Network threat detection method and device, storage medium and computer equipment

By combining Markov chain algorithm and process deviation features, a user behavior feature set is constructed. By utilizing security detection rules and machine learning models, the problem of low adaptability and response efficiency of network threat detection in existing technologies is solved, and efficient protection of network security for the insurance industry is achieved.

CN120979760APending Publication Date: 2025-11-18CHINA PING AN PROPERTY INSURANCE CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202511239813.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing cybersecurity protection technologies are unable to identify new threats, lack adaptability and generalization capabilities, have low response efficiency, cannot effectively curb the spread of attacks, and have limited coverage, making it difficult to achieve closed-loop management of the entire attack lifecycle.

Method used

The Markov chain algorithm is used to model user operation sequences. Combined with process deviation features, a user behavior feature set is constructed. Threat detection is performed using security detection rules and machine learning models, and closed-loop management from detection to response is achieved.

Benefits of technology

It enhances the ability to detect new and disguised threats, shortens response time, strengthens adaptability, and achieves efficient protection against complex attacks, making it suitable for cybersecurity protection in the insurance industry.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979760A_ABST
    Figure CN120979760A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, and discloses a network threat detection method and device, a storage medium and computer equipment, the method can be applied to a high-risk scene involving a user operation process in insurance services, and the method comprises the following steps: preprocessing user behavior data in network operation data to obtain structured data; key behavior features are extracted based on multiple dimensions, an abnormal state transition path is determined by using a Markov chain algorithm, flow deviation degree features are generated, and a user behavior feature set is constructed through feature fusion; performing threat detection based on a security detection rule or by using a machine learning model to obtain a threat detection result; when threats exist in the user behavior feature set, abnormal user behavior data are determined and responded and handled, and a threat detection and processing report is generated. According to the method, the capability of detecting novel, disguise and internal threats is improved, the response time is shortened, the adaptability is enhanced, and a more efficient and reliable solution is provided for network security protection in the insurance industry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, storage medium, and computer equipment for detecting network threats. Background Technology

[0002] With the rapid development of information technology, cyberattack methods are becoming increasingly diversified and intelligent, and the scale and concealment of attacks are constantly escalating, posing a severe challenge to the information security systems of various industries. Among them, insurance companies, as a data-intensive industry, store a large amount of sensitive customer information in their business systems, including personal identity information, health and medical records, bank accounts, and policy financial data. Once a data breach occurs or the system is illegally intruded, it will not only seriously infringe on user privacy, but may also lead to major legal disputes, regulatory penalties, and irreparable damage to brand reputation, directly affecting the sustainable development of the enterprise.

[0003] Current mainstream cybersecurity protection technologies still have significant shortcomings. First, detection mechanisms that rely on predefined rules (such as traditional IDS / IPS) struggle to identify new, disguised threats and lack sufficient adaptability and generalization capabilities. Second, threat discovery often relies on manual assessment and intervention, resulting in slow response processes, delayed handling, and an inability to effectively curb the spread of attacks. Furthermore, existing systems typically have limited coverage, making it difficult to achieve closed-loop management of the entire attack lifecycle, and they are inadequate when facing complex attacks that cross systems and go through multiple stages.

[0004] Therefore, a network threat detection method that can improve detection accuracy, response efficiency, and system adaptability, and comprehensively ensure the safe and stable operation of insurance business, is urgently needed. Summary of the Invention

[0005] In view of this, this application provides a method, apparatus, storage medium and computer equipment for detecting network threats, with the main purpose of solving the technical problems of single detection method, low detection accuracy and low response efficiency in the prior art for detecting network threats.

[0006] According to a first aspect of the present invention, a method for detecting network threats is provided, the method comprising:

[0007] Collect network operation data and extract user behavior data. Preprocess the user behavior data to obtain structured data, wherein the structured data includes user operation sequences.

[0008] Key behavioral features are extracted from the structured data based on multiple dimensions. The Markov chain algorithm is used to determine the abnormal state transition path in the user operation sequence and generate process deviation features. The key behavioral features and the process deviation features are fused to construct a user behavior feature set.

[0009] Threat detection results are obtained by performing threat detection on the user behavior feature set based on preset security detection rules or by using preset machine learning models;

[0010] When the threat detection result indicates that the user behavior feature set is threatened, the corresponding abnormal user behavior data is identified, and the abnormal user behavior data is responded to and processed to generate a threat detection and processing report.

[0011] Optionally, the step of collecting network operation data and extracting user behavior data, and preprocessing the user behavior data to obtain structured data, includes: performing traffic mirroring on the target business platform, forwarding the copied network operation data of the target business platform to a data processing device, wherein the data processing device includes an image recognition tool and a video extraction tool; using the image recognition tool to extract image data from the network operation data and extract image feature vectors, and simultaneously using the video extraction tool to parse the video stream protocol in the network operation data and extract video keyframe features; based on a timestamp mechanism, synchronizing the image feature vectors and the video keyframe features through a preset message queue to generate user behavior data; and standardizing and cleaning the user behavior data based on a preset structured format to obtain structured data.

[0012] Optionally, the step of extracting key behavioral features from the structured data based on multiple dimensions, and using a Markov chain algorithm to determine abnormal state transition paths in the user operation sequence and generate process deviation features includes: extracting multiple key behavioral features from the structured data based on user behavior, business logic, and risk association dimensions; defining a business state space according to a preset business process, and mapping the user operation sequence to corresponding state transition paths based on the business state space; calculating the joint probability of the state transition paths using a Markov chain algorithm, and comparing the joint probability with a preset abnormal probability threshold to determine abnormal state transition paths and generate process deviation features.

[0013] Optionally, the step of performing threat detection on the user behavior feature set based on preset security detection rules to obtain threat detection results includes: acquiring preset network threat intelligence; constructing a threat knowledge base based on the network threat intelligence; constructing a knowledge graph based on preset business data, and adding risk attributes to entities in the knowledge graph using the threat knowledge base; generating security detection rules based on the threat knowledge base and the knowledge graph; performing real-time matching analysis on the user behavior feature set using the security detection rules to identify known threats in the user behavior feature set, and performing multi-dimensional entity association analysis on the user behavior feature set using the knowledge graph to determine hidden threats; and generating threat detection results by combining the known threats and the hidden threats.

[0014] Optionally, the step of using a preset machine learning model to perform threat detection on the user behavior feature set and obtain threat detection results includes: acquiring historical network data and establishing a normal behavior baseline based on the historical network data; training labeled samples using the normal behavior baseline and constructing a threat classification model using a random forest algorithm based on the labeled samples; and using the threat classification model to perform threat detection on the user behavior feature set and obtain threat detection results.

[0015] Optionally, responding to and handling the abnormal user behavior data includes: configuring firewall rules based on the threat detection results, blocking the IP address corresponding to the abnormal user behavior data based on the firewall rules, and intercepting the abnormal user behavior data; dynamically adjusting the access control list, adding the IP address corresponding to the abnormal user behavior data to the blacklist, and isolating the IP address to an independent network area using network segmentation technology; determining the target business platform accessed by the abnormal user behavior data, and performing vulnerability scanning and patching on the target business platform.

[0016] Optionally, generating a threat detection and handling report includes: calculating a comprehensive risk score for the abnormal user behavior data based on risk scores and corresponding score weights across multiple dimensions; confirming the risk level corresponding to the abnormal user behavior data based on the comprehensive risk score; and generating a threat detection and handling report based on the risk level and the comprehensive risk score, wherein the threat detection and handling report includes risk assessment results and handling recommendations.

[0017] According to a second aspect of the present invention, a network threat detection device is provided, the device comprising:

[0018] The data acquisition module is used to collect network operation data and extract user behavior data, and preprocess the user behavior data to obtain structured data, wherein the structured data includes user operation sequences.

[0019] The feature construction module is used to extract key behavioral features from the structured data based on multiple dimensions, use the Markov chain algorithm to determine the abnormal state transition path in the user operation sequence and generate process deviation features, and fuse the key behavioral features and the process deviation features to construct a user behavior feature set.

[0020] The threat detection module is used to perform threat detection on the user behavior feature set based on preset security detection rules or using a preset machine learning model, and obtain threat detection results.

[0021] The threat handling module is used to determine the corresponding abnormal user behavior data when the threat detection result indicates that there is a threat in the user behavior feature set, and to respond to and handle the abnormal user behavior data, and generate a threat detection and handling report.

[0022] According to a third aspect of the present invention, a storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the above-described method for detecting network threats.

[0023] According to a fourth aspect of the present invention, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the above-described method for detecting network threats.

[0024] This invention provides a method, apparatus, storage medium, and computer device for detecting network threats. It utilizes Markov chains to model user operation sequences, improving behavior prediction and anomaly identification capabilities. Simultaneously, it introduces process deviation features to identify hidden threats that traditional detection rules cannot cover. The Markov chain can continuously learn as user behavior evolves, exhibiting strong adaptability. A user behavior feature set integrating key behavioral features and process deviation features is constructed to achieve multi-dimensional dynamic threat identification. It supports dual-mode detection using rule-based detection and machine learning models, improving generalization ability for unknown dangers while maintaining detection accuracy. A closed-loop management mechanism from detection and response to reporting is established, enabling management from threat discovery to automated handling and improving overall detection efficiency. The above method enhances the detection capabilities of new, disguised, and insider threats, shortens response time, and strengthens adaptability, providing a more efficient and reliable solution for network security protection in the insurance industry.

[0025] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0026] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0027] Figure 1 A flowchart illustrating a network threat detection method provided by an embodiment of the present invention is shown;

[0028] Figure 2 A flowchart illustrating another network threat detection method provided by an embodiment of the present invention is shown;

[0029] Figure 3 A schematic diagram of the structure of a network threat detection device provided in an embodiment of the present invention is shown;

[0030] Figure 4 A schematic diagram of the device structure of a computer device provided in an embodiment of the present invention is shown. Detailed Implementation

[0031] Exemplary embodiments of the present application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the scope of the present application to those skilled in the art.

[0032] It should be noted that the technical solutions provided in this application are applicable to different business scenarios in the fintech field, especially in scenarios where customer development and services need to be carried out through brokers or advisors, such as credit and loan services, where banks or financial institutions provide loan products to potential customers through brokers; insurance sales, where insurance companies use broker networks to promote insurance products; and wealth management and investment advisory, where wealth management companies or private banks customize wealth management plans for clients through advisors, etc.

[0033] This application provides a method for detecting network threats, such as... Figure 1 As shown, the method includes the following steps:

[0034] 101. Collect network operation data and extract user behavior data. Preprocess the user behavior data to obtain structured data, which includes user operation sequences.

[0035] Among them, network operation data refers to various logs and interaction records generated during system operation, such as application system logs, network traffic data, database operation logs, and API call records; user behavior data refers to the parts related to user operations extracted from network operation data, such as when user A logged into the system, when user B changed the beneficiary of an insurance policy, and when user C submitted a claim application; preprocessing refers to the process of cleaning and transforming the raw behavior data, including removing invalid or erroneous data, standardizing timestamp formats, standardizing operation types, and normalizing user identities; structured data refers to data that has a unified format after processing and can be directly analyzed by programs, usually stored in tabular or JSON format; user operation sequence refers to the sequence formed by arranging user operations in chronological order over a period of time.

[0036] Specifically, this step is the data preparation stage of the entire threat detection system. It can transform raw, messy network logs into high-quality behavioral data that can be used for security analysis. Following standard data processing procedures, it obtains user operation sequences from structured data, laying the foundation for subsequent modeling, and is closely aligned with insurance business processes.

[0037] In this embodiment, structured data can be automatically processed by the system, reducing manual intervention and improving response efficiency, providing high-quality data input for subsequent modeling or analysis, improving detection accuracy and precision, and is suitable for a variety of complex business scenarios.

[0038] 102. Extract key behavioral features from structured data based on multiple dimensions, use the Markov chain algorithm to determine the abnormal state transition path in the user operation sequence and generate process deviation features, and fuse the key behavioral features and process deviation features to construct a user behavior feature set.

[0039] Among these, multiple dimensions refer to the characteristic sources that characterize user behavior from different angles, such as user identity, operation type, time, frequency, access object, IP address, etc. Multi-dimensional analysis can more comprehensively describe a user's behavior; key behavioral features refer to the security-meaning behavioral attributes extracted from structured data, such as the number of operations per day, operations outside of working hours, and the number of times sensitive fields are accessed, which can reflect abnormal tendencies in user behavior; the Markov chain algorithm is a probability-based mathematical model used to describe the transition rules between states. In this step, it is used to model the transition probability of normal users between various operation states, thereby identifying abnormal state transition paths that do not conform to the conventional path; the process deviation feature is a quantitative indicator generated based on the Markov chain analysis results, used to measure the degree of deviation of an operation sequence from the normal process. The greater the deviation, the higher the feature value, indicating a greater risk; the user behavior feature set is a comprehensive feature vector formed by fusing the extracted key behavioral features and the generated process deviation feature, which serves as the input to the subsequent threat detection model, including both static behavioral attributes and dynamic process anomaly information.

[0040] Specifically, this step no longer relies solely on a single operational event for judgment. Instead, it combines multi-dimensional behavioral characteristics with the temporal logic of operational processes, models normal behavioral patterns using Markov chains, and identifies abnormal transfer paths that violate conventional processes. This is applicable to scenarios in insurance business with rigorous processes and clearly defined steps, such as insurance application, claims, and policy changes. By establishing process deviation characteristics, it can accurately detect hidden attacks that are difficult to cover by traditional rules, such as internal personnel bypassing risk control links and automated scripts performing batch operations. By integrating process deviation characteristics with other key behavioral characteristics, a richer and more discriminative set of user behavior characteristics is constructed, significantly improving the ability to identify complex and highly disguised threats.

[0041] In this embodiment, this step enhances the ability to perceive abnormal behavior. By introducing process modeling, the system has a certain self-learning and adaptive capability, and can dynamically adjust the judgment benchmark as normal behavior patterns change. The feature fusion strategy improves the accuracy and robustness of threat detection, and enhances the precision of detection.

[0042] 103. Based on preset security detection rules or using preset machine learning models, perform threat detection on user behavior feature sets to obtain threat detection results.

[0043] Among them, the preset security detection rules refer to the judgment conditions defined in advance based on known attack patterns or business risk experience, such as the same user attempting to log in more than 5 times within 1 minute or modifying high-value insurance policies outside of working hours, which are used to quickly identify obvious high-risk behaviors; the preset machine learning models refer to the algorithm models trained and deployed through historical data, such as random forests, XGBoost, LSTM, etc., which can automatically learn the differentiation patterns of normal and abnormal behaviors based on user behavior feature sets, and identify complex, hidden or new threats that are difficult to cover by rules; the threat detection results refer to the judgment conclusions output by the system, which are usually expressed as normal or abnormal, and may also include detailed information such as risk scores, risk levels, and suspicious operation types, for subsequent response decisions.

[0044] Specifically, this step leverages the efficiency and interpretability of rule-based detection in identifying known threats, while also incorporating the generalization capabilities of machine learning models for complex, mutated, or unknown threats. By providing parallel detection methods, it can control the false alarm rate while ensuring a high detection rate, thereby improving the overall stability and adaptability of the detection. This is particularly relevant in insurance business scenarios, where there are numerous definable high-risk operational rules as well as constantly evolving fraudulent methods. The dual-track detection mechanism enhances the applicability of the method.

[0045] In this embodiment, this step enhances the comprehensiveness of threat detection. Rules can quickly identify clear risks, and models can discover potential abnormal patterns, significantly expanding the detection coverage. Simultaneously, it enhances the system's flexibility and adaptability. The machine learning model can adapt to new attack methods through continuous training, avoiding the maintenance costs associated with frequent rule updates and providing a more reliable basis for subsequent responses. The detection results not only include a conclusion on whether anomalies exist but can also include risk scores, sources of abnormal features, and other information, supporting tiered responses and automated handling. Overall, the technical solution achieves a shift from passive defense to proactive identification, providing more accurate and reliable technical support for the security protection of insurance systems.

[0046] 104. When the threat detection result indicates that there is a threat in the user behavior feature set, identify the corresponding abnormal user behavior data, respond to and handle the abnormal user behavior data, and generate a threat detection and handling report.

[0047] Among them, abnormal user behavior data refers to specific suspicious operation records located from the original network operation data, such as a user frequently modifying multiple high-value insurance policies late at night or skipping risk assessment to directly purchase insurance. These are the actual behaviors pointed to by the threat detection results. Response and handling refer to a series of security control actions that the system automatically or semi-automatically executes after confirming a threat, such as blocking malicious IPs, isolating infected devices, freezing suspicious accounts, and recording audit logs. The purpose is to curb the spread of risks and prevent the expansion of losses. Threat detection and handling reports summarize the information of the entire process from detection to response, and usually include detection time, description of abnormal behavior, risk level, etc.

[0048] In this embodiment, this step realizes closed-loop management from threat detection to behavior location, to action execution and report generation, transforming detection results into actual security actions. When the system determines that user behavior poses a threat, it can quickly trace back and lock the original abnormal behavior data to ensure the accuracy of the target. Subsequently, it triggers the preset response strategy to achieve automated intervention and shorten response time. Finally, it automatically generates a processing report, improving the overall security system's defense capabilities and operational efficiency, and enhancing the resilience and reliability of the insurance system in the face of complex network attacks.

[0049] This invention provides a method, apparatus, storage medium, and computer device for detecting network threats. It utilizes Markov chains to model user operation sequences, improving behavior prediction and anomaly identification capabilities. Simultaneously, it introduces process deviation features to identify hidden threats that traditional detection rules cannot cover. The Markov chain can continuously learn as user behavior evolves, exhibiting strong adaptability. A user behavior feature set integrating key behavioral features and process deviation features is constructed to achieve multi-dimensional dynamic threat identification. It supports dual-mode detection using rule-based detection and machine learning models, improving generalization ability for unknown dangers while maintaining detection accuracy. A closed-loop management mechanism from detection and response to reporting is established, enabling management from threat discovery to automated handling and improving overall detection efficiency. The above method enhances the detection capabilities of new, disguised, and insider threats, shortens response time, and strengthens adaptability, providing a more efficient and reliable solution for network security protection in the insurance industry.

[0050] This application provides another method for detecting network threats, such as... Figure 2 As shown, the method includes the following steps:

[0051] 201. Collect network operation data and extract user behavior data, and preprocess the user behavior data to obtain structured data.

[0052] The process involves mirroring the network operation data of the target business platform, forwarding the copied data to a data processing device, which includes image recognition and video extraction tools. The image recognition tool extracts image data and image feature vectors from the network operation data, while the video extraction tool parses the video stream protocol and extracts keyframe features. Based on a timestamp mechanism, image feature vectors and video keyframe features are synchronized through a pre-defined message queue to generate user behavior data. Finally, the user behavior data is standardized and cleaned using a pre-defined structured format to obtain structured data.

[0053] Specifically, in typical business scenarios within the insurance industry, target business platforms may include critical business systems such as auto insurance damage assessment systems, online insurance application platforms, claims review systems, and remote video underwriting systems. To collect user access behavior data, network traffic mirroring technology can be utilized. Port mirroring rules are configured on core switches or load balancers to copy and forward copies of the original network traffic in real time to dedicated data processing equipment. This data processing equipment is equipped with image recognition and video extraction tools to parse multimodal data from the network traffic. Specifically, the image recognition tool can employ the open-source OCR engine Tesseract, which interfaces with image data uploaded to the auto insurance damage assessment platform, such as vehicle damage photos, VIN code images, and driver's license scans. It automatically extracts image content and generates image feature vectors, such as text recognition results, confidence scores, image clarity, and key area detection boxes. When a VIN code is recognized... If the reliability score is lower than a preset threshold, such as 0.9, an image re-examination or manual review process can be triggered to prevent fraudulent insurance claims. The video extraction tool is used to analyze video stream data in scenarios such as remote video underwriting and online face-to-face signing. By deploying packet capture and parsing modules that support streaming media protocols such as RTMP and HLS, the video stream is reconstructed from network traffic, and key frame features are extracted, including video resolution, frame rate, encoding format, duration of face appearance, and lip-reading synchronization. For example, when a video resolution lower than 720P or a frame rate lower than 15fps is detected, it is determined to be a low-quality video stream, which may involve pre-recorded or non-real-time underwriting. The system will automatically trigger an alarm to indicate the risk of identity theft.

[0054] Furthermore, all features extracted from image and video data carry precise timestamps and are asynchronously transmitted and aggregated through a unified message queue, Apache Kafka. As a high-throughput, low-latency messaging system, Kafka receives feature streams from different data sources and aligns and correlates them based on timestamps. The system has a timestamp alignment mechanism that allows for a time difference tolerance of ±50ms, ensuring that image recognition results and video frame features within the same user session can be accurately matched to form a complete user behavior. For example, in a video verification process, the system simultaneously collects the user's uploaded ID card image and the real-time verification video. By matching timestamps, it can confirm whether the two belong to the same session and further determine the logical relationship between the ID card image recognition result and the face in the video, and whether the operation time is continuous, thereby generating a structured user behavior data.

[0055] Finally, the raw user behavior data is standardized and mapped, unifying field naming, data types, and encoding rules. Simultaneously, data cleaning operations are performed, including removing duplicate records, filling in missing fields, filtering invalid sessions, and supplementing business context information. For example, policy operation types include application, claims, and cancellation; user roles include customers, agents, and internal employees; access times include weekdays, holidays, and early morning; and policy amount fluctuation thresholds include triggering key monitoring when the cumulative daily operation amount exceeds 1 million yuan. The processed data is ultimately generated as structured data in JSON-LD format, serving as the foundational input for subsequent user behavior analysis, risk modeling, and threat detection.

[0056] In this embodiment, by deploying traffic mirroring technology and combining it with OCR, video stream parsing, and message queue synchronization mechanisms, automated collection and feature extraction of unstructured data such as images and videos in the core insurance system are achieved. This enhances the fine-grained monitoring capabilities for high-risk processes such as remote underwriting and online loss assessment. Through timestamp alignment and structured processing, multi-source heterogeneous data are effectively integrated to construct a complete user behavior profile. This provides a solid data foundation for identifying complex fraudulent activities such as forged materials, identity theft, and internal violations, significantly improving the security level of the insurance system.

[0057] 202. Extract key behavioral features from structured data based on multiple dimensions.

[0058] Among them, several key behavioral features are extracted from structured data based on user behavior, business logic, and risk association dimensions.

[0059] Specifically, after acquiring structured data, key behavioral features are extracted from three dimensions according to preset feature engineering rules. First, from the user behavior dimension, the focus is on the frequency, intensity, and timeliness of individual user operations to reflect whether their behavioral patterns deviate from the normal range. For example, in car insurance or life insurance systems, normal customers or agents typically do not frequently modify policy information in a short period. Therefore, the daily policy modification frequency is defined as a key feature. By statistically analyzing the number of times each user modifies policy information within 24 hours, it is determined whether their behavior is abnormal. When the modification frequency exceeds a preset threshold, such as more than 50 times / day, it is considered a high-frequency abnormal operation, which may involve automated script attacks, and the user behavior can be marked as a high-risk feature. Second, from the business logic dimension, based on the rationality of the insurance business process, operational sequences that violate normal business logic are identified. For example, under normal circumstances, users usually hold the policy for a period of time after purchasing insurance and rarely apply for cancellation in a very short period. However, some insurance fraud... The behavior often manifests as quickly purchasing insurance and then immediately canceling it. By analyzing the timestamps of the purchase and cancellation operations of the same policy or the same user, the time interval is calculated. When the time interval is less than 24 hours, an early warning mechanism is triggered, indicating possible abnormal behavior such as cashing out through cancellation. The features are included in the user behavior feature set for subsequent risk assessment. Finally, from the risk association dimension, it is used to identify potential correlations between multiple policies, multiple users, or multiple operations. For example, in health insurance or group insurance scenarios, if the operational behaviors of multiple policies are highly similar, it may indicate organized fraud. Therefore, the operation sequence of each policy can be encoded into a vector, and the cosine similarity algorithm is used to calculate the behavioral similarity between different policies. When the similarity exceeds a preset threshold, such as greater than 0.85, it is judged as a high similarity operation, and the system automatically triggers the association detection process to further analyze whether these policies are operated by the same device, the same IP, or related agents, thereby identifying potential fraud groups.

[0060] In this embodiment, by extracting key features from three dimensions—user behavior, business logic, and risk association—a multi-faceted and in-depth characterization of abnormal behavior in insurance business scenarios is achieved. Compared with the traditional detection method that relies solely on a single operation log, it can identify more complex and concealed fraud patterns, significantly improving the insurance system's ability to detect internal abuse, external attacks, and structural fraud.

[0061] 203. Use the Markov chain algorithm to determine the abnormal state transition path in the user operation sequence and generate process deviation features.

[0062] Specifically, a business state space is defined based on a preset business process, and user operation sequences are mapped to corresponding state transition paths based on the business state space; the joint probability of the state transition paths is calculated using the Markov chain algorithm, and the joint probability is compared with a preset anomaly probability threshold to determine abnormal state transition paths and generate process deviation features.

[0063] Specifically, taking the online application process for personal insurance or auto insurance as an example, the business state space can include the following five key states: S1: Application (user fills in basic information and submits an application), S2: Risk Assessment (system or manual assessment of health declaration, financial underwriting, etc.), S3: Payment (user completes premium payment), S4: Policy Generation (system issues official policy), and S5: Cancellation (user applies to terminate contract and receives premium refund). These states constitute a finite set of states, namely the business state space S = {S1, S2, S3, S4, S5}, used to model the user's behavioral trajectory throughout the entire business lifecycle. Then, the original user operation log sequence, such as submitting an application, skipping assessment, direct payment, and policy generation, is converted into a state sequence according to a preset mapping rule, resulting in the operation sequence [S1→S3→S4]. This sequence is a state transition path, reflecting the user's actual behavioral path in the business process. Finally, based on historical normal user behavior data, the transition frequency between each state is statistically analyzed and normalized into a state transition probability matrix, as shown in the table below.

[0064]

[0065] The transition probability matrix represents the probability of transitioning from one state to another. For example, the probability of transitioning from S1 (insurance purchase) to S2 (risk assessment) is 0.7, which is a normal process. However, the probability of transitioning from S5 (insurance cancellation) back to S1 (re-insurance) is 0.8, which may reflect suspicious behavior such as arbitrage. When the system receives an operation sequence, it maps it to a state transition path and then uses the Markov chain algorithm to calculate the joint probability of the path. For example, for the path S1→S3→S4, its joint probability is:

[0066] P=P(S1→S3)×P(S3→S4)=0.15×0.65=0.0975

[0067] The system then compares the joint probability with a preset anomaly probability threshold. If the joint probability of the actual path is lower than the threshold, the path is determined to be an abnormal state transition path. For example, some attackers may bypass the risk assessment process through technical means and jump directly from insurance to payment, i.e., path S1→S3, whose transition probability is only 0.15. If multiple low-probability transitions occur consecutively, the overall path probability may decay rapidly and fall below the anomaly probability threshold, triggering a system alarm. The final generated process deviation feature refers to quantifying the above anomaly judgment result into a numerical feature for subsequent risk modeling.

[0068] In this embodiment, by constructing a business state space and applying Markov chain modeling, dynamic modeling and abnormal path identification of user operation processes are realized. Compared with the traditional rule-based static judgment method, this method significantly improves the ability to detect hidden threats by capturing complex violations such as abnormal operation order and process skipping. Especially in the insurance business, the processes of insurance application, underwriting, and claims settlement have strong sequential and compliance requirements. Any behavior that deviates from the normal path may indicate fraud or security risks. By setting a reasonable transfer probability threshold, the system can automatically identify high-risk paths without human intervention.

[0069] 204. Integrate key behavioral features and process deviation features to construct a user behavior feature set.

[0070] In this embodiment, multiple key features extracted from user behavior, such as operation frequency, time distribution, and business logic anomalies, are integrated at the data level with process deviation features generated by the Markov chain algorithm to form a comprehensive user behavior feature set. The feature set includes both static attributes of user behavior and the degree of anomaly in dynamic operation paths, which can more comprehensively and accurately depict user behavior patterns and provide high-quality input data for subsequent threat detection.

[0071] 205. Perform threat detection on the user behavior feature set based on preset security detection rules to obtain threat detection results.

[0072] The process involves: acquiring pre-defined network threat intelligence; constructing a threat knowledge base based on this intelligence; building a knowledge graph based on pre-defined business data; adding risk attributes to entities in the knowledge graph using the threat knowledge base; generating security detection rules based on the threat knowledge base and the knowledge graph; performing real-time matching analysis on user behavior feature sets using these security detection rules to identify known threats within the user behavior feature sets; conducting multi-dimensional entity association analysis on the user behavior feature sets using the knowledge graph to determine hidden threats; and generating threat detection results by combining known and hidden threats.

[0073] Specifically, the system collects malicious information related to insurance business from threat intelligence sources, including but not limited to malicious IP addresses, malicious domain names, malicious file hashes, attack fingerprints, and C2 communication characteristics. Based on this, it further integrates fraud and attack patterns within the insurance industry to construct a threat knowledge base tailored to insurance business scenarios. This knowledge base not only includes general cybersecurity threats but also industry-specific threats. For example, it includes a database of forged insurance application materials, recording image features of forged ID cards, driver's licenses, and medical documents, and identifying abnormal OCR patterns; IP address ranges from high-risk areas, marking IPs originating from overseas, frequently initiating abnormal access, or previously involved in insurance fraud; and an insurance fraud pattern database, including digital fingerprints of typical insurance fraud behaviors. All of this cyber threat intelligence is stored in a structured format in the threat knowledge base and supports dynamic updates and version management.

[0074] Furthermore, this involves constructing a semantically rich insurance security knowledge graph using core business data from the insurance system. Specifically, a graph database (Neo4j) is used as the storage and computing engine. The following core node entities are defined: Policy (attributes include policy amount, insurance type, effective date, policyholder, beneficiary, etc.); User (attributes include user role, historical behavior score, affiliated institution, etc.); Device (attributes include access IP, MAC address, device fingerprint, geolocation, operating system, etc.). Semantic relationships are established between entities, such as: (User) - [:Operation] -> (Policy), (Policy) - [:Relationship] -> (Device), (IP) - [:Affiliation] -> (High-risk area). The constructed knowledge graph achieves unified modeling of multi-dimensional entities such as policies, users, devices, and geolocations. Then, intelligence information from the threat knowledge base is injected into the knowledge graph to analyze relevant entities. Risk labeling is performed, for example: if an IP address exists in the high-risk IP database, its corresponding "device" node is marked as risk_level=high; if the material image associated with an insurance policy matches the forgery feature database, the policy node is marked as is_forged=true; if a user frequently operates high-risk insurance policies, the risk score of its node is automatically increased. Based on this, the knowledge graph not only reflects business relationships but also integrates security context. Furthermore, by combining static rule templates and the graph structure, executable security detection rules are automatically generated. For example, rule 1: if a user operates multiple high-value insurance policies (>1 million yuan) and these policies are all associated with the same high-risk IP device, a group fraud warning is triggered; rule 2: if an insurance policy is canceled within 24 hours of its generation, and the cancellation operation comes from an overseas IP, an abnormal cancellation alarm is triggered. The above rules can be directly used for subsequent real-time matching analysis.

[0075] Next, the user behavior feature set generated in the previous steps is input into the rule engine and compared in real time with the pre-generated security detection rules. Once a match is found, a known threat is determined to exist, such as SQL injection behavior, malicious IP access, high frequency of insurance cancellation, and other obvious violations. At the same time, deep association analysis is performed in the knowledge graph using the graph query language (Cypher) to uncover hidden threats that are difficult to detect. Finally, the system merges the known threats found by rule matching with the hidden threats mined by the knowledge graph to generate a unified threat detection output. The threat detection results not only include the judgment of whether it is abnormal, but also include information such as risk level, involved entities, association paths, and confidence level.

[0076] In this embodiment, by constructing a threat knowledge base and an insurance business knowledge graph, accurate identification of known threats and in-depth mining of hidden threats are achieved. It has stronger context awareness and correlation analysis capabilities, and can effectively identify complex fraudulent behaviors across accounts, devices, and policies. At the same time, the rule generation and threat analysis processes are highly automated, improving detection efficiency and accuracy. It is suitable for data-intensive, complex, and fraudulent business scenarios in the insurance industry, enhancing the system's defense capabilities.

[0077] 206. Use a pre-set machine learning model to perform threat detection on the user behavior feature set and obtain the threat detection results.

[0078] The process involves acquiring historical network data and establishing a baseline for normal behavior based on this data; training labeled samples using the baseline; constructing a threat classification model using a random forest algorithm based on the labeled samples; and using the threat classification model to perform threat detection on the user behavior feature set to obtain the threat detection results.

[0079] Specifically, the system collects historical network operation data and user operation logs from the core insurance business system over a period of time, including login records, policy operations, claims submissions, file access, API calls, and other behavioral data. By cleaning, normalizing, and extracting features from the above data, the system statistically analyzes the operation patterns of various types of users in different business scenarios and constructs a normal behavior baseline. The normal behavior baseline not only includes statistical indicators such as average daily number of operations, common access periods, and typical operation paths, but also introduces a dynamic modeling mechanism. The system uses the Isolation Forest algorithm to establish a dynamic baseline model of user behavior. The system expands user behavior features to 15 dimensions, including operation frequency, access period, policy amount distribution, operation sequence length, device stability, and cross-system access frequency. The system sets the model parameters: n_estimators = 100, contamination = 0.01, to identify abnormal behaviors that deviate from the normal pattern.

[0080] It should be noted that Isolation Forest assesses the degree of anomalousness for each sample by constructing multiple isolated trees, and its anomalousness scoring formula is as follows:

[0081] Score(x) = 2 -E(h(x)) / c(n)

[0082] In the formula, E(h(x)) represents the average path length of the sample in all isolated trees. The longer the path, the rarer and more likely the behavior is to be abnormal. c(n) is the normalization factor.

[0083] When the abnormal score of a user's behavior exceeds a preset threshold, the system determines that it deviates from the normal baseline and can be used for subsequent sample annotation.

[0084] Furthermore, historical data is automatically labeled based on a dynamic baseline model. Behaviors that do not significantly deviate from the baseline are marked as normal, while behaviors that deviate significantly are marked as abnormal. This labeling process reduces the cost of manual labeling and improves sample quality and consistency. On this basis, the user behavior feature set in the labeled samples is used as input, and whether it is a threat is used as the output label to train a classification model based on random forest. This classification model consists of multiple decision trees, which can effectively handle high-dimensional features, avoid overfitting, and provide feature importance ranking, thereby enhancing the interpretability of the model.

[0085] To further improve detection performance, a hybrid model combining XGBoost and BiLSTM can be used for optimization. To enhance the model's understanding of insurance business semantics, a TF-IDF weighting mechanism is introduced, and an insurance domain dictionary containing over 200 professional terms is constructed. The traditional TF-IDF formula is also improved to highlight the importance of key business terms in behavioral analysis, thereby enhancing the model's ability to identify fraudulent intent. Finally, the user behavior feature set collected and constructed in real time is input into the trained machine learning model. The model outputs a classification result indicating whether the behavior is normal or abnormal, and can include information such as risk probability and confidence level. This can be used to trigger alarms, block operations, or generate reports, achieving intelligent identification of unknown threats and complex attacks.

[0086] In this embodiment, by establishing a baseline of normal behavior based on historical data and combining it with isolated forests to achieve dynamic anomaly detection, the problem that traditional static thresholds are difficult to adapt to behavioral changes is solved. By automatically labeling samples and training machine learning models such as random forests, the ability to identify new attacks and covert fraudulent behaviors is significantly improved. The introduction of TF-IDF weighting, BiLSTM time series modeling and hybrid model structures further enhances the model's understanding and discrimination accuracy of insurance business context.

[0087] 207. When the threat detection result indicates that there is a threat in the user behavior feature set, identify the corresponding abnormal user behavior data, respond to and handle the abnormal user behavior data, and generate a threat detection and handling report.

[0088] This involves configuring firewall rules based on threat detection results, blocking IP addresses corresponding to abnormal user behavior data based on these rules, and intercepting the abnormal user behavior data; dynamically adjusting access control lists to add IP addresses corresponding to abnormal user behavior data to the blacklist, and using network segmentation technology to isolate these IP addresses to independent network zones; identifying the target business platform accessed by the abnormal user behavior data, and performing vulnerability scanning and patching on the target business platform.

[0089] Specifically, after the system completes threat detection on the user behavior feature set and confirms the existence of abnormal behavior, it first generates targeted firewall policy instructions based on the detection results. By calling the API interface of the firewall or security gateway, it dynamically configures access control rules to precisely block identified malicious IP addresses. For example, in a car insurance damage assessment platform or claims review system, if it detects that an IP address frequently submits forged materials or bypasses risk control processes within a short period, the system will automatically generate firewall rules to block the IP's access to relevant business interfaces, preventing it from continuing to initiate abnormal requests. Simultaneously, it combines API gateway protection mechanisms to configure rate limiting policies to prevent malicious users from conducting high-frequency probing through legitimate interfaces. Afterwards, the system uses automated scripts or a security orchestration platform to block malicious IPs identified in the threat detection results. The system writes access control lists (ACLs) to network devices in real time. This process supports integration with mainstream firewalls, switches, WAFs, and other devices to ensure that policies take effect immediately. The system also handles abnormal behavior in a tiered manner based on factors such as the policy amount, user role, and operation type. For example, abnormal operations involving policies worth millions are immediately blocked with high priority. For agent accounts with daily sales exceeding the threshold (>100 policies) or abnormal surrender rates (>30%), a medium-level alarm is triggered and operation permissions are restricted. Furthermore, through VLAN segmentation or SDN (Software Defined Networking) technology, devices or users marked as high-risk are dynamically migrated to isolation zones, restricting them to accessing only internal audit systems or security analysis platforms and preventing them from accessing core business resources. This achieves precise isolation and prevents lateral movement.

[0090] Furthermore, upon detecting a threat, the system automatically traces the business systems involved, such as auto insurance damage assessment platforms, online insurance portals, and claims review systems. The system automatically calls a vulnerability scanning tool (OpenVAS) to perform deep security checks on the affected business platforms to identify any unpatched vulnerabilities, such as authentication flaws, missing input validation, or configuration errors. Once a vulnerability is found, an automated remediation process is immediately initiated. The system also deploys a dynamic WAF rule base, integrates open-source engines such as ModSecurity, and extends insurance-specific protection rules. For example, it detects abnormal patterns in high-risk operations such as deductible modifications and uses ELK (Elasticsearch + Logstash + Kibana) to analyze log traffic in real time. When abnormal requests exceed 100 times per minute within a unit of time, the WAF rule level is automatically upgraded to enhance protection strength.

[0091] In this embodiment, by linking threat detection results with network control, access isolation, vulnerability remediation, and other processes, a closed-loop security operation system from discovery to response to remediation is constructed. This system achieves second-level blocking and automated handling of abnormal behavior, significantly shortens the average response time, effectively curbs the spread of attacks, and improves the flexibility and security of the network boundary through multi-level control methods such as dynamic ACLs, VLAN isolation, and API rate limiting. It also enhances the system's own anti-attack capabilities and data integrity assurance, making it particularly suitable for scenarios in the insurance industry where high-value data is concentrated and compliance requirements are strict.

[0092] Furthermore, based on the risk scores and corresponding weights of abnormal user behavior across multiple dimensions, a comprehensive risk score for the abnormal user behavior data is calculated using a weighted average. The risk level corresponding to the abnormal user behavior data is confirmed based on the comprehensive risk score, and a threat detection and handling report is generated based on the risk level and the comprehensive risk score. The threat detection and handling report includes risk assessment results and handling recommendations.

[0093] Specifically, after detecting and analyzing the characteristics of abnormal user behavior, the system performs quantitative scoring from three levels: user, policy, and operation. Combined with preset scoring weights, a unified comprehensive risk score is calculated through a weighted fusion algorithm to comprehensively measure the potential threat level of the behavior.

[0094] In this embodiment, the scores and weights of each dimension are set as follows: The user dimension score (U_score) reflects the credibility of a user's historical behavior. It is scored based on information such as whether the user has engaged in any violations in the past and whether they have been repeatedly marked as high-risk. The score ranges from 0 to 100. For example, if an agent has no history of violations, then U_score = 0; if they have triggered abnormal policy cancellations or high-frequency policy issuance alarms multiple times, then U_score can rise to 60-80. The weight of this dimension is set to 30%. The policy dimension score (P_score) reflects the sensitivity and risk characteristics of the policy itself, comprehensively considering the policy amount, type of insurance, effective date, and whether it is associated with high-risk factors. Factors such as region are considered. For example, when a single policy amount exceeds 1 million yuan, the P_score = 70; if the policy is accessed from an overseas IP address or belongs to a high-fraud-rate insurance product, the P_score can be increased to 90, with this dimension's weight set at 40%. The operation dimension score (O_score) reflects the compliance and abnormality of the operation, mainly based on process deviation, operation time, and permission overreach. For example, if a user skips risk assessment and directly purchases insurance, the O_score = 60; if policies are modified in batches between 0:00 and 6:00 AM, the O_score = 50, with this dimension's weight set at 30%. The comprehensive risk score is calculated using the following weighted formula:

[0095] Score=0.3×U_score+0.4×P_score+0.3×O_scoreScore=0.3×U_score+0.4×P_score+0.3×O_score;

[0096] The final score ranges from [0, 100], with higher values ​​indicating a greater overall risk associated with the abnormal behavior.

[0097] Furthermore, the calculated comprehensive risk score is mapped to a pre-defined five-level risk classification system, specifically divided as follows: 0-20: Low risk, representing minor abnormal behavior, continuous observation is recommended; 21-40: Attention, representing certain risks, requiring enhanced monitoring; 41-60: Medium risk, representing deviations from normal operations, manual review is recommended; 61-80: High risk, representing clear signs of violation, operation permissions restricted; 81-100: Emergency risk, representing a high degree of suspicion of fraud or attack, immediate blocking and alerting. This classification mechanism supports dynamic adjustment, and thresholds can be optimized according to business development and changes in the threat landscape. Ultimately, the system automatically generates a structured threat detection and handling report, which includes not only basic information such as detection time, abnormal IP, and operational behavior, but also risk assessment results, such as the comprehensive risk score and scores for each dimension, as well as handling recommendations, such as blocking IPs, isolating devices, and restricting account permissions. The system supports pushing reports to security managers, compliance departments, or regulatory reporting platforms in PDF, email, or API interface formats.

[0098] In this embodiment of the application, by constructing a multi-dimensional risk scoring system, quantitative assessment and accurate classification of abnormal behavior are achieved, which improves the scientific nature and operability of risk identification. The generated threat detection and handling report not only provides detection conclusions, but also includes the causes of risks, the scope of impact, and the handling path, thereby improving the response efficiency and decision-making quality of security incidents and enhancing the insurance system's proactive defense capabilities, compliance support capabilities, and continuous improvement capabilities in complex network environments.

[0099] Furthermore, to further enhance the capabilities of the threat detection and response system described in this application, regular red-blue team exercises can be conducted to simulate real-world attack scenarios, comprehensively testing and improving the system's detection accuracy, response speed, and defense resilience. For example, a simulated car insurance fraud attack involves attackers uploading forged vehicle damage images, tampering with VIN code recognition results, and bypassing OCR confidence checks to test the system's ability to identify fraudulent claims. A simulated health insurance fraud attack involves simulating multiple highly similar medical claim applications submitted by the same user within a short period, combined with abnormal time-based operations and cross-policy related behaviors, to verify the system's ability to detect organized fraud. Simultaneously, a policy data contamination testing tool is developed to proactively inject noisy samples into the training data to evaluate the stability and robustness of the threat classification model under data perturbation, ensuring the model retains reliable discrimination capabilities in real-world complex environments. Additionally, a federated learning mechanism is introduced, based on the open-source framework FATE (Flexible Automachine Learning). The toolkit constructs a horizontal federated learning system, consisting of five participating insurance companies and one regulatory node. Each participant trains an XGBoost model locally using its own data and uses the SecureBoost algorithm to jointly iterate the tree model. Only encrypted gradient information is exchanged; the original data is not shared. Paillier homomorphic encryption technology is used during communication to ensure the security of intermediate information transmission, improving the model's ability to generalize and identify new cross-institutional attacks while meeting the protection requirements for personal and commercial data. Furthermore, the system deploys a blockchain evidence storage subsystem based on Hyperledger Fabric. The network uses the Raft consensus mechanism and includes four Orderer nodes to ensure consistent transaction order. Each insurance company deploys two Peer nodes to participate in chaincode execution and ledger maintenance. All critical security operations are recorded on the blockchain in the form of transactions, achieving full-process traceability through blockchain technology and providing credible evidence support for subsequent regulatory inspections.

[0100] Furthermore, as Figure 1 In terms of specific implementation, this application provides a network threat detection device, such as... Figure 3As shown, the device includes: a data acquisition module 301, a feature construction module 302, a threat detection module 303, and a threat processing module 304.

[0101] The data acquisition module 301 is used to collect network operation data and extract user behavior data, and preprocess the user behavior data to obtain structured data, wherein the structured data includes user operation sequences.

[0102] The feature construction module 302 is used to extract key behavioral features from structured data based on multiple dimensions, use the Markov chain algorithm to determine the abnormal state transition path in the user operation sequence and generate process deviation features, and fuse the key behavioral features and process deviation features to construct a user behavior feature set.

[0103] The threat detection module 303 is used to perform threat detection on the user behavior feature set based on preset security detection rules or by using a preset machine learning model, and obtain threat detection results.

[0104] The threat handling module 304 is used to identify the corresponding abnormal user behavior data when the threat detection result indicates that there is a threat in the user behavior feature set, and to respond to and handle the abnormal user behavior data, and generate a threat detection and handling report.

[0105] In specific application scenarios, the data acquisition module 301 can be used to perform traffic mirroring on the target business platform, forwarding the copied network operation data of the target business platform to the data processing device. The data processing device includes an image recognition tool and a video extraction tool. The image recognition tool extracts image data from the network operation data and extracts image feature vectors, while the video extraction tool parses the video stream protocol in the network operation data and extracts video keyframe features. Based on a timestamp mechanism, the image feature vectors and video keyframe features are synchronized through a preset message queue to generate user behavior data. The user behavior data is then standardized and cleaned based on a preset structured format to obtain structured data.

[0106] In specific application scenarios, the feature construction module 302 can be used to extract multiple key behavioral features from structured data based on user behavior, business logic, and risk association dimensions; define a business state space according to a preset business process; map user operation sequences to corresponding state transition paths based on the business state space; calculate the joint probability of state transition paths using the Markov chain algorithm; compare the joint probability with a preset anomaly probability threshold; determine abnormal state transition paths; and generate process deviation features.

[0107] In specific application scenarios, the threat detection module 303 can be used to acquire preset network threat intelligence, build a threat knowledge base based on the network threat intelligence; build a knowledge graph based on preset business data, and add risk attributes to entities in the knowledge graph using the threat knowledge base; generate security detection rules based on the threat knowledge base and the knowledge graph; perform real-time matching analysis on user behavior feature sets using security detection rules to identify known threats in the user behavior feature sets, and perform multi-dimensional entity association analysis on user behavior feature sets using the knowledge graph to determine hidden threats; and generate threat detection results by combining known threats and hidden threats.

[0108] In specific application scenarios, the threat detection module 303 can be used to acquire historical network data, establish a normal behavior baseline based on the historical network data, train labeled samples using the normal behavior baseline, construct a threat classification model based on the labeled samples using the random forest algorithm, and use the threat classification model to perform threat detection on the user behavior feature set to obtain the threat detection results.

[0109] In specific application scenarios, the threat handling module 304 can be used to configure firewall rules based on threat detection results, block IP addresses corresponding to abnormal user behavior data based on firewall rules, and intercept abnormal user behavior data; dynamically adjust access control lists, add IP addresses corresponding to abnormal user behavior data to the blacklist, and use network segmentation technology to isolate IP addresses to independent network areas; determine the target business platform accessed by abnormal user behavior data, and perform vulnerability scanning and patching on the target business platform.

[0110] In specific application scenarios, the threat handling module 304 can be used to calculate a comprehensive risk score for abnormal user behavior data by weighting the risk scores and corresponding score weights of abnormal user behavior across multiple dimensions; confirm the risk level corresponding to the abnormal user behavior data based on the comprehensive risk score; and generate a threat detection and handling report based on the risk level and the comprehensive risk score. The threat detection and handling report includes risk assessment results and handling recommendations.

[0111] It should be noted that other corresponding descriptions of the functional units involved in the network threat detection device provided in this embodiment can be found in [reference needed]. Figure 1 and Figure 2 The corresponding descriptions in [the document] will not be repeated here.

[0112] Based on the above, Figure 1 Accordingly, this embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements the aforementioned method for detecting network threats.

[0113] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. The software product to be identified can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), including several instructions to enable a computer device (such as a personal computer, server, or network device) to execute the network threat detection methods for various implementation scenarios of this application.

[0114] Based on the above, Figure 1 and Figure 2 The method shown, and Figure 3 The network threat detection device embodiment shown is designed to achieve the above objectives, such as... Figure 4 As shown, this embodiment also provides a physical device for detecting network threats. This device includes a communication bus, a processor, a memory, and a communication interface. It may also include input / output interfaces and a display device. The various functional units can communicate with each other via the bus. The memory stores a computer program, and the processor executes the program stored in the memory to perform the network threat detection method described in the above embodiment.

[0115] Optionally, the physical device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.

[0116] Those skilled in the art will understand that the structure of a network threat detection physical device provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.

[0117] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the aforementioned physical device, supporting the operation of information processing programs and other software and / or programs to be identified. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software in the information processing physical device.

[0118] Through the above description of the implementation methods, those skilled in the art can clearly understand that this application can be implemented using software plus necessary general-purpose hardware platforms, or it can be implemented through hardware. By applying the technical solution of this application, Markov chains are used to model user operation sequences, improving behavior prediction and anomaly identification capabilities. Simultaneously, process deviation features are introduced, enabling the identification of hidden threats that traditional detection rules cannot cover. Markov chains can continuously learn as user behavior evolves, exhibiting strong adaptability. A user behavior feature set integrating key behavioral features and process deviation features is constructed to achieve multi-dimensional dynamic threat identification. Dual-mode detection using rule detection and machine learning models is supported, improving generalization ability for unknown dangers while maintaining detection accuracy. A closed-loop management mechanism from detection, response to reporting is established, realizing management from threat discovery to automated handling, and improving overall detection efficiency. The above methods improve the detection capabilities for new, disguised, and internal threats, shorten response time, enhance adaptability, and provide a more efficient and reliable solution for cybersecurity protection in the insurance industry.

[0119] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.

[0120] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.

Claims

1. A method for detecting network threats, characterized in that, The method includes: Collect network operation data and extract user behavior data. Preprocess the user behavior data to obtain structured data, wherein the structured data includes user operation sequences. Key behavioral features are extracted from the structured data based on multiple dimensions. The Markov chain algorithm is used to determine the abnormal state transition path in the user operation sequence and generate process deviation features. The key behavioral features and the process deviation features are fused to construct a user behavior feature set. Threat detection results are obtained by performing threat detection on the user behavior feature set based on preset security detection rules or by using preset machine learning models; When the threat detection result indicates that the user behavior feature set is threatened, the corresponding abnormal user behavior data is identified, and the abnormal user behavior data is responded to and processed to generate a threat detection and processing report.

2. The method according to claim 1, characterized in that, The process involves collecting network operation data and extracting user behavior data, then preprocessing the user behavior data to obtain structured data, including: Traffic mirroring is performed on the target business platform, and the copied network operation data of the target business platform is forwarded to the data processing device, wherein the data processing device includes an image recognition tool and a video extraction tool; The image recognition tool is used to extract image data from the network operation data and extract image feature vectors. At the same time, the video extraction tool is used to parse the video stream protocol in the network operation data and extract video keyframe features. Based on a timestamp mechanism, the image feature vector and the video keyframe features are synchronized through a preset message queue to generate user behavior data. The user behavior data is standardized and cleaned based on a preset structured format to obtain structured data.

3. The method according to claim 1, characterized in that, The process of extracting key behavioral features from the structured data based on multiple dimensions, determining abnormal state transition paths in the user operation sequence using the Markov chain algorithm, and generating process deviation features includes: Based on user behavior, business logic, and risk association dimensions, multiple key behavioral features are extracted from the structured data. Define a business state space according to a preset business process, and map the user operation sequence to a corresponding state transition path based on the business state space; The joint probability of the state transition path is calculated using the Markov chain algorithm, and the joint probability is compared with a preset anomaly probability threshold to determine the abnormal state transition path and generate process deviation features.

4. The method according to claim 1, characterized in that, The threat detection based on the preset security detection rules on the user behavior feature set, to obtain the threat detection result, includes: Acquire preset network threat intelligence and construct a threat knowledge base based on the network threat intelligence; A knowledge graph is constructed based on preset business data, and risk attributes are added to entities in the knowledge graph using the threat knowledge base. Security detection rules are generated based on the threat knowledge base and the knowledge graph. The security detection rules are used to perform real-time matching analysis on the user behavior feature set to identify known threats in the user behavior feature set, and the knowledge graph is used to perform multi-dimensional entity association analysis on the user behavior feature set to determine hidden threats. The known threats and the hidden threats are combined to generate threat detection results.

5. The method according to claim 1, characterized in that, The step of using a preset machine learning model to perform threat detection on the user behavior feature set to obtain threat detection results includes: Acquire historical network data and establish a baseline for normal behavior based on the historical network data; The labeled samples are trained using the normal behavior baseline, and a threat classification model is constructed based on the labeled samples using the random forest algorithm; The threat classification model is used to perform threat detection on the user behavior feature set to obtain the threat detection results.

6. The method according to claim 1, characterized in that, The response and handling of the abnormal user behavior data includes: Configure firewall rules based on the threat detection results, block the IP addresses corresponding to the abnormal user behavior data based on the firewall rules, and intercept the abnormal user behavior data. The access control list is dynamically adjusted to add the IP addresses corresponding to the abnormal user behavior data to the blacklist, and network segmentation technology is used to isolate the IP addresses to an independent network area. Identify the target business platform accessed by the abnormal user behavior data, and perform vulnerability scanning and remediation on the target business platform.

7. The method according to claim 1, characterized in that, The generation of the threat detection and handling report includes: Based on the risk scores of the abnormal user behavior across multiple dimensions and their corresponding weights, a weighted comprehensive risk score for the abnormal user behavior data is calculated. Based on the comprehensive risk score, the risk level corresponding to the abnormal user behavior data is determined, and a threat detection and handling report is generated based on the risk level and the comprehensive risk score. The threat detection and handling report includes risk assessment results and handling recommendations.

8. A network threat detection device, characterized in that, The device includes: The data acquisition module is used to collect network operation data and extract user behavior data, and preprocess the user behavior data to obtain structured data, wherein the structured data includes user operation sequences. The feature construction module is used to extract key behavioral features from the structured data based on multiple dimensions, use the Markov chain algorithm to determine the abnormal state transition path in the user operation sequence and generate process deviation features, and fuse the key behavioral features and the process deviation features to construct a user behavior feature set. The threat detection module is used to perform threat detection on the user behavior feature set based on preset security detection rules or using a preset machine learning model, and obtain threat detection results. The threat handling module is used to determine the corresponding abnormal user behavior data when the threat detection result indicates that there is a threat in the user behavior feature set, and to respond to and handle the abnormal user behavior data, and generate a threat detection and handling report.

9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Website information auditing control method and system

    CN121210772A

  • Dynamic evolution-based network abnormal user identification method, apparatus and device, and storage medium

    CN121462296A

  • Abnormal behavior prediction method and system based on user behavior portrait

    CN122027374A

  • Abnormal behavior prediction method and system based on user behavior portrait

    CN122027374B