Account behavior anomaly monitoring method, device, equipment, medium and program product
By calculating the similarity of account behavior and risk factors, the problem of low accuracy in monitoring abnormal account behavior in existing technologies has been solved, achieving more efficient anomaly identification and dynamic adaptive monitoring.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2026-03-12
- Publication Date
- 2026-07-28
AI Technical Summary
In existing technologies, abnormal account behavior monitoring relies on predefined static rules, resulting in low accuracy in anomaly identification and difficulty in identifying complex abnormal behaviors.
By acquiring real-time behavioral information and historical behavioral patterns of target accounts, the similarity between current behavior and historical behavioral patterns is calculated, and anomaly monitoring results are generated by combining risk factors. This approach comprehensively utilizes multi-source heterogeneous data such as account attributes, operation sequences, and environmental context.
It significantly improves the accuracy of anomaly identification, reduces false positives, and is more sensitive to identifying complex risks, while possessing continuous adaptability and intelligence.
Smart Images

Figure CN122472872A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing, and in particular to a method, apparatus, device, medium, and program product for monitoring abnormal account behavior. Background Technology
[0002] In the business scenarios of banks and other financial institutions, users generally use mobile phones and other terminal devices to log in to software accounts to conduct online payments, transfers and remittances. To ensure the safety of users' funds, it is necessary to monitor abnormal behaviors such as user misoperations.
[0003] Currently, anomaly monitoring of account behavior relies on predefined static rules, such as setting thresholds for single transaction amounts. However, this rule-based approach has significant limitations; it simplifies anomaly monitoring to a numerical comparison of a single feature, resulting in a simplistic rule set and low accuracy in anomaly identification. Summary of the Invention
[0004] This application provides a method, apparatus, device, medium, and program product for monitoring abnormal account behavior, in order to solve the technical problem of low accuracy in identifying abnormal account behavior.
[0005] Firstly, this application provides a method for monitoring abnormal account behavior, including:
[0006] Obtain real-time behavioral information and historical behavioral patterns of the target account;
[0007] Based on real-time behavioral information, calculate the similarity between the target account's current behavior and historical behavioral patterns;
[0008] Risk factors for target accounts are determined based on historical behavioral patterns and real-time behavioral information.
[0009] Anomaly monitoring results for current behavior are generated based on similarity and risk factors.
[0010] Secondly, this application provides an account behavior anomaly monitoring device, comprising:
[0011] The acquisition module is used to acquire real-time behavioral information and historical behavioral patterns of the target account;
[0012] The similarity processing module is used to calculate the similarity between the current behavior and historical behavior patterns of a target account based on real-time behavior information.
[0013] The risk processing module is used to determine the risk factors of a target account based on historical behavior patterns and real-time behavior information.
[0014] The monitoring module is used to generate abnormal monitoring results for the current behavior based on similarity and risk factors.
[0015] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;
[0016] The memory stores the instructions that the computer executes;
[0017] The processor executes computer execution instructions stored in memory to implement an account behavior anomaly monitoring method as described in any of the first aspects.
[0018] Fourthly, this application provides a computer-readable storage medium, comprising: computer-executable instructions stored in the computer-readable storage medium, wherein the computer-executable instructions, when executed by a processor, are used to implement the account behavior anomaly monitoring method as described in any of the first aspects.
[0019] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements an account behavior anomaly monitoring method as described in any of the first aspects.
[0020] The account behavior anomaly monitoring method, device, equipment, medium, and program products provided in this application acquire real-time behavior information and historical behavior patterns of target accounts, can calculate the similarity between current behavior and historical behavior patterns, and can also determine the risk factors of the target account. Finally, anomaly monitoring results are generated based on the similarity and risk factors. The similarity calculation can cover multi-source heterogeneous data such as account attributes, operation sequences, and environmental context, while the risk factors can characterize the impact of obvious abnormal behavior. Combining these two dimensions overcomes the problems of traditional monitoring methods having single features and simple anomaly judgment, reduces false positives, and significantly improves the accuracy of anomaly identification. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0022] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;
[0023] Figure 2 A flowchart illustrating an account behavior anomaly monitoring method provided in this application embodiment;
[0024] Figure 3 A flowchart illustrating a method for correcting historical behavior patterns, provided as an embodiment of this application;
[0025] Figure 4 This is a schematic diagram of the structure of an account behavior anomaly monitoring device provided in an embodiment of this application;
[0026] Figure 5This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0027] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0028] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0029] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.
[0030] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0031] It should be noted that the account behavior anomaly monitoring methods, devices, equipment, media and program products provided in this application can be used in the fintech field, or in any field other than fintech. The application fields of the account behavior anomaly monitoring methods, devices, equipment, media and program products in this application are not limited.
[0032] In financial transaction scenarios, monitoring abnormal user account behavior is a core aspect of ensuring fund security. With the rapid development of internet finance, users are making transfers and payments more frequently via mobile phones, computers, and other terminal devices. However, at the same time, monitoring abnormal behaviors such as account theft and user misoperation has become even more important.
[0033] Currently, anomaly monitoring of account behavior relies on predefined static rule engines. This monitoring method has significant limitations. These rule engines primarily determine anomalies by comparing specific indicators such as transaction amounts. Their rules are simple and mechanical, with single characteristic indicators, and their accuracy is usually poor. For example, when a user's account is stolen, attackers can easily disguise their actions by making multiple small transfers, bypassing the rule engine's anomaly detection criteria, making it impossible to identify abnormal behavior.
[0034] To address the low accuracy of anomaly detection in account behavior, this application proposes a technical concept: modeling user historical behavior patterns based on historical account data, monitoring real-time account behavior information and calculating similarity to historical behavior patterns, determining risk factors based on historical behavior patterns and current real-time behavior information, and comprehensively identifying anomalies by combining these two dimensions: risk factors and the similarity between current and historical behavior patterns. The similarity calculation can encompass multi-source heterogeneous data such as account attributes, operation sequences, and environmental context. Combined with the risk factors present in the current behavior, this significantly improves the accuracy of anomaly detection.
[0035] Figure 1 This is a schematic diagram illustrating an application scenario provided by an embodiment of this application. For example... Figure 1 As shown, terminal 102 communicates with server 101 via a network. A data storage system can store the data that server 101 needs to process. The data storage system can be integrated onto server 101 or located in the cloud or on other network servers. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Server 101 can be implemented using a standalone server or a server cluster consisting of multiple servers.
[0036] The account behavior anomaly monitoring methods, devices, equipment, media, and program products provided in this application can be applied to, for example... Figure 1In the application environment shown, terminal 102 can run software clients related to financial services such as mobile banking. Users can log in to their accounts and perform business operations such as payments and transfers through the software clients on terminal 102. The data storage system can contain a database of any architecture, which can store historical data of user accounts and rules or models related to anomaly detection. Server 101 can obtain user account information and real-time behavioral data of users through the software clients by communicating with terminal 102. Then, server 101 can perform anomaly monitoring based on this data and execute subsequent business processes based on the anomaly monitoring results.
[0037] The account behavior anomaly monitoring methods, devices, equipment, media, and program products provided in this application are intended to solve the above-mentioned technical problems of the prior art.
[0038] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0039] Figure 2 This is a flowchart illustrating a method for monitoring abnormal account behavior provided in an embodiment of this application. Figure 2 As shown, the method includes:
[0040] Step S201: Obtain real-time behavior information and historical behavior patterns of the target account.
[0041] The account behavior anomaly monitoring method of this application embodiment can be applied to server 101 in the above application scenario, executed by the monitoring system running on the server, or it can be applied to other scenarios.
[0042] In this embodiment, real-time behavioral information may include the current account's attributes (such as account level, customer group to which the account belongs), login device, login region, time, and behavioral operations such as fund transfers. Historical behavioral patterns may be multi-dimensional features obtained by modeling the account's historical behavioral information, and may include the user's frequently used login regions, times, devices, user operating habits, and behavioral baselines. The behavioral baseline may be a user behavior reference benchmark (such as feature weights and confidence intervals) generated by a machine learning model based on historical behavioral information.
[0043] Step S202: Calculate the similarity between the target account's current behavior and historical behavior patterns based on real-time behavior information.
[0044] The core of this step is to quantitatively compare a user's current action or series of actions through their account with their long-term historical behavior patterns, thereby obtaining a similarity score that reflects the degree to which the current behavior deviates from the user's historical behavior habits.
[0045] In this embodiment, the historical behavior pattern is not a simple accumulation of raw data, but a dynamic profile formed after in-depth mining and modeling of user historical behavior information. The historical behavior pattern includes multi-dimensional feature benchmarks, such as static profiles like the user's frequently logged-in geographical area, frequently used device fingerprints, and typical active time periods, as well as a behavioral baseline. This baseline defines a reference benchmark and normal fluctuation range for each key feature (such as transaction time, amount, and operation rhythm). When calculating similarity, the system performs multi-dimensional analysis: for example, regarding the login time feature, if the user's behavioral baseline shows that their frequently used time period is weekdays from 9:00 to 17:00, while the current login time is 2:00 AM, the system calculates the time difference and maps it to a lower "time dimension similarity component." Simultaneously, the system can also analyze the context sequence of behavior, such as the operation chain of "login → check balance → large transfer," and perform a matching degree analysis with the user's historical habit chain of "login → check balance → small consumption or financial management," calculating the corresponding similarity component. Finally, by weighted fusion of all dimensions of similarity components, a comprehensive total similarity is output.
[0046] Step S203: Determine the risk factors of the target account based on historical behavior patterns and real-time behavior information.
[0047] Risk factors may include operating in uncommon locations, operating with uncommon equipment, and unusual transaction amounts.
[0048] The core of this step is to perform anomaly detection in a specific direction on the current behavior, in addition to calculating the overall similarity. The goal is to identify individual features or combinations of features that clearly and specifically deviate from the user's historical behavior patterns.
[0049] Specifically, key dimensions in real-time behavioral information (such as geographic location, transaction amount, device identification, etc.) can be compared one by one with the corresponding behavioral baselines in historical behavioral patterns. For example, if a user's behavioral baseline shows that their frequently used login locations are concentrated in city A, but the current real-time login location is from a city C that has never appeared before, then the risk factor of an uncommon location is identified. Similarly, if the baseline of a user's historical transaction amount (such as a normal distribution) shows that 95% of their transactions are within 10,000 yuan, but the current real-time transaction amount suddenly reaches 100,000 yuan, then the risk factor of an unusual transaction amount is identified. In addition, using unbound / unrecorded devices, initiating sensitive operations during unusually active periods (such as 3 a.m.), etc., can all be identified as risk factors.
[0050] Step S204: Generate anomaly monitoring results for the current behavior based on similarity and risk factors.
[0051] The core of this step is to comprehensively analyze the quantitative indicator of similarity obtained earlier and the qualitative indicator of risk factors, thereby generating a clear anomaly monitoring result.
[0052] In the embodiments of this application, the anomaly monitoring results can be regression-type numerical results, such as anomaly scores or risk scores. The anomaly monitoring results can also be categorized discrete results; for example, binary classification can include two types: anomaly and non-anomaly, while tri- or more classifications can include multiple types such as non-anomaly, low-risk anomaly, medium-risk anomaly, and high-risk anomaly.
[0053] For example, a composite rule can be predefined for both similarity and risk factors. This rule can correlate the numerical range of similarity with the specific type, quantity, and combination of identified risk factors. For instance, if the similarity is below a first threshold and both uncommon location operation and uncommon equipment operation are identified as risk factors, a high-risk anomaly level monitoring result is generated. If the similarity is only below the first threshold but no risk factors are identified, a medium-risk anomaly level monitoring result is generated.
[0054] In this embodiment, after obtaining the anomaly monitoring results, the system can also make risk decisions and take actions such as secondary verification or behavior interception for abnormal behavior. For example, the anomaly monitoring results can be a risk score. When the score is below 30, the system does not need to take any action; when the score is greater than 30 but less than 70, the system initiates a secondary verification request to the client, requiring the user to verify again whether the current behavior is abnormal; when the score is greater than 70, an interception operation can be directly taken.
[0055] For example, a user logs into their account in city A using a new device and transfers 100,000 yuan. The client collects real-time behavioral information as {Location: City A-a1 area, Device: New mobile phone, Amount: 100,000}. After obtaining the data collected by the client, the system calls the user's historical behavior patterns and finds that the user is based in city B and has never logged into their account in city A. Furthermore, the transfer amount far exceeds the historical maximum amount. Based on comprehensive analysis, the system outputs a risk score of 85. The system then makes a decision based on the risk score to automatically intercept the transfer operation and issue an alarm.
[0056] The account behavior anomaly monitoring method in this embodiment acquires real-time behavior information and historical behavior patterns of the target account. It can calculate the similarity between the current behavior and the historical behavior patterns, and also determine the risk factors of the target account. Finally, it generates anomaly monitoring results based on the similarity and risk factors. The similarity calculation can cover multi-source heterogeneous data such as account attributes, operation sequences, and environmental context. The risk factors can characterize the impact of obvious abnormal behavior. Combining these two dimensions overcomes the problems of single features and simple anomaly judgment in traditional monitoring methods, reduces false positives, and significantly improves the accuracy of anomaly identification.
[0057] In one embodiment, calculating the similarity between the target account's current behavior and historical behavior patterns based on real-time behavioral information includes:
[0058] Multimodal features are extracted from real-time behavioral information and the extraction results are fused to obtain the multimodal feature vector corresponding to the current behavior. The multimodal feature vector is compared with the behavioral baseline generated based on historical behavioral patterns, and the comprehensive similarity is calculated.
[0059] For example, multimodal features such as account attributes, operation sequences, and environmental context can be extracted from real-time behavioral information. These heterogeneous features can be mapped to a unified high-dimensional vector space, thereby generating a multi-dimensional feature vector that can comprehensively represent the current complex behavioral state. Then, the behavioral baseline can also be mapped to the same high-dimensional space, and the comprehensive similarity between the two high-dimensional vectors can be accurately quantified by calculating measures such as the distance or the cosine of the angle between them in this shared space.
[0060] In the above embodiments, similarity calculation is achieved by multimodal feature fusion and behavioral baseline comparison. This can comprehensively utilize multiple features of the current behavior, overcome the one-sidedness of a single data feature, and by comparing with a dynamic baseline, not only can deviations in surface behavior be perceived, but also the inherent consistency of behavioral patterns can be understood in depth, thereby greatly improving the accuracy of similarity assessment and providing a high-quality data foundation for subsequent anomaly detection.
[0061] In one embodiment, when calculating the overall similarity, a behavioral chain sequence representing the order and logical association of behaviors can be extracted based on real-time behavioral information; the behavioral chain sequence is matched and analyzed with the baseline sequence contained in the behavioral baseline, and the sequence similarity component is calculated as a key factor of the overall similarity.
[0062] In this embodiment, similarity can be calculated from the contextual logic level of the behavior sequence. Specifically, operation events arranged in chronological order and with inherent logical connections can be extracted from real-time behavior information to form the current behavior chain sequence. This sequence is then matched and analyzed one by one with multiple typical historical behavior chain sequences (i.e., baseline sequences) pre-stored in the behavior baseline. The similarity between the current behavior chain sequence and each baseline sequence is calculated, and the maximum value is selected as the sequence similarity component reflecting the degree of fit between the current behavior and the historical behavior pattern. This component can be incorporated into the comprehensive similarity calculation as a key factor.
[0063] In the above embodiments, by calculating the similarity based on the behavior chain sequence, it is possible to effectively identify abnormal operations that appear normal in a single feature dimension but have an incorrect combination of operation sequences, thereby reducing the risk of missed detections due to ignoring the operation context.
[0064] In one embodiment, anomaly monitoring results for current behavior are generated based on similarity and risk factors, including:
[0065] Obtain a similarity threshold for anomaly detection; adjust the similarity threshold based on risk factors, compare the calculated similarity with the similarity threshold, and generate anomaly monitoring results based on the comparison results.
[0066] In this embodiment, a basic similarity threshold is first obtained, and then the threshold is dynamically adjusted upwards based on the identified specific risk factors. After adjustment, the system compares the calculated comprehensive similarity with this new, more stringent threshold. If the similarity is lower than the new threshold, it can be determined that the system meets the risk score or abnormality level corresponding to that threshold.
[0067] For example, the basic similarity threshold is 0.6. If the similarity is below 0.6, it is considered to be abnormal. If the calculated similarity is 0.7, there is no abnormality when comparing the similarity alone. However, if a risk factor is identified and the similarity threshold is adjusted from 0.6 to 0.8 based on the risk factor, then a similarity of 0.7 will be considered to be abnormal.
[0068] In the above embodiments, by introducing risk factors to adjust static thresholds in real time, dynamic decision-making under risk perception can be achieved, significantly improving the accuracy and adaptability in dealing with complex risks. When a clear risk factor appears, by automatically raising the judgment threshold, the current behavior can be more sensitively and accurately marked as abnormal, thereby effectively preventing high-risk underreporting and improving the interpretability of anomaly monitoring results.
[0069] In one embodiment, such as Figure 3 As shown, after generating the anomaly monitoring results for the current behavior, the following is also included:
[0070] Step S301: Obtain user feedback information regarding the anomaly monitoring results.
[0071] Step S302: Dynamically correct historical behavior patterns based on user feedback.
[0072] In the embodiments of this application, historical behavior patterns can be updated and corrected based on user feedback, thereby achieving closed-loop self-learning evolution based on user feedback.
[0073] For example, after generating anomaly monitoring results and taking corresponding measures (such as secondary verification), feedback information from user clients or human reviewers can be proactively collected. For instance, when a user completes secondary verification and confirms that the transaction was performed by them and there are no anomalies, this confirmation of a safe transaction will be recorded. Subsequently, the system can use this feedback, such as incorporating the behavioral characteristics of the misjudged transaction into the learning sample, to periodically update and dynamically correct the original historical behavioral patterns and baselines, thereby achieving continuous optimization of the system model.
[0074] In the above embodiments, establishing a feedback loop enables the system to self-learn and evolve. As user habits naturally change or actively evolve, the system captures and learns these new behavioral patterns in a timely manner through feedback, avoiding continuous false alarms due to outdated models. The introduction of manual review and feedback can also provide a means to correct complex misjudgments and deal with new anomaly patterns, enabling anomaly monitoring to have continuously improving adaptability and intelligence.
[0075] In one embodiment, obtaining real-time behavioral information and historical behavioral patterns of the target account further includes:
[0076] Perform anonymization operations on real-time behavioral information and historical behavioral patterns.
[0077] The de-identification process includes blurring geographical location information and user identity information.
[0078] In this application embodiment, privacy protection design can be integrated at the source stage of data acquisition and processing. Specifically, sensitive data in real-time and historical behavioral information can be anonymized. For example, the precise user's geographical location can be blurred into a 500-meter square area code and encrypted for storage, instead of recording the specific address. In terms of data architecture, information that can directly identify an individual can be physically isolated from the user's historical behavioral patterns and stored in different secure databases. In addition, automatic tasks can be set to periodically and securely clear the original detailed data after feature extraction and model updates are completed.
[0079] In the above embodiments, by taking de-identification measures, the risk of exposure of privacy data during storage, transmission and computing can be reduced, thus protecting the personal privacy and security of users.
[0080] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0081] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0082] Figure 4 This is a schematic diagram of the structure of an account behavior anomaly monitoring device provided in an embodiment of this application, as shown below. Figure 4 As shown, the account behavior anomaly monitoring device 400 includes:
[0083] The acquisition module 401 is used to acquire real-time behavior information and historical behavior patterns of the target account;
[0084] The similarity processing module 402 is used to calculate the similarity between the current behavior and the historical behavior pattern of the target account based on real-time behavior information.
[0085] Risk processing module 403 is used to determine the risk factors of the target account based on historical behavior patterns and real-time behavior information;
[0086] Monitoring module 404 is used to generate abnormal monitoring results of the current behavior based on similarity and risk factors.
[0087] In some possible implementations, the similarity processing module 402 can also be used to: extract multimodal features from real-time behavioral information and fuse the extraction results to obtain the multimodal feature vector corresponding to the current behavior; compare the multimodal feature vector with the behavioral baseline generated based on historical behavioral patterns, and calculate the comprehensive similarity.
[0088] In some possible implementations, the similarity processing module 402 can also be used to: extract behavioral chain sequences that represent the order and logical association of behaviors based on real-time behavioral information; perform matching analysis between the behavioral chain sequences and the baseline sequences contained in the behavioral baseline, and calculate the sequence similarity component as a key factor of the comprehensive similarity.
[0089] In some possible implementations, the monitoring module 404 can also be used to: obtain a similarity threshold for anomaly determination; correct the similarity threshold based on risk factors, compare the calculated similarity with the similarity threshold, and generate anomaly monitoring results based on the comparison results.
[0090] In some possible implementations, the monitoring module 404 can also be used to: obtain user feedback information on abnormal monitoring results; and dynamically correct historical behavior patterns based on user feedback information.
[0091] In some possible implementations, the acquisition module 401 can also be used to: perform desensitization operations on real-time behavioral information and historical behavioral patterns, including obfuscating geographic location information and user identity information.
[0092] The account behavior anomaly monitoring device provided in this embodiment is used to execute the technical solutions in any of the aforementioned method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0093] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0094] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0095] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 5 As shown, the electronic device 50 includes:
[0096] Processor 51, memory 52, and communication interface 53;
[0097] The memory 52 is used to store the executable instructions of the processor 51; the executable instructions can be instructions that the computer can execute.
[0098] The processor 51 is configured to execute the technical solutions in any of the foregoing method embodiments by executing executable instructions.
[0099] Optionally, the memory 52 can be either standalone or integrated with the processor 51.
[0100] Optionally, when the memory 52 is a device independent of the processor 51, the electronic device 50 may further include:
[0101] Bus 54, memory 52 and communication interface 53 are connected to processor 51 through bus 54 and complete communication with each other. Communication interface 53 is used to communicate with other devices.
[0102] Optionally, the communication interface 53 can be implemented using a transceiver. The communication interface is used to enable communication between the database access device and other devices (e.g., clients, read-write databases, and read-only databases). The memory may include random access memory (RAM) and may also include non-volatile memory, such as at least one disk drive.
[0103] Bus 54 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, only one line is used in the diagram, but this does not imply that there is only one bus or one type of bus.
[0104] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0105] The electronic device is used to execute the technical solutions in any of the foregoing method embodiments. Its implementation principle and technical effect are similar, and will not be described again here.
[0106] This application also provides a readable storage medium, which can be a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the technical solution provided in any of the foregoing method embodiments.
[0107] This application also provides a computer program product, including a computer program, which, when executed by a processor, is used to implement the technical solutions provided in any of the foregoing method embodiments.
[0108] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0109] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0110] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0111] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for monitoring abnormal account behavior, characterized in that, include: Obtain real-time behavioral information and historical behavioral patterns of the target account; Based on the real-time behavior information, calculate the similarity between the current behavior of the target account and the historical behavior pattern; The risk factors of the target account are determined based on the historical behavior patterns and the real-time behavior information. Anomaly monitoring results for the current behavior are generated based on the similarity and the risk factors.
2. The method according to claim 1, characterized in that, The step of calculating the similarity between the current behavior of the target account and the historical behavior pattern based on the real-time behavior information includes: Multimodal feature extraction is performed on the real-time behavior information, and the extraction results are fused to obtain the multimodal feature vector corresponding to the current behavior; The multimodal feature vectors are compared with the behavioral baselines generated based on the historical behavioral patterns, and the overall similarity is calculated.
3. The method according to claim 2, characterized in that, The calculation of the overall similarity includes: Based on the real-time behavioral information, extract behavioral chain sequences that represent the order and logical association of behaviors; The behavioral chain sequence is matched with the baseline sequence contained in the behavioral baseline, and the sequence similarity component is calculated as a key factor of the comprehensive similarity.
4. The method according to any one of claims 1 to 3, characterized in that, The step of generating anomaly monitoring results for the current behavior based on the similarity and the risk factor includes: Obtain the similarity threshold used for anomaly detection; The similarity threshold is corrected based on the risk factor, and the calculated similarity is compared with the similarity threshold. Anomaly monitoring results are generated based on the comparison results.
5. The method according to any one of claims 1 to 3, characterized in that, After generating the anomaly monitoring results for the current behavior, the following is also included: Obtain user feedback information regarding the anomaly monitoring results; The historical behavior patterns are dynamically corrected based on the user feedback information.
6. The method according to any one of claims 1 to 3, characterized in that, The acquisition of real-time behavioral information and historical behavioral patterns of the target account also includes: For the real-time behavior information and the historical behavior patterns, a de-identification operation is performed, which includes blurring the geographical location information and user identity information.
7. A device for monitoring abnormal account behavior, characterized in that, include: The acquisition module is used to acquire real-time behavioral information and historical behavioral patterns of the target account; A similarity processing module is used to calculate the similarity between the current behavior of the target account and the historical behavior pattern based on the real-time behavior information. The risk processing module is used to determine the risk factors of the target account based on the historical behavior patterns and the real-time behavior information; The monitoring module is used to generate anomaly monitoring results for the current behavior based on the similarity and the risk factors.
8. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 6.