Risk propagation detection method and device, electronic equipment and storage medium

By constructing a node network and calculating the propagation risk value, the problem of assessing the security of unknown data is solved, and a more stable and reliable risk propagation detection is achieved.

CN114386861BActive Publication Date: 2025-10-24SHANJIE INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210046065.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-14
Publication Date
2025-10-24
Estimated Expiration
2042-01-14

Smart Images

  • Figure CN114386861B_ABST
    Figure CN114386861B_ABST
Patent Text Reader

Abstract

The application provides a risk propagation detection method and device, electronic equipment and storage medium, and relates to the technical field of information security. The risk propagation detection method of the application constructs a node network of to-be-predicted data, calculates the propagation risk values of other nodes except preset nodes in the node network, and then: according to the propagation risk values of the other nodes, determines whether the other nodes are nodes with abnormal risk propagation. The node network is constructed by using the fields in the to-be-predicted data, and then the propagation risk values of the other nodes are calculated by referring to the propagation risk values of the preset nodes in the node network, and then the nodes with abnormal risk propagation are detected according to the propagation risk values of the other nodes. The detection method for data risk propagation is optimized, so that the detection is more stable and the detection result is more reliable.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, in particular to a risk propagation detection method and device, electronic equipment and storage medium. BACKGROUND

[0002] With the rapid development of informatization, data information plays an increasingly important role, and the diversification of data information puts forward higher requirements for information security.

[0003] In the case of known data security, how to analyze the security of other data has always been the focus of research in the field of information security. SUMMARY

[0004] The present application aims to provide a risk propagation detection method and device, electronic equipment and storage medium to analyze the security of other data through the security of known data, in order to overcome the deficiencies of the prior art.

[0005] To achieve the above object, the technical scheme adopted by the embodiments of the present application is as follows:

[0006] In a first aspect, the embodiments of the present application provide a risk propagation detection method, comprising: constructing a node network of to-be-predicted data, wherein a plurality of nodes in the node network are a plurality of fields in the to-be-predicted data, and an edge relationship between each two nodes in the node network is used to represent an association relationship between the corresponding fields of the each two nodes in the to-be-predicted data;

[0007] calculating a propagation risk value of other nodes in the node network except a preset node, wherein the preset node is a node with known propagation risk;

[0008] determining whether the other nodes are risk propagation abnormal nodes according to the propagation risk value of the other nodes.

[0009] Optionally, the calculating the propagation risk value of the other nodes in the node network except the preset node comprises:

[0010] calculating a basic risk value of the other nodes according to the distance between the preset node and the other nodes;

[0011] calculating a one-hop propagation risk value between the other nodes and neighbor nodes of the other nodes in the node network according to the risk level of the neighbor nodes and the basic risk value of the other nodes, wherein the risk level of the neighbor nodes is used to represent the propagation risk of the neighbor nodes;

[0012] calculating the propagation risk value of the other nodes according to the basic risk value of the other nodes and the one-hop propagation risk value.

[0013] Optionally, the calculating the base risk value of the other node according to the number of edge relationships between the preset node and the other node comprises:

[0014] calculating the base risk value of the other node according to the distance between the preset node and the other node and the preset weight corresponding to the risk level of the preset node.

[0015] Optionally, the preset node comprises a node with a risk propagation and a node without a risk propagation; the node without a risk propagation is a node with a resistance to risk propagation; the calculating the base risk value of the other node according to the number of edge relationships between the preset node and the other node comprises:

[0016] if the node with a risk propagation is multiple, calculating multiple first risk propagation values of the other node according to the distance between the multiple nodes with a risk propagation and the other node;

[0017] if the node without a risk propagation is multiple, calculating multiple second risk propagation values of the other node according to the distance between the multiple nodes without a risk propagation and the other node;

[0018] calculating the base risk value of the other node according to the maximum risk propagation value in the multiple first risk propagation values and the minimum risk propagation value in the multiple second risk propagation values.

[0019] Optionally, the calculating the one-hop risk propagation value between the other node and the neighbor node according to the risk level of the neighbor node of the other node in the node network comprises:

[0020] calculating two one-hop risk propagation values between the other node and the neighbor node and between the adjacent node and the neighbor node according to the risk level of the neighbor node of the other node in the node network and the risk level of the neighbor node of the adjacent node of the other node in a propagation direction, respectively;

[0021] calculating the one-hop risk propagation value according to the two one-hop risk propagation values.

[0022] Optionally, if the preset node comprises a black node, the black node is a node with the maximum risk propagation level; the method further comprises:

[0023] calculating a risk propagation value between the other node and the black node according to the number of edge relationships between the black node and the other node;

[0024] The calculating the one-hop propagation risk value comprises:

[0025] The calculating the one-hop propagation risk value comprises:

[0026] Optionally, the neighbor nodes comprise: a known propagation risk neighbor node and an unknown propagation risk neighbor node.

[0027] The calculating the two one-hop propagation risk values comprises:

[0028] The calculating the third propagation risk value comprises:

[0029] The calculating the fourth propagation risk value comprises:

[0030] The calculating the one-hop propagation risk value comprises:

[0031] In a second aspect, an embodiment of the present application further provides a risk propagation detection device, comprising: a constructing module, a calculating module and a judging module; the constructing module is configured to construct a node network of to-be-predicted data, wherein a plurality of nodes in the node network are a plurality of fields in the to-be-predicted data, and an edge relationship between each two nodes in the node network is used to represent an association relationship between the fields corresponding to the each two nodes in the to-be-predicted data.

[0032] The calculating module is configured to calculate a propagation risk value of other nodes except a preset node in the node network; wherein the preset node is a known propagation risk node.

[0033] The judging module is configured to determine whether the other nodes are risk propagation abnormal nodes according to the propagation risk values of the other nodes.

[0034] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: a processor, a storage medium and a bus, the storage medium stores program instructions executable by the processor, when the electronic device is running, the processor and the storage medium communicate through the bus, and the processor executes the program instructions to execute the steps of the risk propagation detection method in the first aspect.

[0035] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, wherein the storage medium stores a computer program, and the computer program is run by a processor to perform the steps of the risk propagation detection method according to any one of the first aspect.

[0036] The present application has the beneficial effects that: the embodiments of the present application provide a risk propagation detection method, by constructing a node network of to-be-predicted data, calculating the propagation risk values of other nodes except preset nodes in the node network, and then: determining whether the other nodes are abnormal nodes of risk propagation according to the propagation risk values of the other nodes. The node network is constructed by using the fields in the to-be-predicted data, and then the propagation risk values of the other nodes are calculated by referring to the propagation risk values of the preset nodes in the node network, and then the abnormal nodes of risk propagation are detected according to the propagation risk values of the other nodes. The detection method for data risk propagation is optimized, so that the detection is more stable and the detection result is more reliable. BRIEF DESCRIPTION OF DRAWINGS

[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation to the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0038] Figure 1 A flowchart of a risk propagation detection method provided by an embodiment of the present application;

[0039] Figure 2 A flowchart of a method for calculating the propagation risk values of other nodes in a risk propagation detection method provided by another embodiment of the present application;

[0040] Figure 3 A flowchart of a method for calculating the basic risk values of other nodes in a risk propagation detection method provided by another embodiment of the present application;

[0041] Figure 4 A flowchart of a method for calculating one-hop propagation risk values in a risk propagation detection method provided by another embodiment of the present application;

[0042] Figure 5 A flowchart of a risk propagation detection method provided by another embodiment of the present application;

[0043] Figure 6 A flowchart of a method for calculating two one-hop propagation risk values in a risk propagation detection method provided by another embodiment of the present application;

[0044] Figure 7 A schematic diagram of a risk propagation detection device provided by an embodiment of the present application is shown in FIG. 1.

[0045] Figure 8 A schematic diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 2. DETAILED DESCRIPTION

[0046] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application.

[0047] In the present application, unless otherwise explicitly specified and limited, the terms "first" and "second" are only used for description purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features limited by "first" and "second" can explicitly or implicitly contain at least one feature. In the description in the present application, the meaning of "multiple" is at least two, for example, two, three, unless otherwise explicitly specified and limited. The terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element limited by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.

[0048] For data risk propagation detection, the embodiments of the present application provide a plurality of possible implementation manners to realize the analysis of the security of other data through the security of known data. The following is explained and described through a plurality of examples in combination with the drawings. Figure 1 A flowchart of a risk propagation detection method provided by an embodiment of the present application is shown in FIG. 3. The method can be implemented by an electronic device running the above risk propagation detection method. The electronic device can be a terminal device or a server. As shown in FIG. 3, the method includes the following steps. Figure 1

[0049] Step 101: constructing a node network of to-be-predicted data, wherein a plurality of nodes in the node network are a plurality of fields in the to-be-predicted data, and an edge relationship between each two nodes in the node network is used to represent an association relationship between the corresponding fields of each two nodes in the to-be-predicted data.

[0050] ​It should be noted that the to-be-predicted data includes at least one data that needs to be predicted, which can be collected from various types of data or various log records in actual business, and the specific source of the to-be-predicted data is not limited in the present application. In addition, the to-be-predicted data can include various types of data fields such as user name, operation type, asset ID, client or server information, IP information, operation time, and the specific type of data field contained in the to-be-predicted data is not limited in the present application.

[0051] After obtaining the to-be-predicted data, a node network of the to-be-predicted data is constructed according to the to-be-predicted data. The node network is composed of a plurality of nodes and links connecting the nodes, and represents a network structure of a plurality of objects and their mutual relationships. Each node in the node network can represent a field in the to-be-predicted data (for example, using a log record as the to-be-predicted data, each field of the log record is taken as a node, such as an IP node, an operation type node, etc.). The edge relationship (i.e., the link) between each two nodes in the node network can represent the association relationship between the fields corresponding to the two nodes connected by the link.

[0052] In a possible implementation, since the to-be-predicted data can include repeated data or repeated fields, such data or fields can cause problems such as an increase in the amount of data of the node network, data redundancy, and the like, which are not conducive to subsequent calculation and analysis based on the node network. Therefore, the to-be-predicted data can be de-duplicated to remove the repeated data or repeated fields in the to-be-predicted data, so as to remove the repeated nodes in the node network, so that the same node appears only once in the node network, and the optimization of the node network is achieved. Further, the number of times of node repetition can be saved in the form of a node attribute, and the data of the number of times of repetition can be used in subsequent calculation and analysis.

[0053] In another possible implementation, after obtaining the to-be-predicted data, a complex network of the to-be-predicted data can be constructed according to the to-be-predicted data. The complex network is a network with some or all of the properties of self-organization, self-similarity, attractor, small world, and scale-free. It should be noted that the node network can also have other construction forms, which are not limited in the present application.

[0054] Step 102: calculating a propagation risk value of other nodes in the node network except the preset nodes; wherein, the preset nodes are nodes with known propagation risk values.

[0055] In the node network, there are a part of preset nodes, and the propagation risk values of these types of nodes are known. It should be noted that the preset nodes can be nodes with known propagation risk values set by the user, or nodes with known propagation risk values calculated according to related algorithms, and the specific source of this type of node is not limited in the present application.

[0056] After the preset node is determined, the propagation risk value of other nodes outside the preset node is calculated. Since the propagation risk value of the preset node is known, it can be used as a source of risk propagation or a source of resistance to risk. The propagation risk value of other nodes is calculated. It should be noted that the propagation risk value is a quantitative representation of the risk of node propagation. In actual implementation, the possibility or danger of the risk of node propagation can be represented by the propagation risk value. The quantitative value can be calculated in different ways according to user settings, for example, the distance between each other node and the risk propagation source can be calculated to quantitatively represent the propagation risk value of each other node; the distance between each other node and the risk resistance source can be calculated to quantitatively represent the propagation risk value of each other node; the nodes within a certain range around each other node can be calculated to quantitatively represent the propagation risk value of each other node, and the like. The above is only an example for illustration, which shows that the calculation method of the propagation risk value is various, and the propagation risk value of each other node obtained according to different calculation methods can also be different. The propagation risk value is a quantitative representation of the risk of propagation, and the specific value may be different according to different calculation methods. The specific calculation method of the propagation risk value is not limited in the present application, and the user can flexibly set the node network, as long as the obtained propagation risk value can quantitatively represent the risk of propagation.

[0057] Step 103: Determine whether the other node is a risk propagation abnormal node according to the propagation risk value of the other node.

[0058] After the propagation risk value of the other node is calculated, whether the other node is a risk propagation abnormal node is determined according to the propagation risk value.

[0059] It should be noted that the user can set the judgment standard of the risk propagation abnormal node according to the calculation method of the propagation risk value, the generated node network, and the like. The specific judgment method is not limited in the present application, as long as the risk propagation abnormal node can be judged. For example, the risk threshold can be set to judge the risk propagation abnormal node. If the propagation risk value of the other node is greater than the risk threshold, the other node is determined to be a risk propagation abnormal node. For another example, the propagation risk value of each other node and the propagation risk value of other nodes around it can be summarized to determine whether the other node is a risk propagation abnormal node. The above is only an example for illustration, and other judgment methods of the risk propagation abnormal node can also be used in actual implementation.

[0060] In summary, the embodiment of the present application provides a risk propagation detection method, which comprises the following steps: constructing a node network of to-be-predicted data, calculating a propagation risk value of other nodes in the node network except a preset node, and determining whether the other nodes are abnormal nodes of risk propagation according to the propagation risk value of the other nodes. The node network is constructed by using fields in the to-be-predicted data, and the propagation risk value of the other nodes is calculated by referring to the propagation risk value of the preset node in the node network, so that the abnormal nodes of risk propagation are detected according to the propagation risk value of the other nodes. The detection method of data risk propagation is optimized, so that the detection is more stable and the detection result is more reliable.

[0061] Optionally, on the basis of the above Figure 1 , the present application further provides a possible implementation of the method for calculating the propagation risk value of the other nodes in the risk propagation detection method, Figure 2 a flowchart of the method for calculating the propagation risk value of the other nodes in the risk propagation detection method according to another embodiment of the present application; as shown in Figure 2 step 102: calculating the propagation risk value of the other nodes in the node network except the preset node, comprising:

[0062] Step 201: calculating a basic risk value of the other nodes according to the distance between the preset node and the other nodes.

[0063] It should be noted that the preset node is a node with a known propagation risk value, which can be used as a source of risk propagation or a source of risk resistance. The distance between the other nodes and the preset node can reflect the distance between the other nodes and the source of risk propagation or the source of risk resistance. Generally, the closer the distance to the source of propagation, the greater the possibility of being affected by the source of propagation, and the greater the possibility of risk propagation of the other nodes. Similarly, the closer the distance to the source of resistance, the greater the possibility of being affected by the source of resistance, and the greater the possibility of the other nodes affecting the resistance of the other nodes to risk propagation. Therefore, the basic risk value of the other nodes can be calculated according to the distance between the preset node and the other nodes.

[0064] In a possible implementation, the base risk value of the other node can be calculated according to the distance between the preset node and the other node (for example, the reciprocal of the distance between the preset node and the other node can be taken as the base risk value of the other node). In this case, if there are multiple preset nodes in the node network, the distance between the multiple preset nodes and the other node can be obtained, and the base risk value of the other node can be obtained. The multiple values can be analyzed or calculated, and the base risk value can be obtained. For example, the maximum value of the multiple values can be taken as the base risk value of the other node, or the average value of the multiple values can be taken as the base risk value of the other node, and the like. The specific value of the base risk value in this case is not limited in the present application, and can be set according to the actual data type, node network, and the like.

[0065] It should be further noted that the propagation risk value of the preset node is known, and the base risk value is also known. However, when there is more than one preset node in the node network, the propagation risk value of each preset node can be different, and the base risk value can also be different. For example, the preset nodes can be classified according to the danger of risk propagation or the possibility of risk propagation, and different propagation risk values and base risk values can be set for preset nodes of different levels. When calculating the base risk value of the other node, the base risk value of the corresponding preset node can be used as a weight for calculation, so that the influence of the preset node on the other node is reflected in the base risk value.

[0066] In step 202, a one-hop propagation risk value between the other node and the neighbor node is calculated according to the risk level of the neighbor node of the other node in the node network and the base risk value of the other node, wherein the risk level of the neighbor node is used to represent the propagation risk of the neighbor node.

[0067] It should be noted that the propagation risk value of each other node is not only affected by the preset node, but also affected by the adjacent node, and therefore the adjacent node of the other node needs to be analyzed. In the present application, the propagation risk value of the neighbor node within one hop is calculated by considering the influence range of each node. The neighbor node within one hop can be a neighbor node that transmits data to the other node within one hop, or a neighbor node that receives data transmitted by the other node within one hop, and the specific composition of the neighbor node is not limited in the present application.

[0068] In calculating the one-hop propagation risk value between the other node and the neighbor node, the one-hop propagation risk value can be quantified according to the risk levels of the neighbor nodes of the other node in the node network, the number of each risk level, and the like. For example, different weights can be added to the neighbor nodes of different risk levels, and the one-hop propagation risk of each neighbor node is weighted in the calculation through the weights, and then the one-hop propagation risk value between the other node and the neighbor node is obtained. The above is only an example for illustration, and other calculation methods can also be used in actual implementation, which are not limited in the present application.

[0069] In a specific implementation, for example, it is assumed that the neighbor nodes can include multiple risk levels, which correspond to importance coefficients m1, m2, m3,..., mn (m1, m2, m3,..., mn are any real numbers in the range of (0, 1), and the sum of each term is 1), the number of neighbor nodes corresponding to each risk level is c1, c2, c3,..., cn (c1, c2, c3,..., cn are any natural numbers), and the risk score corresponding to each risk level is l1, l2, l3,..., ln (l1, l2, l3,..., ln are any real numbers). The one-hop propagation risk value of the other node can be represented as:

[0070]

[0071] In addition, the present application calculates the propagation risk value based on one hop, but it can be understood that the scheme of the present application can also be extended to the calculation of the propagation risk value of the multi-hop neighbor node such as the two-hop neighbor node and the three-hop neighbor node. The specific calculation method is as described above, and will not be described here.

[0072] Step 203: Calculate the propagation risk value of the other node according to the one-hop propagation risk value.

[0073] Through the calculation method in step 202, multiple one-hop propagation risk values can be obtained in different neighbor node selection methods and propagation methods, and the propagation risk value of the other node is calculated through the obtained multiple one-hop propagation risk values. For example, one-hop propagation risk values trans1_score, trans2_score, and trans3_score are obtained through different propagation defense lines and propagation methods. The propagation risk value of the other node is calculated through the multiple one-hop propagation risk values. For example, the propagation risk value trans_score of the other node can be the average of the multiple one-hop propagation risk values.

[0074] The above is only an example for illustration, and other calculation methods can also be used to calculate the propagation risk value of the other node through the one-hop propagation risk value, which are not limited in the present application, and the calculation of the propagation risk value can be realized.

[0075] Optionally, on the basis of the above Figure 2 , the application further provides a possible implementation of calculating the basic risk value of the other node in the risk propagation detection method, step 201: calculating the basic risk value of the other node according to the number of edge relationships between the preset node and the other node, including:

[0076] According to the distance between the preset node and the other node, and the preset weight corresponding to the risk level of the preset node, the basic risk value of the other node is calculated.

[0077] In a specific implementation, the basic risk value of the preset node can be set, for example, it is set that there are three levels in the preset node, and the basic risk values are a (for example, a = 1) for the first-level preset node, b (for example, b = 0.8) for the second-level preset node, and c (for example, c = -1) for the third-level preset node (by setting the basic risk value in the form of negative number, the offset of risk propagation in subsequent calculation is realized). On this basis, the basic risk value of the other node can be calculated in the following way:

[0078] The relationship value with the first-level preset node is: The relationship value with the second-level preset node is:

[0079] The relationship value with the third-level preset node is:

[0080] Wherein, is a preset base value, and n is the distance between the current other node and each type of preset node. The larger n is, the farther the distance is. Thus, the basic risk value of the other node can be calculated, and the specific calculation method can be the accumulation of the relationship value of each other node with the first-level preset node, the relationship value with the second-level preset node, and the relationship value with the third-level preset node, or the calculation according to other preset formulas.

[0081] The above is only an example for illustration, and in actual implementation, the basic risk value can also have other calculation methods, which are not limited by the application, and the user can set the calculation method according to actual calculation needs.

[0082] Optionally, on the basis of the above Figure 2 , the preset node includes: a node with risk propagation, and a node without risk propagation, wherein when the node without risk propagation is a node with risk propagation resistance, the application further provides a possible implementation of calculating the basic risk value of the other node in the risk propagation detection method, Figure 3 is a flowchart of a method for calculating the basic risk value of the other node in the risk propagation detection method according to another embodiment of the application; as Figure 3As shown, step 201: according to the number of edge relationships between the preset node and other nodes, the basic risk value of the other nodes is calculated, including:

[0083] Step 301: If there are multiple nodes with risk of propagation, then according to the distance between the multiple nodes with risk of propagation and other nodes, multiple first propagation risk values of the other nodes are calculated.

[0084] It should be noted that the nodes with risk of propagation included in the preset node indicate that the preset node has risk of propagation. However, in the multiple nodes with risk of propagation, the risk propagation ability of each node can be the same or different, and the present application does not limit this.

[0085] If the risk propagation ability of each node with risk of propagation is the same, then according to the distance between the multiple nodes with risk of propagation and other nodes, the first propagation risk value between the other nodes and each node with risk of propagation is calculated to obtain multiple first propagation risk values.

[0086] If the risk propagation ability of each node with risk of propagation is different, then according to the distance between the multiple nodes with risk of propagation and other nodes, the risk propagation ability of each node with risk of propagation, the first propagation risk value between the other nodes and each node with risk of propagation is calculated to obtain multiple first propagation risk values.

[0087] In a specific implementation, the risk propagation ability of the node with risk of propagation can be represented in the form of a positive weight. The greater the value of the positive number, the stronger the risk propagation ability of the preset node. For example, if the nodes with risk of propagation have two types, and the corresponding weights are a and b (a and b can be any positive real number), then according to the weight and the distance between the multiple nodes with risk of propagation and other nodes, multiple first propagation risk values of the other nodes are calculated, for example, the first propagation risk value of the other nodes for the node with risk of propagation with weight a is: (p) n *a;

[0088] The first propagation risk value of the other nodes for the node with risk of propagation with weight b is: (p) n *b;

[0089] Wherein, the value of p is a preset evaluation value. Generally, the evaluation value can represent the risk propagation ability within one hop range. Since the risk propagation generally presents a form of gradual attenuation, generally the value of p is between 【0, 1】, for example, when the value of p is , the first propagation risk value of the other nodes for the node with risk of propagation with weight a is: The first propagation risk value of other nodes for a node with propagation risk of weight b is:

[0090] If there are M nodes with propagation risk of weight a and N nodes with propagation risk of weight b, then the above calculation method can be used to obtain the first propagation risk value of these M nodes with propagation risk of weight a and a certain other node: (r1_1, r1_2, ..., r1_M). The first propagation risk value of these N nodes with propagation risk of weight b and the other node: (r2_1, r2_2, ..., r2_N). In this example, the multiple first propagation risk values ​​obtained are [(r11, r12, ..., r1 M ), (r21, r22, …, r2 N )].

[0091] The above implementation method takes two types of nodes with propagation risks as an example. In actual implementation, the calculation method in the above implementation method can be extended to the implementation method of multiple types of nodes with propagation risks. This application does not limit the number of types of nodes with propagation risks.

[0092] Step 302: If there are multiple nodes without propagation risk, multiple second propagation risk values ​​of other nodes are calculated based on the distances between the multiple nodes without propagation risk and other nodes.

[0093] It should be noted that the node with no transmission risk included in the preset nodes indicates that the preset node does not have a transmission risk. However, among multiple nodes with no transmission risk, the ability of each node to not transmit or resist risk may be the same or different, and this application does not limit this.

[0094] If each node without propagation risk does not propagate or has the same ability to resist risk, the second propagation risk value between the other nodes and each node without propagation risk can be calculated based on the distances between the multiple nodes without propagation risk and other nodes to obtain multiple second propagation risk values.

[0095] If the ability of each node without propagation risk to not propagate or to resist risk is different, the second propagation risk value between other nodes and each node without propagation risk can be calculated based on the distance between multiple nodes without propagation risk and other nodes, and the ability of each node without propagation risk to not propagate or to resist risk, to obtain multiple second propagation risk values.

[0096] In a specific implementation, the non-propagation or risk resistance capability of the node without risk of propagation can be represented in the form of a negative weight, and the greater the absolute value of the negative number, the stronger the non-propagation or risk resistance capability of the preset node. For example, if the nodes without risk of propagation have two types, and the corresponding weights are c and d (c and d can be any positive real number), then according to the weights and the distances between the nodes without risk of propagation and other nodes, a plurality of second propagation risk values of the other nodes are calculated, for example, the second propagation risk value of the other nodes for the node without risk of propagation with weight c is: (q) n *c;

[0097] The second propagation risk value of the other nodes for the node without risk of propagation with weight d is: (q) n *d;

[0098] Where q is a preset evaluation value, which generally represents the risk resistance capability within one hop range. Since the risk resistance capability generally presents a form of gradual decay (i.e., the farther the distance from the preset node with risk resistance capability, the worse the resistance effect), the value of q is generally between 【0, 1】, for example, when q is , the second propagation risk value of the other nodes for the node without risk of propagation with weight c is: , and the second propagation risk value of the other nodes for the node without risk of propagation with weight d is: It should be noted that the values of the risk resistance capability q and the risk propagation capability p can be the same or different, which is not limited in the present application.

[0099] Suppose there are P nodes without risk of propagation with weight c and Q nodes without risk of propagation with weight d, then through the above calculation method, the second propagation risk values of the P nodes without risk of propagation with weight c and a certain other node can be obtained: (r1_1, r1_2, …, r1_P). The second propagation risk values of the Q nodes without risk of propagation with weight d and the other node are: (t2_1, t2_2, …, t2_Q). In this example, the plurality of second propagation risk values obtained are [(t11, t12, …, t1 P ), (t21, t22, …, t2 Q )].

[0100] In the above implementation, two types of nodes without risk of propagation are taken as an example, and in actual implementation, the calculation method in the above implementation can be extended to the implementation of multiple types of nodes without risk of propagation, and the number of types of nodes without risk of propagation is not limited in the present application.

[0101] Step 303: calculating the basic risk value of the other node according to the maximum spreading risk value in the plurality of first spreading risk values and the minimum spreading risk value in the plurality of second spreading risk values.

[0102] The basic risk value of the other node is calculated by taking the maximum spreading risk value in the plurality of first spreading risk values and the minimum spreading risk value in the plurality of second spreading risk values. It should be noted that the application does not limit the calculation method of the specific basic risk value, which can be calculated according to the user's needs.

[0103] In a specific implementation, the basic risk value of the other node can be obtained by calculating the sum of the maximum spreading risk value and the minimum spreading risk value. For example, the plurality of first spreading risk values is [(r11, r12, …, r1 M ), (r21, r22, …, r2 N )] obtained by the above steps, the plurality of second spreading risk values is [(t11, t12, …, t1 P ), (t21, t22, …, t2 Q )], the maximum value in [(r11, r12, …, r1 M ), (r21, r22, …, r2 N )] is risk max , the minimum value in [(t11, t12, …, t1 P ), (t21, t22, …, t2 Q )] is trust max , and the basic risk value of the other node is basic score .

[0104] basic score = risk max + trust max .

[0105] The above is only an example for illustration, and other calculation methods can also be used in actual implementation, which are not limited by the application.

[0106] Optionally, based on the above Figure 2 , the application further provides a possible implementation of calculating a one-hop spreading risk value in a risk spreading detection method, Figure 4 which is a flowchart of a one-hop spreading risk value calculation method in a risk spreading detection method according to another embodiment of the application. As shown in Figure 4 FIG. 2, step 202: calculating a one-hop spreading risk value between the other node and the neighbor node according to the risk level of the neighbor node of the other node in the node network and the basic risk value of the other node, including:

[0107] Step 401: According to the risk levels of the neighbor nodes of other nodes in the node network, the risk levels of the neighbor nodes of the nodes adjacent to the other nodes in the propagation direction, respectively, calculate two one-hop propagation risk values between the other nodes and the neighbor nodes and between the adjacent nodes and the neighbor nodes.

[0108] In a possible implementation, if the one-hop neighbor node is the neighbor node of the other node as the propagation source at a one-hop distance, i.e., the neighbor node of the other node that performs risk propagation of data from the other node, for example, data propagation from the A node to the B node, it is necessary to analyze the risk level of the neighbor node of the A node. If the one-hop neighbor node is the neighbor node of the node adjacent to the other node in the propagation direction at a one-hop distance, i.e., the neighbor node of the node that receives the data sent by the other node, for example, propagation from the A node to the B node, it is necessary to analyze the risk level of the neighbor node of the B node.

[0109] In a specific implementation, for example, it is assumed that the neighbor node can include three risk levels, there are three levels in the preset node, the importance coefficients corresponding to the three risk levels are m1, m2, and m3 respectively, and the basic risk values corresponding to the three risk levels are L1, L2, and L3 respectively. The one-hop propagation risk value can be calculated by weighted accumulation: trans_score_x=m1*L1+m2*L2+m3*L3.

[0110] Through the above steps, trans_score_1 between the one-hop neighbor node of the other node as the propagation source and the other node and trans_score_2 between the one-hop neighbor node which is the neighbor node of the node adjacent to the other node in the propagation direction at a one-hop distance and the other node can be obtained.

[0111] The above is only an example for illustration, and in actual implementation, other calculation methods in the embodiment of step 202 can also be used to calculate the one-hop propagation risk value, which is not limited in the present application.

[0112] In the above implementation, the neighbor node risk level of three levels is taken as an example, and in actual implementation, the calculation method in the above implementation can be extended to the implementation of multiple levels of neighbor node risk level, and the specific number of levels of the neighbor node risk level is not limited in the present application.

[0113] In a specific implementation, if there is a node without propagation risk in the neighbor node, i.e., a neighbor node without the ability of propagation or resistance to risk, the result of the one-hop propagation risk value in each direction calculated according to the above method can be modified, for example, the result can be modified by setting a coefficient or a weight:

[0114]

[0115] Wherein trans_score_x can be trans_score_1 or trans_score_2 described above, μ∈(0,1), and the specific value of μ can be flexibly set according to the judgment condition of the node of risk propagation anomaly and other conditions, and the specific value of μ is not limited in the present application.

[0116] Step 402: Calculate the one-hop propagation risk value according to the two one-hop propagation risk values.

[0117] The one-hop propagation risk value is calculated through the two one-hop propagation risk values obtained in step 401. In a possible implementation manner, the average value of the two one-hop propagation risk values can be taken as the one-hop propagation risk value trans_score.

[0118]

[0119] The above is only an example for illustration, and other calculation manners of the one-hop propagation risk value can also be used in actual implementation, and the present application does not limit this, as long as the calculation of the one-hop propagation risk value can meet the needs of users.

[0120] The risk propagation ability of the neighbor node of the other node can be more accurately evaluated by respectively calculating and then collecting the two one-hop propagation risk values between the other node and the neighbor node and between the neighbor node and the adjacent node.

[0121] Optionally, based on the above Figure 4 , if the preset node includes a black node which is the node with the highest risk propagation level, the present application further provides a possible implementation manner of the risk propagation detection method, Figure 5 a flowchart of a risk propagation detection method provided by the second embodiment of the present application; as shown in Figure 5 , the method comprises:

[0122] Step 501: Calculate the propagation risk value between the other node and the black node according to the number of edge relationships between the black node and the other node.

[0123] It should be noted that the black node is a black list node, which can be obtained from the user upload and other ways. Generally, the black list node can be taken as the propagation source of risk propagation and as the preset node with the highest risk propagation level. Therefore, the risk propagation ability of the black node is the strongest, and the propagation risk value between the other node and the black node can be calculated through the number of edge relationships between the black node and the other node.

[0124] In a possible implementation, the calculation can be performed in the following manner:

[0125] wherein m is the number of edge relationships between the black node and other nodes.

[0126] In another possible implementation, the influence of the black node can be enhanced or weakened by setting the weight of the black node, for example, setting the weight of the black node as h, and the one-hop propagation risk value can be calculated in the following manner:

[0127] wherein m is the number of edge relationships between the black node and other nodes, and h is the weight value of the black node.

[0128] The above is only an example for illustration, and in actual implementation, other calculation manners of the propagation risk value can also be used, which are not limited in the present application.

[0129] Step 402: calculating the one-hop propagation risk value according to the two one-hop propagation risk values, comprising:

[0130] Step 502: calculating the one-hop propagation risk value according to the two one-hop propagation risk values and the propagation risk value between the other nodes and the black node.

[0131] The one-hop propagation risk value is calculated by the two one-hop propagation risk values obtained in step 401 and the propagation risk value between the other nodes and the black node, and in a possible implementation, the average of the two one-hop propagation risk values and the propagation risk value between the other nodes and the black node can be taken as the one-hop propagation risk value trans_score:

[0132]

[0133] In another possible implementation, since the two one-hop propagation risk values and the propagation risk value between the other nodes and the black node obtained in the present application are obtained based on three different evaluation manners, they have different dimensions and dimension units, and if they are directly calculated without processing, the result of data analysis will be affected. In order to eliminate the influence of the dimensions of the three data, data standardization processing is needed to solve the comparability between the data indicators. Thus, the two one-hop propagation risk values obtained are normalized to the range of (0, 1), and the propagation risk value between the other nodes and the black node is related to the reciprocal of the distance, so the values of the three propagation risk values are all in the range of (0, 1), that is, the two one-hop propagation risk values and the propagation risk value between the other nodes and the black node after normalization are in the same order of magnitude, and thus the one-hop propagation risk value trans_score can be normalized in the above manner:

[0134]

[0135] The above is only an example, and in actual implementation, other calculation methods of the one-hop propagation risk value can also be used, and the application does not limit this, as long as the calculation of the one-hop propagation risk value can meet the needs of users.

[0136] The two one-hop propagation risk values and the propagation risk values between other nodes and the black node are calculated and summarized respectively, and the risk propagation ability is evaluated, so that the result is more accurate and representative.

[0137] Optionally, based on the above Figure 4 , if the neighbor nodes include known propagation risk neighbor nodes and unknown propagation risk neighbor nodes, the application further provides a possible implementation of calculating two one-hop propagation risk values in a risk propagation detection method, Figure 6 a flowchart of a method for calculating two one-hop propagation risk values in a risk propagation detection method according to a third embodiment of the application; as shown in Figure 6 step 401: according to the risk levels of the neighbor nodes of other nodes in the node network and the risk levels of the neighbor nodes of the adjacent nodes of other nodes in the propagation direction, respectively calculating two one-hop propagation risk values between other nodes and neighbor nodes and between adjacent nodes and neighbor nodes, including:

[0138] Step 601: calculating a third propagation risk value between other nodes and known propagation risk neighbor nodes according to the risk levels of the known propagation risk neighbor nodes.

[0139] It should be noted that the known propagation risk neighbor nodes can be user-set known propagation risk nodes (such as blacklisted nodes), or can be known propagation risk nodes calculated according to related algorithms (such as detecting isomers in the node network according to an isomer detection algorithm, and taking the hit nodes as known propagation risk nodes), and the application does not limit the specific source of this type of node.

[0140] In a possible implementation, the risk levels of the known propagation risk neighbor nodes can be embodied in the form of a weight coefficient, for example, there are two levels of known propagation risk neighbor nodes, and the weight coefficients are x and y (x and y can be any real number, for example, one level of node coefficient is set to 0.5, and the coefficient of the second level of node is 0.25). On this basis, the third propagation risk value between other nodes and known propagation risk neighbor nodes is calculated as follows:

[0141] trans_score_rd=c1*x*level1_score+c2*y*level2_score

[0142] Wherein, c represents the number of each risk level node in the neighbor node, c1 represents the number of the first level node, c2 represents the number of the second level node, and level_score represents the risk score of the level node. For the neighbor node with known propagation risk, this value can be set by the user according to actual needs, for example, it can be the basic risk value corresponding to the neighbor node with known propagation risk, for example, the basic risk value corresponding to the first level node can be a (as set above a = 1), and the basic risk value corresponding to the second level node can be b (as set above b = 0.8).

[0143] After substituting the set weight coefficient and the propagation risk of the neighbor node with known propagation risk:

[0144] trans_score_rd = c1*0.5*1 + c2*0.25*0.8

[0145] The above is only an example for illustration. In actual implementation, the neighbor node with known propagation risk can also include a node without propagation risk, i.e., a neighbor node (or a white list node) without the ability to propagate or resist risk. In this case, the trans_score_rd can be modified according to the method of step 401, and the specific modification method is as described in step 401, which will not be described here.

[0146] Step 602: According to the distance between the neighbor node with unknown propagation risk and the preset node, a fourth propagation risk value of the neighbor node with unknown propagation risk is calculated.

[0147] In a possible implementation, the weight coefficient of the neighbor node with unknown propagation risk can be set. In a possible implementation, the weight coefficient of the neighbor node with unknown propagation risk can be set together with the weight coefficient of the neighbor node with known propagation risk in step 601. For example, the sum of all weight coefficients of the weight coefficient of the neighbor node with unknown propagation risk and the weight coefficient of the neighbor node with known propagation risk in step 601 can be set to 1, so as to realize the normalization setting of the weight coefficient. For example, there are two neighbor nodes with known propagation risk, and the weight coefficients are x and y respectively, and the weight coefficient of one neighbor node with unknown propagation risk is z (x, y, and z can be any real number, for example, it is set that x = 0.5, y = 0.25, and z = 0.25). The above is only an example for illustration. In actual implementation, there can be other implementation manners, which are not limited by the present application.

[0148] In a possible implementation, the fourth transmission risk value trans_score_th of the neighbor node with unknown transmission risk can be calculated according to the above-mentioned weight, the distance between the neighbor node with unknown transmission risk and the preset node, and the distance between the neighbor node with unknown transmission risk and the preset node. The specific calculation process can refer to step 601, and details are not described herein.

[0149] In another possible implementation, on the basis of the above-mentioned weight setting, before the fourth transmission risk value trans_score_th of the neighbor node with unknown transmission risk is calculated according to the distance between the neighbor node with unknown transmission risk and the preset node, a set of weight coefficients satisfying convex combination can be further set, which is named as step weight coefficient. The step weight coefficient represents the weight corresponding to each preset node for each neighbor node with unknown transmission risk, and can be set according to the following manner:

[0150] For each neighbor node with unknown transmission risk, the distance between the neighbor node and the preset node is counted, for example, the distance (i.e., the number of edge relationships between the neighbor node and the preset node) between a certain neighbor node with unknown transmission risk and E preset nodes in the node network is l1_1, l1_2, …, l1_M. The sum of all distances is obtained as follows:

[0151]

[0152] The step weight coefficient x i is set as:

[0153]

[0154] Therefore, the fourth transmission risk value trans_score_th of the neighbor node with unknown transmission risk is calculated as:

[0155]

[0156] On this basis, if the distance (i.e., the number of edge relationships between the neighbor node and the preset node) between the neighbor node with unknown transmission risk and E preset nodes in the node network is l1_1, l1_2, …, l1_M, and all the above-mentioned distance values are not repeated, the number of preset nodes with distances l1_1, l1_2, …, l1_M is E_1, E_1, …, E_M, respectively, where E_1, E_1, …, E_M can be any non-negative integer. In this case, the fourth transmission risk value trans_score_th of the neighbor node with unknown transmission risk can be:

[0157]

[0158] Wherein, the level_score represents the risk score of the level node, and for the neighbor node with unknown propagation risk, the basic risk value thereof can be taken as the risk score, thereby introducing the basic risk value of each node into the calculation of the one-hop propagation risk value, further perfecting the calculation method of the one-hop propagation risk value, and making the one-hop propagation risk value more comprehensively represent the propagation risk of each other node.

[0159] It should be noted that, in addition to the above calculation step weight coefficient x i , the value setting method can also be used, for example, for a propagation path with a length of 3, i.e. the number of edge relationships between the neighbor node and the preset node is 3, the importance weight of the internal node can be set to 0.25 under the premise that the overall third-level risk node importance weight is 0.25. The internal importance weight can be fine-tuned according to the actual situation under the premise of satisfying the convex combination. This result is combined with the first and second level nodes to calculate the subsequent risk propagation score. The weight coefficients of the neighbor nodes with unknown propagation risk are 0.6, 0.3, and 0.1 respectively, and the risk score of each node on this propagation path is level3_1, level3_2, and level3_3, then the fourth propagation risk value trans_score_th of this propagation path can be:

[0160] 0.25*(0.6*level3_1+0.3*level3_2+0.1*level3_3).

[0161] Under the premise that the overall weight coefficient is 0.25, the internal node further divides the importance weight according to the distance from the propagation source, i.e. sets the step weight coefficient x i . The step weight coefficient x i can be fine-tuned according to the actual situation under the premise of satisfying the convex combination.

[0162] Step 603: calculating a one-hop propagation risk value according to the third propagation risk value and the fourth propagation risk value.

[0163] The third propagation risk value and the fourth propagation risk value obtained through steps 601 and 602 are used to calculate the one-hop propagation risk value. In one possible implementation manner, the average value of the third propagation risk value and the fourth propagation risk value can be taken as the one-hop propagation risk value trans_score:

[0164] The above is only an example for illustration, and in actual implementation, other calculation methods of the one-hop propagation risk value can also be used, which are not limited in the present application, as long as the calculation of the one-hop propagation risk value can meet the needs of users.

[0165] In a possible implementation, on the basis of taking the basic risk value of each neighbor node as the risk score, a loop iteration calculation can also be set, through which the accuracy of identifying abnormal nodes is further enhanced. Specifically, after a round of calculation of the node network by taking the basic risk value of each neighbor node as the risk score, the one-hop propagation risk value obtained in the previous round of calculation (i.e., the value obtained in step 603) can be used as the risk score for calculation in the subsequent round of calculation. In this iterative manner, the one-hop propagation risk value of each other node is changing, and thus the nodes determined to be abnormal in risk propagation also change in each round. After multiple rounds of iteration, the system tends to converge, and when the nodes determined to be abnormal in risk propagation in the previous round are consistent with the nodes determined to be abnormal in risk propagation in the subsequent round, that is, the nodes determined to be abnormal in risk propagation in the previous two rounds no longer change, the final nodes determined to be abnormal in risk propagation are determined.

[0166] By calculating and then collecting the third propagation risk value between the other node and the neighbor node with known propagation risk and the fourth propagation risk value of the neighbor node with unknown propagation risk, the risk propagation ability of the neighbor node of the other node can be evaluated, and thus the one-hop risk propagation value of the other node can be more accurately evaluated.

[0167] Optionally, on the basis of calculating the one-hop propagation risk value, the calculation result can also be normalized to the range of [0, 1], so that the result is more intuitive.

[0168] Overall, on the basis of the known part of the node propagation risk, each field in the to-be-predicted data is taken as a node to form a node network, and the node determined to be abnormal in risk propagation is detected. The influence of the authoritative node in opinion dynamics is used for reference, and the nodes in the node network can be further equally planned, so that the detection of the node determined to be abnormal in risk propagation is more accurate and reliable.

[0169] The following describes the risk propagation detection apparatus, electronic device, and storage medium provided in the present application, and the specific implementation process and technical effects are described above, and thus will not be described again.

[0170] The present application provides a possible implementation example of a risk propagation detection apparatus, which can perform the risk propagation detection method provided in the above embodiments. Figure 7 A schematic diagram of a risk propagation detection apparatus provided in an embodiment of the present application is shown in FIG. 1. Figure 7As shown, the above-mentioned risk propagation detection device 100 includes: a construction module 71, a calculation module 73, and a judgment module 75; the construction module 71 is used to construct a node network of the data to be predicted, wherein the multiple nodes in the node network are multiple fields in the data to be predicted, and the edge relationship between each two nodes in the node network is used to characterize the association relationship between the corresponding fields of each two nodes in the data to be predicted; the calculation module 73 is used to calculate the propagation risk value of other nodes other than the preset nodes in the node network; wherein the preset nodes are nodes with known propagation risk values; the judgment module 75 is used to determine whether other nodes are nodes with abnormal risk propagation based on the propagation risk values ​​of other nodes.

[0171] Optionally, the calculation module 73 is also used to calculate the basic risk value of other nodes based on the distance between the preset node and other nodes; calculate the one-hop propagation risk value between other nodes and neighboring nodes based on the risk level of the neighboring nodes of other nodes in the node network, wherein the risk level of the neighboring node is used to characterize the propagation risk of the neighboring node; calculate the propagation risk value of other nodes based on the basic risk value of other nodes and the one-hop propagation risk value.

[0172] Optionally, the calculation module 73 is further configured to calculate basic risk values ​​of other nodes according to the distance between the preset node and the other nodes, and the preset weights corresponding to the risk levels of the preset nodes.

[0173] Optionally, the preset nodes include: nodes with propagation risks, and nodes without propagation risks; wherein, nodes without propagation risks are nodes with the function of resisting risk propagation; the calculation module 73 is also used to calculate multiple first propagation risk values ​​of other nodes based on the distances between the multiple nodes with propagation risks and other nodes if there are multiple nodes with propagation risks; if there are multiple nodes without propagation risks, calculate multiple second propagation risk values ​​of other nodes based on the distances between the multiple nodes without propagation risks and other nodes; calculate the basic risk value of other nodes based on the maximum propagation risk value among the multiple first propagation risk values ​​and the minimum propagation risk value among the multiple second propagation risk values.

[0174] Optionally, the calculation module 73 is also used to calculate the two one-hop propagation risk values ​​between other nodes and neighboring nodes, and between adjacent nodes and neighboring nodes based on the risk levels of neighboring nodes of other nodes in the node network and the risk levels of neighboring nodes of adjacent nodes in the propagation direction of other nodes; and calculate the one-hop propagation risk value based on the two one-hop propagation risk values.

[0175] Optionally, the preset node includes a black node, when the black node is a node with the largest risk propagation level, the computing module 73 is further configured to calculate a propagation risk value between the other node and the black node according to a number of edge relationships between the black node and other nodes; and the computing module 73 is further configured to calculate a one-hop propagation risk value according to the two one-hop propagation risk values and the propagation risk value between the other node and the black node.

[0176] Optionally, when the neighbor nodes include known propagation risk neighbor nodes and unknown propagation risk neighbor nodes, the computing module 73 is further configured to calculate a third propagation risk value between the other node and the known propagation risk neighbor node according to a risk level of the known propagation risk neighbor node; calculate a fourth propagation risk value of the unknown propagation risk neighbor node according to a distance between the unknown propagation risk neighbor node and the preset node; and calculate a one-hop propagation risk value according to the third propagation risk value and the fourth propagation risk value.

[0177] The apparatus is configured to execute the method provided by the foregoing embodiments, and has similar implementation principles and technical effects, which will not be described here. The above modules can be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), and the like. For another example, when the above module is implemented in the form of a processing element scheduling code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call code. For another example, the modules can be integrated together to implement a system-on-a-chip (SOC).

[0178] The embodiment of the present application provides a possible implementation example of an electronic device, which can execute the risk propagation detection method provided by the foregoing embodiments. Figure 8 A schematic diagram of an electronic device provided by the embodiment of the present application is provided, which can be integrated in a terminal device or a chip of the terminal device. The terminal device can be a computing device with a data processing function.

[0179] The electronic device includes a processor 801, a storage medium 802, and a bus. The storage medium stores processor-executable program instructions. When the control device is running, the processor communicates with the storage medium through the bus. The processor executes the program instructions to perform the steps of the risk propagation detection method described above. The specific implementation and technical effects are similar, and will not be described here.

[0180] The embodiments of the application provide a possible implementation example of a computer-readable storage medium, which can execute the risk propagation detection method provided by the embodiments described above. The computer program stored on the storage medium is executed by the processor to perform the steps of the risk propagation detection method described above. The computer program stored in one storage medium can include a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) execute part of the steps of the method of each embodiment of the application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (English: Read-Only Memory, abbreviated as: ROM), a random access memory (English: Random Access Memory, abbreviated as: RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0181] In several embodiments of the application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0182] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0183] In addition, the functional units in each embodiment of the application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of hardware plus software function unit.

[0184] The integrated unit in the form of software function unit can be stored in a computer readable storage medium. The software function unit is stored in a storage medium, and includes a plurality of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute part of steps of the method according to various embodiments of the present application. The storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various storage media capable of storing program codes.

[0185] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of the changes or replacements within the technical range disclosed by the present application, which should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of risk propagation detection, characterized in that, The method comprises the following steps: constructing a node network of to-be-predicted data, wherein the to-be-predicted data is derived from various log records in actual business; a plurality of nodes in the node network are a plurality of fields in the to-be-predicted data, an edge relationship between each two nodes in the node network is used to represent an association relationship of the corresponding fields of the each two nodes in the to-be-predicted data; and the plurality of fields in the to-be-predicted data comprise a user name, an operation type, an asset ID, IP information and an operation time; calculating a propagation risk value of other nodes in the node network except preset nodes; wherein the preset nodes are nodes with known propagation risk values; and determining whether the other nodes are nodes with abnormal risk propagation according to the propagation risk values of the other nodes; wherein the calculation of the propagation risk value of the other nodes in the node network except the preset nodes comprises: calculating a basic risk value of the other nodes according to a distance between the preset nodes and the other nodes; the distance is the number of edge relationships; calculating a one-hop propagation risk value between the other nodes and neighbor nodes of the other nodes in the node network according to a risk level of the neighbor nodes and the basic risk value of the other nodes, wherein the risk level of the neighbor nodes is used to represent a propagation risk of the neighbor nodes; calculating the propagation risk value of the other nodes according to the one-hop propagation risk value; wherein the preset nodes comprise nodes with a propagation risk and nodes without a propagation risk; wherein the nodes without a propagation risk are nodes with a resistance to risk propagation; and the calculation of the basic risk value of the other nodes according to the distance between the preset nodes and the other nodes comprises: if the nodes with a propagation risk are a plurality of nodes, then calculating a plurality of first propagation risk values of the other nodes according to distances between the plurality of nodes with a propagation risk and the other nodes; if the nodes without a propagation risk are a plurality of nodes, then calculating a plurality of second propagation risk values of the other nodes according to distances between the plurality of nodes without a propagation risk and the other nodes; calculating the basic risk value of the other nodes according to a maximum propagation risk value in the plurality of first propagation risk values and a minimum propagation risk value in the plurality of second propagation risk values.

2. The method of claim 1, wherein, the calculation of the basic risk value of the other nodes according to the distance between the preset nodes and the other nodes comprises: calculating the basic risk value of the other nodes according to the distance between the preset nodes and the other nodes and a preset weight corresponding to a risk level of the preset nodes.

3. A risk propagation detection apparatus characterized by comprising: The method comprises the following steps: a constructing module, a calculating module and a judging module; The construction module is configured to construct a node network of to-be-predicted data, wherein the to-be-predicted data is derived from various log records in actual business; a plurality of nodes in the node network are a plurality of fields in the to-be-predicted data, and an edge relationship between each two nodes in the node network is used to represent an association relationship of the corresponding fields of the each two nodes in the to-be-predicted data; and the plurality of fields in the to-be-predicted data include a user name, an operation type, an asset ID, IP information, and an operation time. The calculation module is configured to calculate a propagation risk value of other nodes in the node network except for preset nodes; wherein the preset nodes are nodes with known propagation risk values. The judgment module is configured to determine whether the other nodes are nodes with abnormal risk propagation according to the propagation risk values of the other nodes. The calculation module is specifically configured to: calculate a basic risk value of the other nodes according to a distance between the preset nodes and the other nodes; the distance is a number of edge relationships; calculate a one-hop propagation risk value between the other nodes and neighbor nodes of the other nodes in the node network according to risk levels of the neighbor nodes and the basic risk value of the other nodes, wherein the risk levels of the neighbor nodes are used to represent propagation risks of the neighbor nodes; and calculate the propagation risk value of the other nodes according to the one-hop propagation risk value. The preset nodes include nodes with propagation risks and nodes without propagation risks; the nodes without propagation risks are nodes with resistance to risk propagation; and the calculation module is specifically configured to: if the nodes with propagation risks are a plurality of nodes, calculate a plurality of first propagation risk values of the other nodes according to distances between the plurality of nodes with propagation risks and the other nodes; if the nodes without propagation risks are a plurality of nodes, calculate a plurality of second propagation risk values of the other nodes according to distances between the plurality of nodes without propagation risks and the other nodes; and calculate the basic risk value of the other nodes according to a maximum propagation risk value in the plurality of first propagation risk values and a minimum propagation risk value in the plurality of second propagation risk values.

4. An electronic device, comprising: The processor, the storage medium, and the bus are included. The storage medium stores program instructions executable by the processor, and the processor and the storage medium communicate through the bus when the electronic device is running.

5. A computer readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by the processor to perform the steps of the risk propagation detection method according to any one of claims 1 to 2.

Citation Information

Patent Citations

  • To-be-calibrated node marking method and device

    CN110796394A