An e-commerce promotion traffic anomaly identification method and system

CN122196854BActive Publication Date: 2026-09-04XIAMEN FINGERPRINT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610678864.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-05-18
Publication Date
2026-09-04
Estimated Expiration
2046-05-18

AI Technical Summary

Technical Problem

[0003]但是上述数据处理方式,仍存在如下缺陷:在电商促销的秒杀中,真实用户因网络延迟、手指触控精度、决策犹豫等因素,其点击坐标、按压时长,按压速度都呈现高度不规则,但是脚本类为了追求执行效率,往往其点击坐标、按压时长,按压速度都高度一致,而现在技术在流量异常的识别过程中,仅对点击量、访问频率等宏观指标进行阈值判断,并未对用户触控操作产生的行为数据进行数据分析,导致脚本这类异常流量无法在数据处理中被有效识别

Benefits of technology

[0041] By analyzing user touch operation data on the target interactive interface, the touch trajectory value, press energy turbulence coefficient, and operation dispersion are calculated to reflect the degree of difference in continuous touch behavior of a single user. The operation dispersion is then subjected to non-overlapping segmentation, recursive matrix analysis, and third-order symbolic difference to obtain local anomaly factors, recursive self-consistency, and rhythm disorder index. These are then fused to obtain a behavior consistency coefficient, further reflecting the regularity of user touch operations. Furthermore, based on the distribution distortion coefficient, outlier suppression factor, and threshold compaction deviation, the touch anomaly confidence level is calculated collaboratively to determine the probability of abnormal access for that user. Combined with order data, collaborative analysis generates identification indicators for identifying abnormal traffic. This solution effectively distinguishes between scripts and real users from two dimensions: micro-touch behavior and order conversion path, improving the accuracy of abnormal traffic identification in e-commerce promotions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122196854B_ABST
    Figure CN122196854B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of flow identification, and discloses an e-commerce promotion flow abnormality identification method and system. The method comprises the following steps: obtaining touch operation data of a user under a target interactive interface; performing data analysis on the preprocessed touch operation data; and generating operation dispersion degree representing the difference degree of continuous touch behaviors of a single user on the target interactive interface. According to the scheme, micro-behavior data of user touch is mined, multiple analyses are performed on touch track values, pressing energy turbulence coefficients and interval variation coefficients, a behavior consistency coefficient is obtained by fusing a local abnormality factor, a recursive self-consistency degree and a rhythm disorder index, and the recognition index is obtained by combining a distribution distortion coefficient, an outlying suppression factor, a threshold tightness deviation amount and order data. According to the scheme, script type abnormal flow can be accurately identified, and the accuracy of flow abnormality detection in e-commerce promotion can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of traffic identification technology, specifically to a method and system for identifying abnormal traffic during e-commerce promotions. Background Technology

[0002] Currently, when analyzing traffic in e-commerce promotions, data such as click volume and visit frequency are usually processed. In data processing, threshold judgment is usually performed to identify traffic anomalies.

[0003] However, the above data processing methods still have the following shortcomings: In e-commerce promotional flash sales, real users exhibit highly irregular click coordinates, press duration, and press speed due to factors such as network latency, finger touch accuracy, and decision-making hesitation. However, scripts, in pursuit of execution efficiency, often exhibit highly consistent click coordinates, press duration, and press speed. Currently, in the process of identifying traffic anomalies, technology only performs threshold judgments on macro indicators such as click volume and access frequency, without analyzing the behavioral data generated by user touch operations. This results in abnormal traffic such as scripts not being effectively identified in data processing. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention provides a method and system for identifying abnormal traffic during e-commerce promotions, thus solving the aforementioned problems.

[0005] The above-mentioned technical objective of the present invention is achieved through the following technical solution:

[0006] A method for identifying abnormal traffic in e-commerce promotions includes:

[0007] Step S1: Obtain the user's touch operation data under the target interactive interface, perform data analysis on the preprocessed touch operation data, and generate operation dispersion representing the degree of difference in continuous touch behavior of a single user on the target interactive interface.

[0008] Step S2: Perform consistency analysis on the operation dispersion of each user to obtain the behavior consistency coefficient representing the regularity of each user's touch operation on the target interactive interface.

[0009] Step S3: Analyze the behavior consistency coefficient of each user, determine the judgment threshold, and analyze the judgment threshold together with the behavior consistency coefficient to obtain the touch anomaly confidence level, which represents the probability that the access request generated by each user is an abnormal access.

[0010] Step S4: Obtain the order data of users in the target interactive interface, and perform joint analysis on the order data and touch anomaly confidence to obtain the traffic anomaly impact weight, which represents the degree of interference of abnormal traffic on the overall traffic conversion.

[0011] Step S5: Identify abnormal access based on the impact weight of abnormal traffic, and obtain identification indicators that indicate abnormal access leading to abnormal traffic.

[0012] Furthermore, data analysis is performed on the preprocessed touch operation data to generate operation dispersion, which represents the degree of difference in continuous touch behavior of a single user on the target interactive interface, including:

[0013] Based on the touch coordinate position in the touch operation data, the fluctuation of each touch point is calculated to generate a touch trajectory value that represents the degree of spatial tortuosity of the touch trajectory.

[0014] Based on the touch press duration and touch press time interval in the touch operation data, the impact momentum is analyzed to generate a press energy turbulence coefficient that represents the intensity of the press energy fluctuation.

[0015] Furthermore, data analysis is performed on the preprocessed touch operation data to generate operation dispersion, which represents the degree of difference in continuous touch behavior of a single user on the target interactive interface. This also includes:

[0016] By performing multiple analyses on touch trajectory values, press energy turbulence coefficients, and touch press time intervals in touch operation data, an operation dispersion is generated that represents the degree of difference in continuous touch behavior of a single user on the target interactive interface.

[0017] Furthermore, a consistency analysis is performed on the operation dispersion of each user to obtain a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface, including:

[0018] After performing non-overlapping segmentation of the operation dispersion of each user, a variation analysis is conducted to generate a local anomaly factor representing the stability of dispersion fluctuation across the window.

[0019] Based on the operational discreteness, a recursion matrix is ​​constructed. The recursion rate and index in the recursion matrix are analyzed to generate a recursive self-consistency degree that represents the degree of repeatability and completeness of the operational discreteness.

[0020] Furthermore, a consistency analysis is performed on the operation dispersion of each user to obtain a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface, which also includes:

[0021] The operational dispersion is subjected to third-order symbolic difference to generate a rhythm disorder index representing the degree of disorder in repetitive behavior patterns;

[0022] By fusing local anomaly factors, recursive self-consistency, and rhythm disorder index, a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface is obtained.

[0023] Furthermore, the behavior consistency coefficient of each user is analyzed to determine the judgment threshold. The judgment threshold and the behavior consistency coefficient are then analyzed together to obtain the touch anomaly confidence score, representing the probability that each user's access request is an abnormal access. This includes:

[0024] A global analysis of the behavioral consistency coefficients of all users is performed to determine the degree of deviation, and a distribution distortion coefficient representing the deviation of the overall behavioral pattern from the normal distribution is generated.

[0025] The behavioral consistency coefficient for each user is calculated to generate an outlier suppression factor that represents the degree of isolation in the user's behavior.

[0026] Furthermore, the behavior consistency coefficient of each user is analyzed to determine the judgment threshold. The judgment threshold and the behavior consistency coefficient are then analyzed together to obtain the touch anomaly confidence score, representing the probability that each user's access request is an abnormal access. This also includes:

[0027] Analyze the distribution distortion coefficient to obtain the judgment threshold, calculate the deviation of each user's behavior consistency coefficient from the judgment threshold, and generate the threshold compaction deviation amount representing the threshold adaptive matching error;

[0028] By coupling the outlier suppression factor with the threshold tightness deviation and then co-calculating it with the distribution distortion coefficient, a touch anomaly confidence score representing the probability that each user's access request is an abnormal access is obtained.

[0029] Furthermore, a joint analysis of order data and touch anomaly confidence levels yields a traffic anomaly impact weight representing the degree of interference of abnormal traffic on overall traffic conversion, including:

[0030] Based on the order time, payment time and order interval in the order data, calculate the relationship between each order and neighboring orders, and generate a causal distortion degree that represents the degree of deviation between the order behavior and the confidence level of touch anomaly.

[0031] The causal distortion degree and touch anomaly confidence degree are calculated and adjusted according to the order interval to generate a traffic anomaly impact weight that represents the degree of interference of abnormal traffic on the overall traffic conversion.

[0032] Furthermore, based on the impact weight of abnormal traffic, abnormal access is identified, resulting in identification indicators that indicate abnormal access leading to abnormal traffic, including:

[0033] An anomaly flooding risk index is generated by calculating the impact weight of each user's traffic anomalies and the confidence level of touch anomalies, and identification indicators are determined based on the anomaly flooding risk index.

[0034] Furthermore, an e-commerce promotional traffic anomaly identification system, applied to the above-mentioned identification method, includes:

[0035] The touch analysis unit is used to acquire the user's touch operation data under the target interactive interface, perform data analysis on the preprocessed touch operation data, and generate operation dispersion representing the degree of difference in continuous touch behavior of a single user on the target interactive interface.

[0036] The behavior analysis unit is used to perform consistency analysis on the operation dispersion of each user and obtain the behavior consistency coefficient representing the regularity of each user's touch operation on the target interactive interface.

[0037] The abnormal access unit is used to analyze the behavior consistency coefficient of each user, determine the judgment threshold, and analyze the judgment threshold and behavior consistency coefficient together to obtain the touch abnormality confidence level, which represents the probability that the access request generated by each user is an abnormal access.

[0038] The traffic anomaly unit is used to obtain the order data of users in the target interactive interface, and to perform joint analysis on the order data and the confidence of touch anomalies to obtain the traffic anomaly impact weight, which represents the degree of interference of abnormal traffic on the overall traffic conversion.

[0039] The traffic identification unit is used to identify abnormal access based on the impact weight of abnormal traffic, and to obtain identification indicators that indicate that abnormal access has caused abnormal traffic.

[0040] In summary, the present invention has the following main beneficial effects:

[0041] By analyzing user touch operation data on the target interactive interface, the touch trajectory value, press energy turbulence coefficient, and operation dispersion are calculated to reflect the degree of difference in continuous touch behavior of a single user. The operation dispersion is then subjected to non-overlapping segmentation, recursive matrix analysis, and third-order symbolic difference to obtain local anomaly factors, recursive self-consistency, and rhythm disorder index. These are then fused to obtain a behavior consistency coefficient, further reflecting the regularity of user touch operations. Furthermore, based on the distribution distortion coefficient, outlier suppression factor, and threshold compaction deviation, the touch anomaly confidence level is calculated collaboratively to determine the probability of abnormal access for that user. Combined with order data, collaborative analysis generates identification indicators for identifying abnormal traffic. This solution effectively distinguishes between scripts and real users from two dimensions: micro-touch behavior and order conversion path, improving the accuracy of abnormal traffic identification in e-commerce promotions. Attached Figure Description

[0042] Figure 1 This is a step diagram of an e-commerce promotional traffic anomaly identification method according to the present invention;

[0043] Figure 2 This is a schematic diagram of an e-commerce promotional traffic anomaly identification system according to the present invention. Detailed Implementation

[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] refer to Figure 1 and Figure 2 A method for identifying abnormal traffic in e-commerce promotions, comprising:

[0046] Step S1: Obtain the user's touch operation data under the target interactive interface, perform data analysis on the preprocessed touch operation data, and generate the operation dispersion that represents the degree of difference in continuous touch behavior of a single user on the target interactive interface. The target interactive interface is the e-commerce promotion interface.

[0047] Touch operation data includes: the coordinates of the user's click on the target interactive interface, the duration of the touch press, the touch press speed, the touch press time interval, and the number of touches;

[0048] Step S2: Perform consistency analysis on the operation dispersion of each user to obtain the behavior consistency coefficient representing the regularity of each user's touch operation on the target interactive interface.

[0049] Step S3: Analyze the behavior consistency coefficient of each user, determine the judgment threshold, and analyze the judgment threshold together with the behavior consistency coefficient to obtain the touch anomaly confidence level, which represents the probability that the access request generated by each user is an abnormal access.

[0050] Step S4: Obtain the order data of users in the target interactive interface, and perform joint analysis on the order data and touch anomaly confidence to obtain the traffic anomaly impact weight, which represents the degree of interference of abnormal traffic on the overall traffic conversion.

[0051] Order data includes: order time, ordered items, payment time, payment amount, and order interval, etc.

[0052] Step S5: Identify abnormal access based on the impact weight of abnormal traffic, and obtain identification indicators that indicate abnormal access leading to abnormal traffic.

[0053] In one embodiment, data analysis is performed on the preprocessed touch operation data to generate operation discreteness, representing the degree of difference in continuous touch behavior of a single user on the target interactive interface, including:

[0054] Based on the touch coordinates in the touch operation data, the fluctuation of each touch point is calculated to generate a touch trajectory value that represents the degree of spatial meandering of the touch trajectory. Specifically, according to the order in which the user touches the screen, the screen coordinates of each click are recorded as the 1st touch point, the 2nd touch point, up to the Nth touch point, where N is the total number of touches by the user on the target interactive interface, and each touch point contains a horizontal coordinate value and a vertical coordinate value.

[0055] For the i-th touch point and the (i+1)-th touch point, calculate the direction angle of its displacement vector: with the difference in the horizontal coordinate as the numerator and the difference in the vertical coordinate as the denominator, obtain the angle between the displacement and the horizontal axis of the screen through the arctangent function, with the value ranging from -180 degrees to +180 degrees, and obtain the direction angle of the displacement vector from the 1st to the (N-1)th displacement vector in sequence, where i is the index, and the value of i ranges from 1 to N minus 1;

[0056] For two consecutive displacement vectors, calculate the absolute difference of their direction angles. If the difference is greater than 180 degrees, subtract the difference from 360 degrees to obtain the actual change in direction. Add up the actual changes in direction of all adjacent displacement vectors to obtain the total cumulative change in direction.

[0057] Add up the Euclidean distances between all adjacent touch points to get the total length. Take the Euclidean distance between the 1st touch point and the Nth touch point as the straight-line distance. This Euclidean distance is the planar distance of the touch coordinates.

[0058] Divide the total cumulative value of directional change by 180 degrees to get the directional detour factor. Then divide the total length by the straight-line distance to get the reciprocal of the path efficiency. Multiply the directional detour factor by the reciprocal to get the touch trajectory value, which represents the degree of detour in the touch trajectory space. The larger the touch trajectory value, the higher the degree of detour in the user's touch trajectory space on the target interactive interface.

[0059] Based on the touch press duration and touch press time interval in the touch operation data, the impact momentum is analyzed to generate a press energy turbulence coefficient that represents the intensity of the press energy fluctuation. Specifically, the following steps are taken: according to the order of touch occurrence, each touch of the same user is numbered as the first, second, and so on. For each touch, the touch press speed is multiplied by the touch press duration, and the calculation result is normalized to the 0-1 range to obtain the impact momentum of that touch. The unit of touch press speed is pixels / ms, and the units of touch press duration and touch press time interval are both ms.

[0060] Calculate the change in impact momentum between two adjacent touches, calculate the absolute value of the difference between the impact momentum of the next touch and the impact momentum of the previous touch, obtain the absolute amount of change for each touch, and sum these absolute changes to obtain the total cumulative value of momentum change; at the same time, calculate the average value of all impact momentum and the average value of all touch press durations, and sum all touch press time intervals between adjacent touches to obtain the total time interval.

[0061] Finally, multiply the cumulative value of total momentum change by the number of touches, then multiply by the average touch press duration, and then divide the product by the product of the average impact momentum and the total time interval to obtain the press energy turbulence coefficient. The larger the value of the press energy turbulence coefficient, the more violent the user's press energy fluctuation on the target interactive interface and the more irregular the touch behavior.

[0062] In one embodiment, data analysis is performed on the preprocessed touch operation data to generate an operation dispersion representing the degree of difference in continuous touch behavior of a single user on the target interactive interface, which further includes:

[0063] Multiple analyses are performed on touch trajectory values, press energy turbulence coefficients, and touch press time intervals in touch operation data to generate operation dispersion, which represents the degree of difference in continuous touch behavior of a single user on the target interactive interface. Specifically, this includes: extracting all touch press time intervals of the same user from the touch operation data, calculating their arithmetic mean and standard deviation, and dividing the standard deviation by the arithmetic mean to obtain the interval variation coefficient.

[0064] The product of touch trajectory value and pressure energy turbulence coefficient, the product of pressure energy turbulence coefficient and interval variation coefficient, and the product of interval variation coefficient and touch trajectory value are calculated separately to obtain three cross-product terms. Then, the geometric mean of touch trajectory value, pressure energy turbulence coefficient and interval variation coefficient is calculated. The sum of the three cross-product terms is divided by the geometric mean to generate the operation dispersion, which represents the degree of difference in continuous touch behavior of a single user on the target interactive interface.

[0065] By performing multi-dimensional feature analysis on the preprocessed touch operation data, touch trajectory values, pressure energy turbulence coefficients, and interval variation coefficients are generated. Further calculations are then performed to obtain the operation dispersion, which reflects the degree of difference in continuous touch behavior of a single user on the target interactive interface. This solution delves into the tortuousness of touch coordinates, the intensity of pressure energy fluctuations, and the variation characteristics of touch press time intervals. Because real users have significantly higher operation dispersion in scenarios such as flash sales due to factors such as network latency, finger precision, and decision hesitation, while script-type abnormal traffic often has highly consistent parameters in pursuit of execution efficiency, resulting in significantly lower operation dispersion. Therefore, this solution can effectively identify and distinguish script traffic at the micro-behavioral level, improving the accuracy of abnormal traffic detection in e-commerce promotions.

[0066] In one embodiment, a consistency analysis is performed on the operation dispersion of each user to obtain a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface, including:

[0067] After performing non-overlapping segmentation of the operation dispersion of each user, a variation analysis is performed to generate a local anomaly factor representing the stability of dispersion fluctuation across windows. Specifically, this includes: dividing the total number of touches by a single user on the target interactive interface into multiple consecutive windows in chronological order without overlap, with each window containing the same number of touches; if the total number of touches cannot be divided evenly by the window size, the remaining touches that are less than one window at the end are discarded.

[0068] For each window, calculate the local dispersion of that window using the same method as calculating the operational dispersion in step S1, and record it as the local dispersion of the first window, the local dispersion of the second window, and so on up to the local dispersion of the last window.

[0069] Calculate the arithmetic mean and standard deviation of the local dispersion of all windows, divide the standard deviation by the mean to obtain the global coefficient of variation; for each window, take two adjacent windows forward and backward with the window as the center, and take the actual adjacent windows at the beginning and end to form a local neighborhood, calculate the ratio of the standard deviation to the mean of the local dispersion in the local neighborhood to obtain the local coefficient of variation of the window, and obtain the local coefficient of variation of multiple windows in turn.

[0070] Calculate the arithmetic mean of all local coefficients of variation, and then divide the arithmetic mean by the global coefficient of variation to obtain the local anomaly factor, which represents the stability of dispersion fluctuation across windows. If the local anomaly factor is greater than 1, it means that the dispersion fluctuation between windows is more unstable in the local range than in the whole, that is, the regularity of the user's touch operation varies significantly at different times. If the local anomaly factor is ≤1, the opposite is true.

[0071] Based on the operation discreteness, a recursive matrix is ​​constructed, the recursion rate and index in the recursive matrix are analyzed, and a recursive self-consistency degree representing the degree of repeatability of the operation discreteness is generated. Specifically, the local discreteness of each window of a single user is arranged into a one-dimensional sequence in chronological order, and a recursive matrix is ​​constructed using this sequence. For any two positions in the recursive matrix, the absolute value of the difference between the local discreteness at these two positions is calculated.

[0072] Multiply the difference between the maximum and minimum values ​​of all pairwise differences in the recursive matrix by 5% to obtain the similarity threshold. If the absolute value is less than the similarity threshold, mark the points corresponding to these two positions as recursive points; otherwise, mark them as non-recursive points.

[0073] The recursion rate is obtained by dividing the total number of recursive points in the recursion matrix by the total number of elements in the recursion matrix.

[0074] For all diagonal segments consisting of consecutive recursive points, count the length of each diagonal and the number of times it appears. Multiply each diagonal length by its frequency to obtain the total number of diagonal points for that length. Then, sum the total number of diagonal points for all different lengths to obtain the total number of recursive points on the diagonal. Divide this total by the total number of recursive points in the recursion matrix and normalize the result to the 0-1 interval to obtain the deterministic index. The deterministic index is used to represent the proportion of regular diagonals in the recursion. Take the square root of the product of the recursion rate and the deterministic index to obtain the recursive self-consistency degree, which represents the degree of repeatability and completeness of the operation discreteness.

[0075] In one embodiment, a consistency analysis is performed on the operation dispersion of each user to obtain a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface, which further includes:

[0076] The operation dispersion is subjected to third-order symbolic difference to generate a rhythm disorder index representing the degree of repetitive disorder of behavioral patterns. Specifically, this includes: arranging the operation dispersion of a single user on the target interactive interface into a sequence in chronological order, with a length equal to the total number of windows after non-overlapping segmentation; performing third-order symbolic difference on this sequence: starting from the first position, the first-order difference, second-order difference, and third-order difference are calculated sequentially; values ​​greater than 0 in the third-order difference are mapped to +1, values ​​less than 0 are mapped to -1, and values ​​equal to 0 are mapped to 0, thus obtaining a symbolic sequence.

[0077] Using a sliding window with a step size of 1, every four consecutive symbols are taken as a pattern, resulting in multiple patterns. The frequency of each pattern in the sequence is counted. The sum of the squares of the frequencies of all patterns is divided by the square of the total number of sliding windows, and then multiplied by 81 to obtain the rhythm disorder index, which represents the degree of disorder in the repetition of behavioral patterns.

[0078] After the third-order symbolic difference, each symbol takes three possible values: -1, 0, or +1. The pattern formed by four consecutive symbols has 3 to the power of 4, or 81 different tuples. Therefore, after multiplying by 81, when the frequency of some patterns is higher than that of a uniform distribution, the sum of squares of the frequencies increases, and the rhythm disorder index is greater than 1, indicating that the behavioral pattern has a tendency to repeat disorder or stereotype.

[0079] By fusing the local anomaly factor, recursive self-consistency, and rhythm disorder index, a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface is obtained. Specifically, the reciprocal of the local anomaly factor is taken to obtain the local stability factor. The larger the value of the local stability factor, the more stable it is across windows. At the same time, since the rhythm disorder index has a negative contribution to the regularity, that is, the larger the rhythm disorder index, the lower the regularity, its reciprocal is used as the rhythm natural factor.

[0080] Multiplying the recursive self-consistency degree by the local stability factor, dividing by the rhythmic natural factor, and normalizing the result to the 0-1 interval, yields the behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface.

[0081] By analyzing the operational dispersion of each user, the local anomaly factor, recursive consistency, and rhythm disorder index are calculated and fused to obtain the behavioral consistency coefficient. Among them, the local anomaly factor reflects the fluctuation stability of operational dispersion within a continuous window, the recursive consistency reflects the degree of repetition and completeness of the operational dispersion sequence, and the second rhythm disorder index reveals the repetitive tendency of behavioral patterns through third-order symbolic difference. This allows for in-depth exploration of the temporal structure and micro-features of user touch behavior, effectively distinguishing real users from script traffic based on behavioral regularity, and improving the accuracy of abnormal traffic identification in e-commerce promotions.

[0082] In one embodiment, the behavior consistency coefficient of each user is analyzed to determine a judgment threshold. The judgment threshold and the behavior consistency coefficient are then analyzed together to obtain a touch anomaly confidence level representing the probability that the access request generated by each user is an abnormal access, including:

[0083] A global analysis is performed on the behavioral consistency coefficients of all users to determine their degree of deviation and generate a distribution distortion coefficient representing the deviation of the overall behavioral pattern from a normal distribution. Specifically, this includes: arranging the behavioral consistency coefficients of all users in ascending order to obtain an ordered sequence; determining the median position of the ordered sequence; dividing the ordered sequence into a left half and a right half based on the median position; if the number of all users is odd, discarding the median itself; calculating the span of the left half and the span of the right half respectively, where the span is the maximum value minus the minimum value; dividing the span of the left half by the span of the right half to obtain the span ratio; if the number of all users is even, removing the two behavioral consistency coefficients in the middle and dividing the sequence into a left half and a right half, and calculating the span ratio using the same method as above.

[0084] Next, calculate the average difference of the consistency coefficient between adjacent rows in the left half and the average difference of the consistency coefficient between adjacent rows in the right half. Divide the average value of the left half by the average value of the right half to obtain the average interval ratio.

[0085] Then, the ratio of the arithmetic mean to the geometric mean of the consistency coefficients of adjacent behaviors of all users is calculated. This ratio reflects the overall dispersion of the intervals. Multiplying the span ratio, the average interval ratio, and the ratio together, we can obtain the distribution distortion coefficient, which indicates that the overall behavior pattern deviates from the normal distribution. When the consistency coefficients of all user behaviors are perfectly symmetrical and the intervals are uniform, the distribution distortion coefficient is equal to 1. If the distribution distortion coefficient is greater than 1, it indicates that the distribution is right-skewed and the intervals are uneven. If the distribution distortion coefficient is less than 1, it indicates that the distribution is left-skewed and the intervals are uneven.

[0086] The behavioral consistency coefficient for each user is calculated to generate an outlier suppression factor representing the degree of isolation in that user's behavior. The specific calculation formula is as follows: ;

[0087] in, Indicates user outlier repression factor Indicates user Behavioral consistency coefficient, Indicates user Local reference, The range represents the consistency coefficient of behavior among all users. Indicates the total number of users. Indicates user The homogeneous suppression coefficient;

[0088] in, The calculation process is as follows: Arrange all users' behavioral consistency coefficients into a sequence from smallest to largest. For the target user, find the ranking of its behavioral consistency coefficient in the sequence. Taking this ranking as the center, count the second position before and the second position after, and take the behavioral consistency coefficients at these two positions. If the behavioral consistency coefficient exceeds the sequence boundary, take the endpoint value of the sequence. Calculate the mean of these two behavioral consistency coefficients as a local benchmark. ;

[0089] The calculation process is as follows: Subtract the local benchmark from the user's behavior consistency coefficient and take the absolute value, then divide by the range of all user behavior consistency coefficients to obtain the original deviation. Count the number of other users whose behavior consistency coefficients differ from the user's coefficient by no more than the original deviation multiplied by the range and divided by the total number of users. Add 1 to the number of other users and take the reciprocal to obtain the homogeneity suppression coefficient. ;

[0090] The outlier suppression factor is mainly used to represent the degree of isolation of a user's behavior. The larger the value of the outlier suppression factor, the more isolated the user's behavior consistency coefficient is in the local neighborhood, the more significant the difference between the regularity of their touch operation and that of surrounding users, and the higher the probability of abnormal access.

[0091] In one embodiment, the behavior consistency coefficient of each user is analyzed to determine a judgment threshold, and the judgment threshold and behavior consistency coefficient are analyzed together to obtain a touch anomaly confidence level representing the probability that the access request generated by each user is an abnormal access. The method also includes:

[0092] Analyze the distribution distortion coefficient to obtain the judgment threshold, calculate the deviation of each user's behavior consistency coefficient from the judgment threshold, and generate a threshold compaction deviation that represents the threshold adaptive matching error. Specifically, this includes arranging all users' behavior consistency coefficients into a sequence from smallest to largest.

[0093] If the distribution distortion coefficient is greater than 1, it indicates that the distribution is right-skewed and the intervals are uneven. In this case, the judgment threshold is set to twice the difference between the 75th percentile and the 50th percentile of the sequence plus the 50th percentile. If the distribution distortion coefficient is less than 1, it indicates that the distribution is left-skewed. In this case, the judgment threshold is set to twice the difference between the 25th percentile and the 50th percentile of the sequence minus the 50th percentile. If the distribution distortion coefficient is equal to 1, the judgment threshold is the arithmetic mean of the consistency coefficients of all behaviors in the sequence.

[0094] For each user, calculate the absolute difference between their behavior consistency coefficient and the judgment threshold, and then divide it by the standard deviation of all behavior consistency coefficients to obtain the original deviation magnitude; at the same time, calculate the coefficient of variation of the behavior consistency coefficient in the local neighborhood of the user, and use it as a local adjustment factor.

[0095] Multiply the original deviation by the local adjustment factor, and then multiply by the absolute value of the difference between the distribution distortion coefficient and 1 to obtain the threshold compaction deviation, which represents the threshold adaptive matching error. The larger the value of the threshold compaction deviation, the higher the probability of abnormal access for the user.

[0096] The outlier suppression factor is coupled with the threshold tightness deviation, and then co-calculated with the distribution distortion coefficient to obtain the touch anomaly confidence score, which represents the probability that each user's access request is an abnormal access. The specific calculation formula is as follows: ;

[0097] in, This represents the confidence level for touch anomalies, with a value ranging from 0 to 1. It indicates the probability that each user's access request is an abnormal access. Indicates the reference standard, Indicates outlier repression factor. This indicates the threshold compaction deviation. Then it represents the logarithmic space pair and These two abnormal indicators are coupled. Represents the distribution distortion coefficient. This is the normalization function, used to compress and map the internal calculation results to the interval [0, 1]. This represents an exponential function with the natural constant e as its base;

[0098] In this process, the outlier suppression factor and threshold compaction deviation of each user are taken as natural logarithms to obtain two logarithmic compressed values. These two logarithmic compressed values ​​are multiplied together and then divided by the sum of their squares to obtain the base value. The base value reflects the degree of coordinated deviation of the two indicators in the compressed space.

[0099] Multiply the base value by the square root of the distribution distortion coefficient to obtain the product result. Then, use the natural constant e as the base and the product result as the exponent to perform a power operation to obtain the intermediate inflation value.

[0100] Sort all users' median inflation values ​​in ascending order. If the sequence length is odd, use the median as the reference value; if the sequence length is even, use the average of the two middle values ​​as the reference value. .

[0101] By analyzing the behavioral consistency coefficient of each user, the distribution distortion coefficient, outlier suppression factor, and threshold compactness deviation are calculated. These are then fused to obtain the touch anomaly confidence score. The distribution distortion coefficient determines the degree to which the behavior patterns of all users deviate from a normal distribution; the outlier suppression factor measures the degree of isolation of a single user within their local neighborhood; and the threshold compactness deviation reflects the matching error between the user and the adaptive judgment threshold. This solution fully utilizes the micro-differences in the regularity of touch behavior. Because real users exhibit a left-skewed distribution of behavioral consistency coefficients and low local isolation in flash sale scenarios, while script-based traffic, due to its highly regularized operations and statistical patterns, shows a significantly right-skewed behavioral consistency coefficient and a higher outlier suppression factor, the touch anomaly confidence score accurately represents the probability of abnormal access, thereby improving the ability to identify script traffic in e-commerce promotions.

[0102] In one embodiment, a joint analysis of order data and touch anomaly confidence levels is performed to obtain a traffic anomaly impact weight representing the degree of interference of abnormal traffic on overall traffic conversion, including:

[0103] Based on the order time, payment time, and order interval in the order data, the relationship between each order and adjacent orders is calculated, and a causal distortion degree representing the degree of deviation between the order behavior and the confidence level of touch anomaly is generated. Specifically, this includes: for each user, arranging all their orders in chronological order to obtain the order sequence, calculating the payment delay of each order (i.e., payment time minus order time), and the time interval between adjacent orders (i.e., the order time of the next order minus the order time of the previous order).

[0104] For each order in the sequence, excluding the first and last orders, compare the direction of change of the two time intervals before and after the order with the direction of change of the two payment delays before and after the order. If the payment delay increases when the time interval increases or decreases when the time interval decreases, the direction is considered to be consistent; otherwise, it is inconsistent.

[0105] The proportion of orders with inconsistent directions in the statistical sequence is used to obtain the local temporal deviation rate of the user. The local temporal deviation rate of the user is multiplied by the square root of the touch anomaly confidence level to obtain the weighted deviation rate. The arithmetic mean of the weighted deviation rates of all users is calculated, and then multiplied by the overall coefficient of variation of payment delay of all users. This gives the causal distortion degree, which represents the degree of causal deviation between the order placement behavior and the touch anomaly confidence level. The coefficient of variation is the ratio of the standard deviation to the mean.

[0106] The greater the causal distortion, the worse the causal coordination between the order time series and the payment delay. This deviation is more significant among users with a high probability of anomalies, thus reflecting the degree of interference of abnormal traffic on the normal conversion path.

[0107] The causal distortion degree and touch anomaly confidence degree are calculated and adjusted according to the order interval to generate a traffic anomaly impact weight representing the degree of interference of abnormal traffic on overall traffic conversion. Specifically, this includes:

[0108] For all users who have placed orders ≥ twice, calculate the arithmetic mean and geometric mean of the time interval between adjacent orders. Divide the geometric mean by the arithmetic mean to obtain the individual interval uniformity factor for the user. For users who have placed orders only once, the individual interval uniformity factor is directly set to 1.

[0109] The order intervals of all users are merged into a sequence, and the ratio of the geometric mean to the arithmetic mean of the sequence is calculated to obtain the global interval uniformity factor.

[0110] For each user, the global interval uniformity factor is divided by the user's individual interval uniformity factor, and then the natural logarithm is taken and multiplied by the user's touch anomaly confidence level to obtain the interval correction index. If the user's individual interval uniformity factor is 1, then the global interval uniformity factor is used as the interval correction index.

[0111] Using the causal distortion degree as the base and the interval correction exponent as the exponent, the intermediate coupling value is obtained by exponentiation. If the causal distortion degree is equal to 0, the intermediate coupling value is also 0.

[0112] Arrange the intermediate coupling values ​​of all users in ascending order, take the 90th percentile as the upper limit reference value, divide the intermediate coupling value of each user by the upper limit reference value, and normalize the calculation result to the 0-1 range. This gives the traffic anomaly impact weight, which represents the degree of interference of abnormal traffic on the overall traffic conversion. The larger the traffic anomaly impact weight, the higher the degree of interference of abnormal traffic on the overall traffic conversion.

[0113] In one embodiment, abnormal access is identified based on the impact weight of abnormal traffic, resulting in identification indicators that indicate abnormal access leading to abnormal traffic, including:

[0114] An anomaly flooding risk index is generated by calculating the impact weight of each user's traffic anomaly and the confidence level of touch anomaly. Based on the anomaly flooding risk index, identification indicators are determined. Specifically, for each user, the geometric mean of their touch anomaly confidence level and traffic anomaly impact weight is calculated, and then the harmonic mean of the two is calculated. The geometric mean is divided by the harmonic mean to obtain the coupling coefficient.

[0115] Arrange all users' coupling coefficients in ascending order, calculate the difference between each coupling coefficient in the sequence and its previous coupling coefficient, take the median of the absolute values ​​of all differences as the scaling benchmark, for each user, subtract the median of the sequence from its coupling coefficient, divide by the scaling benchmark, and then normalize to the 0-1 interval to obtain the abnormal flooding risk index.

[0116] The geometric mean of the abnormal flooding risk index of all users is used as a dynamic dividing point. If the abnormal flooding risk index of a user is greater than the geometric mean, the identification index is 0, indicating abnormal traffic and an alarm is issued. Otherwise, the identification index is 1, indicating normal traffic.

[0117] By jointly analyzing order data and touch anomaly confidence, the causal distortion degree, individual interval uniformity factor, and global interval uniformity factor are calculated to obtain the traffic anomaly impact weight. An anomaly flooding risk index and identification indicators are then generated. This solution deeply integrates the micro-behavioral characteristics of user touch operations with order conversion behavior. The resulting traffic anomaly impact weight can reflect the degree of interference of abnormal traffic on the overall conversion path. The anomaly flooding risk index and dynamic separation point can adaptively identify abnormal access, effectively distinguish between script traffic and real users, and improve the accuracy of traffic anomaly detection in e-commerce promotions.

[0118] In one embodiment, an e-commerce promotional traffic anomaly identification system, applied to the above-described identification method, includes:

[0119] The touch analysis unit is used to acquire the user's touch operation data under the target interactive interface, perform data analysis on the preprocessed touch operation data, and generate operation dispersion representing the degree of difference in continuous touch behavior of a single user on the target interactive interface.

[0120] The behavior analysis unit is used to perform consistency analysis on the operation dispersion of each user and obtain the behavior consistency coefficient representing the regularity of each user's touch operation on the target interactive interface.

[0121] The abnormal access unit is used to analyze the behavior consistency coefficient of each user, determine the judgment threshold, and analyze the judgment threshold and behavior consistency coefficient together to obtain the touch abnormality confidence level, which represents the probability that the access request generated by each user is an abnormal access.

[0122] The traffic anomaly unit is used to acquire user order data in the target interactive interface, and to perform joint analysis on the order data and touch anomaly confidence to obtain the traffic anomaly impact weight, which represents the degree of interference of abnormal traffic on the overall traffic conversion.

[0123] The traffic identification unit is used to identify abnormal access based on the impact weight of abnormal traffic, and to obtain identification indicators that indicate that abnormal access has caused abnormal traffic.

[0124] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for identifying abnormal traffic in e-commerce promotions, characterized in that, include: Step S1: Obtain the user's touch operation data under the target interactive interface, perform data analysis on the preprocessed touch operation data, and generate operation dispersion representing the degree of difference in continuous touch behavior of a single user on the target interactive interface. Step S2: Perform consistency analysis on the operation dispersion of each user to obtain the behavior consistency coefficient representing the regularity of each user's touch operation on the target interactive interface. Step S3: Analyze the behavior consistency coefficient of each user, determine the judgment threshold, and analyze the judgment threshold and behavior consistency coefficient together to obtain the touch anomaly confidence level, which represents the probability that the access request generated by each user is an abnormal access. This includes: performing a global analysis of the behavior consistency coefficient of all users, determining its deviation degree, and generating a distribution distortion coefficient that represents the deviation of the overall behavior pattern from the normal distribution. Calculate the behavioral consistency coefficient for each user to generate an outlier suppression factor that represents the degree of isolation in the user's behavior; Analyze the distribution distortion coefficient to obtain the judgment threshold, calculate the deviation of each user's behavior consistency coefficient from the judgment threshold, and generate the threshold compaction deviation amount representing the threshold adaptive matching error; The outlier suppression factor is coupled with the threshold tightness deviation and then co-calculated with the distribution distortion coefficient to obtain the touch anomaly confidence, which represents the probability that the access request generated by each user is an abnormal access. Step S4: Obtain the user's order data in the target interactive interface, perform joint analysis on the order data and touch anomaly confidence, and obtain the traffic anomaly impact weight representing the degree of interference of abnormal traffic on the overall traffic conversion. This includes: calculating the relationship between each order and neighboring orders based on the order time, payment time and order interval in the order data, and generating the causal distortion degree representing the degree of deviation between the order behavior and the touch anomaly confidence. The causal distortion degree and touch anomaly confidence degree are calculated and corrected according to the order interval to generate a traffic anomaly impact weight that represents the degree of interference of abnormal traffic on the overall traffic conversion. Step S5: Identify abnormal access based on the impact weight of abnormal traffic, and obtain identification indicators that indicate abnormal access leading to abnormal traffic. This includes: calculating an abnormal flooding risk index based on the impact weight of abnormal traffic and the confidence level of touch abnormality for each user, and determining the identification indicators based on the abnormal flooding risk index.

2. The method for identifying abnormal e-commerce promotional traffic according to claim 1, characterized in that, Data analysis is performed on the preprocessed touch operation data to generate operation dispersion, which represents the degree of difference in continuous touch behavior of a single user on the target interactive interface, including: Based on the touch coordinate position in the touch operation data, the fluctuation of each touch point is calculated to generate a touch trajectory value that represents the degree of spatial tortuosity of the touch trajectory. Based on the touch press duration and touch press time interval in the touch operation data, the impact momentum is analyzed to generate a press energy turbulence coefficient that represents the intensity of the press energy fluctuation.

3. The method for identifying abnormal e-commerce promotional traffic according to claim 2, characterized in that, Data analysis is performed on the preprocessed touch operation data to generate operation dispersion, which represents the degree of difference in continuous touch behavior of a single user on the target interactive interface. This also includes: By performing multiple analyses on touch trajectory values, press energy turbulence coefficients, and touch press time intervals in touch operation data, an operation dispersion is generated that represents the degree of difference in continuous touch behavior of a single user on the target interactive interface.

4. The method for identifying abnormal e-commerce promotional traffic according to claim 3, characterized in that, A consistency analysis is performed on the operation dispersion of each user to obtain a behavioral consistency coefficient representing the regularity of each user's touch operations on the target interactive interface, including: After performing non-overlapping segmentation of the operation dispersion of each user, a variation analysis is conducted to generate a local anomaly factor representing the stability of dispersion fluctuation across the window. Based on the operational discreteness, a recursion matrix is ​​constructed. The recursion rate and index in the recursion matrix are analyzed to generate a recursive self-consistency degree that represents the degree of repeatability and completeness of the operational discreteness.

5. The method for identifying abnormal e-commerce promotional traffic according to claim 4, characterized in that, A consistency analysis is performed on the operation dispersion of each user to obtain a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface, which also includes: The operational dispersion is subjected to third-order symbolic difference to generate a rhythm disorder index representing the degree of disorder in repetitive behavior patterns; By fusing local anomaly factors, recursive self-consistency, and rhythm disorder index, a behavioral consistency coefficient representing the regularity of each user's touch operation on the target interactive interface is obtained.

6. An e-commerce promotional traffic anomaly identification system, applied in the identification method as described in any one of claims 1-5, characterized in that, include: The touch analysis unit is used to acquire the user's touch operation data under the target interactive interface, perform data analysis on the preprocessed touch operation data, and generate operation dispersion representing the degree of difference in continuous touch behavior of a single user on the target interactive interface. The behavior analysis unit is used to perform consistency analysis on the operation dispersion of each user and obtain the behavior consistency coefficient representing the regularity of each user's touch operation on the target interactive interface. The abnormal access unit is used to analyze the behavior consistency coefficient of each user, determine the judgment threshold, and analyze the judgment threshold and behavior consistency coefficient together to obtain the touch abnormality confidence level, which represents the probability that the access request generated by each user is an abnormal access. The traffic anomaly unit is used to obtain the order data of users in the target interactive interface, and to perform joint analysis on the order data and the confidence of touch anomalies to obtain the traffic anomaly impact weight, which represents the degree of interference of abnormal traffic on the overall traffic conversion. The traffic identification unit is used to identify abnormal access based on the impact weight of abnormal traffic, and to obtain identification indicators that indicate that abnormal access has caused abnormal traffic.

Citation Information

Patent Citations

  • Flow data-based fraudulent user identification method and device

    CN116055119A

  • Electronic commerce management system and method based on big data

    CN119990778A