WO2020082559A1 - 基于关联图谱的风险检测方法、装置、设备及存储介质 - Google Patents
基于关联图谱的风险检测方法、装置、设备及存储介质 Download PDFInfo
- Publication number
- WO2020082559A1 WO2020082559A1 PCT/CN2018/122745 CN2018122745W WO2020082559A1 WO 2020082559 A1 WO2020082559 A1 WO 2020082559A1 CN 2018122745 W CN2018122745 W CN 2018122745W WO 2020082559 A1 WO2020082559 A1 WO 2020082559A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- factor
- risk
- preset
- blacklist
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q30/00—Commerce
- G06Q30/06—Buying, selling or leasing transactions
- G06Q30/0601—Electronic shopping [e-shopping]
- G06Q30/0609—Qualifying participants for shopping transactions
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/06—Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
- G06Q10/063—Operations research, analysis or management
- G06Q10/0635—Risk analysis of enterprise or organisation activities
Definitions
- the present application relates to the technical field of knowledge graphs, and in particular to a method, device, equipment and storage medium for risk detection based on correlation graphs.
- the main purpose of the present application is to provide a risk detection method, device, equipment and storage medium based on association graphs, aiming to realize business risk monitoring and improve business security.
- the present application provides a risk detection method based on an association graph.
- the risk detection method includes:
- the risk factor in the information association map is detected based on a preset detection rule, and a corresponding security processing prompt is output according to the risk factor.
- the present application also provides a risk detection device based on an association graph, the risk detection device includes:
- An information acquisition module configured to acquire terminal feature information of the user terminal and acquire registration information of a physical account corresponding to the account registration request when receiving an account registration request sent by the user terminal;
- a fingerprint generation module configured to generate a user terminal fingerprint uniquely corresponding to the user terminal according to the terminal feature information and a preset fingerprint algorithm
- the graph establishment module is used to establish an information association map of the physical account based on the user terminal fingerprint and the registration information, and the information association map includes more than two information factors and the association relationship between different information factors ;
- the risk detection module is configured to detect a risk factor in the information association map based on a preset detection rule, and output a corresponding security processing prompt according to the risk factor.
- the present application also provides a risk detection device based on an association graph.
- the risk detection device includes a processor, a memory, and a computer that is stored on the memory and executable by the processor. Read instructions, wherein when the computer-readable instructions are executed by the processor, the steps of the risk detection method based on the association graph as described above are implemented.
- the present application also provides a storage medium that stores computer readable instructions, wherein when the computer readable instructions are executed by the processor, the risk based on the association graph as described above is realized The steps of the detection method.
- This application collects the user's relevant data when the user registers the account, and then integrates these data through the association graph (knowledge graph) to facilitate the merchant or risk control personnel to understand the correlation between the various information; according to this Correlation graphs are used for risk detection, so as to analyze user data in the form of knowledge relationship analysis to predict potential business risks, realize e-commerce risk early warning, and improve risk detection capabilities and business security.
- association graph knowledge graph
- FIG. 1 is a schematic diagram of the hardware structure of a risk detection device based on an association graph involved in an embodiment of the present application
- FIG. 2 is a schematic flowchart of a first embodiment of a risk detection method based on association graphs of this application;
- FIG. 3 is a schematic diagram of functional modules of a first embodiment of a risk detection device based on an association graph in this application.
- the risk detection method based on association graphs involved in the embodiments of the present application is mainly applied to a risk detection device based on association graphs.
- the risk detection device may be a personal computer (PC), a notebook computer, a server and other devices with data processing functions .
- FIG. 1 is a schematic diagram of a hardware structure of a risk detection device based on an association graph involved in an embodiment of the present application.
- the risk detection device may include a processor 1001 (eg, Central Processing Unit, CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005.
- the communication bus 1002 is used to realize the connection and communication between these components;
- the user interface 1003 may include a display (Display), an input unit such as a keyboard (Keyboard);
- the network interface 1004 may optionally include a standard wired interface, a wireless interface (Such as wireless fidelity WIreless-FIdelity, WI-FI interface);
- the memory 1005 can be a high-speed random access memory (random access memory, RAM), or a stable memory (non-volatile memory), such as disk memory, memory 1005 may optionally be a storage device independent of the foregoing processor 1001.
- RAM random access memory
- non-volatile memory such as disk memory
- memory 1005 may optionally be a storage device independent of the foregoing processor 1001.
- FIG. 1 does not constitute a limitation on the present application, and may include more or less components than those illustrated, or combine certain components, or arrange different components.
- the memory 1005 in FIG. 1 as a computer-readable storage medium may include an operating system, a network communication module, and computer-readable instructions.
- the network communication module can be used to connect to a database and perform data communication with the database; and the processor 1001 can call computer-readable instructions stored in the memory 1005 and execute the risk detection method based on the association graph provided by the embodiments of the present application. .
- Embodiments of the present application provide a risk detection method based on association graphs.
- FIG. 2 is a schematic flowchart of a first embodiment of a risk detection method based on association graphs of the present application.
- the risk detection method includes the following steps:
- Step S10 When receiving an account registration request sent by a user terminal, obtain terminal feature information of the user terminal, and obtain registration information of a physical account corresponding to the account registration request;
- association graphs which is convenient for merchants or Risk control personnel understand the correlation between various information; and then conduct risk detection according to the correlation map, so as to predict the risk by means of big data analysis, realize the e-commerce risk warning, and help maintain business security.
- the risk detection method based on the association map in this embodiment is implemented by a risk detection device based on the association map.
- the risk detection device uses a detection server as an example for description.
- the user terminal such as a personal computer PC, notebook computer, mobile phone, tablet computer, etc.
- the detection server receives the account registration request sent by the user terminal, it will obtain the terminal feature information of the user terminal.
- the terminal feature information may include terminal model characteristics (such as terminal brand, terminal model, production time, etc.), terminal operation System OS characteristics (such as operating system type, operating system version, whether to jailbreak, etc.), browser characteristics (such as browser type, browser version, user agent UA, plug-in configuration, Canvas characteristics, etc.), sensor characteristics (such as gravity sensor characteristics , Acceleration sensor characteristics, etc.), device configuration characteristics (such as network configuration, system flash configuration, etc.), etc.
- terminal model characteristics such as terminal brand, terminal model, production time, etc.
- terminal operation System OS characteristics such as operating system type, operating system version, whether to jailbreak, etc.
- browser characteristics such as browser type, browser version, user agent UA, plug-in configuration, Canvas characteristics, etc.
- sensor characteristics such as gravity sensor characteristics , Acceleration sensor characteristics, etc.
- device configuration characteristics such as network configuration, system flash configuration, etc.
- the detection server may obtain the SDK (Software Development Kit, software development kit) or other technologies to capture the terminal feature information of the user terminal through the feature installed in the user terminal after being authorized by the user ; It can also be that the detection server obtains the terminal feature information of the user terminal from the operator after obtaining the user's authorization.
- SDK Software Development Kit, software development kit
- the detection server when the detection server receives the account registration request, it will also obtain the registration information of the corresponding entity account according to the account registration request, so as to bind the registration information with the user-registered entity account to complete the registration operation.
- the registration information can also include personal information and environmental information; personal information includes user name, mobile phone number, mailbox, ID card number, bank card number, third-party payment platform account, etc .; environmental information includes registration time, current user of the user terminal Terminal IP address (Internet Protocol Address, Internet Protocol address), terminal GPS address, etc.
- the registration information may be entered by the user when performing an account registration operation through the user terminal, and sent by the user terminal to the detection server; or it may be obtained by the detection server.
- Step S20 generating a user terminal fingerprint uniquely corresponding to the user terminal according to the terminal feature information and a preset fingerprint algorithm
- the detection server when obtaining the terminal feature information and registration information of the user terminal, the detection server will generate a unique user terminal fingerprint corresponding to the user terminal according to the terminal feature information and a preset fingerprint algorithm; the user terminal fingerprint may be used for Uniquely identifies the terminal characteristics of the terminal, or is considered to be the unique terminal identification of the user terminal.
- the preset fingerprint algorithm may be set according to actual conditions, for example, a hash hash algorithm or a machine learning algorithm.
- the sha256 algorithm may be used, and terminal feature information whose maximum length does not exceed 2 ⁇ 64 bits is processed in 512-bit grouping to generate a 256-bit user terminal fingerprint through the sha256 algorithm.
- Step S30 Establish an information association map of the physical account based on the user terminal fingerprint and the registration information, where the information association map includes more than two information factors and association relationships between different information factors;
- the detection server when the user terminal fingerprint is obtained, the detection server will establish an information association map of the physical account based on the user terminal fingerprint and registration information, integrate the information related to the physical account in a "relationship” manner, and visually associate
- the user terminal fingerprint and registration information are expressed in the form of information factors.
- the information association graph includes more than two information factors (here "above” includes the number, the same below);
- the different information factors are connected by an association relationship line, which represents the "relationship” between information factors (there is not necessarily an association relationship between any two information factors at the time), which is convenient for businesses or risk control personnel Understand the relationship between different types of information, and analyze potential risk factors accordingly.
- the detection server first translates the user terminal fingerprint and registration information according to a preset transfer rule to obtain at least one factor relationship group, where each factor relationship group includes two information factors and the association relationship between the information factors ,
- the form of the factor relationship group can be (information factor 1, information factor 2, information factor 1 and information factor 2 association relationship); each information factor in the factor relationship group corresponds to a piece of registration information or user terminal fingerprint,
- the association relationship between information factors can be determined from the description angle of the registration information according to the type of registration information; for example, for the user terminal fingerprint A and the registered mobile phone number P, the corresponding factor relationship group of the two is (terminal fingerprint factor, mobile phone Number factor, the mobile phone number used by the terminal); for example, for the user name Z and the registered mobile phone number P, the corresponding factor relationship group of the two is (user name factor, mobile phone number factor, user name bound mobile phone number).
- the detection server can draw the information association map of the entity account according to the factor relationship; for the information factor of each factor relationship group, a node (such as a circle) can be used to represent the information factor, and the association in the factor association group
- a node such as a circle
- the relationship is represented by an association line, that is, different information factors are connected by the association line to obtain an information association graph.
- Step S40 Detect a risk factor in the information association map based on a preset detection rule, and output a corresponding security processing prompt according to the risk factor.
- the detection server after obtaining the information association map, performs risk detection on the information association map according to a preset detection rule, detects the risk factors (information factors with risks) therein, and outputs the corresponding Safe handling tips to achieve risk warning. among them.
- the detection of the risk factor can be achieved in various ways, for example, it can be detected in a way of factor stability, risk conduction (black or gray logic) and other methods.
- the risk factor may be detected by means of risk transmission (black-stained / gray-stained logic).
- the information factor corresponding to the blacklist information may be referred to as an associated blacklist information factor; wherein the determination of the blacklist information may be through a third-party organization
- the constructed blacklist information database (such as black cell phone number database, black cell mailbox, etc.) can also be obtained through other methods.
- the detection server will perform risk detection on the information factors that have an association relationship with the associated blacklist information factors, and the detected information factors may be referred to as information factors to be detected.
- the detection server will first determine the blacklist risk value of the associated blacklist information factor according to the factor type of the associated blacklist information factor to characterize the degree of risk; for example, the associated blacklist information factor is a mobile phone number factor, and the blacklist risk value is 80 ; For another example, the associated blacklist information factor is the mailbox number factor, and the blacklist risk value is 75. At the same time, the detection server will also determine the relationship between the blacklist information factor and the information factor to be detected; for example, the relationship between the mobile phone number is 0.8 and the relationship between the mailbox number is 0.8. The degree is 0.6 etc.
- the detection server When determining the blacklist risk value of the associated blacklist information factor and its corresponding relationship degree, the detection server will calculate the risk value of the information factor to be detected according to the preset risk conduction formula, and determine the risk value based on the risk value to be detected Whether the information factor to be tested belongs to a risk factor; if the risk value to be tested is greater than a preset risk threshold, the information factor to be tested may be considered to be a risk factor; and if the risk value to be tested is less than or equal to the preset risk threshold, It can be considered that the information factor to be detected does not belong to a risk factor.
- the default risk transmission formula is:
- f is the risk value of the information factor to be detected
- k i is the degree of relationship corresponding to the information factor of the i-th associated blacklist, k i > 0, i ⁇ 1
- x i is the i-th associated blacklist
- Risk detection through the above-mentioned risk transmission method can improve the ability of risk detection in the case of insufficient blacklist data coverage, reduce the risk of missed judgments, and help improve business security.
- the associated blacklist information factor in this embodiment may be a blacklist IP factor, that is, the IP address used by the user terminal is a blacklist IP; for the blacklist IP factor, it may be determined by way of honeypot delivery Method (or identification).
- the detection server puts a number of test agent IP addresses into the network in advance and provides them to the network users for free. When it is detected that a test agent IP address is used by a terminal, the detection server will monitor the network behavior of the terminal through the test agent IP address.
- the terminal using the test agent IP address may be called a proxy terminal .
- the detection server When the detection server detects that the agent terminal is attacking through the test agent IP address, it can be considered that the test agent terminal has a certain degree of danger; at this time, the detection server will obtain the real IP address of the agent terminal, and the real The IP address is determined as blacklist information, and the information factor corresponding to the real IP address is the blacklist IP factor, and is used for risk transmission analysis.
- the risk factor in the correlation map can also be detected by means of factor stability. Specifically, for an information factor whose risk is not clear, the detection server can query the historical matching account that matches the information factor in the preset account library (that is, query whether there is the same information or similar information as the current physical account Registered historical matching account); if the historical matching account is queried, the detection server will obtain the historical registration time of the historical matching account.
- the detection server can query the historical matching account that matches the information factor in the preset account library (that is, query whether there is the same information or similar information as the current physical account Registered historical matching account); if the historical matching account is queried, the detection server will obtain the historical registration time of the historical matching account.
- the detection server When the detection server completes the query, the detection server will filter according to the historical registration time of the historical matching account, and count the number of historical matching accounts registered within the preset registration period.
- the current registration time of the physical account Z1 is June 18, and its bound mobile phone number is P; this detection server detects the historical matching accounts Z2, Z3, Z4 with the same bound mobile phone number, where the historical matching account Z2
- the historical registration time of February is 18 years, the historical registration time of the historical matching account Z3 is March 18, and the historical registration time of the historical matching account Z4 is April 17; the default registration period is before the registration time of the physical account Z1 Move 6 months (that is, January 18); then the number of historical matching accounts registered in the preset registration period at this time is 2 (historical matching account Z2 and historical matching account Z3).
- the detection server compares it with a preset matching threshold. If the number of historical matching accounts is greater than the preset matching threshold, it means that the information factor is used multiple times in a short time. When the information factor is unstable, it has a certain degree of risk, and it is determined as a risk factor; and if the number of historical matching accounts is less than or equal to the preset matching threshold, the information factor can be considered to be more stable, It is not a risk factor when testing by factor stability.
- a certain risk factor can be detected by factor stability, and then the risk factor is used as the associated blacklist information in the risk transmission method.
- Factor used to detect the risk of other information factors associated with it, thereby improving the ability of risk detection, reducing the risk of missed judgments, and further improving business security.
- the detection server may output a corresponding security processing prompt according to the risk factor. It is worth noting that, because the number of risk factors included in the information association maps of different entity accounts may also be different, it may be considered that the risk situation of the entity account is also different. It is convenient for merchants or risk control personnel to carry out corresponding processing, which can be different processing according to different risk levels.
- the detection server can count the number of risk factors in the information association graph, and then determine the risk level of the entity account according to the number of risk factors; for example, an entity account with 0 risk factors has a low risk level; 1 to 3 For entity accounts with five risk factors, the risk level is medium-low risk; for entity accounts with four to six risk factors, the risk level is medium-risk; for entity accounts with more than seven risk factors, the risk level is high-risk.
- the detection server can output corresponding security processing prompts according to the risk level; for example, for low-risk physical accounts, any of its business functions can be used normally; for medium- and low-risk physical accounts, the Output suggestions to limit their transaction limits; for medium-risk physical accounts, you can output a suggestion to disable some business functions; for high-risk physical accounts, you can output a suggestion to manually review security.
- terminal feature information of the user terminal is acquired, and registration information of a physical account corresponding to the account registration request is acquired; according to the terminal feature information and preset A fingerprint algorithm generates a user terminal fingerprint uniquely corresponding to the user terminal; an information association map of the physical account is established based on the user terminal fingerprint and the registration information, and the information association map includes more than two information factors, and Correlation relationship between different information factors; detecting a risk factor in the information correlation map based on a preset detection rule, and outputting corresponding security processing prompts according to the risk factor.
- this embodiment collects the user's relevant data when the user registers the account, and then integrates these data through the association graph (knowledge graph) to facilitate the merchant or risk control personnel to understand the association between the various information
- association graph knowledge graph
- risk detection is carried out to analyze user data in the form of knowledge relationship analysis to predict potential business risks, realize e-commerce risk early warning, and improve the ability of risk detection and business security.
- step S40 the method further includes:
- a corresponding washing mechanism can also be set to wash it, so that the risk detection can be more in line with the actual use and reduce the false positive rate .
- the detection server will record the behavior of the physical account; when the preset whitewash cycle passes, the detection server will detect whether the physical account is within the preset whitewash cycle There is risk characteristic behavior.
- the risk factor is whitewashed based on a preset whitewashing rule
- the entity account if the entity account has risk characteristic behavior within the preset whitewashing cycle, it will not be washed; and if the entity account does not have risk characteristic behavior within the preset whitewashing cycle, it may be Wash the risk factor based on preset washing rules.
- a risk value can be set for the risk factor, the risk value will be set to a decayable form, the degree of decay can be calculated using time as a measure (of course, risk decay rules can also be set from other dimensions), such as certain information
- the factor is determined as a risk factor in January 2016, and its initial risk value is 30; after 6 months after the preset whitewash cycle, the corresponding physical account does not have risk characteristic behavior, then its risk value begins to Time and a predetermined decay function to decay; and in June 2017, the risk value of the risk factor decayed to 0, it can be considered that the information factor no longer belongs to the risk factor, that is, the risk factor is washed out.
- embodiments of the present application also provide a risk detection device based on an association graph.
- FIG. 3 is a schematic diagram of functional modules of a first embodiment of a risk detection device based on big data of the present application.
- the risk detection device includes:
- the information acquisition module 10 is configured to acquire terminal feature information of the user terminal when acquiring an account registration request sent by the user terminal, and acquire registration information of a physical account corresponding to the account registration request;
- the fingerprint generating module 20 is configured to generate a user terminal fingerprint corresponding to the user terminal uniquely according to the terminal feature information and a preset fingerprint algorithm;
- the graph establishment module 30 is configured to establish an information association map of the physical account based on the user terminal fingerprint and the registration information, and the information association map includes more than two information factors and associations between different information factors relationship;
- the risk detection module 40 is configured to detect a risk factor in the information association map based on a preset detection rule, and output a corresponding security processing prompt according to the risk factor.
- each virtual function module of the above-mentioned risk detection device is stored in the memory 1005 of the risk detection device based on the association graph shown in FIG. 1 and is used to implement all functions of computer-readable instructions; when each module is executed by the processor 1001, Realize the function of information integration and risk detection through the association graph.
- the graph creation module 30 includes:
- the information translation unit is used to translate the user terminal fingerprint and the registration information based on a preset translation rule to obtain at least one factor relationship group, where each factor relationship group includes two information factors and information factors Relationship
- the graph generating unit is configured to draw the information association graph of the entity account according to the factor relationship group.
- the information association map includes an information factor to be detected and at least one associated blacklist information factor, and there is an association relationship between the information factor to be detected and the associated blacklist information factor,
- the risk detection module 40 includes:
- the risk value determining unit is configured to determine the blacklist risk value of the associated blacklist information factor according to the factor type of the associated blacklist information factor, and according to the relationship between the associated blacklist information factor and the information factor to be detected The association relationship determines the corresponding relationship degree;
- the risk value calculation unit is configured to calculate the risk value to be detected of the information factor to be detected according to a preset risk transmission formula, the blacklist risk value and the relationship degree, and determine the risk value according to the risk value to be detected To detect whether the information factor is a risk factor, the preset risk transmission formula is:
- f is the risk value of the information factor to be detected
- k i is the degree of relationship corresponding to the i-th associated blacklist information factor, k i > 0, i ⁇ 1;
- x i is the blacklist risk value corresponding to the i-th associated blacklist information factor, x i > 0.
- the associated blacklist information factor includes a blacklist IP factor
- the risk detection device also includes:
- IP delivery module used to put a preset number of test agent IP addresses into the network
- the IP determination module is used to obtain the real IP address of the proxy terminal when it is detected that the test proxy IP address is used by the proxy terminal and conduct an attack, and determine the corresponding blacklist IP factor according to the real IP address.
- the risk detection module 40 includes:
- An account query unit configured to query a historical matching account matching the information factor in a preset account library, and obtain a historical registration time of the historical matching account;
- An account number judging unit configured to count the number of historical matching accounts registered within a preset registration period according to the historical registration time, and determine whether the information factor belongs to the size relationship between the number of historical matching accounts and a preset matching threshold Risk factor.
- the risk detection device further includes:
- the behavior detection module is used to detect whether there is a risk characteristic behavior of the physical account in the preset whitewashing cycle after the preset whitewashing cycle;
- the factor whitewashing module is configured to wash the risk factors based on preset whitewashing rules if the physical account does not have the risk characteristic behavior within the preset whitewashing cycle.
- the risk detection module 40 includes:
- a level determining unit configured to count the number of risk factors in the information association map, and determine the risk level of the entity account according to the number of risk factors
- the prompt output unit is configured to output a corresponding security processing prompt according to the risk level of the entity account.
- each module in the above-mentioned risk detection device corresponds to the steps in the above-mentioned embodiment of the risk detection method based on the association graph, and its function and implementation process will not be repeated here one by one.
- an embodiment of the present application further provides a storage medium, and the storage medium may be a non-volatile readable storage medium.
- the storage medium of the present application stores computer-readable instructions, where the computer-readable instructions are executed by the processor to implement the steps of the risk detection method based on the association graph as described above.
- the methods in the above embodiments can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware, but in many cases the former is better Implementation.
- the technical solution of the present application can be embodied in the form of a software product in essence or part that contributes to the existing technology, and the computer software product is stored in a storage medium (such as ROM / RAM) as described above , Magnetic disks, optical disks), including several instructions to enable a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to perform the method described in each embodiment of the present application.
Landscapes
- Business, Economics & Management (AREA)
- Human Resources & Organizations (AREA)
- Engineering & Computer Science (AREA)
- Strategic Management (AREA)
- Economics (AREA)
- Marketing (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Finance (AREA)
- Theoretical Computer Science (AREA)
- Development Economics (AREA)
- Entrepreneurship & Innovation (AREA)
- Educational Administration (AREA)
- Game Theory and Decision Science (AREA)
- Operations Research (AREA)
- Quality & Reliability (AREA)
- Tourism & Hospitality (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
一种基于知识图谱的风险检测方法、装置、设备及可读存储介质,在用户进行账户注册时即收集用户的相关数据,然后通过关联图谱(知识图谱)的方式对这些数据进行整合,方便商家或风控人员了解各项信息之间的关联性;再根据该关联图谱进行风险检测,从而以知识关系分析的方式对用户数据进行分析,以对潜在业务风险进行预测,实现了电子商务风险预警,提高风险检测的能力和业务安全性。
Description
本申请要求于2018年10月25日提交中国专利局、申请号为201811254500.2、发明名称为“基于关联图谱的风险检测方法、装置、设备及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及知识图谱技术领域,尤其涉及一种基于关联图谱的风险检测方法、装置、设备及存储介质。
随着网络技术进步,电子商务蓬勃发展,同时也对交易安全性提出了越来越高的要求;对商家而言,对风险账户进行及时处理,有利于维护电子商务活动的正常进行。但目前的电子商务活动中,主要是在遭受欺诈时进行被动的防御和补救处理,这种业务安全处理方法缺乏提前的风险评估,无法在欺诈发生前提前对风险进行预测,也就不能有效的进行风险监控处理。
发明内容
本申请的主要目的在于提供一种基于关联图谱的风险检测方法、装置、设备及存储介质,旨在实现对业务风险监控,提高业务安全性。
为实现上述目的,本申请提供一种基于关联图谱的风险检测方法,所述风险检测方法包括:
在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;
根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;
根据所述用户终端指纹和所述注册信息建立所述实体账户的信 息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;
基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
此外,为实现上述目的,本申请还提供一种基于关联图谱的风险检测装置,所述风险检测装置包括:
信息获取模块,用于在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;
指纹生成模块,用于根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;
图谱建立模块,用于根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;
风险检测模块,用于基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
此外,为实现上述目的,本申请还提供一种基于关联图谱的风险检测设备,所述风险检测设备包括处理器、存储器、以及存储在所述存储器上并可被所述处理器执行的计算机可读指令,其中所述计算机可读指令被所述处理器执行时,实现如上述的基于关联图谱的风险检测方法的步骤。
此外,为实现上述目的,本申请还提供一种存储介质,所述存储介质上存储有计算机可读指令,其中所述计算机可读指令被处理器执行时,实现如上述的基于关联图谱的风险检测方法的步骤。
本申请在用户进行账户注册时即收集用户的相关数据,然后通过关联图谱(知识图谱)的方式对这些数据进行整合,方便商家或风控人员了解各项信息之间的关联性;再根据该关联图谱进行风险检测,从而以知识关系分析的方式对用户数据进行分析,以对潜在业务风险进行预测,实现了电子商务风险预警,提高风险检测的能力和业务安全性。
图1为本申请实施例方案中涉及的基于关联图谱的风险检测设备的硬件结构示意图;
图2为本申请基于关联图谱的风险检测方法第一实施例的流程示意图;
图3为本申请基于关联图谱的风险检测装置第一实施例的功能模块示意图。
本申请目的的实现、功能特点及优点将结合实施例,参照附图做进一步说明。
应当理解,此处所描述的具体实施例仅仅用以解释本申请,并不用于限定本申请。
本申请实施例涉及的基于关联图谱的风险检测方法主要应用于基于关联图谱的风险检测设备,该风险检测设备可以是个人计算机(personal computer,PC)、笔记本电脑、服务器等具有数据处理功能的设备。
参照图1,图1为本申请实施例方案中涉及的基于关联图谱的风险检测设备的硬件结构示意图。本申请实施例中,该风险检测设备可以包括处理器1001(例如中央处理器Central Processing Unit,CPU),通信总线1002,用户接口1003,网络接口1004,存储器1005。其中,通信总线1002用于实现这些组件之间的连接通信;用户接口1003可以包括显示屏(Display)、输入单元比如键盘(Keyboard);网络接口1004可选的可以包括标准的有线接口、无线接口(如无线保真WIreless-FIdelity,WI-FI接口);存储器1005可以是高速随机存取存储器(random access memory,RAM),也可以是稳定的存储器(non-volatile memory),例如磁盘存储器,存储器1005可选的还可以是独立于前述处理器1001的存储装置。本领域技术人员可以理解,图1中示出的硬件结构并不构成对本申请的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。
继续参照图1,图1中作为一种计算机可读存储介质的存储器1005可以包括操作系统、网络通信模块以及计算机可读指令。在图1中,网络通信模块可用于连接数据库,与数据库进行数据通信;而处理器1001可以调用存储器1005中存储的计算机可读指令,并执行本申请实施例提供的基于关联图谱的风险检测方法。
本申请实施例提供了一种基于关联图谱的风险检测方法。
参照图2,图2为本申请基于关联图谱的风险检测方法第一实施例的流程示意图。
本实施例中,所述风险检测方法包括以下步骤:
步骤S10,在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;
随着网络技术进步,电子商务蓬勃发展,同时也对交易安全性提出了越来越高的要求;对商家而言,对风险账户进行及时处理,有利于维护电子商务活动的正常进行。但目前的电子商务活动中,主要是在遭受欺诈时进行被动的防御和补救处理,这种业务安全处理方法缺乏提前的风险评估,无法在欺诈发生前提前对风险进行预测,也就不能有效的进行风险监控处理。对此,本实施例中提出一种基于关联图谱的风险检测方法,在用户进行账户注册时即收集用户的相关数据,然后通过关联图谱(智慧图谱)的方式对这些数据进行整合,方便商家或风控人员了解各项信息之间的关联性;再根据该关联图谱进行风险检测,从而以大数据分析的方式对风险进行预测,实现了电子商务风险预警,有利于维护业务安全。
本实施例中基于关联图谱的风险检测方法是由基于关联图谱的风险检测设备实现的,该风险检测设备以检测服务器为例进行说明。本实施例中,用户在进行电子商务活动前,首先需要通过用户终端(如个人电脑PC、笔记本电脑、手机、平板电脑等)上进行账户注册操作,用户终端则根据用户的操作向检测服务器发送对应的账户注册请求。检测服务器在接收到用户终端发送的账户注册请求时,将会获取该用户终端的终端特征信息,该终端特征信息可以包括终端机型特征 (如终端品牌、终端型号、生产时间等)、终端操作系统OS特征(如操作系统类型、操作系统版本、是否越狱等)、浏览器特征(如浏览器类型、浏览器版本、用户代理UA、插件配置、Canvas特征等)、传感器特征(如重力传感器特征、加速传感器特征等)、设备配置特征(如网络配置、系统flash的配置等)等。对于上述终端特征信息的获取,可以是检测服务器在得到用户授权后,通过安装在该用户终端中的特征获取SDK(Software Development Kit,软件开发工具包)或其它技术抓取用户终端的终端特征信息;也可以是检测服务器在得到用户的授权后,从运营商处获取该用户终端的终端特征信息。
本实施例中,检测服务器在接收到账户注册请求时,还将根据该账户注册请求获取对应实体账户的注册信息,以将该注册信息与用户注册的实体账户进行绑定,完成注册操作。其中,这些注册信息又可以包括个人信息和环境信息;个人信息包括用户名、手机号、邮箱、身份证号、银行卡号、第三方支付平台账户等;环境信息包括注册时间、用户终端当前的用户终端IP地址(Internet Protocol Address,互联网协议地址)、终端GPS地址等。对于这些注册信息,可以是用户在通过用户终端进行账户注册操作时进行录入,由用户终端发送至检测服务器;也可以是检测服务器主动检测得到。
步骤S20,根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;
本实施例中,检测服务器在得到用户终端的终端特征信息和注册信息时,将根据该终端特征信息和预设指纹算法生成该用户终端唯一对应的用户终端指纹;该用户终端指纹是可以用于唯一标识出该终端的终端特征,或认为是该用户终端独特的终端标识。对于该预设指纹算法,可以是根据实际情况进行设置,例如可以是哈希hash算法、又或者是机器学习算法。例如可以是通过sha256算法进行,通过sha256算法将最大长度不超过2^64bit的终端特征信息按512-bit分组进行处理,生成256-bit的用户终端指纹。
步骤S30,根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、 以及不同信息因子之间的关联关系;
本实施例中,在得到用户终端指纹时,检测服务器将根据该用户终端指纹和注册信息建立实体账户的信息关联图谱,以“关系”的方式将实体账户涉及的信息进行整合,并以可视化关联图的方式进行表示;对于该信息关联图谱,用户终端指纹和注册信息以信息因子的方式进行表示,信息关联图谱中包括两个以上(此处“以上”包括本数,下同)的信息因子;而不同信息因子则通过关联关系线条进行连接,该关联关系线条代表信息因子之间的“关系”(当时不是任何两个信息因子之间都一定会存在关联关系),从而方便商家或风控人员了解不同类型信息之间关联,并据此分析潜在的风险因素。
具体的,检测服务器首先将根据预设转移规则对用户终端指纹和注册信息进行转译,得到至少一个因子关系组,其中每个因子关系组中均包括两个信息因子和信息因子之间的关联关系,该因子关系组的形式可以为(信息因子1,信息因子2,信息因子1和信息因子2的关联关系);因子关系组中的每个信息因子与一项注册信息或用户终端指纹对应,而信息因子之间的关联关系则可以根据注册信息的类型获该注册信息的描述角度确定;例如对于用户终端指纹A和注册手机号P,两者对应的因子关系组为(终端指纹因子,手机号因子,终端所用手机号);又例如对于用户名Z、注册手机号P,两者对应的因子关系组为(用户名因子,手机号因子,用户名绑定手机号)。
在得到因子关系组时,检测服务器即可根据因子关系绘制实体账户的信息关联图谱;对于每个因子关系组的信息因子,可以用一节点(如圆)表示信息因子,因子关联组中的关联关系则用关联关系线条表示,也即不同信息因子通过关联关系线条进行连接,从而得到信息关联图谱。
步骤S40,基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
本实施例中,在得到了信息关联图谱后,检测服务器根据预设检测规则对信息关联图谱进行风险检测,检测出其中的风险因子(具有风险的信息因子),并根据该风险因子输出对应的安全处理提示,从 而实现风险预警。其中。其中,对于风险因子的检测可以是通过多种方式实现的,例如可以是通过因子稳定性的方式进行检测、风险传导(染黑或染灰逻辑的方式)等多种方式实现。
可选地,当用户终端指纹或某个注册信息属于黑名单信息时,可以是通过风险传导(染黑/染灰逻辑)的方式进行风险因子的检测。具体的,当用户终端指纹或某个注册信息确定属于黑名单信息时,该黑名单信息对应的信息因子可称为关联黑名单信息因子;其中该黑名单信息的确定,可以是通过第三方机构构建的黑名单信息库得到(例如黑产手机号码库、黑产邮箱等),也可以是通过其它方式得到。此时,检测服务器将对与该关联黑名单信息因子具有关联关系的信息因子进行风险检测,该被检测的信息因子可称为待检测信息因子。检测服务器首先将根据关联黑名单信息因子的因子类型确定该关联黑名单信息因子的黑名单风险值,用以表征风险程度;例如关联黑名单信息因子为手机号因子,其黑名单风险值为80;又例如关联黑名单信息因子为邮箱号因子,其黑名单风险值为75等。同时,检测服务器还将根据该关联黑名单信息因子与待检测信息因子之间的关联关系确定两者之间的关系度;例如,绑定手机号的关系度为0.8,绑定邮箱号的关系度为0.6等。
在确定关联黑名单信息因子的黑名单风险值以及其对应的关系度时,检测服务器将会根据预设风险传导公式计算待检测信息因子的待检测风险值,根据该待检测风险值来判断该待检测信息因子是否属于风险因子;如果该待检测风险值大于一预设风险阈值,则可认为该待检测信息因子属于风险因子;而如果该待检测风险值小于或等于该预设风险阈值,则可认为该待检测信息因子不属于风险因子。而该预设风险传导公式为:
其中,f为所述待检测信息因子的待检测风险值;k
i为第i个关联黑名单信息因子对应的关系度,k
i>0,i≥1;x
i为第i个关联黑名单信息因子对应的黑名单风险值,x
i>0。通过上述利用风险传导的 方式进行风险检测,可在黑名单数据量覆盖度不足的情况下提高风险检测的能力,减少了风险漏判率,有利于提高业务安全性。
进一步的,本实施例中的关联黑名单信息因子可能是黑名单IP因子,也即用户终端所用的IP地址为黑名单IP;对于该黑名单IP因子,可以是通过蜜罐投放的方式进行确定方法(或识别)。具体的,检测服务器预先向网络中投放若干的测试代理IP地址,并以免费的方式供网络用户使用。当检测到某一测试代理IP地址被某一终端使用时,检测服务器将会通过该测试代理IP地址监测该终端的网络行为,为描述方便,该使用测试代理IP地址的终端可称为代理终端。检测服务器在检测到该代理终端通过测试代理IP地址进行攻击行为时,即可认为该测试代理终端具有一定的危险性;此时检测服务器将会获取该代理终端的真实IP地址,并将该真实IP地址确定为黑名单信息,该真实IP地址对应的信息因子即为黑名单IP因子,并用以进行风险传导分析。
可选地,关联图谱中的风险因子,还可以是通过因子稳定性的方式进行检测的。具体的,对于某一个风险性不明确的信息因子,检测服务器可在预设账户库中查询与该信息因子匹配的历史匹配账户(也即查询是否存在与当前的实体账户使用相同信息或相似信息进行注册的历史匹配账户);若查询到了该历史匹配账户,检测服务器将会获取该历史匹配账户的历史注册时间。
当检测服务器查询完毕时,检测服务器将根据该历史匹配账户的历史注册时间进行筛选,并统计在预设注册周期内注册的历史匹配账户数。例如,当前实体账户Z1的注册时间为18年6月,其绑定手机号为P;对此检测服务器检测到具有相同绑定手机号的历史匹配账户Z2、Z3、Z4,其中历史匹配账户Z2的历史注册时间为18年2月,历史匹配账户Z3的历史注册时间为18年3月,历史匹配账户Z4的历史注册时间为17年4月;预设注册周期为实体账户Z1的注册时间前移6个月(即18年1月);则此时在预设注册周期内注册的历史匹配账户数为2个(历史匹配账户Z2和历史匹配账户Z3)。在得到历史匹配账户数时,检测服务器会将其与一预设匹配阈值进行比较,若 该历史匹配账户数大于该预设匹配阈值,则说明该信息因子在短时间内被多次使用,此时可认为该信息因子不稳定,其存在一定的风险性,并将其确定为风险因子;而若该历史匹配账户数小于或等于该预设匹配阈值,则可认为该信息因子较稳定,其在通过因子稳定性的方式进行检测时不属于风险因子。
值得说明的是,对于上述两种方式在具体实施中可以结合使用,例如可先通过因子稳定性的方式检测出某个风险因子,然后再将该风险因子作为风险传导方式中的关联黑名单信息因子,用以检测其它与之关联的信息因子的风险性,从而提高风险检测的能力,减少了风险漏判率,进一步提高业务安全性。
本实施例中,在检测出信息关联图谱中的风险因子时,检测服务器可根据该风险因子输出对应的安全处理提示。值得说明的是,由于不同实体账户的信息关联图谱中,所包括的风险因子数也可能不同,则可认为实体账户的风险情况也不相同,本实施例中为了进一步提高风险预警的准确性,方便商家或风控人员进行对应处理,可以是根据不同的风险等级进行不同的处理。具体的,检测服务器可以对信息关联图谱中的风险因子数进行统计,然后根据风险因子数确定该实体账户的风险等级;例如0个风险因子的实体账户,其风险等级为低风险;1至3个风险因子的实体账户,其风险等级为中低风险;4至6个风险因子的实体账户,其风险等级为中风险;7个以上风险因子的实体账户,其风险等级为高风险。在确定实体账户的风险等级时,检测服务器可根据该风险等级输出对应的安全处理提示;例如对于低风险的实体账户,其任何的业务功能均可正常使用;对于中低风险的实体账户,可输出建议限制其交易额度的提示;对于中风险的实体账户,可输出建议禁用一部分业务功能的提示;对于高风险的实体账户,可输出建议人工复核安全性的提示。
本实施例中,在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;根据所述用户终端指纹和所述注册信息 建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。通过以上方式,本实施例在用户进行账户注册时即收集用户的相关数据,然后通过关联图谱(知识图谱)的方式对这些数据进行整合,方便商家或风控人员了解各项信息之间的关联性;再根据该关联图谱进行风险检测,从而以知识关系分析的方式对用户数据进行分析,以对潜在业务风险进行预测,实现了电子商务风险预警,提高风险检测的能力和业务安全性。
基于上述图2所述实施例,提出本申请基于大数据的风险检测方法的第二实施例。
本实施例中,步骤S40之后还包括:
在经过预设洗白周期时,检测所述实体账户在所述预设洗白周期内是否命中风险特征行为;
本实施例中,信息关联图谱中的某个信息因子被检测为风险因子后,还可以设置相应的洗白机制对其进行洗白,从而使得风险检测能够更符合实际使用情况,降低误判率。具体的,某个信息因子被检测为风险因子后,检测服务器会对实体账户的行为进行记录;当经过预设洗白周期时,检测服务器将会检测该实体账户在预设洗白周期内是否存在风险特征行为。
若所述实体账户在所述预设洗白周期内不存在所述风险特征行为,则基于预设洗白规则对所述风险因子进行洗白;
本实施例中,如果该实体账户在预设洗白周期内存在风险特征行为,则不会对其进行洗白;而如果该实体账户在预设洗白周期内不存在风险特征行为,则可基于预设洗白规则对该风险因子进行洗白。例如,对于风险因子可设置一个风险值,该风险值将被设置成可衰减的形式,其衰减程度可以以时间作为度量进行计算(当然也可以从其它维度设置风险衰减规则),例如某一信息因子是在2016年1月被确定为风险因子,其初始的风险值为30;在经过预设洗白周期6个月后,其对应的实体账户不存在风险特征行为,则其风险值开始根据时间和 一预设衰减函数进行衰减;而在2017年6月时该风险因子的风险值衰减至0,则可认为该信息因子不再属于风险因子,即该风险因子被洗白。通过这种风险衰减的方式,可以将一些黑名单信息逐渐洗白,从而在一定程度避免了风险误判的发生。当然,在实际中,若还采用了风险传导的方式进行风险检测,则当某一个风险因子被洗白时,检测服务器将重新根据风险传导的方式检测与该洗白的风险因子关联的因子风险性。
此外,本申请实施例还提供一种基于关联图谱的风险检测装置。
参照图3,图3为本申请基于大数据的风险检测装置第一实施例的功能模块示意图。
本实施例中,所述风险检测装置包括:
信息获取模块10,用于在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;
指纹生成模块20,用于根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;
图谱建立模块30,用于根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;
风险检测模块40,用于基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
其中,上述风险检测装置的各虚拟功能模块存储于图1所示基于关联图谱的风险检测设备的存储器1005中,用于实现计算机可读指令的所有功能;各模块被处理器1001执行时,可实现通过关联图谱的方式进行信息整合和风险检测的功能。
进一步的,图谱建立模块30包括:
信息转译单元,用于基于预设转译规则对所述用户终端指纹和所述注册信息进行转译,得到至少一个因子关系组,其中每个因子关系组中均包括两个信息因子和信息因子之间的关联关系;
图谱生成单元,用于根据所述因子关系组绘制所述实体账户的信 息关联图谱。
进一步的,所述信息关联图谱中包括待检测信息因子和至少一个关联黑名单信息因子,所述待检测信息因子和所述关联黑名单信息因子之间具有关联关系,
所述风险检测模块40包括:
风险值确定单元,用于根据所述关联黑名单信息因子的因子类型确定所述关联黑名单信息因子的黑名单风险值,并根据所述关联黑名单信息因子与所述待检测信息因子之间的关联关系确定对应的关系度;
风险值计算单元,用于根据预设风险传导公式、所述黑名单风险值和所述关系度计算所述待检测信息因子的待检测风险值,并根据所述待检测风险值判断所述待检测信息因子是否属于风险因子,所述预设风险传导公式为:
其中,f为所述待检测信息因子的待检测风险值;
k
i为第i个关联黑名单信息因子对应的关系度,k
i>0,i≥1;
x
i为第i个关联黑名单信息因子对应的黑名单风险值,x
i>0。
进一步的,所述关联黑名单信息因子包括黑名单IP因子,
所述风险检测装置还包括:
IP投放模块,用于向网络中投放预设数量的测试代理IP地址;
IP确定模块,用于当检测到所述测试代理IP地址被代理终端使用并进行攻击行为,获取所述代理终端的真实IP地址,并根据所述真实IP地址确定对应的黑名单IP因子。
进一步的,所述风险检测模块40包括:
账户查询单元,用于在预设账户库中查询与所述信息因子匹配的历史匹配账户,并获取所述历史匹配账户的历史注册时间;
账户数判断单元,用于根据所述历史注册时间统计在预设注册周期内注册的历史匹配账户数,并根据所述历史匹配账户数与预设匹配阈值的大小关系判断所述信息因子是否属于风险因子。
进一步的,所述风险检测装置还包括:
行为检测模块,用于在经过预设洗白周期时,检测所述实体账户在所述预设洗白周期内是否存在风险特征行为;
因子洗白模块,用于若所述实体账户在所述预设洗白周期内不存在所述风险特征行为,则基于预设洗白规则对所述风险因子进行洗白。
进一步的,所述风险检测模块40包括:
等级确定单元,用于统计所述信息关联图谱中的风险因子数,并根据所述风险因子数确定所述实体账户的风险等级;
提示输出单元,用于根据所述实体账户的风险等级输出对应的安全处理提示。
其中,上述风险检测装置中各个模块的功能实现与上述基于关联图谱的风险检测方法实施例中各步骤相对应,其功能和实现过程在此处不再一一赘述。
此外,本申请实施例还提供一种存储介质,所述存储介质可以为非易失性可读存储介质。
本申请存储介质上存储有计算机可读指令,其中所述计算机可读指令被处理器执行时,实现如上述的基于关联图谱的风险检测方法的步骤。
其中,计算机可读指令被执行时所实现的方法可参照本申请基于关联图谱的风险检测方法的各个实施例,此处不再赘述。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者系统不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者系统所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者系统中还存在另外的相同要素。
上述本申请实施例序号仅仅为了描述,不代表实施例的优劣。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现, 当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在如上所述的一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
以上仅为本申请的优选实施例,并非因此限制本申请的专利范围,凡是利用本申请说明书及附图内容所作的等效结构或等效流程变换,或直接或间接运用在其他相关的技术领域,均同理包括在本申请的专利保护范围内。
Claims (20)
- 一种基于关联图谱的风险检测方法,其特征在于,所述风险检测方法包括:在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
- 如权利要求1所述的风险检测方法,其特征在于,所述根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱的步骤包括:基于预设转译规则对所述用户终端指纹和所述注册信息进行转译,得到至少一个因子关系组,其中每个因子关系组中均包括两个信息因子和信息因子之间的关联关系;根据所述因子关系组生成所述实体账户的信息关联图谱。
- 如权利要求1所述的风险检测方法,其特征在于,所述信息关联图谱中包括待检测信息因子和至少一个关联黑名单信息因子,所述待检测信息因子和所述关联黑名单信息因子之间具有关联关系,所述基于预设检测规则检测所述信息关联图谱中的风险因子的步骤包括:根据所述关联黑名单信息因子的因子类型确定所述关联黑名单信息因子的黑名单风险值,并根据所述关联黑名单信息因子与所述待检测信息因子之间的关联关系确定对应的关系度;根据预设风险传导公式、所述黑名单风险值和所述关系度计算所述待检测信息因子的待检测风险值,并根据所述待检测风险值判断所 述待检测信息因子是否属于风险因子,所述预设风险传导公式为:其中,f为所述待检测信息因子的待检测风险值;k i为第i个关联黑名单信息因子对应的关系度,k i>0,i≥1;x i为第i个关联黑名单信息因子对应的黑名单风险值,x i>0。
- 如权利要求3所述的风险检测方法,其特征在于,所述关联黑名单信息因子包括黑名单IP因子,所述风险检测方法还包括:向网络中投放预设数量的测试代理IP地址;当检测到所述测试代理IP地址被代理终端使用并进行攻击行为,获取所述代理终端的真实IP地址,并根据所述真实IP地址确定对应的黑名单IP因子。
- 如权利要求1所述的风险检测方法,其特征在于,所述基于预设检测规则检测所述信息关联图谱中的风险因子的步骤包括:在预设账户库中查询与所述信息因子匹配的历史匹配账户,并获取所述历史匹配账户的历史注册时间;根据所述历史注册时间统计在预设注册周期内注册的历史匹配账户数,并根据所述历史匹配账户数与预设匹配阈值的大小关系判断所述信息因子是否属于风险因子。
- 如权利要求1所述的风险检测方法,其特征在于,所述基于预设检测规则检测所述信息关联图谱中的风险因子的步骤之后,还包括:在经过预设洗白周期时,检测所述实体账户在所述预设洗白周期内是否存在风险特征行为;若所述实体账户在所述预设洗白周期内不存在所述风险特征行为,则基于预设洗白规则对所述风险因子进行洗白。
- 如权利要求1所述的风险检测方法,其特征在于,所述根据所述风险因子输出对应的安全处理提示的步骤包括:统计所述信息关联图谱中的风险因子数,并根据所述风险因子数 确定所述实体账户的风险等级;根据所述实体账户的风险等级输出对应的安全处理提示。
- 一种基于关联图谱的风险检测装置,其特征在于,所述风险检测装置包括:信息获取模块,用于在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;指纹生成模块,用于根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;图谱建立模块,用于根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;风险检测模块,用于基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
- 如权利要求8所述的风险检测装置,其特征在于,所述图谱建立模块包括:信息转译单元,用于基于预设转译规则对所述用户终端指纹和所述注册信息进行转译,得到至少一个因子关系组,其中每个因子关系组中均包括两个信息因子和信息因子之间的关联关系;图谱生成单元,用于根据所述因子关系组绘制所述实体账户的信息关联图谱。
- 如权利要求8所述的风险检测装置,其特征在于,所述信息关联图谱中包括待检测信息因子和至少一个关联黑名单信息因子,所述待检测信息因子和所述关联黑名单信息因子之间具有关联关系,所述风险检测模块包括:风险值确定单元,用于根据所述关联黑名单信息因子的因子类型确定所述关联黑名单信息因子的黑名单风险值,并根据所述关联黑名单信息因子与所述待检测信息因子之间的关联关系确定对应的关系度;风险值计算单元,用于根据预设风险传导公式、所述黑名单风险 值和所述关系度计算所述待检测信息因子的待检测风险值,并根据所述待检测风险值判断所述待检测信息因子是否属于风险因子,所述预设风险传导公式为:其中,f为所述待检测信息因子的待检测风险值;k i为第i个关联黑名单信息因子对应的关系度,k i>0,i≥1;x i为第i个关联黑名单信息因子对应的黑名单风险值,x i>0。
- 如权利要求10所述的风险检测装置,其特征在于,所述关联黑名单信息因子包括黑名单IP因子,所述风险检测装置还包括:IP投放模块,用于向网络中投放预设数量的测试代理IP地址;IP确定模块,用于当检测到所述测试代理IP地址被代理终端使用并进行攻击行为,获取所述代理终端的真实IP地址,并根据所述真实IP地址确定对应的黑名单IP因子。
- 如权利要求8所述的风险检测装置,其特征在于,所述风险检测模块包括:账户查询单元,用于在预设账户库中查询与所述信息因子匹配的历史匹配账户,并获取所述历史匹配账户的历史注册时间;账户数判断单元,用于根据所述历史注册时间统计在预设注册周期内注册的历史匹配账户数,并根据所述历史匹配账户数与预设匹配阈值的大小关系判断所述信息因子是否属于风险因子。
- 如权利要求8所述的风险检测装置,其特征在于,所述风险检测装置还包括:行为检测模块,用于在经过预设洗白周期时,检测所述实体账户在所述预设洗白周期内是否存在风险特征行为;因子洗白模块,用于若所述实体账户在所述预设洗白周期内不存在所述风险特征行为,则基于预设洗白规则对所述风险因子进行洗白。
- 如权利要求8所述的风险检测装置,其特征在于,所述风险检测模块包括:等级确定单元,用于统计所述信息关联图谱中的风险因子数,并根据所述风险因子数确定所述实体账户的风险等级;提示输出单元,用于根据所述实体账户的风险等级输出对应的安全处理提示。
- 一种基于关联图谱的风险检测设备,其特征在于,所述风险检测设备包括处理器、存储器、以及存储在所述存储器上并可被所述处理器执行的计算机可读指令,其中所述计算机可读指令被所述处理器执行时,实现如下步骤:在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
- 如权利要求15所述的风险检测设备,其特征在于,所述根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱的步骤包括:基于预设转译规则对所述用户终端指纹和所述注册信息进行转译,得到至少一个因子关系组,其中每个因子关系组中均包括两个信息因子和信息因子之间的关联关系;根据所述因子关系组生成所述实体账户的信息关联图谱。
- 如权利要求15所述的风险检测设备,其特征在于,所述信息关联图谱中包括待检测信息因子和至少一个关联黑名单信息因子,所述待检测信息因子和所述关联黑名单信息因子之间具有关联关系,所述基于预设检测规则检测所述信息关联图谱中的风险因子的步骤包括:根据所述关联黑名单信息因子的因子类型确定所述关联黑名单 信息因子的黑名单风险值,并根据所述关联黑名单信息因子与所述待检测信息因子之间的关联关系确定对应的关系度;根据预设风险传导公式、所述黑名单风险值和所述关系度计算所述待检测信息因子的待检测风险值,并根据所述待检测风险值判断所述待检测信息因子是否属于风险因子,所述预设风险传导公式为:其中,f为所述待检测信息因子的待检测风险值;k i为第i个关联黑名单信息因子对应的关系度,k i>0,i≥1;x i为第i个关联黑名单信息因子对应的黑名单风险值,x i>0。
- 一种存储介质,其特征在于,所述存储介质上存储有计算机可读指令,其中所述计算机可读指令被处理器执行时,实现如下步骤:在接收到用户终端发送的账户注册请求时,获取所述用户终端的终端特征信息,并获取所述账户注册请求对应实体账户的注册信息;根据所述终端特征信息和预设指纹算法生成所述用户终端唯一对应的用户终端指纹;根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱,所述信息关联图谱中包括两个以上的信息因子、以及不同信息因子之间的关联关系;基于预设检测规则检测所述信息关联图谱中的风险因子,并根据所述风险因子输出对应的安全处理提示。
- 如权利要求18所述的存储介质,其特征在于,所述根据所述用户终端指纹和所述注册信息建立所述实体账户的信息关联图谱的步骤包括:基于预设转译规则对所述用户终端指纹和所述注册信息进行转译,得到至少一个因子关系组,其中每个因子关系组中均包括两个信息因子和信息因子之间的关联关系;根据所述因子关系组生成所述实体账户的信息关联图谱。
- 如权利要求18所述的存储介质,其特征在于,所述信息关联图谱中包括待检测信息因子和至少一个关联黑名单信息因子,所述 待检测信息因子和所述关联黑名单信息因子之间具有关联关系,所述基于预设检测规则检测所述信息关联图谱中的风险因子的步骤包括:根据所述关联黑名单信息因子的因子类型确定所述关联黑名单信息因子的黑名单风险值,并根据所述关联黑名单信息因子与所述待检测信息因子之间的关联关系确定对应的关系度;根据预设风险传导公式、所述黑名单风险值和所述关系度计算所述待检测信息因子的待检测风险值,并根据所述待检测风险值判断所述待检测信息因子是否属于风险因子,所述预设风险传导公式为:其中,f为所述待检测信息因子的待检测风险值;k i为第i个关联黑名单信息因子对应的关系度,k i>0,i≥1;x i为第i个关联黑名单信息因子对应的黑名单风险值,x i>0。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201811254500.2A CN109559192A (zh) | 2018-10-25 | 2018-10-25 | 基于关联图谱的风险检测方法、装置、设备及存储介质 |
| CN201811254500.2 | 2018-10-25 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020082559A1 true WO2020082559A1 (zh) | 2020-04-30 |
Family
ID=65865242
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/122745 Ceased WO2020082559A1 (zh) | 2018-10-25 | 2018-12-21 | 基于关联图谱的风险检测方法、装置、设备及存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN109559192A (zh) |
| WO (1) | WO2020082559A1 (zh) |
Families Citing this family (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110322344A (zh) * | 2019-04-19 | 2019-10-11 | 平安科技(深圳)有限公司 | 一种数据管理方法、装置、电子设备及存储介质 |
| CN110135978B (zh) * | 2019-04-25 | 2021-07-30 | 北京淇瑀信息科技有限公司 | 用户金融风险评估方法、装置、电子设备和可读介质 |
| CN110264210B (zh) * | 2019-05-06 | 2023-08-08 | 创新先进技术有限公司 | 账号正确性的检测方法和装置 |
| CN110223477B (zh) * | 2019-05-31 | 2021-03-23 | 广州仪速安电子科技有限公司 | 一种实验室火灾爆炸预警方法及其系统 |
| TWI778271B (zh) * | 2019-06-24 | 2022-09-21 | 玉山商業銀行股份有限公司 | 電子交易檢核方法及電子交易系統 |
| CN110738388B (zh) * | 2019-09-02 | 2023-09-12 | 深圳壹账通智能科技有限公司 | 关联图谱评估风险传导的方法、装置、设备和存储介质 |
| CN110517097B (zh) * | 2019-09-09 | 2024-02-02 | 广东莞银信息科技股份有限公司 | 识别异常用户的方法、装置、设备及存储介质 |
| CN111080306A (zh) * | 2019-12-17 | 2020-04-28 | 中国建设银行股份有限公司 | 交易风险确定方法、装置、设备及存储介质 |
| CN111125546A (zh) * | 2019-12-25 | 2020-05-08 | 深圳前海微众银行股份有限公司 | 数据处理方法、装置、设备及计算机可读存储介质 |
| CN111401777B (zh) * | 2020-03-30 | 2024-03-12 | 未来地图(深圳)智能科技有限公司 | 企业风险的评估方法、装置、终端设备及存储介质 |
| CN111583037B (zh) * | 2020-04-30 | 2023-04-07 | 支付宝(杭州)信息技术有限公司 | 风险关联对象的确定方法、装置和服务器 |
| CN113761517B (zh) * | 2020-06-03 | 2023-08-11 | 百度在线网络技术(北京)有限公司 | 用于确定第三方sdk的方法、装置、设备及存储介质 |
| CN111724250A (zh) * | 2020-06-29 | 2020-09-29 | 深圳壹账通智能科技有限公司 | 风险传播的确定方法、装置、计算机系统及可读存储介质 |
| CN112184012B (zh) * | 2020-09-27 | 2024-05-31 | 平安资产管理有限责任公司 | 一种企业风险预警方法、装置、设备及可读存储介质 |
| CN112215513A (zh) * | 2020-10-22 | 2021-01-12 | 国网辽宁省电力有限公司营销服务中心 | 一种电力系统用户行为事件的离线分析方法和系统 |
| CN113783828B (zh) * | 2020-11-25 | 2023-09-05 | 北京沃东天骏信息技术有限公司 | 一种业务系统监控方法和装置 |
| CN113762684B (zh) * | 2020-12-14 | 2025-01-17 | 北京沃东天骏信息技术有限公司 | 新用户风险评估方法、装置、电子设备及介质 |
| CN114022206A (zh) * | 2021-11-05 | 2022-02-08 | 广州宸祺出行科技有限公司 | 一种网约车平台的黑名单和白名单的自动化管理方法及装置 |
| CN114170009B (zh) * | 2021-12-15 | 2025-03-25 | 深圳前海微众银行股份有限公司 | 风险评估方法、装置、设备及计算机可读存储介质 |
| CN115470126B (zh) * | 2022-09-05 | 2023-06-20 | 中国电子产品可靠性与环境试验研究所((工业和信息化部电子第五研究所)(中国赛宝实验室)) | 软件安全漏洞模式数据库构建与软件渗透测试方法 |
| CN116050521A (zh) * | 2023-02-09 | 2023-05-02 | 北京奇艺世纪科技有限公司 | 风险防控方法、装置和相关设备 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2015096053A1 (zh) * | 2013-12-25 | 2015-07-02 | 华为技术有限公司 | 一种网络支付方法、装置及系统 |
| CN106998315A (zh) * | 2016-01-22 | 2017-08-01 | 阿里巴巴集团控股有限公司 | 一种注册认证的方法、装置及系统 |
| CN107067157A (zh) * | 2017-03-01 | 2017-08-18 | 北京奇艺世纪科技有限公司 | 业务风险评估方法、装置及风控系统 |
| CN108399509A (zh) * | 2018-04-12 | 2018-08-14 | 阿里巴巴集团控股有限公司 | 确定业务请求事件的风险概率的方法及装置 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106230829B (zh) * | 2016-08-03 | 2019-06-11 | 浪潮通用软件有限公司 | 面向网络威胁发现的虚拟身份知识图谱的构建方法 |
-
2018
- 2018-10-25 CN CN201811254500.2A patent/CN109559192A/zh active Pending
- 2018-12-21 WO PCT/CN2018/122745 patent/WO2020082559A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2015096053A1 (zh) * | 2013-12-25 | 2015-07-02 | 华为技术有限公司 | 一种网络支付方法、装置及系统 |
| CN106998315A (zh) * | 2016-01-22 | 2017-08-01 | 阿里巴巴集团控股有限公司 | 一种注册认证的方法、装置及系统 |
| CN107067157A (zh) * | 2017-03-01 | 2017-08-18 | 北京奇艺世纪科技有限公司 | 业务风险评估方法、装置及风控系统 |
| CN108399509A (zh) * | 2018-04-12 | 2018-08-14 | 阿里巴巴集团控股有限公司 | 确定业务请求事件的风险概率的方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN109559192A (zh) | 2019-04-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020082559A1 (zh) | 基于关联图谱的风险检测方法、装置、设备及存储介质 | |
| TWI734466B (zh) | 針對隱私資料洩漏的風險評估方法及裝置 | |
| CN110111110A (zh) | 基于知识图谱检测欺诈的方法和装置、存储介质 | |
| CN107231382B (zh) | 一种网络威胁态势评估方法及设备 | |
| CN108334417A (zh) | 确定数据异常的方法和装置 | |
| CN112866023A (zh) | 网络检测、模型训练方法、装置、设备及存储介质 | |
| TW201816678A (zh) | 一種非法交易檢測方法及裝置 | |
| CN112784281A (zh) | 一种工业互联网的安全评估方法、装置、设备及存储介质 | |
| CN111786974B (zh) | 一种网络安全评估方法、装置、计算机设备和存储介质 | |
| CN111754241A (zh) | 一种用户行为感知方法、装置、设备及介质 | |
| CN109274639A (zh) | 开放平台异常数据访问的识别方法和装置 | |
| CN105376222A (zh) | 基于云计算平台的智能防御系统 | |
| US9438626B1 (en) | Risk scoring for internet protocol networks | |
| CN110213255A (zh) | 一种对主机进行木马检测的方法、装置及电子设备 | |
| CN111259404B (zh) | 中毒样本生成方法、装置、设备及计算机可读存储介质 | |
| CN112738018A (zh) | Arp欺骗攻击检测方法、装置、计算机设备和存储介质 | |
| CN114676231A (zh) | 一种目标信息检测方法、设备和介质 | |
| CN115391230A (zh) | 一种测试脚本生成、渗透测试方法、装置、设备及介质 | |
| CN108509796A (zh) | 一种风险性的检测方法及服务器 | |
| CN110955890B (zh) | 恶意批量访问行为的检测方法、装置和计算机存储介质 | |
| CN115499205A (zh) | 异常外联行为的检测方法及装置、存储介质及电子设备 | |
| JP6258189B2 (ja) | 特定装置、特定方法および特定プログラム | |
| CN108282468A (zh) | 一种应用层DDoS攻击检测方法及装置 | |
| CN109636575A (zh) | 终端风险检测方法、装置、设备及可读存储介质 | |
| CN112541183B (zh) | 数据处理方法及装置、边缘计算设备、存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18938214 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 16/06/2021) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18938214 Country of ref document: EP Kind code of ref document: A1 |




