Method, apparatus, computer device, and storage medium for identifying abnormal user login behavior
By calculating the abnormal probability of multiple abnormal features in the user's current login behavior information and historical login information, the problem of low user login behavior recognition accuracy in the prior art is solved, and more accurate user abnormal login behavior recognition is achieved.
Patent Information
- Application Number
- CN202111372249.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-18
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-11-18
AI Technical Summary
When the prior art detects abnormal login behavior of users in real time, the detection method is single, and the user login behavior cannot be accurately characterized, resulting in low recognition accuracy.
By obtaining the current login behavior information of the target user, combining historical login information, the probability of abnormal login time, abnormal login location, abnormal server migration, and abnormal login time interval, are calculated, and these probabilities are combined for abnormal identification.
It improves the accuracy of user login behavior abnormality judgment, can more accurately identify user login behavior, and enhances the security of network accounts.
Smart Images

Figure CN114238885B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet security technologies, and particularly to a method, device, computer device, and storage medium for identifying abnormal user login behaviors. Background Art
[0002] With the development of computer technologies, the Internet has penetrated into all aspects of ordinary people's lives. People access remote servers through the Internet and participate in various activities in the Internet environment. In the process of using network services, users generally need user accounts to access the Internet. A user account is used to record the user's username and password, affiliated groups, accessible network resources, as well as the user's personal files and settings. Each user should have a user account in the domain controller to access the server and use the resources on the network. However, the development of computer technologies itself has also been accompanied by increasingly severe Internet security threats. Internet security incidents such as cracked email accounts, stolen personal Internet accounts, and leaked user personal privacy have emerged in an endless stream.
[0003] Currently, there are mainly two directions for the security prevention of network accounts: (1) Pre-event prevention: improving the strength of user account passwords; requiring users to use more security verification information; relying on relevant verification tools to log in to the account; secure login based on voiceprint recognition and voice recognition; etc. (2) Real-time detection: timely detecting the legitimacy of each account login, and performing additional verification or even directly rejecting suspected abnormal login requests.
[0004] Among them, although pre-event prevention has good effects, it also requires higher security awareness from the users themselves. Currently, real-time detection has a single detection method, cannot accurately depict user login behaviors, and is prone to the problem of low accuracy in identifying abnormal user login behaviors. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide a method, device, computer device, and storage medium for identifying abnormal user login behaviors that can accurately identify abnormal user login behaviors.
[0006] A method for identifying abnormal user login behaviors, characterized in that the method includes:
[0007] Obtain current login information corresponding to the current login behavior of a target user, where the login information includes the current login time point, current login location, and current server identifier of the current server logged in by the target user corresponding to the current login behavior;
[0008] Based on the probability distribution of historical login time points corresponding to the target user according to the current login time point, determine the login time anomaly probability corresponding to the current login behavior of the target user;
[0009] Based on the historical login location probability distribution corresponding to the target user, determine the abnormal probability of the login location corresponding to the current login behavior of the target user according to the current login location.
[0010] Based on the historical login time interval probability distribution corresponding to the target user, determine the abnormal probability of the login time interval corresponding to the current login behavior of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user.
[0011] Obtain the identifier of the previous server logged in by the previous login behavior of the target user. Based on the historical login state transition matrix corresponding to the target user, and according to the current server identifier and the identifier of the previous server, determine the abnormal probability of server migration indicating that the current login behavior transfers from the previous server to the current server.
[0012] Based on the abnormal probability of login time, the abnormal probability of login location, the abnormal probability of server migration, and the abnormal probability of login time interval, perform abnormal identification on the current login behavior of the target user.
[0013] In one embodiment, before determining the abnormal probability of the login time corresponding to the current login behavior of the target user based on the historical login time point probability distribution corresponding to the target user according to the current login time point, the method further includes:
[0014] Obtain multiple historical login time points of the target user within a first historical time period; wherein, each historical login time point corresponds to a historical login behavior of the target user, and the first historical time period includes multiple login cycles.
[0015] Using the same division principle, divide each login cycle within the first historical time period into several interval segments; wherein, for each login cycle, it includes several interval segments that are the same as those of other login cycles.
[0016] For each interval segment, according to the multiple historical login time points, count the historical interval login times of the target user in the same interval segment of each login cycle within the first historical time period.
[0017] Based on the historical interval login times of the target user in the same interval segment of each login cycle and the several interval segments, obtain the historical login time point probability distribution of the target user.
[0018] Determining the abnormal login time probability corresponding to the current login behavior of the target user according to the current login time point, based on the historical login time point probability distribution corresponding to the target user, includes:
[0019] According to the interval segment where the current login time point is located in the login cycle, and based on the historical login time point probability distribution corresponding to the target user, determine the abnormal login time probability corresponding to the current login behavior of the target user.
[0020] In one embodiment, obtaining the historical login time point probability distribution of the target user based on the historical interval login times of the target user in the same interval segment of each login cycle and the several interval segments includes:
[0021] For each interval segment, count the historical interval login times of the target user in the same interval segment of each login cycle, and obtain the total historical interval login times of the target user in each interval segment;
[0022] According to the several interval segments and the total historical interval login times corresponding to each interval segment, draw the historical login time point probability parameter distribution of the target user;
[0023] Perform curve fitting and normalization processing on the historical login time point probability parameter distribution to obtain the historical login time point probability distribution.
[0024] In one embodiment, before determining the abnormal login location probability corresponding to the current login behavior of the target user according to the current login location, based on the historical login location probability distribution corresponding to the target user, the method further includes:
[0025] Obtain multiple historical login locations of the target user within a second historical time period, and each historical login location corresponds to a historical login behavior of the target user;
[0026] Obtain corresponding multiple historical login distances according to the multiple historical login locations; the historical login distance is the distance between each historical login location and the logged-in server address;
[0027] Perform spatial clustering on the multiple historical login distances to obtain multiple login distance intervals;
[0028] Count the number of historical login distances of the target user in each login distance interval within the second historical time period, and obtain the historical login location probability distribution;
[0029] Determining the abnormal probability of the login location corresponding to the current login behavior of the target user based on the historical login location probability distribution corresponding to the target user according to the current login location includes:
[0030] For the target user, determine the current login distance according to the current login location and the previous login location of the current login location;
[0031] According to the login distance interval to which the current login distance belongs and the historical login location probability distribution, determine the abnormal probability of the login location corresponding to the current login behavior of the target user.
[0032] In one embodiment, before determining the abnormal probability of the login time interval corresponding to the current login behavior of the target user based on the historical login time interval probability distribution of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user, the method further includes:
[0033] Obtain multiple historical login time points of the target user within a third historical time period; wherein, each historical login time point corresponds to a historical login behavior of the target user;
[0034] Obtain multiple historical login time intervals according to the multiple historical login time points, where the historical login time interval is the time interval between each login behavior of the target user and the previous login behavior;
[0035] Obtain the standard variance and average value of the multiple historical login time intervals, and obtain the historical login time interval probability distribution of the target user according to the standard variance and average value;
[0036] Determining the abnormal probability of the login time interval corresponding to the current login behavior of the target user based on the historical login time interval probability distribution of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user includes:
[0037] According to the current login time interval between the current login time point and the previous login time of the current target user and the historical login time interval probability distribution, determine the abnormal probability of the continuous login time interval corresponding to the current login behavior of the target user.
[0038] In one embodiment, before obtaining the prior server identifier of the prior server logged in by the previous login behavior of the target user, and determining the abnormal probability of server migration of the current login behavior representing the transfer from the prior server to the current server based on the historical login state transition matrix corresponding to the target user and according to the current server identifier and the prior server identifier, the method further includes:
[0039] Obtain multiple historical login server identifiers corresponding to the target user within a fourth historical time period, where each historical login server logged in for each historical login behavior corresponds to one historical login server identifier;
[0040] According to the multiple historical login server identifiers, obtain the probability of login transfer occurring between two consecutive historical login behaviors of the target user corresponding to a target historical login server identifier group, and obtain an initial login state transition matrix; wherein, each target historical login server identifier group contains two target historical login server identifiers, and the target historical login server identifier is included in the target historical login server identifier set;
[0041] Perform normalization processing on the initial login state transition matrix to obtain a historical login state transition matrix.
[0042] In one embodiment, according to the multiple historical login server identifiers, obtaining the probability of login transfer occurring between two consecutive historical login behaviors of the target user corresponding to a target historical login server identifier group, and obtaining an initial login state transition matrix includes:
[0043] Remove duplicates from the multiple historical login server identifiers to obtain a target historical login server identifier set;
[0044] Generate multiple target historical login server identifier groups according to the target historical login server identifier set;
[0045] According to the historical login server identifiers corresponding to two consecutive historical login behaviors of the target user respectively, calculate the historical login server transfer probability of the target user logging in to the two historical login servers corresponding to each target historical login server identifier group in sequence;
[0046] Generate an initial login state transition matrix based on the multiple target historical login server identifier groups and the historical login server transfer probability corresponding to each target historical login server identifier group.
[0047] A user abnormal login behavior recognition device, characterized in that the device includes:
[0048] An acquisition module, configured to acquire current login information corresponding to the current login behavior of the target user, where the login information includes the current login time point, the current login location, and the current server identifier of the current server logged in for the current login behavior of the target user;
[0049] The first calculation module is configured to determine the login time anomaly probability corresponding to the current login behavior of the target user based on the historical login time point probability distribution corresponding to the target user according to the current login time point;
[0050] The second calculation module is configured to determine the login location anomaly probability corresponding to the current login behavior of the target user based on the historical login location probability distribution corresponding to the target user according to the current login location;
[0051] The third calculation module is configured to determine the login time interval anomaly probability corresponding to the current login behavior of the target user based on the historical login time interval probability distribution of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user;
[0052] The fourth calculation module is configured to obtain the prior server identifier of the server logged in by the previous login behavior of the target user, and based on the historical login state transition matrix corresponding to the target user, and according to the current server identifier and the prior server identifier, determine the server migration anomaly probability that the current login behavior represents a transfer from the prior server to the current server;
[0053] The anomaly recognition module is configured to perform anomaly recognition on the current login behavior of the target user according to the login time anomaly probability, the login location anomaly probability, the server migration anomaly probability, and the login time interval anomaly probability.
[0054] A computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned user abnormal login behavior recognition method are implemented.
[0055] A computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the steps of the above-mentioned user abnormal login behavior recognition method are implemented.
[0056] The above-mentioned method, device, computer equipment and storage medium for identifying abnormal user login behaviors determine the abnormal probabilities of login time, login location, server migration, and login time interval corresponding to the current login behavior of the target user by combining the current login information such as the current login time point, current login location, and current server identifier of the currently logged-in server corresponding to the current login behavior of the target user with the historical login information corresponding to the target user's previous login behavior, and identify the abnormality of the target user's current login behavior. Among them, based on the characteristic curves (probability distributions) corresponding to each abnormal feature (login time, login location, server migration, and login time interval) of the target user's historical login behavior, the abnormal probabilities of the login time, login location, server migration, and login time interval that are most relevant to the user's login behavior are fully considered, improving the accuracy of judging the abnormality of the target user's login behavior. Description of the Drawings
[0057] Figure 1 It is an application environment diagram of the method for identifying abnormal user login behaviors in an embodiment;
[0058] Figure 2 It is a schematic flowchart of the method for identifying abnormal user login behaviors in an embodiment;
[0059] Figure 3 It is the probability distribution of the historical login time point of the method for identifying abnormal user login behaviors in an embodiment;
[0060] Figure 4 It is the spatial clustering result of the method for identifying abnormal user login behaviors in an embodiment;
[0061] Figure 5 It is the probability distribution of the historical login location of the method for identifying abnormal user login behaviors in an embodiment;
[0062] Figure 6 It is the probability distribution of the historical login time interval of the method for identifying abnormal user login behaviors in an embodiment;
[0063] Figure 7 It is a schematic diagram of the Markov model of the method for identifying abnormal user login behaviors in an embodiment;
[0064] Figure 8 It is the combined identification model of abnormal user login behaviors of the method for identifying abnormal user login behaviors in an embodiment;
[0065] Figure 9 It is a structural block diagram of the device for identifying abnormal user login behaviors in an embodiment;
[0066] Figure 10 It is the internal structure diagram of the computer equipment in an embodiment. Detailed implementation manners
[0067] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0068] The method for identifying abnormal user login behavior provided by the present application can be applied to an application environment as Figure 1 shown. Among them, the user performs a server login operation through the terminal 102 (user terminal), and the login information corresponding to each login behavior is sent to the server 104 through the network. The server 104 identifies whether the current login behavior of the user is abnormal based on the historical login information previously sent by the terminal 102 and in combination with the current login information. Among them, the terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers and portable wearable devices. The user can use the user identity information (such as the user account password) to access the server through the terminal 102, and the accessed server may not be Figure 1 the server 104 in. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0069] Before describing the method for identifying abnormal user login behavior in the present application, some terms involved in the embodiments of the present application are first explained as follows:
[0070] User: The user can be a real user or a virtual computer user. Each user has a set of identity identification information, such as the user account password. The user can use the user account password to log in to different servers for network access.
[0071] Login behavior: The behavior of a user using the user account password for a network access is a login behavior.
[0072] Login information: Each login behavior corresponds to a set of login information, including the login time point, login location, and server identifier of the logged-in server, etc., which is used to judge whether the user's login behavior is abnormal to ensure the security of the user account information.
[0073] In one embodiment, as Figure 2 shown, a method for identifying abnormal user login behavior is provided. Taking the application of this method to the Figure 1 server in as an example, the method includes the following steps:
[0074] Step S202: Obtain the current login information corresponding to the target user's current login behavior. The login information includes the current login time point, the current login location, and the current server identifier of the current server logged in by the target user for the current login behavior.
[0075] Specifically, for a specific login behavior of the target user, the server will obtain the login information corresponding to the current login behavior. The login information mainly includes the login time, location, and the server logged in, etc., which is used to describe the target user's current login behavior.
[0076] Step S204: Based on the historical login time point probability distribution corresponding to the target user, determine the abnormal probability of the login time corresponding to the target user's current login behavior according to the current login time point.
[0077] Specifically, for the determined target user, there is a certain historical pattern in their login behavior. Based on the historical login behavior, the server can characterize the feature of the target user's historical login time to obtain a specific pattern, that is, the historical login time point probability distribution corresponding to the target user. The historical login time point probability distribution can effectively illustrate the historical login time pattern of the target user within a historical time period. According to the display of the historical login time point probability distribution, the probability of the target user logging in at a specific time point can be determined, and the abnormal probability of the login time of the current login behavior can be determined.
[0078] Step S206: Based on the historical login location probability distribution corresponding to the target user, determine the abnormal probability of the login location corresponding to the target user's current login behavior according to the current login location.
[0079] Specifically, for the determined target user, based on the historical login behavior of the target user, the server can characterize the feature of the historical login location within a certain login time period, that is, the historical login location probability distribution. This distribution shows the probability of the user performing a login action at a specific location. Based on the historical login location probability distribution, the probability of the target user logging in at a specific location can be determined, and the abnormal probability of the login location of the current login behavior can be determined.
[0080] Step S208: Based on the historical login time interval probability distribution of the target user, determine the abnormal probability of the login time interval corresponding to the target user's current login behavior according to the login time interval between the target user's current login behavior and the previous login behavior.
[0081] Specifically, for a determined target user, the interval between two consecutive login behaviors is also one of the important factors for judging whether the login behavior is abnormal. For example, for a specific target user, there has never been a situation where two consecutive logins occur within less than one hour in their past historical login behaviors. Then, when the time interval between the target user's current login and the previous login behavior is less than 1, the probability of abnormality is relatively high. By analyzing the historical login behaviors of the target user, the server can determine the corresponding probability distribution of the historical login time intervals. Based on this probability distribution, the abnormality probability of the login time interval of a specific login behavior of the target user can be determined.
[0082] Step S210: Obtain the identifier of the previous server logged in by the target user's previous login behavior. Based on the historical login state transition matrix corresponding to the target user, and according to the current server identifier and the previous server identifier, determine the server migration abnormality probability that the current login behavior represents a transfer from the previous server to the current server.
[0083] Specifically, for a determined target user, there is a certain pattern among the servers they log in to. For example, after a human resources manager logs in to the 4A system, they are likely to transfer and log in to the human resources system. After a project manager logs in to the 4A system, they are likely to transfer and log in to the contract management system or the e-commerce system, etc. By analyzing the historical login behaviors of the target user, the server obtains a probability matrix (historical login state transition matrix) for evaluating the probability of the target user migrating between different servers, that is, the probability of jumping from the server A corresponding to the previous login behavior to the server B corresponding to the next login behavior. When it is necessary to evaluate a new login behavior, as long as the server logged in by the previous login behavior of the current login behavior is determined, the server migration abnormality probability of the target user transferring from the previous server to the current server can be determined from the historical login state transition matrix.
[0084] Step S212: Based on the login time abnormality probability, login location abnormality probability, server migration abnormality probability, and login time interval abnormality probability, perform abnormality identification on the current login behavior of the target user.
[0085] Specifically, for a determined target user, the login time, login location, server migration, and login time interval respectively belong to an aspect of a single login behavior and are all factors affecting the abnormal evaluation of the user's login behavior. When evaluating the abnormality of a specific user's login behavior, it is necessary to determine the weight ratios of the abnormal probabilities of the login time, login location, server migration, and login time interval respectively. In one embodiment, the above weight ratios can be the same or different from each other pairwise, and no specific limitation is made in this embodiment. Therefore, the server needs to comprehensively consider the abnormal probabilities of the login time, login location, server migration, and login time interval to accurately evaluate whether a specific login behavior is abnormal, that is, determine the weight ratio corresponding to each influencing factor according to requirements.
[0086] In the above method for identifying abnormal user login behavior, based on the current login information such as the current login time point, current login location, and current server identifier of the current server logged in by the target user, combined with the historical login information corresponding to the target user's previous login behavior, the abnormal probabilities of the login time, login location, server migration, and login time interval corresponding to the target user's current login behavior are determined to identify the abnormality of the target user's current login behavior. Among them, based on the characteristic curves (probability distributions) corresponding to each abnormal feature (login time, login location, server migration, and login time interval) of the target user's historical login behavior, the abnormal probabilities of the login time, login location, server migration, and login time interval that are most relevant to the user's login behavior are fully considered, improving the accuracy of the abnormal judgment of the target user's login behavior.
[0087] In one embodiment, before determining the abnormal login time probability corresponding to the current login behavior of the target user based on the historical login time point probability distribution corresponding to the target user according to the current login time point, the method further includes: obtaining multiple historical login time points of the target user within a first historical time period; wherein each historical login time point corresponds to a historical login behavior of the target user, and the first historical time period includes multiple login cycles; using the same division principle, dividing each login cycle within the first historical time period into several interval segments; wherein for each login cycle, it contains several interval segments that are the same as those of other login cycles; for each interval segment, based on the multiple historical login time points, counting the historical interval login times of the target user in the same interval segment of each login cycle within the first historical time period; based on the historical interval login times of the target user in the same interval segment of each login cycle and the several interval segments, obtaining the historical login time point probability distribution of the target user; determining the abnormal login time probability corresponding to the current login behavior of the target user according to the current login time point based on the historical login time point probability distribution corresponding to the target user, including: determining the abnormal login time probability corresponding to the current login behavior of the target user according to the interval segment where the current login time point is located in the login cycle and based on the historical login time point probability distribution corresponding to the target user.
[0088] Specifically, in order to obtain the historical login time point probability distribution of the determined target user within a period of time, the method adopted in this embodiment is that the server obtains the historical login time points corresponding to multiple historical login behaviors of the target user within a relatively long time period (the first historical time period, for example, greater than 24 hours), and then takes a relatively short time period (for example, 24 hours) as a cycle, and the first historical time period contains multiple cycles. For each cycle, it is divided into the same time segments according to the same division rule, for example, divided into 12 segments and numbered sequentially at one-hour intervals (or half-hour intervals, which is not specifically limited in this embodiment). Since there are multiple cycles, there are also multiple segments numbered 1. Based on the historical interval login times of the target user in the same interval segment of each login cycle and the interval segments, the historical login time point probability distribution of the target user can be obtained. When it is necessary to judge a specific user login behavior, only by comparing the current login time point with the historical login time point probability distribution, the corresponding abnormal login time probability can be determined.
[0089] In the above embodiment, characterizing a large number of user login behaviors within a time cycle, that is, increasing the sample size, can effectively improve the accuracy of the final historical login time point probability distribution, and further improve the accuracy of user login anomaly recognition.
[0090] In one embodiment, based on the historical interval login times of the target user in the same interval segment of each login cycle and several interval segments, the historical login time point probability distribution of the target user is obtained, including: for each interval segment, counting the historical interval login times of the target user in the same interval segment of each login cycle to obtain the total historical interval login times of the target user in each interval segment; according to several interval segments and the total historical interval login times corresponding to each interval segment, plotting the historical login time point probability parameter distribution of the target user; performing curve fitting and normalization processing on the historical login time point probability parameter distribution to obtain the historical login time point probability distribution.
[0091] Specifically, for a time period, it may include multiple cycles, and one cycle includes multiple time segments. For example, for the time segment numbered 1 in a cycle, when plotting the specific historical login time point probability distribution, it is necessary to count the total number of logins of the user in multiple time segments numbered 1 within the entire time period based on the historical login time points. Finally, the number of logins of the target user corresponding to each numbered segment can be obtained, and then based on each time segment and the corresponding number of logins of the target user, a scatter plot can be drawn. In this embodiment, further curve fitting and normalization processing are also performed to obtain the final historical login time point probability distribution.
[0092] In the above embodiment, depicting a large number of user login behaviors within a time cycle, that is, increasing the sample size, can effectively improve the accuracy of the final historical login time point probability distribution, and further improve the accuracy of user login anomaly recognition.
[0093] In one embodiment, before determining the login location anomaly probability corresponding to the current login behavior of the target user based on the historical login location probability distribution corresponding to the target user according to the current login location, the method further includes: obtaining multiple historical login locations of the target user within a second historical time period, each historical login location corresponding to a historical login behavior of the target user; obtaining corresponding multiple historical login distances according to the multiple historical login locations; the historical login distance being the distance between each historical login location and the logged-in server address; performing spatial clustering on the multiple historical login distances to obtain multiple login distance intervals; counting the number of historical login distances of the target user within each login distance interval within the second historical time period to obtain the historical login location probability distribution; determining the login location anomaly probability corresponding to the current login behavior of the target user based on the historical login location probability distribution corresponding to the target user according to the current login location, including: for the target user, determining the current login distance according to the current login location and the previous login location of the current login location; and determining the login location anomaly probability corresponding to the current login behavior of the target user according to the login distance interval to which the current login distance belongs and the historical login location probability distribution.
[0094] Specifically, the server characterizes the login characteristics of the target user accessing servers at different geographical locations (based on the logged-in target IP) through the historical login location probability distribution. The method it adopts is to perform spatial partitioning (simple clustering) on multiple target server IPs logged in by the target user based on the distance between the server IPs logged in by the target user. The server uses the distance between the IP address corresponding to the user's login behavior and the target server IP address as the judgment basis to characterize the multiple login behaviors of the target user and determines the login probability of the user in different login location intervals.
[0095] In the above embodiment, determining the probability values of the target user in multiple login distance intervals can accurately characterize the historical login behavior characteristics of the target user, thereby improving the accuracy of user login anomaly recognition.
[0096] In one embodiment, before determining the abnormal probability of the login time interval corresponding to the current login behavior of the target user based on the probability distribution of the historical login time intervals of the target user according to the time interval between the current login behavior and the previous login behavior of the target user, the method further includes: obtaining multiple historical login time points of the target user within a third historical time period; wherein each historical login time point corresponds to a historical login behavior of the target user; obtaining multiple historical login time intervals according to the multiple historical login time points, where the historical login time interval is the time interval between each login behavior of the target user and the previous login behavior; obtaining the standard variance and the average value of the multiple historical login time intervals, and obtaining the probability distribution of the historical login time intervals of the target user according to the standard variance and the average value; determining the abnormal probability of the login time interval corresponding to the current login behavior of the target user based on the probability distribution of the historical login time intervals of the target user according to the time interval between the current login behavior and the previous login behavior of the target user, including: determining the abnormal probability of the consecutive login time intervals corresponding to the current login behavior of the target user according to the current login time interval between the current login time point and the previous login time of the current target user and the probability distribution of the historical login time intervals.
[0097] Specifically, the time interval corresponding to two consecutive login behaviors of the target user is also one of the important features of its login behavior. For example, if the time intervals are very short for multiple consecutive times, it is very likely to be a cyber attack. In this embodiment, the server first obtains the sequence of consecutive login time intervals of the target user within a period of time (the third historical time period), then models this time interval sequence to obtain the corresponding probability density curve, and after normalization, obtains the probability distribution of the historical login time intervals used to describe the behavior characteristics of the consecutive login time intervals of the target user, and then determines the abnormal probability of the consecutive login time intervals corresponding to the current login behavior based on the probability distribution of the historical login time intervals.
[0098] In the above embodiment, by determining the behavior characteristics of the consecutive login time intervals of the target user, the abnormal probability of the consecutive login time intervals corresponding to the current login behavior can be determined through the time interval between the current login behavior of the target user and the previous historical login behavior, thereby improving the accuracy of user login anomaly recognition.
[0099] In one embodiment, before obtaining the prior server identifier of the prior server logged in by the target user's previous login behavior, determining the server migration abnormal probability that the current login behavior represents a transfer from the prior server to the current server based on the historical login state transition matrix corresponding to the target user, and according to the current server identifier and the prior server identifier, the method further includes: obtaining a plurality of historical login server identifiers corresponding to the target user within a fourth historical time period, where each historical login server logged in by each historical login behavior corresponds to a historical login server identifier; according to the plurality of historical login server identifiers, obtaining the probability of login transfer occurring between two consecutive historical login behaviors of the target user corresponding to a target historical login server identifier group, and obtaining an initial login state transition matrix; where each target historical login server identifier group contains two target historical login server identifiers, and the target historical login server identifier is included in the target historical login server identifier set; performing normalization processing on the initial login state transition matrix to obtain a historical login state transition matrix.
[0100] Specifically, the Markov model can effectively characterize the transfer characteristics of user login to the system. For example, after a human resources management staff logs in to the 4A system, they are likely to transfer and log in to the human resources system. After a project management staff logs in to the 4A system, they are likely to transfer and log in to the contract management system or the e-commerce system. Suppose a certain user ip u (user IP) has a set of logged-in server IPs {ip1, ip2,..., ip n}. Understanding the above set of server IPs as n different states of the user ip u , so the behavior of the user logging in to different servers (including logging in to the same server twice, i.e., state self-transition) is understood as the transfer of the user between different states. According to the Markov property, the user's current state is only related to the most recent past state. Therefore, by the server IP addresses of the servers logged in by the user within a period of time (the fourth historical time period), a probability matrix (historical login state transition matrix) for evaluating the probability of the target user migrating between different servers is obtained, that is, the probability of jumping from the server A corresponding to the previous login behavior to the server B corresponding to the next login behavior. When it is necessary to evaluate a new login behavior, as long as the server logged in by the previous login behavior of the current login behavior is determined, the server migration abnormal probability of the target user transferring from the prior server to the current server can be determined from the historical login state transition matrix.
[0101] In the above embodiment, through the historical login state transition matrix, the server can determine the server migration abnormal probability corresponding to the current login behavior, fully evaluate the influence of the server migration abnormal probability in the identification and judgment of the target user's login abnormality, and improve the accuracy of the target user's login abnormality identification.
[0102] In one embodiment, based on multiple historical login server identifiers, the probability of login transfer occurring between a target historical login server identifier group corresponding to two consecutive historical login behaviors of a target user is obtained, and an initial login state transition matrix is obtained, including: removing duplicates from the multiple historical login server identifiers to obtain a set of target historical login server identifiers; generating multiple target historical login server identifier groups according to the set of target historical login server identifiers; calculating the historical login server transfer probability that the target user logs in to two historical login servers corresponding to each target historical login server identifier group in sequence according to the historical login server identifiers corresponding to the two consecutive historical login behaviors of the target user; generating an initial login state transition matrix based on the multiple target historical login server identifier groups and the historical login server transfer probability corresponding to each target historical login server identifier group.
[0103] Specifically, in the historical login state transition matrix, the number of rows of the matrix is equal to the number of columns, and the row and column numbers respectively correspond to two specific historical login servers that the target user logs in to successively. By the login information of the target user within a period of time (the fourth historical period), the historical login server transfer probability corresponding to each matrix element in the matrix can be specifically determined, including the probability that the target user logs in to different servers and the same server in two consecutive login behaviors. The historical login state transition matrix obtained thereby can comprehensively reflect the probability of the user transferring between different historical login servers, and can accurately characterize the characteristics of the user's login transfer between different historical login servers based on the user's multiple historical login behaviors.
[0104] In the above embodiment, through the historical login state transition matrix, the server can determine the probability of abnormal server migration corresponding to the current login behavior, fully evaluate the influence of the probability of abnormal server migration in the identification and judgment of the target user's login abnormality, and improve the accuracy of identifying the target user's login abnormality.
[0105] Further, in the above embodiment, the first historical period, the second historical period, the third historical period, and the fourth historical period may be the same or different.
[0106] It should be understood that although Figure 2 the steps in the flowchart Figure 2At least some of the steps may include multiple steps or multiple stages, and these steps or stages do not necessarily need to be executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turns with at least some of the steps or stages in other steps or other steps.
[0107] Further, as Figures 3 - 8 shown, it is a specific embodiment for illustrating the process of identifying abnormal user login behavior by using the above method. In this embodiment, first, user login features are extracted, including: user login behavior time distribution feature (probability distribution of historical login time points), user login behavior space distribution feature (probability distribution of historical login locations), user adjacent login time interval distribution feature (probability distribution of historical login time intervals), and Markov transition feature of the user's login server (historical login state transition matrix). Then, based on the above features, the abnormality of the target user's current login behavior is identified. The specific process is as follows:
[0108] Step 1: Obtain the user login behavior time distribution feature
[0109] Characterize the login times of the user at different time periods, such as commuting times, day and night, etc., and learn a probability density curve. For a user, taking half an hour as an interval segment, a day is divided into 48 interval segments, represented by {I1, I2,..., I 48}. Compress the historical login data of the past 60 days into one day accordingly, and count the login times of each interval segment I i , denoted as n i . Use n to represent the total number of logins in one day (data of 60 days). Fit the above discrete points with a smooth curve 0 ≤ g(x) ≤ 1, such that
[0110]
[0111] To keep the degrees of each model consistent, perform uniform scaling on g(x), that is, find a constant λ > 0 such that the maximum value of T(x) = λg(x) is 1, that is, T(x) is the probability density curve of the time distribution of the user's login behavior, as Figure 3 shown.
[0112] Step 2: Obtain the user login behavior space distribution feature
[0113] First, characterize the login features of the user accessing servers at different geographical locations (based on the login target IP). The idea is to perform spatial partitioning (simple clustering) on the target server IP based on the IP distance.
[0114] Suppose a certain user ipu (The user IP) The set of logged-in server IPs is {i p1 , i p2 ,..., i pn}. The improved Minkowski distance between two IPs is defined as follows:
[0115] Let ip1 = [x1, x2, x3, x4] and ip2 = [y1, y2, y3, y4], then
[0116]
[0117] Calculate the IP distance between the user ip u and the server IP list {ip1, ip2,..., ip n},
[0118] [dif(ip u , ip1), dif(ip u , ip2),..., dif(ip u , ip n )] = [d1, d2,..., d n
[0119] Determine the following partition points:
[0120] MAX = max{d1, d2,..., d n}
[0121] MIN = min{d1, d2,..., d n}
[0122] MEAN = mean{d1, d2,..., d n}
[0123]
[0124]
[0125] Obviously, MIN ≤ MIN_MEAN ≤ MEAN ≤ MEAN_MAX ≤ MAX.
[0126] Therefore, the above partition points divide the real number axis into 6 parts, as Figure 4 shown:
[0127] cluster_1: [0, MIN)
[0128] cluster_2: [MIN, MIN_MEAN)
[0129] cluster_3: [MIN_MEAN, MEAN)
[0130] cluster_4: [MEAN, MEAN_MAX)
[0131] cluster_5: [MEAN_MAX, MAX]
[0132] cluster_6: (MAX, 1623.379391329776]
[0133] Then, use a simple clustering algorithm to calculate the clustering space. The specific process includes:
[0134] (1) Calculate the user ip u and the server ip i of the improved Minkowski distance:
[0135] d i = dif(ip u , ip i ).
[0136] (2) Judge the interval to which d i belongs and classify it into the corresponding cluster, that is, ip i ∈ cluster_j.
[0137] For each user, obtain the login data of the user for 60 days, count the number of logins c(cluster_j) of each category, j = 1, 2, 3, 4, 5, 6, and construct a piecewise space distribution probability curve expression:
[0138]
[0139] The corresponding piecewise space distribution probability curve is as Figure 5 shown.
[0140] Step 3: Distribution characteristics of the time interval between adjacent user logins
[0141] Characterize the time interval characteristics of multiple consecutive user logins. If the time intervals are very short for multiple consecutive times, it is very likely to be a network attack.
[0142] For each user, obtain the time interval sequence of the user's consecutive logins for 60 days
[0143] {t1, t2,..., t n};
[0144] Model the above time interval sequence with a one-dimensional truncated Gaussian model, that is
[0145]
[0146] Among them, the parameters σ and μ are determined by the data {t1, t2,..., t n}. Here, take the truncated probability density curve, that is:
[0147] (1) If x < μ, then
[0148]
[0149] (2) If x ≥ μ, then
[0150]
[0151] To keep the model scale consistent, scale the above probability density function to obtain the probability density distribution function as follows:
[0152]
[0153] When using G(x) to describe the behavior characteristics of the user's continuous login time interval, the corresponding curve is as Figure 6 shown.
[0154] Step 4: Markov transition characteristics of user logging in to the server
[0155] As Figure 7 shown, the Markov model can effectively characterize the transition characteristics of users logging in to the system. For example, after a human resources management staff logs in to the 4A system, they are likely to transfer and log in to the human resources system. After a project management staff logs in to the 4A system, they are likely to transfer and log in to the contract management system or the e-commerce system.
[0156] Suppose a certain user ip u (user IP) logs in to the server IP set {ip1, ip2,..., ip n}. Understand the above server IP set as n different states of the user ip u . Therefore, the behavior of the user logging in to different servers (including logging in to the same server twice, that is, state self-transition) is understood as the transition of the user between different states. According to the Markov property, the user's current state is only related to the most recent past state, denoted as:
[0157] t ij = p(ip j |ip i )
[0158] represents the probability that the user transfers to state ip i under the condition of being in state ip j . Then the corresponding state transition matrix is obtained as follows:
[0159]
[0160] In this embodiment, the above state transition matrix can be determined by using the login data of the past 60 days and the maximum likelihood estimation. To keep the scales of all models consistent, the above state transition matrix is normalized, that is
[0161]
[0162] Step 5: User Abnormal Login Behavior Combination Recognition Model
[0163] Using the above four types of user behavior characteristics, establish a user abnormal login behavior combination recognition model as Figure 8 shown.
[0164] Model input: the attributes of the user's ip u , the ip current of the currently logged-in server and the login time time current , and the ip past of the server logged in by the user last time recently and the login time time past ; combined weights p1 + p2 + p3 + p3 = 1 and decision threshold λ > 0.
[0165] Model output: whether the user's ip u has abnormal login.
[0166] The specific inference process of the user abnormal login behavior combination recognition is as follows:
[0167] (1) Based on the time distribution characteristics of the user's login behavior (probability distribution of historical login time points), determine the abnormal login time probability P t = 1 - T(time current ).
[0168] (2) Based on the spatial distribution characteristics of the user's login behavior (probability distribution of historical login locations), determine the abnormal login location probability:
[0169] Use the simple clustering algorithm in step 2 to judge the clustering category to which the ip current belongs, that is:
[0170] ip current ∈cluster_j;
[0171] Calculate the abnormal login location probability P s = 1 - S(cluster_j).
[0172] (3) Based on the distribution characteristics of the time intervals between adjacent user logins (probability distribution of historical login time intervals), determine the abnormal login time interval probability:
[0173] Calculate the time interval t_gap = time current - timepast ;
[0174] Calculate the abnormal probability \(P\) of the login time interval g = 1 - \(G(t_{gap})\).
[0175] (4) Determine the abnormal probability of server migration based on the Markov transition characteristics (historical login state transition matrix) of the user logging in to the server:
[0176] \(P\) m = 1 - \(t\) ip_past,ip_current = 1 - \(p(ip_{current}|ip_{past})\).
[0177] (5) Calculate the abnormal probability of the current login behavior of the target user:
[0178] \(P = p1\cdot P\) t + \(p2\cdot P\) s + \(p3\cdot P\) g + \(p4\cdot P\) m .
[0179] (6) Identify whether the current login behavior of the target user is abnormal:
[0180] If \(P>r\), then the user \(ip\) u is a non-abnormal login user, where \(r\) is the preset abnormal probability threshold for login behavior. When the abnormal probability of the current login behavior of the target user exceeds the preset abnormal probability threshold for login behavior, it indicates that the current login behavior of the target user is abnormal.
[0181] In one embodiment, as Figure 9 shown, a device for identifying abnormal user login behavior is provided, including: an acquisition module 902, a first calculation module 904, a second calculation module 906, a third calculation module 908, a fourth calculation module 910, and an abnormal identification module 912, where:
[0182] The acquisition module 902 is used to acquire the current login information corresponding to the current login behavior of the target user. The login information includes the current login time point, the current login location, and the current server identifier of the current server logged in by the target user.
[0183] The first calculation module 904 is used to determine the abnormal probability of the login time corresponding to the current login behavior of the target user based on the probability distribution of the historical login time points corresponding to the target user according to the current login time point.
[0184] The second calculation module 906 is used to determine the abnormal probability of the login location corresponding to the current login behavior of the target user based on the probability distribution of the historical login locations corresponding to the target user according to the current login location.
[0185] A third calculation module 908, configured to determine the abnormal probability of the login time interval corresponding to the current login behavior of the target user based on the login time interval between the current login behavior and the previous login behavior of the target user and based on the historical login time interval probability distribution of the target user.
[0186] A fourth calculation module 910, configured to obtain the identifier of the previous server logged in by the previous login behavior of the target user, and determine the abnormal probability of server migration indicating the transfer from the previous server to the current server for the current login behavior based on the historical login state transition matrix corresponding to the target user and according to the current server identifier and the identifier of the previous server.
[0187] An abnormality recognition module 912, configured to perform abnormality recognition on the current login behavior of the target user according to the abnormal probability of login time, the abnormal probability of login location, the abnormal probability of server migration, and the abnormal probability of login time interval.
[0188] The above user abnormal login behavior recognition device determines the abnormal probability of login time, the abnormal probability of login location, the abnormal probability of server migration, and the abnormal probability of login time interval corresponding to the current login behavior of the target user by combining the current login information such as the current login time point, the current login location, and the current server identifier of the current server logged in by the current login behavior of the target user with the historical login information corresponding to the previous login behavior of the target user, and performs abnormality recognition on the current login behavior of the target user. Among them, based on the characteristic curves (probability distributions) corresponding to each abnormal feature (login time, login location, server migration, and login time interval) of the historical login behavior of the target user, the abnormal probabilities of the login time, login location, server migration, and login time interval that are most relevant to the user's login behavior are fully considered, improving the accuracy of judging the abnormality of the target user's login behavior.
[0189] In one embodiment, the first calculation module is further configured to: obtain multiple historical login time points of a target user within a first historical time period; wherein each historical login time point corresponds to a historical login behavior of the target user, and the first historical time period includes multiple login cycles; divide each login cycle within the first historical time period into several interval segments according to the same division principle; wherein for each login cycle, it includes several interval segments that are the same as those of other login cycles; for each interval segment, based on the multiple historical login time points, count the historical interval login times of the target user in the same interval segment of each login cycle within the first historical time period; based on the historical interval login times of the target user in the same interval segment of each login cycle and the several interval segments, obtain the probability distribution of the historical login time points of the target user; determine the login time anomaly probability corresponding to the current login behavior of the target user according to the interval segment in which the current login time point is located in the login cycle and based on the probability distribution of the historical login time points corresponding to the target user.
[0190] In the above embodiment, characterizing a large number of user login behaviors within a time period is to increase the sample size, which can effectively improve the accuracy of the final probability distribution of the historical login time points.
[0191] In one embodiment, the first calculation module is further configured to: for each interval segment, count the historical interval login times of the target user in the same interval segment of each login cycle, and obtain the total historical interval login times of the target user in each interval segment; according to the several interval segments and the total historical interval login times corresponding to each interval segment, draw the probability parameter distribution of the historical login time points of the target user; perform curve fitting and normalization processing on the probability parameter distribution of the historical login time points to obtain the probability distribution of the historical login time points.
[0192] In the above embodiment, characterizing a large number of user login behaviors within a time period is to increase the sample size, which can effectively improve the accuracy of the final probability distribution of the historical login time points.
[0193] In one embodiment, the second calculation module is further configured to: obtain multiple historical login locations of the target user within a second historical time period, where each historical login location corresponds to a historical login behavior of the target user; obtain multiple corresponding historical login distances according to the multiple historical login locations; the historical login distance is the distance between each historical login location and the logged-in server address; perform spatial clustering on the multiple historical login distances to obtain multiple login distance intervals; count the number of historical login distances of the target user within each login distance interval within the second historical time period to obtain a historical login location probability distribution; for the target user, determine the current login distance according to the current login location and the previous login location of the current login location; and determine the login location anomaly probability corresponding to the current login behavior of the target user according to the login distance interval to which the current login distance belongs and the historical login location probability distribution.
[0194] In the above embodiment, determining the probability values of the target user in multiple login distance intervals can accurately characterize the historical login behavior characteristics of the target user.
[0195] In one embodiment, the third calculation module is further configured to: obtain multiple historical login time points of the target user within a third historical time period; where each historical login time point corresponds to a historical login behavior of the target user; obtain multiple historical login time intervals according to the multiple historical login time points, and the historical login time interval is the time interval between each login behavior of the target user and the previous login behavior; obtain the standard variance and average value of the multiple historical login time intervals, and obtain the historical login time interval probability distribution of the target user according to the standard variance and average value; and determine the continuous login time interval anomaly probability corresponding to the current login behavior of the target user according to the current login time interval between the current login time point of the current target user and the previous login time and the historical login time interval probability distribution.
[0196] In the above embodiment, to determine the continuous login time interval behavior characteristics of the target user, the continuous login time interval anomaly probability corresponding to the current login behavior can be determined through the time interval between the current login behavior of the target user and the previous historical login behavior, thereby improving the accuracy of user login anomaly recognition.
[0197] In one embodiment, the fourth computing module is further configured to: obtain a plurality of historical login server identifiers corresponding to the target user within a fourth historical time period, where each historical login server logged in by each historical login behavior corresponds to one historical login server identifier; according to the plurality of historical login server identifiers, obtain the probability of login transfer occurring between a target historical login server identifier group corresponding to two consecutive historical login behaviors of the target user, and obtain an initial login state transition matrix; where each target historical login server identifier group contains two target historical login server identifiers, and the target historical login server identifier is included in the target historical login server identifier set; perform normalization processing on the initial login state transition matrix to obtain a historical login state transition matrix.
[0198] In the above embodiment, through the historical login state transition matrix, the server can determine the server migration anomaly probability corresponding to the current login behavior, fully evaluate the influence of the server migration anomaly probability in the identification and judgment of the target user's login anomaly, and improve the accuracy of the target user's login anomaly identification.
[0199] In one embodiment, the fourth computing module is further configured to: remove duplicates from the plurality of historical login server identifiers to obtain a target historical login server identifier set; generate a plurality of target historical login server identifier groups according to the target historical login server identifier set; calculate the historical login server transfer probability that the target user logs in to the two historical login servers corresponding to each target historical login server identifier group in sequence according to the historical login server identifiers corresponding to two consecutive historical login behaviors of the target user; generate an initial login state transition matrix based on the plurality of target historical login server identifier groups and the historical login server transfer probability corresponding to each target historical login server identifier group.
[0200] In the above embodiment, through the historical login state transition matrix, the server can determine the server migration anomaly probability corresponding to the current login behavior, fully evaluate the influence of the server migration anomaly probability in the identification and judgment of the target user's login anomaly, and improve the accuracy of the target user's login anomaly identification.
[0201] For the specific limitations of the user abnormal login behavior recognition device, reference can be made to the limitations on the user abnormal login behavior recognition method in the above text, which will not be elaborated here. Each module in the above user abnormal login behavior recognition device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above respective modules.
[0202] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structural diagram may be as shown in Figure 10 . The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store user abnormal login behavior recognition data, including historical login data and current login data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for recognizing user abnormal login behavior.
[0203] Those skilled in the art can understand that Figure 10 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0204] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, it implements the steps in the above method embodiments.
[0205] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, it implements the steps in the above method embodiments.
[0206] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, it implements the steps in the above method embodiments.
[0207] It should be noted that the user information (including but not limited to user device information, user personal information, and user login information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0208] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0209] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0210] The above embodiments only express several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A method for identifying abnormal user login behavior, characterized in that, The method includes: Obtaining current login information corresponding to the current login behavior of the target user, where the login information includes the current login time point, current login location, and current server identifier of the current server logged in by the target user for the current login behavior; Based on the historical login time point probability distribution corresponding to the target user according to the current login time point, determining the login time anomaly probability corresponding to the current login behavior of the target user; Based on the historical login location probability distribution corresponding to the target user according to the current login location, determining the login location anomaly probability corresponding to the current login behavior of the target user; Based on the historical login time interval probability distribution of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user, determining the login time interval anomaly probability corresponding to the current login behavior of the target user; Obtaining the prior server identifier of the prior server logged in by the previous login behavior of the target user, and based on the historical login state transition matrix corresponding to the target user, and according to the current server identifier and the prior server identifier, determining the server migration anomaly probability that the current login behavior represents a transfer from the prior server to the current server; Multiplying the login time anomaly probability, login location anomaly probability, login time interval anomaly probability, and server migration anomaly probability by their corresponding combined weights respectively and then adding them up to obtain the current login behavior anomaly probability of the target user; when the current login behavior anomaly probability is less than the preset login behavior anomaly probability threshold, the current login behavior of the target user is normal; when the current login behavior anomaly probability is greater than the preset login behavior anomaly probability threshold, the current login behavior of the target user is abnormal.
2. The method according to claim 1, wherein Before determining the login time anomaly probability corresponding to the current login behavior of the target user based on the historical login time point probability distribution corresponding to the target user according to the current login time point, the method further includes: Obtaining multiple historical login time points of the target user within a first historical time period; where each historical login time point corresponds to a historical login behavior of the target user, and the first historical time period includes multiple login cycles; Using the same division principle to divide each login cycle within the first historical time period into several interval segments; where for each login cycle, it includes several interval segments that are the same as those of other login cycles; For each interval segment, according to the multiple historical login time points, counting the historical interval login times of the target user in the same interval segment of each login cycle within the first historical time period; Based on the historical interval login times of the target user in the same interval segment of each login cycle and the several interval segments, obtaining the historical login time point probability distribution of the target user; Determining the login time anomaly probability corresponding to the current login behavior of the target user based on the historical login time point probability distribution corresponding to the target user according to the current login time point includes: Determine the login time anomaly probability corresponding to the current login behavior of the target user according to the interval segment where the current login time point is located in the login cycle and based on the historical login time point probability distribution corresponding to the target user.
3. The method according to claim 2, wherein The obtaining of the historical login time point probability distribution of the target user based on the historical interval login times of the target user in the same interval segment of each login cycle and the several interval segments includes: For each interval segment, count the historical interval login times of the target user in the same interval segment of each login cycle, and obtain the total historical interval login times of the target user in each interval segment; According to the several interval segments and the total historical interval login times corresponding to each interval segment, draw the historical login time point probability parameter distribution of the target user; Perform curve fitting and normalization processing on the historical login time point probability parameter distribution to obtain the historical login time point probability distribution.
4. The method according to claim 1, characterized in that Before determining the login location anomaly probability corresponding to the current login behavior of the target user according to the current login location and based on the historical login location probability distribution corresponding to the target user, the method further includes: Obtain multiple historical login locations of the target user within a second historical time period, and each historical login location corresponds to a historical login behavior of the target user; Obtain corresponding multiple historical login distances according to the multiple historical login locations; the historical login distance is the distance between each historical login location and the logged-in server address; Perform spatial clustering on the multiple historical login distances to obtain multiple login distance intervals; Count the number of historical login distances of the target user in each login distance interval within the second historical time period, and obtain the historical login location probability distribution; The determining of the login location anomaly probability corresponding to the current login behavior of the target user according to the current login location and based on the historical login location probability distribution corresponding to the target user includes: For the target user, determine the current login distance according to the current login location and the previous login location of the current login location; According to the login distance interval to which the current login distance belongs and the historical login location probability distribution, determine the login location anomaly probability corresponding to the current login behavior of the target user.
5. The method according to claim 1, characterized in that, Before determining the login time interval anomaly probability corresponding to the current login behavior of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user and based on the historical login time interval probability distribution of the target user, the method further includes: Obtain multiple historical login time points of the target user within a third historical time period; wherein, each historical login time point corresponds to a historical login behavior of the target user; Obtain multiple historical login time intervals according to the multiple historical login time points, and the historical login time interval is the time interval between each login behavior of the target user and the previous login behavior; Obtain the standard deviation and average value of the multiple historical login time intervals, and based on the standard deviation and average value, obtain the probability distribution of the historical login time intervals of the target user; The determining the abnormal probability of the login time interval corresponding to the current login behavior of the target user based on the probability distribution of the historical login time intervals of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user includes: Determine the abnormal probability of the consecutive login time intervals corresponding to the current login behavior of the target user according to the current login time interval between the current login time point and the previous login time of the current target user and the probability distribution of the historical login time intervals.
6. The method according to claim 1, characterized in that, Before the method determines the abnormal probability of server migration that the current login behavior represents a transfer from the previous server to the current server based on the historical login state transition matrix corresponding to the target user and according to the current server identifier and the previous server identifier by obtaining the previous server identifier of the previous server logged in by the previous login behavior of the target user, the method further includes: Obtain multiple historical login server identifiers corresponding to the target user within a fourth historical time period, and each historical login server logged in by each historical login behavior corresponds to a historical login server identifier; According to the multiple historical login server identifiers, obtain the probability of login transfer occurring between two consecutive historical login behaviors of the target user corresponding to a target historical login server identifier group, and obtain an initial login state transition matrix; wherein, each target historical login server identifier group contains two target historical login server identifiers, and the target historical login server identifier is included in the set of target historical login server identifiers; Perform normalization processing on the initial login state transition matrix to obtain a historical login state transition matrix.
7. The method according to claim 6, characterized in that The obtaining the probability of login transfer occurring between two consecutive historical login behaviors of the target user corresponding to a target historical login server identifier group according to the multiple historical login server identifiers and obtaining an initial login state transition matrix includes: Remove duplicates from the multiple historical login server identifiers to obtain a set of target historical login server identifiers; Generate multiple target historical login server identifier groups according to the set of target historical login server identifiers; Calculate the historical login server transfer probability that the target user logs in to the two historical login servers corresponding to each target historical login server identifier group in sequence according to the historical login server identifiers corresponding to the two consecutive historical login behaviors of the target user; Generate an initial login state transition matrix based on the multiple target historical login server identifier groups and the historical login server transfer probability corresponding to each target historical login server identifier group.
8. An apparatus for identifying abnormal user login behavior, characterized in that, The device includes: An obtaining module, configured to obtain current login information corresponding to the current login behavior of the target user, where the login information includes the current login time point, the current login location, and the current server identifier of the current server logged in by the target user corresponding to the current login behavior; The first calculation module is configured to determine the login time anomaly probability corresponding to the current login behavior of the target user based on the historical login time point probability distribution corresponding to the target user according to the current login time point; The second calculation module is configured to determine the login location anomaly probability corresponding to the current login behavior of the target user based on the historical login location probability distribution corresponding to the target user according to the current login location; The third calculation module is configured to determine the login time interval anomaly probability corresponding to the current login behavior of the target user based on the historical login time interval probability distribution of the target user according to the login time interval between the current login behavior and the previous login behavior of the target user; The fourth calculation module is configured to obtain the prior server identifier of the prior server logged in by the previous login behavior of the target user, and based on the historical login state transition matrix corresponding to the target user, and according to the current server identifier and the prior server identifier, determine the server migration anomaly probability that the current login behavior represents a transfer from the prior server to the current server; The anomaly recognition module is configured to multiply the login time anomaly probability, the login location anomaly probability, the login time interval anomaly probability, and the server migration anomaly probability by the corresponding combined weights respectively and then sum them to obtain the current login behavior anomaly probability of the target user; when the current login behavior anomaly probability is less than the preset login behavior anomaly probability threshold, the current login behavior of the target user is normal; when the current login behavior anomaly probability is greater than the preset login behavior anomaly probability threshold, the current login behavior of the target user is abnormal.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Account exception detection method based on user login behavior
CN110445790A
Intelligent detection method and detection system for server exception of hybrid strategy
CN111061620A