WO2016066041A1 - 一种电子凭证传输账号的检测方法及设备 - Google Patents

一种电子凭证传输账号的检测方法及设备 Download PDF

Info

Publication number
WO2016066041A1
WO2016066041A1 PCT/CN2015/092508 CN2015092508W WO2016066041A1 WO 2016066041 A1 WO2016066041 A1 WO 2016066041A1 CN 2015092508 W CN2015092508 W CN 2015092508W WO 2016066041 A1 WO2016066041 A1 WO 2016066041A1
Authority
WO
WIPO (PCT)
Prior art keywords
account
electronic voucher
downstream node
electronic
mode
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/092508
Other languages
English (en)
French (fr)
Inventor
吴东杏
毛仁歆
何慧梅
何帝君
林瑞华
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Publication of WO2016066041A1 publication Critical patent/WO2016066041A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce

Definitions

  • the present application relates to the field of communications technologies, and in particular, to a method for detecting an electronic voucher transmission account.
  • the application also relates to a detection device for an electronic voucher transmission account.
  • the data carrier records the sales information of the merchant in each transaction and the feedback of the user, and displays the merchandise sales information of the merchant and its personal credit information.
  • many buyers have the purchasing psychology of sellers with high sales and good credit. Therefore, some merchants use the speculative letter to improve the credit, that is, they purchase through other normal accounts according to the normal purchase process, and then they are not normal.
  • the present invention provides a method for detecting an electronic voucher transmission account, which is used to solve the technical problem in the prior art that it is difficult to verify an electronic voucher transmission account to confirm whether it has a real problem.
  • the method includes:
  • the account receives an electronic voucher transmitted by the account to be detected;
  • the present application also provides a detection device for an electronic voucher transmission account, including:
  • a querying module configured to query all current secondary accounts corresponding to the account to be detected, and determine a three-party transmission operation corresponding to each of the secondary accounts and the to-be-detected account, and to the secondary account in the three-party transmission operation
  • the intermediate account transmitting the electronic voucher receives the electronic voucher transmitted by the account to be detected;
  • a determining module configured to determine whether a special secondary account exists, and the number of three-party transmission operations existing between the special secondary account and the to-be-detected account is higher than a preset first threshold
  • An extracting module configured to: when the determining module confirms that there is a special secondary account, extract the electronic certificate in the three-party transmission operation according to all three-party transmission operations corresponding to the special secondary account and the to-be-detected account Transfer record
  • An obtaining module configured to obtain the mode information of the number of electronic certificates in the electronic voucher transmission record
  • a determining module configured to determine, according to the number of the three-party transmission operations and the mode information, whether the account to be detected has a problem.
  • the current secondary account corresponding to the account to be detected is queried, and the three-party transmission operation corresponding to each secondary account and the to-be-detected account is determined, and after determining that there is a special secondary account. Extracting the electronic voucher transmission record according to all the current three-party transmission operations corresponding to the special secondary account and the to-be-detected account, and obtaining the number of the three-party transmission operation after acquiring the mode information of the number of the electronic voucher in the electronic voucher transmission record and The mode information determines whether there is a problem with the account to be detected. Therefore, it is possible to accurately verify the detected electronic voucher transmission account in a large number of electronic voucher transaction records, which significantly improves the management convenience of the current electronic voucher transmission.
  • FIG. 1 is a schematic flowchart of a method for detecting an electronic voucher transmission account number according to the present application
  • FIG. 2 is a schematic diagram showing the formation of a capital network in the prior art
  • FIG. 3 is a schematic diagram of a typical rogue network mode in the prior art
  • 4a is a schematic diagram of a three-party transaction mode in the prior art
  • 4b is a schematic diagram of a three-layer capital network in the prior art
  • FIG. 5 is a schematic diagram of reversely identifying a flow of speculative funds in a specific embodiment of the present application.
  • FIG. 6 is a schematic flowchart of constructing a capital network based on BSP in a specific embodiment of the present application
  • 7a is a schematic diagram of a superstep 0 delivery message in a specific embodiment of the present application.
  • 7b is a schematic diagram of a superstep 1 delivery message in a specific embodiment of the present application.
  • 7c is a schematic diagram of a superstep 3 delivery message in a specific embodiment of the present application.
  • FIG. 8 is a schematic structural diagram of a device for detecting an electronic voucher transmission account number according to the present application.
  • the capital flow mode of the speculative behavior is a very obvious three-party transaction mode of strong remittance + strong remittance, but due to the huge amount of data, it is impossible to effectively find such a mode only through stand-alone search. Therefore, the present application accurately locates the speculative network with abnormal mode by using the message passing mechanism, and finally selects the abnormal account and further recognizes the credit behavior of the account.
  • a method for detecting an electronic voucher transmission account number proposed by the present application includes the following steps:
  • S102 Query all current secondary accounts corresponding to the account to be detected, and determine a three-party transmission operation corresponding to each of the secondary accounts and the to-be-detected account, and transmit the electronic credentials to the secondary account in the three-party transmission operation.
  • the intermediate account receives the electronic voucher transmitted by the account to be detected.
  • the step may be specifically implemented by the following process. It should be noted that other embodiments having the same implementation effects as the following processes are also covered by the present application:
  • the downstream node determines whether there is still a second downstream node that has received the electronic voucher sent by itself, and when the judgment result is yes, according to the Transmitting, by the first electronic voucher flow information, second electronic voucher flow information to the second downstream node, where the second electronic voucher flow information includes at least an account of the originating node, an account of the first downstream node, and a The account number of the second downstream node;
  • the downstream node when the downstream node receives the second electronic voucher flow information, the downstream node root Generating, according to the second electronic voucher flow information, a three-party transmission operation with the start node, the first downstream node, and the second downstream node, where an account of the first downstream node is the three-party transmission operation In the intermediate account, the account of the second downstream node is a secondary account in the three-party transmission operation.
  • the first electronic voucher flow information further includes a first electronic voucher number, and the first electronic voucher number is sent by the starting node to the first The number of electronic voucher of the downstream node;
  • the second electronic voucher flow information further includes a quantity of the first electronic voucher and a quantity of the second electronic voucher, wherein the quantity of the second electronic voucher is sent by the first downstream node to the The number of second electronic credentials of the two downstream nodes.
  • S102 Determine whether there is a special secondary account, and the number of the three-party transmission operations existing between the special secondary account and the to-be-detected account is higher than a preset first threshold.
  • the electronic voucher transmission record needs to be divided before the specific analysis. And a second electronic voucher transmission record between the account to be detected and the intermediate account and a second electronic voucher transmission record between the intermediate account and the special secondary account.
  • the mode of the number of electronic voucher in the first electronic voucher transmission record may be used as the first mode, and the mode of the number of electronic voucher in the second electronic voucher transmission record as the second mode And determining a first ratio of the first mode in the number of electronic voucher records recorded by the first electronic voucher, and determining an electronic voucher number of the second voucher in the second electronic voucher transmission record a second ratio; the first mode, the second mode, the first ratio, and the second ratio are finally used as the mode information.
  • S105 Determine, according to the number of the three-party transmission operations and the mode information, whether the account to be detected has a problem.
  • whether the account to be detected has a problem may be determined according to the following manner:
  • the technical solution of the present application will be described in conjunction with a specific application scenario.
  • the account to be detected in the above embodiment is a merchant account having a suspected speculation in a specific implementation scenario
  • the intermediate account is a trumpet used by the merchant to transfer the account
  • the secondary account is It is the size of the merchant used to speculate.
  • a complicated capital network is constructed to represent a fund transaction relationship between accounts, and the capital flow characteristics of the local network are used to accurately find an abnormal credit network and an account with abnormal transactions, so as to facilitate Identify the anti-profit business after the occurrence of the speculative activity.
  • FIG. 2 a schematic diagram of the existing capital network is formed.
  • it is often a complex directed network diagram based on capital flow constructed based on the flow of funds of all accounts in the past period of time.
  • the complete speculation cheating must be carried in a capital transaction chain involving large, small, and merchants, it can be seen that the capital chain is the carrier for completing the transfer of speculative funds, so the flow of funds can be used to construct the speculative funds.
  • the internet The internet.
  • FIG. 3 it is a schematic diagram of the existing typical rogue network model.
  • the funds of the speculative fund network will have the characteristics of strong remittance and strong remittance. There will be a large number of different transactions between the corresponding first and last network nodes. No.
  • the fund characteristics of the local network of the credit fund are also different from the normal fund network. Therefore, the specific embodiment of the present application identifies the cheating behavior of the credit by constructing a three-layer fund network as shown in FIG. 4a.
  • the capital flow characteristics of the network are abnormally different from the capital characteristics of the normal three-tier fund network.
  • all connectable three-tier funds network there will be two funds flow amount and the amount of money in the remittance part and the remittance part.
  • the ratio of the amount of the two stages in the normal capital network will be very low, and the proportion of the amount of money and the amount of money in the speculative fund network will be significantly higher than the normal capital network, as shown in Figure 4b.
  • the application selects the flow of funds of all accounts in the past period of time to construct a network of funds to identify as many cheating acts as possible, which involves hundreds of millions of funds transactions.
  • the corresponding fund network will have tens of millions of nodes and hundreds of millions of edges. If all the connectable three-tier funds are calculated, there will be a data explosion problem.
  • this application adopts the message delivery model shown in Figure 5 to construct the capital network, and reversely considers the direction of the flow of speculative funds when calculating the identification of the credit network, thereby improving the speculative network. Identification efficiency.
  • a start node trigger message delivery mechanism is required. If you directly mine the potential speculative network according to the flow direction of the actual speculative funds, “Large->Small->Business”, all nodes need to send messages at the initial stage, because the accounts corresponding to any one node have May be a speculative large size. Conversely, if you reversely consider the flow of speculative funds, starting from the merchant node to find a potential network of speculative funds, the amount of messages sent by the network will be greatly reduced, and the calculation efficiency is higher, because there is a transaction function in all accounts. Accounts only account for a small percentage.
  • the merchant suspected of cheating is first marked as the starting node, and the starting node triggers the BSP message delivery mechanism.
  • the message will contain the information of the flow of funds. If it is a two-party transaction, the format of the message is “[id1, amt, id2]”, corresponding to the fund outflow party, the transaction amount, and the capital inflow party. If it is a three-party transaction, the message format is “[id1, amt1, id2, amt2, id3]”, which corresponds to the capital outflow party of the first transaction fund flow, the transaction amount, and the capital inflow party of the first capital flow. The transaction amount of the second capital flow and the capital inflow of the second capital flow.
  • the starting node will pass the transaction information contained in the outgoing edge to the corresponding downstream node.
  • a, b, g are the starting nodes, but g has no outgoing and downstream nodes, so only nodes a and b will pass messages to downstream nodes c and d.
  • the content of the message a is sent to c is "[a,200,c]”
  • the content of the message delivered by a to d is "[a,200,d]”
  • the content of the message delivered by b to d is "[b,300 , d]”.
  • Node c receives 1 message "[a,200,c]". Since there is a downstream node e, it can constitute a three-party transaction, so c will send the message "[a,200,c,400,e]" to node e. .
  • Node d receives 2 messages "[a,200,d]” and "[b,300,d]", and has a downstream node e, so d will send 2 messages "[a,200,d,200 , e]" and "[b, 300, d, 200, e]" are given to node e, as shown in Figure 7b.
  • the BSP message passing mechanism can be used to quickly find all connectable three-layer trading networks, and the number of intermediate nodes, the amount of remittances, and the total amount of remittances are based on the network. Compared with the ratio of the amount of remittance and the sum of the remittances, the ratio of the number of remittances can identify the network of speculative funds, so as to accurately locate the speculative large, speculative trumpet and speculative merchants.
  • the present application also provides a detection device for an electronic voucher transmission account, as shown in FIG. 8, including:
  • the querying module 810 is configured to query all current secondary accounts corresponding to the to-be-detected accounts, and determine a three-party transmission operation corresponding to each of the secondary accounts and the to-be-detected accounts, and perform the third-level transmission operation in the three-party transmission operation.
  • the intermediate account of the account transmission electronic voucher receives the electronic voucher transmitted by the account to be detected;
  • the determining module 820 is configured to determine whether there is a special secondary account, and the number of the three-party transmission operations existing between the special secondary account and the to-be-detected account is higher than a preset first threshold;
  • the extracting module 830 is configured to: when the determining module confirms that there is a special secondary account, extract the electronic in the three-party transmission operation according to all current three-party transmission operations corresponding to the special secondary account and the to-be-detected account Voucher transmission record
  • the obtaining module 840 is configured to obtain the mode information of the number of electronic certificates in the electronic voucher transmission record
  • the determining module 850 is configured to determine, according to the number of the three-party transmission operations and the mode information, whether the account to be detected has a problem.
  • the acquiring module specifically includes:
  • a dividing sub-module configured to divide the electronic voucher transmission record into a first electronic voucher transmission record between the to-be-detected account and the intermediate account, and a first between the intermediate account and the special secondary account Two electronic voucher transmission records;
  • a mode obtaining submodule configured to use a mode of the number of electronic voucher in the first electronic voucher transmission record as a first mode, and a mode of the number of electronic voucher in the second electronic voucher transmission record as a second Moderate
  • a ratio acquisition submodule configured to determine a first proportion of the first plurality of electronic voucher records in the first electronic voucher transmission record to determine the second mode in the second electronic voucher The second percentage of the number of electronic voucher records recorded;
  • the determining module is specifically configured to determine a ratio of the first mode to the second mode, and the number of the three-party transmission operations is greater than a preset second threshold, and When the first ratio and the second ratio are both greater than a preset percentage threshold, and the ratio is less than or equal to a preset threshold ratio, the second account is determined to be in a problem.
  • the threshold is greater than or equal to the first threshold.
  • the query module specifically includes:
  • a setting sub-module configured to set the to-be-detected account as a starting node, and set an account other than the to-be-detected account as a downstream node;
  • a sending submodule configured to send first electronic credential flow information to a first downstream node that receives an electronic credential sent by the originating node, where the first electronic credential flow information includes at least an account number and a location of the originating node Describe the account number of the first downstream node;
  • a first output submodule configured to: when the downstream node receives the first electronic voucher flow information, determine whether the downstream node further has a second downstream node that receives an electronic voucher sent by itself, and determines When the result is YES, the second electronic credential flow information is sent to the second downstream node according to the first electronic voucher flow information, where the second electronic voucher flow information includes at least an account of the originating node, the first An account of the downstream node and an account of the second downstream node;
  • a second output submodule configured to: when the downstream node receives the second electronic voucher flow information, instruct the downstream node to generate, according to the second electronic voucher flow information, the starting node, the first a three-party transmission operation of the downstream node and the second downstream node, wherein an account of the first downstream node is an intermediate account in the three-party transmission operation, and an account of the second downstream node is in the three-party transmission operation Secondary account number.
  • the first electronic voucher flow information further includes a first electronic voucher number, the first electronic voucher The number is the number of electronic credentials sent by the originating node to the first downstream node;
  • the second electronic voucher flow information further includes a first electronic voucher number and a second electronic voucher number, wherein the second electronic voucher number is a second electronic voucher sent by the first downstream node to the second downstream node quantity.
  • the present application can be implemented by hardware, or by software plus a necessary general hardware platform.
  • the technical solution of the present application may be embodied in the form of a software product, which may be stored in a non-volatile storage medium (which may be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including several The instructions are for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform the methods described in various implementation scenarios of the present application.
  • modules in the apparatus in the implementation scenario may be distributed in the apparatus for implementing the scenario according to the implementation scenario description, or may be correspondingly changed in one or more devices different from the implementation scenario.
  • the modules of the above implementation scenarios may be combined into one module, or may be further split into multiple sub-modules.

Landscapes

  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Finance (AREA)
  • Marketing (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Telephonic Communication Services (AREA)

Abstract

一种电子凭证传输账号的检测方法。该方法通过查询当前所有与待检测账号对应的二级账号及确定与各二级账号及待检测账号对应的三方传输操作,并在判断存在特殊二级账号之后根据当前所有与该特殊二级账号以及待检测账号对应的三方传输操作提取其中的电子凭证传输记录,在获取了电子凭证传输记录中的电子凭证数量的众数信息后根据三方传输操作的数量以及众数信息确定待检测账号是否存在问题。从而在海量的电子凭证交易记录中能够精确地对待检测的电子凭证传输账号进行验证,显著地提升了当前电子凭证传输的管理便捷性。

Description

一种电子凭证传输账号的检测方法及设备 技术领域
本申请涉及通信技术领域,特别涉及一种电子凭证传输账号的检测方法。本申请同时还涉及一种电子凭证传输账号的检测设备。
背景技术
随着科学技术的不断发展,网络购物越来越成为人们生活中所不可或缺的重要部分。用户通过数据运营商的网络平台向商家订购商品,商家将商品发给用户,这样即完成了一次网络购物的过程。
为了使用户的个人权益能够得到保障,数据运营商会记录商家在每一次交易的销售信息以及用户的反馈,并将该商家的商品销售信息及其个人信用信息进行展示。出于保障的考虑,很多买家都有选择销量高、信用好的卖家的购买心理,因此有的商家利用炒信来提升信用度,即通过自身的其他账号按正常的购买流程购买,然后不正常发货,以抬高信用为目的,或双方在无实际成交的情况下做出正面评价,这种通过不正当方式提高账户信用积分或商品销量的行为不仅妨害了买家高效真实的购物权益,同时也扰乱了网络交易平台卖家公平竞争的市场秩序。
然而,鉴于目前网络交易中庞大的用户群和海量的交易数据,资金流所构建的资金网络会非常复杂和庞大,如何从中发现有炒信行为的账号具有非常大的困难,而且现在许多专业的炒信作弊团队已经能够绕过注册Email、交易IP和交易MAC等前置规则的判断,利用大量的交易操作将炒信行为做得更加隐蔽。因此,如何快速地对具有炒信行为的账号进行检测以确认其是否真正存在炒信行为,成为数据运营商当下亟待解决的问题。
发明内容
本申请提出了一种电子凭证传输账号的检测方法,用以解决现有技术中难以对电子凭证传输账号进行验证以确认其是否真正存在问题的技术问题,该方法包括:
查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,在所述三方传输操作中向二级账号传输电子凭证的中间账号接收由所述待检测账号传输的电子凭证;
判断是否存在特殊二级账号,所述特殊二级账号与所述待检测账号之间所存在的三方传输操作的数量高于预设的第一阈值;
若存在,根据当前所有与所述特殊二级账号以及所述待检测账号对应的三方传输操作,提取所述三方传输操作中的电子凭证传输记录;
获取所述电子凭证传输记录中的电子凭证数量的众数信息;
根据所述三方传输操作的数量以及所述众数信息确定所述待检测账号是否存在问题。
相应地,本申请还提出了一种电子凭证传输账号的检测设备,包括:
查询模块,用于查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,在所述三方传输操作中向二级账号传输电子凭证的中间账号接收由所述待检测账号传输的电子凭证;
判断模块,用于判断是否存在特殊二级账号,所述特殊二级账号与所述待检测账号之间所存在的三方传输操作的数量高于预设的第一阈值;
提取模块,用于在所述判断模块确认存在特殊二级账号时,根据当前所有与所述特殊二级账号以及所述待检测账号对应的三方传输操作,提取所述三方传输操作中的电子凭证传输记录
获取模块,用于获取所述电子凭证传输记录中的电子凭证数量的众数信息;
确定模块,用于根据所述三方传输操作的数量以及所述众数信息确定所述待检测账号是否存在问题。
由此可见,通过应用本发明的技术方案,查询当前所有与待检测账号对应的二级账号及确定与各二级账号及待检测账号对应的三方传输操作,并在判断存在特殊二级账号之后根据当前所有与该特殊二级账号以及待检测账号对应的三方传输操作提取其中的电子凭证传输记录,在获取了电子凭证传输记录中的电子凭证数量的众数信息后根据三方传输操作的数量以及众数信息确定待检测账号是否存在问题。从而在海量的电子凭证交易记录中能够精确地对待检测的电子凭证传输账号进行验证,显著地提升了当前电子凭证传输的管理便捷性。
附图说明
图1为本申请提出的一种电子凭证传输账号的检测方法流程示意图;
图2为现有技术中资金网络形成示意图;
图3为现有技术中典型的炒信网络模式示意图;
图4a为现有技术中三方交易模式示意图;
图4b为现有技术中三层资金网络示意图;
图5为本申请具体实施例中逆向识别炒信资金流的示意图;
图6为本申请具体实施例中基于BSP构建资金网络的流程示意图;
图7a为本申请具体实施例中superstep 0传递消息示意图;
图7b为本申请具体实施例中superstep 1传递消息示意图;
图7c为本申请具体实施例中superstep 3传递消息示意图;
图8为本申请提出的一种电子凭证传输账号的检测设备的结构示意图。
具体实施方式
如背景技术所述,炒信行为的资金流模式为非常明显的强汇出+强汇入的三方交易模式,但由于数据量的庞大性,仅通过单机搜索已经无法有效的寻找出这样的模式,因此本申请通过利用消息传递机制精准定位出有异常模式的炒信网络,最终选取其中异常的账号进而识别账号的炒信行为。
如图1所示,为本申请提出的一种电子凭证传输账号的检测方法,包括如下步骤:
S102,查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,在所述三方传输操作中向二级账号传输电子凭证的中间账号接收由所述待检测账号传输的电子凭证。
在优选的实施例中,该步骤可具体通过以下流程实现,在此需要说明的是,与以下流程具有相同实现效果的其他实施方式,也属于本申请的保护范围:
A.将所述待检测账号设置为起始节点,以及将除所述待检测账号以外的其他账号设为下游节点;
B.向接收过所述起始节点发送的电子凭证的第一下游节点发送第一电子凭证流信息,所述第一电子凭证流信息至少包括所述起始节点的账号以及所述第一下游节点的账号;
C.当所述下游节点接收到所述第一电子凭证流信息时,所述下游节点判断是否还存在接收过由自身发送的电子凭证的第二下游节点,并在判断结果为是时根据所述第一电子凭证流信息向所述第二下游节点发送第二电子凭证流信息,所述第二电子凭证流信息至少包括所述起始节点的账号、所述第一下游节点的账号以及所述第二下游节点的账号;
D.当所述下游节点接收到所述第二电子凭证流信息时,所述下游节点根 据所述第二电子凭证流信息生成与所述起始节点、所述第一下游节点以及所述第二下游节点的三方传输操作,其中所述第一下游节点的账号为所述三方传输操作中的中间账号,所述第二下游节点的账号为所述三方传输操作中的二级账号。
为了便于同时获取电子凭证的数量,在上述过程中,所述第一电子凭证流信息还包括第一电子凭证数量,所述第一电子凭证数量为由所述起始节点发送给所述第一下游节点的电子凭证的数量;所述第二电子凭证流信息还包括第一电子凭证数量以及第二电子凭证数量,所述第二电子凭证数量为由所述第一下游节点发送给所述第二下游节点的第二电子凭证的数量。
S102,判断是否存在特殊二级账号,所述特殊二级账号与所述待检测账号之间所存在的三方传输操作的数量高于预设的第一阈值。
S103,若存在,根据当前所有与所述特殊二级账号以及所述待检测账号对应的三方传输操作,提取所述三方传输操作中的电子凭证传输记录。
S104,获取所述电子凭证传输记录中的电子凭证数量的众数信息。
由于三方传输操作中同时存在待检测账号与中间账号之间的电子凭证传输,以及中间账号与特殊二级账号之间的电子凭证传输,因此在具体分析之前,需要将所述电子凭证传输记录划分为所述待检测账号与所述中间账号之间的第一电子凭证传输记录以及所述中间账号与所述特殊二级账号之间的第二电子凭证传输记录。
在划分之后,即可将所述第一电子凭证传输记录中电子凭证数量的众数作为第一众数,以及将所述第二电子凭证传输记录中电子凭证数量的众数作为第二众数;并确定所述第一众数在所述第一电子凭证传输记录的电子凭证数量中的第一占比,以及确定所述第二众数在所述第二电子凭证传输记录的电子凭证数量中的第二占比;最终将所述第一众数、所述第二众数、所述第一占比、所述第二占比作为所述众数信息。
S105,根据所述三方传输操作的数量以及所述众数信息确定所述待检测账号是否存在问题。
基于S104所得到的众数信息以及三方传输操作的数量,在优选的实施方式中,可以通过以下方式根据确定所述待检测账号是否存在问题:
A.确定所述第一众数与所述第二众数的比值;
B.若所述三方传输操作的数量大于预设的第二阈值,且所述第一占比、所述第二占比均大于预设的占比阈值,且所述比值小于或等于预设的出入比阈值,则确认所述待检测账号存在问题,所述第二阈值大于或等于所述第一阈值。
需要说明的是,以上方式仅为本申请优选实施例所提出的一种实现方案,本领域技术人员可基于众数信息以及三方传输操作的数量利用其它方式来对待检测账号进行验证,这些都属于本发明的保护范围。
为了进一步阐述本申请的技术思想,现结合具体的应用场景,对本申请的技术方案进行说明。由于电子凭证通常是以资金的形式出现,因此以上的实施例中的待检测账号为具体实施场景中具有炒信嫌疑的商家账号,中间账号则是商家用以转账的小号,而二级账号则是商家用来炒信的大号。在本申请的具体实施例中,通过构造复杂的资金网络来表示账号间的资金交易关系,并利用局部网络的资金流特点精准地找出异常的炒信网络和有异常交易的账号,以便于在炒信活动发生后识别打击炒信商家。
如图2所示,为现有资金网络形成简略示意图,它在实际情况下往往是根据所有账号在过去一段时间的资金流情况所构建的基于资金流动的复杂有向网络图。根据完整的炒信作弊行为必须承载于一笔涉及大号、小号、商家的资金交易链中可以看出,资金链是完成炒信资金转移的载体,因此利用资金的流动可以构建炒信资金网络。
如图3所示,为现有的典型炒信网络模式示意图,炒信资金网络的资金会具有强汇出、强汇入的特点,对应的首、尾网络节点中间会存在大量不同的交易小号,炒信资金网络局部的资金特点也不同于正常的资金网络,因此本申请具体实施例通过构建如图4a所示的三层的资金网络中来识别炒信作弊行为。
在图4b所示的炒信资金网络中,网络的资金流特点是异常于正常的三层资金网络的资金特点的。在所有可连接的三层资金网络中,汇出部分和汇入部分会存在两个资金流金额众数及金额众数占比。正常的资金网络中两个阶段的金额众数占比会很低,而炒信资金网络的金额众数和金额众数占比会明显高于正常的资金网络,如图4b所示。
基于以上内容,在具体实施例中,本申请会选取所有账号在过去一段时间的资金流动情况来构建资金网络以尽可能的识别更多的炒信作弊行为,其中涉及到了上亿笔的资金交易,对应的资金网络会有上千万个节点和上亿条边,如果计算所有可连接的三层资金网络则会出现数据爆炸问题。为了解决海量数据和资金网络庞大的难题,本申请采取如图5所示的消息传递模型来构建资金网络,并且在计算识别炒信网络时逆向考虑炒信资金流的方向,从而提高炒信网络的识别效率。
在图5所示的利用BSP消息传递机制实现三层资金网络的构建时,需要有起始节点触发消息传递机制。如果直接根据实际炒信资金的流动方向“大号->小号->商家”来挖掘潜在的炒信网络,则起始阶段需要所有的节点都发送消息,因为任何一个节点对应的账号都有可能是炒信大号。反过来如果逆向考虑炒信资金的流动,从商家节点出发去寻找潜在的炒信资金网络,网络发送的消息量会大幅减少,计算效率更高,因为在所有的账号中是有商家交易功能的账号只占很少的一部分。
具体的,资金网络的建立流程如图6所示,相应过程如下:
在利用BSP初始化资金网络的过程中,首先将有作弊嫌疑的商家标记为起始节点,由起始节点来触发BSP消息传递机制。消息中会包含资金流的信息,如果是一笔两方交易,消息的格式为“[id1,amt,id2]”,分别对应资金流出方、交易金额、资金流入方。如果是一笔三方交易,消息格式为“[id1,amt1,id2,amt2,id3]”,分别对应第一笔交易资金流的资金流出方、交易金额、第一笔资金流的资金流入方、第二笔资金流的交易金额、第二笔资金流的资金流入方。下面是消息传递示例:
A.1)在第0个superstep,起始节点会将出边所包含的交易信息传递给对应的下游节点。如图7a所示,a、b、g是起始节点,但g没有出边和下游节点,所以只有节点a和b会传递消息给下游节点c和d。其中a给c传递的消息内容为“[a,200,c]”,a给d传递的消息内容为“[a,200,d]”,b给d传递的消息内容为“[b,300,d]”。
B.在第1个superstep,只有节点c和d会收到消息。节点c收到1条消息“[a,200,c]”,由于有下游节点e,可构成三方交易,因此c将会发送消息“[a,200,c,400,e]”给节点e。节点d收到2条消息“[a,200,d]”和“[b,300,d]”,并且有下游节点e,所以d将会发送2条消息“[a,200,d,200,e]”和“[b,300,d,200,e]”给节点e,如图7b所示。
C.在第2个superstep,只有节点e有收到消息,节点e收到了3条消息“[a,200,c,400,e]”、“[a,200,d,200,e]”和“[b,300,d,200,e]”。此时消息传递机制结束,节点e会输出这3条消息所涉及的三方交易内容,如图7c所示。
通过对节点输出的消息进行分析,可以利用BSP消息传递机制可以快速地找出所有可连接的三层交易网络,而根据网络的中间节点个数、汇出金额众数、汇出金额众数占比、汇入金额众数和汇出金额众数比值共4个特征就可以识别炒信资金网络,从而精准定位炒信大号、炒信小号和炒信商户。
为达到以上技术目的,本申请还提出了一种电子凭证传输账号的检测设备,如图8所示,包括:
查询模块810,用于查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,在所述三方传输操作中向二级账号传输电子凭证的中间账号接收由所述待检测账号传输的电子凭证;
判断模块820,用于判断是否存在特殊二级账号,所述特殊二级账号与所述待检测账号之间所存在的三方传输操作的数量高于预设的第一阈值;
提取模块830,用于在所述判断模块确认存在特殊二级账号时,根据当前所有与所述特殊二级账号以及所述待检测账号对应的三方传输操作,提取所述三方传输操作中的电子凭证传输记录
获取模块840,用于获取所述电子凭证传输记录中的电子凭证数量的众数信息;
确定模块850,用于根据所述三方传输操作的数量以及所述众数信息确定所述待检测账号是否存在问题。
在具体的应用场景中,所述获取模块具体包括:
划分子模块,用于将所述电子凭证传输记录划分为所述待检测账号与所述中间账号之间的第一电子凭证传输记录以及所述中间账号与所述特殊二级账号之间的第二电子凭证传输记录;
众数获取子模块,用于将所述第一电子凭证传输记录中电子凭证数量的众数作为第一众数,以及将所述第二电子凭证传输记录中电子凭证数量的众数作为第二众数;
占比获取子模块,用于确定所述第一众数在所述第一电子凭证传输记录的电子凭证数量中的第一占比,以确定所述第二众数在所述第二电子凭证传输记录的电子凭证数量中的第二占比;
生成子模块,用于将所述第一众数、所述第二众数、所述第一占比、所述第二占比作为所述众数信息。
在具体的应用场景中,所述确定模块,具体用于确定所述第一众数与所述第二众数的比值,并在所述三方传输操作的数量大于预设的第二阈值,且所述第一占比、所述第二占比均大于预设的占比阈值,且所述比值小于或等于预设的出入比阈值时,确认所述待检测账号存在问题,所述第二阈值大于或等于所述第一阈值。
在具体的应用场景中,所述查询模块,具体包括:
设置子模块,用于将所述待检测账号设置为起始节点,以及将除所述待检测账号以外的其他账号设为下游节点;
发送子模块,用于向接收过所述起始节点发送的电子凭证的第一下游节点发送第一电子凭证流信息,所述第一电子凭证流信息至少包括所述起始节点的账号以及所述第一下游节点的账号;
第一输出子模块,用于在所述下游节点接收到所述第一电子凭证流信息时,判断所述下游节点是否还存在接收过由自身发送的电子凭证的第二下游节点,并在判断结果为是时根据所述第一电子凭证流信息向所述第二下游节点发送第二电子凭证流信息,所述第二电子凭证流信息至少包括所述起始节点的账号、所述第一下游节点的账号以及所述第二下游节点的账号;
第二输出子模块,用于在所述下游节点接收到所述第二电子凭证流信息时,指示所述下游节点根据所述第二电子凭证流信息生成与所述起始节点、所述第一下游节点以及所述第二下游节点的三方传输操作,其中所述第一下游节点的账号为所述三方传输操作中的中间账号,所述第二下游节点的账号为所述三方传输操作中的二级账号。
在具体的应用场景中,还包括:
所述第一电子凭证流信息还包括第一电子凭证数量,所述第一电子凭证 数量为由所述起始节点发送给所述第一下游节点的电子凭证的数量;
所述第二电子凭证流信息还包括第一电子凭证数量以及第二电子凭证数量,所述第二电子凭证数量为由所述第一下游节点发送给所述第二下游节点的第二电子凭证的数量。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到本申请可以通过硬件实现,也可以借助软件加必要的通用硬件平台的方式来实现。基于这样的理解,本申请的技术方案可以以软件产品的形式体现出来,该软件产品可以存储在一个非易失性存储介质(可以是CD-ROM,U盘,移动硬盘等)中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施场景所述的方法。
本领域技术人员可以理解附图只是一个优选实施场景的示意图,附图中的模块或流程并不一定是实施本申请所必须的。
本领域技术人员可以理解实施场景中的装置中的模块可以按照实施场景描述进行分布于实施场景的装置中,也可以进行相应变化位于不同于本实施场景的一个或多个装置中。上述实施场景的模块可以合并为一个模块,也可以进一步拆分成多个子模块。
上述本申请序号仅仅为了描述,不代表实施场景的优劣。
以上公开的仅为本申请的几个具体实施场景,但是,本申请并非局限于此,任何本领域的技术人员能思之的变化都应落入本申请的保护范围。

Claims (10)

  1. 一种电子凭证传输账号的检测方法,其特征在于,包括:
    查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,在所述三方传输操作中向二级账号传输电子凭证的中间账号接收由所述待检测账号传输的电子凭证;
    判断是否存在特殊二级账号,所述特殊二级账号与所述待检测账号之间所存在的三方传输操作的数量高于预设的第一阈值;
    若存在,根据当前所有与所述特殊二级账号以及所述待检测账号对应的三方传输操作,提取所述三方传输操作中的电子凭证传输记录;
    获取所述电子凭证传输记录中的电子凭证数量的众数信息;
    根据所述三方传输操作的数量以及所述众数信息确定所述待检测账号是否存在问题。
  2. 如权利要求1所述的方法,其特征在于,获取所述电子凭证传输记录中的电子凭证数量的众数信息,具体为:
    将所述电子凭证传输记录划分为所述待检测账号与所述中间账号之间的第一电子凭证传输记录以及所述中间账号与所述特殊二级账号之间的第二电子凭证传输记录;
    将所述第一电子凭证传输记录中电子凭证数量的众数作为第一众数,以及将所述第二电子凭证传输记录中电子凭证数量的众数作为第二众数;
    确定所述第一众数在所述第一电子凭证传输记录的电子凭证数量中的第一占比,以及确定所述第二众数在所述第二电子凭证传输记录的电子凭证数量中的第二占比;
    将所述第一众数、所述第二众数、所述第一占比、所述第二占比作为所述众数信息。
  3. 如权利要求2所述的方法,其特征在于,根据所述三方传输操作的数 量以及所述众数信息确定所述待检测账号是否存在问题,具体为:
    确定所述第一众数与所述第二众数的比值;
    若所述三方传输操作的数量大于预设的第二阈值,且所述第一占比、所述第二占比均大于预设的占比阈值,且所述比值小于或等于预设的出入比阈值,则确认所述待检测账号存在问题,所述第二阈值大于或等于所述第一阈值。
  4. 如权利要求1-3任一项所述的方法,其特征在于,查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,具体为:
    将所述待检测账号设置为起始节点,以及将除所述待检测账号以外的其他账号设为下游节点;
    向接收过所述起始节点发送的电子凭证的第一下游节点发送第一电子凭证流信息,所述第一电子凭证流信息至少包括所述起始节点的账号以及所述第一下游节点的账号;
    当所述下游节点接收到所述第一电子凭证流信息时,所述下游节点判断是否还存在接收过由自身发送的电子凭证的第二下游节点,并在判断结果为是时根据所述第一电子凭证流信息向所述第二下游节点发送第二电子凭证流信息,所述第二电子凭证流信息至少包括所述起始节点的账号、所述第一下游节点的账号以及所述第二下游节点的账号;
    当所述下游节点接收到所述第二电子凭证流信息时,所述下游节点根据所述第二电子凭证流信息生成与所述起始节点、所述第一下游节点以及所述第二下游节点的三方传输操作,其中所述第一下游节点的账号为所述三方传输操作中的中间账号,所述第二下游节点的账号为所述三方传输操作中的二级账号。
  5. 如权利要求4所述的方法,其特征在于,还包括:
    所述第一电子凭证流信息还包括第一电子凭证数量,所述第一电子凭证数量为由所述起始节点发送给所述第一下游节点的电子凭证的数量;
    所述第二电子凭证流信息还包括第一电子凭证数量以及第二电子凭证数量,所述第二电子凭证数量为由所述第一下游节点发送给所述第二下游节点的第二电子凭证的数量。
  6. 一种电子凭证传输账号的检测设备,其特征在于,包括:
    查询模块,用于查询当前所有与待检测账号对应的二级账号,并确定与各所述二级账号及所述待检测账号对应的三方传输操作,在所述三方传输操作中向二级账号传输电子凭证的中间账号接收由所述待检测账号传输的电子凭证;
    判断模块,用于判断是否存在特殊二级账号,所述特殊二级账号与所述待检测账号之间所存在的三方传输操作的数量高于预设的第一阈值;
    提取模块,用于在所述判断模块确认存在特殊二级账号时,根据当前所有与所述特殊二级账号以及所述待检测账号对应的三方传输操作,提取所述三方传输操作中的电子凭证传输记录
    获取模块,用于获取所述电子凭证传输记录中的电子凭证数量的众数信息;
    确定模块,用于根据所述三方传输操作的数量以及所述众数信息确定所述待检测账号是否存在问题。
  7. 如权利要求6所述的设备,其特征在于,所述获取模块具体包括:
    划分子模块,用于将所述电子凭证传输记录划分为所述待检测账号与所述中间账号之间的第一电子凭证传输记录以及所述中间账号与所述特殊二级账号之间的第二电子凭证传输记录;
    众数获取子模块,用于将所述第一电子凭证传输记录中电子凭证数量的 众数作为第一众数,以及将所述第二电子凭证传输记录中电子凭证数量的众数作为第二众数;
    占比获取子模块,用于确定所述第一众数在所述第一电子凭证传输记录的电子凭证数量中的第一占比,以确定所述第二众数在所述第二电子凭证传输记录的电子凭证数量中的第二占比;
    生成子模块,用于将所述第一众数、所述第二众数、所述第一占比、所述第二占比作为所述众数信息。
  8. 如权利要求7所述的设备,其特征在于,
    所述确定模块,具体用于确定所述第一众数与所述第二众数的比值,并在所述三方传输操作的数量大于预设的第二阈值,且所述第一占比、所述第二占比均大于预设的占比阈值,且所述比值小于或等于预设的出入比阈值时,确认所述待检测账号存在问题,所述第二阈值大于或等于所述第一阈值。
  9. 如权利要求6-8任一项所述的设备,其特征在于,所述查询模块,具体包括:
    设置子模块,用于将所述待检测账号设置为起始节点,以及将除所述待检测账号以外的其他账号设为下游节点;
    发送子模块,用于向接收过所述起始节点发送的电子凭证的第一下游节点发送第一电子凭证流信息,所述第一电子凭证流信息至少包括所述起始节点的账号以及所述第一下游节点的账号;
    第一输出子模块,用于在所述下游节点接收到所述第一电子凭证流信息时,判断所述下游节点是否还存在接收过由自身发送的电子凭证的第二下游节点,并在判断结果为是时根据所述第一电子凭证流信息向所述第二下游节点发送第二电子凭证流信息,所述第二电子凭证流信息至少包括所述起始节点的账号、所述第一下游节点的账号以及所述第二下游节点的账号;
    第二输出子模块,用于在所述下游节点接收到所述第二电子凭证流信息 时,指示所述下游节点根据所述第二电子凭证流信息生成与所述起始节点、所述第一下游节点以及所述第二下游节点的三方传输操作,其中所述第一下游节点的账号为所述三方传输操作中的中间账号,所述第二下游节点的账号为所述三方传输操作中的二级账号。
  10. 如权利要求9所述的设备,其特征在于,还包括:
    所述第一电子凭证流信息还包括第一电子凭证数量,所述第一电子凭证数量为由所述起始节点发送给所述第一下游节点的电子凭证的数量;
    所述第二电子凭证流信息还包括第一电子凭证数量以及第二电子凭证数量,所述第二电子凭证数量为由所述第一下游节点发送给所述第二下游节点的第二电子凭证的数量。
PCT/CN2015/092508 2014-10-29 2015-10-22 一种电子凭证传输账号的检测方法及设备 Ceased WO2016066041A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410594627.4A CN105631681B (zh) 2014-10-29 2014-10-29 一种电子凭证传输账号的检测方法及设备
CN201410594627.4 2014-10-29

Publications (1)

Publication Number Publication Date
WO2016066041A1 true WO2016066041A1 (zh) 2016-05-06

Family

ID=55856593

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/092508 Ceased WO2016066041A1 (zh) 2014-10-29 2015-10-22 一种电子凭证传输账号的检测方法及设备

Country Status (2)

Country Link
CN (1) CN105631681B (zh)
WO (1) WO2016066041A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102339445A (zh) * 2010-07-23 2012-02-01 阿里巴巴集团控股有限公司 对网络交易用户的可信度进行评价的方法和系统
CN102831540A (zh) * 2012-07-31 2012-12-19 广西师范大学 面向电子商务系统的信用攻击检测与防御方法及其系统
CN103577991A (zh) * 2012-08-03 2014-02-12 阿里巴巴集团控股有限公司 一种用户的识别方法和装置
US20140129288A1 (en) * 2012-11-06 2014-05-08 Dna Response Inc. Systems and Methods for Detecting and Eliminating Marketing of Fraudulent Goods
CN103955833A (zh) * 2014-03-31 2014-07-30 浙江工商大学 基于虚假交易和社交关系矩阵分析的水军身份确认方法

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040177040A1 (en) * 2003-03-05 2004-09-09 Ming-Ching Shiu Method for securing card transaction by using mobile device
CN103778151B (zh) * 2012-10-23 2017-06-09 阿里巴巴集团控股有限公司 一种识别特征群体的方法及装置和搜索方法及装置

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102339445A (zh) * 2010-07-23 2012-02-01 阿里巴巴集团控股有限公司 对网络交易用户的可信度进行评价的方法和系统
CN102831540A (zh) * 2012-07-31 2012-12-19 广西师范大学 面向电子商务系统的信用攻击检测与防御方法及其系统
CN103577991A (zh) * 2012-08-03 2014-02-12 阿里巴巴集团控股有限公司 一种用户的识别方法和装置
US20140129288A1 (en) * 2012-11-06 2014-05-08 Dna Response Inc. Systems and Methods for Detecting and Eliminating Marketing of Fraudulent Goods
CN103955833A (zh) * 2014-03-31 2014-07-30 浙江工商大学 基于虚假交易和社交关系矩阵分析的水军身份确认方法

Also Published As

Publication number Publication date
CN105631681B (zh) 2019-06-21
CN105631681A (zh) 2016-06-01

Similar Documents

Publication Publication Date Title
US12056681B2 (en) Secure mobile checkout system
US20220398592A1 (en) Peer-to-peer money transfers
JP6697584B2 (ja) データリスクを識別する方法及び装置
US20190325473A1 (en) Reward point redemption for cryptocurrency
US10510078B2 (en) Anomaly detection in groups of transactions
CN113168637A (zh) 交易验证期间的次级欺诈检测
US9230077B2 (en) Alias-based social media identity verification
WO2016180267A1 (zh) 交互数据的处理方法及装置
US20190034933A1 (en) Providing Identification Information to Mobile Commerce Applications
WO2020177450A1 (zh) 信息归并方法、交易查询方法、装置、计算机及存储介质
US11488146B1 (en) System and method for closing pre-authorization amounts on a virtual token account
CN109690599A (zh) 资源交易的方法、节点、装置及存储介质
RU2015136777A (ru) Органы эмиссии жетонов транзакции
US20140282930A1 (en) Social Media Based Identity Verification
CN103578030B (zh) 一种web业务数据处理方法和web业务数据处理装置
CN102541899A (zh) 一种信息识别方法及设备
TW201604803A (zh) 網路支付控制方法和裝置
US11227220B2 (en) Automatic discovery of data required by a rule engine
CN106034151A (zh) 终端设备关联关系的建立方法及装置
WO2016172985A1 (zh) 佣金分配方法和系统
US20230281653A1 (en) System and methods for soft credit approval using text redirect
WO2016066041A1 (zh) 一种电子凭证传输账号的检测方法及设备
CN112561703B (zh) 基于异步网络刻画和实时特征提取的局部关系网络的刻画方法、系统
CN104021494B (zh) 网络订购实名制产品的操作系统及操作方法
CN107038635A (zh) 一种用于处理交易订单的管理方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15854102

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15854102

Country of ref document: EP

Kind code of ref document: A1