A method and system for intelligent management of computer user information security
By deploying a lightweight data collector and a federated graph neural network on the terminal to construct a cross-platform user behavior causal chain graph, the problem of user behavior correlation in cross-device environments is solved, and high-precision anomaly detection and dynamic security response are achieved.
Patent Information
- Application Number
- CN202510769288.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-06-10
AI Technical Summary
Existing technologies cannot obtain the correlation of user behavior across devices and environments without infringing on user privacy. Furthermore, the use of preset fixed strategies leads to a high false alarm rate and rigid strategies, making it impossible to identify complex attack chains.
By deploying lightweight collectors on multiple terminals to collect behavioral factors, generating factor summaries, and using a federated graph neural network framework to establish a graph structure, a cross-platform user behavior causal chain graph is constructed, automatically identifying causal mutation points, and generating dynamic security response strategies by combining behavioral chain integrity, temporal continuity, and device trust.
It enables accurate identification of user behavior relationships across devices and environments without infringing on user privacy, reduces false alarm rates, improves the accuracy of anomaly detection and the flexibility of strategies, and can identify complex attack chains.
Smart Images

Figure CN120474811B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, specifically to a method and system for intelligent management of computer user information security. Background Technology
[0002] Intelligent management of computer user information security refers to the use of advanced information technology, including artificial intelligence (AI), machine learning, and big data analysis, to protect the personal information security of computer users and prevent data leakage, misuse, or unauthorized access.
[0003] Patent publication number CN118228229A describes in its specification that "This invention relates to a computer user information security intelligent management method and system. The method includes: verifying login request information; if the verification is successful, granting the user login permissions and allowing them to access corresponding information data; predicting the predicted login time of each user within each unit time period based on a time prediction model; during user login, determining whether a confidentiality instruction is triggered based on the distance information between the associated device and the login device; when a confidentiality instruction is triggered, determining whether a forced logout instruction is initiated based on the predicted login time and the actual login time; if no forced logout instruction is initiated, determining the information data encryption level based on the distance information between the associated device and the login device. This invention has..." While the aforementioned technology reconstructs the terminal security protection paradigm through the dual dimensions of spatial location perception and temporal behavior prediction, solving the impersonation risk of traditional static password verification and avoiding security risks during the window period caused by users forgetting to log out, it has the advantage of being more accurate than traditional fixed timeout strategies. However, computer users are not active on only one device and in one environment. This means that existing technologies cannot directly obtain the correlation of user behavior across devices and environments without infringing on user privacy. At the same time, existing technologies often use preset fixed strategies to detect abnormal user behavior, which leads to high false alarm rates, rigid strategies, and an inability to identify complex attack chains.
[0004] In conclusion, developing an intelligent management method and system for computer user information security remains a critical issue that urgently needs to be addressed in the field of information security technology. Summary of the Invention
[0005] The purpose of this invention is to address the problem that existing technologies cannot directly obtain the correlation of user behavior across devices and environments without infringing on user privacy, as computer users are not active on only one device and in one environment. At the same time, existing technologies often use preset fixed strategies to detect abnormal user behavior, which leads to high false alarm rates, rigid strategies, and the inability to identify complex attack chains. This invention provides a computer user information security intelligent management method and system.
[0006] To achieve the above objectives, the present invention provides the following technical solution:
[0007] This invention provides a method for intelligent management of computer user information security, comprising:
[0008] S1. Deploy lightweight collectors locally on multiple endpoints to collect behavioral factors without collecting identity information, and generate factor summaries after processing.
[0009] S2. Based on the federated graph neural network framework, each terminal node establishes a graph structure for the factor summary locally, and aggregates the intermediate graph vector weights received by the central node.
[0010] S3. The central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and automatically identifies causal mutation points based on the weights of the intermediate graph vectors.
[0011] S4. Calculate the risk score based on the causal mutation point, and generate a dynamic security response strategy based on the integrity of the behavior chain, the continuity of time, and the trust level of the device.
[0012] In step S1, lightweight collectors are deployed locally on multiple endpoints to collect behavioral factors without collecting identity information. The method for generating factor summaries after processing is as follows:
[0013] The lightweight data collector, within the scope of user authorization, is deployed locally on multiple endpoints including PCs, mobile devices, and browser extensions. The behavioral factors include, but are not limited to, login time, operation frequency, file type, and network IP mode. The lightweight data collector locally executes a behavioral modeling function to perform sliding window feature extraction on the original behavioral factor data and combines the feature vectors of the behavioral factors. Where v (i) This represents the behavioral feature vector of the i-th user. Let α represent the mean of the times when the behavior occurs in the time series α of the i-th user. H represents the standard deviation of the action time in the time series α of the i-th user. (i) The entropy value represents the uncertainty of the i-th user's behavior, D. (i)The switching intensity of the i-th user between different devices is represented by a chaotic mapping + local perturbation mechanism for compression and encryption, and a factor digest is generated after processing.
[0014] In step S2, based on the federated graph neural network framework, the method for aggregating the factor summaries locally by each terminal node and the intermediate graph vector weights received by the central node is as follows:
[0015] The graph structure for the factor summary is as follows:
[0016]
[0017] In the formula, the node set Feature vectors and edge sets representing the behavioral factors of different categories Reflecting the dependencies between features, edge weights are calculated using joint mutual information, expressed as:
[0018]
[0019] In the formula, This represents the edge weight between node j and node k in the i-th terminal. Represents a node With nodes mutual information, Σ x,y p represents the summation over all possible combinations of eigenvalues (x, y). jk (x, y) represents a node and The value is the joint probability distribution of x and y, p j (x) represents a node The marginal probability, p, of taking the value x alone. k (y) represents a node The marginal probability of a single value being y. The logarithm of the ratio of joint probability to marginal probability reflects the degree of dependence between the two. A local user behavior graph embedding representation is trained. This graph embedding representation first undergoes graph embedding initialization and local graph convolutional propagation. Each node initializes its feature vector using a Chebyshev multinomial spectral graph convolutional propagation mechanism. Then, a variational graph autoencoder is used locally to perform self-supervised learning of the node embeddings, generating latent node representations. A federated graph embedding update mechanism is then established. Each terminal node only uploads a summary of the local graph embedding model weights. Federated aggregation is performed through the central node, and the data is also transmitted back to all terminals through the central node. Graph alignment mapping is then performed to unify the graph embedding dimension and optimize the global consistency loss. Each terminal node receives the aggregated model parameters and mapping function and fine-tunes the federated graph neural network.
[0020] Further, in step S3, the central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and the method for automatically identifying causal mutation points based on the intermediate graph vector weights is as follows:
[0021] The cross-platform user behavior causal chain graph constructs a time causal chain graph structure for all event nodes in the behavior graph according to the event timestamp and operation order, expressed as:
[0022]
[0023] In the formula, Represents a cross-platform global causal chain graph. This represents the set of all nodes in a cross-platform global causal chain graph. Represents the set of all edges in a cross-platform global causal chain graph. This represents the set of nodes that localize all i-th terminal nodes to the local graph. Combined to form a complete set of nodes This represents the set of edges that merge all local graphs. This represents a cross-platform set of connection edges. The central node applies a graph attention neural network to the causal chain graph to model the strength of causal influence between nodes. The expression is:
[0024]
[0025] In the formula, Let σ represent the embedding representation of node j at layer l+1, and let σ represent the nonlinear activation function. Describes the set of neighboring nodes of node j. Sum the results of each neighbor node k. W represents the attention weight of node j in layer l to its neighbor node k. (l) This represents the learnable linear transformation weight matrix of the l-th layer. Let represent the embedding representation of node k at layer l, exp(·) represent the exponential function, and LeakyReLU(·) represent the ReLU activation function with leakage. This represents the transpose of the learnable attention weight vector, [Wh j ||Wh k The symbol ] represents concatenating the feature vectors of nodes j and k after a linear transformation. This represents the embedding representation h of the behavior pattern of each node after calculating the attention score for all neighboring nodes k' of node j and performing inference. j Used to analyze the causal tension of user behavior.
[0026] Further, in step S3, the central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and the method for automatically identifying causal mutation points based on the intermediate graph vector weights is as follows:
[0027] The automatic identification of causal abrupt change points includes, but is not limited to, short-term device switching, drastic changes in behavior patterns, and breaks in the causal chain. Short-term device switching is defined as the existence of short-term behavior transmission between different devices, and the inferred edges satisfy the following formula:
[0028] Δt jk =|t j -t k |<δ, and device(ν) j )≠device(ν k ),
[0029] In the formula, Δt jk Represents node ν j With node ν k The time difference between corresponding events, δ, is a preset time threshold, t j , t k Representing behavior nodes ν j and ν k timestamp, device(ν j ) represents node ν j The corresponding device identifier, device(ν) k ) represents node ν k The corresponding device identifier, device(ν) j )≠device(ν k This indicates that the two behavioral nodes come from different devices. The edge is determined to be a mutation edge, and the node is marked as a switching mutation point. The behavioral pattern changes drastically. Based on the node behavioral pattern embedding, the behavioral tension increases abruptly within a short time window. The expression is:
[0030]
[0031] In the formula, This represents the behavior pattern embedding vector of the j-th node in the user behavior graph at time t. This represents the embedding vector of the behavior pattern of node j at time t+Δt. Let L be the L2 norm of the vector, ||·||2 represent the degree of change in the behavioral embedding of node j within a short time interval Δt, and γ represent the preset threshold for drastic behavioral change. If the causal chain is broken, then if the behavioral pattern embedding of one of the nodes has no clear leading behavior, then the event node is marked as the causal break point.
[0032] Further, in step S4, the method for calculating a risk score based on the causal mutation point and generating a dynamic security response strategy based on the integrity of the behavioral chain, temporal continuity, and device trust level is as follows:
[0033] Risk scores are calculated based on the causal mutation points. The central node receives all detected causal mutation points and, combining the integrity of the behavior chain, temporal continuity, and device trust level, calculates a comprehensive risk score for each user's current behavior path. A weighted normalization function is then used to synthesize the final risk score, expressed as:
[0034] R u =1-(ω1C) u +ω2T u +ω3S u ), where ω1+ω2+ω3=1
[0035] In the formula, R u Let ω1 represent the risk score of user u, ω2 represent the weighting coefficient of the integrity score, ω3 represent the weighting coefficient of the time continuity score, and ω3 represent the weighting coefficient of the device trust score. ω1 + ω2 + ω3 = 1 indicates that the sum of all weighting coefficients is 1, and a weighted average is applied. C u T represents the completeness score of the user behavior chain. u S represents the time continuity score of user behavior. u This indicates the trust rating of the device used by the user, based on the user's risk score R. u The dynamic security response strategy is generated by combining mutation type, device characteristics and behavioral context. The dynamic security response strategy includes, but is not limited to, no additional authentication is required for normal behavior chains, SMS verification code is triggered when switching to weak trust, and human-machine recognition is initiated when suspicious causal paths occur.
[0036] Further, in step S4, the method for calculating a risk score based on the causal mutation point and generating a dynamic security response strategy based on the integrity of the behavioral chain, temporal continuity, and device trust level is as follows:
[0037] After user authentication is completed using the dynamic security response strategy, the central node performs a label update operation and a federated graph neural network update based on the user authentication feedback result. The label update operation marks the current behavior chain path as either a safe or risky sample for subsequent federated training supervision. The federated graph neural network update uses the user authentication feedback result as a reinforcement signal to be sent back to the local node, updating the federated graph neural network model parameters θ. i The central nodes are aggregated based on a federated averaging mechanism, expressed as:
[0038]
[0039] In the formula, θ g+1 Let represent the global model parameters in the (g+1)th round, E represent the total number of terminal nodes participating in federated learning, and i represent the number of the i-th terminal node. Let e represent the parameters of the local model of the i-th terminal node after the g-th round of training. i Let represent the number of local training data samples held by the i-th terminal node, and e represent the sum of the total number of samples across all terminal nodes. This represents the weight of the i-th node in the total samples, and then the new model parameters θ are... g+1 The data is simultaneously pushed to each of the aforementioned terminal nodes.
[0040] On the other hand, the present invention also provides a computer user information security intelligent management system, comprising:
[0041] The behavioral factor collection module uses lightweight collectors deployed locally on multiple endpoints to collect behavioral factors without collecting identity information, and then generates factor summaries after processing.
[0042] The graph structure module, based on the federated graph neural network framework, establishes a graph structure for the factor summary locally through each terminal node, and aggregates the intermediate graph vector weights received by the central node.
[0043] The behavioral causal chain graph module uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and automatically identifies causal mutation points based on the weights of the intermediate graph vectors.
[0044] The risk scoring module calculates a risk score based on the causal mutation point and generates a dynamic security response strategy based on the integrity of the behavior chain, the continuity of time, and the trust level of the device.
[0045] The lightweight data collector, within the scope of user authorization, is deployed locally on multiple endpoints including PCs, mobile devices, and browser extensions. The behavioral factors include, but are not limited to, login time, operation frequency, file type, and network IP mode. The lightweight data collector locally executes a behavioral modeling function to perform sliding window feature extraction on the original behavioral factor data and combines the feature vectors of the behavioral factors. Where v (i) This represents the behavioral feature vector of the i-th user. Let α represent the mean of the times when the behavior occurs in the time series α of the i-th user. H represents the standard deviation of the action time in the time series α of the i-th user. (i) The entropy value represents the uncertainty of the i-th user's behavior, D. (i) The switching intensity of the i-th user between different devices is represented by a chaotic mapping + local perturbation mechanism for compression and encryption, and a factor digest is generated after processing.
[0046] The operation process of the graph structure module includes:
[0047] The graph structure for the factor summary is as follows:
[0048]
[0049] In the formula, the node set Feature vectors and edge sets representing the behavioral factors of different categories Reflecting the dependencies between features, edge weights are calculated using joint mutual information, expressed as:
[0050]
[0051] In the formula, This represents the edge weight between node j and node k in the i-th terminal. Represents a node With nodes mutual information, Σ x,y p represents the summation over all possible combinations of eigenvalues (x, y). jk (x, y) represents a node and The value is the joint probability distribution of x and y, p j (x) represents a node The marginal probability, p, of taking the value x alone. k (y) represents a node The marginal probability of a single value being y. The logarithm of the ratio of joint probability to marginal probability reflects the degree of dependence between the two. A local user behavior graph embedding representation is trained. This graph embedding representation first undergoes graph embedding initialization and local graph convolutional propagation. Each node initializes its feature vector using a Chebyshev multinomial spectral graph convolutional propagation mechanism. Then, a variational graph autoencoder is used locally to perform self-supervised learning of the node embeddings, generating latent node representations. A federated graph embedding update mechanism is then established. Each terminal node only uploads a summary of the local graph embedding model weights. Federated aggregation is performed through the central node, and the data is also transmitted back to all terminals through the central node. Graph alignment mapping is then performed to unify the graph embedding dimension and optimize the global consistency loss. Each terminal node receives the aggregated model parameters and mapping function and fine-tunes the federated graph neural network.
[0052] The cross-platform user behavior causal chain graph constructs a time causal chain graph structure for all event nodes in the behavior graph according to the event timestamp and operation order, expressed as:
[0053]
[0054] In the formula, Represents a cross-platform global causal chain graph. This represents the set of all nodes in a cross-platform global causal chain graph. Represents the set of all edges in a cross-platform global causal chain graph. This represents the set of nodes that localize all i-th terminal nodes to the local graph. Combined to form a complete set of nodes This represents the set of edges that merge all local graphs. This represents a cross-platform set of connection edges. The central node applies a graph attention neural network to the causal chain graph to model the strength of causal influence between nodes. The expression is:
[0055]
[0056] In the formula, Let σ represent the embedding representation of node j at layer l+1, and let σ represent the nonlinear activation function. Describes the set of neighboring nodes of node j. Sum the results of each neighbor node k. W represents the attention weight of node j in layer l to its neighbor node k. (l) This represents the learnable linear transformation weight matrix of the l-th layer. Let represent the embedding representation of node k at layer l, exp(·) represent the exponential function, and LeakyReLU(·) represent the ReLU activation function with leakage. This represents the transpose of the learnable attention weight vector, [Wh j ||Wh k The symbol ] represents concatenating the feature vectors of nodes j and k after a linear transformation. This represents the embedding representation h of the behavior pattern of each node after calculating the attention score for all neighboring nodes k' of node j and performing inference. j This is used to analyze the causal tension of user behavior; the automatic identification of causal abrupt change points includes, but is not limited to, short-term device switching, drastic changes in behavior patterns, and breaks in the causal chain. Short-term device switching is defined as the existence of short-term behavior transmission between different devices, and the inferred edges satisfy the following formula:
[0057] Δt jk =|t j -t k |<δ, and device(ν) j )≠device(ν k ),
[0058] In the formula, Δt jk Represents node ν j With node ν kThe time difference between corresponding events, δ, is a preset time threshold, t j , t k Representing behavior nodes ν j and ν k timestamp, device(ν j ) represents node ν j The corresponding device identifier, device(ν) k ) represents node ν k The corresponding device identifier, device(ν) j )≠device(ν k This indicates that the two behavioral nodes come from different devices. The edge is determined to be a mutation edge, and the node is marked as a switching mutation point. The behavioral pattern changes drastically. Based on the node behavioral pattern embedding, the behavioral tension increases abruptly within a short time window. The expression is:
[0059]
[0060] In the formula, This represents the behavior pattern embedding vector of the j-th node in the user behavior graph at time t. This represents the embedding vector of the behavior pattern of node j at time t+Δt. Let L be the L2 norm of the vector, ||·||2 represent the degree of change in the behavioral embedding of node j within a short time interval Δt, and γ represent the preset threshold for drastic behavioral change. If the causal chain is broken, then if the behavioral pattern embedding of one of the nodes has no clear leading behavior, then the event node is marked as the causal break point.
[0061] The operation process of the risk scoring module includes:
[0062] Risk scores are calculated based on the causal mutation points. The central node receives all detected causal mutation points and, combining the integrity of the behavior chain, temporal continuity, and device trust level, calculates a comprehensive risk score for each user's current behavior path. A weighted normalization function is then used to synthesize the final risk score, expressed as:
[0063] R u =1-(ω1C) u +ω2T u +ω3S u ), where ω1+ω2+ω3=1
[0064] In the formula, R u Let ω1 represent the risk score of user u, ω2 represent the weighting coefficient of the integrity score, ω3 represent the weighting coefficient of the time continuity score, and ω3 represent the weighting coefficient of the device trust score. ω1 + ω2 + ω3 = 1 indicates that the sum of all weighting coefficients is 1, and a weighted average is applied. C uT represents the completeness score of the user behavior chain. u S represents the time continuity score of user behavior. u This indicates the trust rating of the device used by the user, based on the user's risk score R. u Combining mutation type, device characteristics, and behavioral context, a dynamic security response strategy is generated. This strategy includes, but is not limited to, requiring no additional authentication for normal behavior chains, triggering SMS verification codes for weak trust switching, and initiating human-machine identification for suspicious causal paths. After user authentication is completed, the central node performs label update and federated graph neural network update operations based on the user authentication feedback. The label update operation marks the current behavior chain path as either a safe or risky sample for subsequent federated training supervision signals. The federated graph neural network update uses the user authentication feedback as a reinforcement signal to send back to the local node, updating the federated graph neural network model parameters θ. i The central nodes are aggregated based on a federated averaging mechanism, expressed as:
[0065]
[0066] In the formula, θ g+1 Let represent the global model parameters in the (g+1)th round, E represent the total number of terminal nodes participating in federated learning, and i represent the number of the i-th terminal node. Let e represent the parameters of the local model of the i-th terminal node after the g-th round of training. i Let represent the number of local training data samples held by the i-th terminal node, and e represent the sum of the total number of samples across all terminal nodes. This represents the weight of the i-th node in the total samples, and then the new model parameters θ are... g+1 The data is simultaneously pushed to each of the aforementioned terminal nodes.
[0067] Beneficial effects
[0068] Compared with known public technologies, the technical solution provided by this invention has the following beneficial effects:
[0069] When used, the lightweight data collector employed in this invention is applicable to different terminal platforms and has low requirements for device computing and storage resources, achieving the effect of multi-terminal compatibility and low deployment overhead. It is convenient to obtain the user's behavioral correlation across devices and environments without infringing on user privacy. By utilizing node embedding changes and structural reasoning, it can automatically discover hidden anomalies, such as behavioral fraud during device switching and robot disguise operations, which is beneficial to distinguish it from traditional static rules and improve the accuracy of behavioral mutation recognition. Attached Figure Description
[0070] Figure 1This is a flowchart of a computer user information security intelligent management method according to the present invention;
[0071] Figure 2 This is a system diagram of a computer user information security intelligent management system according to the present invention. Detailed Implementation
[0072] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0073] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0074] The present invention will now be described in further detail with reference to the accompanying drawings:
[0075] Example 1:
[0076] like Figure 1 As shown, the present invention provides a method for intelligent management of computer user information security, comprising:
[0077] S1. Deploy lightweight collectors locally on multiple endpoints to collect behavioral factors without collecting identity information, and generate factor summaries after processing.
[0078] Furthermore, in step S1, lightweight collectors are locally deployed on multiple endpoints to collect behavioral factors without collecting identity information. The method for generating factor summaries after processing is as follows:
[0079] The lightweight data collector, within the scope of user authorization, is deployed locally on multiple endpoints including PCs, mobile devices, and browser extensions. The behavioral factors include, but are not limited to, login time, operation frequency, file type, and network IP mode. The lightweight data collector locally executes a behavioral modeling function to perform sliding window feature extraction on the original behavioral factor data and combines the feature vectors of the behavioral factors. Where v (i) This represents the behavioral feature vector of the i-th user. Let α represent the mean of the times when the behavior occurs in the time series α of the i-th user. H represents the standard deviation of the action time in the time series α of the i-th user. (i) The entropy value represents the uncertainty of the i-th user's behavior, D. (i) The value represents the switching intensity of the i-th user between different devices. It is compressed and encrypted using a chaotic mapping + local perturbation mechanism, and a factor digest is generated after processing.
[0080] In this embodiment, a multi-terminal user behavior factor collection and summary generation method is adopted. Without collecting identity information, a lightweight collector is used to perform privacy-preserving behavior factor modeling on the user end, laying a data foundation for subsequent federated graph neural learning and causal analysis. This facilitates compliance with data compliance and privacy computing specifications. The lightweight collector used is suitable for different terminal platforms with low requirements for device computing and storage resources, and is suitable for large-scale deployment scenarios, achieving the effect of multi-terminal compatibility and low deployment overhead.
[0081] S2. Based on the federated graph neural network framework, each terminal node establishes a graph structure for the factor summary locally, and aggregates the intermediate graph vector weights received by the central node.
[0082] Further, in step S2, based on the federated graph neural network framework, the method for establishing a graph structure for the factor summary locally by each terminal node and aggregating the intermediate graph vector weights received by the central node is as follows:
[0083] The graph structure for the factor summary is as follows:
[0084]
[0085] In the formula, the node set Feature vectors and edge sets representing the behavioral factors of different categories Reflecting the dependencies between features, edge weights are calculated using joint mutual information, expressed as:
[0086]
[0087] In the formula, This represents the edge weight between node j and node k in the i-th terminal. Represents a node With nodes mutual information, Σ x,y p represents the summation over all possible combinations of eigenvalues (x, y). jk (x, y) represents a node and The value is the joint probability distribution of x and y, p j (x) represents a node The marginal probability, p, of taking the value x alone. k (y) represents a node The marginal probability of a single value being y. The logarithm of the ratio of joint probability to marginal probability reflects the degree of dependence between the two. A local user behavior graph embedding representation is trained. This graph embedding representation first undergoes graph embedding initialization and local graph convolutional propagation. Each node initializes its feature vector using a Chebyshev multinomial spectral graph convolutional propagation mechanism. Then, a variational graph autoencoder is used locally to perform self-supervised learning of the node embeddings, generating latent node representations. A federated graph embedding update mechanism is then established. Each terminal node only uploads a summary of the local graph embedding model weights. Federated aggregation is performed through the central node, and the data is also transmitted back to all terminals through the central node. Graph alignment mapping is then performed to unify the graph embedding dimension and optimize the global consistency loss. Each terminal node receives the aggregated model parameters and mapping function and fine-tunes the federated graph neural network.
[0088] In this embodiment, the method is based on a federated graph neural network framework. It completes the behavioral graph structure modeling without leaving the terminal device, effectively avoiding the problem of sensitive data leakage. It is convenient to comply with the data minimization principle and data compliance requirements such as GDPR. By jointly quantifying the statistical dependencies between features through mutual information, it can effectively capture the nonlinear relationships between complex behavioral factors. The method uses Chebyshev spectral convolution and variational graph autoencoder to perform deep embedding learning on the local behavioral graph, which improves the modeling and expression capabilities of user behavior structure and provides strong feature support for subsequent tasks such as anomaly detection and risk assessment.
[0089] S3. The central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and automatically identifies causal mutation points based on the weights of the intermediate graph vectors.
[0090] Further, in step S3, the central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and the method for automatically identifying causal mutation points based on the intermediate graph vector weights is as follows:
[0091] The cross-platform user behavior causal chain graph constructs a time causal chain graph structure for all event nodes in the behavior graph according to the event timestamp and operation order, expressed as:
[0092]
[0093] In the formula, Represents a cross-platform global causal chain graph. This represents the set of all nodes in a cross-platform global causal chain graph. Represents the set of all edges in a cross-platform global causal chain graph. This represents the set of nodes that localize all i-th terminal nodes to the local graph. Combined to form a complete set of nodes This represents the set of edges that merge all local graphs. This represents a cross-platform set of connection edges. The central node applies a graph attention neural network to the causal chain graph to model the strength of causal influence between nodes. The expression is:
[0094]
[0095] In the formula, Let σ represent the embedding representation of node j at layer l+1, and let σ represent the nonlinear activation function. Describes the set of neighboring nodes of node j. Sum the results of each neighbor node k. W represents the attention weight of node j in layer l to its neighbor node k. (l) This represents the learnable linear transformation weight matrix of the l-th layer. Let represent the embedding representation of node k at layer l, exp(·) represent the exponential function, and LeakyReLU(·) represent the ReLU activation function with leakage. This represents the transpose of the learnable attention weight vector, [Wh j ||Wh k The symbol ] represents concatenating the feature vectors of nodes j and k after a linear transformation. This represents the embedding representation h of the behavior pattern of each node after calculating the attention score for all neighboring nodes k' of node j and performing inference. j Used to analyze the causal tension of user behavior.
[0096] Further, in step S3, the central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and the method for automatically identifying causal mutation points based on the intermediate graph vector weights is as follows:
[0097] The automatic identification of causal abrupt change points includes, but is not limited to, short-term device switching, drastic changes in behavior patterns, and breaks in the causal chain. Short-term device switching is defined as the existence of short-term behavior transmission between different devices, and the inferred edges satisfy the following formula:
[0098] Δt jk =|t j -t k |<δ, and device(ν) j )≠device(ν k ),
[0099] In the formula, Δt jk Represents node ν j With node ν k The time difference between corresponding events, δ, is a preset time threshold, t j , t k Representing behavior nodes ν j and ν k timestamp, device(ν j ) represents node ν j The corresponding device identifier, device(ν) k ) represents node ν k The corresponding device identifier, device(ν) j )≠device(ν k This indicates that the two behavioral nodes come from different devices. The edge is determined to be a mutation edge, and the node is marked as a switching mutation point. The behavioral pattern changes drastically. Based on the node behavioral pattern embedding, the behavioral tension increases abruptly within a short time window. The expression is:
[0100]
[0101] In the formula, This represents the behavior pattern embedding vector of the j-th node in the user behavior graph at time t. This represents the embedding vector of the behavior pattern of node j at time t+Δt. Let L be the L2 norm of the vector, ||·||2 represent the degree of change in the behavioral embedding of node j within a short time interval Δt, and γ represent the preset threshold for drastic behavioral change. If the causal chain is broken, then if the behavioral pattern embedding of one of the nodes has no clear leading behavior, then the event node is marked as the causal break point.
[0102] In this embodiment, the method uses graph neural networks to uniformly model cross-platform behavior, which solves the problem of fragmented user behavior across multiple devices and platforms and the difficulty in uniformly modeling it. By utilizing node embedding changes and structural reasoning, it automatically discovers hidden anomalies, such as behavioral fraud during device switching and robot spoofing operations, which helps to distinguish it from traditional static rules and improve the accuracy of behavioral mutation identification.
[0103] S4. Calculate the risk score based on the causal mutation point, and generate a dynamic security response strategy based on the integrity of the behavior chain, the continuity of time, and the trust level of the device.
[0104] Further, in step S4, the method for calculating a risk score based on the causal mutation point and generating a dynamic security response strategy based on the integrity of the behavioral chain, temporal continuity, and device trust level is as follows:
[0105] Risk scores are calculated based on the causal mutation points. The central node receives all detected causal mutation points and, combining the integrity of the behavior chain, temporal continuity, and device trust level, calculates a comprehensive risk score for each user's current behavior path. A weighted normalization function is then used to synthesize the final risk score, expressed as:
[0106] R u =1-(ω1C) u +ω2T u +ω3S u ), where ω1+ω2+ω3=1
[0107] In the formula, R u Let ω1 represent the risk score of user u, ω2 represent the weighting coefficient of the integrity score, ω3 represent the weighting coefficient of the time continuity score, and ω3 represent the weighting coefficient of the device trust score. ω1 + ω2 + ω3 = 1 indicates that the sum of all weighting coefficients is 1, and a weighted average is applied. C u T represents the completeness score of the user behavior chain. u S represents the time continuity score of user behavior. u This indicates the trust rating of the device used by the user, based on the user's risk score R. u The dynamic security response strategy is generated by combining mutation type, device characteristics and behavioral context. The dynamic security response strategy includes, but is not limited to, no additional authentication is required for normal behavior chains, SMS verification code is triggered when switching to weak trust, and human-machine recognition is initiated when suspicious causal paths occur.
[0108] Further, in step S4, the method for calculating a risk score based on the causal mutation point and generating a dynamic security response strategy based on the integrity of the behavioral chain, temporal continuity, and device trust level is as follows:
[0109] After user authentication is completed using the dynamic security response strategy, the central node performs a label update operation and a federated graph neural network update based on the user authentication feedback result. The label update operation marks the current behavior chain path as either a safe or risky sample for subsequent federated training supervision. The federated graph neural network update uses the user authentication feedback result as a reinforcement signal to be sent back to the local node, updating the federated graph neural network model parameters θ. i The central nodes are aggregated based on a federated averaging mechanism, expressed as:
[0110]
[0111] In the formula, θ g+1 Let represent the global model parameters in the (g+1)th round, E represent the total number of terminal nodes participating in federated learning, and i represent the number of the i-th terminal node. Let e represent the parameters of the local model of the i-th terminal node after the g-th round of training. i Let represent the number of local training data samples held by the i-th terminal node, and e represent the sum of the total number of samples across all terminal nodes. This represents the weight of the i-th node in the total samples, and then the new model parameters θ are... g+1 The data is simultaneously pushed to each of the aforementioned terminal nodes.
[0112] In this embodiment, the method dynamically generates response strategies based on changes in user behavior, improving system security while taking into account user experience. By mining causal mutation points and identifying device switching, it achieves unified modeling of related behavioral paths between different devices, which facilitates the solution of the problem of behavior silos in heterogeneous terminals. The model parameters are updated through user authentication feedback results, which has the ability to continuously learn and self-optimize, so that the system's ability to identify abnormal behavior continuously improves over time.
[0113] Example 2:
[0114] like Figure 2 As shown, Embodiment 2 provides a computer user information security intelligent management system, including:
[0115] The behavioral factor collection module uses lightweight collectors deployed locally on multiple endpoints to collect behavioral factors without collecting identity information, and then generates factor summaries after processing.
[0116] The graph structure module, based on the federated graph neural network framework, establishes a graph structure for the factor summary locally through each terminal node, and aggregates the intermediate graph vector weights received by the central node.
[0117] The behavioral causal chain graph module uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and automatically identifies causal mutation points based on the weights of the intermediate graph vectors.
[0118] The risk scoring module calculates a risk score based on the causal mutation point and generates a dynamic security response strategy based on the integrity of the behavior chain, the continuity of time, and the trust level of the device.
[0119] The lightweight data collector, within the scope of user authorization, is deployed locally on multiple endpoints including PCs, mobile devices, and browser extensions. The behavioral factors include, but are not limited to, login time, operation frequency, file type, and network IP mode. The lightweight data collector locally executes a behavioral modeling function to perform sliding window feature extraction on the original behavioral factor data and combines the feature vectors of the behavioral factors. Where v (i) This represents the behavioral feature vector of the i-th user. Let α represent the mean of the times when the behavior occurs in the time series α of the i-th user. H represents the standard deviation of the action time in the time series α of the i-th user. (i) The entropy value represents the uncertainty of the i-th user's behavior, D. (i) The value represents the switching intensity of the i-th user between different devices. It is compressed and encrypted using a chaotic mapping + local perturbation mechanism, and a factor digest is generated after processing.
[0120] The operation process of the graph structure module includes:
[0121] The graph structure for the factor summary is as follows:
[0122]
[0123] In the formula, the node set Feature vectors and edge sets representing the behavioral factors of different categories Reflecting the dependencies between features, edge weights are calculated using joint mutual information, expressed as:
[0124]
[0125] In the formula, This represents the edge weight between node j and node k in the i-th terminal. Represents a node With nodes mutual information, Σ x,y p represents the summation over all possible combinations of eigenvalues (x, y). jk (x, y) represents a node and The value is the joint probability distribution of x and y, p j(x) represents a node The marginal probability, p, of taking the value x alone. k (y) represents a node The marginal probability of a single value being y. The logarithm of the ratio of joint probability to marginal probability reflects the degree of dependence between the two. A local user behavior graph embedding representation is trained. This graph embedding representation first undergoes graph embedding initialization and local graph convolutional propagation. Each node initializes its feature vector using a Chebyshev multinomial spectral graph convolutional propagation mechanism. Then, a variational graph autoencoder is used locally to perform self-supervised learning of the node embeddings, generating latent node representations. A federated graph embedding update mechanism is then established. Each terminal node only uploads a summary of the local graph embedding model weights. Federated aggregation is performed through the central node, and the data is also transmitted back to all terminals through the central node. Graph alignment mapping is then performed to unify the graph embedding dimension and optimize the global consistency loss. Each terminal node receives the aggregated model parameters and mapping function and fine-tunes the federated graph neural network.
[0126] The cross-platform user behavior causal chain graph constructs a time causal chain graph structure for all event nodes in the behavior graph according to the event timestamp and operation order, expressed as:
[0127]
[0128] In the formula, Represents a cross-platform global causal chain graph. This represents the set of all nodes in a cross-platform global causal chain graph. Represents the set of all edges in a cross-platform global causal chain graph. This represents the set of nodes that localize all i-th terminal nodes to the local graph. Combined to form a complete set of nodes This represents the set of edges that merge all local graphs. This represents a cross-platform set of connection edges. The central node applies a graph attention neural network to the causal chain graph to model the strength of causal influence between nodes. The expression is:
[0129]
[0130] In the formula, Let σ represent the embedding representation of node j at layer l+1, and let σ represent the nonlinear activation function. Describes the set of neighboring nodes of node j. Sum the results of each neighbor node k. W represents the attention weight of node j in layer l to its neighbor node k. (l) This represents the learnable linear transformation weight matrix of the l-th layer. Let represent the embedding representation of node k at layer l, exp(·) represent the exponential function, and LeakyReLU(·) represent the ReLU activation function with leakage. This represents the transpose of the learnable attention weight vector, [Wh j ||Wh k The symbol ] represents concatenating the feature vectors of nodes j and k after a linear transformation. This represents the behavior pattern embedding representation h of each node after calculating attention scores for all neighboring nodes k' of node j and performing inference. j This is used to analyze the causal tension of user behavior; the automatic identification of causal abrupt change points includes, but is not limited to, short-term device switching, drastic changes in behavior patterns, and breaks in the causal chain. Short-term device switching is defined as the existence of short-term behavior transmission between different devices, and the inferred edges satisfy the following formula:
[0131] Δt jk =|t j -t k |<δ, and device(ν) j )≠device(ν k ),
[0132] In the formula, Δt jk Represents node ν j With node ν k The time difference between corresponding events, δ, is a preset time threshold, t j , t k Representing behavior nodes ν j and ν k timestamp, device(ν j ) represents node ν j The corresponding device identifier, device(ν) k ) represents node ν k The corresponding device identifier, device(ν) j )≠device(ν k This indicates that the two behavioral nodes come from different devices. The edge is determined to be a mutation edge, and the node is marked as a switching mutation point. The behavioral pattern changes drastically. Based on the node behavioral pattern embedding, the behavioral tension increases abruptly within a short time window. The expression is:
[0133]
[0134] In the formula, This represents the behavior pattern embedding vector of the j-th node in the user behavior graph at time t. This represents the embedding vector of the behavior pattern of node j at time t+Δt. Let L be the L2 norm of the vector, ||·||2 represent the degree of change in the behavioral embedding of node j within a short time interval Δt, and γ represent the preset threshold for drastic behavioral change. If the causal chain is broken, then if the behavioral pattern embedding of one of the nodes has no clear leading behavior, then the event node is marked as the causal break point.
[0135] The operation process of the risk scoring module includes:
[0136] Risk scores are calculated based on the causal mutation points. The central node receives all detected causal mutation points and, combining the integrity of the behavior chain, temporal continuity, and device trust level, calculates a comprehensive risk score for each user's current behavior path. A weighted normalization function is then used to synthesize the final risk score, expressed as:
[0137] R u =1-(ω1C) u +ω2T u +ω3S u ), where ω1+ω2+ω3=1
[0138] In the formula, R u Let ω1 represent the risk score of user u, ω2 represent the weighting coefficient of the integrity score, ω3 represent the weighting coefficient of the time continuity score, and ω3 represent the weighting coefficient of the device trust score. ω1 + ω2 + ω3 = 1 indicates that the sum of all weighting coefficients is 1, and a weighted average is applied. C u T represents the completeness score of the user behavior chain. u S represents the time continuity score of user behavior. u This indicates the trust rating of the device used by the user, based on the user's risk score R. u Combining mutation type, device characteristics, and behavioral context, a dynamic security response strategy is generated. This strategy includes, but is not limited to, requiring no additional authentication for normal behavior chains, triggering SMS verification codes for weak trust switching, and initiating human-machine identification for suspicious causal paths. After user authentication is completed, the central node performs label update and federated graph neural network update operations based on the user authentication feedback. The label update operation marks the current behavior chain path as either a safe or risky sample for subsequent federated training supervision signals. The federated graph neural network update uses the user authentication feedback as a reinforcement signal to send back to the local node, updating the federated graph neural network model parameters θ. i The central nodes are aggregated based on a federated averaging mechanism, expressed as:
[0139]
[0140] In the formula, θ g+1Let represent the global model parameters in the (g+1)th round, E represent the total number of terminal nodes participating in federated learning, and i represent the number of the i-th terminal node. Let e represent the parameters of the local model of the i-th terminal node after the g-th round of training. i Let represent the number of local training data samples held by the i-th terminal node, and e represent the sum of the total number of samples across all terminal nodes. This represents the weight of the i-th node in the total samples, and then the new model parameters θ are... g+1 The data is simultaneously pushed to each of the aforementioned terminal nodes.
[0141] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for intelligent management of computer user information security, characterized in that, include: S1. Deploy lightweight collectors locally on multiple endpoints to collect behavioral factors without collecting identity information, and generate factor summaries after processing. S2. Based on the federated graph neural network framework, each terminal node establishes a graph structure for the factor summary locally, and aggregates the intermediate graph vector weights received by the central node. S3. The central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and automatically identifies causal mutation points based on the weights of the intermediate graph vectors. S4. Calculate the risk score based on the causal mutation point, and generate a dynamic security response strategy based on the integrity of the behavior chain, the continuity of time, and the trust level of the device. In step S1, lightweight collectors are deployed locally on multiple endpoints to collect behavioral factors without collecting identity information. The method for generating factor summaries after processing is as follows: The lightweight data collector, within the scope of user authorization, is deployed locally on multiple endpoints including PCs, mobile devices, and browser extensions. The behavioral factors include, but are not limited to, login time, operation frequency, file type, and network IP mode. The lightweight data collector locally executes a behavioral modeling function to perform sliding window feature extraction on the original behavioral factor data and combines the feature vectors of the behavioral factors. Where v (i) This represents the behavioral feature vector of the i-th user. Let α represent the mean of the times when the behavior occurs in the time series α of the i-th user. H represents the standard deviation of the action time in the time series α of the i-th user. (i) The entropy value represents the uncertainty of the i-th user's behavior, D. (i) The switching intensity of the i-th user between different devices is represented by a chaotic mapping + local perturbation mechanism for compression and encryption, and a factor digest is generated after processing. In step S2, based on the federated graph neural network framework, the method for aggregating the factor summaries locally by each terminal node and the intermediate graph vector weights received by the central node is as follows: The graph structure for the factor summary is as follows: In the formula, the node set The feature vectors representing the behavioral factors of different categories, and the edge set ε i Reflecting the dependencies between features, edge weights are calculated using joint mutual information, expressed as: In the formula, This represents the edge weight between node j and node k in the i-th terminal. Represents a node With nodes mutual information, Σ x,y p represents the summation over all possible combinations of eigenvalues (x, y). jk (x, y) represents a node and The value is the joint probability distribution of x and y, p j (x) represents a node The marginal probability, p, of taking the value x alone. k (y) represents a node The marginal probability of a single value being y. The logarithm of the ratio of joint probability to marginal probability reflects the degree of dependence between the two. A local user behavior graph embedding representation is trained. This graph embedding representation first undergoes graph embedding initialization and local graph convolutional propagation. Each node initializes its feature vector using a Chebyshev multinomial spectral graph convolutional propagation mechanism. Then, a variational graph autoencoder is used locally to perform self-supervised learning of the node embeddings, generating latent node representations. A federated graph embedding update mechanism is then established. Each terminal node only uploads a summary of the local graph embedding model weights. Federated aggregation is performed through the central node, and the data is also transmitted back to all terminals through the central node. Graph alignment mapping is then performed to unify the graph embedding dimension and optimize the global consistency loss. Each terminal node receives the aggregated model parameters and mapping function and fine-tunes the federated graph neural network.
2. The intelligent management method for computer user information security according to claim 1, characterized in that, In step S3, the central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph. The method for automatically identifying causal mutation points based on the intermediate graph vector weights is as follows: The cross-platform user behavior causal chain graph constructs a time causal chain graph structure for all event nodes in the behavior graph according to the event timestamp and operation order, expressed as: In the formula, Represents a cross-platform global causal chain graph. ε represents the set of all nodes in a cross-platform global causal chain graph. c Represents the set of all edges in a cross-platform global causal chain graph. This represents the set of nodes that localize all i-th terminal nodes to the local graph. Combined to form a complete set of nodes ∪ i ε i ε represents the set of edges fused from all local graphs. i , ε cross This represents a cross-platform set of connection edges. The central node applies a graph attention neural network to the causal chain graph to model the strength of causal influence between nodes. The expression is: In the formula, Let σ represent the embedding representation of node j at layer l+1, and let σ represent the nonlinear activation function. Describes the set of neighboring nodes of node j. Sum the results of each neighbor node k. W represents the attention weight of node j in layer l to its neighbor node k. (l) This represents the learnable linear transformation weight matrix of the l-th layer. Let represent the embedding representation of node k at layer l, exp(·) represent the exponential function, and LeakyReLU(·) represent the ReLU activation function with leakage. This represents the transpose of the learnable attention weight vector, [Wh j ||Wh k The symbol ] represents concatenating the feature vectors of nodes j and k after a linear transformation. This represents the embedding representation h of the behavior pattern of each node after calculating the attention score for all neighboring nodes k' of node j and performing inference. j Used to analyze the causal tension of user behavior.
3. The intelligent management method for computer user information security according to claim 2, characterized in that, In step S3, the central node uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph. The method for automatically identifying causal mutation points based on the intermediate graph vector weights is as follows: The automatic identification of causal abrupt change points includes, but is not limited to, short-term device switching, drastic changes in behavior patterns, and breaks in the causal chain. Short-term device switching is defined as the existence of short-term behavior transmission between different devices, and the inferred edges satisfy the following formula: Δt jk = |t j - t k | < δ, and device(ν j ) ≠ device(ν k ) In the formula, Δt jk Represents node ν j With node ν k The time difference between corresponding events, δ, is a preset time threshold, t j , t k Representing behavior nodes ν j and ν k timestamp, device(ν j ) represents node ν j The corresponding device identifier, device(ν) k ) represents node ν k The corresponding device identifier, device(ν) j )≠device(ν k This indicates that the two behavioral nodes come from different devices. The edge is determined to be a mutation edge, and the node is marked as a switching mutation point. The behavioral pattern changes drastically. Based on the node behavioral pattern embedding, the behavioral tension increases abruptly within a short time window. The expression is: In the formula, This represents the behavior pattern embedding vector of the j-th node in the user behavior graph at time t. This represents the embedding vector of the behavior pattern of node j at time t+Δt. Let L be the L2 norm of the vector, ||·||2 represent the degree of change in the behavioral embedding of node j within a short time interval Δt, and γ represent the preset threshold for drastic behavioral change. If the causal chain is broken, then if the behavioral pattern embedding of one of the nodes has no clear leading behavior, then the event node is marked as the causal break point.
4. The intelligent management method for computer user information security according to claim 3, characterized in that, In step S4, the method for calculating a risk score based on the causal mutation point and generating a dynamic security response strategy based on the integrity of the behavioral chain, temporal continuity, and device trust level is as follows: Risk scores are calculated based on the causal mutation points. The central node receives all detected causal mutation points and, combining the integrity of the behavior chain, temporal continuity, and device trust level, calculates a comprehensive risk score for each user's current behavior path. A weighted normalization function is then used to synthesize the final risk score, expressed as: R u =1-(ω1C u +ω2T u +ω3S u ), whereω1+ω2+ω3=1 In the formula, R u Let ω1 represent the risk score of user u, ω2 represent the weighting coefficient of the integrity score, ω3 represent the weighting coefficient of the time continuity score, and ω3 represent the weighting coefficient of the device trust score. ω1 + ω2 + ω3 = 1 indicates that the sum of all weighting coefficients is 1, and a weighted average is applied. C u T represents the completeness score of the user behavior chain. u S represents the time continuity score of user behavior. u This indicates the trust rating of the device used by the user, based on the user's risk score R. u The dynamic security response strategy is generated by combining mutation type, device characteristics and behavioral context. The dynamic security response strategy includes, but is not limited to, no additional authentication is required for normal behavior chains, SMS verification code is triggered when switching to weak trust, and human-machine recognition is initiated when suspicious causal paths occur.
5. The intelligent management method for computer user information security according to claim 4, characterized in that, In step S4, the method for calculating a risk score based on the causal mutation point and generating a dynamic security response strategy based on the integrity of the behavioral chain, temporal continuity, and device trust level is as follows: After user authentication is completed using the dynamic security response strategy, the central node performs a label update operation and a federated graph neural network update based on the user authentication feedback result. The label update operation marks the current behavior chain path as either a safe or risky sample for subsequent federated training supervision. The federated graph neural network update uses the user authentication feedback result as a reinforcement signal to be sent back to the local node, updating the federated graph neural network model parameters θ. i The central nodes are aggregated based on a federated averaging mechanism, expressed as: In the formula, θ g+1 Let represent the global model parameters in the (g+1)th round, E represent the total number of terminal nodes participating in federated learning, and i represent the number of the i-th terminal node. Let e represent the parameters of the local model of the i-th terminal node after the g-th round of training. i Let represent the number of local training data samples held by the i-th terminal node, and e represent the sum of the total number of samples across all terminal nodes. This represents the weight of the i-th node in the total samples, and then the new model parameters θ are... g+1 The data is simultaneously pushed to each of the aforementioned terminal nodes.
6. A computer user information security intelligent management system, based on the computer user information security intelligent management method according to any one of claims 1-5, characterized in that, include: The behavioral factor collection module uses lightweight collectors deployed locally on multiple endpoints to collect behavioral factors without collecting identity information, and then generates factor summaries after processing. The graph structure module, based on the federated graph neural network framework, establishes a graph structure for the factor summary locally through each terminal node, and aggregates the intermediate graph vector weights received by the central node. The behavioral causal chain graph module uses a graph neural network inference algorithm to construct a cross-platform user behavior causal chain graph, and automatically identifies causal mutation points based on the weights of the intermediate graph vectors. The risk scoring module calculates a risk score based on the causal mutation point and generates a dynamic security response strategy based on the integrity of the behavior chain, the continuity of time, and the trust level of the device.
7. The intelligent management system for computer user information security according to claim 6, characterized in that, The operation process of the behavioral factor collection module includes: The lightweight data collector, within the scope of user authorization, is deployed locally on multiple endpoints including PCs, mobile devices, and browser extensions. The behavioral factors include, but are not limited to, login time, operation frequency, file type, and network IP mode. The lightweight data collector locally executes a behavioral modeling function to perform sliding window feature extraction on the original behavioral factor data and combines the feature vectors of the behavioral factors. Where v (i) This represents the behavioral feature vector of the i-th user. Let α represent the mean of the times when the behavior occurs in the time series α of the i-th user. H represents the standard deviation of the action time in the time series α of the i-th user. (i) The entropy value represents the uncertainty of the i-th user's behavior, D. (i) The switching intensity of the i-th user between different devices is represented by a chaotic mapping + local perturbation mechanism for compression and encryption, and a factor digest is generated after processing. The operation process of the graph structure module includes: The graph structure for the factor summary is as follows: In the formula, the node set The feature vectors representing the behavioral factors of different categories, and the edge set ε i Reflecting the dependencies between features, edge weights are calculated using joint mutual information, expressed as: In the formula, This represents the edge weight between node j and node k in the i-th terminal. Represents a node With nodes mutual information, Σ x,y p represents the summation over all possible combinations of eigenvalues (x, y). jk (x, y) represents a node and The value is the joint probability distribution of x and y, p j (x) represents a node The marginal probability, p, of taking the value x alone. k (y) represents a node The marginal probability of a single value being y. The logarithm of the ratio of joint probability to marginal probability reflects the degree of dependence between the two. A local user behavior graph embedding representation is trained. This graph embedding representation first undergoes graph embedding initialization and local graph convolutional propagation. Each node initializes its feature vector using a Chebyshev multinomial spectral graph convolutional propagation mechanism. Then, a variational graph autoencoder is used locally to perform self-supervised learning of the node embeddings, generating latent node representations. A federated graph embedding update mechanism is then established. Each terminal node only uploads a summary of the local graph embedding model weights. Federated aggregation is performed through the central node, and the data is also transmitted back to all terminals through the central node. Graph alignment mapping is then performed to unify the graph embedding dimension and optimize the global consistency loss. Each terminal node receives the aggregated model parameters and mapping function and fine-tunes the federated graph neural network.
8. The intelligent management system for computer user information security according to claim 7, characterized in that, The operation process of the behavioral causal chain graph module includes: The cross-platform user behavior causal chain graph constructs a time causal chain graph structure for all event nodes in the behavior graph according to the event timestamp and operation order, expressed as: In the formula, Represents a cross-platform global causal chain graph. ε represents the set of all nodes in a cross-platform global causal chain graph. c Represents the set of all edges in a cross-platform global causal chain graph. This represents the set of nodes that localize all i-th terminal nodes to the local graph. Combined to form a complete set of nodes ∪ i ε i ε represents the set of edges fused from all local graphs. i , ε cross This represents a cross-platform set of connection edges. The central node applies a graph attention neural network to the causal chain graph to model the strength of causal influence between nodes. The expression is: In the formula, Let σ represent the embedding representation of node j at layer l+1, and let σ represent the nonlinear activation function. Describes the set of neighboring nodes of node j. Sum the results of each neighbor node k. W represents the attention weight of node j in layer l to its neighbor node k. (l) This represents the learnable linear transformation weight matrix of the l-th layer. Let represent the embedding representation of node k at layer l, exp(·) represent the exponential function, and LeakyReLU(·) represent the ReLU activation function with leakage. This represents the transpose of the learnable attention weight vector, [Wh j ||Wh k The symbol ] represents concatenating the feature vectors of nodes j and k after a linear transformation. This represents the embedding representation h of the behavior pattern of each node after calculating the attention score for all neighboring nodes k' of node j and performing inference. j This is used to analyze the causal tension of user behavior; the automatic identification of causal abrupt change points includes, but is not limited to, short-term device switching, drastic changes in behavior patterns, and breaks in the causal chain. Short-term device switching is defined as the existence of short-term behavior transmission between different devices, and the inferred edges satisfy the following formula: Δt jk = |t j - t k | < δ, and device(ν j ) ≠ device(ν k ) In the formula, Δt jk Represents node ν j With node ν k The time difference between corresponding events, δ, is a preset time threshold, t j , t k Representing behavior nodes ν j and ν k timestamp, device(ν j ) represents node ν j The corresponding device identifier, device(ν) k ) represents node ν k The corresponding device identifier, device(ν) j )≠device(ν k This indicates that the two behavioral nodes come from different devices. The edge is determined to be a mutation edge, and the node is marked as a switching mutation point. The behavioral pattern changes drastically. Based on the node behavioral pattern embedding, the behavioral tension increases abruptly within a short time window. The expression is: In the formula, This represents the behavior pattern embedding vector of the j-th node in the user behavior graph at time t. This represents the embedding vector of the behavior pattern of node j at time t+Δt. Let L be the L2 norm of the vector, ||·||2 represent the degree of change in the behavioral embedding of node j within a short time interval Δt, and γ represent the preset threshold for drastic behavioral change. If the causal chain is broken, then if the behavioral pattern embedding of one of the nodes has no clear leading behavior, then the event node is marked as the causal break point. The operation process of the risk scoring module includes: Risk scores are calculated based on the causal mutation points. The central node receives all detected causal mutation points and, combining the integrity of the behavior chain, temporal continuity, and device trust level, calculates a comprehensive risk score for each user's current behavior path. A weighted normalization function is then used to synthesize the final risk score, expressed as: R u =1-(ω1C u +ω2T u +ω3S u ), whereω1+ω2+ω3=1 In the formula, R u Let ω1 represent the risk score of user u, ω2 represent the weighting coefficient of the integrity score, ω3 represent the weighting coefficient of the time continuity score, and ω3 represent the weighting coefficient of the device trust score. ω1 + ω2 + ω3 = 1 indicates that the sum of all weighting coefficients is 1, and a weighted average is applied. C u T represents the completeness score of the user behavior chain. u S represents the time continuity score of user behavior. u This indicates the trust rating of the device used by the user, based on the user's risk score R. u Combining mutation type, device characteristics, and behavioral context, a dynamic security response strategy is generated. This strategy includes, but is not limited to, requiring no additional authentication for normal behavior chains, triggering SMS verification codes for weak trust switching, and initiating human-machine identification for suspicious causal paths. After user authentication is completed, the central node performs label update and federated graph neural network update operations based on the user authentication feedback. The label update operation marks the current behavior chain path as either a safe or risky sample for subsequent federated training supervision signals. The federated graph neural network update uses the user authentication feedback as a reinforcement signal to send back to the local node, updating the federated graph neural network model parameters θ. i The central nodes are aggregated based on a federated averaging mechanism, expressed as: In the formula, θ g+1 Let represent the global model parameters in the (g+1)th round, E represent the total number of terminal nodes participating in federated learning, and i represent the number of the i-th terminal node. Let e represent the parameters of the local model of the i-th terminal node after the g-th round of training. i Let represent the number of local training data samples held by the i-th terminal node, and e represent the sum of the total number of samples across all terminal nodes. This represents the weight of the i-th node in the total samples, and then the new model parameters θ are... g+1 The data is simultaneously pushed to each of the aforementioned terminal nodes.
Citation Information
Patent Citations
Computer user information security intelligent management method and system
CN118228229A
Fraud risk detection method and device based on user node relation network
CN110349004A
Supply chain financial digital identity zero-knowledge authentication and identity management method and device based on block chain
CN118505250A