Method and device for detecting abnormal transmission of hacked account, and medium
By encoding and training the discrete variables and continuous variables of the target email, combined with the transformation of the neural network layer and the comparison of user sending feature vectors, the problem of difficulty in efficiently and accurately detecting whether the email is an abnormally stolen account, achieving efficient and accurate detection effect.
Patent Information
- Application Number
- PCT/CN2024/111741
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-21
- Filing Date
- 2024-08-13
- Publication Date
- 2025-06-26
AI Technical Summary
The prior art is difficult to efficiently and accurately detect whether an email is an abnormally stolen account, and due to the lack of an effective semantic analysis mechanism for mailing text, it is easy to lead to misjudgment.
By obtaining the discrete and continuous variables of the target email, they are encoded and trained respectively, the first representation vector and the second representation vector are obtained. After mixing, the input neural network layer is transformed to obtain the output scalar, and compared with the user's sending feature vector. If the difference exceeds the preset threshold, it is determined to be a sending abnormality.
It realizes efficient and accurate detection of emails, reduces the occurrence of misjudgments, and improves detection efficiency.
Smart Images

Figure CN2024111741_26062025_PF_FP_ABST
Abstract
Description
A method, device and medium for detecting abnormal message sending by account theft Technical Field
[0001] The present invention relates to the technical field of e-mails, and in particular to a method, device and medium for detecting abnormal e-mail transmission caused by account theft. Background Art
[0002] User email account theft is a common problem. There are many reasons for stolen email accounts and passwords, including phishing, Trojans, database manipulation, and brute-force attacks on simple passwords. If a user's email account is compromised, it may be used to send spam or phishing emails if the email itself is not valuable. Existing methods primarily extract sending behavior information from sent emails and then determine whether the sending behavior is abnormal by calculating the degree of deviation between this information and historical sending behavior.
[0003] However, due to the lack of an effective semantic analysis mechanism for email text, existing technical means can easily lead to misjudgment of whether email sending is abnormal; and the use of traditional statistical methods such as "standard deviation, mean and coefficient of variation" to characterize the characteristics of sent information results in a small amount of information, resulting in slow progress and low efficiency in the detection process.
[0004] Summary of the Invention
[0005] The present invention provides a method, device and medium for detecting abnormal email sending caused by account theft, so as to solve the problem that it is difficult to detect abnormal email sending caused by account theft efficiently and accurately.
[0006] In order to solve the above problems, the present invention provides a method for detecting abnormal email transmission caused by account theft, comprising:
[0007] Obtain the discrete and continuous variables of the target emails;
[0008] Encoding the discrete variable to obtain a first representation vector corresponding to the discrete variable;
[0009] Training the continuous variable through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable;
[0010] Mixing the first representation vector and the second representation vector and inputting the mixed vector into the neural network layer for transformation to obtain an output scalar;
[0011] If the difference between the output scalar and the user's email feature vector exceeds a preset threshold, the detection result of the target email is an email sending anomaly; wherein, the user's email feature vector is obtained by training a preset model with the label prediction accuracy of the mailbox where the target email is located as the objective function.
[0012] The present invention can effectively extract the text information and other ancillary information of the target email by encoding and training discrete variables and continuous variables respectively, and then obtain an output scalar for comparison and judgment through mixed output to obtain the detection result. This detection method is simple, fast and highly practical. Among them, encoding the discrete variables is to expand the values of the discrete features in the discrete variables into a space with other physical meanings, so that the obtained first characterization vector has the physical meaning of representing the discrete variables, which is convenient for subsequent processing and calculation; after mixing the first characterization vector and the second characterization vector and inputting them into the neural network layer, the information therein can be sorted out, which is convenient for subsequent comparison with the user's message feature vector to obtain the difference between the two; because the user's message feature vector is trained based on the data of the mailbox where the target email is located, the obtained user's message feature vector contains the user's message sending and receiving habits of the mailbox where the target email is located, so it can be used as a measurement standard, which can greatly reduce the occurrence of misjudgment of the detection result.
[0013] Compared with the existing technology, this solution can obtain detection results by extracting characterization vectors and obtaining differences from discrete variables and continuous variables of the target email. This detection method can effectively improve detection efficiency. Since the user's email feature vector is trained based on the data of the mailbox where the target email is located, it can be used as a specific similarity evaluation criterion exclusive to the user of the mailbox to measure the abnormality of the output scalar, and thus obtain accurate detection results. Therefore, it can solve the problem of difficulty in efficiently and accurately detecting abnormal email sending due to account theft.
[0014] As a preferred solution, the continuous variable is trained through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable, specifically:
[0015] Inputting the continuous variable into the neural network layer so that the continuous variable is transmitted layer by layer in the neural network layer;
[0016] Using the last layer of neural network of the neural network layer to perform adaptive training on the continuous variable, so that the last layer of neural network fits the implicit information related to the continuous variable;
[0017] Obtain the component vector of the last layer of neural network after training, and obtain the second representation vector corresponding to the continuous variable.
[0018] This preferred solution allows the continuous variables to be transmitted layer by layer in the neural network layer, so that the neural network layer can effectively analyze the continuous variables and obtain information; by fitting the last layer of the neural network in the neural network layer to the adaptive training problem related to the continuous variables, the obtained second representation vector can contain implicit information related to the continuous variables, and well represent the relationship between the various information in the continuous variables and the information direction.
[0019] As a preferred solution, the last layer of neural network of the neural network layer is used to perform adaptive training on the continuous variable, so that the last layer of neural network fits the implicit information related to the continuous variable, specifically:
[0020] Adaptive training is performed on the continuous variable using the last layer of neural network of the neural network layer, and the weight of each neuron in the last layer of neural network is adjusted so that the vector of the last layer of neural network fits the implicit information related to the continuous variable.
[0021] This preferred solution is a detailed explanation of the training process, which is to fit the weights that are most suitable for solving the adaptive training problem, and then obtain the component vectors; the component vectors represent the comprehensive information of the continuous variables, and the comprehensive information is well-organized and clearly pointed. Therefore, for the original continuous variables, the information extracted from the component vectors is further sorted out, which can provide good data support for subsequent detection and analysis.
[0022] As a preferred solution, the user email feature vector is obtained by training a preset model using the label prediction accuracy of the mailbox where the target email is located as the objective function, specifically:
[0023] Obtaining a number of spam email samples and a number of normal email samples sent by different senders from the mailbox where the target email is located;
[0024] Changing the senders of the plurality of spam email samples to senders of the plurality of normal email samples to obtain a plurality of test email samples;
[0025] Using the plurality of test email samples and the plurality of normal email samples as training samples;
[0026] The label prediction accuracy of the training samples is used as the objective function, and the preset model is trained using the training samples to obtain the user message sending feature vector.
[0027] This preferred solution trains the preset model with label prediction accuracy as the objective function, so that the obtained user email feature vector can be used as a standard to obtain the data abnormality level of the current target email through comparison vectors; and by modifying the sender, the test email sample and the normal email sample can become a good training control group, so that the trained user email feature vector can learn the similarities and differences between spam and normal emails, and become a good email abnormality measurement standard.
[0028] As a preferred solution, the discrete variable is encoded to obtain a first characterization vector corresponding to the discrete variable, specifically:
[0029] Encoding the discrete variable into a one-hot encoding form by a hash algorithm to obtain an encoding result;
[0030] The encoding result is used to query a preset information conversion table to obtain the first characterization vector corresponding to the discrete variable.
[0031] This preferred solution encodes discrete variables in the form of one-hot encoding, which can expand the values of discrete features in discrete variables into a physically meaningful Euclidean space, so that a certain value of the discrete feature corresponds to a point in the Euclidean space, where the features of each dimension can be regarded as continuous features, which makes the distance calculation between features more reasonable; and this encoding expansion method can convert discrete classification labels in discrete variables into binary first representation vectors, so that the final first representation vector has the physical meaning of representing the discrete variable, which is convenient for subsequent processing and calculation.
[0032] As a preferred solution, the discrete variables and continuous variables of the target email are obtained as follows:
[0033] Obtaining the target email, performing information extraction on the target email, and obtaining the discrete variable and the continuous variable;
[0034] The discrete variables include email text, the name of the software used to send the email, the geographical location from which the email was sent, the time the email was sent, and the email address; the continuous variables include the number of times the email appears repeatedly, the number of recipients, the number of domain names to which the email is sent, the number of historical communications, and the size of the email.
[0035] The present invention also provides a device for detecting abnormal letter transmission caused by account theft, comprising a variable acquisition module, an encoding module, a training module, a scalar acquisition module and a judgment module;
[0036] The variable acquisition module is used to acquire discrete variables and continuous variables of the target email;
[0037] The encoding module is used to encode the discrete variable to obtain a first representation vector corresponding to the discrete variable;
[0038] The training module is configured to train the continuous variable through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable;
[0039] The scalar acquisition module is configured to mix the first characterization vector and the second characterization vector and input the mixed vector into the neural network layer for transformation to obtain an output scalar;
[0040] The judgment module is used to determine that the detection result of the target email is an abnormal email sending if the difference between the output scalar and the user email sending feature vector exceeds a preset threshold; wherein the user email sending feature vector is obtained by training a preset model with the label prediction accuracy of the mailbox where the target email is located as the objective function.
[0041] As a preferred solution, the training module includes a transfer unit, a fitting unit and a vector acquisition unit;
[0042] The transmission unit is used to input the continuous variable into the neural network layer, so that the continuous variable is transmitted layer by layer in the neural network layer;
[0043] The fitting unit is configured to perform adaptive training on the continuous variable using the last layer of neural network of the neural network layer, so that the last layer of neural network fits the implicit information related to the continuous variable;
[0044] The vector acquisition unit is used to obtain the component vector of the last layer of the neural network after training, and obtain the second representation vector corresponding to the continuous variable.
[0045] As a preferred solution, the fitting unit is specifically:
[0046] Adaptive training is performed on the continuous variable using the last layer of neural network of the neural network layer, and the weight of each neuron in the last layer of neural network is adjusted so that the vector of the last layer of neural network fits the implicit information related to the continuous variable.
[0047] As a preferred solution, the judgment module includes a first training unit, a second training unit, a third training unit and a fourth training unit;
[0048] The first training unit is configured to obtain a number of spam email samples and a number of normal email samples sent by different senders from the mailbox where the target email is located;
[0049] The second training unit is used to change the senders of the plurality of spam email samples to senders of the plurality of normal email samples to obtain a plurality of test email samples;
[0050] The third training unit is configured to use the plurality of test email samples and the plurality of normal email samples as training samples;
[0051] The fourth training unit is configured to use the label prediction accuracy of the training samples as an objective function, and to train the preset model using the training samples to obtain the user sending feature vector.
[0052] As a preferred solution, the encoding module includes an encoding unit and a query unit;
[0053] The encoding unit is configured to encode the discrete variable into a one-hot encoding form using a hash algorithm to obtain an encoding result;
[0054] The query unit is configured to use the encoding result to query a preset information conversion table to obtain the first representation vector corresponding to the discrete variable.
[0055] As a preferred solution, the variable acquisition module is specifically:
[0056] Obtaining the target email, performing information extraction on the target email, and obtaining the discrete variable and the continuous variable;
[0057] The discrete variables include email text, the name of the software used to send the email, the geographical location from which the email was sent, the time the email was sent, and the email address; the continuous variables include the number of times the email appears repeatedly, the number of recipients, the number of domain names to which the email is sent, the number of historical communications, and the size of the email.
[0058] The present invention also provides a storage medium on which a computer program is stored. The computer program is called and executed by a computer to implement the above-mentioned method for detecting abnormal sending of stolen messages. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] FIG1 is a flow chart of a method for detecting abnormal email transmission caused by account theft according to an embodiment of the present invention;
[0060] FIG2 is a schematic structural diagram of a device for detecting abnormal message transmission caused by account theft provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0061] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0062] In the description of this application, it should be understood that the terms "first," "second," "third," and "fourth" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features indicated. Thus, a feature specified as "first," "second," "third," and "fourth" may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise specified, "several" means two or more.
[0063] The method for detecting abnormal email sending caused by account theft described in the embodiment of the present invention is mainly used when enterprises, organizations or individuals use email boxes and need to ensure the security of email boxes or information. It can detect when an email account is stolen and spam / phishing messages are sent out.
[0064] Example 1:
[0065] Referring to FIG. 1 , an embodiment of the present invention provides a method for detecting abnormal email transmission caused by account theft, including steps S1 to S5 . The specific implementation steps are as follows:
[0066] S1. Obtain the discrete variables and continuous variables of the target email.
[0067] Step S1 of the embodiment of the present invention is specifically as follows:
[0068] Obtain target emails, extract information from the target emails, and obtain discrete variables and continuous variables;
[0069] The discrete variables include email text token, email sending software name (e.g., Outlook, Foxmail, and Webmail), email sending location (e.g., China, Guangdong, Guangzhou), email sending time (e.g., 2 o'clock), and email address.
[0070] Among them, continuous variables include the number of times the email appears repeatedly, the number of recipients, the number of receiving domain names, the number of historical communications, and the size of the email.
[0071] S2. Encode the discrete variable to obtain a first representation vector corresponding to the discrete variable.
[0072] Step S2 of the embodiment of the present invention is specifically as follows:
[0073] The discrete variables are encoded into one-hot encoding (unique hot encoding) through the hash method (hash algorithm) to obtain the encoding result;
[0074] The encoding result is used to query in a preset information conversion table to obtain the first characterization vector corresponding to the discrete variable.
[0075] This embodiment encodes discrete variables in the form of one-hot encoding, which can expand the values of discrete features in the discrete variables into a physically meaningful Euclidean space, so that a certain value of the discrete feature corresponds to a point in the Euclidean space, where the features of each dimension can be regarded as continuous features, which makes the distance calculation between features more reasonable; and this encoding expansion method can convert the discrete classification labels in the discrete variables into a binary first representation vector, so that the final first representation vector has the physical meaning of representing the discrete variable, which is convenient for subsequent processing and calculation.
[0076] S3. Train the continuous variable through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable.
[0077] Step S3 of the embodiment of the present invention is specifically as follows:
[0078] Input the continuous variables into the fully connected layer so that the continuous variables are transmitted layer by layer in the neural network layer;
[0079] The last layer of neural network in the neural network layer is used to perform adaptive training on the continuous variable, and the weight of each neuron in the last layer of neural network is adjusted so that the vector of the last layer of neural network fits the implicit information related to the continuous variable;
[0080] Obtain the component vector of the last layer of neural network after training, and obtain the second representation vector corresponding to the continuous variable.
[0081] For example:
[0082] Let A represent the number of times an email has recurred, and B represent the number of previous communications. Because users handle recurring emails differently from past communications, they will have different attitudes and approaches to these two types of emails.
[0083] Variables A and B are both input into the fully connected layer and passed layer by layer in the fully connected layer neural network. In this way, each neuron in each layer knows the number of times the email appears repeatedly and the number of historical communications. After training, the weights of the neurons in the last layer are adjusted to fit the implicit relationship pointed to by variables A and B.
[0084] At this point, the vector composed of the neural network in the last layer can be considered as a representation vector containing variables A and B. This representation vector contains the implicit relationship and information direction between variables A and B, and can well represent issues related to the training objectives (for example, whether users will only process a certain type of email).
[0085] On this basis, the input continuous variables are expanded to n variables. Since the number of neurons in each fully connected layer is fixed (generally a 64-dimensional or 128-dimensional vector), no matter what the n continuous variables are input, the fully connected layer can calculate a 64-dimensional or 128-dimensional vector to represent the comprehensive information of the input features of these n variables.
[0086] In this embodiment, since the continuous variable itself has physical meaning, it can be directly used as the input of the neural network. By allowing the continuous variable to be transmitted layer by layer in the neural network layer, the neural network layer can effectively analyze the continuous variable and obtain information. By fitting the last layer of the neural network layer to the adaptive training problem related to the continuous variable, the obtained second representation vector can contain implicit information related to the continuous variable, and effectively represent the relationship between each piece of information in the continuous variable and the information direction.
[0087] Moreover, adaptive training is to fit the weights that are most suitable for solving the adaptive training problem, and then obtain the component vectors; the component vectors represent the comprehensive information of the continuous variables, which is well-organized and has a clear direction. Therefore, for the original continuous variables, the information extracted from the component vectors is further sorted out, which can provide good data support for subsequent detection and analysis.
[0088] S4. Mix the first representation vector and the second representation vector and input them into the neural network layer for transformation to obtain an output scalar.
[0089] Step S4 of the embodiment of the present invention is specifically as follows:
[0090] Performing a dot product operation on the first characterization vector and the second characterization vector to fully mix information of the first characterization vector and the second characterization vector;
[0091] The mixed first representation vector and second representation vector are input into the fully connected layer for transformation to obtain an output scalar.
[0092] In this embodiment, since the second representation vector is obtained through the fully connected layer and has a certain dimension, it is transformed by the dot product operation and then input into the fully connected layer, so that the dimensions of the first representation vector and the second representation vector can be unified, so that the obtained output scalar contains all surface literal information and implicit information about the discrete variables and continuous variables.
[0093] S5. If the difference between the output scalar and the user's email feature vector exceeds a preset threshold, the detection result of the target email is an email sending anomaly; wherein the user's email feature vector is obtained by training a preset model with the label prediction accuracy of the mailbox where the target email is located as the objective function.
[0094] In step S5 of the embodiment of the present invention, S5 includes S5.1 to S5.2, specifically:
[0095] S5.1. If the difference between the output scalar and the user's message sending feature vector exceeds the preset threshold, the detection result of the target email is that the message sending is abnormal; if the difference between the output scalar and the user's message sending feature vector does not exceed the preset threshold, the detection result of the target email is that the message sending is normal.
[0096] S5.2. Add the abnormally sent emails to the review queue and wait for review by the reviewer until the reviewer releases it or it waits in the review queue for more than the preset time before sending it.
[0097] It should be noted that the reviewer refers to the system administrator of the email, not the sender of the current target email; the review queue refers to the system administrator's review interface queue, not the sending queue of the current target email.
[0098] The process of constructing the user's message sending feature vector includes S5.21 to S5.24, specifically:
[0099] S5.21. Obtain several spam email samples and several normal email samples sent by different senders from the mailbox where the target email is located; among them, normal email samples refer to emails that the sender and receiver have communicated with two or more times before.
[0100] S5.22. Change the senders of several spam email samples to senders of several normal email samples to obtain several test email samples.
[0101] S5.23. Use several test email samples and several normal email samples as training samples.
[0102] S5.24. Using the label prediction accuracy of the training samples as the objective function, the preset model is trained using the training samples to obtain a user message feature vector; wherein the user message feature vector represents the degree of similarity between the email features of the email currently sent by the user and the normal emails previously sent by the user.
[0103] This embodiment trains the preset model with label prediction accuracy as the objective function, so that the obtained user email feature vector can be used as a standard to obtain the data abnormality level of the current target email through comparison vectors; and by modifying the sender, the test email sample and the normal email sample can become a good training control group, so that the trained user email feature vector can learn the similarities and differences between spam and normal emails, and become a good standard for measuring email abnormality.
[0104] In general, the embodiments of the present invention have the following beneficial effects:
[0105] By encoding and training discrete and continuous variables separately, the embodiments of the present invention can effectively extract the text information and other ancillary information of a target email. By then mixing the outputs, an output scalar is obtained for comparison and judgment, resulting in a detection result. This detection method is simple, fast, and highly practical. Encoding the discrete variables involves expanding the values of the discrete features within the discrete variables into a space with a different physical meaning, so that the resulting first representation vector has the physical meaning of representing the discrete variables, facilitating subsequent processing and calculation. Mixing the first and second representation vectors and inputting them into the neural network layer allows for the information therein to be sorted, facilitating subsequent comparison with the user's message feature vector to determine the differences between the two. Because the user's message feature vector is trained based on the data of the mailbox containing the target email, it captures the message sending and receiving habits of the user in the mailbox containing the target email. Therefore, it can be used as a metric to significantly minimize the occurrence of false positives in detection results.
[0106] Example 2:
[0107] Referring to FIG2 , an embodiment of the present invention provides a device for detecting abnormal email transmission caused by account theft, comprising a variable acquisition module 10 , an encoding module 20 , a training module 30 , a scalar acquisition module 40 , and a judgment module 50 ;
[0108] The variable acquisition module 10 is used to acquire discrete variables and continuous variables of the target email;
[0109] An encoding module 20, configured to encode the discrete variable to obtain a first representation vector corresponding to the discrete variable;
[0110] A training module 30 is configured to train the continuous variable through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable;
[0111] A scalar acquisition module 40 is configured to mix the first characterization vector and the second characterization vector and input the mixed vector into a neural network layer for transformation to obtain an output scalar;
[0112] The judgment module 50 is used to judge that the detection result of the target email is an abnormal email sending if the difference between the output scalar and the user email sending feature vector exceeds a preset threshold; wherein the user email sending feature vector is obtained by training a preset model with the label prediction accuracy of the mailbox where the target email is located as the objective function.
[0113] In one embodiment, the variable acquisition module 10 is specifically:
[0114] Obtain target emails, extract information from the target emails, and obtain discrete variables and continuous variables;
[0115] The discrete variables include email text token, email sending software name (e.g., Outlook, Foxmail, and Webmail), email sending location (e.g., China, Guangdong, Guangzhou), email sending time (e.g., 2 o'clock), and email address.
[0116] Among them, continuous variables include the number of times the email appears repeatedly, the number of recipients, the number of receiving domain names, the number of historical communications, and the size of the email.
[0117] In one embodiment, the encoding module 20 includes an encoding unit and a query unit;
[0118] The encoding unit is used to encode the discrete variable into a one-hot encoding form by using a hash method (hash algorithm) to obtain an encoding result;
[0119] The query unit is used to use the encoding result to query in a preset information conversion table to obtain a first characterization vector corresponding to the discrete variable.
[0120] This embodiment encodes discrete variables in the form of one-hot encoding, which can expand the values of discrete features in the discrete variables into a physically meaningful Euclidean space, so that a certain value of the discrete feature corresponds to a point in the Euclidean space, where the features of each dimension can be regarded as continuous features, which makes the distance calculation between features more reasonable; and this encoding expansion method can convert the discrete classification labels in the discrete variables into a binary first representation vector, so that the final first representation vector has the physical meaning of representing the discrete variable, which is convenient for subsequent processing and calculation.
[0121] In one embodiment, the training module 30 includes a transfer unit, a fitting unit, and a vector acquisition unit;
[0122] The transfer unit is used to input the continuous variables into the fully connected layer, so that the continuous variables are transferred layer by layer in the neural network layer;
[0123] A fitting unit is used to perform adaptive training on the continuous variable using the last layer of neural network in the neural network layer, and to adjust the weight of each neuron in the last layer of neural network so that the vector of the last layer of neural network fits the implicit information related to the continuous variable;
[0124] The vector acquisition unit is used to obtain the component vector of the last layer of the neural network after training and obtain the second representation vector corresponding to the continuous variable.
[0125] For example:
[0126] Let A represent the number of times an email has recurred, and B represent the number of previous communications. Because users handle recurring emails differently from past communications, they will have different attitudes and approaches to these two types of emails.
[0127] Variables A and B are both input into the fully connected layer and passed layer by layer in the fully connected layer neural network. In this way, each neuron in each layer knows the number of times the email appears repeatedly and the number of historical communications. After training, the weights of the neurons in the last layer are adjusted to fit the implicit relationship pointed to by variables A and B.
[0128] At this point, the vector composed of the neural network in the last layer can be considered as a representation vector containing variables A and B. This representation vector contains the implicit relationship and information direction between variables A and B, and can well represent issues related to the training objectives (for example, whether users will only process a certain type of email).
[0129] On this basis, the input continuous variables are expanded to n variables. Since the number of neurons in each fully connected layer is fixed (generally a 64-dimensional or 128-dimensional vector), no matter what the n continuous variables are input, the fully connected layer can calculate a 64-dimensional or 128-dimensional vector to represent the comprehensive information of the input features of these n variables.
[0130] In this embodiment, since the continuous variable itself has physical meaning, it can be directly used as the input of the neural network. By allowing the continuous variable to be transmitted layer by layer in the neural network layer, the neural network layer can effectively analyze the continuous variable and obtain information. By fitting the last layer of the neural network layer to the adaptive training problem related to the continuous variable, the obtained second representation vector can contain implicit information related to the continuous variable, and effectively represent the relationship between each piece of information in the continuous variable and the information direction.
[0131] Moreover, adaptive training is to fit the weights that are most suitable for solving the adaptive training problem, and then obtain the component vectors; the component vectors represent the comprehensive information of the continuous variables, which is well-organized and has a clear direction. Therefore, for the original continuous variables, the information extracted from the component vectors is further sorted out, which can provide good data support for subsequent detection and analysis.
[0132] In one embodiment, the scalar acquisition module 40 is specifically:
[0133] Performing a dot product operation on the first characterization vector and the second characterization vector to fully mix information of the first characterization vector and the second characterization vector;
[0134] The mixed first representation vector and second representation vector are input into the fully connected layer for transformation to obtain an output scalar.
[0135] In this embodiment, since the second representation vector is obtained through the fully connected layer and has a certain dimension, it is transformed by the dot product operation and then input into the fully connected layer, so that the dimensions of the first representation vector and the second representation vector can be unified, so that the obtained output scalar contains all surface literal information and implicit information about the discrete variables and continuous variables.
[0136] In one embodiment, the judgment module 50 includes a judgment unit and a review unit;
[0137] Among them, the judgment unit is used to determine that if the difference between the output scalar and the user's email feature vector exceeds a preset threshold, the detection result of the target email is that the email sending is abnormal; if the difference between the output scalar and the user's email feature vector does not exceed the preset threshold, the detection result of the target email is that the email sending is normal.
[0138] The review unit is used to add emails with abnormal sending to the review queue and wait for review by the reviewer until the reviewer releases them or they are sent after waiting in the review queue for more than the preset time.
[0139] It should be noted that the reviewer refers to the system administrator of the email, not the sender of the current target email; the review queue refers to the system administrator's review interface queue, not the sending queue of the current target email.
[0140] The process of constructing the user's message feature vector includes a first training unit, a second training unit, a third training unit, and a fourth training unit;
[0141] Among them, the first training unit is used to obtain a number of spam email samples and a number of normal email samples sent by different senders from the mailbox where the target email is located; among them, the normal email samples refer to emails that the sender and receiver have communicated with twice or more before.
[0142] The second training unit is used to change the senders of several spam email samples to senders of several normal email samples to obtain several test email samples.
[0143] The third training unit is configured to use a plurality of test email samples and a plurality of normal email samples as training samples.
[0144] The fourth training unit is used to train a preset model using the training samples with the label prediction accuracy of the training samples as the objective function to obtain the user's email feature vector; wherein the user's email feature vector represents the degree of similarity between the email features of the user's current email and the normal emails previously sent by the user.
[0145] This embodiment trains the preset model with label prediction accuracy as the objective function, so that the obtained user email feature vector can be used as a standard to obtain the data abnormality level of the current target email through comparison vectors; and by modifying the sender, the test email sample and the normal email sample can become a good training control group, so that the trained user email feature vector can learn the similarities and differences between spam and normal emails, and become a good standard for measuring email abnormality.
[0146] In general, the embodiments of the present invention have the following beneficial effects:
[0147] By encoding and training discrete variables and continuous variables separately, this device can effectively extract the text information and other ancillary information of the target email, and then obtain an output scalar through mixed output for comparison and judgment to obtain the detection result. This detection method is simple, fast and highly practical. Among them, encoding discrete variables is to expand the values of discrete features in discrete variables into a space with other physical meanings, so that the obtained first representation vector has the physical meaning of representing discrete variables, which is convenient for subsequent processing and calculation; mixing the first representation vector and the second representation vector and inputting them into the neural network layer can sort out the information therein, which is convenient for subsequent comparison with the user's message feature vector to obtain the difference between the two; since the user's message feature vector is trained based on the data of the mailbox where the target email is located, the obtained user's message feature vector contains the information sending and receiving habits of the user in the mailbox where the target email is located, so it can be used as a measurement standard to greatly reduce the occurrence of misjudgment of detection results.
[0148] Example 3:
[0149] An embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device containing the computer-readable storage medium is controlled to execute the method for detecting abnormal sending of stolen messages;
[0150] Wherein, if the method for detecting abnormal sending of stolen messages is implemented in the form of a software functional unit and used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process of the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. Wherein, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc.
[0151] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for detecting abnormal email sending by account theft, characterized in that: include: Get the discrete and continuous variables of the target emails; Encoding the discrete variable to obtain a first representation vector corresponding to the discrete variable; Training the continuous variable through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable; Mixing the first characterization vector and the second characterization vector and inputting the mixed vector into the neural network layer for transformation to obtain an output scalar; If the difference between the output scalar and the user's email feature vector exceeds a preset threshold, the detection result of the target email is an abnormal email sending; wherein the user's email feature vector is obtained by training a preset model with the label prediction accuracy of the mailbox where the target email is located as the objective function.
2. A method for detecting abnormal email sending by account theft as claimed in claim 1, characterized in that: The continuous variable is trained through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable, specifically: Inputting the continuous variable into the neural network layer so that the continuous variable is transmitted layer by layer in the neural network layer; Using the last layer of neural network of the neural network layer to perform adaptive training on the continuous variable, so that the last layer of neural network fits the implicit information related to the continuous variable; Obtain the component vector of the last layer of the neural network after training, and obtain the second representation vector corresponding to the continuous variable.
3. A method for detecting abnormal email sending by account theft as claimed in claim 2, characterized in that: The last layer of neural network of the neural network layer is used to perform adaptive training on the continuous variable, so that the last layer of neural network fits the implicit information related to the continuous variable, specifically: The last neural network layer of the neural network layer is used to perform adaptive training on the continuous variable, and the weight of each neuron in the last neural network layer is adjusted so that the vector of the last neural network layer is fitted to the implicit information related to the continuous variable.
4. A method for detecting abnormal email sending by account theft as claimed in claim 1, characterized in that: The user email feature vector is obtained by training a preset model using the label prediction accuracy of the mailbox where the target email is located as the objective function, specifically: Obtaining a number of spam email samples and a number of normal email samples sent by different senders from the mailbox where the target email is located; Changing the senders of the plurality of spam email samples to senders of the plurality of normal email samples to obtain a plurality of test email samples; Using the plurality of test email samples and the plurality of normal email samples as training samples; The label prediction accuracy of the training sample is used as the objective function, and the preset model is trained using the training sample to obtain the user sending feature vector.
5. A method for detecting abnormal email sending by account theft as claimed in claim 1, characterized in that: The discrete variable is encoded to obtain a first characterization vector corresponding to the discrete variable, specifically: Encoding the discrete variable into a one-hot encoding form by using a hash algorithm to obtain an encoding result; The encoding result is used to query in a preset information conversion table to obtain the first characterization vector corresponding to the discrete variable.
6. A method for detecting abnormal email sending by account theft as claimed in claim 1, characterized in that: Get the discrete and continuous variables of the target email, specifically: Acquire the target email, extract information from the target email, and obtain the discrete variable and the continuous variable; The discrete variables include email text, email sending software name, email sending location, email sending time and email address; the continuous variables include the number of email repetitions, the number of recipients, the number of receiving domain names, the number of historical communications and the size of the email.
7. A device for detecting abnormal sending of stolen messages, characterized in that: It includes a variable acquisition module, an encoding module, a training module, a scalar acquisition module and a judgment module; Wherein, the variable acquisition module is used to acquire discrete variables and continuous variables of the target email; The encoding module is used to encode the discrete variable to obtain a first representation vector corresponding to the discrete variable; The training module is used to train the continuous variable through a preset neural network layer to obtain a second representation vector corresponding to the continuous variable; The scalar acquisition module is used to mix the first characterization vector and the second characterization vector and input them into the neural network layer for transformation to obtain an output scalar; The judgment module is used to determine that if the difference between the output scalar and the user's email feature vector exceeds a preset threshold, the detection result of the target email is an abnormal email sending; wherein the user's email feature vector is obtained by training a preset model with the label prediction accuracy of the mailbox where the target email is located as the objective function.
8. A device for detecting abnormal sending of stolen messages according to claim 7, characterized in that: The training module includes a transfer unit, a fitting unit and a vector acquisition unit; The transmission unit is used to input the continuous variable into the neural network layer, so that the continuous variable is transmitted layer by layer in the neural network layer; The fitting unit is used to use the last layer of neural network of the neural network layer to perform adaptive training on the continuous variable, so that the last layer of neural network fits the implicit information related to the continuous variable; The vector acquisition unit is used to acquire the component vector of the last layer of the neural network after training, and obtain the second representation vector corresponding to the continuous variable.
9. A device for detecting abnormal sending of stolen messages according to claim 8, characterized in that: The fitting unit is specifically: The last neural network layer of the neural network layer is used to perform adaptive training on the continuous variable, and the weight of each neuron in the last neural network layer is adjusted so that the vector of the last neural network layer is fitted to the implicit information related to the continuous variable.
10. The device for detecting abnormal sending of stolen messages according to claim 7, characterized in that: The judgment module includes a first training unit, a second training unit, a third training unit and a fourth training unit; The first training unit is used to obtain a number of spam email samples and a number of normal email samples sent by different senders from the mailbox where the target email is located; The second training unit is used to change the senders of the plurality of spam email samples to senders of the plurality of normal email samples to obtain a plurality of test email samples; The third training unit is used to use the plurality of test email samples and the plurality of normal email samples as training samples; The fourth training unit is used to use the label prediction accuracy of the training samples as the objective function, and use the training samples to train the preset model to obtain the user sending feature vector.
11. A device for detecting abnormal sending of stolen messages according to claim 7, characterized in that: The encoding module includes an encoding unit and a query unit; The encoding unit is used to encode the discrete variable into a one-hot encoding form through a hash algorithm to obtain an encoding result; The query unit is used to use the encoding result to query in a preset information conversion table to obtain the first characterization vector corresponding to the discrete variable.
12. The device for detecting abnormal sending of stolen messages according to claim 7, characterized in that: The variable acquisition module is specifically: Acquire the target email, extract information from the target email, and obtain the discrete variable and the continuous variable; The discrete variables include email text, email sending software name, email sending location, email sending time and email address; the continuous variables include the number of email repetitions, the number of recipients, the number of receiving domain names, the number of historical communications and the size of the email.
13. A storage medium, characterized in that: The storage medium stores a computer program, which is called and executed by a computer to implement a method for detecting abnormal sending of stolen messages as claimed in any one of claims 1 to 6.
Citation Information
Patent Citations
A FastText algorithm-based high-precision intelligent misjudgment prevention method and device for a mail system
CN109831373A
Mail classification method and device based on behavior structure and semantic content joint analysis
CN111221970A
Junk mail identification method and device, and computer readable storage medium
CN113630302A
Junk mail detection method and system of neural network combining semantics and behaviors
CN117201446A
Method and device for detecting abnormal signaling of account stealing, and medium
CN117768435A