CN113032764A - Account registration login service wind control system and service wind control method - Google Patents

Account registration login service wind control system and service wind control method Download PDF

Info

Publication number
CN113032764A
CN113032764A CN202110316922.3A CN202110316922A CN113032764A CN 113032764 A CN113032764 A CN 113032764A CN 202110316922 A CN202110316922 A CN 202110316922A CN 113032764 A CN113032764 A CN 113032764A
Authority
CN
China
Prior art keywords
user
data
login
registration
risk level
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202110316922.3A
Other languages
Chinese (zh)
Inventor
方其云
蔡鹏�
杜威
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Dingxiang Technology Co ltd
Original Assignee
Beijing Dingxiang Technology Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Dingxiang Technology Co ltd filed Critical Beijing Dingxiang Technology Co ltd
Priority to CN202110316922.3A priority Critical patent/CN113032764A/en
Publication of CN113032764A publication Critical patent/CN113032764A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The invention provides a service wind control system and a service wind control method for account registration login, which comprise the following steps: the system comprises a data acquisition module, a decision-making module and a disposal module; the data acquisition module is used for acquiring user operation data of the business wind control system: the user operation data includes: user registration data and user login data; the decision-making module is used for carrying out feature derivation based on user operation data to obtain target feature information; the target feature information includes: registering feature information and logging in the feature information; the decision-making module is also used for judging the risk level of the user operation data based on the target characteristic information; and the processing module is used for returning target result information to the user based on the risk level, wherein the target result information is processing result information corresponding to the risk level. The invention alleviates the technical problem that the wind control system is easy to break through in the prior art.

Description

Account registration login service wind control system and service wind control method
Technical Field
The invention relates to the technical field of wind control systems, in particular to a service wind control system and a service wind control method for account registration and login.
Background
For most products, a user account system is essential, some products have independent account systems, and some are authorized to third parties. However, whether the account system is independent of itself or authorized outside, the risk control of the module is very important. Common risks include account theft: brute force cracking and database collision attacks; malicious number brushing: registering and logging black and gray products in batches; malicious attack: high frequency request attacks result in server crashes.
The existing wind control system is corresponding to a database collision attack, depends on a list database and equipment dimensions during batch registration and batch login risks, and is easy to break through when a scene that terminal equipment cannot be obtained or a black and gray product uses a second-playing IP method/equipment fingerprint cracking technology.
Disclosure of Invention
In view of this, the present invention provides a service wind control system and a service wind control method for account registration and login, so as to alleviate the technical problem that the wind control system is easily broken through in the prior art.
In a first aspect, an embodiment of the present invention provides a service wind control system for account registration and login, including: the system comprises a data acquisition module, a decision-making module and a disposal module; the data acquisition module is used for acquiring user operation data of the business wind control system: the user operation data includes: user registration data and user login data; the decision module is used for carrying out feature derivation based on the user operation data to obtain target feature information; the target feature information includes: registering feature information and logging in the feature information; the decision module is further used for judging the risk level of the user operation data based on the target characteristic information; and the processing module is used for returning target result information to the user based on the risk level, wherein the target result information is processing result information corresponding to the risk level.
Further, the data acquisition module comprises: the system comprises a first data acquisition unit and a second data acquisition unit, wherein the first data acquisition unit is used for acquiring the user registration data; the user registration data includes: the device information of the user in the registration scene and the user information of the user in the registration scene; the second data acquisition unit is used for acquiring the user login data; the user login data comprises: device information of a user in a login scene and user information of the user in the login scene.
Further, the decision module comprises: the system comprises a first decision unit and a second decision unit, wherein the first decision unit is used for performing feature derivation based on the user registration data to obtain registration feature information; the registration feature information includes at least one of: the characteristic field is the same as the IP registration times within a preset time period; the second decision unit is used for performing characteristic derivation based on the user registration data and the user login data to obtain login characteristic information; the login feature information comprises at least one of: characteristic field, registration login time difference, whether the attribution of the registration login IP is consistent or not, and whether the fingerprint of the registration login equipment is consistent or not.
Further, the first decision unit is further configured to: and judging the risk level of the user registration data based on the registration characteristic information.
Further, the risk classes include: a first risk level, a second risk level, and a third risk level; the treatment module further comprises a first treatment unit for: if the risk level of the user registration data is judged to be a first risk level based on the registration characteristic information, returning registration success information; if the risk level of the user registration data is judged to be a second risk level based on the registration characteristic information, returning registration verification information; and if the risk level of the user registration data is judged to be a third risk level based on the registration characteristic information, returning registration failure information.
Further, the second decision unit is further configured to: and judging the risk level of the user login data based on the login characteristic information.
Further, the risk classes include: a first risk level, a second risk level, and a third risk level; the treatment module further comprises a second treatment unit for: if the risk level of the user login data is judged to be a first risk level based on the login characteristic information, login success information is returned; if the risk level of the user login data is judged to be a second risk level based on the login characteristic information, login verification information is returned; and if the risk level of the user login data is judged to be a third risk level based on the login characteristic information, returning login failure information.
Further, the decision module further comprises: an external data interface for accessing external data, the external data comprising: a mobile phone number risk list and an IP risk list.
Further, the decision module is further configured to output a risk label of the user operation data based on the risk level.
In a second aspect, an embodiment of the present invention further provides a service wind control method for account registration login, which is applied to a service wind control system; the method comprises the following steps: acquiring user operation data of the service wind control system: the user operation data includes: user registration data and user login data; performing characteristic derivation based on the user operation data to obtain target characteristic information; the target feature information includes: registering feature information and logging in the feature information; judging the risk level of the user operation data based on the target characteristic information; and returning target result information to the user based on the risk level, wherein the target result information is the processing result information corresponding to the risk level.
The invention provides a service wind control system and a service wind control method for account registration login, which comprise the following steps: the system comprises a data acquisition module, a decision-making module and a disposal module; the data acquisition module is used for acquiring user operation data of the business wind control system: the decision-making module is used for carrying out feature derivation based on user operation data to obtain target feature information; the decision-making module is also used for judging the risk level of the user operation data based on the target characteristic information; and the processing module is used for returning target result information to the user based on the risk level, wherein the target result information is processing result information corresponding to the risk level. According to the invention, the registration data and the login data in the user operation data are subjected to unified feature derivation, so that the precision and the safety of the wind control system are improved, and the technical problem that the wind control system is easy to break through in the prior art is solved.
Drawings
In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly described below, and it is obvious that the drawings in the following description are some embodiments of the present invention, and other drawings can be obtained by those skilled in the art without creative efforts.
Fig. 1 is a schematic diagram of an account registration login service wind control system according to an embodiment of the present invention;
fig. 2 is a schematic diagram of another account registration login service wind control system according to an embodiment of the present invention;
fig. 3 is a schematic diagram of a first data acquisition unit according to an embodiment of the present invention;
fig. 4 is a schematic diagram of a first decision unit according to an embodiment of the present invention;
fig. 5 is a schematic diagram of a second decision unit according to an embodiment of the present invention;
fig. 6 is a schematic diagram of a first handling unit returning target result information to a user according to an embodiment of the present invention;
fig. 7 is a schematic diagram of a second handling unit returning target result information to a user according to an embodiment of the present invention;
fig. 8 is a flowchart of an account registration login service wind control method according to an embodiment of the present invention.
Detailed Description
The technical solutions of the present invention will be described clearly and completely with reference to the accompanying drawings, and it should be understood that the described embodiments are some, but not all embodiments of the present invention. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention.
The first embodiment is as follows:
fig. 1 is a schematic diagram of a service management system for account registration login according to an embodiment of the present invention. As shown in fig. 1, the system includes: a data acquisition module 10, a decision module 20 and a treatment module 30.
Specifically, the data acquisition module 10 is configured to acquire user operation data of the service wind control system: the user operation data includes: user registration data and user login data.
The decision module 20 is configured to perform feature derivation based on user operation data to obtain target feature information; the target feature information includes: registering feature information, and logging in the feature information.
And the decision module 20 is further configured to determine a risk level of the user operation data based on the target characteristic information.
And the handling module 30 is configured to return target result information to the user based on the risk level, where the target result information is processing result information corresponding to the risk level.
The invention provides a business wind control system for account registration and login, which can carry out unified wind control management by opening two scenes of account registration and login, and simultaneously, improves the precision and the safety of a wind control system by carrying out unified characteristic derivation on registration data and login data in user operation data, and relieves the technical problem that the wind control system is easy to break through in the prior art.
Optionally, fig. 2 is a schematic diagram of another service management system for account registration login provided in an embodiment of the present invention. As shown in fig. 2, the data acquisition module 10 includes: a first data acquisition unit 11 and a second data acquisition unit 12. The first data acquisition unit 11 is set in a registration scene of the business wind control system, and the second data acquisition unit 12 is set in a login scene of the business wind control system.
Specifically, the first data acquisition unit 11 is configured to acquire user registration data; the user registration data includes: device information of the user in the registration scenario and user information of the user in the registration scenario.
Fig. 3 is a schematic diagram of a first data acquisition unit provided in accordance with an embodiment of the present invention. As shown in fig. 3, the first data collecting unit 11 collects device information through a device information interface, where the device information collection relates to different terminals, and collected fields also have differences, for example, an application terminal has Android, Ios, Web, and wechat applets, and an Android collection field has an IP address, imei1, imei2, a mac address, and the like; ios acquisition fields comprise IP addresses, idfa, idfv, mac addresses and the like; the Web acquisition field comprises an IP address, ua, resolution, screen window information and the like; the WeChat applet acquisition field comprises an equipment pixel ratio, screen window information, a WeChat version number and the like; then, the device characteristic processing is performed according to the information collected by the device, and the device risk characteristic and the device unique ID are output to the decision module 20. As shown in fig. 3, the first data collecting unit 11 collects user information through a user information interface, where the user information collecting field includes an IP address, a mobile phone number, a mailbox, an openid, an inviter ID, and the like, and then outputs the collected user information to the decision module 20.
The second data acquisition unit 12 is used for acquiring user login data; the user login data comprises: device information of a user in a login scene and user information of the user in the login scene. The related ends of the equipment information acquisition in the login scene are different, and the acquired fields are also different; the application end comprises Android, Ios, Web and WeChat small programs, and the Android acquisition field comprises an IP address, imei1, imei2, mac address and the like; ios acquisition fields comprise IP addresses, idfa, idfv, mac addresses and the like; the Web acquisition field comprises an IP address, ua, resolution, screen window information and the like; the WeChat applet acquisition field comprises an equipment pixel ratio, screen window information, a WeChat version number and the like; processing equipment characteristics according to the information acquired by the equipment, and outputting equipment risk characteristics and an equipment unique ID; the user information acquisition field comprises an IP address, a mobile phone number, an account ID, an account nickname, a mailbox and the like; and after the user information is collected, associating the registration collection information associated with the account ID, such as account registration time, account registration IP, account registration equipment ID and the like, according to the account ID.
In the embodiment of the present invention, the decision module 20 further includes: an external data interface for accessing external data, the external data comprising: a mobile phone number risk list and an IP risk list.
Optionally, as shown in fig. 2, the decision module 20 includes: a first decision unit 21 and a second decision unit 22. The first decision unit 21 is set in a registration scenario of the business wind control system, and the second decision unit 22 is set in a login scenario of the business wind control system.
Specifically, the first decision unit 21 is configured to perform feature derivation based on user registration data to obtain registration feature information; the registration feature information includes at least one of: and the characteristic field is the same as the IP registration times in a preset time period.
Optionally, if the external data needs to be docked in the registration scenario, the first decision unit 21 may develop a corresponding query interface to call the external data, where the external data used in the registration scenario generally relates to a mobile phone number risk list and an IP risk list.
Fig. 4 is a schematic diagram of a first decision unit according to an embodiment of the present invention. As shown in fig. 4, the first decision unit 21 has three functions as follows:
(1) local marking data storage can be used for transmitting offline data and realizing real-time system automatic storage of decision marking data; specifically, as shown in fig. 4, the first decision unit 21 implements storage and access of local data through a local data interface. Storing offline data such as a black mobile phone number and a black IP number marked in history, or classifying mobile phone numbers tested by internal staff into different lists; and (4) real-time storage logic, such as data marked as high risk in decision making, realizes real-time export of the mobile phone number, the IP address and the equipment ID to a local list.
(2) The characteristic derivation comprises the characteristic derivation of the field and the characteristic derivation of the correlation dimension between the fields of the time slice; and (4) carrying out time slice statistics according to the transmission data (namely the user registration data) to obtain the same-IP registration times in a preset time period, such as the near 1-minute same-IP registration times, the near 10-minute same-IP registration times, the near 1-hour same-IP registration times and the like.
(3) The configuration of each logic rule, that is, the decision rule shown in fig. 4, is implemented, for example, whether the registered mobile phone number hits the external mobile phone number risk library or not, whether the IP aggregation registration or not, and whether the device aggregation registration or other abnormal behaviors are determined.
Optionally, the first decision unit 21 is further configured to: the risk level of the user registration data is determined based on the registration characteristic information and then output to the disposal module 30.
The second decision unit 22 is configured to perform feature derivation based on the user registration data and the user login data to obtain login feature information; the login feature information includes at least one of: characteristic field, registration login time difference, whether the attribution of the registration login IP is consistent or not, and whether the fingerprint of the registration login equipment is consistent or not.
Fig. 5 is a schematic diagram of a second decision unit according to an embodiment of the present invention. As shown in fig. 5, if the external data needs to be docked in the login scenario, the second decision unit 22 may develop a corresponding query interface to call the external data, where the external data used in the login scenario generally relates to a mobile phone number risk list and an IP risk list.
In the embodiment of the present invention, the second decision unit 22 performs feature derivation according to external data, local data, and user login data, performs feature derivation according to associated account ID user registration data, and further performs decision rule determination, where the login feature information includes: the method comprises the steps of determining indexes such as registration login time difference, whether registration login IP home areas are consistent or not, whether fingerprints of registration login equipment are consistent or not and the like, and judging abnormal behaviors such as short registration login time difference, mismatching of the registration IP home areas and the login IP home areas, multiple accounts aggregated login with the equipment and the like.
Optionally, the second decision unit 22 is further configured to determine a risk level of the user login data based on the login feature information, and then output the risk level to the disposal module 30.
In an optional implementation manner provided by the embodiment of the present invention, the decision module 20 is further configured to output a risk label of the user operation data based on the risk level. Specifically, the decision module 20 may convert the risk level into a corresponding risk label and then output the risk label to the treatment module 30.
As shown in fig. 2, in the embodiment of the present invention, the treatment module 30 further includes: the system comprises a first handling unit 31 and a second handling unit 32, wherein the first handling unit 31 is arranged in a registration scene of the business wind control system, and the second handling unit 32 is arranged in a login scene of the business wind control system.
Optionally, in an embodiment of the present invention, the risk level includes: a first risk level, a second risk level, and a third risk level; wherein the first risk level represents no risk, the second risk level represents medium risk, and the third risk level represents high risk.
Fig. 6 is a schematic diagram of a first handling unit returning target result information to a user according to an embodiment of the present invention. As shown in fig. 6, the first handling unit 31 is further configured to:
if the risk level of the user registration data is judged to be a first risk level based on the registration characteristic information, returning registration success information;
if the risk level of the user registration data is judged to be a second risk level based on the registration characteristic information, returning registration verification information; for example, a common registration verification method includes a verification code with a man-machine identification function, and the like, and if the verification is successful, the registration is successful, and if the verification is failed, the registration is failed;
and if the risk level of the user registration data is judged to be the third risk level based on the registration characteristic information, returning registration failure information.
Fig. 7 is a schematic diagram of a second handling unit provided according to an embodiment of the present invention, where the second handling unit 32 is further configured to return target result information to a user, as shown in fig. 7:
if the risk level of the user login data is judged to be a first risk level based on the login characteristic information, login success information is returned;
if the risk level of the user login data is judged to be a second risk level based on the login characteristic information, login verification information is returned; specifically, the data aiming at the intermediate risk needs to be subjected to a login verification mode, a plurality of verification modes such as face recognition, sliding verification codes, short message verification codes and the like are commonly verified by real persons, the successful verification returns the login success, and the failed verification returns the login failure;
and if the risk level of the user login data is judged to be the third risk level based on the login characteristic information, returning login failure information.
In the prior art, for the database collision attack, the batch registration and the batch login attack, the basic prevention and control can be carried out by counting the login times of the same IP or the same equipment in unit time, but when the black and gray product uses the technical means to continuously change the login IP and the equipment fingerprint, the rule fails, and the batch login request of the black and gray product cannot be distinguished from the request of a normal client. The account registration and login service wind control system provided by the invention can perform unified characteristic derivation on the registration and login events of the account, and adds the indexes of registration and login time difference, whether the registration and login IP are consistent, whether the registration and login IP are in the same region, whether the registration and login equipment fingerprints are consistent and the like. When the attack happens, the logging quantity of the sleeping accounts which are registered early but are inactive, the logging IP of the sleeping accounts in the non-same area, the non-same equipment, the abnormal logging time and other indexes are abnormal, and the wind control system can be helped to set the abnormal request as medium risk or high risk.
Example two:
fig. 8 is a flowchart of a service management method for account registration login according to an embodiment of the present invention, where the method is applied to the service management system in the first embodiment. As shown in fig. 8, the method specifically includes the following steps:
step S802, user operation data of the business wind control system is obtained; the user operation data includes: user registration data and user login data.
Step S804, performing characteristic derivation based on user operation data to obtain target characteristic information; the target feature information includes: registering feature information, and logging in the feature information.
Optionally, the registration feature information includes at least one of: the characteristic field is the same as the IP registration times within a preset time period; the login feature information includes at least one of: characteristic field, registration login time difference, whether the attribution of the registration login IP is consistent or not, and whether the fingerprint of the registration login equipment is consistent or not.
Step S806, the risk level of the user operation data is determined based on the target feature information.
And step S808, returning target result information to the user based on the risk level, wherein the target result information is the processing result information corresponding to the risk level.
According to the business wind control method for account registration login provided by the embodiment of the invention, the registration data and the login data in the user operation data are subjected to unified feature derivation, so that the precision and the safety of the wind control system are improved, and the technical problem that the wind control system is easy to break through in the prior art is solved.
Finally, it should be noted that: the above embodiments are only used to illustrate the technical solution of the present invention, and not to limit the same; while the invention has been described in detail and with reference to the foregoing embodiments, it will be understood by those skilled in the art that: the technical solutions described in the foregoing embodiments may still be modified, or some or all of the technical features may be equivalently replaced; and the modifications or the substitutions do not make the essence of the corresponding technical solutions depart from the scope of the technical solutions of the embodiments of the present invention.

Claims (10)

1.一种账户注册登录的业务风控系统,其特征在于,包括:数据采集模块,决策模块和处置模块;1. a business risk control system for account registration and login, characterized in that, comprising: a data acquisition module, a decision-making module and a disposal module; 所述数据采集模块,用于获取所述业务风控系统的用户操作数据:所述用户操作数据包括:用户注册数据和用户登录数据;The data collection module is used to obtain user operation data of the business risk control system: the user operation data includes: user registration data and user login data; 所述决策模块,用于基于所述用户操作数据进行特征衍生,得到目标特征信息;所述目标特征信息包括:注册特征信息,登录特征信息;The decision-making module is configured to perform feature derivation based on the user operation data to obtain target feature information; the target feature information includes: registration feature information, login feature information; 所述决策模块,还用于基于所述目标特征信息判断所述用户操作数据的风险等级;The decision-making module is further configured to judge the risk level of the user operation data based on the target feature information; 所述处置模块,用于基于所述风险等级,对用户返回目标结果信息,所述目标结果信息为与所述风险等级相对应的处理结果信息。The processing module is configured to return target result information to the user based on the risk level, where the target result information is processing result information corresponding to the risk level. 2.根据权利要求1所述的系统,其特征在于,所述数据采集模块包括:第一数据采集单元和第二数据采集单元,其中,2. The system according to claim 1, wherein the data collection module comprises: a first data collection unit and a second data collection unit, wherein, 所述第一数据采集单元,用于获取所述用户注册数据;所述用户注册数据包括:用户在注册场景下的设备信息和用户在注册场景下的用户信息;The first data collection unit is configured to acquire the user registration data; the user registration data includes: device information of the user in the registration scenario and user information of the user in the registration scenario; 所述第二数据采集单元,用于获取所述用户登录数据;所述用户登录数据包括:用户在登录场景下的设备信息和用户在登录场景下的用户信息。The second data collection unit is configured to acquire the user login data; the user login data includes: device information of the user in a login scenario and user information of the user in a login scenario. 3.根据权利要求1所述的系统,其特征在于,所述决策模块包括:第一决策单元和第二决策单元,其中,3. The system according to claim 1, wherein the decision-making module comprises: a first decision-making unit and a second decision-making unit, wherein, 所述第一决策单元,用于基于所述用户注册数据进行特征衍生,得到注册特征信息;所述注册特征信息包括以下至少之一:特征字段,在预设时间段内同IP注册次数;The first decision-making unit is configured to perform feature derivation based on the user registration data to obtain registration feature information; the registration feature information includes at least one of the following: a feature field, the number of registrations with the same IP within a preset time period; 所述第二决策单元,用于基于所述用户注册数据和所述用户登录数据进行特征衍生,得到登录特征信息;所述登录特征信息包括以下至少之一:特征字段,注册登录时间差,注册登录IP归属地是否一致,注册登录设备指纹是否一致。The second decision-making unit is configured to perform feature derivation based on the user registration data and the user login data to obtain login feature information; the login feature information includes at least one of the following: a feature field, a registration login time difference, a registration login Whether the IP attribution is the same, and whether the fingerprints of the registered and logged-in devices are the same. 4.根据权利要求3所述的系统,其特征在于,所述第一决策单元,还用于:基于所述注册特征信息判断所述用户注册数据的风险等级。4 . The system according to claim 3 , wherein the first decision unit is further configured to: determine the risk level of the user registration data based on the registration feature information. 5 . 5.根据权利要求4所述的系统,其特征在于,所述风险等级包括:第一风险等级,第二风险等级和第三风险等级;所述处置模块,还包括第一处置单元,用于:5. The system according to claim 4, wherein the risk level comprises: a first risk level, a second risk level and a third risk level; the handling module further comprises a first handling unit for : 若基于所述注册特征信息判断所述用户注册数据的风险等级为第一风险等级,则返回注册成功信息;If it is judged that the risk level of the user registration data is the first risk level based on the registration feature information, the registration success information is returned; 若基于所述注册特征信息判断所述用户注册数据的风险等级为第二风险等级,则返回注册验证信息;If it is judged that the risk level of the user registration data is the second risk level based on the registration feature information, the registration verification information is returned; 若基于所述注册特征信息判断所述用户注册数据的风险等级为第三风险等级,则返回注册失败信息。If it is determined based on the registration feature information that the risk level of the user registration data is the third risk level, registration failure information is returned. 6.根据权利要求3所述的系统,其特征在于,所述第二决策单元,还用于:基于所述登录特征信息判断所述用户登录数据的风险等级。6 . The system according to claim 3 , wherein the second decision unit is further configured to: determine the risk level of the user login data based on the login feature information. 7 . 7.根据权利要求6所述的系统,其特征在于,所述风险等级包括:第一风险等级,第二风险等级和第三风险等级;所述处置模块,还包括第二处置单元,用于:7. The system according to claim 6, wherein the risk level comprises: a first risk level, a second risk level and a third risk level; the handling module further comprises a second handling unit for : 若基于所述登录特征信息判断所述用户登录数据的风险等级为第一风险等级,则返回登录成功信息;If it is determined based on the login feature information that the risk level of the user login data is the first risk level, the login success information is returned; 若基于所述登录特征信息判断所述用户登录数据的风险等级为第二风险等级,则返回登录验证信息;If it is determined based on the login feature information that the risk level of the user login data is the second risk level, the login verification information is returned; 若基于所述登录特征信息判断所述用户登录数据的风险等级为第三风险等级,则返回登录失败信息。If it is determined based on the login feature information that the risk level of the user login data is the third risk level, login failure information is returned. 8.根据权利要求1所述的系统,其特征在于,所述决策模块还包括:外部数据接口,用于接入外部数据,所述外部数据包括:手机号风险名单,IP风险名单。8 . The system according to claim 1 , wherein the decision-making module further comprises: an external data interface for accessing external data, the external data comprising: a mobile phone number risk list and an IP risk list. 9 . 9.根据权利要求1所述的系统,其特征在于,所述决策模块,还用于基于所述风险等级,输出所述用户操作数据的风险标签。9 . The system according to claim 1 , wherein the decision module is further configured to output a risk label of the user operation data based on the risk level. 10 . 10.一种账户注册登录的业务风控方法,应用于业务风控系统;其特征在于,包括:10. A business risk control method for account registration and login, applied to a business risk control system; characterized in that, comprising: 获取所述业务风控系统的用户操作数据:所述用户操作数据包括:用户注册数据和用户登录数据;Obtain user operation data of the business risk control system: the user operation data includes: user registration data and user login data; 基于所述用户操作数据进行特征衍生,得到目标特征信息;所述目标特征信息包括:注册特征信息,登录特征信息;Perform feature derivation based on the user operation data to obtain target feature information; the target feature information includes: registration feature information, login feature information; 基于所述目标特征信息判断所述用户操作数据的风险等级;Determine the risk level of the user operation data based on the target feature information; 基于所述风险等级,对用户返回目标结果信息,所述目标结果信息为与所述风险等级相对应的处理结果信息。Based on the risk level, target result information is returned to the user, where the target result information is processing result information corresponding to the risk level.
CN202110316922.3A 2021-03-24 2021-03-24 Account registration login service wind control system and service wind control method Pending CN113032764A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202110316922.3A CN113032764A (en) 2021-03-24 2021-03-24 Account registration login service wind control system and service wind control method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202110316922.3A CN113032764A (en) 2021-03-24 2021-03-24 Account registration login service wind control system and service wind control method

Publications (1)

Publication Number Publication Date
CN113032764A true CN113032764A (en) 2021-06-25

Family

ID=76473499

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202110316922.3A Pending CN113032764A (en) 2021-03-24 2021-03-24 Account registration login service wind control system and service wind control method

Country Status (1)

Country Link
CN (1) CN113032764A (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113570166A (en) * 2021-09-08 2021-10-29 湖南惠农科技有限公司 Wind control real-time prediction identification method and device
CN113570199A (en) * 2021-06-30 2021-10-29 北京达佳互联信息技术有限公司 Information processing method, electronic resource distribution method, device, electronic device and storage medium
CN114066470A (en) * 2021-11-19 2022-02-18 武汉极意网络科技有限公司 Account risk assessment method based on relational network
CN114140124A (en) * 2021-12-03 2022-03-04 武汉极意网络科技有限公司 An account risk assessment method based on account behavior

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108108973A (en) * 2017-12-01 2018-06-01 北京三快在线科技有限公司 Business risk control method and device
CN108345613A (en) * 2017-01-25 2018-07-31 阿里巴巴集团控股有限公司 A kind of Risk Identification Method and device
CN111125695A (en) * 2019-12-26 2020-05-08 武汉极意网络科技有限公司 Account risk assessment method, device, equipment and storage medium

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108345613A (en) * 2017-01-25 2018-07-31 阿里巴巴集团控股有限公司 A kind of Risk Identification Method and device
CN108108973A (en) * 2017-12-01 2018-06-01 北京三快在线科技有限公司 Business risk control method and device
CN111125695A (en) * 2019-12-26 2020-05-08 武汉极意网络科技有限公司 Account risk assessment method, device, equipment and storage medium

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113570199A (en) * 2021-06-30 2021-10-29 北京达佳互联信息技术有限公司 Information processing method, electronic resource distribution method, device, electronic device and storage medium
CN113570166A (en) * 2021-09-08 2021-10-29 湖南惠农科技有限公司 Wind control real-time prediction identification method and device
CN114066470A (en) * 2021-11-19 2022-02-18 武汉极意网络科技有限公司 Account risk assessment method based on relational network
CN114140124A (en) * 2021-12-03 2022-03-04 武汉极意网络科技有限公司 An account risk assessment method based on account behavior

Similar Documents

Publication Publication Date Title
CN113032764A (en) Account registration login service wind control system and service wind control method
US10505932B2 (en) Method and system for tracking machines on a network using fuzzy GUID technology
US10686829B2 (en) Identifying changes in use of user credentials
EP2748781B1 (en) Multi-factor identity fingerprinting with user behavior
CN108881265B (en) Network attack detection method and system based on artificial intelligence
CN104239758B (en) A kind of man-machine recognition methods and corresponding man-machine identifying system
US10165005B2 (en) System and method providing data-driven user authentication misuse detection
CN112714093A (en) Account abnormity detection method, device and system and storage medium
CN102484640A (en) Threat detection in a data processing system
CN111274046A (en) Service call validity detection method and device, computer equipment and computer storage medium
US20240121244A1 (en) Risk-aware access control system and related methods
CN114154147A (en) Man-machine behavior detection method, system, equipment and medium
CN106817342A (en) Active identity authorization system based on user behavior feature recognition
CN115065512A (en) Account login method, system, device, electronic equipment and storage medium
CN112437034A (en) False terminal detection method and device, storage medium and electronic device
US9754209B1 (en) Managing knowledge-based authentication systems
CN110309473A (en) Merge the anti-brush ticket method and device of identity and voting behavior monitoring
CN111723364A (en) Credential stuffing detection method, device, computer equipment and storage medium
CN109428804A (en) A kind of account management method and device
CN115706669A (en) Network security situation prediction method and system
CN117238070B (en) Household safety control method and system based on intelligent community
KR101576993B1 (en) Method and System for preventing Login ID theft using captcha
Vaidya et al. Intrusion detection system
CN113362514A (en) Interface login method, first device, second device and verification system
CN111339829A (en) User identity authentication method, device, computer equipment and storage medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20210625