Abnormal login detection method and device, equipment and storage medium
By obtaining user login log data and determining the normal login time range and abnormal threshold using DBSCAN algorithm and statistical analysis, the problem that traditional security protection mechanisms are difficult to detect complex attack methods is solved, and high-precision and efficient abnormal login detection is achieved.
Patent Information
- Application Number
- CN202510262117.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-27
AI Technical Summary
Traditional security protection mechanisms are difficult to deal with complex and changeable attack methods, such as brute force cracking and disguised login, and abnormal login behavior is highly hidden and random, making it difficult to accurately detect through simple log analysis.
By obtaining user login log data, density clustering analysis is used to determine the user's normal login time range; at the same time, based on statistical analysis of historical login data, abnormal login threshold is determined; if the current login time is not within the normal range or the number of login failures exceeds the threshold, it is determined to be abnormal login behavior.
Effectively identify and prevent abnormal behaviors such as brute-force cracking and abnormal time login, improve the accuracy and efficiency of abnormal login detection, and reduce false alarms and missed reports.
Smart Images

Figure CN120050110A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to an abnormal login detection method, device, equipment and storage medium. Background Art
[0002] With the development of information technology, more and more systems and applications rely on the network for operation, making user identity authentication and login behavior detection the key to system security protection. However, traditional security protection mechanisms are usually difficult to cope with complex and changeable attack methods, such as brute force cracking and disguised login. Current protection measures mostly rely on static rules or fixed threshold settings, lack dynamic adjustment capabilities, and are prone to false positives or false negatives.
[0003] In addition, abnormal login behaviors are often hidden and random, and it is difficult to capture the full picture of abnormal behaviors through simple log analysis, which reduces the accuracy of abnormal login behavior detection and network security protection capabilities. Summary of the invention
[0004] In view of this, the purpose of this application is to provide an abnormal login detection method, device, equipment and storage medium, which can effectively identify and prevent abnormal login behaviors such as brute force cracking and logging in at abnormal times, while improving the accuracy and efficiency of abnormal login detection. The specific scheme is as follows:
[0005] In a first aspect, the present application discloses a method for detecting abnormal login, comprising:
[0006] When a user login operation is detected, the login log data of the currently logged-in target user is obtained to obtain the current login data; the current login data includes the current login time and the number of current login failures within a preset time window;
[0007] Determine whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of failed logins exceeds the abnormal login threshold corresponding to the target user; the normal login time range is a normal login time period obtained by performing density clustering analysis on login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by a distribution parameter obtained by performing statistical analysis on the number of failed logins of different users within the preset time window based on the historical login data;
[0008] If the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior.
[0009] Optionally, the abnormal login detection method further includes:
[0010] Collect logs related to different user logins to obtain historical login data;
[0011] Perform feature extraction on the historical login data to obtain user login information containing target fields; the target fields include a login user field, a login time field, a login IP field, and a login result field;
[0012] Dividing the user login information according to the preset time window to obtain a plurality of divided login information, and counting the number of login failures of each user in each preset time window based on the divided login information;
[0013] Calculate the distribution parameters corresponding to the number of failed logins in all preset time windows; the distribution parameters include the mean value and standard deviation of the number of failed logins;
[0014] Determine an abnormal login threshold corresponding to each user based on the distribution parameter;
[0015] The DBSCAN algorithm is used to perform density cluster analysis on the login time data corresponding to different users in the historical login data to obtain the normal login time period of the corresponding users and obtain the normal login time range.
[0016] Optionally, determining an abnormal login threshold corresponding to each user based on the distribution parameter includes:
[0017] The product of the standard deviation in the distribution parameter and the preset proportional factor is calculated, and the sum of the average value in the distribution parameter and the product is calculated to obtain the abnormal login threshold of the corresponding user.
[0018] Optionally, the use of the DBSCAN algorithm to perform density cluster analysis on the login time data corresponding to different users in the historical login data to obtain the normal login time period of the corresponding user and obtain the normal login time range includes:
[0019] Convert the login time data corresponding to different users in the historical login data according to a preset timing method to obtain converted time data;
[0020] Perform density cluster analysis on the converted time data using the DBSCAN algorithm to calculate the absolute distance between each historical login time point and other login time points, and determine whether the historical login time point is a core point based on the absolute distance, a preset neighborhood radius, and a preset minimum number of points;
[0021] If the historical login time point is a core point, the core point and other login time points within the corresponding preset neighborhood radius are aggregated to form a node cluster;
[0022] A cluster with the largest number of nodes is determined from all the node clusters to obtain a target cluster, and a normal login time period of a corresponding user is determined based on a minimum time and a maximum time in the target cluster to obtain a normal login time range of the corresponding user.
[0023] Optionally, judging whether the historical login time point is a core point based on the absolute distance, a preset neighborhood radius and a preset minimum number of points includes:
[0024] Counting the number of other login time points within a preset neighborhood radius of each of the historical login time points to obtain the number of login nodes, and determining whether the number of login nodes is greater than or equal to a preset minimum number of points;
[0025] If the number of login nodes is greater than or equal to the preset minimum number of points, the current historical login time point is determined to be a core point.
[0026] Optionally, after determining that the target user has abnormal login behavior, the method further includes:
[0027] Collecting logs related to logins of different users according to a first time period to obtain first login data, and updating the abnormal login threshold corresponding to each user based on the first login data;
[0028] Logs related to logins of different users are collected according to a second time period to obtain second login data, and the normal login time range corresponding to each user is updated based on the second login data.
[0029] Optionally, the abnormal login detection method further includes:
[0030] When a login failure operation is detected, the login failure time and the corresponding user ID are obtained, and the login failure time and the corresponding user ID are saved in a preset cache set;
[0031] When the preset expiration time is reached, the data before the preset time length in the preset cache set is cleared; the preset time length is the product of the preset time window and a preset coefficient.
[0032] In a second aspect, the present application discloses an abnormal login detection device, comprising:
[0033] A data acquisition module is used to acquire the login log data of the currently logged-in target user when a user login operation is monitored, and obtain the current login data; the current login data includes the current login time and the number of current login failures within a preset time window;
[0034] A judgment module is used to judge whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is a normal login time period obtained by performing density clustering analysis on login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by using a distribution parameter obtained by performing statistical analysis on the number of login failures of different users within the preset time window based on the historical login data;
[0035] The determination module is used to determine that the target user has abnormal login behavior if the current login time is not within the normal login time range corresponding to the target user and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user.
[0036] In a third aspect, the present application discloses an electronic device, comprising a processor and a memory; wherein the processor implements the aforementioned abnormal login detection method when executing a computer program stored in the memory.
[0037] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned abnormal login detection method is implemented.
[0038] It can be seen that when the present application monitors a user login operation, the login log data of the currently logged-in target user is obtained to obtain the current login data; the current login data includes the current login time and the current number of login failures within the preset time window; it is determined whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is the normal login time period obtained after density clustering analysis of login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by the distribution parameters obtained after statistical analysis of the number of login failures of different users within the preset time window based on the historical login data; if the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior. The present application pre-uses the DBSCAN algorithm to perform a density clustering analysis on the login time data in the historical login data of different users, thereby generating a normal login time range corresponding to different users, and uses the distribution parameters obtained after statistical analysis of the number of login failures of different users within a preset time window based on the historical login data to determine the abnormal login thresholds corresponding to different users. In this way, based on the pre-generated normal login time range and abnormal login threshold corresponding to each user, real-time detection of abnormal login behaviors such as brute force cracking and abnormal time login can be performed. Through the above-mentioned abnormal login detection mechanism based on the DBSCAN algorithm and statistical analysis, not only can brute force cracking and abnormal login time and other abnormal login behaviors be effectively identified and prevented, but also the accuracy and efficiency of abnormal login detection are improved, thereby reducing false alarms and omissions. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0040] Figure 1 A flow chart of an abnormal login detection method disclosed in this application;
[0041] Figure 2 A specific abnormal login detection method flow chart disclosed in this application;
[0042] Figure 3 This is a schematic diagram of the structure of an abnormal login detection device disclosed in this application;
[0043] Figure 4 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0044] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0045] The present application discloses a method for detecting abnormal login. Figure 1 As shown, the method includes:
[0046] Step S11: when a user login operation is monitored, the login log data of the currently logged-in target user is obtained to obtain current login data; the current login data includes the current login time and the current number of login failures within a preset time window.
[0047] In this embodiment, when it is monitored that a user has performed a login operation on a certain device, the login log data of the target user who is currently performing the login operation is first collected to obtain the corresponding current login data; wherein the current login data specifically includes the current login time and the current number of login failures within a preset time window, and the length of the preset time window can be selected according to actual application requirements.
[0048] Specifically, when collecting login log data, you can use log management tools, such as Graylog (a tool used to save system logs syslog to MongoDB) to collect the original logs of the Syslog (system log or system record) protocol, so as to obtain login log data related to the current logged-in user from multiple sources (such as servers, network devices, firewalls, etc.). For example, by capturing the log traffic of the firewall through the Graylog tool, you can obtain the traffic log information related to the user login, which usually includes the success and failure records of login attempts, source IP addresses (Source IP Address), timestamps and other information.
[0049] Step S12: Determine whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is the normal login time period obtained by density clustering analysis of login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by distribution parameters obtained by statistical analysis of the number of login failures of different users within the preset time window based on the historical login data.
[0050] In this embodiment, after obtaining the current login data of the target user, it is determined whether the current login time in the current login data is within the normal login time range corresponding to the target user, and / or whether the current number of login failures in the current login data exceeds the abnormal login threshold corresponding to the target user.
[0051] It is understandable that the login behavior of normal users usually has a regularity in time. For example, office users usually log in during working hours. Therefore, it is possible to determine whether the currently logged-in user has abnormal login behavior by setting the normal login time range. In addition, abnormal login behavior of brute force cracking is usually accompanied by multiple login failures. Therefore, the number of login failures of the logged-in user can be counted to determine whether the logged-in user has abnormal login behavior based on the number of login failures obtained by statistics.
[0052] It should be pointed out that the normal login time range is the normal login time period obtained by density clustering analysis of login time data in historical login data of different users using the DBSCAN algorithm (Density-Based Spatial Clustering of Applications with Noise, a density-based clustering algorithm); the abnormal login threshold is a threshold determined by the distribution parameters obtained by statistical analysis of the number of login failures of different users within the preset time window based on the historical login data.
[0053] Specifically, the process of determining the abnormal login threshold and the normal login time range may include: collecting logs related to different user logins to obtain historical login data; performing feature extraction on the historical login data to obtain user login information containing target fields; the target fields include a login user field, a login time field, a login IP field, and a login result field; dividing the user login information according to a preset time window to obtain multiple divided login information, and based on the divided login information, counting the number of login failures of each user in each preset time window; calculating the distribution parameters corresponding to the number of login failures in all preset time windows; the distribution parameters include the mean and standard deviation of the number of login failures; determining the abnormal login threshold corresponding to each user based on the distribution parameters; using the DBSCAN algorithm to perform density clustering analysis on the login time data corresponding to different users in the historical login data to obtain the normal login time period of the corresponding user and obtain the normal login time range. In this embodiment, the login logs of different users U who log in to a certain device can be collected first to obtain historical login data, and then the collected historical login data can be cleaned and formatted to eliminate invalid data and redundant information; then, the collected historical login data can be feature extracted and formatted to obtain user login information including at least target fields such as login user field, login time field, login IP (Internet Protocol) field and login result field (such as login failure, login success). For example, the login time is converted to a unified time zone; in addition, the missing fields need to be completed. For example, when the login time is missing in the original log collected by the Graylog tool, the log timestamp is used to supplement it, and the logs that cannot be completed can be directly eliminated.
[0054] Next, the user login information is divided according to the preset time window w (such as n minutes) to obtain multiple divided login information, and the login behaviors in each time window w (such as n minutes) are grouped. For example, based on the divided login information, the number of login failures of each user U in each preset time window w (such as n minutes) is counted, and the number of login failures in all time windows is summarized into a list; then, the number of login failures in all preset time windows w (such as n minutes) is calculated. Corresponding distribution parameters; wherein the distribution parameters include the average value of the number of login failures and standard deviation , the preset time window can be dynamically adjusted according to the actual application requirements; finally, the abnormal login threshold corresponding to each user U is determined based on the calculated distribution parameters, and the DBSCAN algorithm is used to perform density clustering analysis on the login time data corresponding to different users U in the above historical login data, so as to obtain the normal login time period of the corresponding user U, that is, the normal login time range. It should be pointed out that in this embodiment, it is assumed that the number of login failures in each time window w (such as n minutes) follows a normal distribution, so the average value can be calculated. and standard deviation To determine login abnormalities.
[0055] Specifically, determining the abnormal login threshold corresponding to each user based on the distribution parameter may include: calculating the product of the standard deviation in the distribution parameter and a preset proportional factor, and calculating the sum of the average value in the distribution parameter and the product to obtain the abnormal login threshold of the corresponding user. In this embodiment, the abnormal login threshold m is specifically based on the standard deviation in the distribution parameter. and average , and the preset scale factor k is calculated, and the specific calculation formula is: m=μ+k*σ. For example, when the preset scale factor k is 2, m=μ+2σ.
[0056] in, , ;
[0057] In the formula, is the number of failed logins in the i-th time window, and L is the total number of all time windows. By calculating the average and standard deviation of failed logins to dynamically set the abnormal login threshold, it can adapt to abnormal login behavior detection in various scenarios, such as effective detection of abnormal login behavior of brute force cracking.
[0058] In this embodiment, the use of the DBSCAN algorithm to perform density clustering analysis on the login time data corresponding to different users in the historical login data to obtain the normal login time period of the corresponding users and obtain the normal login time range can specifically include: converting the login time data corresponding to different users in the historical login data according to a preset timing method to obtain converted time data; using the DBSCAN algorithm to perform density clustering analysis on the converted time data to calculate the absolute distance between each historical login time point and other login time points, and judging whether the historical login time point is a core point based on the absolute distance, a preset neighborhood radius and a preset minimum number of points; if the historical login time point is a core point, aggregating the core point and other login time points within the corresponding preset neighborhood radius to form a node cluster; determining the cluster containing the largest number of nodes from all the node clusters to obtain a target cluster, and determining the normal login time period of the corresponding user based on the minimum time and maximum time in the target cluster to obtain the normal login time range of the corresponding user. In this embodiment, after collecting historical login data (including user name and login time), the login time data corresponding to different users in the historical login data can be converted according to a preset timing method to obtain converted time data. For example, the login time in the historical login data is converted into minutes starting from 00:00 of the current day, T=H×60+M, where H is the number of hours and M is the number of minutes, for example, 08:30 is converted to 510.
[0059] Furthermore, the DBSCAN algorithm is used to perform density cluster analysis on the converted time data to calculate the absolute distance between each historical login time point and other login time points, and then based on the absolute distance, the preset neighborhood radius in the DBSCAN algorithm and the preset minimum number of points minPts to determine whether the corresponding historical login time point is a core point, where the minimum number of points minPts means that a cluster must contain at least this number of login records to be considered a normal time period; if the historical login time point is a core point, the core point and its neighborhood radius are The other login time points in the cluster are aggregated to form a node cluster, and then a cluster with the largest number of nodes is determined from all the node clusters, and the normal login time period of the corresponding user is determined based on the minimum time and maximum time in the cluster with the largest number of nodes, that is, the normal login time range. For example, when the minimum time in the cluster with the largest number of nodes is 08:30 (i.e., 510 minutes) and the maximum time is 09:30 (570 minutes), the normal time range is 08:30-09:30. By selecting the cluster with the most nodes from the clusters formed by clustering and using it as the normal login time range of the user, the false alarm rate and missed alarm rate of abnormal login detection can be effectively reduced.
[0060] In this embodiment, the determination of whether the historical login time point is a core point based on the absolute distance, the preset neighborhood radius and the preset minimum number of points may specifically include: counting the number of other login time points within the preset neighborhood radius of each historical login time point to obtain the number of login nodes, and determining whether the number of login nodes is greater than or equal to the preset minimum number of points; if the number of login nodes is greater than or equal to the preset minimum number of points, determining that the current historical login time point is a core point. For example, assuming that the login times within 1 hour are closely related, then , and set the minimum number of points minPts to 5 or more, that is, a cluster contains at least 5 login records to be considered a normal time period, you can first perform density clustering analysis on the pre-processed minute data, and for each login time point , calculate the time point With other time points The absolute distance between , the specific calculation formula is:
[0061] .
[0062] For each login time , find its neighborhood radius For all points within, if the neighborhood radius If the number of points in the time is greater than or equal to minPts (such as 5), the login time point is considered is a core point; if the neighborhood radius The number of points in the neighborhood is less than minPts (such as 5), but within the neighborhood radius of a core point If the login time is within It is a boundary point.
[0063] Furthermore, all core points and points in their neighborhood can be merged to form clusters. If a login node does not belong to any cluster, it will be marked as a noise point and regarded as a node with abnormal login behavior.
[0064] Step S13: If the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior.
[0065] In this embodiment, if the current login time is outside the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user (such as m=μ+2σ), then it is determined that the target user has abnormal login behavior. That is, as long as it deviates from the normal login time range and / or exceeds the abnormal login threshold, it is determined that there is abnormal login behavior.
[0066] In a specific implementation, it is possible to first determine whether the current login time falls within the normal login time range corresponding to the target user (such as 08:30-18:30). If the current login time falls outside the normal login time range corresponding to the target user (such as 08:30-18:30), it is then determined whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user. If the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior. Detecting abnormal login behavior from two dimensions, abnormal login threshold and normal login time range, can more comprehensively identify abnormal login behavior, which not only improves the accuracy of detection, but also better adapts to changing attack patterns.
[0067] It should be pointed out that the normal login time range and abnormal login threshold corresponding to each user can be saved in a preset data structure to improve detection efficiency and accuracy.
[0068] Further, after determining that the target user has abnormal login behavior, it may also include: generating abnormal login alarm information for the target user, and sending the abnormal login alarm information to the target terminal according to a preset sending method. In this embodiment, in order to timely block abnormal login behavior, avoid information leakage and network security caused by abnormal login behaviors such as brute force cracking and disguised login, and realize effective monitoring and timely response to abnormal login behavior, after monitoring the existence of abnormal login behavior, detailed abnormal login alarm information for the current login user (which may include abnormal login user name, abnormal login time, login user ID, abnormal login type, etc.) can be generated, and then the abnormal login alarm information is sent to the target terminal, such as the target user terminal, the system administrator terminal, etc., according to a preset sending method, such as through email, SMS or other instant messaging tools, so that the corresponding terminal can respond accordingly in time after receiving the alarm information, and take necessary protective measures, thereby improving the overall security and response efficiency of the system, such as automatically or manually triggering the corresponding device action according to the preset strategy, for example, when an abnormal login behavior of the brute force type occurs, the login user and login IP are temporarily banned.
[0069] It can be seen that when the embodiment of the present application monitors a user login operation, the login log data of the currently logged-in target user is obtained to obtain the current login data; the current login data includes the current login time and the current number of login failures within the preset time window; it is determined whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is the normal login time period obtained after density clustering analysis of login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by the distribution parameters obtained after statistical analysis of the number of login failures of different users within the preset time window based on the historical login data; if the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior. The embodiment of the present application uses the DBSCAN algorithm to perform density clustering analysis on the login time data in the historical login data of different users in advance, thereby generating normal login time ranges corresponding to different users, and uses the distribution parameters obtained after statistical analysis of the number of login failures of different users within a preset time window based on the historical login data to determine the abnormal login thresholds corresponding to different users. In this way, based on the pre-generated normal login time range and abnormal login threshold corresponding to each user, real-time detection of abnormal login behaviors such as brute force cracking and abnormal time login can be performed. Through the above-mentioned abnormal login detection mechanism based on the DBSCAN algorithm and statistical analysis, not only can brute force cracking and abnormal login at abnormal time be effectively identified and prevented, but also the accuracy and efficiency of abnormal login detection are improved, thereby reducing false alarms and omissions.
[0070] The present application embodiment discloses a specific abnormal login detection method, see Figure 2 As shown, the method includes:
[0071] Step S21: when a user login operation is monitored, the login log data of the currently logged-in target user is obtained to obtain current login data; the current login data includes the current login time and the current number of login failures within a preset time window.
[0072] Step S22: Determine whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is the normal login time period obtained by density clustering analysis of login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by distribution parameters obtained by statistical analysis of the number of login failures of different users within the preset time window based on the historical login data.
[0073] Step S23: If the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior.
[0074] Step S24: collecting logs related to logins of different users according to a first time period to obtain first login data, and updating the abnormal login threshold corresponding to each user based on the first login data.
[0075] In this embodiment, logs related to logins of different users may be collected according to a first time period (e.g., every week) to obtain first login data, and then the abnormal login threshold corresponding to each user may be updated based on the first login data. In addition, the abnormal login threshold may be continuously optimized in combination with feedback from users and system administrators, thereby improving the accuracy and real-time performance of abnormal login behavior detection.
[0076] Step S25: collecting logs related to logins of different users according to a second time period to obtain second login data, and updating the normal login time range corresponding to each user based on the second login data.
[0077] In this embodiment, logs related to logins of different users may be collected according to a second time period (e.g., every month) to obtain second login data, and the normal login time range corresponding to each user may be updated based on the second login data. At the same time, the normal login time range may be continuously updated in combination with feedback from users and system administrators, thereby improving the accuracy and real-time performance of abnormal login behavior detection.
[0078] In this embodiment, the abnormal login detection for brute force type may also include: when a login failure operation is detected, the login failure time and the corresponding user identifier are obtained, and the login failure time and the corresponding user identifier are saved in a preset cache set; when the preset expiration time is reached, the data before the preset time length in the preset cache set is cleared; the preset time length is the product of the preset time window and the preset coefficient. For example, when a login failure operation is detected, the login failure timestamp and the corresponding user name are saved in the preset cache set bCacheSet, and each element in the cache set bCacheSet is composed of the following: member: represents the user name or user identifier; score: timestamp, indicating the user's login failure time. In addition, the key in the cache set bCacheSet is used to store the user name, and the set also provides functions such as adding elements, querying the number of elements in the set, clearing expired elements according to the time range, and setting the overall expiration time of the set. The specific steps to implement brute force detection are as follows:
[0079] First, insert the new login failure record into the cache set bCacheSet through the add element function, and the score in the set is the current timestamp. Then, for each login failure record, use the clear expired element function according to the time range to clear the expired data in the cache set bCacheSet within the specified time interval (such as the current time moving forward the preset time window n minutes), so as to ensure that only the login failure records within the preset time window are retained. Further, use the query element number function in the set to obtain the number of login failures within the current time window n minutes. If the number of login failures within the current time window exceeds the preset threshold (i.e., the trigger threshold m of brute force cracking), it is determined that there is an abnormal login behavior of the brute force cracking type, and the current user information and current login time are recorded, and the corresponding abnormal login alarm information has been generated. Finally, the overall expiration time function of the cache set bCacheSet can be used to set the expiration time of the cache set to twice the time window size, i.e., 2n. In this way, old data can be automatically cleared to avoid data occupying cache resources for a long time.
[0080] For more specific processing procedures of the above steps S21 to S23, reference may be made to the corresponding contents disclosed in the above embodiments, which will not be described in detail here.
[0081] It can be seen that after obtaining the abnormal login threshold and normal login time range of each user, the embodiment of the present application updates them according to the preset time period, which can continuously optimize the judgment basis of abnormal login detection, thereby improving the accuracy of abnormal login detection and effectively reducing the false alarm rate and missed alarm rate.
[0082] Correspondingly, the present application also discloses an abnormal login detection device, see Figure 3 As shown, the device comprises:
[0083] The data acquisition module 11 is used to acquire the login log data of the currently logged-in target user when a user login operation is monitored, and obtain the current login data; the current login data includes the current login time and the number of current login failures within a preset time window;
[0084] The judgment module 12 is used to judge whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is a normal login time period obtained by performing density clustering analysis on login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by using a distribution parameter obtained by performing statistical analysis on the number of login failures of different users within the preset time window based on the historical login data;
[0085] The determination module 13 is used to determine that the target user has abnormal login behavior if the current login time is not within the normal login time range corresponding to the target user and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user.
[0086] Among them, the specific working processes of the above-mentioned modules can refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.
[0087] It can be seen that in the embodiment of the present application, when a user login operation is monitored, the login log data of the currently logged-in target user is obtained to obtain the current login data; the current login data includes the current login time and the current number of login failures within the preset time window; it is determined whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; the normal login time range is the normal login time period obtained after density clustering analysis of login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by the distribution parameters obtained after statistical analysis of the number of login failures of different users within the preset time window based on the historical login data; if the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior. The embodiment of the present application uses the DBSCAN algorithm to perform density clustering analysis on the login time data in the historical login data of different users in advance, thereby generating normal login time ranges corresponding to different users, and uses the distribution parameters obtained after statistical analysis of the number of login failures of different users within a preset time window based on the historical login data to determine the abnormal login thresholds corresponding to different users. In this way, based on the pre-generated normal login time range and abnormal login threshold corresponding to each user, real-time detection of abnormal login behaviors such as brute force cracking and abnormal time login can be performed. Through the above-mentioned abnormal login detection mechanism based on the DBSCAN algorithm and statistical analysis, not only can brute force cracking and abnormal login at abnormal time be effectively identified and prevented, but also the accuracy and efficiency of abnormal login detection are improved, thereby reducing false alarms and omissions.
[0088] In some specific embodiments, the abnormal login detection device may further include:
[0089] The first collection unit is used to collect logs related to logins of different users to obtain historical login data;
[0090] A feature extraction unit, used to extract features from the historical login data to obtain user login information containing target fields; the target fields include a login user field, a login time field, a login IP field, and a login result field;
[0091] A division unit, used to divide the user login information according to a preset time window to obtain a plurality of divided login information;
[0092] A statistical unit, used for counting the number of login failures of each user within each preset time window based on the divided login information;
[0093] A first calculation unit, configured to calculate distribution parameters corresponding to the number of failed logins in all preset time windows; the distribution parameters include a mean value and a standard deviation of the number of failed logins;
[0094] A threshold determination unit, configured to determine an abnormal login threshold corresponding to each user based on the distribution parameter;
[0095] The first cluster analysis unit is used to perform density cluster analysis on the login time data corresponding to different users in the historical login data by using the DBSCAN algorithm to obtain the normal login time period of the corresponding user and obtain the normal login time range.
[0096] In some specific embodiments, the threshold determination unit may specifically include:
[0097] The second calculation unit is used to calculate the product of the standard deviation in the distribution parameter and the preset proportional factor, and calculate the sum of the average value in the distribution parameter and the product to obtain the abnormal login threshold of the corresponding user.
[0098] In some specific embodiments, the first cluster analysis unit may specifically include:
[0099] A data conversion unit, used to convert the login time data corresponding to different users in the historical login data according to a preset timing method to obtain converted time data;
[0100] A second cluster analysis unit is used to perform density cluster analysis on the converted time data using a DBSCAN algorithm to calculate the absolute distance between each historical login time point and other login time points, and determine whether the historical login time point is a core point based on the absolute distance, a preset neighborhood radius and a preset minimum number of points;
[0101] an aggregation unit, configured to aggregate the core point and other login time points within the corresponding preset neighborhood radius to form a node cluster if the historical login time point is a core point;
[0102] A node cluster determination unit, used to determine a cluster containing the largest number of nodes from all the node clusters to obtain a target cluster;
[0103] The time period determination unit is used to determine the normal login time period of the corresponding user based on the minimum time and the maximum time in the target cluster to obtain the normal login time range of the corresponding user.
[0104] In some specific embodiments, the second cluster analysis unit may specifically include:
[0105] A number counting unit, used to count the number of other login time points within a preset neighborhood radius of each of the historical login time points, to obtain the number of login nodes;
[0106] A judging unit, used to judge whether the number of login nodes is greater than or equal to a preset minimum number of points;
[0107] A determination unit is used to determine that the current historical login time point is a core point if the number of login nodes is greater than or equal to a preset minimum number of points.
[0108] In some specific embodiments, after the determination module 13, the following may also be included:
[0109] A second collection unit is used to collect logs related to logins of different users according to a first time period to obtain first login data;
[0110] A first updating unit, configured to update the abnormal login threshold corresponding to each user based on the first login data;
[0111] A third collection unit is used to collect logs related to logins of different users according to a second time period to obtain second login data;
[0112] The second updating unit is used to update the normal login time range corresponding to each user based on the second login data.
[0113] In some specific embodiments, after the determination module 13, the following may also be included:
[0114] An acquisition and storage unit, configured to acquire a login failure time and a corresponding user ID when a login failure operation is detected, and store the login failure time and the corresponding user ID in a preset cache set;
[0115] The clearing unit is used to clear the data before the preset time length in the preset cache set when the preset expiration time is reached; the preset time length is the product of the preset time window and the preset coefficient.
[0116] Furthermore, the present application also discloses an electronic device. Figure 4 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.
[0117] Figure 4A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the abnormal login detection method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0118] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0119] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0120] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the abnormal login detection method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0121] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the abnormal login detection method disclosed above. The specific steps of the method can refer to the corresponding contents disclosed in the above embodiments, and will not be repeated here.
[0122] Furthermore, an embodiment of the present application also discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the abnormal login detection method disclosed above.
[0123] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0124] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0125] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0126] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0127] The above is a detailed introduction to an abnormal login detection method, device, equipment and storage medium provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for detecting abnormal login, characterized in that: include: When a user login operation is detected, the login log data of the currently logged-in target user is obtained to obtain the current login data; The current login data includes the current login time and the number of current login failures within a preset time window; Determine whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; The normal login time range is a normal login time period obtained by performing density cluster analysis on login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by a distribution parameter obtained by performing statistical analysis on the number of login failures of different users within the preset time window based on the historical login data; If the current login time is not within the normal login time range corresponding to the target user, and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user, it is determined that the target user has abnormal login behavior.
2. The abnormal login detection method according to claim 1, characterized in that: Also includes: Collect logs related to different user logins to obtain historical login data; Perform feature extraction on the historical login data to obtain user login information containing target fields; the target fields include a login user field, a login time field, a login IP field, and a login result field; Dividing the user login information according to the preset time window to obtain a plurality of divided login information, and counting the number of login failures of each user in each preset time window based on the divided login information; Calculate the distribution parameters corresponding to the number of failed logins in all preset time windows; the distribution parameters include the mean value and standard deviation of the number of failed logins; Determine an abnormal login threshold corresponding to each user based on the distribution parameter; The DBSCAN algorithm is used to perform density cluster analysis on the login time data corresponding to different users in the historical login data to obtain the normal login time period of the corresponding users and obtain the normal login time range.
3. The abnormal login detection method according to claim 2, characterized in that: The determining the abnormal login threshold corresponding to each user based on the distribution parameter includes: The product of the standard deviation in the distribution parameter and the preset proportional factor is calculated, and the sum of the average value in the distribution parameter and the product is calculated to obtain the abnormal login threshold of the corresponding user.
4. The abnormal login detection method according to claim 2, characterized in that: The DBSCAN algorithm is used to perform density cluster analysis on the login time data corresponding to different users in the historical login data to obtain the normal login time period of the corresponding user and obtain the normal login time range, including: Convert the login time data corresponding to different users in the historical login data according to a preset timing method to obtain converted time data; Perform density cluster analysis on the converted time data using the DBSCAN algorithm to calculate the absolute distance between each historical login time point and other login time points, and determine whether the historical login time point is a core point based on the absolute distance, a preset neighborhood radius, and a preset minimum number of points; If the historical login time point is a core point, the core point and other login time points within the corresponding preset neighborhood radius are aggregated to form a node cluster; A cluster with the largest number of nodes is determined from all the node clusters to obtain a target cluster, and a normal login time period of a corresponding user is determined based on a minimum time and a maximum time in the target cluster to obtain a normal login time range of the corresponding user.
5. The abnormal login detection method according to claim 4, characterized in that: The determining whether the historical login time point is a core point based on the absolute distance, the preset neighborhood radius and the preset minimum number of points includes: Counting the number of other login time points within a preset neighborhood radius of each of the historical login time points to obtain the number of login nodes, and determining whether the number of login nodes is greater than or equal to a preset minimum number of points; If the number of login nodes is greater than or equal to the preset minimum number of points, the current historical login time point is determined to be a core point.
6. The abnormal login detection method according to claim 1, characterized in that: After determining that the target user has abnormal login behavior, the method further includes: Collecting logs related to logins of different users according to a first time period to obtain first login data, and updating the abnormal login threshold corresponding to each user based on the first login data; Logs related to logins of different users are collected according to a second time period to obtain second login data, and the normal login time range corresponding to each user is updated based on the second login data.
7. The abnormal login detection method according to any one of claims 1 to 6, characterized in that: Also includes: When a login failure operation is detected, the login failure time and the corresponding user ID are obtained, and the login failure time and the corresponding user ID are saved in a preset cache set; When the preset expiration time is reached, the data before the preset time length in the preset cache set is cleared; the preset time length is the product of the preset time window and a preset coefficient.
8. An abnormal login detection device, characterized in that: include: The data acquisition module is used to acquire the login log data of the currently logged-in target user and obtain the current login data when a user login operation is detected; The current login data includes the current login time and the number of current login failures within a preset time window; A judgment module, used to judge whether the current login time is within the normal login time range corresponding to the target user, and / or whether the current number of login failures exceeds the abnormal login threshold corresponding to the target user; The normal login time range is a normal login time period obtained by performing density cluster analysis on login time data in historical login data of different users using the DBSCAN algorithm, and the abnormal login threshold is a threshold determined by a distribution parameter obtained by performing statistical analysis on the number of login failures of different users within the preset time window based on the historical login data; The determination module is used to determine that the target user has abnormal login behavior if the current login time is not within the normal login time range corresponding to the target user and / or the current number of login failures exceeds the abnormal login threshold corresponding to the target user.
9. An electronic device, characterized in that: It comprises a processor and a memory; wherein, when the processor executes the computer program stored in the memory, the abnormal login detection method as described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, it implements the abnormal login detection method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Login abnormity detection method, system and device
CN107172104A
Web service account theft real-time monitoring method and system based on Flink
CN110138791A
Account permission locking method and device, computer equipment and storage medium
CN110298149A
Account login method and device and electronic equipment
CN117375894A
Violent login alarm method and device, electronic equipment and storage medium
CN118101318A
Cited By
Abnormal login detection method and device based on time ring coordinate system
CN120342787A