CN107093090A - Abnormal user recognition methods and device - Google Patents

Abnormal user recognition methods and device Download PDF

Info

Publication number
CN107093090A
CN107093090A CN201610937572.1A CN201610937572A CN107093090A CN 107093090 A CN107093090 A CN 107093090A CN 201610937572 A CN201610937572 A CN 201610937572A CN 107093090 A CN107093090 A CN 107093090A
Authority
CN
China
Prior art keywords
single user
user
community
incidence relation
time
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201610937572.1A
Other languages
Chinese (zh)
Inventor
刘梦宇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Xiaodu Information Technology Co Ltd
Original Assignee
Beijing Xiaodu Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Xiaodu Information Technology Co Ltd filed Critical Beijing Xiaodu Information Technology Co Ltd
Priority to CN201610937572.1A priority Critical patent/CN107093090A/en
Publication of CN107093090A publication Critical patent/CN107093090A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/02Marketing; Price estimation or determination; Fundraising
    • G06Q30/0201Market modelling; Market analysis; Collecting market data
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/06Buying, selling or leasing transactions
    • G06Q30/0601Electronic shopping [e-shopping]
    • G06Q30/0633Lists, e.g. purchase orders, compilation or processing

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Finance (AREA)
  • Strategic Management (AREA)
  • Development Economics (AREA)
  • Engineering & Computer Science (AREA)
  • General Business, Economics & Management (AREA)
  • Physics & Mathematics (AREA)
  • Marketing (AREA)
  • General Physics & Mathematics (AREA)
  • Economics (AREA)
  • Theoretical Computer Science (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Data Mining & Analysis (AREA)
  • Game Theory and Decision Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The present embodiments relate to data mining technology field, more particularly to a kind of abnormal user recognition methods and device.Wherein, methods described includes:According to History Order data, each the lower incidence relation of single user between any two is determined;According to each the described lower incidence relation of single user between any two, customer relationship network is generated;Community's division is carried out to the customer relationship network, multiple communities are obtained;User behavior feature in the multiple community, determines abnormal user.Abnormal user recognition methods provided in an embodiment of the present invention and device, comprehensive and accurate can excavate potential abnormal user.

Description

Abnormal user recognition methods and device
Technical field
The present embodiments relate to data mining technology field, more particularly to a kind of abnormal user recognition methods and device.
Background technology
The type and quantity for the application software ordered the goods or serviced with the development of Internet technology, on user's line also exist It is skyrocketed through.The supplier of above-mentioned each service class application software has to attract user and businessman to use oneself application software When certain subsidy or preferential can be provided to lower single user and for the businessman for lower single user provider product or service.Some are used There is malice brush single act, especially by multiple user accounts to obtain the subsidy or preferential of software vendor offer in family The single behavior of group's brush is carried out, can be to causing no small loss in software development.Therefore how to be determined in numerous lower single users Go out to have the user of the abnormal behaviours such as brush list to turn into a urgent problem to be solved.
Currently, the mode for excavating potential abnormal user in order user is mainly according to co-occurrence principle, will be simultaneously at certain The lower single user that the common occurrence number of one businessman exceedes given threshold is defined as abnormal user, is such as defined as group's brush single user.
Above-mentioned determination group brush single user of the prior art recognizes the mode of abnormal user, although can be to a certain degree On excavate the user community brush single user with the abnormal behaviour such as brush is single, but it is wheel to be occasionally used for the single user account of group's brush Outflow is existing, and the number of times that some accounts occur not is a lot, and what these seldom occurred in group's brush list has abnormal behaviour User account be likely to be submerged in normal user account, be not found.
The content of the invention
The embodiment of the present invention provides a kind of abnormal user recognition methods and device, potentially has with comprehensive and accurate excavation The user of abnormal behaviour.
In a first aspect, the embodiments of the invention provide a kind of abnormal user recognition methods, including:
According to History Order data, each the lower incidence relation of single user between any two is determined;
According to each the described lower incidence relation of single user between any two, customer relationship network is generated;
Community's division is carried out to the customer relationship network, multiple communities are obtained;
User behavior feature in the multiple community, determines abnormal user.
Second aspect, the embodiments of the invention provide a kind of abnormal user identifying device, including:
Incidence relation determining unit, for according to History Order data, determining each the lower association of single user between any two Relation;
Relational network generation unit, for according to each the described lower incidence relation of single user between any two, generating user Relational network;
Community's division unit, for carrying out community's division to the customer relationship network, obtains multiple communities, wherein each The community includes at least two times single users;
Abnormal user determining unit, for the user behavior feature in the multiple community, determines abnormal user.
Scheme of the embodiment of the present invention identification with abnormal behaviour abnormal user when, first according to lower single user two-by-two it Between incidence relation generation customer relationship network, and according to complex network community division principle to customer relationship network carry out society Division, obtains multiple communities.Wherein, there is direct or indirect association, different societies between the lower single user in each community May it not associated between the user in area, therefore, when single user can be determined to be abnormal user under the part in a community When, other lower single users in the community are direct or indirect because the abnormal user with determining has to be associated, therefore also may be used To be confirmed as abnormal user, scheme of the embodiment of the present invention can apply in the scene of excavation group brush single user, utilize this Mode can excavate the brush single user being of little use in Shua Dan cliques, so that the group's brush single user obtained is more accurate complete Face.
It should be appreciated that the general description of the above and detailed description hereinafter are only exemplary and explanatory, not The embodiment of the present invention can be limited.
Brief description of the drawings
Accompanying drawing herein is merged in specification and constitutes the part of this specification, shows the implementation for meeting the present invention Example, and be used to together with specification to explain the principle of the embodiment of the present invention.
Fig. 1 is a kind of possible application scenarios schematic diagram of the present invention;
Fig. 2 is the flow chart of the abnormal user recognition methods of the embodiment of the present invention one;
Fig. 3 is the flow chart of the abnormal user recognition methods of the embodiment of the present invention two;
Fig. 4 is a kind of structural representation of figure network;
Fig. 5 is the structural representation of abnormal user identifying device of the embodiment of the present invention;
Fig. 6 is a kind of structural representation of server of the embodiment of the present invention.
Embodiment
Here exemplary embodiment will be illustrated in detail, its example is illustrated in the accompanying drawings.Following description is related to During accompanying drawing, unless otherwise indicated, the same numbers in different accompanying drawings represent same or analogous key element.Following exemplary embodiment Described in embodiment do not represent all embodiments consistent with the embodiment of the present invention.On the contrary, they be only with As be described in detail in the appended claims, embodiment of the present invention some in terms of consistent apparatus and method example.
In the existing method for determining group's brush single user, mainly according to the co-occurrence number of times of lower single user, such as first Lower single user places an order 100 times in preset time period in the first businessman, and second time single user is in the preset time period first Businessman places an order 90 times, and the co-occurrence number of times of first time single user and second time single user in the preset time period is 90 times, it is assumed that Co-occurrence threshold value is 80, then first time single user and second time single user co-occurrence number of times are more than co-occurrence threshold value, thereby determine that under first Single user and second time single user are group's brush single user.In addition, the three times single users are also under first time single user and second A lower single user in Shua Dan cliques belonging to single user, but the three times single users in above-mentioned preset time period first Businessman's number of times that places an order is only 10 times, is less than co-occurrence threshold value with the co-occurrence number of times of first time single user and/or second time single user, really Fixed the three times single users are normally lower single user, it is seen then that existing that potential group's brush single user is excavated in numerous lower single users Method can there is a situation where to omit some lower single users.
In order to which the user with abnormal behaviours such as group's brush lists for solving in the prior art, to determine is inaccurate incomplete Problem, the embodiments of the invention provide a kind of abnormal user identifying schemes, is descended in single user two-by-two according to each in this scenario Between incidence relation, set up customer relationship network;And community's division principle is utilized, customer relationship network is divided into multiple societies Area, when single user is confirmed as abnormal user under the part in community, all lower single users in the community where it may It is confirmed as abnormal user, it is possible thereby to which more comprehensive and accurate determine the user with abnormal behaviour.
Fig. 1 is a kind of possible application scenarios schematic diagram of the present invention.As shown in figure 1, application software involved in the present invention A kind of basic system architecture include:Buyer client 101, seller client 102, the person's of sending with charge free client 103 and server 104, the quantity of buyer client 101, seller client 102 and the person's of sending with charge free client 103 is multiple, and and server 104 connections.
In the application software system framework shown in Fig. 1, server 104 by commodity, service do not subsidize or favor information It is shown in buyer client 101 and seller client 102;User is placed an order by buyer client 101 to certain commodity or service, Buyer client 101 generates sequence information according to the lower single operation of user and is sent to server 104;Server bid in 104 future The sequence information of family's client 101 is sent to seller client 102, so that seller prepares corresponding commodity or service;Server 104 also give the person's of sending with charge free client 103 using the sequence information received as logistics Order splitting, so that the person of sending with charge free dispenses for buyer Commodity provide service.Wherein, in the flow of the order processing, if user is placed an order completely by buyer client 101 Foot enjoys subsidy or preferential condition, and server 104 also feeds back corresponding subsidy or preferential to buyer client 101, similarly connect Single seller receives orders to meet to enjoy and subsidized or during preferential condition, and server 104 also feeds back to seller client 102 respectively Corresponding subsidy or preferential.
Some buyers or seller may use malice brush single file to gain the subsidy or preferential of software vendor offer by cheating For for example:Some sellers may voluntarily register multiple accounts that place an order, and false to oneself commodity using the plurality of account that places an order Place an order, so as to gain subsidy that software vendor provided buyer and seller simultaneously by cheating and preferential, by this kind in order to deceive in the application Take some preferential, subsidies or in order that seller shop reaches certain credit grade and the false behavior placed an order is referred to as brush single file For, and the behavior for using multiple different accounts that place an order brush list is referred to as clique's brush list, wherein in clique's brush single act In, the account one lower single user of correspondence that places an order.
It is single etc. with group's brush there is provided identification in the loss that malice brush single tape is come, scheme of the embodiment of the present invention in order to reduce The method of abnormal behaviour user.
Fig. 2 is the flow chart of the abnormal user recognition methods of the embodiment of the present invention one.Method shown in Fig. 2 is applied to shown in Fig. 1 Application software system framework when, server be this method executive agent, including:
S201, according to History Order data, determines each the lower incidence relation of single user between any two.
Server determines association between any two in each lower single user according to the History Order data in preset time period Relation.In the application, the incidence relation in each lower single user between any two can not only be embodied on co-occurrence number of times, may be used also To be embodied in ship-to that different user placed an order using identical IP, different lower single users, to recall address identical, and not In the equal different dimension of remarks phase placed an order with lower single user, so as between the lower single user of deep layer secondary response difference Incidence relation.
S202, according to each the described lower incidence relation of single user between any two, generates customer relationship network.
Server is it is determined that after each the lower incidence relation of single user between any two, generate customer relationship network, the user Relational network can embody each the lower incidence relation of single user between any two.
S203, carries out community's division to the customer relationship network, obtains multiple communities.
Server carries out community's division according to complex network community division principle to customer relationship network, obtains multiple societies Having between lower single user in area, each community may not between direct or indirect incidence relation, the user of different communities With association.
S204, the user behavior feature in the multiple community, determines abnormal user.
Server goes to determine the user with abnormal behaviour from above-mentioned multiple communities, for example, in some community, when When determining greater number of lower single user for brush single user, due to remaining brush single user and the lower single user for being defined as brush single user Between there is the lower single user in direct or indirect association, therefore whole community can be determined that brush single user.
It in summary it can be seen, scheme of the embodiment of the present invention, when identification has the user of abnormal behaviour, basis places an order first The incidence relation generation customer relationship network of user between any two, and according to complex network community division principle to customer relationship Network carries out community's division, obtains multiple communities.There is direct or indirect association between lower single user in each community, no May it not associated between the user of community, accordingly, when single user can be determined to be and have under the part in a community During the user of abnormal behaviour, other lower single users in the community due to the above-mentioned abnormal user determined have directly or The association connect, therefore abnormal user can also be confirmed as, it is alone that scheme of the embodiment of the present invention can apply to excavation group brush In the scene at family, it is particularly possible to excavate the brush single user being of little use in Shua Dan cliques, so that the group's brush single user obtained It is more accurate comprehensive.
Fig. 3 is the flow chart of the abnormal user recognition methods of the embodiment of the present invention two.Method shown in Fig. 3 is applied to shown in Fig. 1 Application software system framework when, server be this method executive agent, including:
S301, obtains the History Order data in preset time period, such as obtains the history produced in the nearest 30 day time and order Forms data.Wherein, lower single user (being referred to as the account that places an order) can be included in each History Order data, place an order when institute With the IP of equipment, ship-to, recall the information such as address and remarks.
S302, according to the History Order data of acquisition, determines each the lower incidence relation of single user between any two.
Server according to History Order data, it is determined that in lower single user under any two the lower single user of single user-the first and The mode of incidence relation between second time single user includes:
(1) server determines the co-occurrence number of times of first time single user and second time single user in above-mentioned preset time period. Specifically, above-mentioned preset time period is divided into multiple unit intervals, the plurality of unit interval sum is equal to preset time period, And it is misaligned between the plurality of unit interval.Such as preset time period in S301 is nearest 30 days, then with one day when Between be within (24 hours) unit interval.
Optionally, server determines first time single user and second time single user co-occurrence in the preset time period time Number, including:Server determines the co-occurrence number of times of first time single user and second time single user in each unit interval.
Wherein, server determines the co-occurrence number of times of first time single user and second time single user in each unit interval Including:Server determines shared time in identical businessman in each unit interval of first time single user and second time single user Number, for example, first time single user and second time single user in first unit interval 4 times in first businessman's co-occurrence, The second businessman's co-occurrence 3 times, then the one the first lower single users and the two the second lower co-occurrences of the single user in the unit interval Number of times is 7 times, similarly, first time single user and second time single user can be calculated in this mode in each unit interval Co-occurrence number of times.
Server calculates each unit interval of first time single user and second time single user in preset time period Co-occurrence number of times after, the co-occurrence number of times sum in all unit intervals is defined as alone under first time single user and second Co-occurrence number of times of the family in the preset time period.
(2) server is determined in the co-occurrence number of times of first time single user and second time single user in above-mentioned preset time period Identical IP number, identical ship-to number of times, identical recall address number of times and identical remarks number of times.
(3) server is according to the co-occurrence number of times of first time single user and second time single user, described The identical IP number, the identical ship-to number of times in co-occurrence number of times, described identical recall address number of times and the phase With remarks number of times, the incidence relation of first time single user and second time single user is determined.
Optionally, server is in advance the co-occurrence number of times of two users, identical IP number, identical ship-to number of times, phase With recall address number of times and identical remarks number of times distribution weight;Server is calculating first time single user and second time single user Co-occurrence number of times in preset time period, the identical IP number in the co-occurrence number of times, identical ship-to number of times, identical call together Return after address number of times and identical remarks number of times, according to being the co-occurrence number of times, the identical IP number in advance, described identical receive Address number of times, the identical weight for recalling address number of times and the identical remarks number of times distribution, it is alone under determining described first Family and the incidence relation of second time single user.
For example, the co-occurrence number of times of first time single user, second time single user in preset time period is 10 times, at this 10 times In, the use of identical IP number of times is 6 times, the number of times of identical ship-to be 2 times, the identical number of times for recalling address is 4 times, identical The number of times of remarks is 1 time;Server is in advance co-occurrence number of times, identical IP number, identical ship-to number of times, identical recall address The weight that number of times and identical remarks number of times are distributed is respectively w1、w2、w3、w4, then the pass of first time single user and second time single user Connection relation=w1×10+w2×6+w3×2+w4×4+w5×1。
, can be with the way of the incidence relation between above-mentioned first time single user of the determination provided and second time single user Determine the incidence relation of single user between any two under each in History Order data.
S303, according to each the lower incidence relation of single user between any two, generates customer relationship network.
Server is it is determined that after each time incidence relation of single user between any two, single user is descended between any two according to each Incidence relation generation customer relationship network, the customer relationship network can reflect that each association of lower single user between any two is closed System.
S304, determines lower single user of the incidence relation less than predetermined threshold value in the customer relationship network.
S305, the lower single user by the incidence relation less than predetermined threshold value is deleted from the customer relationship network, shape Into one strong customer relationship network.
After server generation customer relationship network, determine that incidence relation is less than predetermined threshold value from the customer relationship network Lower single user, and incidence relation is deleted less than the lower single user of predetermined threshold value from relational network, forms one strong use Family relational network.
S306, figure network is converted into by the strong customer relationship network.
Fig. 4 is a kind of structural representation of figure network.Wherein, figure network is such as Fig. 4 to the abstract of strong customer relationship network Shown, in figure network, lower single user is represented using node, is used between the node corresponding to the lower single user with incidence relation Frontier juncture joins, and the incidence relation between lower single user can be intuitively determined from the figure network shown in Fig. 4.
S307, is that each lower single user in the figure network distributes community's mark, is identified with identical community Lower single user belongs to same community, for example with Fast Unfold community discoveries algorithm be figure network in it is each under it is alone Community's mark is distributed at family, it is possible thereby to which the figure network shown in Fig. 4 is divided into multiple communities.
As shown in figure 4, the node with direct or indirect incidence relation can distribute identical community mark in figure network Know, the node without direct or indirect incidence relation can distribute different community's marks.The node of specific difference community It can be identified, or be identified using community's identification code using different colours.
S308, it is determined that belonging in each lower single user of same community, user's characteristic information meets the single information of default brush Lower single user number.
S309, when belonging in each lower single user of same community, user's characteristic information meets under the single information of default brush When single user number is more than given threshold, it is abnormal user to determine all lower single users in the community.
Figure network is divided into behind multiple communities by server, and server determines that the user of each lower single user of each community is special Whether reference breath meets the single information of default brush, if user's characteristic information meets alone under the single information of default brush in a community When family number is more than given threshold, directly or indirectly associated because other lower single users in community have, therefore can It is abnormal user with all lower single users determined in the community.
In this programme, the default single information of brush can be set according to actual needs, such as taking out order, Can set the single information of brush as ship-to be residential building region, it is assumed that 2/3 time single user in a community descends take-away to order Single ship-to is A, and server determines that ship-to A is residential building areal geology or Administrative Area geology, if received Address is that A is residential building areal geology, it may be determined that 2/3 time single user and its where community other lower single users for group Body brush single user, naturally it is also possible to determine whether for group's brush single user, such as to place an order the time further combined with other information, if The order time is taken out under 2/3 time single user for non-dining peak period, such as 0. -10 point, 22 points to 24 points, then can be true The other lower single users for determining 2/3 time single user and community where it are group's brush single user, the above is only an example, have Body determines whether lower single user in some community is that the mode of group's brush single user can according to Order Type, brush single act The characteristic feature that can have is determined.
The description of embodiment of the method more than, it is apparent to those skilled in the art that the present invention is real Applying example can add the mode of required general hardware platform to realize by software, naturally it is also possible to by hardware, but many situations It is lower the former be more preferably embodiment.Understood based on such, the technical scheme of the embodiment of the present invention is substantially in other words to existing The part for having technology to contribute can be embodied in the form of software product, and the computer software product is stored in one and deposited In storage media, including some instructions are to cause a computer equipment (can be personal computer, server, or network Equipment etc.) perform all or part of step of each of the invention embodiment methods described.And foregoing storage medium includes:It is read-only Memory (ROM), random access memory (RAM), magnetic disc or CD etc. are various can be with the medium of store program codes.
In addition, as the realization to the various embodiments described above, the embodiment of the present invention additionally provides a kind of abnormal user identification dress Put, the device is located in the server shown in Fig. 1, and Fig. 5 is the structural representation of abnormal user identifying device of the embodiment of the present invention. As shown in figure 5, the device includes:Incidence relation determines list, relational network generation unit 402, community's division unit 403 and exception User's determining unit 404;Wherein:
Incidence relation determining unit 401, for according to History Order data, determining each the lower pass of single user between any two Connection relation;
Relational network generation unit 402, for according to each the described lower incidence relation of single user between any two, generation to be used Family relational network;
Community's division unit 403, for carrying out community's division to the customer relationship network, obtains multiple communities;
Abnormal user determining unit 404, the user behavior feature in the multiple community, determines abnormal user.
In a kind of possible design, the incidence relation determining unit 401, specifically for:
According to History Order data, determine first time single user and second time single user in preset time period Co-occurrence number of times;
Determine identical IP number in the co-occurrence number of times of first time single user and second time single user, phase With ship-to number of times, identical recall address number of times and identical remarks number of times;
According to the co-occurrence number of times of first time single user and second time single user, in the co-occurrence number of times The identical IP number, the identical ship-to number of times, it is described it is identical recall address number of times and the identical remarks number of times, Determine the incidence relation of first time single user and second time single user.
In a kind of possible design, the incidence relation determining unit 401, specifically for:
According to the co-occurrence number of times, described identical IP times for being in advance first time single user and second time single user Several, described identical ship-to number of times, the identical weight for recalling address number of times and the identical remarks number of times distribution, it is determined that The incidence relation of first time single user and second time single user.
In a kind of possible design, the preset time period includes multiple unit intervals, the multiple unit interval Section sum is equal to the preset time period, not overlapping between the multiple period;
The incidence relation determining unit 401, specifically for:
Determine first time single user and second time single user in each unit interval in identical business The number of times that family places an order;
By all unit interval of first time single user and second time single user in the preset time period The number of times sum placed an order in section in identical businessman, is defined as first time single user and second time single user described pre- If the co-occurrence number of times in the period.
In a kind of possible design, unit is deleted, for the relational network generation unit 402 according to described under each After the incidence relation of single user between any two, generation customer relationship network,
Determine lower single user of the incidence relation less than predetermined threshold value in the customer relationship network;
Lower single user by the incidence relation less than predetermined threshold value is deleted from the customer relationship network.
In a kind of possible design, the relational network generation unit 402, be additionally operable to perform the delete step it The customer relationship network afterwards is converted into figure network, in the figure network, and node represents to connect between the user that places an order, node Side represent that there is between lower single user incidence relation.
In a kind of possible design, community's division unit 403, specifically for:
Community's mark is distributed for each lower single user in the figure network, with alone under identical community mark Family belongs to same community.
Collect in the possible design of one kind, the abnormal user determining unit 404, specifically for:
It is determined that belonging in each lower single user of same community, user's characteristic information meets alone under the single information of default brush Family number;
When belonging in each lower single user of same community, user's characteristic information meets the lower single user of the single information of default brush When number is more than given threshold, it is abnormal user to determine all lower single users in the community.
Fig. 6 is a kind of structural representation of server of the embodiment of the present invention.As shown in fig. 6, server includes processor, deposited Reservoir and communication interface.Wherein, processor, memory are connected with communication interface by communication bus;Communication bus 504 can be Peripheral Component Interconnect standard (peripheral component interconnect, abbreviation PCI) bus or extension industrial standard Structure (extended industry standard architecture, abbreviation EISA) bus etc..Communication bus 504 can be with It is divided into address bus, data/address bus, controlling bus etc..For ease of representing, only represented in Fig. 6 with a thick line, it is not intended that Only one bus or a type of bus.
Communication interface 501 is used for from external equipment (for example:The network equipment) transceiving data.For example:The processing of processor 502 Data can be delivered to external equipment through communication interface 502.
Memory 503, for depositing program.Specifically, program can include program code, and program code includes computer Operational order.Memory 503 may include random access memory (random access memory, abbreviation RAM), it is also possible to Also include nonvolatile memory (non-volatile memory), for example, at least one magnetic disk storage.It illustrate only in figure One processor, certainly, processor 503 can also be as needed, is multiple processors.Logistic Scheduling flow in the application can To store in memory.Processor 502 performs the exception in above-described embodiment according to the program code stored in memory 503 The flow of user identification method.
Scheme of the embodiment of the present invention is when applied to the scene for excavating group's brush single user, first according to lower single user two-by-two Between incidence relation generation customer relationship network, and according to complex network community division principle to customer relationship network carry out Community is divided, and obtains multiple communities.There is direct or indirect association between lower single user in each community, different communities May it not associated between user, accordingly, should when single user can be determined to be brush single user under the part in a community Other lower single users in community due to brush single user have it is direct or indirect associate, therefore it is single to be confirmed as brush User, the brush single user being of little use in Shua Dan cliques can be excavated using this mode, so that the group's brush single user obtained It is more accurate comprehensive.
The embodiment of the present invention can be described in the general context of computer executable instructions, example Such as program module.Usually, program module include performing particular task or realize the routine of particular abstract data type, program, Object, component, data structure etc..The embodiment of the present invention can also be put into practice in a distributed computing environment, it is distributed at these In computing environment, task is performed by the remote processing devices connected by communication network.In a distributed computing environment, Program module can be located at including in the local and remote computer-readable storage medium including storage device.
It should be noted that herein, the relational terms of such as " first " and " second " or the like are used merely to one Individual entity or operation make a distinction with another entity or operation, and not necessarily require or imply these entities or operate it Between there is any this actual relation or order.Moreover, term " comprising ", "comprising" or its any other variant are intended to Cover including for nonexcludability, so that process, method, article or equipment including a series of key elements not only include those Key element, but also other key elements including being not expressly set out, or also include for this process, method, article or set Standby intrinsic key element.In the absence of more restrictions, the key element limited by sentence "including a ...", it is not excluded that Also there is other identical element in the process including key element, method, article or equipment.
Those skilled in the art will readily occur to this hair after considering specification and putting into practice inventive embodiments disclosed herein Other embodiments of bright embodiment.Any modification, purposes or the adaptability that the application is intended to the embodiment of the present invention become Change, these modifications, purposes or adaptations follow the general principle of the embodiment of the present invention and including the embodiment of the present invention Undocumented common knowledge or conventional techniques in the art.Description and embodiments be considered only as it is exemplary, The true scope and spirit of the embodiment of the present invention are pointed out by following claim.
It should be appreciated that the accurate knot that the embodiment of the present invention is not limited to be described above and is shown in the drawings Structure, and various modifications and changes can be being carried out without departing from the scope.The scope of the embodiment of the present invention is only by appended right It is required that to limit.

Claims (16)

1. a kind of abnormal user recognition methods, it is characterised in that including:
According to History Order data, each the lower incidence relation of single user between any two is determined;
According to each the described lower incidence relation of single user between any two, customer relationship network is generated;
Community's division is carried out to the customer relationship network, multiple communities are obtained;
User behavior feature in the multiple community, determines abnormal user.
2. according to the method described in claim 1, it is characterised in that described according to History Order data, determine alone under each The incidence relation of first time single user of single user and second time single user under any two in family, including:
According to History Order data, first time single user and second time single user being total in preset time period are determined Occurrence number;
Determine identical IP number in the co-occurrence number of times of first time single user and second time single user, identical receive Goods address number of times, identical recall address number of times and identical remarks number of times;
According to the co-occurrence number of times of first time single user and second time single user, the institute in the co-occurrence number of times State identical IP number, the identical ship-to number of times, it is described it is identical recall address number of times and the identical remarks number of times, it is determined that The incidence relation of first time single user and second time single user.
3. method according to claim 2, it is characterised in that according to alone under first time single user and described second The co-occurrence number of times at family, the identical IP number in the co-occurrence number of times, the identical ship-to number of times, the phase With address number of times and the identical remarks number of times is recalled, the association of first time single user and second time single user is set up Relation, including:
According to be in advance the co-occurrence number of times of first time single user and second time single user, the identical IP number, institute Identical ship-to number of times, the identical weight for recalling address number of times and the identical remarks number of times distribution are stated, it is determined that described The incidence relation of first time single user and second time single user.
4. according to the method in claim 2 or 3, it is characterised in that the preset time period includes multiple unit intervals, The multiple unit interval sum is equal to not overlapping between the preset time period, the multiple unit interval;
The co-occurrence number of times that first time single user and second time single user are determined in preset time period, including:
Determine first time single user and second time single user in each unit interval under identical businessman Single number of times;
By first time single user and second time single user in all unit intervals in the preset time period The number of times sum placed an order in identical businessman, is defined as first time single user and second time single user when described default Between co-occurrence number of times in section.
5. method according to any one of claim 1 to 4, it is characterised in that each lower single user described in the basis After incidence relation between any two, generation customer relationship network, methods described also includes:
Determine lower single user of the incidence relation less than predetermined threshold value in the customer relationship network;
Lower single user by the incidence relation less than predetermined threshold value is deleted from the customer relationship network.
6. method according to claim 5, it is characterised in that the incidence relation is less than to the lower single user of predetermined threshold value After being deleted from the customer relationship network, methods described also includes:
The customer relationship network after the execution delete step is converted into figure network, in the figure network, node Represent that the side connected between lower single user, node represents there is incidence relation between lower single user.
7. method according to claim 6, it is characterised in that described that community's division is carried out to the customer relationship network, Multiple communities are obtained, including:
Community's mark is distributed for each lower single user in the figure network, the lower single user category identified with identical community In same community.
8. according to the method described in claim 1, it is characterised in that the user behavior feature in the multiple community, really Determine abnormal user, including:
It is determined that belonging in each lower single user of same community, user's characteristic information meets the lower single user of the single information of default brush Number;
When belonging in each lower single user of same community, user's characteristic information meets the lower single user number of the single information of default brush During more than given threshold, it is abnormal user to determine all lower single users in the community.
9. a kind of abnormal user identifying device, it is characterised in that including:
Incidence relation determining unit, for according to History Order data, determining each the lower incidence relation of single user between any two;
Relational network generation unit, for according to each the described lower incidence relation of single user between any two, generating customer relationship Network;
Community's division unit, for carrying out community's division to the customer relationship network, obtains multiple communities;
Abnormal user determining unit, for the user behavior feature in the multiple community, determines abnormal user.
10. device according to claim 9, it is characterised in that the incidence relation determining unit, specifically for:
According to History Order data, the co-occurrence number of times of first time single user and second time single user in preset time period is determined;
Determine identical IP number in the co-occurrence number of times of first time single user and second time single user, identical receive Goods address number of times, identical recall address number of times and identical remarks number of times;
According to the co-occurrence number of times of first time single user and second time single user, the institute in the co-occurrence number of times State identical IP number, the identical ship-to number of times, it is described it is identical recall address number of times and the identical remarks number of times, it is determined that The incidence relation of first time single user and second time single user.
11. device according to claim 10, it is characterised in that the incidence relation determining unit, specifically for:
According to be in advance the co-occurrence number of times of first time single user and second time single user, the identical IP number, institute Identical ship-to number of times, the identical weight for recalling address number of times and the identical remarks number of times distribution are stated, it is determined that described The incidence relation of first time single user and second time single user.
12. the device according to claim 10 or 11, it is characterised in that the preset time period includes multiple unit interval Section, the multiple unit interval sum is equal to the preset time period, not overlapping between the multiple period;
The incidence relation determining unit, specifically for:
Determine first time single user and second time single user in each unit interval under identical businessman Single number of times;
By first time single user and second time single user in all unit intervals in the preset time period The number of times sum placed an order in identical businessman, is defined as first time single user and second time single user when described default Between co-occurrence number of times in section.
13. the device according to any one of claim 9 to 12, it is characterised in that unit is deleted, for the network of personal connections After network generation unit each the lower incidence relation of single user between any two, generation customer relationship network according to,
Determine lower single user of the incidence relation less than predetermined threshold value in the customer relationship network;
Lower single user by the incidence relation less than predetermined threshold value is deleted from the customer relationship network.
14. device according to claim 13, it is characterised in that the relational network generation unit, is additionally operable to perform The customer relationship network after the delete step is converted into figure network, and in the figure network, node represents the use that places an order The side connected between family, node represents there is incidence relation between lower single user.
15. device according to claim 14, it is characterised in that community's division unit, specifically for:
Community's mark is distributed for each lower single user in the figure network, the lower single user category identified with identical community In same community.
16. device according to claim 9, it is characterised in that the abnormal user determining unit, specifically for:
It is determined that belonging in each lower single user of same community, user's characteristic information meets the lower single user of the single information of default brush Number;
When belonging in each lower single user of same community, user's characteristic information meets the lower single user number of the single information of default brush During more than given threshold, it is abnormal user to determine all lower single users in the community.
CN201610937572.1A 2016-10-25 2016-10-25 Abnormal user recognition methods and device Pending CN107093090A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201610937572.1A CN107093090A (en) 2016-10-25 2016-10-25 Abnormal user recognition methods and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201610937572.1A CN107093090A (en) 2016-10-25 2016-10-25 Abnormal user recognition methods and device

Publications (1)

Publication Number Publication Date
CN107093090A true CN107093090A (en) 2017-08-25

Family

ID=59649309

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201610937572.1A Pending CN107093090A (en) 2016-10-25 2016-10-25 Abnormal user recognition methods and device

Country Status (1)

Country Link
CN (1) CN107093090A (en)

Cited By (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107454100A (en) * 2017-08-31 2017-12-08 重庆小雨点小额贷款有限公司 Data processing method, device and server
CN107609950A (en) * 2017-09-27 2018-01-19 掌合天下(北京)信息技术有限公司 Order processing method and device
CN107918905A (en) * 2017-11-22 2018-04-17 阿里巴巴集团控股有限公司 Abnormal transaction identification method, apparatus and server
CN108734469A (en) * 2018-03-22 2018-11-02 阿里巴巴集团控股有限公司 The method and apparatus for determining consumer's risk label undetermined
CN108763359A (en) * 2018-05-16 2018-11-06 武汉斗鱼网络科技有限公司 A kind of usage mining method, apparatus and electronic equipment with incidence relation
CN109255632A (en) * 2018-09-03 2019-01-22 武汉斗鱼网络科技有限公司 A kind of user community recognition methods, device, equipment and medium
CN109272319A (en) * 2018-08-14 2019-01-25 阿里巴巴集团控股有限公司 Community's mapping and transaction violation community identification method, device, electronic equipment
CN109271418A (en) * 2018-08-14 2019-01-25 阿里巴巴集团控股有限公司 Suspicious clique's recognition methods, device, equipment and computer readable storage medium
CN109285009A (en) * 2018-08-06 2019-01-29 北京三快在线科技有限公司 It brushes single recognition methods and brushes single identification device
CN109508519A (en) * 2017-09-14 2019-03-22 北京京东尚科信息技术有限公司 Method and apparatus for handling request
CN109697595A (en) * 2017-10-20 2019-04-30 杭州海康威视系统技术有限公司 The recognition methods of cheating attendance data and device, storage medium, computer equipment
CN109886702A (en) * 2017-12-04 2019-06-14 北京京东尚科信息技术有限公司 The method and apparatus of abnormal behaviour in a kind of judgement business activity
CN109902698A (en) * 2017-12-08 2019-06-18 北京京东尚科信息技术有限公司 Information generating method and device
WO2019134307A1 (en) * 2018-01-02 2019-07-11 武汉斗鱼网络科技有限公司 Malicious user identification method and apparatus, and readable storage medium
CN110020662A (en) * 2019-01-09 2019-07-16 阿里巴巴集团控股有限公司 The training method and device of user's disaggregated model
WO2019165697A1 (en) * 2018-02-28 2019-09-06 武汉斗鱼网络科技有限公司 Method and device for identifying click farming users, terminal device and storage medium
CN110428001A (en) * 2019-07-31 2019-11-08 腾讯科技(深圳)有限公司 A kind of community mining method, apparatus, server and storage medium
CN110517104A (en) * 2019-07-18 2019-11-29 阿里巴巴集团控股有限公司 Account association discovery method, apparatus, server and medium
CN110689084A (en) * 2019-09-30 2020-01-14 北京明略软件系统有限公司 Abnormal user identification method and device
CN111209512A (en) * 2020-01-03 2020-05-29 北京同邦卓益科技有限公司 User identification method, device and equipment
CN111476510A (en) * 2020-06-23 2020-07-31 武汉斗鱼鱼乐网络科技有限公司 Method and system for identifying risk user, storage medium and equipment
CN112308352A (en) * 2019-07-30 2021-02-02 阿里巴巴集团控股有限公司 Order identification method and device and electronic equipment
CN112837128A (en) * 2021-02-19 2021-05-25 拉扎斯网络科技(上海)有限公司 Order assignment method and device, computer equipment and computer readable storage medium
CN113111132A (en) * 2020-01-13 2021-07-13 北京沃东天骏信息技术有限公司 Method and device for identifying target user
WO2021159766A1 (en) * 2020-02-11 2021-08-19 腾讯科技(深圳)有限公司 Data identification method and apparatus, and device, and readable storage medium
CN113762684A (en) * 2020-12-14 2021-12-07 北京沃东天骏信息技术有限公司 New user risk assessment method and device, electronic equipment and medium
CN113807862A (en) * 2021-01-29 2021-12-17 北京沃东天骏信息技术有限公司 Access security control method, device, equipment and storage medium
CN113810341A (en) * 2020-06-12 2021-12-17 武汉斗鱼鱼乐网络科技有限公司 Method, system, storage medium and equipment for identifying target network group

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103106616A (en) * 2013-02-27 2013-05-15 中国科学院自动化研究所 Community detection and evolution method based on features of resources integration and information spreading
CN103914493A (en) * 2013-01-09 2014-07-09 北大方正集团有限公司 Method and system for discovering and analyzing microblog user group structure
CN105657659A (en) * 2016-01-29 2016-06-08 北京邮电大学 Method and system for identifying scalping user in taxi service

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103914493A (en) * 2013-01-09 2014-07-09 北大方正集团有限公司 Method and system for discovering and analyzing microblog user group structure
CN103106616A (en) * 2013-02-27 2013-05-15 中国科学院自动化研究所 Community detection and evolution method based on features of resources integration and information spreading
CN105657659A (en) * 2016-01-29 2016-06-08 北京邮电大学 Method and system for identifying scalping user in taxi service

Cited By (38)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107454100A (en) * 2017-08-31 2017-12-08 重庆小雨点小额贷款有限公司 Data processing method, device and server
CN107454100B (en) * 2017-08-31 2019-07-16 重庆小雨点小额贷款有限公司 Data processing method, device and server
CN109508519A (en) * 2017-09-14 2019-03-22 北京京东尚科信息技术有限公司 Method and apparatus for handling request
CN107609950A (en) * 2017-09-27 2018-01-19 掌合天下(北京)信息技术有限公司 Order processing method and device
CN109697595A (en) * 2017-10-20 2019-04-30 杭州海康威视系统技术有限公司 The recognition methods of cheating attendance data and device, storage medium, computer equipment
CN109697595B (en) * 2017-10-20 2020-11-27 杭州海康威视系统技术有限公司 Method and device for identifying attendance data, storage medium and computer equipment
CN107918905B (en) * 2017-11-22 2021-10-15 创新先进技术有限公司 Abnormal transaction identification method and device and server
CN107918905A (en) * 2017-11-22 2018-04-17 阿里巴巴集团控股有限公司 Abnormal transaction identification method, apparatus and server
CN109886702A (en) * 2017-12-04 2019-06-14 北京京东尚科信息技术有限公司 The method and apparatus of abnormal behaviour in a kind of judgement business activity
CN109902698A (en) * 2017-12-08 2019-06-18 北京京东尚科信息技术有限公司 Information generating method and device
WO2019134307A1 (en) * 2018-01-02 2019-07-11 武汉斗鱼网络科技有限公司 Malicious user identification method and apparatus, and readable storage medium
WO2019165697A1 (en) * 2018-02-28 2019-09-06 武汉斗鱼网络科技有限公司 Method and device for identifying click farming users, terminal device and storage medium
CN108734469A (en) * 2018-03-22 2018-11-02 阿里巴巴集团控股有限公司 The method and apparatus for determining consumer's risk label undetermined
CN108763359A (en) * 2018-05-16 2018-11-06 武汉斗鱼网络科技有限公司 A kind of usage mining method, apparatus and electronic equipment with incidence relation
CN109285009A (en) * 2018-08-06 2019-01-29 北京三快在线科技有限公司 It brushes single recognition methods and brushes single identification device
CN109285009B (en) * 2018-08-06 2021-03-02 北京三快在线科技有限公司 Bill brushing identification method and bill brushing identification device
CN109272319B (en) * 2018-08-14 2022-05-31 创新先进技术有限公司 Community mapping and transaction violation community identification method and device, and electronic equipment
CN109271418A (en) * 2018-08-14 2019-01-25 阿里巴巴集团控股有限公司 Suspicious clique's recognition methods, device, equipment and computer readable storage medium
CN109271418B (en) * 2018-08-14 2022-03-04 蚂蚁智安安全技术(上海)有限公司 Suspicious group identification method, device, equipment and computer readable storage medium
CN109272319A (en) * 2018-08-14 2019-01-25 阿里巴巴集团控股有限公司 Community's mapping and transaction violation community identification method, device, electronic equipment
CN109255632A (en) * 2018-09-03 2019-01-22 武汉斗鱼网络科技有限公司 A kind of user community recognition methods, device, equipment and medium
CN110020662A (en) * 2019-01-09 2019-07-16 阿里巴巴集团控股有限公司 The training method and device of user's disaggregated model
CN110517104A (en) * 2019-07-18 2019-11-29 阿里巴巴集团控股有限公司 Account association discovery method, apparatus, server and medium
CN112308352A (en) * 2019-07-30 2021-02-02 阿里巴巴集团控股有限公司 Order identification method and device and electronic equipment
CN110428001B (en) * 2019-07-31 2024-04-05 腾讯科技(深圳)有限公司 Community mining method and device, server and storage medium
CN110428001A (en) * 2019-07-31 2019-11-08 腾讯科技(深圳)有限公司 A kind of community mining method, apparatus, server and storage medium
CN110689084B (en) * 2019-09-30 2022-03-01 北京明略软件系统有限公司 Abnormal user identification method and device
CN110689084A (en) * 2019-09-30 2020-01-14 北京明略软件系统有限公司 Abnormal user identification method and device
CN111209512A (en) * 2020-01-03 2020-05-29 北京同邦卓益科技有限公司 User identification method, device and equipment
CN113111132A (en) * 2020-01-13 2021-07-13 北京沃东天骏信息技术有限公司 Method and device for identifying target user
CN113111132B (en) * 2020-01-13 2024-06-21 北京沃东天骏信息技术有限公司 Method and device for identifying target user
WO2021159766A1 (en) * 2020-02-11 2021-08-19 腾讯科技(深圳)有限公司 Data identification method and apparatus, and device, and readable storage medium
CN113810341A (en) * 2020-06-12 2021-12-17 武汉斗鱼鱼乐网络科技有限公司 Method, system, storage medium and equipment for identifying target network group
CN113810341B (en) * 2020-06-12 2023-08-22 武汉斗鱼鱼乐网络科技有限公司 Method and system for identifying target network group, storage medium and equipment
CN111476510A (en) * 2020-06-23 2020-07-31 武汉斗鱼鱼乐网络科技有限公司 Method and system for identifying risk user, storage medium and equipment
CN113762684A (en) * 2020-12-14 2021-12-07 北京沃东天骏信息技术有限公司 New user risk assessment method and device, electronic equipment and medium
CN113807862A (en) * 2021-01-29 2021-12-17 北京沃东天骏信息技术有限公司 Access security control method, device, equipment and storage medium
CN112837128A (en) * 2021-02-19 2021-05-25 拉扎斯网络科技(上海)有限公司 Order assignment method and device, computer equipment and computer readable storage medium

Similar Documents

Publication Publication Date Title
CN107093090A (en) Abnormal user recognition methods and device
CN103491146B (en) Method, device and system for releasing network information
CN108205766A (en) Information-pushing method, apparatus and system
CN110837917A (en) Customer visit management system, method, terminal equipment and storage medium
US10311449B2 (en) Systems and methods for targeted advertising
CN108416630A (en) A kind of determination method and device of target audience
US11551170B2 (en) Business management system that uses product data with product classes
KR102514471B1 (en) Sales agency service management system
US11481817B2 (en) Systems and methods for multi-platform integration
US20100211530A1 (en) System and method for distributing earnings
US20140278644A1 (en) System and method for controlling the elements of parts and labor costs in a facilities management computing environment
CN111160916A (en) Risk transaction identification method and device
CN107203919B (en) Service information processing method and device
KR102461497B1 (en) Method and server for predicting or recommending construction material for construction process
WO2023043846A1 (en) Computer systems and methods for generating predictive change events
CN115695210A (en) Cloud server deployment method and device, electronic equipment and storage medium
KR20190094091A (en) Method for providing a car rental service
US20150170038A1 (en) Method And System For Generating Item Recommendation
CN113034150B (en) Refund method for unmanned retail terminal
US20190213622A1 (en) Secure and remote dynamic requirements matching
US20220036460A1 (en) Systems and Methods for Asset Analysis
CN110838003B (en) Management system, method, equipment and readable medium for shared office
KR20200065326A (en) Sales management server, method and computer-readable medium storing program for matching with the person in charge
WO2019102699A1 (en) Method for carrying out conversational customer interview and gas appliance sale and payment, computer, and computer-readable storage medium
Cisneros-Cabrera et al. A laddering approach to explore the motivations of taking computer advice for supply networks formation

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information
CB02 Change of applicant information

Address after: Building N3, building 12, No. 27, Jiancai Chengzhong Road, Haidian District, Beijing 100086

Applicant after: Beijing Xingxuan Technology Co.,Ltd.

Address before: 100085 Beijing, Haidian District on the road to the information on the ground floor of the 1 to the 3 floor of the 2 floor, room 11, 202

Applicant before: Beijing Xiaodu Information Technology Co.,Ltd.

RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20170825