Cross-platform user behavior analysis method and system based on transfer learning

By extracting cross-domain security features and transferring learning, the challenges of data sharing and analysis between different security platforms have been solved, enabling the correlation and integration of user behavior across platforms and improving the accuracy and real-time performance of network security protection.

CN120811792AActive Publication Date: 2025-10-17LESHAN NORMAL UNIV

Patent Information

Application Number
CN202511308335.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2025-10-17
Estimated Expiration
2045-09-15

AI Technical Summary

Technical Problem

User behavior data between different security platforms is difficult to share and correlate for analysis, which makes it impossible to fully utilize the malicious behavior knowledge accumulated in the source domain to assist the target domain in conducting more accurate user behavior analysis and security protection. Data analysis from a single platform is insufficient to comprehensively capture user behavior characteristics and potential security threats in different scenarios.

Method used

By acquiring network behavior data from the source and target domains, cross-domain security features are extracted and a cross-domain security behavior association graph is constructed. A transfer learning model is used to transfer historical malicious behavior patterns from the source domain to the target domain, generating cross-platform migration security features. Furthermore, abnormal security behavior patterns are identified through temporal security association analysis, and network security protection strategies are generated.

Benefits of technology

It enables the association and integration of user behavior features across platforms, improves the accuracy and timeliness of abnormal behavior detection, enhances network security protection capabilities, and identifies and intercepts risks in real time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811792A_ABST
    Figure CN120811792A_ABST
Patent Text Reader

Abstract

The invention provides a cross-platform user behavior analysis method and system based on transfer learning, and relates to the technical field of network security, first, historical network behavior record data of a source domain security platform and real-time network behavior flow data of a target domain security platform are obtained, the historical network behavior record data comprise security behavior sequences of source domain users in different access scenes, and the real-time network behavior flow data are stored in the target domain security platform; the method comprises the following steps of: performing cross-domain security feature extraction on two types of data, constructing a cross-domain security behavior association graph, migrating source domain historical malicious behavior mode knowledge to a target domain through a migration learning model based on the graph, generating cross-platform migration security features, and performing cross-domain security feature extraction on the target domain historical malicious behavior mode knowledge. And calling a security behavior analysis model to carry out joint modeling and time sequence security association analysis, identifying an abnormal security behavior mode of a target domain user, and finally matching a network security disposal rule base according to the abnormal mode, generating and issuing a protection strategy, and realizing real-time risk interception.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a cross-platform user behavior analysis method and system based on transfer learning. BACKGROUND

[0002] In the field of network security, with the continuous expansion and complexity of network applications, user behavior analysis on different security platforms is crucial to network security. Currently, due to differences in architecture, application scenarios, and user groups, different security platforms have accumulated a large amount of user network behavior data.

[0003] Existing user behavior analysis methods are usually limited to a single platform. For the source domain security platform, although rich historical network behavior record data is accumulated, these data cover a variety of security behavior sequences of users in different access scenarios, such as login operations, permission changes, resource access, and abnormal blocking, but these data can only reflect the behavior patterns of users within the platform. The target domain security platform mainly focuses on real-time network behavior stream data, which contains dynamic security operation records of target domain users in the current session, such as session identification, access request type, permission verification state, and resource operation trajectory, but it lacks in-depth mining and utilization of historical malicious behavior patterns.

[0004] Data between different platforms is difficult to directly share and correlate, resulting in the inability to fully utilize the malicious behavior knowledge accumulated by the source domain to assist the target domain in more accurate user behavior analysis and security protection. At the same time, data analysis of a single platform cannot fully capture the behavior characteristics and potential security threats of users in different scenarios, leaving gaps and blind spots in network security protection. SUMMARY

[0005] In view of the above-mentioned problems, in combination with the first aspect of the present application, the embodiments of the present application provide a cross-platform user behavior analysis method based on transfer learning, which comprises: acquiring historical network behavior record data of a source domain security platform and real-time network behavior stream data of a target domain security platform, the historical network behavior record data containing security behavior sequences of source domain users in different access scenarios, the security behavior sequences containing login operation records, permission change records, resource access records, and abnormal blocking records, the real-time network behavior stream data containing dynamic security operation records of target domain users in the current session, the dynamic security operation records containing session identification, access request type, permission verification state, and resource operation trajectory; performing cross-domain security feature extraction processing on the historical network behavior record data and the real-time network behavior stream data, identifying network behavior types with security semantic association in the source domain and the target domain, and constructing a cross-domain security behavior association graph. Based on the cross-domain security behavior association graph, the historical malicious behavior mode knowledge of the source domain security platform is migrated to the target domain security platform through a transfer learning model to generate cross-platform migration security features that fuse cross-domain malicious mode features. The cross-platform migration security features and the current security behavior features of the target domain in the real-time network behavior flow data are jointly modeled and processed by calling a security behavior analysis model, and abnormal security behavior modes of the target domain user are identified through time sequence security association analysis. According to the abnormal security behavior modes, a network security protection strategy containing risk behavior types and corresponding blocking measures is generated, and the network security protection strategy is issued to an access control module of the target domain security platform to perform real-time risk interception operations.

[0006] In another aspect, the embodiment of the present application also provides a cross-platform user behavior analysis system based on transfer learning, which comprises a processor and a machine readable storage medium.

[0007] Based on the above aspects, the historical network behavior record data of the source domain security platform and the real-time network behavior flow data of the target domain security platform are acquired, cross-domain security features are extracted from the two types of data, and a cross-domain security behavior association graph is constructed, so that the network behavior types with security semantic association in the source domain and the target domain are effectively identified, the association and integration of cross-platform behavior features are realized, the historical malicious behavior mode knowledge of the source domain is migrated to the target domain based on the cross-domain security behavior association graph and using a transfer learning model, cross-platform migration security features that fuse cross-domain malicious mode features are generated, the value of the source domain data is fully utilized, the cross-platform migration security features and the current security behavior features of the target domain are jointly modeled and processed by calling a security behavior analysis model, abnormal security behavior modes of the target domain user are accurately identified through time sequence security association analysis, the accuracy and timeliness of abnormal behavior detection are improved, finally, a network security protection strategy is generated and issued according to the abnormal security behavior modes and a preset network security handling rule library, and real-time risk interception operations are realized, so that the network security protection capability is effectively improved. BRIEF DESCRIPTION OF DRAWINGS

[0008] Figure 1 is an execution flow diagram of the cross-platform user behavior analysis method based on transfer learning provided by the embodiment of the present application.

[0009] Figure 2is a schematic diagram of exemplary hardware and software components of the cross-platform user behavior analysis system based on transfer learning provided by an embodiment of the present application. DETAILED DESCRIPTION

[0010] The present application will be described in detail below with reference to the accompanying drawings, Figure 1 is a flowchart of the cross-platform user behavior analysis method based on transfer learning provided by an embodiment of the present application, which will be described in detail below.

[0011] Step S110: Obtain historical network behavior record data of the source domain security platform and real-time network behavior stream data of the target domain security platform, wherein the historical network behavior record data contains security behavior sequences of the source domain user in different access scenarios, the security behavior sequences contain login operation records, permission change records, resource access records and abnormal blocking records, and the real-time network behavior stream data contains dynamic security operation records of the target domain user in the current session, the dynamic security operation records contain session identification, access request type, permission verification state and resource operation trajectory.

[0012] In this embodiment, the source domain security platform is set as an office network security platform in an enterprise, and the target domain security platform is set as a cloud business system security platform of the enterprise.

[0013] When obtaining the historical network behavior record data of the source domain security platform, the data interface built-in the source domain security platform is required to extract. The data interface complies with a preset data interaction protocol and can call all security behavior sequences in a specified time period from the database of the source domain. These security behavior sequences are classified and stored according to user identification, and each user identification corresponds to various records generated by the user in different access scenarios.

[0014] The extraction of the login operation record needs to cover relevant information of each time the user logs in the system. The login method information is obtained by analyzing the field about the login verification method in the system log, and different login methods correspond to different identification codes; the login device information is extracted from the device access record, including the type identification of the device, the hardware feature code, etc.; and the login location information is determined based on the identification information of the network access point, which corresponds to a specific network area.

[0015] The acquisition of the permission change record depends on the operation log of the permission management module in the source domain security platform. When the user's permission is changed, the system will automatically record the permission level before and after the change, the executor of the change operation, the time point of the change and the reason for the change, etc. These information will be completely extracted and included in the historical network behavior record data.

[0016] The extraction of resource access records requires traversing the access logs of all accessible resources in the source domain. For each user's access behavior, the resource identifier, access start and end time, operation type (such as read, modify, delete, etc.) during access, and access frequency statistics are recorded.

[0017] The extraction of abnormal blocking records comes from the security protection module logs of the source domain security platform. When the system detects abnormal behavior of a user and blocks it, it can record the time of blocking, the blocked user identifier, the specific behavior description that triggered the blocking, the blocking method (such as temporary login prohibition, operation permission restriction, etc.), and the duration of the blocking.

[0018] When obtaining real-time network behavior stream data of the target domain security platform, it is realized through the real-time data collection module of the target domain security platform. This real-time data collection module can monitor the user's session process in real time, and encapsulate the dynamic security operation records in a preset format before transmitting them to the data processing center.

[0019] The session identifier is automatically generated by the target domain security platform when the user establishes a session, and is a unique string used to identify the user's operations during the entire session. The access request type is determined according to the operation instruction initiated by the user in the session, and different operation instructions correspond to different request type identifiers.

[0020] The acquisition of permission verification status is based on the results of the permission verification of the target domain security platform on user operations. When a user performs an operation, the system will perform permission verification and record the verification results (such as pass, fail, need further verification, etc.) in real time.

[0021] The recording of resource operation trajectory is the tracking of the sequence and specific operation content of the user's access and operation of various cloud resources during the session. Each resource operation is recorded, including the resource name, operation type, operation time point, and operation result.

[0022] For user privacy sensitive data involved in the data acquisition process, such as user identity authentication information and personal preference settings, data desensitization technology is used for processing. Specifically, sensitive fields are replaced or encrypted to ensure that specific user information cannot be identified during data storage and transmission. At the same time, access control mechanisms are used to restrict access to sensitive data, only authorized personnel and systems can access these data to prevent privacy leakage.

[0023] Step S120: Cross-domain security feature extraction processing is performed on the historical network behavior record data and the real-time network behavior stream data, network behavior types with security semantic association in the source domain and the target domain are identified, and a cross-domain security behavior association graph is constructed.

[0024] This step aims to extract security features from the behavior data of the source domain and the target domain, find network behavior types with security semantic association, and construct an association graph based thereon.

[0025] Step S121: A source domain security feature set is extracted from the security behavior sequence of the historical network behavior record data, the source domain security feature set includes login behavior features, permission operation features, resource access features, and abnormal response features, the login behavior features are used to describe the login mode, login device, and login location information of the source domain user, the permission operation features are used to represent the change behavior of the user to the system permission, the resource access features are used to describe the path and frequency law of the user accessing the network resource, and the abnormal response features are used to record the blocking record and response type of the security platform to the abnormal behavior.

[0026] When the source domain security feature set is extracted, the historical network behavior record data needs to be deeply analyzed. For the login behavior features, relevant information is extracted from the login operation record and feature processing is performed. The login mode feature is represented by the identification code of the login mode, different identification codes correspond to different login modes; the login device feature is composed of the type identification and hardware feature code of the device; and the login location feature is converted into a corresponding location feature vector based on the identification information of the network access point.

[0027] The extraction of the permission operation features is an analysis of the permission change record, which converts the change behavior of the user to the system permission into a feature vector. The feature vector includes the direction of the permission change (promotion or reduction), the amplitude of the change, the frequency of the change, and the trigger condition of the change.

[0028] The extraction of the resource access features is based on the resource access record. The path feature vector is generated by analyzing the path of the user accessing the network resource; the frequency feature vector is constructed according to the statistical information of the access frequency, and the path feature vector and the frequency feature vector jointly constitute the resource access features.

[0029] The extraction of the abnormal response features is obtained from the abnormal blocking record. The blocking record and response type of the security platform to the abnormal behavior are converted into a feature vector, which includes the frequency of the blocking, the way of the blocking, the speed of the response, and the intensity of the response.

[0030] Step S122: Extract a target domain security feature set from the dynamic security operation record of the real-time network behavior flow data, the target domain security feature set including session access features, permission verification features, resource operation features, and connection state features, the session access features being used to describe session establishment methods and durations of target domain users, the permission verification features being used to represent permission verification results of user operations, the resource operation features being used to reflect operation trajectories of the target domain resources, and the connection state features being used to record stability of network connections and data transmission states.

[0031] When the target domain security feature set is extracted, the real-time network behavior flow data is parsed and characterized. The session access features are extracted from session establishment information to obtain session establishment methods (such as web login, client login, etc.), which are converted into corresponding feature codes; the session duration is calculated by the time difference between the session start and end times, and is converted into a duration feature vector.

[0032] The permission verification features are generated based on permission verification states, different verification results (pass, fail, further verification, etc.) are converted into corresponding feature values to form a permission verification feature vector.

[0033] The resource operation features are extracted by analyzing operation trajectories of the target domain resources. Each type of operation is coded, and an operation sequence feature vector is generated according to the operation sequence and operation object to reflect the resource operation features.

[0034] The connection state features are extracted based on network connection monitoring data. The stability of the network connection is converted into a stability feature vector through information such as connection interruption frequency and connection delay changes; the data transmission state is converted into a transmission state feature vector according to information such as transmission rate and transmission completeness, and the stability feature vector and the transmission state feature vector jointly constitute the connection state features.

[0035] Step S123: Perform security semantic association recognition processing on login behavior features and permission operation features in the source domain security feature set and session access features and permission verification features in the target domain security feature set, determine a cross-domain security behavior type pair with similar protection targets by analyzing security function intentions of the features, and the cross-domain security behavior type pair includes a corresponding relationship between a source domain login behavior and a target domain session establishment behavior, and a corresponding relationship between a source domain permission change behavior and a target domain permission verification behavior.

[0036] The security semantic association recognition processing is the core of this step, and similar behavior types between cross-domains are found by analyzing security function intentions behind the features.

[0037] Step S1231: Extract login behavior semantic description information from the login behavior features of the source domain security feature set, which includes login method description, login device type description, and login location description.

[0038] When extracting the login behavior semantic description information, the login behavior features are semantically analyzed. The login method description is a textual description of the login method in the login behavior features, such as "password login" and "fingerprint login". The login device type description is converted from the device type identification in the login device features to descriptions such as "desktop computer" and "mobile terminal". The login location description is converted from the network access point information corresponding to the login location feature vector to descriptions such as "office area intranet" and "external public network".

[0039] Step S1232: Extract session establishment semantic description information from the session access features of the target domain security feature set, which includes session initiation method description, session device identification description, and session network environment description.

[0040] The session access features are semantically analyzed to extract the session establishment semantic description information. The session initiation method description is a textual description of the session establishment method, such as "initiating a session through a browser" and "initiating a session through a dedicated client". The session device identification description is converted from the device information involved in the session access features to descriptions such as "Windows system device" and "iOS system device". The session network environment description is converted from the network access information at the time of session establishment to descriptions such as "enterprise internal LAN" and "Internet".

[0041] Step S1233: Perform security function intent labeling processing on the login behavior semantic description information and the session establishment semantic description information, and determine the corresponding security protection intent through manual labeling or pre-trained intent recognition model. The security protection intent includes identity authenticity verification intent, device legality verification intent, and environment security verification intent.

[0042] When performing security function intent labeling, if manual labeling is used, security experts can determine the security protection intent behind the login behavior semantic description information and the session establishment semantic description information, and perform corresponding labeling.

[0043] If a pre-trained intent recognition model is used, the pre-trained intent recognition model is trained through a large amount of labeled data and can recognize the security protection intent corresponding to the semantic description information. The login behavior semantic description information and the session establishment semantic description information are input into the pre-trained intent recognition model, and the model can output the corresponding security protection intent label, such as identity authenticity verification intent, device legality verification intent, or environment security verification intent.

[0044] For example, for the login behavior semantic description information "log in to the desktop computer in the office area network through password", the security protection intent can be marked as identity authenticity verification intent and environment security verification intent; for the session establishment semantic description information "initiate a session through a browser in an Internet environment using an iOS system device", the security protection intent can be marked as device legality verification intent and environment security verification intent.

[0045] Step S1234: The login behavior semantic description information and the session establishment semantic description information with the same security protection intent are preliminarily matched to form a candidate security behavior type pair.

[0046] After obtaining the security protection intent of the login behavior semantic description information and the session establishment semantic description information, the security protection intents of the two are compared. When the security protection intents of the two are the same, the corresponding login behavior and session establishment behavior are preliminarily matched to form a candidate security behavior type pair.

[0047] For example, if the security protection intent of a login behavior is identity authenticity verification intent and device legality verification intent, and the security protection intent of a session establishment behavior is also identity authenticity verification intent and device legality verification intent, the two behaviors form a candidate security behavior type pair.

[0048] Step S1235: Extract the permission operation semantic description information and the permission verification semantic description information corresponding to the source domain permission operation feature and the target domain permission verification feature respectively, and determine the corresponding security protection intents to form another group of candidate security behavior type pairs.

[0049] The permission operation semantic description information is extracted from the source domain permission operation feature, and the permission operation semantic description information is a textual description of the user permission change behavior, such as "promote user A's permission from ordinary employee to department administrator" and "revoke user B's file modification permission".

[0050] The permission verification semantic description information is extracted from the target domain permission verification feature, and the permission verification semantic description information is a textual description of the permission verification result, such as "user C's operation permission verification passed" and "user D's operation permission verification failed due to insufficient permissions".

[0051] The same method as step S1233 is used to determine the security protection intents corresponding to the permission operation semantic description information and the permission verification semantic description information, which can include permission rationality verification intent, operation compliance verification intent, etc.

[0052] The permission operation semantic description information and the permission verification semantic description information with the same security protection intention are matched to form another set of candidate security behavior type pairs.

[0053] Step S1236: Function similarity of the candidate security behavior type pairs is calculated. The function similarity score is generated by comparing the coincidence degree of the behavior trigger condition, operation execution flow and security response result. When the function similarity score exceeds a preset similarity threshold, it is determined that the cross-domain security behavior type pair has security semantic association.

[0054] When the function similarity of the candidate security behavior type pairs is calculated, the trigger condition of the two behaviors in each candidate pair is first analyzed. The trigger condition includes the prerequisite of the behavior occurrence, the event triggering the behavior, etc. The trigger condition similarity is obtained by comparing the coincidence degree of the trigger conditions of the two behaviors.

[0055] Then, the operation execution flow is analyzed, including the steps of behavior execution, the involved modules, the order of operation, etc. The flow similarity is obtained by comparing the coincidence degree of the operation execution flows of the two behaviors.

[0056] Then, the security response result is analyzed, including the response generated by the system after the behavior execution, the influence on the system state, etc. The response result similarity is obtained by comparing the coincidence degree of the security response results of the two behaviors.

[0057] The trigger condition similarity, the flow similarity and the response result similarity are comprehensively calculated according to the preset weight to generate the function similarity score. The preset weight is determined according to the importance of each factor in the function similarity evaluation. For example, the weight of the trigger condition and the response result can be higher than the weight of the operation execution flow.

[0058] When the function similarity score exceeds the preset similarity threshold, it is indicated that the candidate security behavior type pair has high function similarity, and it is further determined that the cross-domain security behavior type pair has security semantic association.

[0059] Step S124: Based on the cross-domain security behavior type pair, the association rules between the security behavior types are extracted by combining the network security policy documents of the source domain and the target domain. The association rules include the behavior trigger condition association, the operation object association and the security policy response association.

[0060] The network security policy documents of the source domain and the target domain are obtained. These documents specify the processing mode, trigger condition, operation object, etc. of different security behaviors in detail.

[0061] Based on the cross-domain security behavior type pair, the clauses and regulations related to these behavior types are searched in the network security policy documents. By analyzing these clauses, the association rules between the security behavior types are extracted.

[0062] Behavior trigger condition association refers to the association between the trigger condition of one security behavior and the trigger condition of another security behavior. For example, the trigger condition of "multiple incorrect password logins" in the source domain may be associated with the trigger condition of "re-initiation of session after abnormal interruption" in the target domain.

[0063] Operation object association refers to the association between the operation objects targeted by two security behaviors. For example, the permission change behavior for the "internal database" in the source domain and the access behavior for the "cloud database" in the target domain may have an operation object association.

[0064] Security policy response association refers to the association between the security platform's response policies for two security behaviors. For example, the "temporary account freeze" response to abnormal login behavior in the source domain and the "terminate session connection" response to abnormal session behavior in the target domain may have a policy association.

[0065] Step S125: Based on the cross-domain security behavior type pairs and association rules, a cross-domain security behavior association graph is constructed with security behavior types as nodes and association rules as edges. The edge attributes of the cross-domain security behavior association graph include an association strength description, which is generated based on the functional similarity of cross-domain security behaviors and the overlap of protection targets.

[0066] Each security behavior type in the cross-domain security behavior type pair is used as a node in the association graph, and each node contains information such as the identification and semantic description of the security behavior type.

[0067] The extracted association rules are used as edges connecting nodes. Each edge corresponds to an association rule, and the type of association rule (such as behavior trigger condition association, operation object association, etc.) is recorded.

[0068] The edge association strength description is generated by combining the functional similarity and protection target overlap of cross-domain security behaviors. Functional similarity is the functional similarity score calculated in step S1236, while protection target overlap is obtained by comparing the overlap of the protection targets of two security behaviors.

[0069] The functional similarity and the protection target overlap are integrated, for example, taking the average of the two, or adding them after assigning different weights according to importance, to obtain a numerical value describing the association strength. The larger the value, the higher the association strength.

[0070] The constructed cross-domain security behavior association map can clearly show the association relationship and association strength between security behavior types in the source domain and the target domain.

[0071] Step S130: Based on the cross-domain security behavior association graph, the historical malicious behavior pattern knowledge of the source domain security platform is migrated to the target domain security platform through a transfer learning model to generate cross-platform migration security features that fuse cross-domain malicious pattern features.

[0072] This step uses the cross-domain security behavior association graph to realize cross-domain migration of malicious behavior pattern knowledge through a transfer learning model, thereby generating security features that fuse cross-domain malicious pattern features, enhancing the target domain's ability to identify malicious behavior.

[0073] Step S131: The malicious behavior samples in the historical network behavior record data are input into the source domain security feature layer of the transfer learning model, and based on the association rules in the cross-domain security behavior association graph, the source domain malicious behavior features are processed in the feature space mapping, the source domain malicious behavior features are converted from the source domain security feature space to the target domain security feature space, and the initial migration malicious features are generated, which include the source domain common malicious login pattern features, the unauthorized operation pattern features and the abnormal resource access pattern features.

[0074] Malicious behavior samples are selected from historical network behavior record data. These samples are known malicious behavior sequences labeled, such as multiple attempts to crack passwords, unauthorized privilege escalation, and large amounts of sensitive resource downloads.

[0075] These malicious behavior samples are input into the source domain security feature layer of the transfer learning model, which is responsible for extracting and representing the source domain malicious behavior features. The source domain security feature layer is composed of multiple neurons, which extract the source domain malicious behavior features by processing the input malicious behavior samples. These features exist in the form of feature vectors in the source domain security feature space.

[0076] Based on the association rules in the cross-domain security behavior association graph, the corresponding relationship between the source domain malicious behavior features and the feature dimensions in the target domain security feature space is determined. For example, the "login frequency" dimension of the malicious login pattern feature in the source domain may correspond to the "session initiation frequency" dimension of the session establishment behavior feature in the target domain, and the "login location anomaly" dimension in the source domain may correspond to the "session network environment anomaly" dimension in the target domain.

[0077] According to these corresponding relationships, the source domain malicious behavior feature vector is processed in the feature space mapping. Specifically, each feature component in the source domain malicious behavior feature vector is mapped to the target domain security feature space according to the corresponding dimension to generate a feature vector in the target domain security feature space, i.e. the initial migration malicious feature.

[0078] The malicious login mode feature in the initial migration malicious feature includes the mapping features of the common modes in the source domain, such as multiple failed logins in a short time and login initiation from abnormal positions in the target domain feature space; the unauthorized operation mode feature covers the mapping features of the modes such as unauthorized permission promotion and operation beyond the permission range in the source domain; and the abnormal resource access mode feature includes the mapping features of the modes such as a large number of access to sensitive resources and frequent access to resources during non-working hours in the source domain.

[0079] Step S132: The domain offset calibration processing is performed on the initial migration malicious feature by the security domain adaptation module of the migration learning model, a preset adjustment coefficient corresponding to the correlation strength description is based on the cross-domain security behavior correlation graph, the weight of each feature component in the initial migration malicious feature is dynamically adjusted, and the calibrated migration malicious feature is generated, the preset adjustment coefficient is positively correlated with the correlation strength description, and the corresponding adjustment coefficient is given to the corresponding feature component according to the correlation strength description.

[0080] The security domain adaptation module is a key module in the migration learning model for processing the domain difference between the source domain and the target domain, which adjusts the initial migration malicious feature to reduce the influence of domain offset.

[0081] Step S1321: In the security domain adaptation module, a security domain difference evaluation function is constructed based on the cross-domain security behavior correlation graph, and the security domain difference evaluation function is used to quantify the security protection rule difference between the initial migration malicious feature and the target domain security feature set.

[0082] The construction of the security domain difference evaluation function needs to comprehensively consider the differences between the source domain and the target domain in the security protection rules reflected in the cross-domain security behavior correlation graph. These differences may be reflected in the judgment standard of the behavior trigger condition, the severity of the security response strategy, the division granularity of the operation permission, etc.

[0083] The input of the function is the initial migration malicious feature and the target domain security feature set, and by calculating the difference between the two in the feature dimension related to each security protection rule, a quantitative difference value is output. For example, for the rule-related dimension of "login frequency threshold", the difference between the threshold corresponding to the feature component mapped from the source domain and the actual threshold of the target domain is compared, and the above difference is included in the function calculation.

[0084] Step S1322: According to the security domain difference evaluation function, the domain offset index of each feature component in the initial migration malicious feature is calculated, the domain offset index is positively correlated with the security rule difference degree of the feature component in the source domain and the target domain, and the domain offset index value of the corresponding feature component corresponds to the difference degree.

[0085] Each feature component in the initial migrated malicious feature is respectively input into the security domain difference evaluation function, and the difference degree of the feature component under the security rules of the source domain and the target domain is calculated. According to the size of the difference degree, the corresponding domain offset index is determined. The greater the difference degree, the higher the domain offset index, indicating that the applicability of the feature component in the target domain is lower, and a large adjustment is needed.

[0086] For example, if a certain feature component in the initial migrated malicious feature corresponds to "the password error threshold is 5 times" in the source domain, and the corresponding threshold in the target domain is 3 times, the difference is large, and the domain offset index of the feature component is high.

[0087] Step S1323: Extract the association strength description corresponding to each feature component from the cross-domain security behavior association graph, query the preset mapping table based on the association strength description, and determine the preset adjustment coefficient of each feature component, wherein the association strength description and the preset adjustment coefficient in the mapping table are in a corresponding relationship.

[0088] The association strength description of each edge in the cross-domain security behavior association graph corresponds to the association closeness of the associated security behavior type in the source domain and the target domain. For each feature component in the initial migrated malicious feature, find the corresponding association relationship in the association graph, and extract the association strength description of the association relationship.

[0089] The preset mapping table is constructed according to a large number of domain migration experiences and security expert knowledge, which records the preset adjustment coefficient corresponding to different association strength descriptions. The higher the value of the association strength description, the larger the corresponding preset adjustment coefficient, indicating that the reliability of the feature component in cross-domain migration is higher, and a higher weight should be given.

[0090] For example, when the association strength description is "strong association", the preset adjustment coefficient may be 0.8; when the association strength description is "moderate association", the preset adjustment coefficient may be 0.5; and when the association strength description is "weak association", the preset adjustment coefficient may be 0.2.

[0091] Step S1324: Generate a feature component calibration parameter based on the domain offset index and the preset adjustment coefficient.

[0092] The generation of the feature component calibration parameter is obtained by comprehensively considering the domain offset index and the preset adjustment coefficient. Specifically, the domain offset index is used to modify the preset adjustment coefficient. The higher the domain offset index, the greater the attenuation effect on the preset adjustment coefficient, and the smaller the obtained calibration parameter; on the contrary, the lower the domain offset index, the closer the calibration parameter is to the preset adjustment coefficient.

[0093] For example, the calibration parameter can be generated in a manner that the preset adjustment coefficient is multiplied by (1 minus the ratio of the domain offset index and the maximum domain offset index), so as to realize dynamic adjustment of the feature component weight.

[0094] Step S1325: multiplying each feature component in the initial migrated malicious feature by the corresponding feature component calibration parameter to generate an adjusted feature component.

[0095] For each feature component in the initial migrated malicious feature, the value of the feature component is multiplied by the corresponding feature component calibration parameter to obtain an adjusted feature component. Through this operation, the feature component with small domain offset and high correlation strength has a higher value after adjustment and plays a greater role in subsequent feature processing; and the influence of the feature component with large domain offset and low correlation strength is weakened.

[0096] Step S1326: combining the adjusted feature components in the order of the feature dimensions of the target domain security feature set to generate a calibrated migrated malicious feature.

[0097] According to the arrangement order of the feature dimensions in the target domain security feature set, the adjusted feature components are rearranged and combined to form a calibrated migrated malicious feature, which completely conforms to the dimension structure of the target domain security feature space and can better adapt to the security environment of the target domain.

[0098] Step S133: extracting a target domain basic security feature from the target domain security feature set, the target domain basic security feature including a permission level feature, a resource access control list feature and a session management rule feature specific to the target domain.

[0099] The features that can reflect the unique security properties of the target domain are filtered from the target domain security feature set as the target domain basic security feature. The permission level feature is related to the user permission level system divided by the target domain according to its business needs, including the operation range corresponding to different permission levels and the division standard of the permission level; the resource access control list feature records the access permission settings of each resource in the target domain for different users or user groups, such as which user can access a certain resource and can perform which operation; and the session management rule feature covers the rules of the target domain for session creation, maintenance and termination, such as session timeout time and session concurrency limit.

[0100] The extraction of these features needs to be combined with the security configuration file and policy document of the target domain to ensure that the extracted features can accurately reflect the basic security properties of the target domain.

[0101] Step S134: associating and integrating the calibrated migrated malicious feature with the target domain basic security feature to generate a fusion intermediate security feature.

[0102] The correlation integration processing is a process of organically combining the calibrated migrated malicious features and the target domain basic security features. First, the internal correlation between the two features is analyzed, for example, the unauthorized operation mode feature in the calibrated migrated malicious features may be associated with the permission level feature in the target domain basic security features, and the abnormal resource access mode feature may be associated with the resource access control list feature.

[0103] According to the correlation relationship, the two features are spliced. The calibrated migrated malicious feature vector and the target domain basic security feature vector are connected according to the order of feature dimensions to form a longer feature vector, that is, a fusion intermediate security feature. The above splicing method retains the complete information of the two features, so that the fused feature contains not only the malicious mode knowledge migrated from the source domain, but also the basic security characteristics of the target domain.

[0104] Step S135: calling a malicious knowledge distillation unit of the migration learning model, encoding the historical malicious behavior mode knowledge of the source domain security platform into a malicious knowledge vector, the malicious knowledge vector containing malicious behavior sequence templates, abnormal feature combination modes and security response rules identified by the source domain.

[0105] The function of the malicious knowledge distillation unit is to extract and encode the relatively complex historical malicious behavior mode knowledge in the source domain into a concise vector form. First, the historical malicious behavior mode knowledge of the source domain security platform is summarized and summarized, and the representative malicious behavior sequence templates are extracted, such as the above typical sequence of “attempting to log in —— permission promotion —— resource stealing”; the abnormal feature combination mode, that is, the combination form when multiple abnormal features appear at the same time, such as the combination of “remote login + a large number of permission queries + sensitive resource access”; and the security response rules for these malicious behaviors, such as “detecting remote login and a large number of permission queries, triggering secondary verification” and the like.

[0106] Then, the knowledge is converted into a malicious knowledge vector by using an encoding algorithm. In the encoding process, each malicious behavior sequence template, abnormal feature combination mode and security response rule is mapped to a specific dimension in the vector, and the numerical size represents the importance or frequency of the knowledge.

[0107] Step S136: performing knowledge enhancement processing on the fusion intermediate security feature through the malicious knowledge vector, so that the fusion intermediate security feature carries the regularity knowledge of the source domain malicious behavior mode, generating a cross-platform migration security feature, the cross-platform migration security feature containing the cross-domain common malicious features migrated from the source domain and the local security features of the target domain.

[0108] The knowledge enhancement processing is a process of integrating the source domain malicious behavior pattern knowledge contained in the malicious knowledge vector into the fusion intermediate security features. Specifically, the malicious knowledge vector and the fusion intermediate security feature vector are spliced to form a new feature vector, i.e., the cross-platform migration security feature.

[0109] The spliced cross-platform migration security feature not only contains the cross-domain common malicious features migrated from the source domain represented by the calibrated migration malicious features, and the target domain local security features represented by the target domain basic security features, but also integrates the regularity knowledge of the source domain malicious behavior pattern, thereby greatly enhancing the representation ability of the feature.

[0110] Step S140: calling a security behavior analysis model to jointly model the cross-platform migration security feature and the target domain current security behavior feature in the real-time network behavior flow data, and identifying the abnormal security behavior pattern of the target domain user through time sequence security correlation analysis.

[0111] In this step, the security behavior analysis model is used to combine the cross-platform migration security feature and the target domain current security behavior feature for modeling analysis, and find out the abnormal security behavior pattern through time sequence correlation analysis.

[0112] The security behavior analysis model is an intelligent analysis framework integrating recurrent neural network (RNN) and long short-term memory network (LSTM), which is used to jointly model the cross-platform migration security feature and the target domain real-time network behavior feature, and identify the abnormal security behavior pattern of the target domain user through time sequence security correlation analysis. The security behavior analysis model includes multiple layers of structures: Shared security feature layer: using RNN to extract the correlation between cross-domain common malicious behavior patterns and target domain real-time behaviors, and generating a cross-domain common security feature vector; Target domain security feature layer: combining the target domain security policy document to strengthen the feature components corresponding to the local unique security rules, and generating a target domain unique security feature vector; Time sequence security correlation module: generating a time sequence correlation model through time window division, behavior dependence rule extraction (such as trigger condition dependence, operation sequence dependence), and security behavior transition probability matrix construction, which is used to describe the difference between normal and malicious behavior patterns; Abnormality judgment mechanism: realizing real-time identification and early warning of abnormal security behaviors by calculating the security deviation (weighted fusion feature component difference and protection priority) between actual behaviors and expected behaviors.

[0113] Step S141: input the cross-platform migration security features and the target domain current security behavior features into the shared security feature layer of the security behavior analysis model, perform deep security feature extraction processing through a recurrent neural network, capture the correlation between the cross-domain common malicious behavior patterns and the real-time behavior of the target domain, and generate a cross-domain common security feature vector.

[0114] The target domain current security behavior features are features reflecting the current operation state of the user extracted from real-time network behavior flow data, including the current session state, ongoing resource operations, permission verification results, etc.

[0115] The cross-platform migration security features and the target domain current security behavior features are simultaneously input into the shared security feature layer of the security behavior analysis model. The shared security feature layer adopts a recurrent neural network (RNN) structure, which can process sequence data and capture the time sequence dependency relationship therein.

[0116] The recurrent neural network, through its internal memory unit, can retain previously processed feature information when processing input features, thereby analyzing the correlation between the cross-domain common malicious behavior patterns contained in the cross-platform migration security features and the real-time behavior of the target domain. For example, when an operation sequence similar to the cross-domain common malicious behavior pattern appears in the target domain current security behavior features, the network can identify the above correlation.

[0117] Among them, the cross-domain common malicious behavior pattern refers to a set of malicious behavior features with security semantic correlation in the source domain (enterprise internal office network) and the target domain (cloud business system), which is a common threat pattern refined from the source domain historical malicious behavior knowledge through transfer learning and adapted to the target domain.

[0118] After processing by the recurrent neural network, deep features reflecting the above correlation are extracted, forming a cross-domain common security feature vector.

[0119] Step S142: input the cross-domain common security feature vector into the target domain security feature layer of the security behavior analysis model, and perform targeted optimization processing combined with the target domain security policy document to strengthen the feature components corresponding to the target domain specific security rules, and generate a target domain specific security feature vector.

[0120] The target domain security feature layer focuses on optimization processing of the cross-domain common security feature vector related to the target domain. First, the security policy document of the target domain is obtained, which specifies the security rules specific to the target domain, such as access restrictions for specific resources, approval processes for special operations, etc.

[0121] According to the target domain security policy document, determine the feature components that need to be strengthened. These feature components correspond to security rules specific to the target domain, such as feature components related to "sensitive field access permissions of cloud database", feature components related to "cross-region data transmission approval", etc.

[0122] The feature components in the cross-domain common security feature vector are strengthened, for example, by increasing their weights, so that these feature components are more prominent in subsequent analysis. After the above targeted optimization, a target domain specific security feature vector is generated, which better reflects the security behavior characteristics of the target domain itself.

[0123] Step S143: Fuse the cross-domain common security feature vector and the target domain specific security feature vector to generate a joint security behavior feature vector, which contains cross-domain migrated malicious mode features and target domain current real-time security behavior features.

[0124] The fusion process uses splicing to connect the cross-domain common security feature vector and the target domain specific security feature vector in order of feature dimensions to form a joint security behavior feature vector.

[0125] The above fusion method preserves all the information of the two feature vectors, so that the joint security behavior feature vector contains both cross-domain migrated malicious mode features and target domain current real-time security behavior features.

[0126] Step S144: Call the time sequence security correlation module of the security behavior analysis model to perform time sequence dependency analysis on the joint security behavior feature vector, and construct a time sequence correlation model of user security behavior sequence by analyzing the trigger relationship, sequence relationship and causal relationship between security behavior features at consecutive time points. The time sequence correlation model is used to describe the feature change rule under normal security behavior mode and the feature abnormal trajectory under malicious behavior mode.

[0127] The time sequence security correlation module is responsible for analyzing the joint security behavior feature vector in time sequence to mine the dependency relationship between security behaviors.

[0128] Step S1441: Arrange the joint security behavior feature vector in time sequence according to the time sequence of security behavior occurrence, each feature element in the security behavior time sequence corresponds to a user security behavior feature at a time point, and the user security behavior feature includes login status, permission level, resource access record and operation result at the time point.

[0129] According to the time stamp of the security behavior, each feature element in the joint security behavior feature vector is sorted to form a security behavior time sequence. Each feature element corresponds to a user security behavior feature at a specific time point, wherein the login state includes logged in, not logged in, login exception, etc.; the permission level is the permission level possessed by the user at the time point; the resource access record covers the resource identifier and operation type accessed at the time point; and the operation result includes success, failure, rejection, etc.

[0130] Step S1442: In the timing security association module, the security behavior time sequence is subjected to time window division processing, and a plurality of continuous security behavior feature elements are grouped into a security behavior window. Each security behavior window contains continuous security behavior features within a preset time length, and the time length is determined according to the average response time of the target domain security event.

[0131] The division of the time window is to facilitate the analysis of the security behavior features within a certain time range. The determination of the preset time length needs to refer to the average response time of the target domain security event to ensure that each time window can cover a complete security event processing period or a related continuous behavior sequence.

[0132] For example, if the average response time of the target domain security event is 10 minutes, the length of the time window can be set to 10 minutes, and each security behavior window contains all security behavior feature elements within the 10 minutes.

[0133] Step S1443: The feature elements in each security behavior window are subjected to association analysis. By analyzing the trigger conditions, operation sequence and causality between the preceding security behavior feature elements and the subsequent security behavior feature elements in the security behavior window, the dependency rules between the security behaviors are extracted, including behavior trigger condition dependency, operation execution sequence dependency and security state change dependency.

[0134] For each security behavior window, the relationship between the preceding feature elements and the subsequent feature elements is analyzed one by one. The behavior trigger condition dependency refers to the occurrence of the subsequent behavior depending on the preceding behavior meeting a specific trigger condition, such as "only after successful login (preceding behavior) can resource access (subsequent behavior) be performed"; the operation execution sequence dependency refers to the fixed execution sequence between behaviors, such as "first apply for permission (preceding behavior), then change permission (subsequent behavior)"; and the security state change dependency refers to the preceding behavior causing the system security state to change, thereby triggering the subsequent behavior, such as "permission elevation (preceding behavior) causes the system security state level to decrease, thereby triggering security audit (subsequent behavior)".

[0135] Through the analysis of these relationships, the corresponding dependency rules are extracted as the basis for describing the association between security behaviors.

[0136] Step S1444: constructing a security behavior transition probability matrix based on the dependency rules, the security behavior transition probability matrix being used to represent the possibility of transitioning from one security behavior feature element to the next security behavior feature element, and a higher matrix element value representing a higher frequency of occurrence of the corresponding behavior transition path in the normal security behavior mode.

[0137] The rows and columns of the security behavior transition probability matrix correspond to different security behavior feature elements, respectively. The element value in the matrix represents the probability of transitioning from the security behavior feature element corresponding to the row to the security behavior feature element corresponding to the column. The calculation of the probability is based on the dependency rules and the frequency of occurrence of the two behavior feature elements in the historical behavior data. For example, if the number of times that behavior A is followed by behavior B in the historical data accounts for a high proportion of the total number of occurrences of behavior A, then the element value of A row and B column in the matrix is larger.

[0138] Step S1445: combining the security behavior transition probability matrices of multiple security behavior windows, modeling and processing the long-term dependence of the security behavior time sequence through a long short-term memory network, and generating a time sequence correlation model for describing the differences between the normal and malicious security behavior modes, the time sequence correlation model including a normal security behavior transition path set and a malicious security behavior transition path set.

[0139] The long short-term memory network (LSTM) can effectively capture the long-term dependence in the time sequence and is suitable for modeling the security behavior time sequence. The security behavior transition probability matrices of multiple security behavior windows are input into the long short-term memory network as inputs.

[0140] The network distinguishes the behavior transition characteristics in the normal security behavior mode and the malicious security behavior mode by learning the behavior transition rules between different windows. The normal security behavior transition path set includes behavior transition paths that frequently occur in the normal case, and the transition probability thereof is higher. The malicious security behavior transition path set includes special transition paths that only occur in the malicious behavior mode, and the occurrence probability thereof in the normal mode is lower.

[0141] The generated time sequence correlation model can store these path sets in a structured data form, and each path includes a sequence of behavior feature elements, a transition probability, and a corresponding behavior mode label (normal or malicious). For example, the normal security behavior transition path can be “login success — query public resources — logout”, and the transition probability thereof is higher. The malicious security behavior transition path can be “abnormal login — privilege escalation attempt — access sensitive resources”, and the transition probability thereof in the normal mode is lower.

[0142] Step S145: Based on the time series association model, the joint security behavior feature vector is subjected to malicious behavior pattern prediction processing to generate an expected security behavior feature sequence of the target domain user. The expected security behavior feature sequence reflects the security behavior features that the user should subsequently generate under normal security rules.

[0143] The constructed time series association model is used to predict the joint safety behavior feature vector. First, the safety behavior feature sequence of the current moment and the previous moment is extracted from the joint safety behavior feature vector and input into the time series association model.

[0144] The temporal association model analyzes the degree of match between the current behavior sequence and the normal path based on a set of normal safety behavior transition paths, predicting the user's likely safety behavior characteristics at subsequent time points. During the prediction process, the temporal association model can reference the transition probabilities of normal safety behavior transition paths, prioritizing transition paths with higher probabilities as the basis for prediction.

[0145] The generated expected security behavior feature sequence is a chronological sequence of feature vectors, each corresponding to an expected security behavior feature at a future point in time. These features encompass aspects such as login status, permission level, resource access plan, and operation type, reflecting the expected user behavior under normal security rules. For example, if the user is currently logged in and accessing standard work resources, the expected security behavior feature sequence might include "continue accessing relevant work resources - submitting operation results - remaining logged in or logging out normally."

[0146] Among them, normal security rules are a behavioral specification system built based on the target domain security policy document, historical normal behavior data, and cross-domain security behavior association maps. They are used to define the behavioral characteristics and security protection guidelines of target domain users in legal operation scenarios. Its core components include: Dynamic behavior baseline: A set of normal security behavior transfer paths generated by a time series association model, such as "successful login - access to public resources - normal logout" and other high-frequency behavior sequences, reflecting the temporal dependencies of common user operations. Static policy constraints: Rules clearly defined in the target domain security policy document, including session management rules (such as session timeouts and concurrency limits), permission level classification standards (such as the scope of operations corresponding to different permissions), and resource access control lists (such as access rights configuration for sensitive resources). Expected behavior generation mechanism: A sequence of security behavior features that a user should subsequently generate is predicted based on a temporal association model. This reflects the expected behavior under normal rule constraints and serves as a benchmark for determining whether the actual behavior is abnormal (e.g., expected resource access scope, permission operation type, etc.).

[0147] Step S146: Real-time comparison analysis is performed between the target domain current security behavior feature and the expected security behavior feature sequence, and a security deviation degree between the actual security behavior feature and the expected security behavior feature is calculated. When the security deviation degree exceeds a preset deviation threshold, the corresponding behavior feature is marked as an abnormal security candidate feature.

[0148] Real-time comparison analysis is a key link for judging whether the current behavior of the user is abnormal. The security deviation degree is calculated to quantify the difference between the actual behavior and the expected behavior.

[0149] Step S1461: A real-time security behavior feature vector is extracted from the target domain current security behavior feature, and the real-time security behavior feature vector includes a login state vector, a permission operation vector, a resource access vector, and a connection state vector at a current time point.

[0150] The login state vector is used to describe the login situation of the current user, including login identification, login duration, login device state, and the like. The permission operation vector records the permission-related operations being performed by the current user, such as permission query, permission application, and the like. The resource access vector reflects the access situation of the current user to resources, including the accessed resource identification, access mode, access progress, and the like. The connection state vector includes current state information of network connection, such as connection speed, connection stability, data transmission volume, and the like.

[0151] Step S1462: An expected security behavior feature vector corresponding to the current time point is extracted from the expected security behavior feature sequence, and the expected security behavior feature vector is generated based on the prediction of the normal behavior mode by the time sequence correlation model, and includes expected login state, expected permission operation, expected resource access, and expected connection state.

[0152] According to the current time point, the corresponding expected security behavior feature vector in the expected security behavior feature sequence is found. The expected login state in the expected security behavior feature vector corresponds to the real-time login state vector, the expected permission operation corresponds to the real-time permission operation vector, the expected resource access corresponds to the real-time resource access vector, and the expected connection state corresponds to the real-time connection state vector.

[0153] For example, if the current time point is 10 minutes after the user logs in, the expected resource access in the expected security behavior feature vector can be “accessing document resources of project A”, and the expected permission operation can be “no permission change operation”.

[0154] Step S1463: After the feature component alignment processing of the real-time security behavior feature vector and the expected security behavior feature vector, a difference vector is calculated between the corresponding feature components of the real-time security behavior feature vector and the expected security behavior feature vector. Each element of the difference vector represents the deviation degree of the actual value of a single security feature component from the expected value.

[0155] The feature component alignment processing is to ensure that the real-time security behavior feature vector and the expected security behavior feature vector are one-to-one corresponding in the feature dimension, facilitating the subsequent difference calculation. For the same feature dimension existing in the two vectors, direct alignment is performed; for certain feature dimensions existing only in one of the vectors, the feature component at the corresponding position in the other vector is set to a default value (such as zero), indicating that the feature has no actual meaning in the current case.

[0156] After alignment, the difference of the corresponding feature components is calculated. For each feature component, the component value in the real-time security behavior feature vector is subtracted from the component value in the expected security behavior feature vector, and the difference value obtained is taken as the element value at the corresponding position in the difference vector. The size of the element value represents the deviation degree of the actual value of a single security feature component from the expected value, and a positive value indicates that the actual value is higher than the expected value, and a negative value indicates that the actual value is lower than the expected value.

[0157] Step S1464: Based on the protection priority of each security feature component in the target domain security policy, a priority weight is assigned to each element in the difference vector.

[0158] The importance of different security feature components in the protection system is explicitly specified in the target domain security policy, i.e., the protection priority. For example, the protection priority of feature components related to sensitive resource access is higher, while the protection priority of feature components related to ordinary resource browsing is lower.

[0159] According to these protection priorities, a corresponding priority weight is assigned to each element in the difference vector. The higher the protection priority of a feature component, the greater its corresponding priority weight, meaning that the deviation of this feature component has a greater impact on the overall security situation. The value range of the priority weight is set according to actual needs to ensure that the relative importance of different feature components can be reflected.

[0160] Step S1465: Weighted inner product operation is performed on the difference vector and the priority weight to generate a security deviation degree comprehensive score. The higher the security deviation degree comprehensive score, the greater the deviation degree of the actual security behavior from the expected normal behavior.

[0161] The process of weighted inner product operation is as follows: each element in the difference vector is multiplied by the corresponding priority weight, and then all the product results are added to obtain the sum, which is the security deviation degree comprehensive score.

[0162] For example, if the difference vector is [d1, d2, d3] and the corresponding priority weight is [w1, w2, w3], the comprehensive score of the security deviation degree is d1 x w1 + d2 x w2 + d3 x w3. Through the above calculation method, both the deviation degree of each feature component and the importance of the feature component in security protection are considered, so that the comprehensive score can more accurately reflect the overall deviation between the actual behavior and the expected behavior.

[0163] Step S1466: comparing the comprehensive score of the security deviation degree with a preset security threshold, and determining that the current security behavior feature is an abnormal security candidate feature when the comprehensive score of the security deviation degree exceeds the preset security threshold, and recording the time point and behavior details corresponding to the abnormal security candidate feature.

[0164] The preset security threshold is set according to the security requirements and historical security event data of the target domain, and is a critical value for judging whether the behavior is abnormal. The setting of the preset security threshold needs to comprehensively consider the false positive rate and the false negative rate of the system to ensure effective identification of abnormal behaviors while avoiding excessive false positives.

[0165] When the comprehensive score of the security deviation degree exceeds the preset security threshold, it indicates that the current security behavior deviates greatly from the expected normal behavior, and there may be a security risk, so it is marked as an abnormal security candidate feature. At the same time, the time point, user identifier, specific behavior content (such as accessed resources, executed operations, etc.), and the comprehensive score of the security deviation degree corresponding to the abnormal security candidate feature are recorded in detail.

[0166] Step S147: performing a context security correlation verification process on the abnormal security candidate feature, and combining the adjacent security behavior features before and after the abnormal security candidate feature to determine whether it conforms to the feature combination rule of the known malicious behavior mode, and when there are abnormal security candidate features that continuously conform to the malicious mode, determining an abnormal security behavior mode, the abnormal security behavior mode includes the starting time point of the abnormal behavior, the continuous behavior sequence, and the corresponding security risk type.

[0167] The context security correlation verification process is used to further confirm whether the abnormal security candidate feature belongs to a real abnormal security behavior mode to avoid misjudgment due to accidental deviation of a single feature.

[0168] First, the security behavior features adjacent to the abnormal security candidate feature are obtained to form a behavior feature sequence segment containing the candidate feature. The length of the behavior feature sequence segment is set according to the actual situation, and usually covers a certain number of behavior features before the candidate feature and a certain number of behavior features after the candidate feature to fully reflect the context environment of the candidate feature.

[0169] Then, the behavior feature sequence fragment is compared with a feature combination rule of a known malicious behavior pattern. The feature combination rule of the known malicious behavior pattern is summarized from historical malicious behavior data and security expert knowledge, and contains a feature sequence pattern of a typical malicious behavior, such as "abnormal login - multiple privilege escalation attempts - access to sensitive resources - large amount of data download".

[0170] In the comparison process, whether the behavior features in the sequence fragment match the feature combination rule of the malicious pattern is analyzed, including the order of behaviors, the value range of feature components, the change trend of security deviation, and the like. If there are continuous abnormal security candidate features in the sequence fragment, and the combination of the features conforms to the feature combination rule of a known malicious behavior pattern, it can be determined that the behavior pattern corresponding to the sequence fragment is an abnormal security behavior pattern.

[0171] After the abnormal security behavior pattern is determined, the starting time point (i.e., the time when the first abnormal security candidate feature appears), the continuous behavior sequence (the complete behavior sequence from the starting time point to the last abnormal security candidate feature), and the corresponding security risk type (such as data leakage risk, privilege abuse risk, and the like) need to be determined.

[0172] Step S150: According to the abnormal security behavior pattern, a network security protection strategy containing a risk behavior type and a corresponding blocking measure is generated by matching a preset network security handling rule library, and the network security protection strategy is issued to an access control module of a target domain security platform to perform a real-time risk interception operation.

[0173] In this step, according to the identified abnormal security behavior pattern, a corresponding network security protection strategy is formulated and executed, so as to realize real-time interception and handling of security risks.

[0174] Step S151: Risk behavior type classification processing is performed on the abnormal security behavior pattern, the feature change trajectory of the abnormal security behavior pattern is matched with a malicious behavior template library in the network security handling rule library, and the risk behavior type to which the abnormal behavior belongs is determined, the risk behavior type including an unauthorized login risk, an unauthorized operation risk, a malicious resource transmission risk, and an abnormal connection risk, each risk behavior type corresponding to a specific malicious behavior feature combination.

[0175] The risk behavior type classification processing is a prerequisite for accurately formulating a protection strategy, and the risk type is determined by matching a malicious behavior template.

[0176] For example, step S1511: a feature change trajectory is extracted from the abnormal security behavior pattern, the feature change trajectory containing a starting time point of the abnormal behavior, a behavior sequence, a resource identifier involved, an operation result, and a change trend of a security deviation.

[0177] The extraction of the feature change trajectory is a detailed analysis of the abnormal security behavior pattern. The starting time point determines the starting time of the abnormal behavior; the behavior sequence is the sequential arrangement of all behavior features in the abnormal behavior process; the involved resource identifier records the resources targeted by the abnormal behavior; the operation result reflects the execution of each behavior (success, failure, etc.); and the security deviation degree change trend shows the change of the comprehensive score of the security deviation degree from the beginning to the end of the abnormal behavior (such as gradually increasing, suddenly increasing and then remaining stable, etc.).

[0178] For example, the feature change trajectory of a certain abnormal security behavior pattern can be: the starting time point is 9:00, the behavior sequence is "login from a different place - attempt to modify permissions - access customer database - download a large amount of data", the involved resource identifier is "customer database", the operation result is "success - failure - success - success" in turn, and the security deviation degree change trend is "gradually increasing to exceed the threshold value and then remaining high".

[0179] Step S1512: retrieve a preset malicious behavior template set from a malicious behavior template library of a network security handling rule library, the malicious behavior template set including an unauthorized login template, an unauthorized operation template, a malicious resource transmission template, and an abnormal connection template, each malicious behavior template including a typical malicious behavior sequence, a feature component threshold value range, and a security deviation degree change feature.

[0180] The network security handling rule library is a pre-constructed database containing various security handling rules and templates, wherein the malicious behavior template library stores standard templates for different risk behavior types.

[0181] The unauthorized login template includes a typical unauthorized login behavior sequence such as "login from a strange device - multiple password errors - login using the default password", a feature component threshold value range such as "login location deviation value from common location exceeds X" and "login device is an unregistered device", and a security deviation degree change feature of "security deviation degree sharply increases at login moment".

[0182] The unauthorized operation template includes a behavior sequence such as "ordinary permission user attempts to access administrator interface - modifies permission configuration file - executes administrator operation", a feature component threshold value range such as "permission operation request exceeds user's current permission level Y level or more", and a security deviation degree change feature of "security deviation degree gradually increases with the increase of unauthorized operation attempt times".

[0183] The behavior sequence of a malicious resource transfer template may be "accessing sensitive resources - compressing and packaging sensitive files - transferring data to an external IP address", with characteristic component threshold ranges such as "transferred file size exceeds Z" and "transmission target IP is an address in the high-risk IP list", and the security deviation change characteristic is "the security deviation reaches a peak during the resource transmission stage".

[0184] The behavioral sequence of the abnormal connection template includes "establishing connections with multiple unknown IPs in a short period of time - sending abnormally formatted data packets - attempting to detect system vulnerabilities", the characteristic component threshold range is such as "the number of connection requests per minute exceeds W times", and the security deviation change characteristic is "the security deviation continues to increase as the number of connection requests increases."

[0185] Step S1513: Calculate the trajectory similarity between the feature change trajectory and each malicious behavior template, and generate a trajectory similarity score by comparing the matching degree of the behavior sequence, the compliance degree of the feature component threshold, and the similarity of the safety deviation change trend.

[0186] Trajectory similarity calculation comprehensively evaluates the similarity between feature change trajectories and malicious behavior templates from multiple dimensions.

[0187] The degree of matching of behavior sequences is determined by comparing the consistency of the type, order, and number of behaviors in the two behavior sequences. For example, if the behavior sequence of a feature change trajectory is 80% consistent with the behavior sequence of a template, the degree of matching is high.

[0188] The degree of conformance of the feature component threshold is to check whether the feature components in the feature change trajectory fall within the feature component threshold range specified by the template. The more feature components that conform, the higher the similarity of that dimension.

[0189] The similarity of the safety deviation change trends is determined by comparing the safety deviation change curves of the two over time. The more similar the curve shapes are, the higher the similarity in this dimension is.

[0190] The similarities of the three dimensions are calculated using preset weights to generate a trajectory similarity score. The weights are determined based on the importance of each dimension in the similarity assessment. For example, the matching degree of the behavioral sequence may be given the highest weight.

[0191] Step S1514: Sort the trajectory similarity scores from high to low, select the malicious behavior template with the highest trajectory similarity score as the matching template, and when the highest trajectory similarity score exceeds a preset template matching threshold, determine the malicious behavior type corresponding to the matching template as a risky behavior type of the abnormal safety behavior pattern.

[0192] After sorting the trajectory similarity scores of all malicious behavior templates, the template with the highest score is selected as the matching template. The preset template matching threshold is a critical value for judging whether the matching is successful. The preset template matching threshold is set according to the specificity of the template and the actual matching demand.

[0193] When the highest trajectory similarity score exceeds the preset template matching threshold, it indicates that the abnormal security behavior pattern is highly similar to the matching template, and thus the malicious behavior type corresponding to the matching template is determined as the risk behavior type of the abnormal security behavior pattern. For example, if the matching template with the highest score is a malicious resource transmission template, the risk behavior type is malicious resource transmission risk.

[0194] Step S152: Based on the risk behavior type, the risk level division standard in the network security handling rule library is queried, and the risk level evaluation value is calculated by combining the continuous time length, influence range and security deviation comprehensive score of the abnormal security behavior pattern. The risk level evaluation value is used to represent the severity of the risk behavior, and corresponds to different response priorities.

[0195] The calculation of the risk level evaluation value helps to determine the emergency degree and handling strength of the response.

[0196] Firstly, the corresponding risk level division standard is queried from the network security handling rule library according to the risk behavior type. Different risk behavior types have different division standards. For example, the level division of malicious resource transmission risk may focus more on the sensitivity and transmission amount of the transmitted data, while the unauthorized login risk may focus more on the permission level of the login account.

[0197] Then, the specific parameters of the abnormal security behavior pattern are evaluated. The continuous time length refers to the time length from the start of the abnormal behavior to the identification of the abnormal behavior. The longer the time length, the higher the risk level may be. The influence range includes the number of affected resources, the range of users, the system module, etc. The wider the influence range, the higher the risk level. The higher the security deviation comprehensive score, the greater the degree of behavior deviation from the normal, and the higher the risk level.

[0198] According to the risk level division standard, these parameters are converted into corresponding scores, and then the risk level evaluation value is calculated according to a preset calculation formula (such as weighted summation). The risk level evaluation value is usually divided into several level intervals, each interval corresponds to a different response priority, such as very high, high, medium, low. The higher the priority, the more urgent and severe the handling measures need to be taken.

[0199] Step S153: According to the risk behavior type and the risk level evaluation value, the matching risk blocking measures are retrieved from the network security handling rule library. The risk blocking measures include session termination measures, permission restriction measures, access blocking measures, identity secondary verification measures and security alarm measures.

[0200] The network security handling rule library stores risk blocking measures corresponding to each risk behavior type and risk level evaluation value.

[0201] When the risk behavior type is unauthorized login risk and the risk level evaluation value is high, the possible blocking measures include session termination measures (immediately terminate the current login session) and identity secondary verification measures (require the user to re-verify through a more stringent identity verification method); if the risk level evaluation value is extremely high, access blocking measures (prohibit the user from logging in again within a certain time) may also be added.

[0202] For the risk of unauthorized operation, according to the risk level, permission restriction measures (temporarily reduce the user's permission to the default level) and access blocking measures (prohibit access to specific high-permission resources) may be taken.

[0203] The blocking measures corresponding to the malicious resource transmission risk may include access blocking measures (cut off the connection with the external transmission target), session termination measures, and security alarm measures (send real-time alarm information to security management personnel) may also be triggered under high risk level.

[0204] The possible blocking measures for abnormal connection risk are access blocking measures (prohibit connection with unknown IP) and session termination measures.

[0205] Step S154: integrate the risk behavior type, risk level evaluation value, and corresponding risk blocking measures into a network security protection strategy, which also includes the user range to which the strategy applies, the effective time range, and the execution priority.

[0206] The network security protection strategy is a comprehensive plan for risk handling. The user range to which the strategy applies specifies the specific users or user groups to which the strategy applies; the effective time range specifies when the strategy starts to take effect and the duration of the effect, such as "immediate effect, lasting for 24 hours"; the execution priority is determined according to the risk level evaluation value, ensuring that high-priority strategies can be executed first.

[0207] For example, a complete network security protection strategy may be: the risk behavior type is malicious resource transmission risk, the risk level evaluation value is extremely high, the risk blocking measures include "immediately terminate the session, cut off the connection with the external IP, and send an alarm to the security administrator", the applicable user range is "user A", the effective time range is "from the time the strategy is generated to 24 hours later", and the execution priority is "highest". In the integration process, it is necessary to ensure that the information in the policy corresponds accurately and logically. For example, when the risk level assessment value is "very high", the corresponding risk blocking measures should have sufficient severity, and the execution priority should also be set to the highest to respond quickly to serious risks. At the same time, the user range to which the policy applies needs to be accurately matched with the users involved in the abnormal security behavior pattern, avoiding affecting irrelevant users. Step S155: The network security protection policy is issued to the access control module of the target domain security platform to perform real-time risk interception operations. After the generation of the network security protection policy is completed, the policy is transmitted to the access control module through the policy issuing mechanism inside the target domain security platform. The issuing process adopts an encrypted transmission method to ensure that the policy is not tampered with or leaked during transmission. After receiving the network security protection policy, the access control module parses the policy and extracts key information such as risk blocking measures, applicable user range, effective time range, and execution priority. According to the execution priority, the access control module performs the corresponding risk interception operations in order. For example, for the network security protection policy in the above example, the access control module first verifies whether user A is in the current session, and if so, immediately performs the "terminate session" operation to disconnect user A from the cloud service system. Then, according to the external IP information specified in the policy, the connection with these IPs is cut off to prevent malicious resources from continuing to transmit. At the same time, according to the preset alarm mechanism, alarm information containing risk details such as risk behavior type, occurrence time, and involved users is sent to the terminal device of the security administrator. During execution, the access control module can record operation logs in real time, including the time of policy execution, specific measures executed, operation results, etc., for subsequent auditing and tracing. If an abnormal situation is encountered during execution, such as the inability to terminate the session, the access control module can automatically trigger a backup plan, such as limiting all operation permissions of user A, and send alarm information again to prompt manual intervention.

[0208] In addition, the access control module can automatically stop the related interception operations and restore the normal access permissions of the user (if the permissions were limited before) according to the effective time range in the policy after the policy expires, ensuring that the risk is effectively disposed of while reducing the impact on normal business.

[0209] Figure 2 A schematic diagram of exemplary hardware and software components of a cross-platform user behavior analysis system 100 based on transfer learning that can implement the idea of the present application is shown. For example, the processor 120 can be used in the cross-platform user behavior analysis system 100 based on transfer learning and used to perform the functions in the present application.

[0210] For example, the cross-platform user behavior analysis system 100 based on transfer learning can include a network port 110 connected to a network, one or more processors 120 for executing program instructions, a communication bus 130, and different forms of storage media 140, such as a disk, a ROM, or a RAM, or any combination thereof. Illustratively, the cross-platform user behavior analysis system 100 based on transfer learning can also include program instructions stored in a ROM, a RAM, or other types of non-transitory storage media, or any combination thereof. The methods of the present application can be implemented according to these program instructions. The cross-platform user behavior analysis system 100 based on transfer learning also includes an I / O interface 150 between the computer and other input and output devices.

[0211] In addition, the embodiments of the present application also provide a readable storage medium, in which computer executable instructions are preset, and when a processor executes the computer executable instructions, the cross-platform user behavior analysis method based on transfer learning is realized.

[0212] It should be noted that, in order to simplify the description of the present application and to help the understanding of one or more embodiments of the present application, in the foregoing description of the embodiments of the present application, various features are sometimes combined into one embodiment, drawing or description thereof.

Claims

1. A cross-platform user behavior analysis method based on transfer learning, characterized in that: The method comprises: Obtain historical network behavior record data of the source domain security platform and real-time network behavior flow data of the target domain security platform. The historical network behavior record data includes the security behavior sequence of the source domain user in different access scenarios. The security behavior sequence includes login operation records, permission change records, resource access records, and abnormal blocking records. The real-time network behavior flow data includes the dynamic security operation record of the target domain user in the current session. The dynamic security operation record includes the session identifier, access request type, permission verification status, and resource operation track. Performing cross-domain security feature extraction processing on the historical network behavior record data and the real-time network behavior flow data, identifying network behavior types with security semantic associations in the source domain and the target domain, and constructing a cross-domain security behavior association map; Based on the cross-domain security behavior association graph, the historical malicious behavior pattern knowledge of the source domain security platform is transferred to the target domain security platform through a transfer learning model to generate a cross-platform migration security feature that integrates cross-domain malicious pattern features; Calling a security behavior analysis model to jointly model the cross-platform migration security features and the current security behavior features of the target domain in the real-time network behavior stream data, and identifying abnormal security behavior patterns of users in the target domain through time-series security association analysis; According to the abnormal security behavior pattern matching preset network security handling rule library, a network security protection strategy including risk behavior types and corresponding blocking measures is generated, and the network security protection strategy is sent to the access control module of the target domain security platform to perform real-time risk interception operations.

2. The cross-platform user behavior analysis method based on transfer learning according to claim 1 is characterized in that: The cross-domain security feature extraction processing is performed on the historical network behavior record data and the real-time network behavior flow data, the network behavior types with security semantic associations in the source domain and the target domain are identified, and a cross-domain security behavior association graph is constructed, including: Extracting a source domain security feature set from the security behavior sequence of the historical network behavior record data, the source domain security feature set includes login behavior features, permission operation features, resource access features, and abnormal response features. The login behavior features are used to describe the login method, login device, and login location information of the source domain user. The permission operation features are used to represent the user's change behavior on system permissions. The resource access features are used to describe the path and frequency pattern of the user's access to network resources. The abnormal response features are used to record the security platform's blocking records and response types to abnormal behaviors. Extracting a target domain security feature set from the dynamic security operation records of the real-time network behavior stream data, the target domain security feature set includes session access features, permission verification features, resource operation features, and connection status features. The session access features are used to describe the session establishment method and duration of the target domain user; the permission verification features are used to represent the permission verification results of the user operation; the resource operation features are used to reflect the user's operation traces of adding, deleting, modifying, and querying the target domain resources; and the connection status features are used to record the stability of the network connection and the data transmission status. Perform security semantic association identification processing on the login behavior features and permission operation features in the source domain security feature set and the session access features and permission verification features in the target domain security feature set, and determine cross-domain security behavior type pairs with similar protection goals by analyzing their respective security function intentions. The cross-domain security behavior type pairs include the correspondence between source domain login behavior and target domain session establishment behavior, and the correspondence between source domain permission change behavior and target domain permission verification behavior; Based on the cross-domain security behavior type pair, combined with the network security policy documents of the source domain and the target domain, extracting association rules between security behavior types, wherein the association rules include behavior trigger condition association, operation object association, and security policy response association; Based on the cross-domain security behavior type pairs and association rules, a cross-domain security behavior association graph is constructed with security behavior types as nodes and association rules as edges. The edge attributes of the cross-domain security behavior association graph include an association strength description, which is comprehensively generated based on the functional similarity of cross-domain security behaviors and the overlap of protection targets.

3. The cross-platform user behavior analysis method based on transfer learning according to claim 2 is characterized in that: The performing security semantic association identification processing on the login behavior features and permission operation features in the source domain security feature set and the session access features and permission verification features in the target domain security feature set includes: Extracting login behavior semantic description information from the login behavior features of the source domain security feature set, wherein the login behavior semantic description information includes a login method description, a login device type description, and a login location description; Extracting session establishment semantic description information from the session access feature of the target domain security feature set, wherein the session establishment semantic description information includes a session initiation method description, a session device identification description, and a session network environment description; Perform security function intent labeling on the login behavior semantic description information and the session establishment semantic description information, and determine the corresponding security protection intents through manual labeling or pre-trained intent recognition models. The security protection intents include identity authenticity verification intent, device legitimacy verification intent, and environmental safety verification intent; Preliminarily match the login behavior semantic description information with the session establishment semantic description information with the same security protection intention to form candidate security behavior type pairs; Extract the permission operation semantic description information and permission verification semantic description information corresponding to the source domain permission operation characteristics and the target domain permission verification characteristics respectively, and determine the corresponding security protection intentions to form another set of candidate security behavior type pairs; Functional similarity calculation is performed on the candidate security behavior type pairs, and a functional similarity score is generated by comparing the degree of overlap of behavior triggering conditions, operation execution processes and security response results. When the functional similarity score exceeds the preset similarity threshold, it is determined to be a cross-domain security behavior type pair with security semantic association.

4. The cross-platform user behavior analysis method based on transfer learning according to claim 2 is characterized in that: Based on the cross-domain security behavior association graph, the historical malicious behavior pattern knowledge of the source domain security platform is migrated to the target domain security platform through a transfer learning model to generate a cross-platform migration security feature that integrates cross-domain malicious pattern features, including: Inputting malicious behavior samples in the historical network behavior record data into the source domain security feature layer of the transfer learning model, performing feature space mapping processing on the source domain malicious behavior features based on the association rules in the cross-domain security behavior association graph, converting the source domain malicious behavior features from the source domain security feature space to the target domain security feature space, and generating initial migration malicious features, wherein the initial migration malicious features include common malicious login mode features, unauthorized operation mode features, and abnormal resource access mode features in the source domain; The initial migrated malicious features are calibrated for domain offset using the security domain adaptation module of the transfer learning model. Based on the preset adjustment coefficient corresponding to the correlation strength description of the cross-domain security behavior correlation graph, the weights of the feature components in the initial migrated malicious features are dynamically adjusted to generate a calibrated migrated malicious feature. The preset adjustment coefficient is positively correlated with the correlation strength description, and the corresponding feature component of the correlation strength description is assigned a corresponding adjustment coefficient. Extracting target domain basic security features from the target domain security feature set, wherein the target domain basic security features include target domain-specific permission level features, resource access control list features, and session management rule features; Associating and integrating the calibrated migrated malicious features with the target domain basic security features to generate a fused intermediate security feature; The malicious knowledge distillation unit of the transfer learning model is called to encode the historical malicious behavior pattern knowledge of the source domain security platform into a malicious knowledge vector. The malicious knowledge vector includes the malicious behavior sequence template, abnormal feature combination pattern and security response rules identified in the source domain. The fused intermediate security feature is subjected to knowledge enhancement processing through the malicious knowledge vector, so that the fused intermediate security feature carries the regular knowledge of the malicious behavior pattern of the source domain, and generates a cross-platform migration security feature. The cross-platform migration security feature includes the cross-domain common malicious features migrated from the source domain and the local security features of the target domain.

5. The cross-platform user behavior analysis method based on transfer learning according to claim 4 is characterized in that: The security domain adaptation module of the transfer learning model performs domain offset calibration on the initial migrated malicious features, dynamically adjusts the weights of each feature component in the initial migrated malicious features based on a preset adjustment coefficient corresponding to the correlation strength description of the cross-domain security behavior correlation graph, and generates a calibrated migrated malicious feature, including: In the security domain adaptation module, a security domain difference evaluation function is constructed based on the cross-domain security behavior association graph, wherein the security domain difference evaluation function is used to quantify the difference in security protection rules between the initial migration malicious features and the target domain security feature set; Calculating the domain shift index of each feature component in the initial migrated malicious feature according to the security domain difference evaluation function, wherein the domain shift index is positively correlated with the degree of difference in security rules between the source domain and the target domain of the feature component, and the degree of difference corresponds to the domain shift index value of the feature component; Extracting a correlation strength description corresponding to each characteristic component from the cross-domain security behavior correlation graph, querying a preset mapping table based on the correlation strength description, and determining a preset adjustment coefficient for each characteristic component, wherein the correlation strength description in the mapping table corresponds to the preset adjustment coefficient; generating a characteristic component calibration parameter based on the domain shift index and a preset adjustment coefficient; Performing a product operation on each feature component in the initial migrated malicious feature and a corresponding feature component calibration parameter to generate an adjusted feature component; The adjusted feature components are combined in order of feature dimensions of the target domain security feature set to generate a calibrated migrated malicious feature.

6. The cross-platform user behavior analysis method based on transfer learning according to claim 1 is characterized in that: The calling of the security behavior analysis model to jointly model the cross-platform migration security features and the current security behavior features of the target domain in the real-time network behavior stream data, and identifying abnormal security behavior patterns of users in the target domain through time-series security association analysis, includes: Inputting the cross-platform migration security features and the current security behavior features of the target domain into the shared security feature layer of the security behavior analysis model, performing deep security feature extraction processing through a recurrent neural network, capturing the correlation between cross-domain common malicious behavior patterns and real-time behavior of the target domain, and generating a cross-domain common security feature vector; Inputting the cross-domain common security feature vector into the target domain security feature layer of the security behavior analysis model, performing targeted optimization processing in combination with the target domain security policy document, strengthening the feature components corresponding to the target domain-specific security rules, and generating a target domain-specific security feature vector; Fusion of the cross-domain common security feature vector and the target domain-specific security feature vector to generate a joint security behavior feature vector, wherein the joint security behavior feature vector includes the malicious pattern features of cross-domain migration and the current real-time security behavior features of the target domain; The temporal security association module of the security behavior analysis model is called to perform time series dependency analysis on the joint security behavior feature vector. By analyzing the triggering relationship, sequence relationship, and causal relationship between security behavior features at consecutive time points, a temporal association model of the user security behavior sequence is constructed. The temporal association model is used to describe the feature change pattern under normal security behavior mode and the feature abnormal trajectory under malicious behavior mode; Perform malicious behavior pattern prediction processing on the joint security behavior feature vector based on the time series association model to generate an expected security behavior feature sequence of the target domain user, wherein the expected security behavior feature sequence reflects the security behavior features that the user should subsequently generate under normal security rules; Performing real-time comparison and analysis of the current safety behavior characteristics of the target domain with the expected safety behavior characteristic sequence, calculating the safety deviation between the actual safety behavior characteristics and the expected safety behavior characteristics, and marking the corresponding behavior characteristics as abnormal safety candidate characteristics when the safety deviation exceeds a preset deviation threshold; The abnormal security candidate features are subjected to contextual security association verification processing, and are combined with the adjacent security behavior features to determine whether they conform to the feature combination rules of known malicious behavior patterns. When there are abnormal security candidate features that continuously conform to malicious patterns, they are determined to be abnormal security behavior patterns. The abnormal security behavior pattern includes the starting time point of the abnormal behavior, the continuous behavior sequence and the corresponding security risk type.

7. The cross-platform user behavior analysis method based on transfer learning according to claim 6 is characterized in that: The calling of the time series security association module of the security behavior analysis model to perform time series dependency analysis processing on the joint security behavior feature vector includes: Arrange the joint security behavior feature vectors into a security behavior time series according to the chronological order of the security behavior occurrence, wherein each feature element in the security behavior time series corresponds to a user security behavior feature at a time point, and the user security behavior feature includes the login status, permission level, resource access record, and operation result at that time point; In the temporal security association module, the security behavior time series is divided into time windows, and multiple continuous security behavior feature elements are combined into security behavior windows. Each security behavior window contains continuous security behavior features within a preset time length. The time length is determined according to the average response time of the target domain security incident; Performing correlation analysis on the characteristic elements in each of the safety behavior windows, extracting dependency rules between safety behaviors by analyzing the triggering conditions, operation sequence, and causal relationships between the preceding safety behavior characteristic elements and the subsequent safety behavior characteristic elements in the safety behavior window, wherein the dependency rules include behavior triggering condition dependency, operation execution sequence dependency, and safety status change dependency; Constructing a safety behavior transition probability matrix based on the dependency rules, wherein the safety behavior transition probability matrix is ​​used to represent the probability of transitioning from one safety behavior characteristic element to the next safety behavior characteristic element, wherein a higher matrix element value indicates a higher frequency of occurrence of the corresponding behavior transition path in a normal safety behavior mode; Combining the security behavior transition probability matrices of multiple security behavior windows, the long-term dependency of the security behavior time series is modeled through a long short-term memory network to generate a temporal association model for describing the differences between normal and malicious security behavior patterns. The temporal association model includes a set of normal security behavior transition paths and a set of malicious security behavior transition paths.

8. The cross-platform user behavior analysis method based on transfer learning according to claim 6 is characterized in that: The step of comparing and analyzing the current security behavior characteristics of the target domain with the expected security behavior characteristic sequence in real time and calculating the security deviation between the actual security behavior characteristics and the expected security behavior characteristics includes: Extracting a real-time security behavior feature vector from the current security behavior feature of the target domain, wherein the real-time security behavior feature vector includes a login state vector, a permission operation vector, a resource access vector, and a connection state vector at the current time point; Extracting an expected security behavior feature vector corresponding to the current time point from the expected security behavior feature sequence, wherein the expected security behavior feature vector is generated based on the prediction of the normal behavior pattern by the time series association model and includes expected login status, expected permission operation, expected resource access, and expected connection status; After aligning the feature components of the real-time safety behavior feature vector and the expected safety behavior feature vector, a difference vector of corresponding feature components between the real-time safety behavior feature vector and the expected safety behavior feature vector is calculated, where each element of the difference vector represents the degree of deviation between the actual value and the expected value of a single safety feature component; assigning a priority weight to each element in the difference vector based on the protection priority of each security feature component in the target domain security policy; Performing a weighted inner product operation on the difference vector and the priority weight to generate a comprehensive safety deviation score, wherein a higher comprehensive safety deviation score indicates a greater degree of deviation between the actual safety behavior and the expected normal behavior; The safety deviation comprehensive score is compared with the preset safety threshold. When the safety deviation comprehensive score exceeds the preset safety threshold, the current safety behavior feature is determined to be an abnormal safety candidate feature, and the time point and behavior details corresponding to the abnormal safety candidate feature are recorded.

9. The cross-platform user behavior analysis method based on transfer learning according to claim 1 is characterized in that: The method of matching a preset network security handling rule library based on the abnormal security behavior pattern to generate a network security protection strategy including risk behavior types and corresponding blocking measures includes: The abnormal security behavior pattern is classified into risk behavior types. By matching the characteristic change trajectory of the abnormal security behavior pattern with the malicious behavior template library in the network security disposal rule library, the risk behavior type to which the abnormal behavior belongs is determined. The risk behavior types include unauthorized login risk, unauthorized operation risk, malicious resource transmission risk and abnormal connection risk. Each risk behavior type corresponds to a specific combination of malicious behavior characteristics; Based on the risk behavior type, the risk level classification standard in the network security disposal rule library is queried. The risk level assessment value is calculated by combining the duration, impact range and safety deviation comprehensive score of the abnormal security behavior pattern. The risk level assessment value is used to indicate the severity of the risk behavior and corresponds to different response priorities. According to the risk behavior type and risk level assessment value, matching risk blocking measures are retrieved from the network security disposal rule library. The risk blocking measures include session termination measures, permission restriction measures, access blocking measures, identity secondary verification measures and security warning measures; The risk behavior type, risk level assessment value and corresponding risk blocking measures are integrated into a network security protection strategy, which also includes the user scope to which the strategy applies, the effective time range and the execution priority.

10. A cross-platform user behavior analysis system based on transfer learning, characterized in that: It includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the cross-platform user behavior analysis method based on transfer learning as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Entity relationship extraction method and device based on transfer learning model, equipment and medium

    CN119443105A

  • Cross-platform user behavior data intelligent aggregation and analysis processing method and system

    CN120408101A

  • Large factory cross-platform user drainage and growth promotion system based on artificial intelligence

    CN120448639A

  • Geological disaster monitoring data processing method and system based on reinforcement learning

    CN120632432A

  • Privacy preserving transfer learning

    US20240273401A1

Cited By

  • Construction real-name order receiving system and compliance auditing mechanism

    CN121119982A

  • Data security management method, system and device, storage medium and program product

    CN121413032A