Method and Apparatus of Identifying User Risk
Abstract
The present disclosure provides techniques to identify suspicious user logins. These techniques may include acquiring, by a computing device, a routing path associated with a user login based on login information. The computing device may extract current routing characteristic information from the routing path, and identify whether the current user login is suspicious based on the current routing characteristic information. These techniques reduce the influence of IP address changes on user identification as well as errors associated with user identification, and identify geographic positions more accurately.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving, by a server, login information of a user; acquiring a routing path based on the login information of the user; extracting routing characteristic information from the routing path; and determining a risk associated with the user based on the routing characteristic information.
2 . The method of claim 1 , wherein the login information of the user includes a user identity, information of a client terminal on which the user initiates a login request, and information of the server.
3 . The method of claim 2 , wherein the acquiring the routing path based on the login information of the user comprises:
sending, by the server, a routing discovery message to the client terminal; determining routing node information using hop-by-hop routing corresponding to the routing discovery message; and generating the routing path based on the routing node information.
4 . The method of claim 3 , wherein the acquiring the routing path based on the login information of the user comprises:
receiving, by the server, the routing discovery message from a client terminal; determining routing node information using hop-by-hop routing corresponding to the routing discovery message; and generating the routing path based on the routing node information.
5 . The method of claim 1 , wherein the extracting routing characteristic information from the routing path comprises:
extracting information of a key router from the routing path; and generating the routing characteristic information based on the information of the key router.
6 . The method of claim 5 , wherein the information of the key router includes information of a router having an amount of traffic greater than a preset threshold.
7 . The method of claim 1 , wherein the determining the risk associated with the user based on the routing characteristic information comprises:
retrieving historical routing characteristic information corresponding to the user; and determining the risk by comparing the historical routing characteristic information with the routing characteristic information.
8 . The method of claim 1 , wherein the login information of the user includes a machine identity, and the determining the degree of risk associated with the user based on the routing characteristic information comprises:
presetting one or more correspondences between a machine identity and a user class that includes multiple users each having the path characteristic information; and determining the risk associated with the user based on the one or more correspondences.
9 . A system comprising:
one or more processors; and memory to maintain a plurality of components executable by the one or more processors, the plurality of components comprising:
a routing path acquisition module configured to:
receive login information of a user, and
acquire a routing path based on the login information of the user,
a current path extraction module configured to extract routing characteristic information from the routing path, and
a risk judgment module configured to determining a risk associated with the user based on the routing characteristic information.
10 . The system of claim 9 , wherein the login information of the user includes a user identity, information of a client terminal on which the user initiates a login request, and information of a server associated with the system, and the acquiring the routing path based on the login information of the user comprises:
sending a routing discovery message to the client terminal; determining routing node information using hop-by-hop routing corresponding to the routing discovery message; and generating the routing path based on the routing node information.
11 . The system of claim 10 , wherein the acquiring the routing path based on the login information of the user comprises:
receiving the routing discovery message from a client terminal; determining routing node information using hop-by-hop routing corresponding to the routing discovery message; and generating the routing path based on the routing node information.
12 . The system of claim 9 , wherein the extracting routing characteristic information from the routing path comprises:
extracting information of a key router from the routing path; and generating the routing characteristic information based on the information of the key router.
13 . The system of claim 12 , wherein the information of the key router includes information of a router having an amount of traffic greater than a preset threshold.
14 . The system of claim 9 , wherein the determining the risk associated with the user based on the routing characteristic information comprises:
retrieving historical routing characteristic information corresponding to the user; and determining the risk by comparing the historical routing characteristic information with the routing characteristic information.
15 . The system of claim 9 , wherein the login information of the user includes a machine identity, and the determining the degree of risk associated with the user based on the routing characteristic information comprises:
presetting one or more correspondences between a machine identity and a user class that includes multiple users each having the path characteristic information; and determining the risk associated with the user based on the one or more correspondences.
16 . One or more computer-readable media storing computer-executable instructions that, when executed by one or more processors, instruct the one or more processors to perform acts comprising:
receiving login information of a user; acquiring a routing path based on the login information of the user; extracting routing characteristic information from the routing path; and determining a risk associated with the user based on the routing characteristic information.
17 . The one or more computer-readable media of claim 16 , wherein the login information of the user includes a user identity, information of a client terminal on which the user initiates a login request, and information of a server, and the acquiring the routing path based on the login information of the user comprises:
sending, by the server, a routing discovery message to the client terminal; determining routing node information using hop-by-hop routing corresponding to the routing discovery message; and generating the routing path based on the routing node information.
18 . The one or more computer-readable media of claim 17 , wherein the routing discovery message is an Internet Control Message Protocol (ICMP) discovery message.
19 . The one or more computer-readable media of claim 18 , wherein the routing node information is associated with one or more nodes, and traffic of an individual node of the one or more nodes is greater than a predetermined value.
20 . The one or more computer-readable media of claim 16 , wherein the determining the degree of risk comprising determining the degree of risk by comparing the routing node information and particular routing node information that is recorded within a predetermined time period.Join the waitlist — get patent alerts
Track US2014033306A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.