Abnormality detection method, model training method and related device

By using an autoencoder to detect user operation behavior sessions, the problems of low efficiency and low accuracy of abnormal behavior detection in the prior art are solved, and more efficient and accurate abnormal behavior detection effects are achieved.

CN114124412BActive Publication Date: 2025-05-09HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010755506.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-07-30
Publication Date
2025-05-09
Estimated Expiration
2040-07-30

AI Technical Summary

Technical Problem

The prior art has low efficiency and low accuracy in detecting user abnormal behavior, and cannot meet user needs.

Method used

The session of user operation behavior is detected by using an autoencoder (AE model). By extracting the behavioral characteristics and time characteristics in the session, the target AE model is trained to determine whether the operation is a normal operation.

Benefits of technology

It improves the efficiency and accuracy of abnormal detection, reduces the dependence of feature engineering and rule sets, and can effectively capture timing abnormal behavior characteristics.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114124412B_ABST
    Figure CN114124412B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides an anomaly detection method, a model training method and related devices, the method comprising: extracting a first conversation, wherein the first conversation is used to describe the behavioral characteristics and time characteristics when operating a first account within a preset time length, and the time characteristics are used to reflect the correlation of the behavioral characteristics in time sequence; inputting the first conversation into a target autoencoder AE model to obtain a detection result; wherein the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics when the target account is normally operated within a preset time length. The use of the embodiment of the present application can improve the efficiency and accuracy of anomaly detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to an anomaly detection method, a model training method and related devices. Background Art

[0002] The rise of the Internet marks the arrival of the information age. As the Internet enters thousands of households, data and information are growing explosively. At the same time, attackers use illegal means to steal account information and obtain private data, which poses a huge threat to user privacy and assets. In order to protect the key information and data of enterprises and individuals from being stolen and misused, it is usually necessary to detect the behavior of user accounts to facilitate corresponding security responses to abnormal behaviors such as unauthorized operations and remote logins. Especially for resource accounts in cloud service accounts, behavior detection becomes crucial, because resource accounts control the allocation and permission control of all available resources. Once these account information is leaked, it will be a huge loss of profit and security reputation for cloud service providers who aim to make profits from this.

[0003] At present, user abnormal behavior detection usually uses rule-based methods and data feature-based methods. However, both feature engineering and rule-based analysis methods rely on manually established rules or features, and most of them can only analyze a single behavior. However, behavioral data usually has many features and a large amount of data. Some key variable features may be obscured by a large number of other variable features, which ultimately leads to low efficiency and unsatisfactory accuracy of anomaly detection and cannot meet user needs.

[0004] Therefore, improving the efficiency and accuracy of anomaly detection is a hot topic that technicians in this field are currently studying. Summary of the invention

[0005] The embodiments of the present application disclose an anomaly detection method, a model training method, and related devices, which can improve the efficiency and accuracy of anomaly detection.

[0006] In a first aspect, an embodiment of the present application discloses a method for detecting abnormal behavior, comprising:

[0007] Extracting a first session, wherein the first session is used to describe a behavior feature and a time feature when operating the first account within a preset time length, and the time feature is used to reflect the correlation of the behavior feature in time sequence;

[0008] The first conversation is input into the target autoencoder AE model to obtain a detection result; wherein, the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model for training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length.

[0009] In the embodiment of the present application, an autoencoder is used to detect the first session corresponding to the operation behavior. On the one hand, since the autoencoder is unsupervised training, there is no need to build feature engineering or rule sets, which avoids experience-based anomaly detection, reduces a large amount of research input by researchers, and improves the efficiency of anomaly detection. On the other hand, the first session contains behavioral characteristics and time characteristics of the operation behavior, and the session reflects the correlation of behavioral characteristics in time sequence. Therefore, the trained autoencoder model can form a behavior sequence in time sequence for anomaly detection during detection, rather than detecting a single behavior, which helps to detect time-series abnormal behavior characteristics other than key features, and improves the accuracy of anomaly detection.

[0010] In a possible implementation manner of the first aspect, inputting the first conversation into a target AE model to obtain a detection result includes:

[0011] Inputting the first session into the target AE model to obtain a first reconstruction session;

[0012] determining a first reconstruction error based on the first session and the first reconstruction session;

[0013] If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model.

[0014] In another possible implementation of the first aspect, extracting the first session includes:

[0015] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of operating an account;

[0016] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a first data set; the first data set includes at least one piece of operation behavior data;

[0017] The first conversation is obtained by dividing the data in the first data set according to a time sequence relationship and a preset time length.

[0018] In another possible implementation of the first aspect, the preset time length is 15 minutes; and dividing according to the preset time length based on the temporal relationship of the data in the first data set to obtain the first session includes:

[0019] According to the time series relationship of the data in the first data set, the first session is obtained by dividing the data into 15 minutes; the first session includes n pieces of operation behavior data within 15 minutes; each of the n pieces of data includes q features, and the q features are used to indicate the behavior features and the time features.

[0020] In another possible implementation of the first aspect, the behavioral characteristics include at least one of an Internet Protocol IP address, a Media Access Control MAC address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a MAC address, an account ID, or an operation location.

[0021] In a second aspect, an embodiment of the present application discloses an autoencoder AE model training method, comprising:

[0022] Extract at least two sessions, where each session is used to describe the behavior characteristics and time characteristics of normal operation of the target account within a preset time period, and the time characteristics in each session are used to reflect the temporal correlation of the behavior characteristics in each session;

[0023] The AE model is trained according to the at least two conversations to obtain a target AE model, wherein the target autoencoder model is used to detect whether an operation of completing the first conversation is a normal operation according to the first conversation.

[0024] In an embodiment of the present application, at least two sessions are extracted from the normal operation behavior data, and the autoencoder is trained with the at least two sessions to obtain a target autoencoder model. Since the at least two sessions are data confirmed to be normal operations, the target AE model obtained by training the at least two sessions, for the sessions corresponding to normal operations, the output reconstructed sessions will not deviate too much from the original input sessions, thereby being able to effectively capture the inherent similarities and commonalities between normal account behaviors. At the same time, since the session obtained by abnormal operation is abnormal, after being input into the encoder, the final reconstructed session will deviate more from the original input session, so that it can be detected by the model.

[0025] On the one hand, since the autoencoder is trained in an unsupervised manner, there is no need to build feature engineering or rule sets, which avoids experience-based anomaly detection, reduces the large amount of research input by researchers, and improves the efficiency of anomaly detection. On the other hand, each session contains the behavioral characteristics and time characteristics of the operation, and the session reflects the correlation of behavioral characteristics in time sequence. Therefore, the trained autoencoder model can form a behavioral sequence in chronological order for anomaly detection during detection, rather than detecting a single behavior. This helps to detect temporal abnormal behavioral characteristics other than key features, and improves the accuracy of anomaly detection.

[0026] In a possible implementation manner of the second aspect, the method further includes:

[0027] Inputting the at least two conversations into the target AE model to obtain at least two reconstruction errors;

[0028] A first threshold is determined according to the at least two reconstruction errors; the first threshold is used to measure whether the operation of completing the first session is a normal operation.

[0029] In yet another possible implementation of the second aspect, determining the first threshold according to the at least two reconstruction errors includes:

[0030] The first threshold is determined according to distribution of the at least two reconstruction errors.

[0031] In another possible implementation of the second aspect, the method further includes:

[0032] Extracting multiple sessions, where a portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of normal operations on the first target account within a preset time period, and another portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of abnormal operations on the second target account within the preset time period;

[0033] The target AE model is verified according to the multiple sessions and the first threshold; if the number of sessions corresponding to the abnormal operations detected according to the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed.

[0034] In yet another possible implementation of the second aspect, extracting at least two conversations includes:

[0035] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of normal operation of the target account;

[0036] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a target data set;

[0037] According to the temporal relationship of the data in the target data set, the data is divided according to a preset time length to obtain the at least two conversations.

[0038] In another possible implementation of the second aspect, the preset time length is 15 minutes; and the dividing according to the preset time length based on the temporal relationship of the data in the target data set to obtain the at least two conversations includes:

[0039] According to the temporal relationship of the data in the target data set, at least two sessions are obtained by dividing the data into 15-minute time lengths; each of the at least two sessions includes at least one operation behavior data within 15 minutes; each of the at least one data includes q features, and the q features are used to indicate the behavior features and the time features; wherein q is greater than or equal to 1.

[0040] In yet another possible implementation of the second aspect, the acquiring multiple pieces of operation behavior data includes:

[0041] A plurality of samples are selected from the log of the unified identity authentication service IAM; the plurality of samples include data of normal operation of the target account in a plurality of time periods on a plurality of dates;

[0042] From the plurality of samples, filtering samples whose Internet Protocol IP addresses belong to whitelist login IPs;

[0043] The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

[0044] In another possible implementation of the second aspect, the behavioral characteristics include at least one of an IP address, a media access control mac address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a mac address, an account ID, or an operation location.

[0045] In yet another possible implementation of the second aspect, the training the autoencoder model according to the at least two conversations to obtain a target autoencoder model includes:

[0046] Inputting the at least two sessions into the AE model to obtain at least two reconstruction sessions;

[0047] According to the at least two sessions and the at least two reconstruction sessions, the AE model is updated by a gradient descent algorithm to obtain the target AE model.

[0048] In yet another possible implementation of the second aspect, inputting the at least two conversations into the autoencoder model to obtain at least two reconstructed conversations includes:

[0049] establishing an input matrix based on the at least two conversations;

[0050] Based on the AE model, the input matrix is ​​encoded and decoded to obtain an output matrix; the output matrix includes the at least two reconstruction sessions.

[0051] In a third aspect, an embodiment of the present application discloses an abnormal behavior detection device, comprising:

[0052] An extraction unit, configured to extract a first session, wherein the first session is used to describe a behavior feature and a time feature when operating the first account within a preset time length, and the time feature is used to reflect the correlation of the behavior feature in time sequence;

[0053] A detection unit is used to input the first conversation into a target autoencoder AE model to obtain a detection result; wherein the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length.

[0054] In a possible implementation manner of the third aspect, the detection unit is specifically used to:

[0055] Inputting the first session into the target AE model to obtain a first reconstruction session;

[0056] determining a first reconstruction error based on the first session and the first reconstruction session;

[0057] If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model.

[0058] In a possible implementation manner of the third aspect, the extraction unit is specifically used to:

[0059] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of operating an account;

[0060] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a first data set; the first data set includes at least one piece of operation behavior data;

[0061] The first conversation is obtained by dividing the data in the first data set according to a time sequence relationship and a preset time length.

[0062] In a possible implementation manner of the third aspect, the preset time length is 15 minutes; and the extraction unit is specifically used to:

[0063] According to the time series relationship of the data in the first data set, the first session is obtained by dividing the data into 15 minutes; the first session includes n pieces of operation behavior data within 15 minutes; each of the n pieces of data includes q features, and the q features are used to indicate the behavior features and the time features.

[0064] In a possible implementation of the third aspect, the behavioral characteristics include at least one of an Internet Protocol IP address, a Media Access Control MAC address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a MAC address, an account ID, or an operation location.

[0065] In a fourth aspect, an embodiment of the present application discloses an autoencoder AE model training device, comprising:

[0066] An extraction unit, configured to extract at least two conversations, wherein each conversation is used to describe the behavior characteristics and time characteristics of normal operation of the target account within a preset time period, and the time characteristics in each conversation are used to reflect the correlation of the behavior characteristics in each conversation in terms of time sequence;

[0067] A training unit is used to train the AE model according to the at least two conversations to obtain a target AE model, wherein the target autoencoder model is used to detect whether an operation of completing the first conversation is a normal operation according to the first conversation.

[0068] In a possible implementation manner of the fourth aspect, the training unit is further used to input the at least two conversations into the target AE model to obtain at least two reconstruction errors;

[0069] The training unit is further used to determine a first threshold according to the at least two reconstruction errors; the first threshold is used to measure whether the operation of completing the first session is a normal operation.

[0070] In a possible implementation manner of the fourth aspect, the training unit is further used to:

[0071] The first threshold is determined according to distribution of the at least two reconstruction errors.

[0072] In a possible implementation manner of the fourth aspect, the extraction unit is further used to extract multiple sessions, a portion of the multiple sessions is used to describe behavior characteristics and time characteristics when the first target account is normally operated within a preset time period, and another portion of the multiple sessions is used to describe behavior characteristics and time characteristics when the second target account is abnormally operated within the preset time period;

[0073] The device also includes: a verification unit, used to verify the target AE model according to the multiple sessions and the first threshold; if the number of sessions corresponding to the abnormal operations detected according to the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed.

[0074] In a possible implementation manner of the fourth aspect, the extraction unit is specifically used to:

[0075] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of normal operation of the target account;

[0076] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a target data set;

[0077] The first session is obtained by dividing the data in the target data set according to a temporal relationship of the data and a preset time length.

[0078] In a possible implementation manner of the fourth aspect, the preset time length is 15 minutes; and the extraction unit is specifically configured to:

[0079] According to the temporal relationship of the data in the target data set, at least two sessions are obtained by dividing the data into 15-minute time lengths; each of the at least two sessions includes at least one operation behavior data within 15 minutes; each of the at least one data includes q features, and the q features are used to indicate the behavior features and the time features; wherein q is greater than or equal to 1.

[0080] In a possible implementation manner of the fourth aspect, the extraction unit is specifically used to:

[0081] A plurality of samples are selected from the log of the unified identity authentication service IAM; the plurality of samples include data of normal operation of the target account in a plurality of time periods on a plurality of dates;

[0082] From the plurality of samples, filtering samples whose Internet Protocol IP addresses belong to whitelist login IPs;

[0083] The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

[0084] In a possible implementation of the fourth aspect, the behavioral characteristics include at least one of an IP address, a media access control mac address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a mac address, an account ID, or an operation location.

[0085] In a possible implementation manner of the fourth aspect, the training unit is specifically used to:

[0086] Inputting the at least two sessions into the AE model to obtain at least two reconstruction sessions;

[0087] According to the at least two sessions and the at least two reconstruction sessions, the AE model is updated by a gradient descent algorithm to obtain the target AE model.

[0088] In a possible implementation manner of the fourth aspect, the training unit is specifically used to:

[0089] establishing an input matrix based on the at least two conversations;

[0090] Based on the AE model, the input matrix is ​​encoded and decoded to obtain an output matrix; the output matrix includes the at least two reconstruction sessions.

[0091] In a fifth aspect, an embodiment of the present application discloses a business node, which includes a processor and a memory; the processor is used to execute computer instructions stored in the memory, so that the business node implements the method described in the first aspect or any possible implementation method of the first aspect.

[0092] In a sixth aspect, an embodiment of the present application discloses a server, comprising a processor and a memory; the processor is used to execute computer instructions stored in the memory, so that the server implements the method described in the second aspect or any possible implementation manner of the second aspect.

[0093] In the seventh aspect, an embodiment of the present application discloses a computer-readable storage medium, in which computer instructions are stored, and the computer instructions are used to implement the method described in the first aspect or any possible implementation of the first aspect, or the computer instructions are used to implement the method described in the second aspect or any possible implementation of the second aspect.

[0094] In an eighth aspect, an embodiment of the present application discloses an anomaly detection system, which includes a business node and a server, wherein the business node includes the anomaly detection device described in the third aspect or any possible implementation of the third aspect, and the server includes the model training device described in the fourth aspect or any possible implementation of the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0095] The following is an introduction to the drawings used in the embodiments of the present application.

[0096] Figure 1 It is a schematic diagram of the architecture of an anomaly detection system provided in an embodiment of the present application;

[0097] Figure 2 It is a schematic diagram of the architecture of another anomaly detection system provided in an embodiment of the present application;

[0098] Figure 3 It is a schematic diagram of the architecture of another anomaly detection system provided in an embodiment of the present application;

[0099] Figure 4 It is a schematic diagram of the architecture of another anomaly detection system provided in an embodiment of the present application;

[0100] Figure 5 is a structural diagram of an anomaly detection system provided in an embodiment of the present application;

[0101] Figure 6 It is a schematic diagram of the architecture of another anomaly detection system provided in an embodiment of the present application;

[0102] Figure 7 It is a flowchart of a model training method provided in an embodiment of the present application;

[0103] Figure 8 It is a structural diagram of a session provided in an embodiment of the present application;

[0104] Fig. 9 It is a schematic diagram of the structure of operation behavior data provided by an embodiment of the present application;

[0105] Fig.10 It is a structural diagram of an autoencoder AE model provided in an embodiment of the present application;

[0106] Fig.11 It is a flowchart of an anomaly detection method provided in an embodiment of the present application;

[0107] Fig.12 It is a flowchart of another abnormality detection method provided in an embodiment of the present application;

[0108] Fig.13is a structural schematic diagram of an abnormality detection device provided in an embodiment of the present application;

[0109] Fig.14 It is a structural schematic diagram of a model training device provided in an embodiment of the present application;

[0110] Fig.15 It is a structural diagram of a service node provided in an embodiment of the present application;

[0111] Fig.16 It is a structural diagram of a model training server provided in an embodiment of the present application. DETAILED DESCRIPTION

[0112] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. It should be noted that in the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs, and the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0113] The following is a brief introduction to the relevant technologies and professional terms involved in this application to facilitate understanding.

[0114] 1. Deep Learning

[0115] Deep learning is a branch of machine learning. It is an algorithm that uses artificial neural networks as its architecture to represent and learn data. Deep learning is the study of the inherent laws and representation levels of sample data. The information obtained in the learning process is of great help in interpreting data such as text, images, and sounds. Its ultimate goal is to enable machines to have analytical learning capabilities like humans and to be able to recognize data such as text, images, and sounds.

[0116] 2. Autoencoder

[0117] An autoencoder is an artificial neural network used in unsupervised learning for data, and is a type of seq2seq model. An autoencoder usually consists of an encoder and a decoder. It has the function of a general representation algorithm for time-series data and is often used for dimensionality reduction and outlier detection.

[0118] 3. Unified Identity and Access Management (IAM)

[0119] IAM is a basic service provided by cloud service providers for identity authentication and permission management, helping users to securely control the operation permissions of cloud services and resources.

[0120] The system architecture and business scenarios of the embodiments of the present application are described below. It should be noted that the system architecture and business scenarios described in this application are intended to more clearly illustrate the technical solutions of the present application and do not constitute a limitation on the technical solutions provided by the present application. It is known to those skilled in the art that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by the present application are also applicable to similar technical problems.

[0121] See also Figure 1 , Figure 1 It is a schematic diagram of an anomaly detection system 10 provided in an embodiment of the present application, wherein the anomaly detection system 30 includes an internal network server 101 and a pattern generation server 102, wherein the auditor collects audit data according to the internal network server 101. The pattern generation server 102 analyzes the collected audit data using corresponding association rules or sequence patterns, and then compares the behavior pattern obtained by the analysis with the normal behavior pattern to obtain a pattern comparison result. On the one hand, the normal behavior pattern library is continuously supplemented, and on the other hand, a corresponding audit security response is made to a very small number of abnormal behavior patterns such as confirmation of unauthorized access and remote login. This method requires analysis of the behavior patterns behind the data. As the business becomes more and more complex, the behavior patterns become more and more complex, and cannot meet the user's needs for anomaly detection of complex business systems.

[0122] See also Figure 2 , Figure 2It is a schematic diagram of another abnormality detection system 20 provided in an embodiment of the present application. The abnormality detection system 20 processes the data to be detected 201 through a rule set 202 to obtain a detection result 204 of "determined normal" and a detection result 205 of "determined abnormal". For example, the data to be detected 201 may include indicators such as the number of logins requested by a certain IP within a period of time, the request success rate, and the request method. In the process of constructing the rule set 202, the abnormal behavior is composed of one or more rules. For example, referring to area 203, it can be seen that the rule set may include the number of requests, the request success rate, the request method, etc. These rules may be thresholds that specify statistics (for example, the number of requests exceeds a certain threshold), or they may be explicitly declared values ​​of variables. Further, the rules and rules are usually connected together using logical connection elements such as AND or NOT to form a composite rule, so as to achieve the purpose of abnormal behavior analysis. However, rule-based abnormal behavior analysis requires a full understanding of the business and the input of experts. When the scenarios of abnormal behavior gradually increase, not only the labor cost is huge, but also the rule set will gradually expand, and the coupling between the rules is large, and it is often more difficult to sort out the existing rules. On the other hand, since the rule set is very clear, it also leaves room for hackers to bypass detection. Hackers can conduct targeted intrusions, which will bring greater information security risks.

[0123] See also Figure 3 , Figure 3It is a schematic diagram of another anomaly detection system 30 provided in an embodiment of the present application. The data processing module 301 of the anomaly detection system 30 is used to process data missing, data duplication, data error, etc., so that the data becomes standardized data. The feature engineering module 302 is used to extract key features for distinguishing normal and abnormal behaviors from the standardized data, or it can also be vectorized. The learning algorithm module 303 can be an isolation forest (IsolationForest), a one-class support vector machine (One-Class SVM), etc., which are all commonly used algorithms for outlier detection or singular point detection, and are used to establish an algorithm model 304. The algorithm model 304 can be used to be deployed in a business node as a deployment model 306, and the deployment model 306 can be used to detect real data 305 to obtain a judgment result. However, the performance of the anomaly detection system depends largely on the selection and implementation of feature engineering, and whether it is an effective feature engineering depends on the valuable experience of researchers, just like the rule-based analysis method. In the field of network security, normal behaviors account for the vast majority of the subjects, and they are very similar; while abnormal behaviors are rare and different from each other, it is difficult for researchers to summarize the common characteristics of all abnormal behaviors using a certain scenario, which makes it impossible for feature engineering to capture common features that do not exist. As time goes by, new variants of abnormal behaviors will emerge, and old models will need to be updated regularly due to performance degradation, which greatly wastes the energy of researchers.

[0124] See also Figure 4 , Figure 4 This is a schematic diagram of the architecture of another anomaly detection system 40 provided in an embodiment of the present application, including a model training server 401 and a business node 402.

[0125] Among them, the model training server 401 is an electronic device with data processing capabilities. The model training server 401 includes an AE model. The model training server 401 can train the AE model according to the training data to obtain a target AE model. The target AE model can be deployed in the business node 402 to detect the operation behavior data of the user operation, so as to determine whether the user's operation is abnormal. Among them, the training data is data confirmed to be normal operation. When training the AE model, the data needs to be processed into session data, and the AE model can encode and decode abnormal behaviors with time series and reconstruct the data. Specifically, since the training data is data confirmed to be normal operation, the training data is used for encoding and decoding, and the reconstructed data output will not deviate too much from the original result, so that the inherent similarities and commonalities between normal account behaviors can be effectively captured. At the same time, due to the fact that the abnormal account behavior itself is rare, after the encoding and decoding process, the reconstructed data finally obtained deviates more from the original result, so that it can be detected by the model.

[0126] Business node 402 is an electronic device with data receiving and sending capabilities, which can be specifically used to implement access to a certain business function through an account. For example, a server deployed with IAM can be regarded as 402, and the target AE model can be used to detect the log of the unified identity authentication service, thereby realizing abnormal behavior analysis. For another example, an application server deployed with a Web Application Firewall (WAF) can be regarded as a business node 402, and the target AE model can be used for abnormal interception analysis of user login behavior on the application server. For another example, a situation awareness platform can also be regarded as a business node 402, and the target AE model can be used in the situation awareness platform to display and analyze data by docking with the data of user login behavior.

[0127] In a possible implementation, the anomaly detection system 40 may include three layers: an algorithm layer, a management layer, and a data layer. Figure 5 , Figure 5 is a schematic diagram of a possible anomaly detection system provided in an embodiment of the present application. The anomaly detection system may be Figure 4 The anomaly detection system 40 shown includes an algorithm layer 501, a management layer 502 and a data layer 503, wherein:

[0128] The algorithm layer 501, as the top layer of the entire system, may include data cleaning, data vectorization, model training and other deep learning algorithm implementations. The algorithm layer 501 includes a data cleaning module, a data vectorization module, a neural network training module and a deep learning module. The data cleaning module is used to clean the data used for training, remove invalid data, etc.; the data vectorization module is used to encode the data used for training, etc.; the neural network training module and the deep learning module are used to train the autoencoder model according to the training data.

[0129] As an important component connecting the data layer and the algorithm layer, the management layer 502 can solve the problems of job scheduling, data docking, data storage and data lifecycle management. Optionally, the management layer 502 can specifically include a job scheduling module, a data docking module, a data storage module and a data lifecycle management module. The job scheduling module is used to manage the progress of training jobs, or can also be used to schedule training data, etc.; the data docking module is used to dock the data of the algorithm layer and the management layer, etc.; the data storage module is used to arrange storage space for data such as training results, data cleaning results, or model output results; the data lifecycle management module is used to manage the validity period of data, or can also be used to clean up some expired data, etc.

[0130] The data layer 503 provides the source of the underlying data, which may include black and white samples for training, service or device logs for detection, other required related important data, and the display of data results. Optionally, the data layer 503 may specifically include a training black and white sample data module, a service / device original log module, a result data module, and other related data modules. The training black and white sample data module is used to collect or store black and white sample data, etc., where the black sample is a sample that confirms that there is an abnormal operation, and the white sample is a sample that confirms that the operation is normal; the service / device original log module is used to obtain the log of the server or other equipment that executes the business, etc., and the log can be used to obtain black and white sample data; the result data module is used to store data such as training results, or data clearing results, or model output results; other related data modules are used to store whitelist IP addresses, and other operation data, etc.

[0131] It is understandable that the model training server 401 can be an independent server or a server cluster composed of multiple servers. Figure 6 The model training server 401 can be composed of three parts: a training server 603, a management server 602 and a data server 601.

[0132] Correspondingly, the service node 402 may be a single service node or a service node cluster consisting of multiple service nodes.

[0133] Optionally, the anomaly detection system 40 can be applied to at least the following scenarios:

[0134] Application scenario 1: Monitoring and analysis of tenant resource allocation and permission control for cloud services.

[0135] Application scenario 2: Enterprise monitoring and analysis of internal user operation permissions.

[0136] Application scenario three: Security testing of internal enterprise system accounts.

[0137] Application scenario 4: Security testing of an enterprise’s operating permissions for external tenants.

[0138] See also Figure 7 , Figure 7 A model training method provided in an embodiment of the present application includes but is not limited to the following steps:

[0139] Step S701: The model training server extracts at least two conversations.

[0140] Specifically, each of the at least two sessions is used to describe the behavior characteristics and time characteristics of the normal operation of the target account within a preset time period, and the time characteristics in each session are used to reflect the temporal correlation of the behavior characteristics in each session. Optionally, the behavior characteristics include one or more of an Internet Protocol (IP) address, a media access control mac address, an account ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval, etc.

[0141] For example, see Figure 8 , Figure 8 This is a structural diagram of a possible session 80 provided in an embodiment of the present application. Session 80 includes 3 rows of data horizontally, namely a1, a2, and a3, and 12 columns vertically, namely b1-b12. Among them, a1, a3, and a3 can be arranged in chronological order from far to near, and one or more columns of data are used to indicate a behavioral feature or a time feature of the target account. For example, columns b1 and b2 are used to indicate the request method of the request (request) issued when operating the target account. The request method can be based on the "account password" request method and the "delegated request" request method and some other request methods. Among them, b1 is 0 and b2 is 1, which can indicate a request method based on the "account password". It can be understood that Figure 8 The behavior features and time features in the session 80 shown are only examples. In a specific implementation, the session 80 may not include some of the features shown in the session 80, or may include features not shown in the session 80. Figure 8Other features shown in .

[0142] Optionally, the at least two conversations may be extracted from a plurality of pieces of operation behavior data, each piece of the plurality of operation behavior data being used to describe behavior characteristics and time characteristics of normal operation of the target account.

[0143] For example, see Fig. 9 , Fig. 9 It is a structural diagram of an operation behavior data provided by an embodiment of the present application, including operation behavior data 901, operation behavior data 902, operation behavior data 903, operation behavior data 904 and operation behavior data 905, etc. The multiple operation data include request time, request method, request result, IP address, account ID, request URL, interval, request location, wherein the request time can be data in timestamp format (of course, it can also be in other formats); the request method can be the "account password" request method and the "delegated request" request method and some other request methods; the request result is "success" to indicate that the request is successful, of course, there are other request results (such as "failure" to indicate request failure, etc.), which will not be repeated here. The IP address is the source address of the request, the account ID is the identity identifier of the request, the request uniform resource locator (URL) is used to indicate the resource address corresponding to the request, the interval is used to indicate the time interval between the request and the last request made by the account, and the request location is used to indicate the actual address of the request. It can be seen that operation behavior data 901, operation behavior data 903, and operation behavior data 905 are obtained by the account with operation account ID "0002"; correspondingly, operation behavior data 902 and operation behavior data 903 are obtained by the account with operation account ID "0002".

[0144] The first node may process the plurality of operation behavior data to extract at least two sessions. For example, the first node divides the plurality of operation behavior data according to a preset granularity to obtain a target data set. Optionally, the preset division strength may include one or more of an IP address, a MAC address, an account ID, or a request location, etc. For example, see Fig. 9, multiple operation behavior data are divided according to IP addresses, and data set 901 (including operation behavior data of sequence numbers 1 and 3), data set 907 (including operation behavior data of sequence numbers 2 and 4), and data set 908 (including operation behavior data of sequence number 5) can be obtained. For another example, multiple operation behavior data are divided according to account ID, and data set 909 (including operation behavior data of sequence numbers 1, 3 and 5) and data set 910 (including operation behavior data of sequence numbers 2 and 4) can be obtained. Further, the first node divides the data according to the preset time length according to the temporal relationship of the data in the target data set to obtain the first session. For example, the first node divides the data according to the temporal relationship of the data in the data set 909 according to the time window of 15 minutes, and regards the data within the time length of 15 minutes as a session. Optionally, the number of rows of the at least two sessions can be the same, for example, the number of rows of at least two sessions is n. For operation behavior data less than n, the remaining rows of the extracted session can be padded with 0.

[0145] It can be seen that, in a possible implementation scheme, extracting at least two conversations may include at least the following steps: obtaining multiple pieces of operation behavior data; dividing the multiple pieces of operation behavior data according to a preset division granularity to obtain a target data set; dividing the data according to a preset time length based on the temporal relationship of the data in the target data set to obtain the at least two conversations.

[0146] It is understandable that, for the convenience of description in this application, the operation behavior data is represented in a form that is easy to understand. In actual processing, the operation behavior data may be characters obtained after encoding, such as Figure 8Each line of the session structure shown is obtained as one piece of operation behavior data. Optionally, the encoding of the operation behavior is related to the category of the behavior feature. Specifically, there can be three categories of features, namely, classification features (no size and no sequence, such as request method, IP address, request URL, etc.), numerical features (with size, such as time interval), and sequence features (no size but with order). Among them, numerical features do not need to be re-encoded; sequence features can use a variable to customize the size; classification features need to be represented by multiple variables, such as using one-hot encoding. For example, in session 80, column b3 is used to indicate the request result of the request (request) issued when operating the target account, where b3 column 0 can indicate that the request result is "failed", and b3 column 1 can indicate that the request result is "successful". For example, the three columns b10, b11, and b12 are used to indicate the requested location, among which "b10 column is 0, b11 column is 2, and b12 column is 1" can indicate that the requested location is Wuhan, Hubei, and "b10 column is 0, b11 column is 1, and b12 column is 1" can indicate that the requested location is Shenzhen, Guangdong.

[0147] Optionally, the multiple pieces of operation behavior data can be obtained by processing multiple samples, and the samples can be selected from IAM. Further optionally, the model training server selects multiple samples from the log of the unified identity authentication service IAM, and the multiple samples include data when the target account is normally operated in multiple time periods on multiple dates. The model training server filters the samples whose IP addresses belong to the whitelist login IP from the multiple samples. The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

[0148] Optionally, when acquiring multiple operation behavior data, you can use batch reading instead of reading a large amount of data at one time. Before reading the next batch of data, you can release the processed data to avoid the risk of downtime caused by memory overflow.

[0149] It can be understood that the target account can be one account or multiple accounts.

[0150] Step S702: The model training server trains the AE model according to the at least two conversations to obtain a target AE model.

[0151] Specifically, the AE model is an unsupervised neural network model that can learn the implicit features of the input data, which is called encoding. At the same time, the learned new features can be used to reconstruct the original input data, which is called decoding. The update of the encoder needs to measure the information lost due to encoding and decoding through the loss function, so as to update the model. Fig.10 , Fig.10 1 is a schematic diagram of a possible AE model provided in an embodiment of the present application, including a coding layer 905, an intermediate quantity 1002 and a decoding layer 1003. The at least two sessions can be first input into the coding layer 1001 and encoded to obtain the intermediate quantity 1002. Each session includes n lines of data (see Fig.10 r1-rn is n rows of data for a session), each session is input into n encoding subunits one by one (see Fig.10 C1-Cn are n coding subunits) to obtain the coding intermediate quantity 1002. The coding intermediate quantity is transferred (or copied) to the decoding layer 1003, corresponding to the n decoding subunits of the decoding layer (see Fig.10 D1-Dn are n decoding subunits), and at least two reconstruction sessions are obtained. Each of the at least two reconstruction sessions includes n lines of data (see Fig.10 Where d1-dn are n rows of data of a reconstructed session). According to the at least two sessions and the at least two reconstructed sessions, the direction of gradient descent can be obtained through the loss function, so as to update the AE model through the gradient descent algorithm, so that the difference between the reconstructed session and the original input session is as small as possible.

[0152] Optionally, the encoder and decoder are usually parameterized equations, usually composed of neural networks, for example, they can be one or more of recurrent neural networks (RNNs) such as Long Short Term Memory Network (LSTM) and Gated Recurrent Unit (GRU). Further optionally, the encoder and decoder can be regarded as consisting of two cascaded networks (encoding network and decoding network), and the encoding network is responsible for receiving the input r and transforming the input into an intermediate quantity y through a function h, which can satisfy the following formula:

[0153] y=h(r)

[0154] The decoding network is responsible for taking the intermediate quantity y as its input and obtaining the reconstructed session d through the function f, which can satisfy the following formula:

[0155] d=f(y)=f(h(r))

[0156] The error e is defined as the difference between the original input r and the reconstructed session d, that is, e satisfies the following formula:

[0157] e=r–d

[0158] The goal of training the AE model is to reduce the mean-square error (MSE), that is, to make the error e as small as possible. In this way, since at least two sessions are confirmed to be normal operation data, the target AE model trained with the at least two sessions, for the sessions corresponding to normal operations, the output reconstructed sessions will not deviate too much from the original input sessions, so that the inherent similarities and commonalities between normal account behaviors can be effectively captured. At the same time, since the sessions obtained by abnormal operations are abnormal, after being input into the encoder, the final reconstructed sessions will deviate more from the original input sessions, so they can be detected by the model.

[0159] Optionally, the model training server may establish an input matrix (or referred to as an input layer matrix) based on at least two sessions, where the input matrix includes the at least two reconstruction sessions. For example, the at least two sessions may be N sessions, represented as R1-R N , and the input matrix Q can satisfy the following formula:

[0160] Q=[R1,R2,…,R N ]

[0161] The input matrix Q can be input into the AE model, and the AE model encodes and decodes the N sessions to obtain an output matrix, which includes at least two reconstructed sessions.

[0162] Optionally, the target autoencoder model is used to detect whether an operation of completing the first session is a normal operation according to the first session.

[0163] Optional, Figure 7 The illustrated embodiment also includes part or all of steps S703 to S706, and the steps S703 to S706 are specifically as follows:

[0164] Step S703: The model training server inputs the at least two conversations into the target AE model to obtain at least two reconstruction errors.

[0165] Specifically, for the target AE model obtained after training, at least two conversations can be input into the target AE model to obtain at least two reconstruction conversations; at least two reconstruction errors can be determined based on the at least two conversations and the at least two reconstruction conversations.

[0166] Step S704: The model training server determines a first threshold value based on at least two reconstruction errors.

[0167] Specifically, the first threshold is used to measure whether the operation of completing the first session is a normal operation. For example, the first threshold determined based on the at least two reconstruction errors is 215.0, and the operation corresponding to the session greater than (or greater than or equal to) the first threshold is abnormal. In this case, if the first session (the first session is the session to be detected) is input into the target AE model, and the reconstruction error obtained is 216.5, then the operation of completing the first session is an abnormal operation.

[0168] Step S705: The model training server extracts multiple conversations.

[0169] Specifically, a portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of normal operation of the first target account within a preset time period, and another portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of abnormal operation of the second target account within the preset time period. It can be understood that the first target account can be one account or multiple accounts.

[0170] Optionally, the operation of extracting multiple conversations may refer to the related operation of extracting at least two conversations in step S701, which will not be described in detail here.

[0171] Optionally, the session used to describe the behavior characteristics and time characteristics of normal operation of the first target account within the preset time period may be extracted from a white sample, and the white sample may be a log or operation behavior data confirming normal operation, etc. Correspondingly, the session used to describe the behavior characteristics and time characteristics of abnormal operation of the second target account within the preset time period may be extracted from a black sample, and the black sample may be a log or operation behavior data confirming abnormal operation, etc.

[0172] Step S706: The model training server verifies the target AE model based on multiple sessions.

[0173] Specifically, if the number or proportion of sessions corresponding to abnormal operations detected by the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed. For example, among the multiple sessions in step S705, there are 2 sessions corresponding to normal operations and 8 sessions corresponding to abnormal operations. The second threshold can be 7, that is, if the number of sessions corresponding to the detected abnormal operations is 7, it indicates that the training is completed. Correspondingly, the second threshold can also be a proportion. For example, if the proportion of sessions corresponding to abnormal operations detected by the target AE model is greater than or equal to 80%, it indicates that the training of the target AE model is completed.

[0174] Optionally, if the number or proportion of sessions corresponding to abnormal operations detected by the target AE model is less than or equal to a second threshold, the target AE model may be trained again until the desired effect is achieved.

[0175] Optionally, the model training server may send the target AE model to the business node, or deploy the target AE model in the business node through a manager, so that the business node can detect whether the operation of completing the first session is a normal operation based on the first session.

[0176] Optionally, the target AE model can also be called a session autoencoder.

[0177] exist Figure 7 In the described method, at least two sessions are extracted from the normal operation behavior data, and the autoencoder is trained with the at least two sessions to obtain a target autoencoder model. Since the at least two sessions are data confirmed to be normal operations, the target AE model obtained by training the at least two sessions, for the sessions corresponding to normal operations, the output reconstructed sessions will not deviate too much from the original input sessions, thereby being able to effectively capture the inherent similarities and commonalities between normal account behaviors. At the same time, since the sessions obtained by abnormal operations are abnormal, after being input into the encoder, the final reconstructed sessions will deviate more from the original input sessions, and thus can be detected by the model.

[0178] On the one hand, since the autoencoder is trained in an unsupervised manner, there is no need to build feature engineering or rule sets, which avoids experience-based anomaly detection, reduces the large amount of research input by researchers, and improves the efficiency of anomaly detection. On the other hand, each session contains the behavioral characteristics and time characteristics of the operation behavior, and the session reflects the correlation of behavioral characteristics in time sequence. Therefore, the trained autoencoder model can form a behavior sequence in chronological order for anomaly detection during detection, rather than detecting a single behavior. This helps to detect temporal abnormal behavior characteristics other than key features, and improves the accuracy of anomaly detection.

[0179] See also Fig.11 , Fig.11 This is an anomaly detection method provided by an embodiment of the present application, which includes but is not limited to the following steps:

[0180] Step S1101: The service node extracts the first session.

[0181] Specifically, the first session is used to describe the behavior characteristics and time characteristics when operating the first account within a preset time length, and the time characteristics are used to reflect the correlation of the behavior characteristics in time sequence. Optionally, the behavior characteristics include one or more of IP address, media access control mac address, account identification ID, request category, request result, request path, request location, request content, request failure reason or request time interval, etc.

[0182] Optionally, the at least two conversations may be extracted from a plurality of pieces of operation behavior data, each piece of the plurality of operation behavior data being used to describe a behavior characteristic and a time characteristic of a normal operation of the first account.

[0183] The first node may process the multiple pieces of operation behavior data to extract the first session. For example, the first node divides the multiple pieces of operation behavior data according to a preset granularity to obtain a first data set. Optionally, the preset division strength may include one or more of an IP address, a mac address, an account ID, or a request location, etc. Further, the first node divides the data according to a preset time length based on the temporal relationship of the data in the first data set to obtain the first session. For example, the first node divides the data set according to a time window of 15 minutes, and takes the data within the time length of 15 minutes as the first session. Optionally, the number of rows of the first session may be pre-configured or pre-defined. For example, the number of rows of the first session is configured as n. For operation behavior data that is less than n pieces, the remaining rows of the extracted session may be padded with 0.

[0184] It can be seen that, in a possible implementation, extracting the first session may at least include the following steps: the service node obtains multiple pieces of operation behavior data, each of which is used to describe the behavior characteristics and time characteristics of operating an account. The service node divides the multiple pieces of operation behavior data according to a preset division granularity to obtain a first data set, which includes at least one piece of operation behavior data. The service node divides the data in the first data set according to a preset time length based on the temporal relationship of the data, to obtain the first session.

[0185] Optionally, the multiple pieces of operation behavior data may be selected from IAM. Further optionally, the business node selects multiple samples from the log of the unified identity authentication service IAM, and the multiple samples include data when the first account is operated in multiple time periods on multiple dates. The business node filters the samples whose IP addresses belong to the whitelist login IP from the multiple samples. The filtered multiple samples are grouped, re-encoded and string matched to obtain multiple pieces of operation behavior data.

[0186] It is understandable that the first account may be one account or multiple accounts.

[0187] Step S1102: The service node inputs the first session into the target AE model to obtain a detection result.

[0188] Specifically, the detection result is used to indicate whether the operation of completing the first session is a normal operation. The target AE model is obtained by inputting data of at least two sessions into the AE model training, and each of the at least two sessions is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length.

[0189] Optionally, the target AE model may come from a model training server. For example, the model training server sends the target AE model to the service node, and correspondingly, the service node receives the target AE model from the model training server. Further, the target AE model may be based on Figure 7 The model training method shown is trained.

[0190] Optionally, the business node inputs the first session into the target AE model to obtain a detection result, which can be specifically: the business node inputs the first session into the target AE model to obtain a first reconstructed session. The business node determines a first reconstruction error based on the first session and the first reconstructed session. If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model. Correspondingly, if the first reconstruction error is less than, equal to or less than the first threshold, the detection result is used to indicate that the operation of completing the first session is a normal operation.

[0191] Optionally, the target AE model can also be called a session autoencoder.

[0192] exist Fig.11 In the described method, an autoencoder is used to detect the first session corresponding to the operation behavior. On the one hand, since the autoencoder is unsupervised training, there is no need to build feature engineering or rule sets, which avoids experience-based anomaly detection, reduces a large amount of research input by researchers, and improves the efficiency of anomaly detection. On the other hand, the first session contains the behavioral characteristics and time characteristics of the operation behavior, and the session reflects the correlation of the behavioral characteristics in time sequence. Therefore, the trained autoencoder model can form a behavior sequence in time sequence for anomaly detection during detection, rather than detecting a single behavior, which is helpful for detecting time-series abnormal behavior characteristics other than key features, and improves the accuracy of anomaly detection.

[0193] above Figure 7 as well as Fig.11 The method embodiment shown includes many possible implementation schemes, which are respectively combined with Fig.12 Some of the implementation schemes are illustrated with examples. It should be noted that: Fig.12For related concepts, operations or logical relationships that are not explained, please refer to Figure 7 as well as Fig.11 The corresponding description in the illustrated embodiment is therefore not repeated again.

[0194] See also Fig.12 , Fig.12 This is an anomaly detection method provided by an embodiment of the present application, which includes but is not limited to the following steps:

[0195] Step S1201: The model training server collects multiple samples.

[0196] Specifically, the samples include white samples that are confirmed to be operating normally and black samples that are confirmed to be operating abnormally. The samples can be obtained from IAM. Optionally, the white samples can be selected from the logs that have been verified to be operating normally in a step-by-step manner every other day (i.e., selecting data from different dates and time periods), and the black samples can select as many types of abnormal behaviors as possible.

[0197] Step S1202: The model training server extracts multiple sessions.

[0198] Specifically, each session in the plurality of sessions is used to describe the behavior characteristics and time characteristics of the normal operation of the target account within a preset time period, and the time characteristics in each session are used to reflect the temporal correlation of the behavior characteristics in each session. Optionally, the behavior characteristics include one or more of an IP address, a media access control mac address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval, etc.

[0199] Optionally, the model training server can use the yield generator to read the data. The yield generator reads sample data in the form of data streams, performs basic operations such as data cleaning and feature extraction one by one, and has great advantages in processing multi-field data, which can improve processing efficiency and reduce memory consumption.

[0200] Optionally, the model training server extracting multiple sessions may include some or all of steps S1202a to S1202c, and steps S1202a to S1202c are specifically as follows:

[0201] Step S1202a: The model training server filters samples belonging to the whitelist login IP.

[0202] Specifically, among the multiple samples collected, if the request IP of sample A belongs to the whitelist login IP, then the sample A is not used as data for training the AE model, that is, the sample A is filtered out.

[0203] Step S1202b: The model training server parses the sample and extracts features.

[0204] Specifically, the model training server performs grouping, recoding, and regularization analysis on each field of the sample to obtain the behavioral features of the data and obtain the operation behavior data. The behavioral features of the data include one or more of the IP address, media access control mac address, account ID, request category, request result, request path, request location, request content, request failure reason, or request time interval. Optionally, each operation behavior data r can form a one-dimensional vector containing q features, which are The operation behavior data r (i) Satisfies the following formula:

[0205]

[0206] Step S1202c: The model training server divides the session into multiple sessions according to a preset time length.

[0207] Specifically, the operation behavior data are sorted in chronological order from earliest to latest, and divided according to a preset time length to obtain multiple sessions. Each session contains n data within the same time length. The n data can form a two-dimensional matrix, that is, the session R (j) Satisfies the following formula:

[0208] R (j) =(r (1) , (2) ,…, (i) ),i=1,2,…,n

[0209] Optionally, before dividing to obtain multiple sessions, the multiple operation behavior data may be divided into multiple data sets according to a preset division granularity, and multiple sessions may be divided from the multiple data sets.

[0210] Further optionally, the division granularity may be determined when multiple sessions are divided. For example, multiple operation behavior data may be divided into multiple sessions with the login IP as the division granularity and 15 minutes as the time length.

[0211] Optionally, if the number of operation behavior data items included in the session is different, the value n with the most operation behavior data in the session is selected as the number of columns, or the number of columns n may be pre-configured or pre-defined, and the items less than n are padded with 0.

[0212] Step S1203: The model training server builds a training set session.

[0213] Specifically, the model training server may use at least two sessions corresponding to normal operation behaviors in multiple sessions as training set sessions according to a preset ratio. For example, the model training server randomly divides all sessions corresponding to normal operation behaviors according to a training set: validation set ratio of 8:2, that is, if the number of extracted sessions is 110, of which 100 sessions are extracted from white samples and 10 sessions are extracted from black samples, then the number of training set sessions is 80, and the 80 sessions are all extracted from white samples.

[0214] It can be seen that the constructed training set sessions are all composed of sessions corresponding to normal operations, which are used for training the AE model.

[0215] Step S1204: The model training server builds a validation set session.

[0216] Specifically, the other part of the sessions corresponding to normal operation behaviors and the sessions corresponding to abnormal operation behaviors divided in step S1203 are used for the verification of the final model. For example, if the number of extracted sessions is 110, of which 100 sessions are extracted from white samples and 10 sessions are extracted from black samples, then the number of validation set sessions is 30, of which 20 sessions are extracted from white samples and 10 are extracted from black samples.

[0217] Step S1205: The model training server establishes an input matrix.

[0218] Specifically, the model training server establishes an input matrix based on the training set session, which can also be called a deep learning neural network input matrix. Optionally, the input matrix Q1 can satisfy the following formula:

[0219] Q1=(R (1) ,R (2) ,…,R (j) ),j=1,2,…,N1

[0220] Among them, R (j) is the session, and N1 is the number of sessions in the training set.

[0221] Correspondingly, the model training server can also establish an input matrix based on the validation set session, and the input matrix Q2 can satisfy the following formula:

[0222] Q2=(R (1) ,R (2) ,…,R (j) ),j=1,2,…,N2

[0223] Among them, R (j) is the session, and N2 is the number of sessions in the validation set.

[0224] Step S1205: The model training server encodes the input matrix and outputs the intermediate quantity.

[0225] Specifically, the model training server constructs an encoding layer (Encoder) of the autoencoder, inputs each session in the input matrix into the encoding unit for encoding, and obtains an intermediate quantity, which is also called an encoding vector, or an intermediate vector, etc. Optionally, each operation behavior data in the session can be sequentially passed into n encoding units in order from far to near, and the encoding unit can be one or more of a recurrent neural network (RNN) such as a long short-term memory neural network (LSTM) and a gated recurrent unit (GRU).

[0226] Step S1206: The model training server encodes the input matrix and outputs the intermediate quantity.

[0227] Specifically, the model training server constructs an encoding layer (Encoder) of the autoencoder, inputs each session in the input matrix into the encoding unit for encoding, and obtains an intermediate quantity, which is also called an encoding vector, or an intermediate vector, etc. Optionally, each operation behavior data in the session can be sequentially passed into n encoding units in order from far to near, and the encoding unit can be one or more of a recurrent neural network (RNN) such as a long short-term memory neural network (LSTM) and a gated recurrent unit (GRU).

[0228] Step S1207: The model training server decodes the intermediate quantity to obtain an output matrix.

[0229] Specifically, the model training server passes the intermediate quantity to the decoding unit for decoding to obtain an output matrix. The output matrix includes the reconstructed training set session. The decoding unit can be one or more of a recurrent neural network (RNN) such as a long short-term memory neural network (LSTM) and a gated recurrent unit (GRU).

[0230] Specifically, the model training server decodes the intermediate quantity to obtain an output matrix, which may include part or all of steps S1207a to S1207c. Steps S1207a to S1207c are as follows:

[0231] Step S1207a: The model training server inputs the intermediate quantity into the decoding unit.

[0232] Optionally, for an input session, n pieces of operation behavior data in the session are input into n encoding units to obtain n intermediate quantities, so the model training server inputs the n intermediate quantities into n decoding units in sequence. For N sessions, the input is repeated N times.

[0233] Step S1207b: The model training server constructs a decoding unit and outputs a decoding vector.

[0234] Specifically, n intermediate quantities are sequentially transmitted to the decoding unit, and after calculation by the decoding unit, a decoding vector D is output, and the decoding vector D satisfies the following formula:

[0235] D (j) =(d (1) ,d (2) ,…,d (k) ),k=1,2,…,n

[0236] Step S1207b: The model training server restores the decoding vector matrix according to the time-series layered full connection to obtain the output layer matrix.

[0237] Specifically, according to the time-series hierarchical full connection technology, the output matrix Q1′ obtained satisfies the following formula:

[0238] Q1′=(D (1) ,D (2) ,…,D (l) ),l=1,2,…,N1

[0239] Step S1208: The model training server trains the AE model through a gradient descent algorithm to obtain a target AE model.

[0240] Specifically, according to the difference between the training set session in the input matrix and the reconstructed training set session in the output matrix, the direction of gradient descent is obtained through the loss function, and then the AE model is updated through the gradient descent algorithm to obtain the target AE model.

[0241] Optionally, you can use the adam optimizer for optimization during training, and you can also use MSE as the loss function.

[0242] Step S1209: The model training server inputs the training set session into the target AE model to obtain multiple reconstruction errors.

[0243] Specifically, for the target AE model obtained after training, the training set session can be input into the target AE model to obtain multiple reconstruction sessions; based on the training set session and the multiple reconstruction sessions, multiple reconstruction errors can be determined.

[0244] Step S1210: The model training server determines a first threshold according to the distribution of multiple reconstruction errors.

[0245] Specifically, the first threshold is used to measure whether the operation of completing the first session is a normal operation. For example, according to the distribution of the multiple reconstruction errors, the first threshold is determined to be 215.0, and the operation corresponding to the session greater than (or greater than or equal to) the first threshold is abnormal. In this case, if the first session (the first session is the session to be detected) is input into the target AE model, and the reconstruction error obtained is 216.5, then the operation of completing the first session is an abnormal operation.

[0246] Step S1211: The model training server inputs the verification set session into the target AE model to obtain the verification result.

[0247] Specifically, the verification set session is constructed with an input matrix Q2, and the verification set session can be input into the target AE through the input matrix Q2 to obtain a verification result. The verification result can be specifically indicated by whether the number or proportion of sessions corresponding to the detected abnormal operations reaches a second threshold.

[0248] Step S1212: The model training server confirms whether the number or proportion of sessions corresponding to the detected abnormal operations reaches a second threshold.

[0249] Specifically, if the number or proportion of sessions corresponding to abnormal operations detected by the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed. For example, if it is verified that there are 20 sessions corresponding to normal operations and 10 sessions corresponding to abnormal operations, the second threshold can be 18, that is, if the number of sessions corresponding to the detected abnormal operations is 18, it indicates that the verification is successful and the training is completed. Correspondingly, the second threshold can also be a proportion. If the proportion of sessions corresponding to abnormal operations detected by the target AE model is greater than or equal to 80%, it indicates that the target AE model is successfully verified and the training is completed.

[0250] Optionally, if the number or proportion of sessions corresponding to abnormal operations detected by the target AE model is less than or equal to a second threshold, the target AE model may be trained again until the desired effect is achieved.

[0251] Optionally, if the target AE model training is completed, it can be deployed in the business node. Optionally, the model training server sends the target AE model to the business node, and correspondingly, the business node receives the target AE model from the model training server.

[0252] Step S1213: The service node collects data to be detected.

[0253] Specifically, the business node can collect the data to be detected regularly or irregularly, such as logs, operation behaviors, etc. Taking the business node as IAM as an example, IAM can read the IAM logs of the previous two hours from the data bucket every hour.

[0254] Step S1214: The service node extracts the first session.

[0255] Specifically, each session in the first session is used to describe the behavior characteristics and time characteristics of the normal operation of the first account within a preset time period, and the time characteristics in each session are used to reflect the temporal correlation of the behavior characteristics in each session. Optionally, the behavior characteristics include one or more of an IP address, a media access control mac address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval, etc.

[0256] Optionally, the first session can use a yield generator to read the data. The yield generator reads sample data in a data stream manner, performs basic operations such as data cleaning and feature extraction one by one, and has great advantages in processing multi-field data, which can improve processing efficiency and reduce memory consumption.

[0257] Optionally, extracting the first session from the first session may include part or all of steps S1214a to S1214c, and steps S1214a to S1214c are specifically as follows:

[0258] Step S1214a: The business node filters samples belonging to the whitelist login IP.

[0259] Specifically, among the multiple collected data to be detected, if the request IP of the data to be detected A belongs to the whitelist login IP, the data to be detected A is not used as data to be detected, that is, the data to be detected A is filtered out.

[0260] Step S1214b: The business node parses the sample and extracts features.

[0261] Specifically, the business node groups, recodes, and regularizes each field of the data to be detected, obtains the behavior characteristics of the data, and obtains the operation behavior data. The behavior characteristics of the data include one or more of the IP address, media access control mac address, account ID, request category, request result, request path, request location, request content, request failure reason, or request time interval. Optionally, each operation behavior data r can form a one-dimensional vector containing q features, which are The operation behavior data r (i) Satisfies the following formula:

[0262]

[0263] Step S1214c: The service node divides the session according to a preset time length to obtain a first session.

[0264] Specifically, the service node sorts the operation behavior data from the earliest to the latest in chronological order, and divides them according to the preset time length to obtain multiple sessions. Each session contains n data within the same time length. The n data can form a two-dimensional matrix, that is, the first session R (j) Satisfies the following formula:

[0265] R (j) =(r (1) ,r (2) ,…,r (i) ),i=1,2,…,n

[0266] Optionally, before the first session is obtained by dividing, the plurality of operation behavior data may be divided into a plurality of data sets according to a preset division granularity, and the first session may be obtained from the plurality of data sets.

[0267] Further optionally, the division granularity may be determined when the first session is divided. For example, the first session may be obtained by dividing the plurality of operation behavior data with the login IP as the division granularity and 15 minutes as the time length.

[0268] Optionally, if the number of operation behavior data items included in the session is different, the value n with the most operation behavior data in the session is selected as the number of columns, or the number of columns n may be pre-configured or pre-defined, and the items less than n are padded with 0.

[0269] Step S1215: The service node establishes an input matrix.

[0270] Specifically, the service node establishes an input matrix according to the first session, and the input matrix may also be called a deep learning neural network input matrix. Optionally, the input matrix Q3 may satisfy the following formula:

[0271] Q3=(R (1) ,R (2) ,…,R (j) ),j=1,2,…,N3

[0272] Among them, R (j) is a session, and N3 is the number of sessions included in the first session.

[0273] Step S1216: The business node loads the target AE model.

[0274] Specifically, the business node loads the target AE model obtained in step S1208.

[0275] Step S1217: The service node inputs the first session into the target AE model to obtain a first reconstruction error.

[0276] Specifically, the service node inputs the first session into the target AE model to obtain a first reconstruction session. The service node determines a first reconstruction error according to the first session and the first reconstruction session.

[0277] Step S1218: If the reconstruction error exceeds the first threshold, the service node feeds back to the alarm platform.

[0278] Specifically, if the first reconstruction error is greater than or equal to the first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation. Therefore, the service node can feedback to the alarm platform that there is abnormal operation behavior.

[0279] Optionally, if the first reconstruction error exceeds a first threshold, the target AE model determines that there is abnormal operation behavior, which can be automatically synchronized to the account security alarm platform.

[0280] Optionally, experts can conduct an in-depth investigation. If abnormal behavior is confirmed, risk control will be carried out and the loop will be closed in a timely manner. This black sample can be added to the validation set for subsequent improvement of the model.

[0281] exist Fig.11 In the embodiment shown, by training the AE model, different types of logs can be analyzed for abnormal behaviors without distinction. Compared with traditional machine learning algorithms, it has a wider application range and can detect and analyze abnormal behaviors without expert experience, greatly reducing the training burden and labor costs. In addition, the detection of login IP adopts a session mechanism, and the operation behavior data within a period of time belongs to the same session. In each session, the basic features are extracted one by one, the time series features are retained, and are input into the algorithm as the feature matrix of the session. The behavior sequence is formed in chronological order for anomaly detection, rather than just detecting a single behavior, which helps to effectively detect sequential abnormal behaviors other than key behaviors.

[0282] In addition, when reading in data, the traditional method is to read all the data into the memory for preprocessing, vectorization and other operations. For reading in millions of data, this will consume a lot of memory space. In the embodiment of the present application, the generator mechanism is used to read in the data, which reduces the reading of a large amount of invalid information and greatly saves memory. In addition, the generator mechanism can also perform similar streaming processing while reading in, and the occupied memory is released immediately after processing, thereby saving memory and relieving a large degree of pressure.

[0283] The method of the embodiment of the present application is described in detail above, and the device of the embodiment of the present application is provided below.

[0284] See also Fig.13 , Fig.13 1 is a schematic diagram of the structure of an abnormality detection device 130 provided in an embodiment of the present application. The device 130 may be a service node or a device of a service node, such as a chip or an integrated circuit. The device 130 may include an extraction unit 1301 and a detection unit 1302. The description of each unit is as follows:

[0285] An extraction unit 1301 is used to extract a first session, wherein the first session is used to describe a behavior feature and a time feature when operating a first account within a preset time length, and the time feature is used to reflect the correlation of the behavior feature in time sequence;

[0286] The detection unit 1302 is used to input the first conversation into the target autoencoder AE model to obtain a detection result; wherein the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length.

[0287] In a possible implementation manner, the detection unit 1302 is specifically configured to:

[0288] Inputting the first session into the target AE model to obtain a first reconstruction session;

[0289] determining a first reconstruction error based on the first session and the first reconstruction session;

[0290] If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model.

[0291] In a possible implementation, the extraction unit 1301 is specifically configured to:

[0292] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of operating an account;

[0293] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a first data set; the first data set includes at least one piece of operation behavior data;

[0294] The first conversation is obtained by dividing the data in the first data set according to a time sequence relationship and a preset time length.

[0295] In a possible implementation manner, the preset time length is 15 minutes; the extraction unit 1302 is specifically configured to:

[0296] According to the time series relationship of the data in the first data set, the first session is obtained by dividing the data into 15 minutes; the first session includes n pieces of operation behavior data within 15 minutes; each of the n pieces of data includes q features, and the q features are used to indicate the behavior features and the time features.

[0297] In one possible implementation, the behavioral characteristics include at least one of an Internet Protocol IP address, a Media Access Control MAC address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a MAC address, an account ID, or an operation location.

[0298] It should be noted that the implementation of each unit can also refer to Fig.11 or Fig.12 The anomaly detection device 130 may be Fig.11 or Fig.12 The service node in the method embodiment is shown.

[0299] exist Fig.13In the described anomaly detection device 130, an auto encoder is used to detect the first session corresponding to the operation behavior. On the one hand, since the auto encoder is unsupervised training, there is no need to build feature engineering or rule sets, which avoids experience-based anomaly detection, reduces a large amount of research input by researchers, and improves the efficiency of anomaly detection. On the other hand, the first session contains the behavioral characteristics and time characteristics of the operation behavior, and the session reflects the correlation of the behavioral characteristics in time sequence. Therefore, the trained autoencoder model can form a behavior sequence in time sequence for anomaly detection during detection, rather than detecting a single behavior, which helps to detect time-series abnormal behavior characteristics other than key features, and improves the accuracy of anomaly detection.

[0300] In each embodiment of the present application, the division of units is only a logical division based on functions, and is not intended to limit the specific structure of the device. In a specific implementation, some functional modules may be subdivided into more small functional modules, and some functional modules may be combined into one functional module, but regardless of whether these functional modules are subdivided or combined, the general process performed by the device 130 during video encoding is the same. Usually, each unit corresponds to its own program code (or program instruction), and when the program codes corresponding to each of these units are run on the processor, the unit executes the corresponding process to achieve the corresponding function.

[0301] See also Fig.14 , Fig.14 1 is a schematic diagram of the structure of a model training device 140 provided in an embodiment of the present application. The device 140 may be a model training server, or a device in the model training server, such as a chip or an integrated circuit. The device 140 may include an extraction unit 1401 and a detection unit 1402. The description of each unit is as follows:

[0302] The extraction unit 1401 is used to extract at least two conversations, wherein each conversation is used to describe the behavior characteristics and time characteristics of normal operation of the target account within a preset time period, and the time characteristics in each conversation are used to reflect the correlation of the behavior characteristics in each conversation in time sequence;

[0303] The training unit 1402 is used to train the AE model according to the at least two conversations to obtain a target AE model, wherein the target autoencoder model is used to detect whether an operation of completing the first conversation is a normal operation according to the first conversation.

[0304] In a possible implementation manner, the training unit 1402 is further configured to input the at least two conversations into the target AE model to obtain at least two reconstruction errors;

[0305] The training unit 1402 is further configured to determine a first threshold value according to the at least two reconstruction errors; the first threshold value is used to measure whether the operation of completing the first session is a normal operation.

[0306] In a possible implementation manner, the training unit is further used for:

[0307] The first threshold is determined according to distribution of the at least two reconstruction errors.

[0308] In a possible implementation, the extracting unit 1401 is further configured to extract multiple sessions, where a portion of the multiple sessions is used to describe behavior characteristics and time characteristics when the first target account is normally operated within a preset time period, and another portion of the multiple sessions is used to describe behavior characteristics and time characteristics when the second target account is abnormally operated within the preset time period;

[0309] The device 140 also includes: a verification unit 1403, which is used to verify the target AE model according to the multiple sessions and the first threshold; if the number of sessions corresponding to the abnormal operations detected according to the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed.

[0310] In a possible implementation, the extraction unit 1401 is specifically configured to:

[0311] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of normal operation of the target account;

[0312] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a target data set;

[0313] The first session is obtained by dividing the data in the target data set according to a temporal relationship of the data and a preset time length.

[0314] In a possible implementation manner, the preset time length is 15 minutes; the extraction unit 1401 is specifically configured to:

[0315] According to the temporal relationship of the data in the target data set, at least two sessions are obtained by dividing the data into 15-minute time lengths; each of the at least two sessions includes at least one operation behavior data within 15 minutes; each of the at least one data includes q features, and the q features are used to indicate the behavior features and the time features; wherein q is greater than or equal to 1.

[0316] In a possible implementation, the extraction unit 1401 is specifically configured to:

[0317] A plurality of samples are selected from the log of the unified identity authentication service IAM; the plurality of samples include data of normal operation of the target account in a plurality of time periods on a plurality of dates;

[0318] From the plurality of samples, filtering samples whose Internet Protocol IP addresses belong to whitelist login IPs;

[0319] The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

[0320] In one possible implementation, the behavioral characteristics include at least one of an IP address, a media access control mac address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a mac address, an account ID, or an operation location.

[0321] In a possible implementation manner, the training unit 1402 is specifically configured to:

[0322] Inputting the at least two sessions into the AE model to obtain at least two reconstruction sessions;

[0323] According to the at least two sessions and the at least two reconstruction sessions, the AE model is updated by a gradient descent algorithm to obtain the target AE model.

[0324] In a possible implementation manner, the training unit 1402 is specifically configured to:

[0325] establishing an input matrix based on the at least two conversations;

[0326] Based on the AE model, the input matrix is ​​encoded and decoded to obtain an output matrix; the output matrix includes the at least two reconstruction sessions.

[0327] It should be noted that the implementation of each unit can also refer to Figure 7 or Fig.12 The anomaly detection device 140 may be Figure 7 or Fig.12 The model training server in the method embodiment shown.

[0328] exist Fig.14In the described device 140, at least two sessions are extracted from the normal operation behavior data, and the autoencoder is trained with the at least two sessions to obtain a target autoencoder model. Since the at least two sessions are data confirmed to be normal operations, the target AE model obtained by training the at least two sessions, for the sessions corresponding to normal operations, the output reconstructed sessions will not deviate too much from the original input sessions, thereby being able to effectively capture the inherent similarities and commonalities between normal account behaviors. At the same time, since the sessions obtained by abnormal operations are abnormal, after being input into the encoder, the final reconstructed sessions will deviate more from the original input sessions, and thus can be detected by the model.

[0329] On the one hand, since the autoencoder is trained in an unsupervised manner, there is no need to build feature engineering or rule sets, which avoids experience-based anomaly detection, reduces the large amount of research input by researchers, and improves the efficiency of anomaly detection. On the other hand, each session contains the behavioral characteristics and time characteristics of the operation behavior, and the session reflects the correlation of behavioral characteristics in time sequence. Therefore, the trained autoencoder model can form a behavior sequence in chronological order for anomaly detection during detection, rather than detecting a single behavior. This helps to detect temporal abnormal behavior characteristics other than key features, and improves the accuracy of anomaly detection.

[0330] See also Fig.15 , Fig.15 1 is a schematic diagram of the structure of a service node 150 provided in an embodiment of the present application. The service node 150 may include at least one memory 1501 and at least one processor 1502. Optionally, a bus 1503 may also be included. Further optionally, a communication interface 1504 may also be included, wherein the memory 1501, the processor 1502 and the communication interface 1504 are connected via the bus 1503.

[0331] The memory 1501 is used to provide a storage space, in which data such as an operating system and a computer program can be stored. The memory 1501 includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or a portable read-only memory (CD-ROM).

[0332] Processor 1502 is a module that performs arithmetic operations and / or logical operations, and can specifically be a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an artificial intelligence processor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), and other processing modules, or a combination of multiple of them.

[0333] The communication interface 1504 is used to receive data sent externally and / or send data to the outside, and may be a wired link interface such as an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, etc.) interface. Optionally, the communication interface 1504 may also include a transmitter (such as a radio frequency transmitter, an antenna, etc.) coupled to the interface, or a receiver, etc.

[0334] The processor 1502 in the service node 150 is used to read the computer program stored in the memory 1501 to execute the aforementioned anomaly detection method, for example Fig.11 , Fig.12 The anomaly detection method described.

[0335] For example, the processor 1502 in the service node 150 is used to read the computer program stored in the memory 1501 to perform the following operations:

[0336] Extracting a first session, wherein the first session is used to describe a behavior feature and a time feature when operating the first account within a preset time length, and the time feature is used to reflect the correlation of the behavior feature in time sequence;

[0337] The first conversation is input into the target autoencoder AE model to obtain a detection result; wherein, the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model for training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length.

[0338] In a possible implementation manner, the processor 1502 is specifically configured to:

[0339] Inputting the first session into the target AE model to obtain a first reconstruction session;

[0340] determining a first reconstruction error based on the first session and the first reconstruction session;

[0341] If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model.

[0342] In a possible implementation manner, the processor 1502 is specifically configured to:

[0343] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of operating an account;

[0344] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a first data set; the first data set includes at least one piece of operation behavior data;

[0345] The first conversation is obtained by dividing the data in the first data set according to a time sequence relationship and a preset time length.

[0346] In a possible implementation manner, the preset time length is 15 minutes; the processor 1502 is specifically configured to:

[0347] According to the time series relationship of the data in the first data set, the first session is obtained by dividing the data into 15 minutes; the first session includes n pieces of operation behavior data within 15 minutes; each of the n pieces of data includes q features, and the q features are used to indicate the behavior features and the time features.

[0348] In one possible implementation, the behavioral characteristics include at least one of an Internet Protocol IP address, a Media Access Control MAC address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a MAC address, an account ID, or an operation location.

[0349] It should be noted that the implementation of each module can also refer to Fig.11 or Fig.12 The service node 150 may be Fig.11 or Fig.12 The service node in the method embodiment is shown.

[0350] See also Fig.16, Fig.16 1 is a schematic diagram of the structure of a model training server 160 provided in an embodiment of the present application. The server 160 may include at least one memory 1601 and at least one processor 1602. Optionally, a bus 1603 may also be included. Further optionally, a communication interface 1604 may also be included, wherein the memory 1601, the processor 1602 and the communication interface 1604 are connected via the bus 1603.

[0351] The memory 1601 is used to provide a storage space, and the storage space can store data such as an operating system and a computer program, etc. The memory 1601 includes but is not limited to RAM, ROM, EPROM, or CD-ROM.

[0352] Processor 1602 is a module that performs arithmetic operations and / or logical operations, and may specifically be one or a combination of multiple processing modules such as a CPU, a GPU, an MPU, an artificial intelligence processor, an ASIC, an FPGA, and a CPLD.

[0353] The communication interface 1604 is used to receive data sent externally and / or send data to the outside, and may be a wired link interface such as an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, universal wireless interface, etc.) interface. Optionally, the communication interface 1604 may also include a transmitter (such as a radio frequency transmitter, an antenna, etc.) coupled to the interface, or a receiver, etc.

[0354] The processor 1602 in the server 160 is used to read the computer program stored in the memory 1601 to execute the aforementioned model training method, for example Fig.10 , Fig.12 The model training method described.

[0355] For example, the processor 1602 in the server 160 is used to read the computer program stored in the memory 1601 to perform the following operations:

[0356] Extract at least two sessions, where each session is used to describe the behavior characteristics and time characteristics of normal operation of the target account within a preset time period, and the time characteristics in each session are used to reflect the temporal correlation of the behavior characteristics in each session;

[0357] The AE model is trained according to the at least two conversations to obtain a target AE model, wherein the target autoencoder model is used to detect whether an operation of completing the first conversation is a normal operation according to the first conversation.

[0358] In a possible implementation, the processor 1602 is further configured to:

[0359] Inputting the at least two conversations into the target AE model to obtain at least two reconstruction errors;

[0360] A first threshold is determined according to the at least two reconstruction errors; the first threshold is used to measure whether an operation of completing the first session is a normal operation.

[0361] In a possible implementation, the processor 1602 is further configured to:

[0362] The first threshold is determined according to distribution of the at least two reconstruction errors.

[0363] In a possible implementation, the processor 1602 is further configured to:

[0364] Extracting multiple sessions, where a portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of normal operations on the first target account within a preset time period, and another portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of abnormal operations on the second target account within the preset time period;

[0365] The target AE model is verified according to the multiple sessions and the first threshold; if the number of sessions corresponding to the abnormal operations detected according to the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed.

[0366] In a possible implementation manner, the processor 1602 is specifically configured to:

[0367] Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of normal operation of the target account;

[0368] Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a target data set;

[0369] The first session is obtained by dividing the data in the target data set according to a temporal relationship of the data and a preset time length.

[0370] In a possible implementation manner, the preset time length is 15 minutes; the processor 1602 is specifically configured to:

[0371] According to the temporal relationship of the data in the target data set, at least two sessions are obtained by dividing the data into 15-minute time lengths; each of the at least two sessions includes at least one operation behavior data within 15 minutes; each of the at least one data includes q features, and the q features are used to indicate the behavior features and the time features; wherein q is greater than or equal to 1.

[0372] In a possible implementation manner, the processor 1602 is specifically configured to:

[0373] A plurality of samples are selected from the log of the unified identity authentication service IAM; the plurality of samples include data of normal operation of the target account in a plurality of time periods on a plurality of dates;

[0374] From the plurality of samples, filtering samples whose Internet Protocol IP addresses belong to whitelist login IPs;

[0375] The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

[0376] In one possible implementation, the behavioral characteristics include at least one of an IP address, a media access control mac address, an account identification ID, a request category, a request result, a request path, a request location, a request content, a request failure reason, or a request time interval; the preset division granularity includes at least one of an IP address, a mac address, an account ID, or an operation location.

[0377] In a possible implementation manner, the processor 1602 is specifically configured to:

[0378] Inputting the at least two sessions into the AE model to obtain at least two reconstruction sessions;

[0379] According to the at least two sessions and the at least two reconstruction sessions, the AE model is updated by a gradient descent algorithm to obtain the target AE model.

[0380] In a possible implementation manner, the processor 1602 is specifically configured to:

[0381] establishing an input matrix based on the at least two conversations;

[0382] Based on the AE model, the input matrix is ​​encoded and decoded to obtain an output matrix; the output matrix includes the at least two reconstruction sessions.

[0383] It should be noted that the implementation of each unit can also refer to Figure 7 or Fig.12 The anomaly detection device 160 may be Figure 7 or Fig.12 The model training server in the method embodiment shown.

[0384] The present application also provides a computer-readable storage medium, which stores computer instructions for implementing the above-mentioned anomaly detection method, such as Fig.11 or Fig.12 The anomaly detection method of the embodiment shown.

[0385] The present application also provides a computer-readable storage medium, which stores computer instructions for implementing the above-mentioned model training method, such as Figure 7 or Fig.12 The model training method of the embodiment shown.

[0386] The embodiment of the present application also provides a chip system, which includes at least one processor, a memory and an interface circuit, wherein the interface circuit is used to provide information input / output for at least one processor, and the at least one memory stores computer instructions. When the computer instructions are executed on one or more processors, the chip system executes the above-mentioned abnormality detection method, for example Fig.11 or Fig.12 The anomaly detection method of the embodiment shown.

[0387] The embodiment of the present application also provides a chip system, which includes at least one processor, a memory and an interface circuit, wherein the interface circuit is used to provide information input / output for at least one processor, and the at least one memory stores computer instructions. When the computer instructions are executed on one or more processors, the chip system executes the above-mentioned model training method, for example Figure 7 or Fig.12 The model training method of the embodiment shown.

[0388] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer instruction product. When the computer instruction is loaded and executed on a computer, the process or function described in the embodiment of the present application can be implemented in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instruction can be stored in a computer-readable storage medium or transmitted by a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, a data center, etc. that contains one or more available media integrations. Available media can be magnetic media, (e.g., floppy disk, hard disk, tape), optical media (e.g., DVD), or semiconductor media (e.g., solid state disk (solid state disk, SSD)), etc.

[0389] The steps in the method embodiments of the present application can be adjusted in order, combined, and deleted according to actual needs.

[0390] The modules in the device embodiment of the present application can be merged, divided and deleted according to actual needs.

[0391] The above are only specific implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed in the present application should be covered within the protection scope of the present application.

Claims

1. A method for detecting abnormal behavior, characterized in that: include: Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of an operation behavior of operating an account; Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a first data set, wherein the first data set includes at least one piece of operation behavior data, and the division granularity includes one or more of the behavior characteristics; According to the time sequence relationship of the data in the first data set, the data is divided according to the preset time length to obtain a first session, wherein the first session includes at least one operation behavior data within the preset time length, and the first session is used to describe the behavior characteristics and time characteristics when operating the first account within the preset time length, and the time characteristics are used to reflect the correlation of the behavior characteristics in the time sequence; The first conversation is input into the target autoencoder AE model to obtain a detection result; wherein, the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model for training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length, and the at least two conversations are divided into granularities, and the granularity division is performed based on the preset division granularity.

2. The method according to claim 1, characterized in that The first session is a matrix of A rows and Q columns, each row in the A rows of data is an operation behavior data, the A rows of data are sorted from far to near in chronological order, one or more columns of data in the Q columns of data are used to indicate time features or behavior features, A is a positive number and A≥1, Q is an integer and Q≥1.

3. The method according to claim 1 or 2, characterized in that The step of inputting the first session into a target autoencoder AE model to obtain a detection result includes: Inputting the first session into the target AE model to obtain a first reconstruction session; determining a first reconstruction error based on the first session and the first reconstruction session; If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model.

4. The method according to any one of claims 1 to 3, characterized in that: The behavioral characteristics include at least one of Internet Protocol IP address, Media Access Control MAC address, account identification ID, request category, request result, request path, request location, request content, request failure reason or request time interval; the preset division granularity includes at least one of IP address, MAC address, account ID or operation location.

5. A method for training an autoencoder AE model, characterized in that: include: Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of an operation behavior of a normal operation target account; Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a target data set, wherein the division granularity includes one or more of the behavior characteristics; According to the temporal relationship of the data in the target data set, the data is divided according to the preset time length to obtain at least two sessions, each of which includes at least one operation behavior data within the preset time length, and each session is used to describe the behavior characteristics and time characteristics of normal operation of the target account within the preset time length, and the time characteristics in each session are used to reflect the correlation of the behavior characteristics in each session in terms of time sequence; The AE model is trained according to the at least two conversations to obtain a target AE model, wherein the target autoencoder model is used to detect whether an operation of completing the first conversation is a normal operation according to the first conversation.

6. The method according to claim 5, characterized in that Each session is a matrix of A rows and Q columns, wherein each row in the A rows is an operation behavior data, and the A rows are sorted in chronological order from far to near, and one or more columns in the Q columns are used to indicate time features or behavior features, A is a positive number and A≥1, and Q is an integer and Q≥1.

7. The method according to claim 5 or 6, characterized in that: The method further comprises: Inputting the at least two conversations into the target AE model to obtain at least two reconstruction errors; A first threshold is determined according to the at least two reconstruction errors; the first threshold is used to measure whether an operation of completing the first session is a normal operation.

8. The method according to claim 7, characterized in that The method further comprises: Extracting multiple sessions, where a portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of normal operations on the first target account within a preset time period, and another portion of the multiple sessions is used to describe the behavior characteristics and time characteristics of abnormal operations on the second target account within the preset time period; The target AE model is verified according to the multiple sessions and the first threshold; if the number of sessions corresponding to the abnormal operations detected according to the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed.

9. The method according to claim 8, characterized in that The obtaining of multiple pieces of operation behavior data includes: A plurality of samples are selected from the log of the unified identity authentication service IAM; the plurality of samples include data of normal operation of the target account in a plurality of time periods on a plurality of dates; From the plurality of samples, filtering samples whose Internet Protocol IP addresses belong to whitelist login IPs; The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

10. The method according to any one of claims 5 to 9, characterized in that: The step of training the AE model according to the at least two conversations to obtain a target AE model includes: Inputting the at least two sessions into the AE model to obtain at least two reconstruction sessions; According to the at least two sessions and the at least two reconstruction sessions, the AE model is updated by a gradient descent algorithm to obtain the target AE model.

11. The method according to claim 10, characterized in that The step of inputting the at least two conversations into the autoencoder model to obtain at least two reconstructed conversations includes: establishing an input matrix based on the at least two conversations; Based on the AE model, the input matrix is ​​encoded and decoded to obtain an output matrix; the output matrix includes the at least two reconstruction sessions.

12. An abnormal behavior detection device, characterized in that: include: Extraction unit for: Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of an operation behavior of operating an account; Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a first data set, wherein the first data set includes at least one piece of operation behavior data, and the division granularity includes one or more of the behavior characteristics; According to the time sequence relationship of the data in the first data set, the data is divided according to the preset time length to obtain the first session, wherein the first session includes at least one operation behavior data within the preset time length, and the first session is used to describe the behavior characteristics and time characteristics when operating the first account within the preset time length, and the time characteristics are used to reflect the correlation of the behavior characteristics in the time sequence; A detection unit is used to input the first conversation into a target autoencoder AE model to obtain a detection result; wherein the detection result is used to indicate whether the operation of completing the first conversation is a normal operation; the target AE model is obtained by inputting data of at least two conversations into the AE model training, and each of the at least two conversations is used to describe the behavioral characteristics and time characteristics of the normal operation of the target account within a preset time length, and the at least two conversations are divided into granularities, and the granularity division is performed based on the preset division granularity.

13. The device according to claim 12, characterized in that The first session is a matrix of A rows and Q columns, each row in the A rows of data is an operation behavior data, the A rows of data are sorted from far to near in chronological order, one or more columns of data in the Q columns of data are used to indicate time features or behavior features, A is a positive number and A≥1, Q is an integer and Q≥1.

14. The device according to claim 12 or 13, characterized in that The detection unit is specifically used for: Inputting the first session into the target AE model to obtain a first reconstruction session; determining a first reconstruction error based on the first session and the first reconstruction session; If the first reconstruction error is greater than or equal to a first threshold, the detection result is used to indicate that the operation of completing the first session is not a normal operation; wherein the first threshold is obtained by inputting data of multiple sessions into the target AE model.

15. The device according to any one of claims 12 to 14, characterized in that: The behavioral characteristics include at least one of Internet Protocol IP address, Media Access Control MAC address, account identification ID, request category, request result, request path, request location, request content, request failure reason or request time interval; the preset division granularity includes at least one of IP address, MAC address, account ID or operation location.

16. An autoencoder AE model training device, characterized in that: include: Extraction unit for: Acquire multiple pieces of operation behavior data, each piece of the multiple pieces of operation behavior data is used to describe the behavior characteristics and time characteristics of an operation behavior of a normal operation target account; Dividing the plurality of pieces of operation behavior data according to a preset division granularity to obtain a target data set, wherein the division granularity includes one or more of the behavior characteristics; According to the temporal relationship of the data in the target data set, the data is divided according to the preset time length to obtain at least two sessions, each of which includes at least one operation behavior data within the preset time length, and each session is used to describe the behavior characteristics and time characteristics of normal operation of the target account within the preset time length, and the time characteristics in each session are used to reflect the correlation of the behavior characteristics in each session in terms of time sequence; A training unit is used to train the AE model according to the at least two conversations to obtain a target AE model, wherein the target autoencoder model is used to detect whether an operation of completing the first conversation is a normal operation according to the first conversation.

17. The method according to claim 16, characterized in that Each session is a matrix of A rows and Q columns, wherein each row in the A rows is an operation behavior data, and the A rows are sorted in chronological order from far to near, and one or more columns in the Q columns are used to indicate time features or behavior features, A is a positive number and A≥1, and Q is an integer and Q≥1.

18. The device according to claim 16 or 17, characterized in that The training unit is further used to input the at least two conversations into the target AE model to obtain at least two reconstruction errors; The training unit is further used to determine a first threshold according to the at least two reconstruction errors; the first threshold is used to measure whether the operation of completing the first session is a normal operation.

19. The device according to claim 18, characterized in that The extraction unit is further used to extract multiple sessions, a portion of the multiple sessions is used to describe the behavior characteristics and time characteristics when the first target account is normally operated within a preset time period, and another portion of the multiple sessions is used to describe the behavior characteristics and time characteristics when the second target account is abnormally operated within the preset time period; The device also includes: a verification unit, used to verify the target AE model according to the multiple sessions and the first threshold; if the number of sessions corresponding to the abnormal operations detected according to the target AE model is greater than or equal to the second threshold, it indicates that the training of the target AE model is completed.

20. The device according to any one of claims 16 to 19, characterized in that The extraction unit is specifically used for: A plurality of samples are selected from the log of the unified identity authentication service IAM; the plurality of samples include data of normal operation of the target account in a plurality of time periods on a plurality of dates; From the plurality of samples, filtering samples whose Internet Protocol IP addresses belong to whitelist login IPs; The filtered multiple samples are grouped, re-encoded and string matched to obtain the multiple pieces of operation behavior data.

21. The device according to any one of claims 16 to 20, characterized in that: The training unit is specifically used for: Inputting the at least two sessions into the AE model to obtain at least two reconstruction sessions; According to the at least two sessions and the at least two reconstruction sessions, the AE model is updated by a gradient descent algorithm to obtain the target AE model.

22. The method according to claim 21, characterized in that The training unit is specifically used for: establishing an input matrix based on the at least two conversations; Based on the AE model, the input matrix is ​​encoded and decoded to obtain an output matrix; the output matrix includes the at least two reconstruction sessions.

23. A service node, characterized in that: The service node includes a processor and a memory; the processor is used to execute computer instructions stored in the memory, so that the service node implements the method according to any one of claims 1 to 4.

24. A model training server, characterized in that: The model training server includes a processor and a memory; the processor is used to execute computer instructions stored in the memory, so that the server implements the method described in any one of claims 5-11.

25. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the method according to any one of claims 1 to 4.

26. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the method according to any one of claims 5 to 11.

Citation Information

Patent Citations

  • Behavior detection method and device, electronic equipment and storage medium

    CN111178523A

  • Automatic malicious session detection

    US20190266325A1

  • Systems and methods for detecting anomalous behavior within computing sessions

    US20200195683A1