E-mail processing method and storage medium
By combining detection strategies from local and cloud servers, and utilizing rapid local filtering and deep cloud scanning, the detection challenges caused by the complexity of email structures in existing technologies have been solved. This has enabled efficient and accurate filtering of abnormal emails, reduced resource consumption, and improved the comprehensiveness of detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2024-11-21
- Publication Date
- 2026-05-22
AI Technical Summary
In the existing technology, the complex and diverse structure of emails makes it difficult for local filtering strategies to effectively deal with abnormal emails, and the rampant use of network resources makes it easy for abnormal emails to spread. The effectiveness and coverage of existing local filtering methods are not high.
Combining detection strategies from local and cloud servers, a small-scale, pre-defined database of abnormal email features is deployed locally for initial filtering. If the email is normal, it is sent to the cloud for in-depth scanning. A high-precision detection service is deployed in the cloud to comprehensively determine the email category and decide whether to deliver it.
It enables comprehensive, accurate, and rapid detection of abnormal emails, reducing the probability of users receiving abnormal emails, improving the reliability, flexibility, and scalability of email processing, and reducing the consumption of local network and computing resources.
Smart Images

Figure CN122073533A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to an email processing method and storage medium. Background Technology
[0002] With the rapid development of the internet age, the internet has provided various types of channels and media for exchanging emails between different users. Emails no longer rely on simple text transmission, but have evolved into more complex formats with mixed text and images, embedded attachments, QR codes, traditional Chinese characters, variant characters, and other complex structures, gradually showing a trend of diversification and complexity.
[0003] Current technologies often rely on local filtering to filter abnormal emails. However, with the increasing complexity and diversity of email structures, content parsing becomes more difficult and resource-intensive, rendering local filtering strategies ineffective. Furthermore, the increasing abundance of network resources and the lower cost of acquiring massive amounts of network addresses and domain names have facilitated the spread of abnormal emails through the unchecked and malicious exploitation of these public resources. Attackers constantly change new network addresses, accounts, and domains to spread abnormal emails in bulk, resulting in low effectiveness and coverage of existing local filtering methods. Summary of the Invention
[0004] This application provides an email processing method and storage medium that can comprehensively, accurately, and quickly detect abnormal emails, reducing the probability of users receiving abnormal emails.
[0005] On the one hand, this application provides an email processing method applied to a local server, the method comprising:
[0006] Obtain the target email;
[0007] Extract the target email features of the target email, and determine the matching result of the target email features based on a preset abnormal email feature library. Determine the first category identifier of the target email based on the matching result. The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails. The target email features include multiple types of target attribute features of the target email.
[0008] If the first category identifier indicates that the target email is a normal email, an email category detection request is sent to the cloud server; the email category detection request carries the characteristics of the target email.
[0009] The system receives a second category identifier sent by the cloud server. The second category identifier is obtained by the cloud server through email category detection of each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature. The preset cloud detection strategy is determined by the cloud server based on the type of each target attribute feature included in the target email feature in the received email category request.
[0010] If the second category identifier indicates that the target email is a normal email, the target email is sent to the target recipient account.
[0011] On the other hand, an email processing method is provided for use on a cloud server, the method comprising:
[0012] The system receives an email category detection request from a local server. This request carries target email features. The local server retrieves the target email, extracts its target email features, determines a matching result based on a preset abnormal email feature library, identifies a first category identifier for the target email based on the matching result, and sends the request to the cloud server when the first category identifier indicates the target email is a normal email. The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails. The target email features include various types of target attribute features of the target email.
[0013] Based on the type of each target attribute feature in the target email features, a preset cloud detection strategy corresponding to each target attribute feature is determined;
[0014] Based on a preset cloud detection strategy corresponding to each target attribute feature, email category detection is performed on each target attribute feature to obtain the second category identifier of the target email;
[0015] The second category identifier is sent to the local server so that the local server sends the target email to the target recipient account when the second category identifier indicates that the target email is a normal email.
[0016] On the other hand, an email processing apparatus is provided, which is applied to a local server, and the apparatus includes:
[0017] The email retrieval module is used to retrieve target emails;
[0018] A local email feature matching module is used to extract target email features from the target email, determine the matching result of the target email features based on a preset abnormal email feature library, and determine the first category identifier of the target email based on the matching result; the preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails; the target email features include multiple types of target attribute features of the target email;
[0019] The detection request sending module is used to send an email category detection request to the cloud server if the first category identifier indicates that the target email is a normal email; the email category detection request carries the characteristics of the target email.
[0020] A category identifier receiving module is used to receive a second category identifier sent by the cloud server; the second category identifier is obtained by the cloud server through email category detection of each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature, and the preset cloud detection strategy is determined by the cloud server based on the type of each target attribute feature included in the target email feature in the received email category request;
[0021] The email delivery module is used to send the target email to the target recipient account if the second category identifier indicates that the target email is a normal email.
[0022] On the other hand, an email processing device is provided, which is applied to a cloud server, and the device includes:
[0023] A detection request receiving module is used to receive email category detection requests sent by a local server. The email category detection request carries target email features. The local server obtains the target email, extracts its target email features, determines the matching result of the target email features based on a preset abnormal email feature library, determines a first category identifier for the target email based on the matching result, and sends the request to the cloud server when the first category identifier indicates that the target email is a normal email. The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails. The target email features include various types of target attribute features of the target email.
[0024] The preset cloud detection strategy determination module is used to determine the preset cloud detection strategy corresponding to each target attribute feature based on the type of each target attribute feature in the target email features;
[0025] The email category detection module is used to perform email category detection on each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature, and to obtain the second category identifier of the target email;
[0026] The category identifier sending module is used to send the second category identifier to the local server, so that the local server sends the target email to the target recipient account when the second category identifier indicates that the target email is a normal email.
[0027] On the other hand, a local server is provided, the local server including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the email processing method as described above.
[0028] On the other hand, a cloud server is provided, which includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the email processing method described above.
[0029] On the other hand, an email processing system is provided, which includes a local server and a cloud server;
[0030] The local server is configured to: acquire the target email; extract target email features from the target email, determine the matching result of the target email features based on a preset abnormal email feature library, and determine a first category identifier for the target email based on the matching result; the preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails; the target email features include multiple types of target attribute features of the target email; and if the first category identifier indicates that the target email is a normal email, send an email category detection request to the cloud server; the email category detection request carries the target email features; receive a second category identifier sent by the cloud server; and if the second category identifier indicates that the target email is a normal email, send the target email to the target recipient account.
[0031] The cloud server is configured to receive email category detection requests sent by the local server, determine a preset cloud detection strategy corresponding to each target attribute feature based on the type of each target attribute feature in the target email features, perform email category detection on each target attribute feature based on the preset cloud detection strategy corresponding to each target attribute feature to obtain a second category identifier for the target email, and send the second category identifier to the local server.
[0032] On the other hand, a computer storage medium is provided that stores at least one instruction or at least one program, which is loaded and executed by a processor to implement the email processing method described above.
[0033] On the other hand, a computer program product or computer program is provided, which includes computer instructions stored in a computer storage medium. A processor of a computer device reads the computer instructions from the computer storage medium, executes the computer instructions, and causes the computer device to perform the email processing method described above.
[0034] The email processing method and storage medium provided in this application have the following technical advantages:
[0035] This application embodiment filters target emails locally to obtain a first category identifier. When the first category identifier indicates that the target email is abnormal, it is directly blocked. When the first category identifier indicates that the target email is normal, the target email's characteristics are sent to a cloud server for further detection. The application then receives a second category identifier from the cloud server. If the second category identifier indicates that the target email is normal, it is delivered normally; otherwise, it is blocked. By combining local and cloud detection, the local server can deploy only a small, pre-defined abnormal email feature library for rapid matching, filtering, and blocking, while the cloud server deploys a more accurate abnormal email detection service to ensure comprehensiveness and accuracy. Furthermore, this combination reduces local network bandwidth and computing resource consumption, allowing for flexible configuration and management of emails based on needs and available local resources, thus improving the reliability, flexibility, and scalability of email processing. Therefore, the method provided in this application can comprehensively, accurately, and quickly detect abnormal emails, reducing the probability of users receiving such emails. Attached Figure Description
[0036] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0037] Figure 1 This is a schematic diagram of an email processing system provided in an embodiment of this application;
[0038] Figure 2 This is a flowchart illustrating an email processing method provided in an embodiment of this application;
[0039] Figure 3 This is a flowchart illustrating the local abnormal email filtering method provided in the embodiments of this application;
[0040] Figure 4 This is a schematic diagram of the process for extracting target email features provided in an embodiment of this application;
[0041] Figure 5 This is a schematic diagram illustrating the process of a local server sending an email category detection request to the cloud in an embodiment of this application;
[0042] Figure 6 This is a schematic diagram of the training process of the preset cloud detection model provided in the embodiments of this application;
[0043] Figure 7 This is a schematic diagram of a training process based on an XGBoost model provided in an embodiment of this application;
[0044] Figure 8 This is an overall architecture diagram of the email processing method provided in the embodiments of this application;
[0045] Figure 9 This is a schematic diagram of the structure of an email processing device provided in an embodiment of this application;
[0046] Figure 10 This is a schematic diagram of the structure of an email processing device provided in an embodiment of this application. Detailed Implementation
[0047] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0048] It is understood that in the specific implementation of this application, data such as whitelists are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0049] It should be noted that the terms "first," "first," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0050] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0051] Please see Figure 1 , Figure 1 This is a schematic diagram of an email processing system provided in an embodiment of this application; abnormal emails, or spam, refer to unnecessary or fraudulent emails sent to users without request or authorization. The purpose of abnormal email filtering is to reduce the number of abnormal emails received by users and improve the quality and efficiency of emails. Figure 1 As shown, the email processing system may include at least a local server 100, a cloud server 200, and a terminal 300.
[0052] Local server 100 is equipped with an abnormal email detection service for detecting abnormal emails in incoming mail. Local server 100 provides rich local email filtering strategies for rapid filtering of abnormal emails. Emails marked as abnormal after filtering are sent to a local email interception service for interception; emails marked as normal are sent to cloud server 200. Cloud server 200 is equipped with a cloud-based abnormal email detection service for performing a secondary deep scan of emails sent from the local server and returning the scan results to local server 100. Local server 100 then intercepts or delivers the email locally based on the returned scan results. Terminal 300 can be the device where the target email address is located. After local interception, the email will be placed in the target email address's spam folder, rejected, or deleted directly, ultimately achieving local interception of abnormal emails and delivery of normal emails to the target email address.
[0053] It should be noted that the local server 100 in this application can be an internal enterprise server, with an email system owned and managed by the enterprise. The local server can also be a Virtual Private Server (VPS) or a dedicated server hosted on behalf of a third-party service provider.
[0054] Local server 100 can be a standalone physical server, or a server cluster or distributed system consisting of multiple physical servers. Cloud server 200 can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0055] Terminal 300 may include, but is not limited to, electronic devices such as smartphones, desktop computers, tablets, laptops, smart speakers, digital assistants, augmented reality (AR) / virtual reality (VR) devices, smart wearable devices, in-vehicle terminals, and smart TVs; it may also be software running on the aforementioned electronic devices, such as applications and mini-programs. In this embodiment, the operating system running on the electronic device may include, but is not limited to, Android, iOS, Linux, and Windows.
[0056] The following describes an email processing method based on the aforementioned system. Figure 2This is a flowchart illustrating an email processing method provided in an embodiment of this application. This specification provides the operational steps of the method as described in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operational steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only execution order. In actual system or server product execution, the methods shown in the embodiments or drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown... Figure 2 As shown, the method may include:
[0057] S201: The local server retrieves the target email.
[0058] The target email is an email received by the local server. Before delivering the target email to the target recipient's mailbox, local abnormal email filtering is performed first.
[0059] S203: The local server extracts the target email features of the target email and determines the matching result of the target email features based on the preset abnormal email feature library, and determines the first category identifier of the target email based on the matching result.
[0060] The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails; the target email features include various types of target attribute features of the target email.
[0061] Because email data is diverse and varied, it is impossible to detect the entire target email. Therefore, this application first extracts target email features from the target email according to a preset extraction strategy. The preset extraction strategy can be divided into several types, and correspondingly, the target email features can include various types of target attribute features. It should be noted that target email features can be extracted from the email header or the email body of the target email.
[0062] The preset abnormal email feature library includes various types of preset abnormal email features. These features can be manually set in advance or are characteristics of emails historically marked as abnormal. Emails marked as abnormal can be determined based on user feedback or manually.
[0063] The system searches the preset abnormal email feature database to see if the target email features exist, or to see if there are features similar to the target email features. If a match is found, the first category identifier indicates that the target email is an abnormal email, and the target email is blocked using the local interception service. If a match fails, the first category identifier indicates that the target email is a normal email, and the next filtering step is performed.
[0064] S205: If the first category identifier indicates that the target email is a normal email, the local server sends an email category detection request to the cloud server.
[0065] The email category detection request carries the characteristics of the target email. It should be noted that the email category detection request may also include the email identifier of the target email, used to uniquely identify the target email.
[0066] S207: The cloud server determines the preset cloud detection strategy corresponding to each target attribute feature based on the type of each target attribute feature in the target email features.
[0067] S209: The cloud server performs email category detection on each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature, and obtains the second category identifier of the target email.
[0068] After receiving an email category detection request from the local server, the cloud server matches the target email features carried in the request with a corresponding preset cloud detection strategy to perform email category detection on each target attribute feature and determine whether the target email is a normal email.
[0069] It should be noted that the preset cloud detection strategy corresponds one-to-one with the target attribute features. Therefore, after performing email category detection on each target attribute feature based on the preset cloud detection strategy corresponding to each target attribute feature and obtaining multiple detection results, the multiple detection results are then comprehensively judged to obtain the second category identifier.
[0070] S211: The cloud server sends a second category identifier to the local server.
[0071] It should be noted that the cloud server can also send the email identifier of the target email at the same time, so that the local server can determine the email corresponding to the second category identifier based on the email identifier.
[0072] S213: If the second category identifier indicates that the target email is a normal email, the local server will send the target email to the target recipient account.
[0073] After receiving the second category identifier from the cloud server, the local server will either intercept the target email locally or deliver it normally based on the identifier. If the second category identifier indicates that the target email is a normal email, the local server will send the target email to the target recipient account; otherwise, the target email will be intercepted locally.
[0074] As can be seen from the technical solutions provided in the embodiments of this specification above, the embodiments of this application perform local email filtering on the target email to obtain a first category identifier. When the first category identifier indicates that the target email is an abnormal email, it is directly blocked. When the first category identifier indicates that the target email is a normal email, the target email features of the target email are sent to the cloud server for further detection, and the second category identifier obtained by the cloud server is received. When the second category identifier indicates that the target email is a normal email, it is delivered normally; otherwise, it is blocked. By combining local and cloud detection, the local server can deploy only a small-scale preset abnormal email feature library for fast matching, filtering, and blocking, while the cloud server deploys a more accurate abnormal email detection service to ensure the comprehensiveness and accuracy of the detection. At the same time, by combining local and cloud detection, the consumption of local network bandwidth and computing resources can be reduced, and emails can be flexibly configured and managed according to needs and actual local resources, improving the reliability, flexibility, and scalability of email processing. Therefore, the method provided by this application can comprehensively, accurately, and quickly detect abnormal emails, reducing the probability of users receiving abnormal emails.
[0075] Figure 3 This is a flowchart illustrating the local abnormal email filtering method provided in an embodiment of this application. In one embodiment, before the local server extracts the target email characteristics, the method further includes:
[0076] S301: The local server parses the target email header information to obtain the target sending server information and the target sending subject.
[0077] Email consists of a header and a body. The header includes the sender's email address, the recipient's email address, and the subject. In an email distribution system, sending an email requires the sender's email address's sending server to the recipient's email address's receiving server, and then the receiving server forwards the email to the recipient's email address. In this application, the local server can be considered as the receiving server. Therefore, by parsing the target email's header information, the target sending server information and the target subject can be obtained.
[0078] S303: The local server checks whether the target sending server information and the target sending subject are within the preset whitelist, and obtains the whitelist detection result of the target email.
[0079] It's important to note that whitelist checks can be performed on preset whitelists corresponding to receiving email addresses. Different receiving email addresses can have different preset whitelists. For example, administrators can set preset whitelists for their own email addresses, while users can set preset whitelists for their own email addresses. Both administrator and user preset whitelists can be set and managed according to their own business transactions to meet personalized sending and receiving needs. Preset whitelists can be set manually based on requirements or automatically based on the sender's and recipient's historical email history, thus ensuring that important emails are not blocked.
[0080] Furthermore, the preset whitelist can include multiple dimensions. In one embodiment, the local server detects whether the target sending server information and the target sending subject are within the preset whitelist to obtain the whitelist detection result of the target email, which can include:
[0081] The local server retrieves a preset whitelist, which records multiple preset mail sending server information and multiple preset keywords. The local server matches the target mail sending server information with the multiple preset mail sending server information to obtain the first whitelist matching result. The local server matches the target email subject with the multiple preset keywords to obtain the second whitelist matching result. If at least one of the first whitelist matching result and the second whitelist matching result is a match, the local server determines that the target email has passed the whitelist check and sends the target email to the target recipient account. If both the first whitelist matching result and the second whitelist matching result indicate a match failure, the local server determines that the target email has not passed the whitelist check.
[0082] In one example, assuming the target mail server's domain name is A, and the preset mail server information includes domain names A, B, and C, then it can be determined that the target email passes the whitelist check and can be delivered normally. However, if both the first and second whitelist matching results fail, it means the target email does not meet the whitelist requirements, and further filtering is needed.
[0083] It should be noted that, in addition to preset mailing server information and preset keywords, the preset whitelist can also include other dimensions, which can be set according to actual needs.
[0084] In this embodiment, the local server performs multi-dimensional whitelist matching detection on the target emails to ensure that important emails that pass the whitelist detection can be delivered directly, while target emails that fail the whitelist detection are filtered for abnormal emails at the next level, thereby improving the processing efficiency of emails.
[0085] S305: If the whitelist detection result indicates that the target email has not passed the whitelist detection, the local server determines the third category identifier of the target email based on the target sending server information.
[0086] In one embodiment, the target sending server information includes the target sending domain name and the target sending network address. The local server determines the third category identifier of the target email based on the target sending server information, which may include: the local server determining a sending frequency detection result based on the cumulative sending frequency of the target sending server within a preset time period and a preset frequency threshold; wherein the target sending server corresponds to the target sending server information; the local server determining a sender identity detection result based on the target sending network address and a preset sending network address record; wherein the preset sending network address record corresponds to the target sending domain name; the local server determining a sender credibility detection result based on the credibility of the target sending server and a preset credibility threshold; and the local server determining the third category identifier based on the above sending frequency detection result, the above sender identity detection result, and the above sender credibility detection result.
[0087] If the target email fails the whitelist check, the system performs sending frequency detection, sender identity detection, and sender credibility detection based on the target mail server information. Sending frequency detection is primarily based on the sender account, the sending network address (IP) corresponding to the target mail server, and the sending domain. If the cumulative frequency of sending behavior in any one dimension exceeds the set range, the target email is identified as an abnormal email by a third-category identifier. This strategy effectively prevents bulk abnormal email attacks and protects the stable operation of system services. Sender identity detection is based on the Domain Name System (DNS) settings of the sending domain to check and filter forged and non-standard emails. When setting the email domain, the domain is associated with a sending network address record. The sending IP in the sending network address record is the IP authorized to use the email domain. By checking whether the target sending network address displayed in the email header is in the preset sending network address record, it can be determined whether the target email is a forged email. Email credibility detection checks the reputation of the target email server based on its IP address, account, and domain name. It quickly filters email servers that have a history of sending spam or malicious emails, blocking abnormal emails from entering the mail at the source.
[0088] In this embodiment, multiple forms of detection targeting the sending server, such as sending frequency detection, sending identity detection, and sending credibility detection, are used to quickly filter all abnormal emails, thereby effectively improving the effectiveness and coverage of local email filtering.
[0089] S307: If the third category identifier indicates that the target email is a normal email, the local server extracts the target email features of the target email.
[0090] In this embodiment, before extracting the target email features, the local server first performs two layers of filtering: whitelist detection and target sending server detection. This achieves multi-level email detection and filtering on the local server. After the above-mentioned filtering, if the target email is identified as an abnormal email, it is directly blocked; if the target email is still identified as a normal email, the target email features are further extracted for more refined email detection, thereby improving the efficiency of email processing.
[0091] Figure 4 This is a flowchart illustrating the process of extracting target email features according to an embodiment of this application. In one embodiment, the target email includes target email header information and target email body information. The local server extracts the target email features of the target email, which may include:
[0092] S401: The local server extracts the target sending attribute features corresponding to the target sending server from the target email header information.
[0093] In one embodiment, the local server extracts the target sending attribute features corresponding to the target sending server from the target email header information, which may include: obtaining the location information of the target sending server in the target email header information; obtaining the cumulative number of historical emails received and the cumulative number of abnormal emails sent by the target sending server; the cumulative number of abnormal emails being the number of historical emails identified as abnormal; and determining the aforementioned location information, cumulative number of received emails, and cumulative number of abnormal emails as the target sending attribute features.
[0094] The target email's attribute characteristics can be features at the recipient and sender levels, such as the number of recipients on the whitelist, the number of emails sent by the sender that have been reported as abnormal, or features at the network address level, such as location information, the level of suspicious network addresses, or even at the domain level, such as the cumulative number of historical emails received corresponding to the domain of the target email, or the uniqueness of the sending domain.
[0095] In this embodiment, multiple features are extracted from the header information of the target email to facilitate subsequent local feature matching from multiple dimensions, making the detection of emails more comprehensive.
[0096] S403: The local server extracts the target content attribute features corresponding to the target email body information.
[0097] In one embodiment, extracting the target content attribute features corresponding to the target email body information may include: parsing the target email body information to obtain email metadata; extracting target statistical attributes from the email metadata; the target statistical attributes include at least one of the following: the number of abnormal characters, the number of hyperlinks, and the number of images; extracting target text features from the email metadata; the target text features include at least one of the following: the text vector corresponding to the body text, the text vector corresponding to the text in the image, and the text vector corresponding to the text in the attachment; and determining the target statistical attributes and the target text features as target content attribute features.
[0098] Email metadata comprises the components of the email body, including but not limited to the body text, hyperlinks, images, and attachments. Target content attribute features can be features dimensional to the email content itself. Besides the aforementioned abnormal character count, hyperlink count, and image count, they can also include content category (e.g., meeting notifications, business introductions), content blocking rates, and hyperlink blocking rates. Target text features can be transformed into text vectors using a pre-defined text vector model. This pre-defined text vector model can be an existing technology, such as a Transformer model. It should be noted that target statistical attributes can be combined attribute features, such as the percentage of senders whose emails are flagged as abnormal, or the ratio of abnormal characters to the total number of characters in the body text.
[0099] In this embodiment, multiple features are extracted from the target email body information to facilitate subsequent local feature matching from multiple dimensions, making the detection of emails more comprehensive.
[0100] S405: The local server determines the target email characteristics as the target sending attribute characteristics and the target content attribute characteristics.
[0101] Through the above embodiments, the target email features can include various types of target attribute features such as target sending attribute features, target statistical attributes, and target text features. In this embodiment, by extracting various types of target attribute features for subsequent local feature matching and cloud feature detection, email detection becomes more comprehensive and accurate.
[0102] In the above embodiments, the target email features may include at least one of target sending attribute features, target statistical attributes, and target text features. Accordingly, determining the matching result of the target email features based on the preset abnormal email feature library, and determining the first category identifier of the target email based on the matching result, may include: receiving the preset abnormal email feature library sent by the cloud server; matching the target sending attribute features with the preset abnormal email features in the preset abnormal email feature library to obtain a first feature matching result corresponding to the target sending attribute features; matching the target statistical attributes with the preset abnormal email features in the preset abnormal email feature library to obtain a second feature matching result corresponding to the target statistical attributes; matching the target text features with the preset abnormal email features in the preset abnormal email feature library to obtain a third feature matching result corresponding to the target text features; and determining the first category identifier based on at least one of the first feature matching result, the second feature matching result, and the third feature matching result.
[0103] In this embodiment, the target email sending attribute features, target statistical attributes, and target text features are matched with preset abnormal email features in a preset abnormal email feature library. If a match is found, it indicates that the target email has the email features of an abnormal email, and therefore the first category identifier can be used to characterize the target email as an abnormal email. By matching the extracted email features with the preset abnormal email feature library, the accuracy of email detection by the local server is improved.
[0104] In one embodiment, a preset abnormal email feature database can be built by a cloud server and then distributed to a local server, enabling the local server to perform local feature batch matching. Specifically, the method for building the preset abnormal email feature database may include:
[0105] The cloud server identifies the characteristics of abnormal emails within a preset historical time period as sample email characteristics; the cloud server determines the confidence level of the sample email characteristics based on the cumulative number of occurrences of the sample email characteristics; the cloud server identifies sample email characteristics with a confidence level greater than or equal to a preset confidence threshold as preset abnormal email characteristics, and forms a preset abnormal email characteristic library based on the preset abnormal email characteristics; the cloud server sends the preset abnormal email characteristic library to the local server.
[0106] The preset historical time period can be one week, one month, etc., and can be set according to actual needs. This application does not limit the specific value of the preset historical time period. Abnormal emails within the preset historical time period can be manually labeled or reported by users. Email features of these abnormal emails are extracted and used as sample email features. By counting the frequency of each sample email feature, sample email features with a frequency greater than or equal to a preset threshold can be set to a higher confidence level, while sample email features with a frequency less than the preset threshold can be set to a lower confidence level.
[0107] In this embodiment, the cloud server can form a preset abnormal email feature library by representing sample emails that appear more than or equal to a preset threshold number of times, and then distribute it to the local server. This avoids deploying a large feature library on the local server and saves local server resources.
[0108] It should be noted that when the cloud server distributes the preset abnormal email feature database, it can encrypt the database to improve data security.
[0109] When the local server determines that the first category identifier indicates that the target email is a normal email, it further sends an email category detection request to the cloud server. In one embodiment, the target email characteristics can be directly sent to the cloud server for processing; in another embodiment, the target email characteristics can be encrypted before being sent to the cloud server. Figure 5 This is a flowchart illustrating the process of a local server sending an email category detection request to the cloud in an embodiment of this application. In some embodiments, sending an email category detection request from the local server to the cloud server may include:
[0110] S501: The local server obtains a random number corresponding to the preset encryption policy;
[0111] In one embodiment, the preset encryption strategy can be a salted encryption method, where a random number is used as the salt value and concatenated with the original data before encryption.
[0112] S503: The local server concatenates the target sending attribute features, target statistical attributes, and target text features to obtain the feature encoding string;
[0113] Through the above embodiments, the target email features may include target sending attribute features, target statistical attributes, and target text features, etc. Then, the target sending attribute features, target statistical attributes, and target text features are concatenated to obtain a feature encoding string.
[0114] S505: The local server encrypts the above feature encoding string based on a random number according to a preset encryption strategy to obtain the encrypted feature encoding string.
[0115] In this embodiment of the application, the encryption of the above-mentioned feature encoding string based on random numbers can be done using the Message Digest Algorithm (MD5). This application does not limit the specific encryption method.
[0116] S507: The local server constructs an email category detection request based on the encrypted feature encoding string and a random number;
[0117] S509: The local server sends an email category detection request to the cloud server.
[0118] In this embodiment, by concatenating the target email features into a feature encoding string and sending this string, the resources required are smaller and the security is higher compared to sending the entire target email directly. Furthermore, encrypting the feature encoding string before sending it to the cloud server further enhances data security.
[0119] In one embodiment, after receiving an email category detection request from the local server, the cloud server first parses the request to obtain an encrypted feature encoding string and a random number. Following a preset decryption strategy, the cloud server decrypts the encrypted feature encoding string based on the random number to obtain the various target attribute features. The preset decryption strategy corresponds to the preset encryption strategy used by the local server. After decryption, the target email features, i.e., the various target attribute features, can be decoded segment by segment from the feature encoding string according to the concatenation order.
[0120] It should be noted that the pre-deployed preset cloud detection strategy in the cloud server can be a preset cloud detection model, which is used to provide cloud-based abnormal email detection services. Correspondingly, based on the preset cloud detection strategy corresponding to each target attribute feature, email category detection is performed on each target attribute feature to obtain the second category identifier of the target email, which may include:
[0121] Each target attribute feature is input into a preset cloud detection model corresponding to each target attribute feature to perform email category detection, thereby obtaining the second category identifier of the target email.
[0122] It should be noted that the pre-deployed preset cloud detection strategy in the cloud server can also be a cloud-based abnormal email feature library. This cloud-based abnormal email feature library includes email features corresponding to abnormal emails within a preset historical time period, i.e., the sample email features in the above embodiments. In the above embodiments, the cloud server can, on the one hand, determine the sample email features with a confidence level greater than or equal to a preset confidence threshold as preset abnormal email features, and form a preset abnormal email feature library based on the preset abnormal email features and send it to the local server; on the other hand, it can also form a cloud-based abnormal email feature library based on the email features corresponding to abnormal emails within all the preset historical time periods.
[0123] In this embodiment, the encrypted feature encoding string sent by the local server is decrypted to obtain the characteristics of each target attribute, effectively ensuring the security of private data and avoiding the risk of data leakage during the transmission of the original email data. Furthermore, by deploying a pre-set cloud detection model in the cloud and using the model for email cloud detection, the accuracy and intelligence of the detection are effectively improved, as well as the efficiency of email detection.
[0124] Figure 6 This is a schematic diagram of the training process of the preset cloud detection model provided in the embodiments of this application. Figure 6 The method shown is executed by a cloud server. In one embodiment, the training process of the aforementioned preset cloud detection model may include:
[0125] S601: Retrieve sample emails within a preset historical time period.
[0126] The sample emails were labeled with email category tags;
[0127] The preset historical time period can be set according to actual needs. It should be noted that... Figure 6 The sample emails used in the training process shown can be updated periodically, so that the preset cloud detection model obtained by training is also updated periodically, thus ensuring the timeliness of the preset cloud detection model.
[0128] Email category tags can be manually determined or based on user feedback, such as actions like deleting an email after reading it, clicking a hyperlink, downloading attachments, or the duration of reading the email. Email category tags can be divided into normal emails and abnormal emails. It should be noted that normal emails can also include neutral emails, which are neither regular correspondence nor system emails, nor abnormal emails, such as emails subscribed to by the user.
[0129] S603: Divide the sample emails into training samples and validation samples according to a preset ratio.
[0130] The preset ratio can be set according to actual needs. In one example, the preset ratio can be 4:1. For example, assuming there are 10,000 sample emails, after dividing them according to the preset ratio, the number of training samples will be 8,000 and the number of validation samples will be 2,000.
[0131] S605: Extract sample email features from the training samples.
[0132] The sample email features include various types of attribute features from the training samples.
[0133] Before model training, the training samples are preprocessed. This preprocessing includes parsing the training samples to obtain email metadata, followed by email feature extraction to vectorize the training samples, making them suitable for the data input formats of different machine learning models. It should be noted that the process of extracting email features on the cloud server is different from... Figure 4 The process of extracting email features on the local server is similar and will not be repeated here. Correspondingly, the sample email features also include various types of attribute features, such as sample sending attribute features, sample statistical attributes, and sample text features. Using the same feature extraction method allows the locally extracted features to be directly applied to the cloud-deployed model after being transmitted to the cloud, avoiding additional data format conversion processes and improving email detection efficiency.
[0134] S607: Construct a pre-defined machine learning model that corresponds to the type of the sample attribute features.
[0135] Among them, the sample attribute features are any one of the attribute features of the various types of training samples mentioned above.
[0136] In this embodiment, different machine learning models can be applied to different types of attribute features in the sample email features. For example, a Naive Bayes model can be built and trained for the sample email sending attribute features, and a Text Convolutional Neural Network (TextCNN) model can be built and trained for the sample text features. It should be understood that the above machine learning models are merely examples, and this application does not limit the machine learning models constructed.
[0137] S609: Based on a preset machine learning model, perform feature category detection on sample attribute features to obtain the predicted category.
[0138] S611: Based on the difference between the predicted category and the email category label, iteratively train the preset machine learning model, and determine the model performance index of the candidate machine learning model corresponding to the current iteration number based on the validation samples according to the preset iteration cycle.
[0139] The sample attribute features are input into a pre-defined machine learning model for feature category detection, which outputs the predicted category corresponding to the sample attribute features. Then, a loss value is determined based on the difference between the predicted category and the email category label, and the pre-defined machine learning model is iteratively trained based on this loss value. The pre-defined iteration period can be determined according to the planned number of iterations. For example, assuming a pre-defined number of iterations of 100 and a pre-defined iteration period of 5, the candidate machine learning model corresponding to the current iteration number is validated using validation samples to verify its model performance metrics after every 5 iterations. The model performance metrics can be at least one of the following: precision, recall, and Receiver Operating Characteristic (ROC) curve.
[0140] S613: After training reaches the preset number of iterations, the candidate machine learning model with the highest model performance index is determined as the preset cloud detection model.
[0141] After training reaches the preset number of iterations, i.e., training is complete, the candidate machine learning model with the highest performance index on the validation samples will be selected as the preset cloud detection model and deployed on the cloud server for subsequent use and detection.
[0142] In this embodiment, pre-trained and deployed cloud-based detection models improve email processing efficiency. By training corresponding pre-defined machine learning models for different types of attribute features, the accuracy and comprehensiveness of email detection are enhanced.
[0143] It should be noted that this application does not limit the specific type of machine learning model used in the preset cloud detection model.
[0144] The training process will be explained in detail below using the Extreme Gradient Boosting (XGBoost) model as an example. Figure 7 This is a schematic diagram of a training process based on an XGBoost model provided in an embodiment of this application. In this embodiment, the XGBoost model can be updated daily, with an update cycle of 24 hours. Specifically, this embodiment may include:
[0145] S701: Obtain sample emails and perform data annotation.
[0146] Retrieve sample emails within a preset historical time period (e.g., all emails from the past two weeks). These sample emails can then be labeled as normal, neutral, or abnormal emails, corresponding to positive, neutral, and negative samples. The labeling process is detailed in step S601 and will not be repeated here.
[0147] The labeled samples can then be divided into a training set and a validation set in a 4:1 ratio. The training set contains multiple training samples, and the validation set contains multiple validation samples.
[0148] S702: Attribute preprocessing.
[0149] This step is used to extract email features from the training samples. These features can include various types of attribute features, such as sender attributes, statistical attributes, and text features. Extracting email features from training samples on a cloud server is similar to extracting target email features from a local server. For a detailed explanation of this step, please refer to [link to relevant documentation]. Figure 4 Further details will not be elaborated here.
[0150] In one embodiment, each extracted attribute feature can be used individually as a training sample for model training. That is, the XGBoost model can be trained using the sample sending attribute features to obtain a model for email classification based on sending attribute features, or the XGBoost model can be trained using the sample statistical attributes to obtain a model for email classification based on statistical attributes, or the XGBoost model can be trained using the sample text features to obtain a model for email classification based on text features.
[0151] In another embodiment, the extracted attribute features of various types from the training samples can be concatenated to form a feature encoding string, and the model can be trained based on the feature encoding string. For example, the extracted sample sending attribute features, sample statistical attributes, and sample text features can be concatenated according to a preset concatenation strategy to form a sample feature encoding string. Since the XGBoost model has the ability to handle missing values, for cases where missing attribute features exist, the missing attribute features can be filled with preset values, such as 0.
[0152] S703: Sample weight calculation.
[0153] It should be noted that in the training samples, the number of abnormal emails (negative samples) is often far less than the number of normal emails (positive samples). To alleviate the sample imbalance problem, sample weights are set in this embodiment before training the XGBoost model. These sample weights are used to adjust the weights of positive and negative samples, and are usually set as the ratio of the number of negative samples to the number of positive samples. Assuming a binary classification task with a total of 100 negative samples and 500 positive samples, the sample weight is set to 0.2 (i.e., the total number of negative samples divided by the total number of positive samples). This way, the XGBoost model will pay more attention to negative samples during training, thereby improving the model's prediction accuracy for negative samples.
[0154] S704: Model training.
[0155] Based on the aforementioned training samples and sample weights, the XGBoost model is selected as the classifier for model training. In engineering implementation, the XGBoost 1.4.2 library can be used. Regarding the XGBoost model hyperparameters and training hyperparameters, the maximum tree depth is set to 8, the L2 regularization penalty parameter can be set to 2, the minimum loss decay value can be set to 0.2, the feature sampling ratio can be set to 0.7, the minimum leaf node weight can be set to 3, and the model learning rate can be set to 0.025. Other hyperparameters can use the default values from the model library.
[0156] Next, the model is trained using the training and validation sets obtained according to the preset partitioning ratio, with an early stopping training strategy enabled. The optimal number of training iterations is determined based on the model's performance on the validation set. Additionally, the entire day's email data for the following day within a preset historical time period corresponding to the sample emails can be used as a test set to test the model's detection performance.
[0157] After the above training process, a preset cloud detection model can be obtained. The preset cloud model is different depending on the input features, and the output is the predicted email category, i.e., the second category identifier, which is used to characterize whether the email is normal or abnormal.
[0158] It should be noted that the preset cloud detection model includes a preset sending attribute detection model, a preset statistical attribute detection model, and a preset text detection model; each target attribute feature includes target sending attribute features, target statistical attributes, and target text features.
[0159] Accordingly, each target attribute feature is input into a preset cloud detection model corresponding to each target attribute feature to perform email category detection, thereby obtaining a second category identifier for the target email. This may include: inputting the target sending attribute features into a preset sending attribute detection model to perform behavioral feature category detection, thereby obtaining a first cloud detection result; inputting the target statistical attributes into a preset statistical attribute detection model to perform statistical feature category detection, thereby obtaining a second cloud detection result; inputting the target text features into a preset text detection model to perform text category detection, thereby obtaining a third cloud detection result; and determining the second category identifier based on at least one of the first cloud detection result, the second cloud detection result, and the third cloud detection result.
[0160] Each target attribute feature is input into a pre-defined cloud detection model corresponding to that feature for email category detection. This detection process can be parallelized, thereby shortening the cloud detection time and improving its efficiency. In one implementation, if any of the first, second, and third cloud detection results indicates that the target email is an abnormal email, then a second category identifier can be used to characterize the target email as an abnormal email. If all three cloud detection results indicate that the target email is a normal email, then a second category identifier can be used to characterize the target email as a normal email.
[0161] In this embodiment, the target sending attribute features, target statistical attributes, and target text features are respectively input into the preset sending attribute detection model, the preset statistical attribute detection model, and the preset text detection model. Then, the second category identifier is determined by comprehensively judging multiple cloud detection results, thereby improving the accuracy of cloud detection.
[0162] Figure 8 This is an overall architecture diagram of the email processing method provided in the embodiments of this application. For example... Figure 8 As shown, for inbound emails, the local server first performs local abnormal email filtering. This local abnormal email filtering is a multi-layered filtering process. The first layer of filtering includes whitelist filtering, administrator spam filtering, and user spam filtering. The specific implementation process of the first layer of filtering is described in step S303, and will not be repeated here. Emails that fail the whitelist check proceed to the second layer of filtering. The second layer of filtering includes sender attribute checking, sender server authentication, and sender server trustworthiness checking. The specific implementation process of the second layer of filtering is described in step S305, and will not be repeated here. After consideration at the first and second layers, emails not marked as abnormal proceed to the third layer of filtering. The third layer of filtering involves email feature checking, which can be seen in steps S203 and... Figure 4The illustrated embodiment will not be described in detail here. Next, after the email undergoes local hierarchical filtering, it is sent to the local interception service for unified scanning. If the email is detected as an abnormal email, it will automatically perform blocking actions such as rejecting the email, deleting it, or sending it to the target recipient's spam folder according to the preset interception policy.
[0163] After filtering abnormal emails locally, emails marked as normal are further converted and encrypted before being sent to the cloud server for cloud-based abnormal email identification. The cloud server first decrypts the received data, and then can call at least one of the following: a cloud-based intelligent clustering platform, a cloud-based intelligent classification platform, or a cloud-based abnormal sample feature library, to detect the email category. The multi-dimensional abnormal email identification service deployed in the cloud supports various email classification and clustering algorithms, such as semantic representation models (BERT), XGBoost models, and minimum hash (MinHash) clustering models. After receiving locally encrypted data, it starts different models to classify, identify, and label the features of different types of emails, obtaining cloud identification results. The cloud identification results are then encrypted and transmitted to the local server. The local server determines whether the email is normal or abnormal based on the cloud identification results. If it is normal, it is delivered to the target recipient's mailbox; if it is abnormal, it is blocked locally.
[0164] This application's embodiments enable rapid and accurate filtering of abnormal emails. Furthermore, without increasing local resource consumption, it supports integration with cloud-based abnormal email identification services, applying cloud-based intelligent model algorithms to improve the coverage, accuracy, and real-time performance of abnormal email identification, reducing threats and losses to data security caused by false positives or false negatives. Simultaneously, this application's embodiments, through a series of data processing operations such as feature extraction, data transformation, feature recombination, and data encryption, avoid the risk of leakage of sensitive or confidential information associated with directly transmitting local email information to the cloud, thus better meeting the security management requirements of private data.
[0165] The following describes a specific embodiment of an email processing method described in this specification, using a local server as the execution entity. Specifically, the method includes:
[0166] Obtain the target email;
[0167] Extract the target email features from the target email, determine the matching results of the target email features based on the preset abnormal email feature library, and determine the first category identifier of the target email based on the matching results; the preset abnormal email feature library stores the preset abnormal email features corresponding to abnormal emails; the target email features include various types of target attribute features of the target email;
[0168] If the first category identifier indicates that the target email is a normal email, an email category detection request is sent to the cloud server; the email category detection request carries the characteristics of the target email.
[0169] Receive the second category identifier sent by the cloud server;
[0170] If the second category identifier indicates that the target email is a normal email, the target email will be sent to the target recipient account.
[0171] In some embodiments, the target email includes target email header information and target email body information. The extraction of the target email features from the target email includes:
[0172] Extract the target mailing attribute features corresponding to the target mailing server from the target email header information;
[0173] Extract the target content attribute features corresponding to the target email body information;
[0174] The target email features are defined by the target sending attribute features and the target content attribute features.
[0175] In some embodiments, the target mailing attribute features corresponding to the target mailing server in the extracted target email header information include:
[0176] Obtain the location information of the target mail server from the header information of the target email;
[0177] Get the cumulative number of historical emails received and the cumulative number of abnormal emails sent by the target mail server; the cumulative number of abnormal emails is the number of historical emails that have been identified as abnormal.
[0178] The location information, the cumulative number of received messages, and the cumulative number of abnormal messages are determined as the target sending attribute features.
[0179] In some embodiments, the extraction of target content attribute features corresponding to the target email body information includes:
[0180] Parse the target email body information to obtain email metadata;
[0181] Extract the target statistical attributes of email metadata; the target statistical attributes include at least one of the following: number of abnormal characters, number of hyperlinks, and number of images.
[0182] Extract the target text features of email metadata. The target text features include at least one of the following: text vectors corresponding to the body text, text vectors corresponding to the text in the image, and text vectors corresponding to the text in the attachment.
[0183] The target statistical attributes and target text features are identified as target content attribute features.
[0184] In some embodiments, the above-mentioned determination of the target email feature matching result based on the preset abnormal email feature library, and the determination of the first category identifier of the target email based on the matching result, includes:
[0185] Receive a pre-defined database of abnormal email signatures sent from the cloud server;
[0186] The target email sending attribute features are matched with the preset abnormal email features in the preset abnormal email feature library to obtain the first feature matching result corresponding to the target email sending attribute features;
[0187] The target statistical attribute is matched with the preset abnormal email features in the preset abnormal email feature library to obtain the second feature matching result corresponding to the target statistical attribute.
[0188] The target text features are matched with the preset abnormal email features in the preset abnormal email feature library to obtain the third feature matching result corresponding to the target text features;
[0189] The first category identifier is determined based on at least one of the first feature matching result, the second feature matching result, and the third feature matching result.
[0190] In some embodiments, before extracting the target email features, the method further includes:
[0191] Parse the target email header information to obtain the target mail server information and the target email subject;
[0192] The system detects whether the target email server information and the target email subject are within a preset whitelist, and obtains the whitelist detection results for the target email.
[0193] If the whitelist detection result indicates that the target email has not passed the whitelist detection, the third category identifier of the target email is determined based on the target sending server information;
[0194] If the third category identifier indicates that the target email is a normal email, extract the target email features of the target email.
[0195] In some embodiments, the above-mentioned detection of whether the target sending server information and the target sending subject are within a preset whitelist to obtain the whitelist detection result of the target email includes:
[0196] Retrieve the preset whitelist; the preset whitelist records information on multiple preset mail sending servers and multiple preset keywords;
[0197] The target mail server information is matched with multiple preset mail server information to obtain the first whitelist matching result;
[0198] The target email subject is matched with multiple preset keywords to obtain a second whitelist matching result;
[0199] If at least one of the matching results from the first whitelist and the second whitelist is found to be a match, the target email is confirmed to have passed the whitelist detection and is then sent to the target recipient account.
[0200] If both the first and second whitelist matching results indicate a match failure, it is determined that the target email failed the whitelist detection.
[0201] In some embodiments, the target mail server information includes the target mail domain name and the target mail network address; the above-mentioned determination of the third category identifier of the target email based on the target mail server information includes:
[0202] The sending frequency detection result is determined based on the cumulative sending frequency of the target sending server within a preset time period and a preset frequency threshold; the target sending server corresponds to the target sending server information;
[0203] The sender identity verification result is determined based on the target sending network address and the preset sending network address record; the preset sending network address record corresponds to the target sending domain name;
[0204] The credibility detection result is determined based on the credibility of the target sending server and the preset credibility threshold.
[0205] Based on the results of sending frequency detection, sending identity detection, and sending credibility detection, a third category identifier is determined.
[0206] In some embodiments, sending an email category detection request to a cloud server includes:
[0207] Get the random number corresponding to the preset encryption strategy;
[0208] The target's sending attribute features, target's statistical attributes, and target's text features are concatenated to obtain the feature encoding string;
[0209] According to the preset encryption strategy, the feature encoding string is encrypted based on random numbers to obtain the encrypted feature encoding string;
[0210] A message category detection request is constructed based on the encrypted feature encoding string and random number;
[0211] Send an email category detection request to the cloud server.
[0212] The following describes a specific embodiment of an email processing method described in this specification, using a cloud server as the execution entity. Specifically, the method includes:
[0213] Receive email category detection requests sent by the local server;
[0214] Based on the type of each target attribute feature in the target email features, determine the preset cloud detection strategy corresponding to each target attribute feature;
[0215] Based on the preset cloud detection strategy corresponding to each target attribute feature, email category detection is performed on each target attribute feature to obtain the second category identifier of the target email;
[0216] Send the second category identifier to the local server.
[0217] In some embodiments, the above method further includes:
[0218] Parse the email category detection request to obtain the encrypted feature encoding string and a random number;
[0219] According to the preset decryption strategy, the encrypted feature encoding string is decrypted based on random numbers to obtain the features of each target attribute.
[0220] The above-mentioned email category detection is performed on each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature, resulting in a second category identifier for the target email, including:
[0221] Each target attribute feature is input into a preset cloud detection model corresponding to each target attribute feature to perform email category detection, and the second category identifier of the target email is obtained.
[0222] In some embodiments, the training process of the preset cloud detection model includes:
[0223] Retrieve sample emails from a preset historical time period; the sample emails are labeled with email category tags;
[0224] The sample emails are divided into training samples and validation samples according to a preset ratio;
[0225] Extract sample email features from the training samples; the sample email features include various types of attribute features of the training samples;
[0226] Construct a preset machine learning model corresponding to the type of sample attribute features; the sample attribute features are any one of the multiple types of attribute features of the training samples;
[0227] Based on a pre-defined machine learning model, feature category detection is performed on the sample attribute features to obtain the predicted category;
[0228] Based on the difference between the predicted category and the email category label, the preset machine learning model is iteratively trained, and the model performance index of the candidate machine learning model corresponding to the current iteration number is determined based on the validation samples according to the preset iteration cycle.
[0229] After training reaches the preset number of iterations, the candidate machine learning model with the highest performance index is selected as the preset cloud detection model.
[0230] In some embodiments, the preset cloud detection model includes a preset sending attribute detection model, a preset statistical attribute detection model, and a preset text detection model, and each target attribute feature includes target sending attribute features, target statistical attributes, and target text features;
[0231] The above process involves inputting each target attribute feature into a pre-defined cloud-based detection model corresponding to that target attribute feature to perform email category detection, thereby obtaining a second category identifier for the target email, including:
[0232] The target sending attribute features are input into a preset sending attribute detection model to perform behavioral feature category detection, and the first cloud detection result is obtained.
[0233] The target statistical attributes are input into a preset statistical attribute detection model to perform statistical feature category detection, and a second cloud detection result is obtained.
[0234] The target text features are input into a preset text detection model to perform text category detection, and the third-party cloud detection results are obtained.
[0235] The second category identifier is determined based on at least one of the first cloud detection result, the second cloud detection result, and the third cloud detection result.
[0236] In some embodiments, the above method further includes:
[0237] The characteristics of abnormal emails within a preset historical time period are determined as the characteristics of sample emails.
[0238] The confidence level of a sample email feature is determined based on the cumulative frequency of its occurrence.
[0239] Sample email features with confidence levels greater than or equal to a preset confidence threshold are identified as preset abnormal email features, and a preset abnormal email feature library is formed based on these preset abnormal email features.
[0240] Send a pre-defined database of abnormal email signatures to the local server.
[0241] On the other hand, embodiments of this application also provide a local server, which includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the email processing method provided in the above method embodiments.
[0242] On the other hand, embodiments of this application also provide a cloud server, which includes a processor and a memory. The memory stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the email processing method provided in the above method embodiments.
[0243] In this embodiment, the memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, applications required for the functions, etc.; the data storage area may store data created according to the use of the device, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory may also include a memory controller to provide the processor with access to the memory.
[0244] Figure 9 This is a schematic diagram of the structure of an email processing device provided in an embodiment of this application. This device can be applied to a local server, such as... Figure 9 As shown, the device 900 may include:
[0245] Email retrieval module 901 is used to retrieve target emails;
[0246] The local email feature matching module 902 is used to extract the target email features of the target email, determine the matching result of the target email features based on a preset abnormal email feature library, and determine the first category identifier of the target email according to the matching result; the preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails; the target email features include multiple types of target attribute features of the target email;
[0247] The detection request sending module 903 is used to send an email category detection request to the cloud server if the first category identifier indicates that the target email is a normal email; the email category detection request carries the characteristics of the target email.
[0248] The category identifier receiving module 904 is used to receive a second category identifier sent by the cloud server; the second category identifier is obtained by the cloud server through email category detection of each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature, and the preset cloud detection strategy is determined by the cloud server based on the type of each target attribute feature included in the target email feature in the received email category request;
[0249] The email delivery module 905 is used to send the target email to the target recipient account if the second category identifier indicates that the target email is a normal email.
[0250] In some embodiments, the target email includes target email header information and target email body information, and the local email feature matching module may include:
[0251] The target email sending attribute feature extraction submodule is used to extract the target email sending attribute features corresponding to the target sending server from the target email header information;
[0252] The target content attribute feature extraction submodule is used to extract the target content attribute features corresponding to the target email body information;
[0253] The target email feature determination submodule is used to determine the target sending attribute features and the target content attribute features as the target email features.
[0254] In some embodiments, the target sending attribute feature extraction submodule may include:
[0255] The location information acquisition unit is used to acquire the location information of the target sending server in the target email header information;
[0256] The cumulative quantity acquisition unit is used to acquire the cumulative number of historical emails received and the cumulative number of abnormal emails sent by the target mail server; the cumulative number of abnormal emails is the number of historical emails identified as abnormal.
[0257] The target sending attribute feature determination unit is used to determine the home location information, the cumulative number of received messages, and the cumulative number of anomalies as the target sending attribute features.
[0258] In some embodiments, the target content attribute feature extraction submodule may include:
[0259] The email body parsing unit is used to parse the target email body information to obtain email metadata.
[0260] The target statistical attribute extraction unit is used to extract the target statistical attributes of the email metadata; the target statistical attributes include at least one of the following: the number of abnormal characters, the number of hyperlinks, and the number of images.
[0261] The target text feature extraction unit is used to extract the target text features of the email metadata; the text features include at least one of the following: text vectors corresponding to the body text, text vectors corresponding to the text in the image, and text vectors corresponding to the text in the attachment.
[0262] The target content attribute feature determination unit is used to determine the target statistical attributes and the target text features as the target content attribute features.
[0263] In some embodiments, the local email feature matching module may include:
[0264] The feature database receiving submodule is used to receive the preset abnormal email feature database sent by the cloud server;
[0265] The email sending attribute feature matching submodule is used to match the target email sending attribute feature with the preset abnormal email features in the preset abnormal email feature library to obtain a first feature matching result corresponding to the target email sending attribute feature;
[0266] The statistical attribute matching submodule is used to match the target statistical attribute with the preset abnormal email features in the preset abnormal email feature library to obtain a second feature matching result corresponding to the target statistical attribute.
[0267] The text feature matching submodule is used to match the target text feature with the preset abnormal email features in the preset abnormal email feature library to obtain a third feature matching result corresponding to the target text feature;
[0268] The first category identifier determination submodule is used to determine the first category identifier based on at least one of the first feature matching result, the second feature matching result, and the third feature matching result.
[0269] In some embodiments, the device 900 may further include:
[0270] The email header parsing module is used to parse the target email header information of the target email to obtain the target sending server information and the target sending subject.
[0271] The whitelist detection module is used to detect whether the target email server information and the target email subject are in the preset whitelist, and to obtain the whitelist detection result of the target email.
[0272] The mail sending server detection module is used to determine the third category identifier of the target email based on the target mail sending server information if the whitelist detection result indicates that the target email has not passed the whitelist detection.
[0273] The third category identifier detection module is used to extract the target email features of the target email if the third category identifier indicates that the target email is a normal email.
[0274] In some embodiments, the whitelist detection module may include:
[0275] The whitelist acquisition submodule is used to acquire the preset whitelist; the preset whitelist records multiple preset mail sending server information and multiple preset keywords;
[0276] The first whitelist matching result determination submodule is used to match the target mail sending server information with the multiple preset mail sending server information to obtain the first whitelist matching result;
[0277] The second whitelist matching result determination submodule is used to match the target email subject with the multiple preset keywords to obtain the second whitelist matching result;
[0278] The matching success detection submodule is used to determine that the target email has passed the whitelist detection if there is at least one matching result between the first whitelist matching result and the second whitelist matching result, and then send the target email to the target receiving account.
[0279] The matching failure detection submodule is used to determine that the target email has not passed the whitelist detection if both the first whitelist matching result and the second whitelist matching result indicate a matching failure.
[0280] In some embodiments, the target mail server information includes the target mail domain name and the target mail network address; the mail server detection module may include:
[0281] The sending frequency detection submodule is used to determine the sending frequency detection result based on the cumulative sending frequency of the target sending server within a preset time period and a preset frequency threshold; the target sending server corresponds to the target sending server information;
[0282] The sender identity detection submodule is used to determine the sender identity detection result based on the target sender network address and a preset sender network address record; the preset sender network address record corresponds to the target sender domain name;
[0283] The mail sending credibility detection submodule is used to determine the mail sending credibility detection result based on the credibility of the target mail sending server and a preset credibility threshold;
[0284] The third category identifier determination submodule is used to determine the third category identifier based on the sending frequency detection result, the sending identity detection result, and the sending credibility detection result.
[0285] In some embodiments, the detection request sending module may include:
[0286] The random number acquisition submodule is used to acquire random numbers corresponding to the preset encryption strategy;
[0287] The feature concatenation submodule is used to concatenate the target sending attribute features, the target statistical attributes, and the target text features to obtain a feature encoding string;
[0288] An encryption submodule is used to encrypt the feature encoding string based on the random number according to the preset encryption strategy, so as to obtain the encrypted feature encoding string.
[0289] The email category detection request construction submodule is used to construct the email category detection request based on the encrypted feature encoding string and the random number.
[0290] The request sending submodule is used to send the email category detection request to the cloud server.
[0291] Figure 10 This is a schematic diagram of the structure of an email processing device provided in an embodiment of this application. This device can be applied to a cloud server, such as... Figure 10 As shown, the device 1000 may include:
[0292] The detection request receiving module 1001 is used to receive an email category detection request sent by a local server. The email category detection request carries target email features. The email category detection request is generated when the local server obtains the target email, extracts the target email features of the target email, determines the matching result of the target email features based on a preset abnormal email feature library, determines a first category identifier of the target email based on the matching result, and sends the request to the cloud server when the first category identifier indicates that the target email is a normal email. The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails. The target email features include multiple types of target attribute features of the target email.
[0293] The preset cloud detection strategy determination module 1002 is used to determine the preset cloud detection strategy corresponding to each target attribute feature based on the type of each target attribute feature in the target email features;
[0294] The email category detection module 1003 is used to perform email category detection on each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature, and obtain the second category identifier of the target email;
[0295] The category identifier sending module 1004 is used to send the second category identifier to the local server, so that the local server sends the target email to the target recipient account when the second category identifier indicates that the target email is a normal email.
[0296] In some embodiments, the device 1000 may further include:
[0297] The request parsing module is used to parse the email category detection request and obtain the encrypted feature encoding string and random number;
[0298] The decryption module is used to decrypt the encrypted feature encoding string based on the random number according to a preset decryption strategy to obtain the various target attribute features;
[0299] In some embodiments, the email category detection module may include:
[0300] The model detection module is used to input the various target attribute features into a preset cloud detection model corresponding to each target attribute feature to perform email category detection and obtain the second category identifier of the target email.
[0301] In some embodiments, the device 1000 may further include:
[0302] The sample email acquisition module is used to acquire sample emails within a preset historical time period; the sample emails are labeled with email category tags;
[0303] The sample partitioning module is used to divide the sample emails into training samples and validation samples according to a preset ratio;
[0304] The sample feature extraction module is used to extract sample email features from the training samples; the sample email features include various types of attribute features of the training samples.
[0305] A machine learning model building module is used to build a preset machine learning model corresponding to the type of sample attribute features; the sample attribute features are any one of the multiple types of attribute features of the training samples;
[0306] The prediction category determination module is used to perform feature category detection on the sample attribute features based on the preset machine learning model to obtain the predicted category;
[0307] The iterative training module is used to iteratively train the preset machine learning model based on the difference between the predicted category and the email category label, and determine the model performance index of the candidate machine learning model corresponding to the current iteration number based on the verification samples according to the preset iteration period.
[0308] The preset cloud detection model determination module is used to determine the candidate machine learning model with the highest model performance index as the preset cloud detection model after training has reached a preset number of iterations.
[0309] In some embodiments, the preset cloud detection model may include a preset sending attribute detection model, a preset statistical attribute detection model, and a preset text detection model, and each target attribute feature may include target sending attribute features, target statistical attributes, and target text features; the model detection module may include:
[0310] The first cloud-based detection submodule is used to input the target sending attribute features into the preset sending attribute detection model to perform behavioral feature category detection, and obtain the first cloud-based detection result;
[0311] The second cloud-based detection submodule is used to input the target statistical attributes into the preset statistical attribute detection model to perform statistical feature category detection and obtain the second cloud-based detection result.
[0312] The third cloud-based detection submodule is used to input the target text features into the preset text detection model to perform text category detection and obtain the third cloud-based detection result.
[0313] The second category identifier determination submodule is used to determine the second category identifier based on at least one of the first cloud detection result, the second cloud detection result, and the third cloud detection result.
[0314] In some embodiments, the device 1000 may further include:
[0315] The sample email feature determination module is used to determine the email features corresponding to abnormal emails within a preset historical time period as sample email features.
[0316] The confidence level determination module is used to determine the confidence level of the sample email feature based on the cumulative number of times the sample email feature appears.
[0317] The feature library formation module is used to identify sample email features with confidence levels greater than or equal to a preset confidence threshold as preset abnormal email features, and to form a preset abnormal email feature library based on the preset abnormal email features.
[0318] The feature database sending module is used to send the preset abnormal email feature database to the local server.
[0319] The apparatus and method embodiments described above are based on the same inventive concept.
[0320] On the other hand, embodiments of this application also provide an email processing system, which includes a local server and a cloud server;
[0321] The aforementioned local server is used to obtain the target email; extract the target email features of the target email, and determine the matching result of the target email features based on a preset abnormal email feature library, and determine the first category identifier of the target email according to the matching result; the preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails; the target email features include multiple types of target attribute features of the target email; and if the first category identifier indicates that the target email is a normal email, send an email category detection request to the cloud server; the email category detection request carries the target email features; receive the second category identifier sent by the cloud server; and if the second category identifier indicates that the target email is a normal email, send the target email to the target recipient account.
[0322] The aforementioned cloud server is used to determine a preset cloud detection strategy corresponding to each of the target attribute features in the target email features of the email category detection request; and to perform email category detection on each of the target attribute features based on the preset cloud detection strategy corresponding to each of the target attribute features to obtain a second category identifier for the target email; and to send the second category identifier to the aforementioned local server.
[0323] Embodiments of this application also provide a computer storage medium, wherein the computer stores at least one instruction or at least one program, wherein the at least one instruction or at least one program is loaded and executed by a processor to implement the email processing method provided in the above method embodiments.
[0324] Embodiments of this application also provide a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the email processing method provided in the above-described method embodiments.
[0325] Optionally, in this embodiment, the storage medium may be located at at least one of the multiple network servers in a computer network. Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0326] As can be seen from the embodiments of the email processing method, apparatus, system, or storage medium provided in this application, the embodiments of this application perform local email filtering on the target email to obtain a first category identifier. When the first category identifier indicates that the target email is an abnormal email, it is directly blocked. When the first category identifier indicates that the target email is a normal email, the target email features of the target email are sent to the cloud server for further detection, and the second category identifier obtained by the cloud server is received. When the second category identifier indicates that the target email is a normal email, it is delivered normally; otherwise, it is blocked. By combining local and cloud detection, the local server can deploy only a small-scale preset abnormal email feature library for fast matching, filtering, and blocking, while the cloud server deploys a more accurate abnormal email detection service to ensure the comprehensiveness and accuracy of the detection. At the same time, by combining local and cloud detection, the consumption of local network bandwidth and computing resources can be reduced, and emails can be flexibly configured and managed according to needs and actual local resources, improving the reliability, flexibility, and scalability of email processing. Therefore, the method provided in this application can comprehensively, accurately, and quickly detect abnormal emails, reducing the probability of users receiving abnormal emails.
[0327] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0328] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0329] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer storage medium, such as a read-only memory, a disk, or an optical disk.
[0330] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. An email processing method, characterized in that, Applied to a local server, the method includes: Obtain the target email; Extract the target email features of the target email, and determine the matching result of the target email features based on a preset abnormal email feature library. Determine the first category identifier of the target email based on the matching result. The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails. The target email features include multiple types of target attribute features of the target email. If the first category identifier indicates that the target email is a normal email, an email category detection request is sent to the cloud server; the email category detection request carries the characteristics of the target email. The system receives a second category identifier sent by the cloud server. The second category identifier is obtained by the cloud server through email category detection of each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature. The preset cloud detection strategy is determined by the cloud server based on the type of each target attribute feature included in the target email feature in the received email category request. If the second category identifier indicates that the target email is a normal email, the target email is sent to the target recipient account.
2. The method according to claim 1, characterized in that, The target email includes target email header information and target email body information. Extracting the target email features of the target email includes: Extract the target mailing attribute features corresponding to the target mailing server from the target email header information; Extract the target content attribute features corresponding to the target email body information; The target sending attribute features and the target content attribute features are determined as the target email features.
3. The method according to claim 2, characterized in that, The extraction of the target mailing attribute features corresponding to the target mailing server from the target email header information includes: Obtain the location information of the target sending server from the header information of the target email; Obtain the cumulative number of historical emails received and the cumulative number of abnormal emails sent by the target mail server; the cumulative number of abnormal emails is the number of historical emails identified as abnormal. The location information, the cumulative number of received messages, and the cumulative number of anomalies are determined as the target sending attribute features.
4. The method according to claim 2, characterized in that, The step of extracting the target content attribute features corresponding to the target email body information includes: Parse the target email body information to obtain email metadata; Extract the target statistical attributes from the email metadata; the target statistical attributes include at least one of the following: the number of abnormal characters, the number of hyperlinks, and the number of images. Extract the target text features of the email metadata, wherein the target text features include at least one of the following: text vectors corresponding to the body text, text vectors corresponding to the text in the image, and text vectors corresponding to the text in the attachment; The target statistical attributes and the target text features are determined as the target content attribute features.
5. The method according to claim 4, characterized in that, The step of determining the matching result of the target email features based on a preset abnormal email feature library, and determining the first category identifier of the target email based on the matching result, includes: Receive the preset abnormal email feature database sent by the cloud server; The target sending attribute features are matched with preset abnormal email features in the preset abnormal email feature library to obtain a first feature matching result corresponding to the target sending attribute features; The target statistical attribute is matched with the preset abnormal email features in the preset abnormal email feature library to obtain the second feature matching result corresponding to the target statistical attribute; The target text feature is matched with the preset abnormal email features in the preset abnormal email feature library to obtain the third feature matching result corresponding to the target text feature; The first category identifier is determined based on at least one of the first feature matching result, the second feature matching result, and the third feature matching result.
6. The method according to claim 1, characterized in that, Before extracting the target email features, the method further includes: Parse the target email header information to obtain the target mail server information and the target email subject; The system detects whether the target email server information and the target email subject are within a preset whitelist, and obtains the whitelist detection result of the target email. If the whitelist detection result indicates that the target email fails the whitelist detection, the third category identifier of the target email is determined based on the target sending server information; If the third category identifier indicates that the target email is a normal email, extract the target email features of the target email.
7. The method according to claim 6, characterized in that, The detection of whether the target email sending server information and the target email subject are within a preset whitelist, and obtaining the whitelist detection result of the target email, includes: Obtain the preset whitelist; the preset whitelist records multiple preset mail sending server information and multiple preset keywords; The target mail server information is matched with the multiple preset mail server information to obtain the first whitelist matching result; The target email subject is matched with the multiple preset keywords to obtain the second whitelist matching result; If at least one of the first whitelist matching results and the second whitelist matching result is a match, it indicates a successful match. The target email is then determined to have passed the whitelist detection, and the target email is sent to the target recipient account. If both the first whitelist matching result and the second whitelist matching result indicate a matching failure, it is determined that the target email has not passed the whitelist detection.
8. The method according to claim 6, characterized in that, The target mail server information includes the target mail domain name and the target mail network address; The step of determining the third category identifier of the target email based on the target sending server information includes: The sending frequency detection result is determined based on the cumulative sending frequency of the target sending server within a preset time period and a preset frequency threshold; the target sending server corresponds to the target sending server information; The sender identity detection result is determined based on the target sending network address and the preset sending network address record; the preset sending network address record corresponds to the target sending domain name. The credibility detection result is determined based on the credibility of the target sending server and the preset credibility threshold. Based on the sending frequency detection result, the sending identity detection result, and the sending credibility detection result, the third category identifier is determined.
9. The method according to claim 4, characterized in that, Sending the email category detection request to the cloud server includes: Get the random number corresponding to the preset encryption strategy; The target sending attribute features, the target statistical attributes, and the target text features are concatenated to obtain a feature encoding string; According to the preset encryption strategy, the feature encoding string is encrypted based on the random number to obtain the encrypted feature encoding string; The email category detection request is constructed based on the encrypted feature encoding string and the random number; Send the email category detection request to the cloud server.
10. An email processing method, characterized in that, Applied to a cloud server, the method includes: The system receives an email category detection request from a local server. This request carries target email features. The local server retrieves the target email, extracts its target email features, determines a matching result based on a preset abnormal email feature library, identifies a first category identifier for the target email based on the matching result, and sends the request to the cloud server when the first category identifier indicates the target email is a normal email. The preset abnormal email feature library stores preset abnormal email features corresponding to abnormal emails. The target email features include various types of target attribute features of the target email. Based on the type of each target attribute feature in the target email features, a preset cloud detection strategy corresponding to each target attribute feature is determined; Based on a preset cloud detection strategy corresponding to each target attribute feature, email category detection is performed on each target attribute feature to obtain the second category identifier of the target email; The second category identifier is sent to the local server so that the local server sends the target email to the target recipient account when the second category identifier indicates that the target email is a normal email.
11. The method according to claim 10, characterized in that, After receiving the email category detection request sent by the local server, the method further includes: Parse the email category detection request to obtain the encrypted feature encoding string and a random number; According to the preset decryption strategy, the encrypted feature encoding string is decrypted based on the random number to obtain the various target attribute features; The step of performing email category detection on each target attribute feature based on a preset cloud detection strategy corresponding to each target attribute feature to obtain a second category identifier for the target email includes: Each target attribute feature is input into a preset cloud detection model corresponding to each target attribute feature to perform email category detection, thereby obtaining the second category identifier of the target email.
12. The method according to claim 11, characterized in that, The training process of the preset cloud detection model includes: Retrieve sample emails within a preset historical time period; the sample emails are labeled with email category tags; The sample emails are divided into training samples and validation samples according to a preset ratio; Extract sample email features from the training samples; the sample email features include various types of attribute features of the training samples; Construct a preset machine learning model corresponding to the type of sample attribute features; the sample attribute features are any one of the multiple types of attribute features of the training samples; Based on the preset machine learning model, feature category detection is performed on the sample attribute features to obtain the predicted category; Based on the difference between the predicted category and the email category label, the preset machine learning model is iteratively trained, and the model performance index of the candidate machine learning model corresponding to the current iteration number is determined based on the verification sample according to the preset iteration cycle. After training reaches a preset number of iterations, the candidate machine learning model with the highest model performance index is determined as the preset cloud detection model.
13. The method according to claim 11, characterized in that, The preset cloud detection model includes a preset sending attribute detection model, a preset statistical attribute detection model, and a preset text detection model. The target attribute features include target sending attribute features, target statistical attributes, and target text features. The step of inputting each target attribute feature into a preset cloud detection model corresponding to each target attribute feature to perform email category detection, and obtaining a second category identifier for the target email, includes: The target sending attribute features are input into the preset sending attribute detection model for behavioral feature category detection to obtain the first cloud detection result; The target statistical attribute is input into the preset statistical attribute detection model for statistical feature category detection to obtain the second cloud detection result; The target text features are input into the preset text detection model to perform text category detection, and a third cloud detection result is obtained. The second category identifier is determined based on at least one of the first cloud detection result, the second cloud detection result, and the third cloud detection result.
14. The method according to claim 10, characterized in that, The method further includes: The characteristics of abnormal emails within a preset historical time period are determined as the characteristics of sample emails. The confidence level of the sample email feature is determined based on the cumulative number of times the feature appears. Sample email features with confidence levels greater than or equal to a preset confidence threshold are identified as preset abnormal email features, and a preset abnormal email feature library is formed based on the preset abnormal email features. Send the preset abnormal email feature database to the local server.
15. A computer storage medium, characterized in that, The computer storage medium stores at least one instruction or at least one program, which is loaded and executed by a processor to implement the email processing method as described in any one of claims 1-9 or any one of claims 10-14.