiry evaluation data outside the delivery period. This evaluation data characterizes the degree of abnormality in order inquiries by the target object outside the delivery period. Specifically, the historical characteristics of order inquiries outside the delivery period include the mean number of order inquiries outside the delivery period and the standard deviation of order inquiries outside the delivery period, and the order inquiry evaluation data is the order inquiry characteristic value. In this embodiment, if the current out-of-period tracking volume characteristic falls between the average out-of-period tracking volume of waybills and (average out-of-period tracking volume of waybills plus 10 * standard deviation of out-of-period tracking volume of waybills), the tracking characteristic value is determined to be 1. If the current out-of-period tracking volume characteristic falls between the average out-of-period tracking volume of waybills and (average out-of-period tracking volume of waybills plus 20 * standard deviation of out-of-period tracking volume of waybills), the tracking characteristic value is determined to be 2. Otherwise, the tracking characteristic value is 0. Therefore, the tracking characteristic value is determined by comparing the current out-of-period tracking volume characteristic with the average out-of-period tracking volume of waybills and the standard deviation of out-of-period tracking volume of waybills. This allows the tracking characteristic value to characterize the degree of abnormality in the target object's current tracking behavior. The higher the tracking characteristic value, the more abnormal the target object's out-of-period tracking behavior.

[0137] In step S504 of some embodiments, the rule for non-owner-collected and delivered waybills is pre-defined and used to analyze the degree of abnormality of non-owner-collected and delivered orders currently queried by the target object. Specifically, the rule for non-owner-collected and delivered waybills is: if the currently queried order is not a historical order collected and delivered by the owner, the query feature value is 1; otherwise, the query feature value is 0. Therefore, the non-owner-collected and delivered waybill feature is evaluated based on the non-owner-collected and delivered waybill rule, that is, it is determined whether the non-owner-collected and delivered historical waybill feature exists. If it exists, the query feature value is determined to be 1; otherwise, the query feature value is determined to be 0.

[0138] In step S505 of some embodiments, the current cross-regional order query feature indicates that the region to which the order account queried by the target object belongs is not within the order routing range, and the regional granularity is divided into branch, distribution, and regional. The higher the order query feature value, the more abnormal the account queried by the target object is. Historical cross-regional order query features include: historical cross-regional order query behavior features, historical cross-branch order query behavior features, and historical cross-branch order query behavior features. The current cross-regional order query feature is compared with the historical cross-branch order query behavior features, historical cross-branch order query behavior features, and historical cross-regional order query behavior features, respectively. If the current cross-regional order query feature belongs to the historical cross-regional order query behavior features, the order query feature value is 3; if the current cross-regional order query feature belongs to the historical cross-branch order query behavior features, the order query feature value is 2; if the current cross-regional order query feature belongs to the historical cross-branch order query behavior features, the order query feature value is 1; otherwise, the order query feature value is 0. Therefore, the query feature value is determined by detecting the area traversed by the query of the target object, so as to characterize the degree of anomaly of the query across the region by the query feature value.

[0139] In step S506 of some embodiments, the order inquiry assessment data is obtained by summing the order inquiry assessment data outside the collection and delivery period, the total order inquiry volume assessment data, the order inquiry assessment data outside the collection and delivery period, the non-personalized waybill characteristic assessment data, and the cross-regional order inquiry assessment data. Alternatively, the order inquiry assessment data can be obtained by weighted summing of the order inquiry assessment data outside the collection and delivery period, the total order inquiry volume assessment data, the non-personalized waybill characteristic assessment data, and the cross-regional order inquiry assessment data. This embodiment does not impose specific restrictions on the construction method of the order inquiry assessment data.

[0140] In steps S501 to S506 of this embodiment, the current order-checking behavior of the target object is evaluated from five aspects: order-checking outside the collection and delivery period, total order-checking volume, order-checking volume outside the collection and delivery period, historical waybills not belonging to the recipient, and cross-regional order-checking. This makes the evaluation of the target object's current order-checking behavior more accurate, and can accurately detect abnormal order-checking behavior.

[0141] Please see Figure 6 In some embodiments, step S106 includes, but is not limited to, steps S601 to S603:

[0142] Step S601: Sort the current user behavior data according to the anomaly assessment data to obtain the behavior sequence number;

[0143] Step S602: Filter the target sequence number from the row sequence number according to the preset number;

[0144] Step S603: Filter out abnormal behavior data from the current user behavior data according to the target sequence number.

[0145] In step S601 of some embodiments, this embodiment uses an anomaly sorting algorithm to find abnormal behavior data in the current user behavior data. Therefore, the current user behavior data is sorted in descending order of anomaly assessment data to obtain behavior serial numbers. It should be noted that the smaller the behavior serial number, the more abnormal the current user behavior data is, and vice versa.

[0146] In steps S602 to S603 of some embodiments, the preset number is a pre-defined quantity, i.e., a number of abnormal behavior data to be selected. Therefore, the behavior sequence number of the preset number of selected behaviors is used as the target sequence number, and the current user behavior data corresponding to the target sequence number is used as the abnormal behavior data. Alternatively, abnormal behavior data can be filtered from the current user behavior data based on abnormal assessment data and a preset abnormal threshold.

[0147] Specifically, after sorting the current user behavior data according to the anomaly assessment data, N of the most suspicious (ranked first) current user behavior data are selected as abnormal behavior data.

[0148] In steps S601 to S603 of this embodiment, the current user behavior data is sorted according to the abnormal assessment data, and a preset number of the current user behavior data with the highest ranking are selected as abnormal behavior data, thereby improving the accuracy of abnormal behavior detection.

[0149] Please see Figure 7 In some embodiments, after step S106, the user abnormal behavior detection method may also include, but is not limited to, steps S701 to S702:

[0150] Step S701: Extract features from the abnormal behavior data to obtain abnormal behavior features;

[0151] Step S702: Warning information is generated based on preset warning rules and abnormal behavior characteristics to obtain warning prompt information. In some embodiments, steps S701 to S702 first extract abnormal behavior characteristics from abnormal behavior data, and these abnormal behavior characteristics can represent at least one of login abnormal characteristics and order query abnormal characteristics. Then, warning prompt information is generated based on the warning rules and abnormal behavior characteristics. Since the warning prompt information corresponds to the abnormal behavior characteristics, maintenance personnel can easily understand the current abnormal situation of the target object through the warning prompt information, facilitating targeted maintenance operations, reducing the possibility of information leakage, and improving information security.

[0152] In steps S701 to S702 of this embodiment, early warning information is generated according to the early warning rules and abnormal behavior characteristics. The generated early warning information corresponds to the abnormal behavior characteristics, so that operation and maintenance personnel can know the current abnormal behavior of the target object through the early warning information and take timely operation and maintenance actions.

[0153] Please see Figure 8 This application also provides a user abnormal behavior detection device, which can implement the above-described user abnormal behavior detection method. The device includes:

[0154] The log data acquisition module 801 is used to acquire user log data of the target object and group login log data of the group to which the target object belongs; wherein, the user log data includes: user login log data and user query log data, and the behavior of the target object is similar to the behavior of other objects in the group;

[0155] The personal profile building module 802 is used to build a profile based on user login log data and user query log data to obtain a user's personal profile.

[0156] The group profile building module 803 is used to build profiles based on group login log data to obtain group profiles;

[0157] The behavior data acquisition module 804 is used to acquire the current user behavior data of the target object;

[0158] Anomaly assessment module 805 is used to perform anomaly assessment on current user behavior data based on individual user profiles and group profiles, and obtain anomaly assessment data.

[0159] The data filtering module 806 is used to filter out abnormal behavior data from the current user behavior data based on the abnormality assessment data.

[0160] The specific implementation of this user abnormal behavior detection device is basically the same as the specific implementation of the user abnormal behavior detection method described above, and will not be repeated here.

[0161] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned method for detecting abnormal user behavior. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0162] Please see Figure 9 , Figure 9 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes:

[0163] The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0164] The memory 902 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the user abnormal behavior detection method of the embodiments of this application.

[0165] The input / output interface 903 is used to implement information input and output;

[0166] The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0167] Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904);

[0168] The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0169] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for detecting abnormal user behavior.

[0170] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0171] The user abnormal behavior detection method, apparatus, electronic device, and storage medium provided in this application construct a user profile by using user login log data and user order query log data of the target object, and then construct a group profile based on the group login log data of the target object's group. The user profile and the group profile are used to perform anomaly assessment on the current user behavior data to obtain more accurate anomaly assessment data. This allows for the selection of abnormal behavior data from the current user behavior data based on the anomaly assessment data, making the selection of abnormal behavior data more accurate and improving the accuracy of user abnormal behavior detection.

[0172] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0173] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0174] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0175] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0176] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0177] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0178] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0179] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0180] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0181] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0182] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for detecting abnormal user behavior, characterized in that, The method includes: Obtain user log data of the target object and group login log data of the group to which the target object belongs; wherein, the user log data includes: user login log data and user query log data, and the behavior of the target object is similar to the behavior of other objects in the group; A user profile is constructed based on the user login log data and the user query log data. A profile is constructed based on the group login log data to obtain a group profile; Obtain the current user behavior data of the target object; Based on the individual user profile and the group profile, an anomaly assessment is performed on the current user behavior data to obtain anomaly assessment data. Abnormal behavior data is filtered out from the current user behavior data based on the abnormality assessment data.

2. The method according to claim 1, characterized in that, The anomaly assessment of current user behavior data based on the individual user profile and the group profile yields anomaly assessment data, including: Feature extraction is performed on the current user behavior data to obtain at least two user behavior features; Based on the individual user profile and the group profile, feature evaluation is performed on each user behavior feature to obtain feature evaluation data; The anomaly assessment data is obtained by concatenating at least two of the feature assessment data.

3. The method according to claim 2, characterized in that, The user behavior characteristics include: current login behavior characteristics and current order inquiry behavior characteristics; the individual user profile includes: user login behavior profile and user order inquiry behavior profile; the group profile includes: group login behavior profile. The feature evaluation is performed on each user behavior feature based on the individual user profile and the group profile to obtain feature evaluation data, including: Based on the user login behavior profile and the group login behavior profile, the current login behavior characteristics are evaluated to obtain login evaluation data. Based on the user's query behavior profile, the current query behavior characteristics are evaluated to obtain query evaluation data. The feature evaluation data is constructed based on the login evaluation data and the order query evaluation data.

4. The method according to claim 3, characterized in that, The current login behavior characteristics include: current login address characteristics, current login component characteristics, current login device characteristics, and current login system characteristics; the user login behavior profile includes: historical login address characteristics, historical login component characteristics, historical login device characteristics, and historical login system characteristics; and the group login behavior profile includes: group login address characteristics and group login device characteristics. The login feature evaluation is performed on the current login behavior features based on the user login behavior profile and the group login behavior profile to obtain login evaluation data, including: Based on the historical login address characteristics and the group login address characteristics, the current login address characteristics are evaluated to obtain login address evaluation data. Based on the historical login component characteristics, the current login component characteristics are evaluated to obtain login component evaluation data; Based on the historical login device characteristics and the group login device characteristics, the current login device characteristics are evaluated to obtain login device evaluation data. Based on the historical login system characteristics, the current login system characteristics are evaluated to obtain login system evaluation data; The login evaluation data is constructed based on the login address evaluation data, the login component evaluation data, the login device evaluation data, and the login system evaluation data.

5. The method according to claim 3, characterized in that, The current order tracking behavior characteristics include: current order tracking characteristics outside the current pickup and delivery period, current total order tracking volume characteristics, current order tracking volume outside the current pickup and delivery period characteristics, historical waybill characteristics for items not picked up or delivered by the user, and current cross-regional order tracking characteristics; the user order tracking behavior profile includes: order tracking rules outside the pickup and delivery period, historical total order tracking volume characteristics, historical order tracking volume outside the pickup and delivery period characteristics, rules for waybills picked up or delivered by non-users, and historical cross-regional order tracking characteristics; Based on the user's order inquiry behavior profile, the current order inquiry behavior characteristics are evaluated to obtain order inquiry evaluation data, including: Based on the rules for checking orders outside the delivery period, the current characteristics of checking orders outside the delivery period are evaluated to obtain evaluation data for checking orders outside the delivery period. Based on the historical total query volume characteristics, the current total query volume characteristics are evaluated to obtain total query volume evaluation data; Based on the historical out-of-period order inquiry volume characteristics, the current out-of-period order inquiry volume characteristics are evaluated to obtain out-of-period order inquiry evaluation data. Based on the rules for non-owner-received delivery and pickup waybills, the characteristics of the historical delivery and pickup waybills of non-owner-received delivery and pickup are evaluated to obtain non-owner-received waybill characteristic evaluation data. Based on the historical cross-regional query characteristics, the current cross-regional query characteristics are evaluated to obtain cross-regional query evaluation data. The order inquiry assessment data is constructed based on the order inquiry assessment data outside the collection and delivery period, the total order inquiry volume assessment data, the order inquiry assessment data outside the collection and delivery period, the non-personalized waybill characteristic assessment data, and the cross-regional order inquiry assessment data.

6. The method according to any one of claims 1 to 5, characterized in that, The step of filtering abnormal behavior data from the current user behavior data based on the abnormality assessment data includes: The current user behavior data is sorted based on the anomaly assessment data to obtain a behavior sequence number; Target numbers are selected from the behavior numbers according to a preset number; Abnormal behavior data is filtered from the current user behavior data based on the target sequence number.

7. The method according to any one of claims 1 to 5, characterized in that, After filtering out abnormal behavior data from the current user behavior data based on the abnormality assessment data, the method further includes: Feature extraction is performed on the abnormal behavior data to obtain abnormal behavior features; Warning information is generated based on preset warning rules and the abnormal behavior characteristics, resulting in warning prompts.

8. A user abnormal behavior detection device, characterized in that, The device includes: The log data acquisition module is used to acquire user log data of the target object and group login log data of the group to which the target object belongs; wherein, the user log data includes: user login log data and user query log data, and the behavior of the target object is similar to the behavior of other objects in the group; The personal profile building module is used to build a profile based on the user login log data and the user query log data to obtain a user personal profile. The group profile building module is used to build a profile based on the group login log data to obtain a group profile. The behavior data acquisition module is used to acquire the current user behavior data of the target object; Anomaly assessment module is used to assess the current user behavior data based on the user's individual profile and the group profile, and obtain anomaly assessment data; The data filtering module is used to filter out abnormal behavior data from the current user behavior data based on the abnormality assessment data.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the user abnormal behavior detection method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the user abnormal behavior detection method according to any one of claims 1 to 7.