Service request processing method, device, electronic device and storage medium
By identifying and prioritizing the key service node with the highest interception effect, the method enhances the effectiveness of intercepting fraudulent requests on Internet platforms, addressing the limitations of fixed-node interception methods.
Patent Information
- Application Number
- JP2025512132
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-26
- Filing Date
- 2023-08-16
- Publication Date
- 2025-09-25
AI Technical Summary
Existing Internet platforms face challenges in effectively intercepting fraudulent service requests due to attackers modifying parameters to bypass fixed-node interception methods, leading to low interception effectiveness and accuracy.
A method that identifies a key service node with the highest interception effect among multiple nodes for intercepting fraudulent requests, dynamically allocating computing resources to maximize interception efficiency and adapt to changing attack methods.
Improves the accuracy and efficiency of intercepting fraudulent requests by selecting the most effective service node and optimizing resource allocation, making it harder for attackers to bypass interception.
Smart Images

Figure 2025531707000001_ABST
Abstract
Description
[Technical Field]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to a Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on August 26, 2022, bearing application number 202211037837.4 and entitled "Service request processing method, device, electronic device and storage medium," the entire contents of which are incorporated herein by reference.
[0002] (Technical field) TECHNICAL FIELD The embodiments of the present disclosure relate to the technical field of the Internet, and in particular to a service request processing method, device, electronic device, and storage medium. [Background technology]
[0003] With the rapid development of the Internet industry, there has been an increase in fraudulent activities using Internet technology, such as network attacks, information theft, and extortion scams. Internet platforms generally ensure the security of content and information within their platforms by establishing risk control mechanisms to intercept such fraudulent service requests.
[0004] In the prior art, a platform typically identifies fraudulent requests to achieve fraudulent service objectives based on manual or fixed rule audits, and then intercepts the fraudulent accounts that sent the fraudulent requests, thereby preventing the fraudulent accounts from continuing to send fraudulent requests. Summary of the Invention [Means for solving the problem]
[0005] Embodiments of the present disclosure provide a service request processing method, apparatus, electronic device, and storage medium.
[0006] In a first aspect, an embodiment of the present disclosure provides a service request processing method, the method comprising: The method includes: obtaining a target account, which is an account at risk of issuing fraudulent requests to a target service having at least two service nodes; determining a corresponding key service node based on the target account; and access-intercepting service requests sent from the target account based on the key service node, wherein the key service node is the service node among the at least two service nodes that has the highest interception effect when access-intercepting fraudulent requests issued by the target account.
[0007] In a second aspect, an embodiment of the present disclosure provides a service request processing device, the device comprising: an acquisition module for acquiring a target account, the target account being an account at risk of issuing fraudulent requests to a target service having at least two service nodes; a determination module for determining a corresponding main service node according to the target account; an interception module for access intercepting a service request sent from the target account based on the primary service node; The primary service node is the service node that has the highest interception effect among the at least two service nodes when access intercepting the fraudulent request issued by the target account.
[0008] In a third aspect, an embodiment of the present disclosure provides an electronic device, the device comprising: a processor and a memory communicatively coupled to the processor; the memory stores computer-executable instructions; The processor executes computer-executable instructions stored in the memory to implement the service request processing method described in the first aspect above and various possible designs of the first aspect.
[0009] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium having computer-executable instructions stored thereon, the computer-executable instructions, when executed by a processor, performing the service request processing method described in the first aspect above and various possible designs of the first aspect.
[0010] In a fifth aspect, an embodiment of the present disclosure provides a computer program product including a computer program that, when executed by a processor, implements the service request processing method described in the first aspect above and various possible designs of the first aspect.
[0011] In a sixth aspect, an embodiment of the present disclosure provides a computer program product that, when executed by a processor, implements the service request processing method according to the first aspect above and various possible designs of the first aspect.
[0012] The service request processing method, device, electronic device, and storage medium provided by the embodiments of the present disclosure include: obtaining a target account that is an account at risk of issuing fraudulent requests to a target service having at least two service nodes; determining a corresponding key service node based on the target account; and access-intercepting service requests sent from the target account based on the key service node, where the key service node is the service node with the highest interception effectiveness among the at least two service nodes when access-intercepting fraudulent requests issued by the target account. Before intercepting the fraudulent requests issued by the target account, the key service node with the highest interception effectiveness for the target service is first evaluated; and then the key service node access-intercepts the fraudulent requests issued by the target account. [Brief explanation of the drawings]
[0013] In order to more clearly explain the embodiments of the present disclosure or the technical solutions in the prior art, the following will briefly introduce the accompanying drawings that need to be used in the description of the embodiments or the prior art. The accompanying drawings in the following description are some embodiments of the present disclosure, and it is obvious to those skilled in the art that they can obtain other drawings according to these accompanying drawings without paying creative efforts.
[0014] [Figure 1] FIG. 1 is an application scenario diagram of a service request processing method provided by an embodiment of the present disclosure. [Figure 2] 1 is a schematic flowchart 1 of a service request processing method provided by an embodiment of the present disclosure; [Figure 3] 3 is a flowchart of specific steps for performing step S102 in the embodiment shown in FIG. 2. [Figure 4] FIG. 1 is a schematic diagram of intercepting access to a service node provided by an embodiment of the present disclosure. [Figure 5] 4 is a flowchart of specific steps for performing step S1022 in the embodiment shown in FIG. 3. [Figure 6] 3 is a flowchart of specific steps for performing step S103 in the embodiment shown in FIG. 2. [Figure 7] 2 is a schematic flowchart 2 of a service request processing method provided by an embodiment of the present disclosure; [Figure 8] FIG. 1 is a schematic diagram of an action feature provided by an embodiment of the present disclosure. [Figure 9] 8 is a flowchart of specific steps for performing step S207 in the embodiment shown in FIG. 7. [Figure 10] FIG. 2 is a block diagram illustrating a configuration of a service request processing device provided by an embodiment of the present disclosure. [Figure 11] 1 is a schematic diagram illustrating the configuration of an electronic device provided by an embodiment of the present disclosure. [Figure 12] FIG. 1 is a schematic diagram of a hardware configuration of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0015] In order to clarify the objectives, technical solutions and advantages of the embodiments of the present disclosure, the following will clearly and completely describe the technical solutions in the embodiments of the present disclosure in conjunction with the accompanying drawings in the embodiments of the present disclosure, but it is clear that the described embodiments are only a part of the embodiments of the present disclosure and do not represent all of the embodiments. All other embodiments that can be obtained by a person skilled in the art based on the embodiments of the present disclosure without paying creative effort are within the scope of protection of the present disclosure.
[0016] Application scenarios of the embodiments of the present disclosure are described below.
[0017] 1 is a diagram illustrating an application scenario of a service request processing method provided by an embodiment of the present disclosure. The service request processing method provided by an embodiment of the present disclosure may be applied to application scenarios of Internet platform security protection and risk control management, more specifically, to application scenarios such as social platform security protection. Exemplarily, the method provided by an embodiment of the present disclosure may be applied to a risk control server. In one possible embodiment, as shown in FIG. 1, the risk control server is connected to a platform server. An external request sent from a terminal device first enters the risk control server, where it is processed by the risk control server to identify and intercept fraudulent requests. After interception, normal and legitimate requests are sent to the platform server. In response, the platform server generates platform content, such as user comments and posted information.
[0018] With the rapid development of the Internet industry, the number of fraudulent activities using Internet technology, such as network attacks, information theft, and extortion scams, is also increasing. For example, fraudulent activities such as promoting fraudulent websites and posting fraudulent information on Internet social platforms are often used to obtain fraudulent profits. These fraudulent activities are typically achieved by automatically sending service requests to the platform server using Internet technology, registering accounts on the Internet social platform in bulk, and posting fraudulent content while posing as real users. In conventional technologies, social platforms typically identify fraudulent requests based on rules and then intercept the fraudulent accounts that sent the fraudulent requests at fixed service nodes to prevent them from continuing to send fraudulent requests. For example, when a request to post a fraudulent website is detected, the account that sent the fraudulent request is flagged and intercepted at the account's login service node, preventing it from logging in to the platform. However, fixed-node interception methods have the drawback of being easily recognized by attackers who send fraudulent requests and bypassing interception by changing transmission parameters, resulting in low interception effectiveness and accuracy.
[0019] To solve the above problems, an embodiment of the present disclosure provides a service request processing method. Referring to Fig. 2, Fig. 2 is a schematic flowchart 1 of the service request processing method provided by the embodiment of the present disclosure. The method of this embodiment is applicable to a server, and the service request processing method includes the following steps:
[0020] Step S101: Obtain a target account, where the target account is an account that is at risk of issuing an unauthorized request to the target service, and the target service has at least two service nodes.
[0021] For example, the target account is a subset of all accounts registered on the server, more specifically, the fraudulent accounts in the above application scenario description, and the target account in this embodiment is an aggregate account registered in bulk by an attacker (fraudulent group) and having similar characteristics in one or more dimensions.
[0022] Furthermore, the target account may be an account that has a record of sending fraudulent requests or an account that may send fraudulent requests based on its reputation, where the fraudulent request is a service request containing fraudulent content sent to the server, and the fraudulent content is, for example, fraudulent information, fraudulent website information, etc. After the fraudulent request is responded to by the server, the fraudulent information will be presented on the corresponding web platform. Here, the target account may be obtained from account data preset in the server, or may be determined by detecting and evaluating service requests sent from different accounts in real time, and is not particularly limited herein.
[0023] Furthermore, the fraudulent request issued by the target account corresponds to a target service, such as posting a status on a social platform or posting a comment. Here, the target service has at least two service nodes. For example, the target service is posting a status on a social platform, and the service nodes corresponding to this target service include "Register Account," "Log in to Account," "Follow Friends," and "Post Status." Here, for example, to realize the target service (posting a status on a social platform), the target account needs to send service requests to each service node respectively, thereby finally achieving the purpose of sending a fraudulent request to the target service (posting a status containing fraudulent content on a social platform).
[0024] Step S102: Determine a corresponding key service node based on the target account, where the key service node is the service node with the highest interception effect among the at least two service nodes when access intercepting the fraudulent request issued by the target account.
[0025] For example, after obtaining the target account, a corresponding key service node is determined based on the characteristics of the target account, i.e., the service node with the highest interception effect when accessing and intercepting the fraudulent requests issued by the target account. There are several specific implementations of the "service node with the highest interception effect" in this embodiment, such as the service node with the highest interception rate of fraudulent requests, the service node consuming the least amount of computing resources during interception, or the service node with the longest effective interception duration for intercepting fraudulent requests.
[0026] For example, there are multiple ways to determine the number of corresponding key service nodes based on the characteristics of the target accounts, for example, the characteristics of the target accounts are the number of target accounts, and the corresponding key service nodes are determined based on the number of target accounts; further, for example, the characteristics of the target accounts are historical interception records corresponding to the target accounts, and the key service nodes are determined by obtaining the history of intercepting the target accounts and determining the effectiveness of intercepting the target accounts at each service node.
[0027] Illustratively, as shown in FIG. 3, the specific implementation steps of step S102 include the following steps:
[0028] Step S1021: Obtain a first service request sent from a target account.
[0029] Step S1022: Based on the first service request, determine an interception gain corresponding to each service node, where the interception gain characterizes an effective interception duration for intercepting an attacker to which the target account belongs at the corresponding service node based on unit computing resources.
[0030] For example, after determining a target account, service requests sent from the target account are detected. When a first service request sent from the target account is detected, the first service request is intercepted at different service nodes, and the interception effect, i.e., interception gain, is evaluated. For example, based on the same computing resources, two hours after interception at service node A, an attacker who sends an unauthorized request can bypass access interception at service node A by changing parameters, and eight hours after interception at service node B, an attacker who sends an unauthorized request can bypass access interception at service node B by changing parameters. That is, the effective interception duration at service node B is longer, and the interception gain is higher.
[0031] 4 is a schematic diagram of intercepting access to a service node provided by an embodiment of the present disclosure. Hereinafter, a process for determining an interception gain corresponding to each service node will be described in conjunction with FIG. 4. As shown in FIG. 4, the target service is a service for "posting a status on a social platform," which includes a "login node," a "status editing node," and a "status display node." To achieve the goal of posting a status on a social platform, a first service request needs to be sent sequentially to each service node (the "login node," the "status editing node," and the "status display node"), where the first service request includes three sub-requests: a first sub-request for the "login node," a second sub-request for the "status editing node," and a third sub-request for the "status display node." Exemplarily, the target accounts include N accounts, where N is an integer greater than 2, and the target accounts are divided into three account sets: account set A, account set B, and account set C.When it detects that the target account has sent a service request, for each account in account set A, the first service request sent to the "login node" is intercepted (i.e., the first sub-request is intercepted), so that the accounts in account set A are intercepted at the "login node" and cannot log in; for each account in account set B, the access is not intercepted at the "login node" but the first service request sent to the "status edit node" (i.e., the second sub-request is intercepted), so that the accounts in account set B are intercepted at the "status edit node", so that they can log in but cannot edit their status content; for each account in account set C, the access is not intercepted at the "login node" or the "status edit node", but the first service request sent to the "status display node" (i.e., the third sub-request is intercepted), so that the accounts in account set C are intercepted at the "status display node", so that the accounts in account set C can log in and edit their status content but cannot display their status content on the social platform.
[0032] Furthermore, after the above process is executed, the target account will be intercepted by different service nodes, and will be unable to perform the desired operation on the target service. However, in reality, in response to the above interception, an attacker who sends fraudulent requests using the target account can avoid interception and successfully trigger the target service (for example, posting a status containing fraudulent information on a social platform) by adjusting or modifying program scripts to change parameters in the sent service requests, such as content keywords or login information in the service requests. However, the time and computing resource costs incurred by an attacker sending an unauthorized request to identify the interception rules and circumvent the interception are not the same for access interception at different service nodes. For example, after intercepting access at a "login node," an attacker can directly re-register a new account through a program script and launch an attack, so the time and computing resource costs incurred by the attacker to circumvent interception are relatively low, i.e., the effective interception duration is short. However, after intercepting access at a "status display node," an attacker must sequentially send requests to multiple nodes, such as the "login node" and "status edit node," using the target account, and simultaneously analyze the reasons and rules for preventing the display of unauthorized content on the social platform. This requires more computing resource costs and time, i.e., the effective interception duration is long. The above explanation is for illustrative purposes only. In actual applications, the effective interception duration for intercepting an attacker to which a target account belongs at different service nodes is affected by various factors. Therefore, the interception gain corresponding to each service node can be determined by detecting the actual effective interception duration of each service node.
[0033] In one possible embodiment, as shown in FIG. 5, the implementation of step S1022 includes the following steps:
[0034] Step S1022A: Based on a predetermined unit computing resource, for a first service request sent from the target account, perform access interception in different service nodes respectively, and record a first time corresponding to each service node, where the first time is the start time of the access interception.
[0035] Step S1022B: Detect a second service request for a different service node sent from the target account, and record a second time corresponding to the second service request, where the second service request is a service request to bypass access interception, and the second time is the time when the second service request is received.
[0036] Step S1022C: Determine an interception gain corresponding to each service node according to the first time and the second time.
[0037] Step S1023: Determine a key service node based on the interception gain.
[0038] Exemplarily, the computing resources include, for example, thread resources, memory resources, network resources, etc., and the unit computing resource, which is a computing resource of a predetermined size, is not limited to, but based on the unit computing resource, after intercepting some target accounts in the target account at different service nodes respectively, the corresponding time node, i.e., the first time, is recorded, and then a second service request for each service node sent from the target account is detected, and the time at which the second service request is received, i.e., the second time, is obtained, wherein the second service request is a service request that bypasses access interception. For example, suppose the fraudulent information contained in the first service request is "www.xxx.cn" (e.g., a fraudulent website). The server intercepts the first service request at the "status display node" and replaces the fraudulent information "www.xxx.cn" with the string "####". The attacker then modifies the request parameters to change the fraudulent information "www.xxx.cn" to "www( / ).xxx( / ).cn( / )". The attacker then generates a second service request based on the modified fraudulent information, thereby avoiding the server's identification of the fraudulent information "www.xxx.cn" in the first service request and achieving the goal of bypassing access interception. Therefore, if the server manually or based on a pre-trained recognition model detects that the service request contains content such as "www( / ).xxx( / ).cn( / )", the server considers the second service request to have been detected. The specific identification method is not described here.
[0039] Then, based on the difference between the first time and the second time, an effective interception duration for access interception at the corresponding service node is determined, and an interception gain is obtained. Furthermore, the service node with the largest interception gain is determined as a primary service node.
[0040] In the steps of this embodiment, in the process of actually performing risk control detection, the problem that attackers constantly change their attack methods and modify parameters to bypass interception is addressed by constantly detecting the interception gain of each service node, and the service node with the largest interception gain is selected as the main service node. In subsequent steps, access interception is performed on the fraudulent requests issued by the attacker based on the main service node, thereby increasing the attacker's network attack cost, thereby improving the efficiency of intercepting fraudulent requests and improving the utilization rate of computing resources.
[0041] Step S103: Based on the main service node, perform access interception on the service request sent from the target account.
[0042] For example, after determining the key service node, access interception is performed on service requests sent from target accounts based on the key service node, dynamically maximizing interception efficiency. For example, if the key service node is a service node for "add friends" on a social platform, an attacker can bulk register "target accounts" using a program script and send service requests to perform operations such as user login and "like," but cannot perform "add friends." Meanwhile, if the attacker modifies parameters and sends another fraudulent request, the key service node may be changed based on the interception gain corresponding to each service node, for example, to the service node for "post information" on the social platform. That is, the attacker can send service requests to perform operations such as user login and add friends, but cannot post information. This achieves dynamic access interception to target accounts.
[0043] In one possible embodiment, as shown in FIG. 6, the specific implementation steps of step S103 include the following steps:
[0044] Step S1031: Determine an interception policy based on the main service node, where the interception policy characterizes a computing resource allocation of a predetermined total computing resource to each service node.
[0045] Step S1032: According to the interception policy, the main service node and at least one other service node intercept the service request sent from the target account.
[0046] For example, in an application scenario for Internet platform security protection and risk control management, the risk control server needs to process a large amount of request data in real time. Because multiple attackers simultaneously send fraudulent requests to the platform, the fraudulent request interception policy must take into account the overall computing resource allocation of the risk control server to ensure real-time processing of service requests. Specifically, after determining the key service node, more computing resources can be allocated to the key service node. For example, access interception for all target accounts can be performed only by the key service node, while a smaller amount of computing resources can be allocated to other service nodes other than the key service node for the target service, allowing some accounts within the target account to be intercepted by other service nodes. This creates a more complex interception policy, further improving the effectiveness of fraudulent request interception and solving the problem of attackers constantly changing their attack methods and modifying parameters to bypass interception. Here, the interception policy can be provided by a pre-trained processing model, i.e., the target service and the key service node are input, and a corresponding interception policy is output based on the pre-trained processing model.
[0047] In this embodiment, a target account is acquired, the target account being an account at risk of issuing fraudulent requests to the target service, the target service having at least two service nodes, a corresponding key service node is determined based on the target account, the key service node being the service node with the highest interception effect when performing access interception on the fraudulent requests issued by the target account, and access interception is performed on the service requests sent from the target account based on the key service node. Before intercepting the fraudulent requests issued by the target account, the key service node with the highest interception effect for the target service is first evaluated, and then the fraudulent requests issued by the target account are access intercepted at the key service node, thereby improving the accuracy of intercepting fraudulent requests and simultaneously forming dynamic interception on the target account, which increases the difficulty for the target account to bypass interception by changing access parameters, thereby improving the utilization efficiency of computing resources.
[0048] Referring to Fig. 7, Fig. 7 is a schematic flowchart 2 of a service request processing method provided by an embodiment of the present disclosure. This embodiment adds a step of determining a target account and a step of updating an interception policy based on complaint data to the embodiment shown in Fig. 2, and the service request processing method includes the following steps:
[0049] Step S201: A routine service request is detected.
[0050] Step S202: Obtain multi-dimensional features of the routine service request.
[0051] For example, in the application scenario of Internet platform security protection and risk control management, the risk control server, which is the execution body of this embodiment, obtains service requests sent from different accounts, i.e., routine service requests, by randomly detecting service requests sent by users to the risk control server via terminal devices, and then obtains multi-dimensional features corresponding to the routine service requests. For example, the multi-dimensional features include at least two of account features, device features, behavior features, and content features, each of which is described in detail below.
[0052] The account characteristics are characteristics of the account that sends this routine service request, such as an account identifier (e.g., account name, account avatar), the time of account creation, account record information (e.g., information set in the account, such as age, gender, and place of residence), etc. In one possible embodiment, the routine service request may include identification information of the account that sent this request, and the account characteristics may be further determined based on the identification information.
[0053] The device characteristics are characteristics of the device logged in by the account sending this routine service request, such as a device identifier, a device model, a device login time, a device network address, etc. In one possible embodiment, the routine service request may include identification information of the device sending this request, and the device characteristics may be further determined based on the identification information.
[0054] An action feature characterizes the order of routine service requests sent from the same account to different service nodes, i.e., the order in which the service requests are sent to each service node of the target service, i.e., the timing at which each service node is triggered. The action feature may be jointly determined based on specific content information of multiple routine service requests. FIG. 8 is a schematic diagram of action features provided by an embodiment of the present disclosure. For example, for a specific account Acc_1, if the routine service requests A (a set of multiple service requests) sent by it sequentially trigger the service nodes "User Login," "Add Friend," and "Write a Comment in the Friend's Comments Section," the action feature corresponding to the routine service request A is action feature a. If the routine service requests B (a set of multiple service requests) sent by it sequentially trigger the service nodes "User Login," "Join Hot Topics," and "Write a Comment in the Topics Section," the action feature corresponding to the routine service request B is action feature b.
[0055] The content feature is a feature of the content (e.g., a specific keyword and a phrase containing the specific keyword) and / or an action content of an action feature in the transmitted routine service request. For example, if the routine service request is used to trigger the "add friend" service node, the corresponding content feature is the account identifier of the friend to be added. Note that the content feature may be determined based on specific content information of the routine service request.
[0056] Furthermore, a multi-dimensional feature refers to a combination of at least two of the above four features. More specifically, the multi-dimensional feature may include multiple subclasses within each type of feature (account feature, device feature, action feature, content feature) to obtain more dimensional combinations. For example, the multi-dimensional feature may include 500-dimensional features, thereby achieving a more accurate description of service requirements.
[0057] Step S203: Based on the multi-dimensional features, cluster the accounts corresponding to the routine service requests to obtain a plurality of cluster accounts, where the cluster accounts are a set of a plurality of accounts having the same cluster features, where the cluster features are a subset of the multi-dimensional features.
[0058] Step S204: Determine a target cluster account according to the number of accounts in each cluster account, and the accounts in the target cluster account are the target accounts.
[0059] For example, multidimensional features correspond to descriptive information of routine service requests, and the greater the number of dimensions, the higher the accuracy of the descriptive information. Specifically, for routine service requests sent from legitimate accounts, the multidimensional features of the issued routine service requests are random because each user uses the Internet platform differently and for different purposes. Therefore, routine service requests sent from legitimate accounts usually do not cluster on the same multidimensional features. On the other hand, for fraudulent accounts (target accounts) registered by attackers using script programs, the fraudulent requests issued by the script programs form a high degree of clustering with multidimensional features consisting of several dimensions. Examples of high clustering include logging in at the same time (device feature), common friends (account feature), the same service node trigger order (behavior feature), and the same comment content (content feature). Therefore, based on the multidimensional features corresponding to the routine service requests, accounts corresponding to the routine service requests with the same multidimensional features are clustered to obtain cluster accounts. The number of cluster accounts is then evaluated. If the number of cluster accounts is greater than a predetermined value, the accounts in the cluster account are determined to be abnormal and at risk of issuing fraudulent requests, i.e., to be target accounts.
[0060] In this embodiment, routine service requests are detected, and the routine service requests are comprehensively judged from multiple dimensions. Based on the clustering degree of the multidimensional features of the routine service requests, fraudulent requests generated by script programs are accurately distinguished from legitimate service requests issued by general accounts, thereby achieving accurate positioning of target accounts. This avoids the problem of attackers changing request parameters to accurately position target accounts in the prior art approach of determining target accounts based on expert experience, thereby improving the accuracy of detecting fraudulent accounts.
[0061] Step S205: Determine a corresponding key service node based on the target account, where the key service node is the service node with the highest interception effect when access intercepting the fraudulent request issued by the target account.
[0062] Step S206: Obtain complaint data, where the complaint data is complaint information about the access interception sent from the target account.
[0063] Step S207: Update the target account and / or the interception policy based on the complaint data, and return to step S201, where the interception policy is a policy for access interception of the service request sent from the target account.
[0064] For example, after determining the key service node, the target account's access is intercepted based on the key service node to protect the system ecology. However, at the same time, some requests are mistakenly intercepted, resulting in the interception of legitimate users' service requests and preventing the service node from being successfully triggered. Some users then issue complaint requests in response to the mistaken interception. At the same time, the attacker also uses a script program to send fake complaint requests to the server based on the target account. The complaint data is a set of complaint information submitted by the target account to the Internet platform. After obtaining the complaint data, the server analyzes the complaint data to identify true complaint information submitted by the user that reflects the mistaken interception situation, or to identify false complaint information submitted using a script program. The true and false complaint information are then used to further train a processing model for providing an interception policy, thereby updating the target account previously determined to be a fraudulent account and / or updating the interception policy of the target account. For specific implementation of the interception policy, please refer to the relevant description of the embodiment shown in FIG. 6 and will not be repeated herein.
[0065] Illustratively, as shown in FIG. 9, the specific implementation steps of step S207 include the following steps:
[0066] Step S2071: Cluster the complaint data based on its content to obtain a first complaint sample and a second complaint sample, where the first complaint sample is complaint information sent from a normal account, and the second complaint sample is an account at risk of issuing fraudulent requests to the target service.
[0067] Step S2072: Update the target account and / or the interception policy based on the first complaint sample and / or the second complaint sample.
[0068] For example, after the complaint data is obtained, text clustering is performed according to the content of each complaint information in the complaint data. For example, if the complaint information includes the content item "Statement of Reason for Complaint," text clustering is performed on the "Statement of Reason for Complaint," outliers are excluded, and non-outliers are automatically marked as valid complaint information, i.e., first complaint samples, and other outliers are marked as second complaint samples. Then, the account corresponding to the first complaint sample is marked as a white sample, and a processing model for providing an interception policy is trained based on the white sample. Automatic optimization and iteration of the interception policy are completed, and the accuracy and rationality of the interception policy are improved.
[0069] In this embodiment, the implementation of step S205 is the same as the implementation of step S102 in the embodiment shown in FIG. 2 of the present disclosure, and will not be repeated here.
[0070] Corresponding to the service request processing method of the above embodiment, FIG. 10 is a configuration block diagram of a service request processing device provided by the embodiment of the present disclosure. For convenience of explanation, only the parts related to the embodiment of the present disclosure are shown. Referring to FIG. 10, the service request processing device 3: an acquisition module 31 for acquiring a target account, the target account being an account at risk of issuing fraudulent requests to a target service having at least two service nodes; a determination module 32 for determining a corresponding primary service node based on the target account; an interception module 33 for access intercepting service requests sent from the target account based on the primary service node; The key service node is the service node with the highest interception effect when access intercepting the fraudulent request issued by the target account.
[0071] In an embodiment of the present disclosure, the determination module 32 is specifically used to obtain a first service request sent from a target account, determine an interception gain corresponding to each service node based on the first service request, and determine a key service node based on the interception gain, where the interception gain characterizes an effective interception duration for intercepting an attacker to which the target account belongs at the corresponding service node based on unit computing resources.
[0072] In an embodiment of the present disclosure, when determining an interception gain corresponding to each service node based on the first service request, the determination module 32 specifically performs access interception at different service nodes for the first service request sent from the target account based on a predetermined unit computing resource, records a first time corresponding to each service node, which is the start time of the access interception, detects a second service request sent from the target account to a different service node, and records a second time corresponding to the second service request, which is used to determine an interception gain corresponding to each service node based on the first time and the second time, where the second service request is a service request to bypass access interception, and the second time is the time when the second service request is received.
[0073] In an embodiment of the present disclosure, the interception module 33 is specifically used to determine an interception policy based on a main service node, and intercept service requests sent from the target account at the main service node and at least one other service node based on the interception policy, where the interception policy characterizes a computing resource allocation of a predetermined total computing resource to each service node.
[0074] In the embodiment of the present disclosure, the acquisition module 31 is specifically used to identify target accounts based on multi-dimensional characteristics of routine service requests.
[0075] In an embodiment of the present disclosure, when identifying a target account based on the multidimensional features of a routine service request, the acquisition module 31 specifically acquires the multidimensional features of the routine service request, clusters the accounts corresponding to the routine service request based on the multidimensional features to obtain multiple cluster accounts, and determines the target cluster account based on the number of accounts included in each cluster account, where the cluster account is a set of multiple accounts having the same cluster features, the cluster features are a subset of the multidimensional features, and the accounts included in the target cluster account are the target accounts.
[0076] In an embodiment of the present disclosure, the multidimensional feature includes at least two of an account feature, a device feature, an action feature, and a content feature.
[0077] In an embodiment of the present disclosure, the acquisition module 31 is further used to acquire complaint data and update the target account and / or the interception policy based on the complaint data, where the complaint data is complaint information for the interception policy sent from the target account, and the interception policy is a policy for access interception of the service request sent from the target account.
[0078] In an embodiment of the present disclosure, when updating the target account and / or interception policy based on the complaint data, the acquisition module 31 specifically clusters the complaint data based on its content to obtain a first complaint sample and a second complaint sample, and updates the target account and / or the interception policy based on the first complaint sample and / or the second complaint sample, where the first complaint sample is complaint information sent from a normal account, and the second complaint sample is an account at risk of issuing fraudulent requests to the target service.
[0079] Here, the acquisition module 31, the determination module 32 and the interception module 33 are connected in sequence. The service request processing device 3 provided in this embodiment can implement the technical solutions of the above-mentioned method-related embodiments, and the implementation principles and technical effects are similar, so the description of this embodiment will not be repeated here.
[0080] FIG. 11 is a schematic diagram of the configuration of an electronic device provided according to an embodiment of the present disclosure. As shown in FIG. 11, the electronic device 4 includes: A processor 41 and a memory 42 communicatively connected to the processor 41, The memory 42 stores computer-executable instructions, The processor 41 executes computer-executable instructions stored in the memory 42 to implement the service request processing method in the embodiment shown in FIGS.
[0081] Here, the processor 41 and the memory 42 are optionally connected via a bus 43 .
[0082] The related explanations can be understood by referring to the related explanations and effects corresponding to the steps in the embodiments corresponding to FIGS. 2 to 9, and therefore the explanations here will be omitted.
[0083] Referring to FIG. 12 , which shows a schematic configuration diagram of an electronic device 900 suitable for implementing an embodiment of the present disclosure, the electronic device 900 may be a terminal device or a server. Here, the terminal device includes, but is not limited to, mobile terminals such as a mobile phone, a notebook computer, a digital broadcast receiver, a personal digital assistant (PDA), a tablet computer (Portable Android Device (PAD)), a portable media player (PMP)), an in-vehicle terminal (e.g., a vehicle navigation terminal), a digital television (TV), a fixed terminal such as a desktop computer, etc. Note that the electronic device shown in FIG. 12 is merely an example and does not limit the functions and scope of use of the embodiment of the present disclosure in any way.
[0084] As shown in FIG. 12, the electronic device 900 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 901 that can perform various appropriate operations and processes based on a program stored in a read only memory (ROM) 902 or a program loaded from a storage device 908 into a random access memory (RAM) 903. The RAM 903 also stores various programs and data necessary for the operation of the electronic device 900. The processing device 901, the ROM 902, and the RAM 903 are connected to one another via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.
[0085] Typically, the I / O interface 905 may be connected to input devices 906, including, for example, a touch screen, touch pad, keyboard, mouse, camera, microphone, accelerometer, gyroscope, etc.; output devices 907, including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 908, including, for example, a magnetic tape, hard disk, etc.; and communication devices 909. The communication devices 909 may enable the electronic device 900 to communicate and exchange data with other devices wirelessly or via wires. While FIG. 12 illustrates the electronic device 900 including various devices, it should be understood that it is not necessary for the electronic device 900 to implement or include all of the devices shown. More or fewer devices may alternatively be implemented or included.
[0086] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product including a computer program stored on a computer-readable medium, the computer program including program code for performing the method illustrated in the flowcharts. In such embodiments, the computer program may be downloaded and installed from a network via the communication device 909, or may be installed from the storage device 908, or may be installed from the ROM 902. When the computer program is executed by the processing device 901, it performs the functions described above defined in the method of the embodiments of the present disclosure.
[0087] In the present disclosure, the computer-readable medium may be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. The computer-readable storage medium may be, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of the computer-readable storage medium include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM) or flash memory, an optical fiber, a compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in combination with an instruction execution system, apparatus, or device. Also, in this disclosure, a computer-readable signal medium may include a propagated data signal, either in baseband or as part of a carrier carrying computer-readable program code. Such a propagated data signal may take various forms, including, but not limited to, an electromagnetic signal, an optical signal, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium, other than a computer-readable storage medium, that transmits, propagates, or transmits a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained in the computer-readable medium may be transmitted using any suitable medium, including, but not limited to, wire, fiber optic cable, radio frequency (RF), or the like, or any suitable combination of the foregoing.
[0088] The computer readable medium may be included in the electronic device or may be separate and not assembled to the electronic device.
[0089] The computer-readable medium stores one or more programs, which, when executed by the electronic device, cause the electronic device to perform the method shown in the above embodiments.
[0090] Computer program code for carrying out operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and the like, and conventional procedural programming languages such as "C" or similar programming languages. The program code may run entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the context of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a Local Area Network (LAN) or a Wide Area Network (WAN), or may be connected to an external computer (e.g., connected through the Internet using an Internet Service Provider).
[0091] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functions, and operations that may be implemented in accordance with systems, methods, and computer program products according to embodiments of the present disclosure. In this regard, each box in a flowchart or block diagram may represent a module, program segment, or portion of code, which includes one or more executable instructions for implementing a specified logical function. Note that in some alternative implementations, the functions marked in the boxes may occur in a different order than those marked in the accompanying drawings. For example, two consecutive boxes may actually be executed substantially in parallel, or may be executed in the reverse order depending on the functionality involved. It should also be noted that each box in the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, may be implemented in a dedicated hardware-based system that performs a given function or operation, or in a combination of dedicated hardware and computer instructions.
[0092] The units described in the embodiments of the present disclosure may be implemented by software or hardware, and the name of a unit does not constitute a limitation on the unit itself in a given situation, for example, the first obtaining unit may also be described as "a unit for obtaining at least two Internet Protocol addresses."
[0093] The functionality described herein above may be performed, at least in part, by one or more hardware logic units. For example, without limitation, possible example hardware logic units include Field-Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Parts (ASSPs), System On Chip (SOCs), Complex Programmable Logic Devices (CPLDs), etc.
[0094] In the context of this disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium includes, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More specific examples of machine-readable storage media include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a CD-ROM (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0095] In a first aspect, according to one or more embodiments of the present disclosure, there is provided a service request processing method, the method comprising:
[0096] The method includes: obtaining a target account, which is an account at risk of issuing fraudulent requests to a target service having at least two service nodes; determining a corresponding key service node based on the target account; and access-intercepting service requests sent from the target account based on the key service node, wherein the key service node is the service node among the at least two service nodes that has the highest interception effect when access-intercepting fraudulent requests issued by the target account.
[0097] According to one or more embodiments of the present disclosure, determining a corresponding primary service node based on the target account includes obtaining a first service request sent from the target account; determining an interception gain corresponding to each of the service nodes based on the first service request; and determining the primary service node based on the interception gain, wherein the interception gain characterizes an effective interception duration for intercepting an attacker to which the target account belongs at a corresponding service node based on unit computing resource.
[0098] According to one or more embodiments of the present disclosure, determining an interception gain corresponding to each of the service nodes based on the first service request includes: performing access interception at different service nodes for the first service request sent from the target account based on a predetermined unit computing resource, and recording a first time corresponding to each of the service nodes; detecting a second service request for the different service node sent from the target account, and recording a second time corresponding to the second service request; and determining an interception gain corresponding to each of the service nodes based on the first time and the second time, wherein the first time is a start time of the access interception, the second service request is a service request to bypass the access interception, and the second time is a time when the second service request is received.
[0099] According to one or more embodiments of the present disclosure, access intercepting service requests sent from target accounts based on the primary service node includes determining an interception policy based on the primary service node; and intercepting service requests sent from the target account at the primary service node and at least one other service node based on the interception policy, wherein the interception policy characterizes a computing resource allocation of a predetermined total computing resource to each of the service nodes.
[0100] According to one or more embodiments of the present disclosure, obtaining the target account includes identifying the target account based on multidimensional characteristics of routine service requests.
[0101] According to one or more embodiments of the present disclosure, identifying a target account based on multidimensional features of the routine service request includes: obtaining multidimensional features of the routine service request; clustering accounts corresponding to the routine service request based on the multidimensional features to obtain a plurality of cluster accounts; and determining a target cluster account based on the number of accounts in each of the cluster accounts, wherein the cluster accounts are a set of a plurality of accounts having the same cluster features, the cluster features being a subset of the multidimensional features, and the accounts in the target cluster account are the target accounts.
[0102] According to one or more embodiments of the present disclosure, the multidimensional features include at least two of an account feature, a device feature, an action feature, and a content feature.
[0103] According to one or more embodiments of the present disclosure, the method further includes obtaining complaint data and updating the target account and / or an interception policy based on the complaint data, wherein the complaint data is complaint information regarding the access interception sent from the target account, and the interception policy is a policy for access interception of service requests sent from the target account.
[0104] According to one or more embodiments of the present disclosure, updating the target account and / or interception policy based on the complaint data includes clustering the complaint data based on its content to obtain a first complaint sample and a second complaint sample, and updating the target account and / or interception policy based on the first complaint sample and / or the second complaint sample, wherein the first complaint sample is complaint information sent from a normal account and the second complaint sample is an account at risk of issuing fraudulent requests to the target service.
[0105] In a second aspect, according to one or more embodiments of the present disclosure, there is provided a service request processing apparatus, the apparatus comprising: an acquisition module for acquiring a target account, the target account being an account at risk of issuing fraudulent requests to a target service having at least two service nodes; a determination module for determining a corresponding main service node according to the target account; an interception module for access intercepting a service request sent from the target account based on the primary service node; The primary service node is the service node that has the highest interception effect among the at least two service nodes when access intercepting the fraudulent request issued by the target account.
[0106] According to one or more embodiments of the present disclosure, the determination module is specifically used to obtain a first service request sent from the target account, determine an interception gain corresponding to each of the service nodes based on the first service request, and determine the primary service node based on the interception gain, wherein the interception gain characterizes an effective interception duration for intercepting an attacker to which the target account belongs at the corresponding service node based on unit computing resource.
[0107] According to one or more embodiments of the present disclosure, when determining an interception gain corresponding to each of the service nodes based on the first service request, the determination module specifically performs access interception at different service nodes for the first service request sent from the target account based on a predetermined unit computing resource, records a first time corresponding to each of the service nodes, detects a second service request for the different service node sent from the target account, records a second time corresponding to the second service request, and determines an interception gain corresponding to each of the service nodes based on the first time and the second time, wherein the first time is a start time of the access interception, the second service request is a service request to bypass the access interception, and the second time is a time when the second service request is received.
[0108] According to one or more embodiments of the present disclosure, the interception module is specifically used to determine an interception policy based on the main service node, and intercept service requests sent from the target account at the main service node and at least one other service node based on the interception policy, wherein the interception policy represents a computing resource allocation of a predetermined total computing resource to each of the service nodes.
[0109] According to one or more embodiments of the present disclosure, the acquisition module is specifically used to detect routine service requests and identify the target account based on multi-dimensional characteristics of the routine service requests.
[0110] According to one or more embodiments of the present disclosure, when identifying a target account based on the multidimensional features of the routine service request, the acquisition module is specifically used to acquire the multidimensional features of the routine service request, cluster the accounts corresponding to the routine service request based on the multidimensional features to obtain a plurality of cluster accounts, and determine a target cluster account based on the number of accounts in each of the cluster accounts, where the cluster accounts are a set of a plurality of accounts having the same cluster features, the cluster features are a subset of the multidimensional features, and the accounts in the target cluster accounts are the target accounts.
[0111] According to one or more embodiments of the present disclosure, the multidimensional features include at least two of an account feature, a device feature, an action feature, and a content feature.
[0112] According to one or more embodiments of the present disclosure, the acquisition module is further used to acquire complaint data and update the target account and / or interception policy based on the complaint data, where the complaint data is complaint information for the interception policy sent from the target account, and the interception policy is a policy for access interception of service requests sent from the target account.
[0113] According to one or more embodiments of the present disclosure, when updating the target account and / or interception policy based on the complaint data, the acquisition module specifically clusters the complaint data based on its content to obtain a first complaint sample and a second complaint sample, and updates the target account and / or interception policy based on the first complaint sample and / or the second complaint sample, wherein the first complaint sample is complaint information sent from a normal account, and the second complaint sample is an account at risk of issuing fraudulent requests to the target service.
[0114] In a third aspect, according to one or more embodiments of the present disclosure, there is provided an electronic device, the electronic device comprising: a processor; and a memory communicatively coupled to the processor; the memory stores computer-executable instructions; The processor executes computer-executable instructions stored in the memory to implement the service request processing method described in the first aspect above and various possible designs of the first aspect.
[0115] In a fourth aspect, according to one or more embodiments of the present disclosure, a computer-readable storage medium is provided, the computer-readable storage medium having computer-executable instructions stored thereon, the computer-executable instructions, when executed by a processor, performing the service request processing method described in the first aspect above and various possible designs of the first aspect.
[0116] In a fifth aspect, an embodiment of the present disclosure provides a computer program product including a computer program that, when executed by a processor, performs the service request processing method described in the first aspect above and various possible designs of the first aspect.
[0117] In a sixth aspect, an embodiment of the present disclosure provides a computer program product, which, when executed by a processor, implements the service request processing method according to the first aspect and various possible designs thereof.
[0118] The above description merely describes preferred embodiments of the present disclosure and the technical principles employed. It should be understood by those skilled in the art that the scope of the present disclosure is not limited to a technical solution formed by a specific combination of the above technical features, but also covers other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the concept disclosed above. For example, it includes technical solutions formed by replacing the above features with (but not limited to) technical features having similar functions disclosed in the present disclosure.
[0119] Additionally, although operations are depicted using a particular order, this should not be construed as requiring that these operations be performed in the particular order shown, or that they be performed sequentially. Multitasking and parallel processing may be advantageous in certain environments. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Some features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, each feature described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable subcombination.
[0120] Although the present subject matter has been described using language specific to structural features and / or methodological operations, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or operations described above. Rather, the specific features and operations described above are merely example forms of implementing the claims.
Claims
1. Obtaining a target account, the target account being an account at risk of issuing fraudulent requests to a target service having at least two service nodes; Determine a corresponding main service node based on the target account; access intercepting a service request sent from the target account based on the primary service node; A service request processing method, wherein the primary service node is the service node that has the highest interception effect among the at least two service nodes when access intercepting the fraudulent request issued by the target account.
2. determining a corresponding primary service node based on the target account; Obtaining a first service request sent from the target account; determining an interception gain corresponding to each of the service nodes based on the first service request; determining the primary service node based on the interception gain; The service request processing method of claim 1 , wherein the interception gain characterizes an effective interception duration for intercepting an attacker to which the target account belongs at a corresponding service node based on unit computing resources.
3. determining an interception gain corresponding to each of the service nodes based on the first service request, According to a predetermined unit computing resource, for a first service request sent from the target account, perform access interception at different service nodes, respectively, and record a first time corresponding to each of the service nodes; Detecting a second service request sent from the target account to the different service node and recording a second time corresponding to the second service request; determining an interception gain corresponding to each of the service nodes based on the first time and the second time; 3. The service request processing method according to claim 2, wherein the first time is a start time of the access interception, the second service request is a service request to bypass the access interception, and the second time is a time when the second service request is received.
4. Access intercepting a service request sent from a target account based on the primary service node includes: determining an interception policy based on the primary service node; intercepting, at the primary service node and at least one other service node, a service request sent from the target account based on the interception policy; The method of claim 1 , wherein the interception policy characterizes a computing resource allocation of a predetermined total computing resource to each of the service nodes.
5. The method of claim 1 , wherein obtaining the target account comprises identifying the target account based on multidimensional characteristics of routine service requests.
6. identifying a target account based on multidimensional characteristics of the routine service request; obtaining multidimensional characteristics of the routine service request; clustering the accounts corresponding to the routine service requests based on the multi-dimensional features to obtain a plurality of cluster accounts; determining a target cluster account based on the number of accounts in each of the cluster accounts; 6. The service request processing method of claim 5, wherein the cluster account is a set of multiple accounts having the same cluster feature, the cluster feature is a subset of the multidimensional feature, and an account in the target cluster account is the target account.
7. The service request processing method according to claim 5 or 6, wherein the multidimensional features include at least two of an account feature, a device feature, an action feature, and a content feature.
8. Acquiring complaint data, which is complaint information regarding the access interception sent from the target account; updating the target account and / or interception policy based on the complaint data; The service request processing method according to claim 1 , wherein the interception policy is a policy for access interception of a service request sent from a target account.
9. updating the target account and / or interception policy based on the complaint data; clustering the complaint data based on content to obtain a first complaint sample and a second complaint sample; updating the target account and / or interception policy based on the first complaint sample and / or the second complaint sample; The service request processing method of claim 8 , wherein the first complaint sample is complaint information sent from a normal account, and the second complaint sample is an account at risk of issuing fraudulent requests to the target service.
10. an acquisition module for acquiring a target account, the target account being an account at risk of issuing fraudulent requests to a target service having at least two service nodes; a determination module for determining a corresponding main service node according to the target account; an interception module for access intercepting a service request sent from the target account based on the primary service node; A service request processing device, wherein the main service node is the service node that has the highest interception effect among the at least two service nodes when access intercepting the fraudulent request issued by the target account.
11. a processor and a memory communicatively coupled to the processor; the memory stores computer-executable instructions; 10. An electronic device, wherein the processor executes computer-executable instructions stored in the memory to implement a service request processing method according to any one of claims 1 to 9.
12. A computer-readable storage medium having stored thereon computer-executable instructions that, when executed by a processor, implement the method for processing a service request according to any one of claims 1 to 9.
13. A computer program product comprising a computer program which, when executed by a processor, implements the method for handling service requests according to any one of claims 1 to 9.
14. A computer program for implementing the method for processing a service request according to any one of claims 1 to 9.
Citation Information
Patent Citations
interception system and method
JP2002539716A
Method, computer program, and computer system for performing user authentication
JP2016508633A
System and method for protecting computers from unauthorized remote administration
JP2017228277A
System and method of blocking access to protected applications
JP2018018495A
Hardware-based virtualization security isolation
JP2019517694A