Abnormal detection method and device for user access behavior

By combining multi-order window grouping and the isolation forest model, the problems of high labor cost and low accuracy in detecting anomalies in user access behavior are solved, and more efficient and accurate anomaly detection is achieved.

CN114117421BActive Publication Date: 2025-09-23SHANGHAI GUAN AN INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111441750.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-29
Publication Date
2025-09-23
Estimated Expiration
2041-11-29

AI Technical Summary

Technical Problem

Existing methods for detecting abnormal user access behavior have high labor costs, low processing efficiency and accuracy, and cannot effectively consider the inherent logical relationship between user behavior sequences.

Method used

By obtaining the initial access behavior sequence from the user access behavior data of the web system, multi-order window grouping is performed, the rank sum test method is used to determine the target sliding window order, the combined frequency distribution value of the access behavior combination is calculated, and anomaly detection is performed in combination with the isolation forest model.

Benefits of technology

It effectively reduces labor costs, improves the efficiency and accuracy of detecting abnormal user access behaviors, and can better consider the inherent logical relationship between user behavior sequences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117421B_ABST
    Figure CN114117421B_ABST
Patent Text Reader

Abstract

The present application discloses a method and device for detecting abnormalities in user access behavior, which relates to the field of network information security technology and can improve the efficiency of abnormal behavior detection. The method includes: obtaining an initial access behavior sequence corresponding to a user identifier from user access behavior data of a web system; performing multi-order window grouping on the initial access behavior sequence to obtain multiple target access behavior combination sequences for characterizing different access behavior classification features; calculating a combination frequency distribution value corresponding to the associated access behavior combination based on the associated access behavior combinations between the multiple target access behavior combination sequences; and obtaining a detection result of whether the user access behavior is abnormal using an anomaly detection algorithm based on the combination frequency distribution value. The present application is suitable for detecting abnormalities in user access behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a method and device for detecting anomalies in user access behavior. Background Art

[0002] With the development of mobile Internet, the traditional network boundaries of enterprises are gradually disappearing. For example, in large-scale Internet-using enterprises such as finance and telecommunications, the number of daily active users can reach tens of millions. Among them, the proportion of malicious access represented by gray and black industries remains high. Malicious attacks occur at all times, and new attack methods emerge in an endless stream. Traditional passive defense technology is based on historical experience and can only identify known threats, but cannot detect and defend against unknown threats.

[0003] Existing methods for anomaly data mining primarily include distance-based, statistics-based, density-based, and clustering-based methods. While these methods have achieved significant progress in research by scholars both domestically and internationally, they still suffer from several flaws and shortcomings. For example, distance-based methods present difficulties in selecting distance functions and parameters; statistics-based methods require pre-determined data distribution, but data distribution functions are difficult to obtain in advance; density-based methods are time-consuming and complex; and clustering-based methods are limited to processing clustering problems. These methods, constrained by the attributes and categories of the data to be processed, lack effective theoretical models and methods for processing non-deterministic information and discrete data.

[0004] Currently, the main methods for detecting anomalies in user access behavior include those based on Markov models, directed graph models, and labeled classification and recognition models. Markov models and directed graph models are relatively inefficient for processing large datasets. Labeled classification and recognition models require extensive manual labeling, and their accuracy is entirely dependent on the accuracy of the pre-annotated labels. Consequently, existing methods for detecting anomalies in user access behavior incur high labor costs and suffer from low processing efficiency and accuracy. Summary of the Invention

[0005] In view of this, the present application provides a method and device for detecting anomalies in user access behavior, the main purpose of which is to solve the technical problems of high labor costs, low processing efficiency and accuracy in existing user access behavior anomaly detection.

[0006] According to one aspect of the present application, a method for detecting abnormalities in user access behavior is provided, the method comprising:

[0007] Obtaining an initial access behavior sequence corresponding to the user identifier from user access behavior data of the web system;

[0008] Performing multi-order window grouping on the initial access behavior sequence to obtain multiple target access behavior combination sequences for characterizing different access behavior classification features;

[0009] Calculating, based on the access behavior combinations associated between the plurality of target access behavior combination sequences, a combination frequency distribution value corresponding to the associated access behavior combinations;

[0010] According to the combined frequency distribution value, an anomaly detection algorithm is used to obtain a detection result of whether the user access behavior is abnormal.

[0011] According to another aspect of the present application, a device for detecting abnormalities in user access behavior is provided, the device comprising:

[0012] A sequence acquisition module is used to obtain an initial access behavior sequence corresponding to a user identifier from user access behavior data of a web system;

[0013] A grouping module, configured to perform multi-order window grouping on the initial access behavior sequence to obtain a plurality of target access behavior combination sequences for characterizing classification features of different access behaviors;

[0014] A frequency calculation module, configured to calculate, based on the access behavior combinations associated between the plurality of target access behavior combination sequences, a combined frequency distribution value corresponding to the associated access behavior combinations;

[0015] The evaluation module is used to obtain a detection result of whether the user access behavior is abnormal based on the combined frequency distribution value using an anomaly detection algorithm.

[0016] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the above-mentioned method for detecting abnormalities in user access behavior is implemented.

[0017] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned method for detecting abnormalities in user access behavior when executing the program.

[0018] By means of the above-mentioned technical scheme, the method and device for detecting anomalies in user access behavior provided by the present application, compared with the existing technical scheme for realizing anomaly detection in user access behavior based on Markov model, directed graph model, and labeled classification recognition model, the present application obtains the initial access behavior sequence corresponding to the user identifier from the user access behavior data of the web system, performs multi-order window grouping on the initial access behavior sequence, and obtains multiple target access behavior combination sequences for characterizing the classification characteristics of different access behaviors. According to the access behavior combinations associated between the multiple target access behavior combination sequences, the combination frequency distribution value corresponding to the associated access behavior combination is calculated. According to the combination frequency distribution value, the anomaly detection algorithm is used to obtain the detection result of whether the user access behavior is abnormal. It can be seen that through multi-order window verification, the detection of abnormal user access behavior is achieved by obtaining multiple target access behavior combination sequences that can accurately characterize the classification characteristics of different access behaviors based on the acquired access behavior sequences. This can effectively avoid the existing technical problems of high labor costs, low processing efficiency and accuracy in the detection of abnormal user access behavior based on Markov models, directed graph models, and labeled classification recognition models. By fully considering the inherent logical relationship between user access behavior sequences, the efficiency and accuracy of abnormal user access behavior detection can be effectively improved while reducing labor costs.

[0019] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0021] Figure 1 A flow chart of a method for detecting abnormalities in user access behavior provided by an embodiment of the present application is shown;

[0022] Figure 2 A flow chart showing another method for detecting abnormalities in user access behavior provided by an embodiment of the present application is shown;

[0023] Figure 3 A schematic diagram showing the relationship between the AVF score calculation process and related data provided in an embodiment of the present application is shown;

[0024] Figure 4 A schematic diagram of the structure of a device for detecting abnormalities in user access behavior provided by an embodiment of the present application is shown;

[0025] Figure 5 A schematic structural diagram of another device for detecting abnormalities in user access behavior provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0026] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.

[0027] In order to solve the technical problems of high labor cost, low detection efficiency and low accuracy of the existing user access behavior anomaly detection based on Markov model, directed graph model and labeled classification recognition model, this embodiment provides a user abnormal behavior sequence detection method, which realizes the detection of user access abnormal behavior by multi-order window verification and obtaining multiple target access behavior combination sequences that can accurately characterize the classification characteristics of different access behaviors based on the acquired access behavior sequence. It can solve the technical problem that the existing abnormal data mining method cannot consider the internal logical relationship between user behavior sequences, and effectively improve the efficiency and accuracy of abnormal behavior sequence detection while reducing labor costs. Figure 1 As shown, the method includes:

[0028] Step 101: Acquire an initial access behavior sequence corresponding to a user identifier from user access behavior data of a web system.

[0029] In this embodiment, initial access behavior data corresponding to a user identifier within a specified time period is obtained from the user access behavior data of a web system. The initial access behavior data can be divided into multiple data categories based on the execution entities, such as system access behavior data and host access behavior data. The user identifier is a field that uniquely identifies the user, such as an account ID (ACCT_ID) or an IP address (IP_ADDR). It should be noted that obtaining the user access behavior data of the web system can include obtaining initial access behavior sequences of different categories corresponding to multiple execution entities based on the user identifier, or obtaining initial access behavior sequences corresponding to user identifiers for different access behavior data categories corresponding to multiple execution entities. The dimensions for obtaining the initial access behavior sequences are not specifically limited herein.

[0030] Step 102: performing multi-order window grouping on the initial access behavior sequence to obtain a plurality of target access behavior combination sequences for characterizing different access behavior classification features.

[0031] In this embodiment, a dynamic sliding window is used to perform multi-order window grouping on the initial access behavior sequence based on the time dimension to obtain multiple access behavior combination sequences for different window orders. According to the frequency corresponding to each access behavior combination in each access behavior combination sequence, the rank sum test is used to determine the chi-square value of each access behavior combination sequence used to characterize the classification characteristics of different access behaviors, and the sliding window order corresponding to the maximum chi-square value is used as the target sliding window order, and then the multiple access behavior combination sequences corresponding to the target sliding window order are used as multiple target access behavior combination sequences.

[0032] In practical application scenarios, by performing anomaly assessments on multiple target access behavior combinations representing different classification characteristics, we can effectively reduce the impact of a single high-frequency access behavior on the overall access behavior anomaly assessment, making the overall anomaly assessment more business-interpretable. Furthermore, we use the rank sum test to determine the target sliding window order for optimal grouping effectiveness. Specifically, the greater the feature differences between combinations in an access behavior combination sequence, the greater the effectiveness of the grouping. This effectively avoids the high labor costs associated with existing manual grouping and model tuning.

[0033] Step 103: Calculate the combination frequency distribution value corresponding to the associated access behavior combination according to the access behavior combinations associated between the multiple target access behavior combination sequences.

[0034] In this embodiment, the attribute value frequency (AVF) algorithm is used to calculate the combined frequency distribution value corresponding to the associated access behavior combination. The AVF algorithm can determine whether the user access behavior is abnormal by calculating the frequency distribution characteristics of the associated access behavior combination, that is, the combined frequency distribution value is calculated based on the sum of the frequencies corresponding to multiple access behavior combinations associated between multiple target access behavior combination sequences and the number of target access behavior combination sequences. The smaller the combined frequency distribution value, the higher the abnormality of the user access behavior corresponding to the combined frequency distribution value.

[0035] In actual application scenarios, when faced with massive amounts of user access behavior data, a large amount of probability calculations are required for data processing, resulting in large resource consumption and low processing efficiency. This application uses the AVF algorithm to calculate the frequency of access behavior combinations in multiple target access behavior combination sequences to obtain combined frequency distribution values, which can effectively simplify the calculation process, while reducing the calculation cost and improving the calculation efficiency. In addition, since different target access behavior combination sequences can represent the classification features of different attribute dimensions, the AVF algorithm can be used to determine the correlation between access behavior combinations corresponding to the classification features of different attribute dimensions. Therefore, using multiple combined frequency distribution values ​​corresponding to the classification features of different attribute dimensions as input to the isolation forest model can further improve the accuracy of anomaly detection results.

[0036] Step 104: Based on the combined frequency distribution value, an anomaly detection algorithm is used to obtain a detection result of whether the user access behavior is abnormal.

[0037] In this embodiment, the anomaly detection algorithm is an isolation forest model, which takes the combined frequency distribution value corresponding to multiple target access behavior combination sequences as input, and uses the isolation forest (iForest) model to output the detection result of whether the user access behavior is abnormal. According to the needs of the actual application scenario, an abnormal data sample library can also be constructed based on the combined frequency distribution value corresponding to the anomaly detection result, so as to use the abnormal data sample library to further optimize and update the trained isolation forest model, thereby improving the accuracy of user access behavior anomaly detection.

[0038] For this embodiment, according to the above scheme, an access behavior sequence corresponding to the user identifier can be obtained from the user access behavior data of the web system, and the access behavior sequence can be grouped into multiple windows to obtain multiple target access behavior combination sequences for characterizing the classification characteristics of different access behaviors. According to the access behavior combinations associated between the multiple target access behavior combination sequences, the combination frequency distribution value corresponding to the associated access behavior combination is calculated. According to the combination frequency distribution value, an anomaly detection algorithm is used to obtain a detection result of whether the user access behavior is abnormal. Compared with the existing technical solutions for realizing user access behavior anomaly detection based on Markov models, directed graph models, and labeled classification recognition models, this embodiment uses the target access behavior combination sequence in the time dimension obtained by the dynamic sliding window to improve the efficiency and accuracy of anomaly detection of user access behavior, and effectively avoids the need for manual labeling in the existing technical solutions. The model accuracy is completely dependent on the accuracy of the early labeled labels, resulting in high labor costs, low detection efficiency and accuracy, and the inability to consider the internal logical relationship between user behavior sequences.

[0039] Furthermore, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another abnormal detection method for user access behavior is provided, such as Figure 2 As shown, the method includes:

[0040] Step 201: Based on the user access behavior data of the web system corresponding to the user identifier, an initial access behavior sequence is obtained in the chronological order of the access behavior. The initial access behavior sequence includes a plurality of behavior instructions corresponding to the execution subject.

[0041] During implementation, the user access behavior data of a web system may include user access behavior data corresponding to multiple execution entities. For the user access behavior data corresponding to different execution entities, behavioral instructions related to the operation content are extracted from the behavior log (user access behavior data) corresponding to the user identifier. The behavioral instructions corresponding to different execution entities are merged in the order of their occurrence time. Taking the host access behavior instruction as an example, an initial access behavior sequence containing the host access behavior instruction is obtained, and its generalized form is expressed as: cmd1, cmd2, cmd3, cmd3, cmd4, cmd2, cmd2, cmd5, ..., cmd1. In addition, the sample form of the user access behavior data obtained based on a specified time period is expressed as: cat, hostname, awk, stty, tset, sh, chmod, news, sh, netstat, netscape, netscape, netscape, netscape, netscape, netscape, netscape, netscape, pq, pq, sh, sh, sh, sh, sh, sh.

[0042] Step 202: Use a sliding window to group the initial access behavior sequences according to different window orders to obtain multiple initial access behavior combination sequences.

[0043] In the implementation, the three-order sliding window grouping process of the initial access behavior sequence cmd1, cmd2, cmd3, cmd3, cmd4, cmd2, cmd2, cmd5, cmd6, cmd1, cmd2 is taken as an example to explain step 202 in detail:

[0044] 1) Before using the sliding window to group the initial access behavior sequence, it also includes removing duplicates of consecutive identical behavior instructions in the initial access behavior sequence to obtain the initial access behavior sequence after removing duplicates, which is expressed as: cmd1, cmd2, cmd3, cmd4, cmd2, cmd5, cmd6, cmd1, cmd2;

[0045] 2) By performing a three-order sliding window grouping on the initial access behavior sequence after duplicate removal, multiple initial access behavior combination sequences are obtained, specifically including: the first initial access behavior combination sequence flag1 obtained by the first-order window division, expressed as: [cmd1], [cmd2], [cmd3], [cmd4], [cmd2], [cmd5], [cmd6], [cmd1], [cmd2]; the second initial access behavior combination sequence flag2 obtained by the second-order window division, expressed as: [cmd1, cmd2], [cmd2, cmd3], [cmd3, cmd4], [cmd4, cmd2], [cmd2, cmd5], [cmd5, cmd6], [cmd6, cmd1], [cmd1, cmd2]; the third initial access behavior combination sequence flag3 obtained by the third-order window partition is expressed as: [cmd1, cmd2, cmd3], [cmd2, cmd3, cmd4], [cmd3, cmd4, cmd2], [cmd4, cmd2, cmd5], [cmd2, cmd5, cmd6], [cmd5, cmd6, cmd1], [cmd6, cmd1, cmd2].

[0046] Among them, the sliding window order can be set according to the needs of the specific application scenario. Based on the business behavior calculation cost considerations, the sliding window order can usually be selected in the range of 3 to 10. The order of the sliding window is not specifically limited here.

[0047] Step 203: Determine a plurality of target access behavior combination sequences for representing different access behavior classification features from the plurality of initial access behavior combination sequences according to the combination frequencies corresponding to the plurality of initial access behavior combination sequences.

[0048] In order to illustrate the specific implementation method of step 203, as a preferred embodiment, step 203 may specifically include: determining the target sliding window order by using the rank sum test method according to the combination frequency of each access behavior combination in each initial access behavior combination sequence; based on the target sliding window order, determining multiple target access behavior combination sequences for characterizing different access behavior classification characteristics from the multiple initial access behavior combination sequences; wherein, the multiple target access behavior combination sequences include multiple initial access behavior combination sequences whose sliding window order is greater than or equal to 1 and less than or equal to the target sliding window order.

[0049] During implementation, frequency statistics are performed on each access behavior combination in each initial access behavior combination sequence to obtain the access behavior combination frequency set corresponding to each initial access behavior combination sequence, namely the first access behavior combination frequency set (corresponding to flag1), the second access behavior combination frequency set (corresponding to flag2), and the third access behavior combination frequency set (corresponding to flag3). According to the access behavior combination frequency set, the rank sum test method is used to determine the sliding window order with the largest feature difference between the combinations in the initial access behavior combination sequence (the best sliding window grouping effectiveness), and use it as the target sliding window order, and then determine multiple target access behavior combination sequences with window orders less than or equal to the target sliding window order.

[0050] Specifically, the rank sum test, also known as the sequential sum test, is a nonparametric test used to test whether the differences between data samples are significant. It is independent of the overall distribution form and parameters of the data to be tested and is highly practical. Among them, the Kruskal-Wallis test (KW test), also known as the H test, is a type of rank sum test. Since the number of data samples in each group is greater than or equal to 5 (the number of combinations in this embodiment is greater than 5), the distribution of the data sample statistic KW is very close to the chi-square distribution with k-1 degrees of freedom. Therefore, the chi-square distribution can be used to test the behavior combination statistic KW of the initial access behavior combination sequence. The specific calculation process includes:

[0051] 1) Sort the frequencies in each access behavior combination frequency set from small to large, calculate the rank (ordinal number) of each frequency, and further obtain the rank sum R i Among them, rank is the ordinal number after the data is sorted from small to large. The rank value corresponding to the same data is the same and equal to the average value of the ordinal number corresponding to the same data.

[0052] 2) Use the chi-square value calculation formula to calculate the ratio of the sum of squares between groups of the behavior combination to the rank variance of the behavior combination to obtain the behavior combination statistic KW of the initial access behavior combination sequence. The specific calculation formula is:

[0053]

[0054] Among them, n i The number of frequencies (combinations) in the frequency set for each access behavior combination.

[0055] 3) If there is a knot value (the number of combinations with the same rank value) in the access behavior combination frequency set, a correction coefficient C is added to adjust the behavior combination statistic KW. The adjusted behavior combination statistic KW satisfies the following formula:

[0056] KW c =KW / C

[0057] in, τ j is the number of j-th knot values.

[0058] 4) KW c The larger the value, the higher the feature difference between the access behavior combinations after the sliding window grouping. c The sliding window order corresponding to the value is used as the target sliding window order to ensure the effectiveness of the sliding window grouping.

[0059] In actual application scenarios, each access behavior combination sequence represents the classification characteristics of different attribute dimensions. The greater the feature differences between the access behavior combinations in the access behavior combination sequence, the more obvious the classification characteristics, and the higher the accuracy of user access behavior anomaly detection. Determining the most preferred sliding window order based on the rank sum test method is conducive to improving the effectiveness of sliding window grouping, and thus improving the accuracy of user access behavior anomaly detection.

[0060] Step 204: Determine associated access behavior combinations based on access behavior combination association rules between the multiple target access behavior combination sequences, where the access behavior combination association rules mean that the access behavior combinations obtained from the multiple target access behavior combination sequences are in an inclusion relationship.

[0061] Step 205: Calculate the combined frequency distribution value corresponding to the associated access behavior combination using the AVF algorithm according to the associated access behavior combination.

[0062] During implementation, associated access behavior combinations (access behavior combinations with inclusion relationships) are obtained from multiple target access behavior combination sequences. Based on the ratio of the sum of the frequencies corresponding to each access behavior combination in the associated access behavior combinations to the number of target access behavior combination sequences, the AVF algorithm is used to obtain the combination frequency distribution value corresponding to the associated access behavior combination.

[0063] Specifically, taking the target sliding window order 3 as an example, Figure 3 As shown, AVF calculation is performed on all associated access behavior combinations in flag1, flag2, and flag3. Taking the first access behavior combination [cmd1] of flag1 as an example, the access behavior combination [cmd1] in flag1 has a combination frequency of 40, the access behavior combination [cmd1, cmd2] in flag2 has a combination frequency of 8, and the access behavior combination [cmd1, cmd2, cmd3] in flag3 has a combination frequency of 2. The AVF score value corresponding to the third-order sliding window in the target sliding window order 3 [flag1, flag2, flag3] is (40+8+2) / 3. The AVF score values ​​of all associated access behavior combinations are obtained by analogy.

[0064] It should be noted that the AVF score for the target sliding window order 3 also includes the AVF score [flag1] corresponding to the first-order sliding window and the AVF score [flag1, flag2] corresponding to the second-order sliding window. Thus, based on the AVF scores corresponding to the first-order sliding window, the second-order sliding window, and the third-order sliding window, a normalized table of access behavior combinations, data, is constructed to serve as input data for the isolation forest model. Specifically, for each behavior combination in the access behavior combination sequence obtained based on the first-order sliding window, the first AVF score corresponding to the first-order sliding window, the second AVF score corresponding to the second-order sliding window, and the third AVF score corresponding to the third-order sliding window are sequentially traversed to obtain.

[0065] Step 206: Based on the combined frequency distribution value, an anomaly detection algorithm is used to obtain a detection result of whether the user access behavior is abnormal.

[0066] During implementation, the anomaly detection algorithm is an isolation forest model, and the normalized table data of the access behavior combination obtained by traversal is input into the isolation forest model. Multiple binary trees are generated by multiple segmentation of the normalized table data, that is, the AVF score value set (combined frequency distribution value, that is, the first AVF score value, the second AVF score value, and the third AVF score value) corresponding to each behavior combination in the access behavior combination sequence obtained based on the first-order sliding window division generates a corresponding evaluation label. If the evaluation labels generated by all AVF score value sets corresponding to a certain user identifier are 1 (normal), then the access behavior detection result of the user is determined to be normal; if the evaluation labels generated by all AVF score value sets corresponding to a certain user identifier include abnormal labels, then the access behavior detection result of the user is determined to be 0 (abnormal), and corresponding alarm information is generated according to the abnormal access behavior combination corresponding to the abnormal label and / or the business object corresponding to the abnormal access behavior combination.

[0067] Among them, the isolation forest model is composed of multiple binary trees (iTree). A binary tree is a random tree. Each node has two leaf nodes (or child nodes) on the left and right. An AVF score value set is randomly selected based on the normalized table data, and the AVF score value set (for example, the sum of the AVF score values) is set as a threshold. All AVF score value sets are classified according to the threshold. The access behavior combination with an AVF score value set greater than or equal to the threshold is classified as the right node, and the access behavior combination with an AVF score value set less than the threshold is classified as the left node. The left and right nodes are recursively constructed in this way until the node can no longer be split or the height of the tree reaches a preset value. The binary tree construction is completed. Based on the constructed binary tree, the abnormality of the AVF score value set is judged according to the comprehensive path length from the leaf node to the root node.

[0068] Step 207: After obtaining a detection result indicating that the user access behavior is abnormal using the isolation forest model, the combined frequency distribution value corresponding to the abnormal detection result is used as an update data sample of the isolation forest model for updating and training the isolation forest model.

[0069] During implementation, the user access behavior detection results can be sent to a computer terminal and verified through manual intervention. If the detection result is confirmed to be abnormal, the combined frequency distribution value corresponding to the user's abnormal access behavior will be used as the abnormal data sample library of the isolation forest model to optimize and update the isolation forest model, thereby improving the accuracy of the isolation forest model's abnormality assessment.

[0070] By applying the technical solution of this embodiment, an initial access behavior sequence corresponding to a user identifier is obtained from user access behavior data of a web system, and the initial access behavior sequence is grouped into multiple windows to obtain a plurality of target access behavior combination sequences for characterizing classification features of different access behaviors. Based on the access behavior combinations associated between the plurality of target access behavior combination sequences, a combination frequency distribution value corresponding to the associated access behavior combination is calculated. Based on the combination frequency distribution value, an anomaly detection algorithm is used to obtain a detection result of whether the user access behavior is abnormal. Compared with the existing technical solutions for detecting anomalies in user access behaviors based on Markov models, directed graph models, and labeled classification recognition models, this embodiment uses a target access behavior combination sequence in the time dimension obtained by a dynamic sliding window to improve the efficiency and accuracy of detecting anomalies in user access behaviors, while effectively avoiding the need for manual labeling in the existing technical solutions, in which the accuracy of the model is completely dependent on the accuracy of the pre-labeled labels, resulting in high labor costs, low detection efficiency and accuracy, and the inability to consider the technical problems of the intrinsic logical relationship between user behavior sequences.

[0071] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a device for detecting abnormalities in user access behavior, such as Figure 4 As shown, the device includes: a sequence acquisition module 41, a grouping module 42, a frequency calculation module 43, and an evaluation module 44.

[0072] The sequence acquisition module 41 may be configured to acquire an initial access behavior sequence corresponding to a user identifier from user access behavior data of a web system.

[0073] The grouping module 42 may be used to perform multi-level window grouping on the initial access behavior sequence to obtain a plurality of target access behavior combination sequences for representing different access behavior classification features.

[0074] The frequency calculation module 43 may be configured to calculate a combination frequency distribution value corresponding to the associated access behavior combination according to the associated access behavior combinations between the plurality of target access behavior combination sequences.

[0075] The evaluation module 44 may be configured to obtain a detection result of whether the user access behavior is abnormal based on the combined frequency distribution value using an anomaly detection algorithm.

[0076] In specific application scenarios, such as Figure 5 As shown, the device may further include an updating module 45 .

[0077] In a specific application scenario, the sequence acquisition module 41 can be specifically used to obtain an initial access behavior sequence according to the user access behavior data of the web system corresponding to the user identifier and in the chronological order of the access behavior. The initial access behavior sequence includes multiple behavior instructions corresponding to the execution subject.

[0078] In a specific application scenario, the grouping module 42 includes a first grouping unit 421 and a second grouping unit 422 .

[0079] The first grouping unit 421 may be configured to group the initial access behavior sequences according to different window orders using a sliding window to obtain a plurality of initial access behavior combination sequences.

[0080] The second grouping unit 422 may be configured to determine, from the multiple initial access behavior combination sequences according to the combination frequencies corresponding to the multiple initial access behavior combination sequences, multiple target access behavior combination sequences for representing different access behavior classification features.

[0081] In a specific application scenario, the second grouping unit 422 can be specifically used to determine the target sliding window order using the rank sum test method based on the combination frequency of each access behavior combination in each initial access behavior combination sequence; based on the target sliding window order, determine multiple target access behavior combination sequences for characterizing different access behavior classification characteristics from the multiple initial access behavior combination sequences; wherein, the multiple target access behavior combination sequences include multiple initial access behavior combination sequences whose sliding window order is greater than or equal to 1 and less than or equal to the target sliding window order.

[0082] In a specific application scenario, the frequency calculation module 43 includes an association determination unit 431 and an AVF calculation unit 432 .

[0083] The association determination unit 431 can be used to determine the associated access behavior combinations based on the access behavior combination association rules between the multiple target access behavior combination sequences, wherein the access behavior combination association rules mean that there is an inclusion relationship between the access behavior combinations obtained from the multiple target access behavior combination sequences.

[0084] The AVF calculation unit 432 may be configured to calculate a combined frequency distribution value corresponding to the associated access behavior combination using an AVF algorithm according to the associated access behavior combination.

[0085] In a specific application scenario, the anomaly detection algorithm is an isolation forest model. The update module 45 can be used to use the combined frequency distribution value corresponding to the abnormal detection result as an updated data sample of the isolation forest model after obtaining the detection result that the user access behavior is abnormal using the isolation forest model, for updating the training of the isolation forest model.

[0086] It should be noted that for other corresponding descriptions of the functional units involved in the device for detecting abnormal user access behavior provided in the embodiment of the present application, please refer to Figure 1 and Figure 2 The corresponding description in will not be repeated here.

[0087] Based on the above Figure 1 and Figure 2 The method shown in FIG. 1 is a method for performing the above-mentioned operation. Accordingly, the embodiment of the present application further provides a storage medium on which a computer program is stored. When the program is executed by a processor, the above-mentioned operation is performed. Figure 1 and Figure 2 The anomaly detection method for user access behavior is shown.

[0088] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each implementation scenario of the present application.

[0089] Based on the above Figure 1 、 Figure 2 The method shown, and Figure 4 In order to achieve the above-mentioned purpose, the embodiment of the present application further provides a computer device, which can be a personal computer, a server, a network device, etc. The physical device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to achieve the above-mentioned Figure 1 and Figure 2 The anomaly detection method for user access behavior is shown.

[0090] Optionally, the computer device may further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a Wi-Fi module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and may optionally include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a Bluetooth interface, a Wi-Fi interface), etc.

[0091] Those skilled in the art will understand that the computer device structure provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or a combination of certain components, or different component arrangements.

[0092] The storage medium may also include an operating system and a network communication module. An operating system is a program that manages the hardware and software resources of a computer device, supporting the execution of information processing programs and other software and / or programs. The network communication module facilitates communication between components within the storage medium, as well as with other hardware and software within the physical device.

[0093] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present application can be implemented by means of software plus the necessary general hardware platform, or by means of hardware. By applying the technical solution of the present application, compared with the existing technical solutions based on Markov models, directed graph models and annotated classification and recognition models, the present embodiment realizes the detection of abnormal user access behaviors by multi-order window verification, and obtains multiple target access behavior combination sequences that can accurately characterize the classification characteristics of different access behaviors based on the acquired access behavior sequences. It can effectively avoid the existing technical problems of high labor costs, low processing efficiency and accuracy in detecting abnormal user access behaviors based on Markov models, directed graph models, and annotated classification and recognition models. By fully considering the internal logical relationship between user access behavior sequences, it can effectively improve the efficiency and accuracy of detecting abnormal user access behaviors while reducing labor costs.

[0094] Those skilled in the art will understand that the accompanying drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily required to implement the present application. Those skilled in the art will understand that the modules in the devices in the implementation scenario can be distributed in the devices of the implementation scenario according to the implementation scenario description, or can be changed accordingly and located in one or more devices different from the implementation scenario. The modules of the above-mentioned implementation scenario can be combined into one module, or can be further split into multiple sub-modules.

[0095] The serial numbers of the above application are for descriptive purposes only and do not represent the advantages or disadvantages of the implementation scenarios. The above disclosure only discloses several specific implementation scenarios of the present application, but the present application is not limited thereto. Any changes that can be conceived by those skilled in the art should fall within the scope of protection of the present application.

Claims

1. A method for detecting abnormalities in user access behavior, characterized in that: include: Obtaining an initial access behavior sequence corresponding to the user identifier from user access behavior data of the web system; Performing multi-order window grouping on the initial access behavior sequence to obtain multiple target access behavior combination sequences for characterizing different access behavior classification features; Calculating, based on the access behavior combinations associated between the plurality of target access behavior combination sequences, a combination frequency distribution value corresponding to the associated access behavior combinations; Based on the combined frequency distribution value, an anomaly detection algorithm is used to obtain a detection result of whether the user access behavior is abnormal; The multiple target access behavior combination sequences include multiple initial access behavior combination sequences whose sliding window order is greater than or equal to 1 and less than or equal to the target sliding window order.

2. The method according to claim 1, characterized in that The step of obtaining an access behavior sequence corresponding to a user identifier from user access behavior data of a web system includes: According to the user access behavior data of the web system corresponding to the user identifier, an initial access behavior sequence is obtained according to the time sequence of the access behavior. The initial access behavior sequence includes multiple behavior instructions corresponding to the execution subject.

3. The method according to claim 1, characterized in that The performing multi-order window grouping on the initial access behavior sequence to obtain multiple target access behavior combination sequences for characterizing different access behavior classification features includes: Using a sliding window to group the initial access behavior sequences according to different window orders, to obtain multiple initial access behavior combination sequences; According to the combination frequencies respectively corresponding to the multiple initial access behavior combination sequences, multiple target access behavior combination sequences for representing different access behavior classification features are determined from the multiple initial access behavior combination sequences.

4. The method according to claim 3, characterized in that The determining, based on the combination frequencies respectively corresponding to the multiple initial access behavior combination sequences, multiple target access behavior combination sequences for characterizing different access behavior classification features from the multiple initial access behavior combination sequences includes: According to the combination frequency of each access behavior combination in each initial access behavior combination sequence, the target sliding window order is determined using the rank sum test method; Based on the target sliding window order, a plurality of target access behavior combination sequences for characterizing different access behavior classification features are determined from the plurality of initial access behavior combination sequences.

5. The method according to claim 1, wherein The calculating, based on the access behavior combinations associated between the plurality of target access behavior combination sequences, a combination frequency distribution value corresponding to the associated access behavior combinations includes: determining associated access behavior combinations according to access behavior combination association rules between the multiple target access behavior combination sequences; According to the associated access behavior combination, an AVF algorithm is used to calculate a combined frequency distribution value corresponding to the associated access behavior combination.

6. The method according to claim 5, characterized in that The access behavior combination association rule means that the access behavior combinations respectively obtained from the multiple target access behavior combination sequences are in an inclusion relationship.

7. The method according to claim 1, characterized in that The anomaly detection algorithm is an isolation forest model. After the step of obtaining a detection result of whether the user access behavior is abnormal using the anomaly detection algorithm according to the combined frequency distribution value, the method further includes: When the isolation forest model is used to obtain a detection result indicating that the user access behavior is abnormal, the combined frequency distribution value corresponding to the abnormal detection result is used as an update data sample of the isolation forest model for updating and training the isolation forest model.

8. A device for detecting abnormalities in user access behavior, characterized in that: include: A sequence acquisition module is used to obtain an initial access behavior sequence corresponding to a user identifier from user access behavior data of a web system; a grouping module, configured to perform multi-order window grouping on the initial access behavior sequence to obtain a plurality of target access behavior combination sequences for characterizing different access behavior classification features, wherein the plurality of target access behavior combination sequences include a plurality of initial access behavior combination sequences whose sliding window order is greater than or equal to 1 and less than or equal to the target sliding window order; A frequency calculation module, configured to calculate, based on the access behavior combinations associated between the plurality of target access behavior combination sequences, a combined frequency distribution value corresponding to the associated access behavior combinations; The evaluation module is used to obtain a detection result of whether the user access behavior is abnormal based on the combined frequency distribution value using an anomaly detection algorithm.

9. A storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method for detecting abnormalities in user access behavior according to any one of claims 1 to 7 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, wherein: When the processor executes the program, the method for detecting abnormalities in user access behavior according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Abnormal user detection method, device and system and computer storage medium

    CN110798440A

  • Abnormal behavior detection method and device, equipment and storage medium

    CN111651767A