Abnormal operation behavior detection method, device, equipment and storage medium

By analyzing the database operation log, calculating the abnormal scores of user operation behaviors in each unit time period, and using an ordered weighted average algorithm, the problem of the inability to identify potential abnormal operations in the prior art is solved, and effective detection of potential abnormal operations is achieved.

CN114661568BActive Publication Date: 2025-07-01CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210276220.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-21
Publication Date
2025-07-01
Estimated Expiration
2042-03-21

AI Technical Summary

Technical Problem

The prior art can only detect abnormalities or attacks that have occurred, and cannot be effectively identified for abnormal operations that have a great potential harm but have few occurrences in history.

Method used

By collecting the original operation log of the target user on the database, determining the number of user operation behaviors in each unit time period based on the structured query statement, calculating the abnormal scores of the time period, and using the ordered weighted average operator for weighted average, determining the abnormal scores of the data to determine whether there are abnormal operation behaviors.

Benefits of technology

There is no need to manually label massive historical data, and abnormal behavior detection can be performed in the case of unbalanced positive and negative samples, improving the ability to identify potential abnormal operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114661568B_ABST
    Figure CN114661568B_ABST
Patent Text Reader

Abstract

The present application provides an abnormal operation behavior detection method, device, equipment and storage medium. The specific solution includes: collecting the first original log of the operations of the target user on the database within the first time range; determining the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log; determining the time period anomaly score of each unit time period according to the number of various user operation behaviors in each unit time period; using an ordered weighted average operator to perform an ordered weighted arithmetic average on the time period anomaly scores to determine the data anomaly score of the target user within the first time range; and determining whether the target user has abnormal operation behaviors according to the data anomaly score. By converting the number of various user operation behaviors into a data anomaly score and judging whether the data anomaly score of the target user is abnormal, the operation behaviors that do not conform to the operation habits of the target user can be determined as abnormal operation behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method, apparatus, device, and storage medium for detecting abnormal operation behaviors. Background Art

[0002] A large amount of sensitive data is stored in a database. To prevent the leakage of sensitive data, it is necessary to detect abnormal operation behaviors of database users.

[0003] Currently, the main method for detecting abnormal operation behaviors of database users is as follows: Set operation metrics and operation metric thresholds according to previously occurred operation anomalies or attacks, count the number of operations corresponding to the operation metrics, calculate year-on-year and month-on-month ratios and compare them with the operation metric thresholds. If the year-on-year or month-on-month ratio is abnormal, or the number of operations exceeds the operation metric threshold, it is determined that the database user has abnormal operation behaviors.

[0004] However, since operation metrics and operation metric thresholds are manually set in the prior art, only previously occurred anomalies or attacks can be detected, and abnormal operations with great potential harm but few historical occurrences cannot be effectively identified. Summary of the Invention

[0005] This application provides a method, apparatus, device, and storage medium for detecting abnormal operation behaviors, so as to solve the problem that only previously occurred anomalies or attacks can be detected, and abnormal operations with great potential harm but few historical occurrences cannot be effectively identified.

[0006] In a first aspect, this application provides a method for detecting abnormal operation behaviors, including:

[0007] Collect first original logs of a target user's operations on a database within a first time range;

[0008] Determine the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original logs;

[0009] Determine the time period anomaly scores for each unit time period according to the number of various user operation behaviors in each unit time period;

[0010] Perform an ordered weighted arithmetic average on the time period anomaly scores using an ordered weighted average operator to determine the data anomaly score of the target user within the first time range;

[0011] Determine whether the target user has abnormal operation behaviors according to the data anomaly score.

[0012] Optionally, the determining the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original logs includes:

[0013] Obtain the corresponding relationships between the pre-constructed preset keyword fields and various user operation behaviors;

[0014] Determine the number of structured query statements containing the preset keyword fields in each unit time period as the number of times of various user operation behaviors in the corresponding unit time periods.

[0015] Optionally, the determining the time period anomaly score for each unit time period according to the number of times of various user operation behaviors in each unit time period includes:

[0016] Substitute the number of times of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probabilities of various user operation behaviors in each unit time period;

[0017] Determine the time period anomaly score for each unit time period by using the weighted average method according to the probabilities of various user operation behaviors in each unit time period.

[0018] Optionally, before substituting the number of times of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probabilities of various user operation behaviors in each unit time period, it further includes:

[0019] Collect the second original log of the target user's operations on the database within the second time range; the duration corresponding to the second time range is greater than the duration corresponding to the first time range;

[0020] Construct panel data of various user operation behaviors according to the structured query statements in the second original log; the panel data includes the number of times of user operation behaviors after time granularity aggregation statistics;

[0021] Substitute the panel data of various user operation behaviors into the kernel density estimation algorithm to determine the probability density function corresponding to various user operation behaviors in each unit time period.

[0022] Optionally, the determining the time period anomaly score for each unit time period by using the weighted average method according to the probabilities of various user operation behaviors in each unit time period includes:

[0023] Convert the probabilities of various user operation behaviors in each unit time period into anomaly scores of various user operation behaviors in each unit time period according to the conversion algorithm;

[0024] Weight the anomaly scores of various user operation behaviors in each unit time period to determine the time period anomaly score for each unit time period;

[0025] The conversion algorithm is:

[0026] Sop,t = (1 - p op,t ) * 100

[0027] where S op,t is the anomaly score of various user operation behaviors in each unit time period, p op,t is the probability of various user operation behaviors in each unit time period, op represents the type of user operation behavior, and t represents the unit time period.

[0028] Optionally, the method of using the ordered weighted average operator to perform an ordered weighted arithmetic average on the time period anomaly scores to determine the data anomaly score of the target user within the first time range includes:

[0029] Sort the time period anomaly scores in descending order;

[0030] Generate a time period weighted vector according to an arithmetic progression; the time period weighted vector is sorted in descending order;

[0031] Perform an ordered weighted arithmetic average based on the sorted time period anomaly scores and the time period weighted vector, and determine the ordered weighted arithmetic average result as the data anomaly score of the target user within the first time range.

[0032] Optionally, the method of determining whether the target user has an abnormal operation behavior according to the data anomaly score includes:

[0033] Judge whether the data anomaly score is greater than a preset score threshold;

[0034] If it is determined that the data anomaly score is greater than the preset score threshold, it is determined that the target user has an abnormal operation behavior;

[0035] If it is determined that the data anomaly score is less than or equal to the preset score threshold, it is determined that the target user does not have an abnormal operation behavior.

[0036] In a second aspect, the present application provides an abnormal operation behavior detection device, including:

[0037] A log collection module for collecting the first original log of the target user's operations on the database within the first time range;

[0038] An operation times determination module for determining the number of times of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log;

[0039] A first score determination module for determining the time period anomaly score of each unit time period according to the number of times of various user operation behaviors in each unit time period;

[0040] A second score determination module, configured to perform an ordered weighted arithmetic average on the time period anomaly scores by using an ordered weighted average operator, so as to determine the data anomaly score of the target user within a first time range;

[0041] An action determination module, configured to determine whether the target user has abnormal operation actions according to the data anomaly score.

[0042] In a third aspect, the present application provides an electronic device, including: a processor, as well as a memory and a transceiver communicatively connected to the processor;

[0043] Circuit interconnection is provided among the processor, the memory, and the transceiver;

[0044] The memory stores computer-executable instructions; the transceiver is used for sending and receiving data;

[0045] The processor executes the computer-executable instructions stored in the memory to implement the abnormal operation behavior detection method described above.

[0046] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the abnormal operation behavior detection method described above.

[0047] The abnormal operation behavior detection method, device, equipment, and storage medium provided by the present application collect the first original log of the target user's operations on the database within a first time range; determine the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log; determine the time period anomaly score of each unit time period according to the number of various user operation behaviors in each unit time period; perform an ordered weighted arithmetic average on the time period anomaly scores by using an ordered weighted average operator to determine the data anomaly score of the target user within the first time range; determine whether the target user has abnormal operation actions according to the data anomaly score. By converting the number of various user operation behaviors in each unit time period, which reflects the abnormal degree of the target user's operation behavior, into a data anomaly score and judging whether the data anomaly score of the target user is abnormal, the operation behaviors that do not conform to the target user's operation habits can be determined as abnormal operation behaviors, and there is no need to manually label a large amount of historical data, and abnormal behavior detection can be performed in the case of unbalanced positive and negative samples. Further, performing an ordered weighted arithmetic average on the time period anomaly scores by using an ordered weighted average operator can amplify the effect of the abnormal time period anomaly score on the data anomaly score. When a certain time period anomaly score is abnormal, it will directly cause the overall data anomaly score of the target user to be abnormal, so as to more accurately detect abnormal operation behaviors. Description of the Drawings

[0048] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0049] Figure 1 It is a schematic diagram of a network architecture for this application;

[0050] Figure 2 It is a flowchart of a method for detecting abnormal operation behaviors provided in the first embodiment of this application;

[0051] Figure 3 It is a flowchart of a method for detecting abnormal operation behaviors provided in the second embodiment of this application;

[0052] Figure 4 It is a flowchart of a method for detecting abnormal operation behaviors provided in the third embodiment of this application;

[0053] Figure 5 It is a schematic diagram of panel data corresponding to the query operation provided in the third embodiment of this application;

[0054] Figure 6 It is a schematic diagram of the structure of a device for detecting abnormal operation behaviors provided in the fourth embodiment of this application;

[0055] Figure 7 It is a schematic diagram of the structure of an electronic device provided in the fifth embodiment of this application.

[0056] Through the above-mentioned accompanying drawings, specific embodiments of this application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed Description of the Embodiments

[0057] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.

[0058] Terms such as "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. In the description of the following embodiments, "a plurality" means more than two, unless otherwise specifically defined.

[0059] Since the operation indicators and operation indicator thresholds in the prior art are set manually based on the anomalies or attacks that have occurred, it is impossible to effectively identify abnormal operations that are potentially highly harmful but have occurred few times in history. The inventor found in the research that the number of various user operation behaviors in each unit time period can reflect the operation behaviors of the target user. By determining the operation behaviors that do not conform to the operation habits of the target user as abnormal operation behaviors, it is possible to avoid manual annotation of a large amount of historical data and detect abnormal behaviors in the case of unbalanced positive and negative samples. Further, the degree of abnormality of the target user's operation behavior is converted into a data anomaly score. By judging whether the data anomaly score of the target user is abnormal, it is possible to judge whether the operation behavior of the target user conforms to the operation habits of the target user.

[0060] Figure 1 FIG. is a schematic diagram of a network architecture of the present application, as Figure 1 shown, the network architecture corresponding to the abnormal operation behavior detection method provided by the present application includes: a database server 1 and an electronic device 2. The abnormal operation behavior detection device is located in the electronic device. The first original log of the target user's operations on the database is stored in the database server 1. The electronic device 2 can collect the first original log from the database server 1, determine the number of various user operation behaviors according to the first original log, and obtain the data anomaly score of the target user by weighting according to the number of various user operation behaviors, so as to determine whether the target user has abnormal operation behaviors.

[0061] The following uses specific embodiments to describe in detail the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following will describe the embodiments of the present application with reference to the accompanying drawings.

[0062] Embodiment 1

[0063] Figure 2 FIG. is a flowchart of the abnormal operation behavior detection method provided by Embodiment 1 of the present application. The embodiment of the present application provides an abnormal operation behavior detection method for the problem that only anomalies or attacks that have occurred can be detected, and abnormal operations that are potentially highly harmful but have occurred few times in history cannot be effectively identified. The method in this embodiment is applied to an abnormal operation behavior detection device, and the abnormal operation behavior detection device can be located in an electronic device. Among them, the electronic device can be a digital computer in various forms. Such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers.

[0064] As Figure 2 shown, the specific steps of the method are as follows:

[0065] S101. Collect the first original log of the target user's operations on the database within the first time range.

[0066] Specifically, use data collection software (such as the logstash tool) to collect the database original logs within the first time range at intervals of the first time, obtain the first original logs including the user identifiers of the target users from the database original logs, and save them to the local storage space. Among them, the database original logs include fields such as user identifier (user), structured query statement (sql_text), and execution time (execution_time). The target user is a user with database operation permissions.

[0067] S102. Determine the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log.

[0068] Specifically, classify the structured query statements in the first original log, and determine the number of various structured query statements in each unit time period as the number of corresponding various user operation behaviors in each unit time period.

[0069] The embodiments of the present application do not specifically limit the classification method of the structured query statements. For example, the structured query statements can be classified according to the operation type, or according to the data table, or according to the sensitivity of the operation data table. The classification of the structured query statements can be realized by judging the semantics of the structured query statements through the context, or by identifying the key fields in the structured query statements.

[0070] S103. Determine the time period anomaly score for each unit time period according to the number of various user operation behaviors in each unit time period.

[0071] Among them, the time period anomaly score represents the degree of abnormality of the user operation behavior in each unit time period. For example, the higher the time period anomaly score, the more abnormal the user operation behavior in that unit time period.

[0072] Specifically, obtain the corresponding relationship between the number of various user operation behaviors in each unit time period and the time period operation anomaly scores of various user operation behaviors in each unit time period, determine the time period operation anomaly scores for each unit time period according to this corresponding relationship, and perform weighted summation on the time period operation anomaly scores for each unit time period to determine the time period anomaly score for each unit time period. Exemplarily, the time period operation anomaly score of the user operation behavior P1 in the unit time period T1 is S T1,P1 , and the time period operation anomaly score of the user operation behavior P2 in the unit time period T1 is S T1,P2, the time period operation anomaly score of the user operation behavior P1 in the unit time period T2 is S T2,P1 , the time period operation anomaly score of the user operation behavior P2 in the unit time period T2 is S T2,P2 , for S T1,P1 、S T1,P2 perform weighted summation to determine the time period anomaly score S of the unit time period T1 T1 , for S T2,P1 、S T2,P2 perform weighted summation to determine the time period anomaly score S of the unit time period T2 T2 .

[0073] Among them, the correspondence between the number of various user operation behaviors in each unit time period and the anomaly scores of various user operation behaviors in each unit time period can be a preset algorithm or a preset relationship table, etc. The time period operation anomaly score represents the anomaly degree of various user operation behaviors in each unit time period.

[0074] S104. Use an ordered weighted average operator to perform an ordered weighted arithmetic average on the time period anomaly scores to determine the data anomaly score of the target user within the first time range.

[0075] Among them, the ordered weighted average operator (the full English name is: ordered weighted averaging, abbreviated as OWA) rearranges the data according to size and aggregates them through weighting. The weights of the weighted aggregation have no association with the data and are only related to the position after the data is sorted. In the embodiments of the present application, using the ordered weighted average operator to perform an ordered weighted arithmetic average on the time period anomaly scores can amplify the effect of the abnormal time period anomaly scores on the data anomaly score.

[0076] Specifically, obtain the time period weighted vector, sort the time period anomaly scores according to size, substitute the sorted time period anomaly scores and the time period weighted vector into the formula of the ordered weighted arithmetic average, and determine the calculation result as the data anomaly score of the target user within the first time range. Among them, the time period weighted vector can be set in advance according to experience or generated according to the preset rules and the number of time period anomaly scores. The formula of the ordered weighted average operator is:

[0077]

[0078] In the implementation of the present application, w j = (w1, w2,..., w n ) is the time period weighted vector, w j ∈ [0, 1], j ∈ {1, 2,..., n}, ∑w j = 1, b j = (b1, b2,..., bn ) is the abnormal score for the sorted time period, S t =(a1, a2,..., a n ) is the obtained abnormal score for the time period, and S is the data abnormal score of the target user within the first time range.

[0079] In the embodiments of the present application, the abnormal scores for the time periods can be sorted in ascending order, and then the obtained weighted vectors for the time periods are also sorted in ascending order; alternatively, the abnormal scores for the time periods can be sorted in descending order, and then the obtained weighted vectors for the time periods are also sorted in descending order.

[0080] Optionally, in the embodiments of the present application, the abnormal score for the operation can also be determined, and the ordered weighted average operator is used to perform an ordered weighted arithmetic average on various abnormal scores for the operations to determine the data abnormal score of the target user within the first time range. Among them, the abnormal score for the operation represents the abnormal degree of various user operation behaviors. The abnormal scores for various operations are determined by performing a weighted sum on the abnormal scores for the time period operations of various user operation behaviors. Exemplarily, the abnormal score for the time period operation of the user operation behavior P1 in the unit time period T1 is S T1,P1 , and the abnormal score for the time period operation of the user operation behavior P2 in the unit time period T1 is S T1,P2 , and the abnormal score for the time period operation of the user operation behavior P1 in the unit time period T2 is S T2,P1 , and the abnormal score for the time period operation of the user operation behavior P2 in the unit time period T2 is S T2,P2 , and a weighted sum is performed on S T1,P1 and S T2,P1 to determine the abnormal score S P1 for the user operation behavior P1, and a weighted sum is performed on S T1,P2 and S T2,P2 to determine the abnormal score S P2 for the user operation behavior P2; the ordered weighted average operator is used to perform an ordered weighted arithmetic average on S P1 and S P2 to determine the data abnormal score of the target user within the first time range.

[0081] S105. Determine whether the target user has abnormal operation behaviors according to the data abnormal score.

[0082] In the embodiments of the present application, the data abnormal score can represent the abnormal degree of the operation behavior of the target user for operating the database within the first time range. Exemplarily, the higher the data abnormal score, the more abnormal the operation behavior of the target user for operating the database within the first time range. The data abnormal score can be compared with a preset score threshold, and the target user whose data abnormal score exceeds the preset score threshold is determined as the target user with abnormal operation behaviors.

[0083] In the embodiment of the present application, the first original log of the target user's operations on the database within the first time range is collected; the number of various user operation behaviors in each unit time period within the first time range is determined according to the structured query statements in the first original log; the time period anomaly score of each unit time period is determined according to the number of various user operation behaviors in each unit time period; the ordered weighted average operator is used to perform an ordered weighted arithmetic average on the time period anomaly scores to determine the data anomaly score of the target user within the first time range; and it is determined whether the target user has abnormal operation behaviors according to the data anomaly score. By converting the number of various user operation behaviors in each unit time period, which reflects the abnormal degree of the target user's operation behaviors, into a data anomaly score and judging whether the data anomaly score of the target user is abnormal, the operation behaviors that do not conform to the operation habits of the target user can be determined as abnormal operation behaviors, so that it is not necessary to perform manual annotation on a large amount of historical data, and abnormal behavior detection can be performed under the condition of unbalanced positive and negative samples. Further, by using the ordered weighted average operator to perform an ordered weighted arithmetic average on the time period anomaly scores, the effect of the abnormal time period anomaly scores on the data anomaly score can be amplified. When a certain time period anomaly score is abnormal, it will directly cause the overall data anomaly score of the target user to be abnormal, thereby enabling more accurate detection of abnormal operation behaviors.

[0084] Embodiment 2

[0085] Figure 3 The following is a flowchart of the abnormal operation behavior detection method provided in Embodiment 2 of the present application. In this embodiment of the present application, a specific example is combined to explain in detail the abnormal operation behavior detection method provided in the present application, as Figure 3 shown. The specific steps of the method are as follows:

[0086] Step S201: Collect the first original log of the target user's operations on the database within the first time range.

[0087] In the embodiment of the present application, the method of collecting the first original log is similar to that in step S101, and will not be elaborated here one by one.

[0088] Exemplarily, the first time can be 1 day. The original log of the database within 1 day can be collected, and the original log of the database is converted into a tabular data structure. For example, the Pandas library in Python can be used to parse the original log data according to the user identifier (user), structured query statement (sql_text), and execution time (execution_time), and the parsed data is read in the dataframe format.

[0089] Optionally, after converting the original database log into a tabular data structure, the original database log can be cleaned to eliminate invalid data. For example, delete data rows with null values and / or delete data with abnormal formats such as execution time.

[0090] Optionally, after cleaning the original database log, the first original log including the user identifier of the target user can be obtained according to the user identifier (user) field.

[0091] Step S202: Obtain the corresponding relationship between each pre-built preset keyword field and various user operation behaviors.

[0092] In the embodiment of the present application, the corresponding relationship between each pre-built preset keyword field and various user operation behaviors is obtained from the storage space.

[0093] Exemplarily, the user operation behaviors may include: insert operation, delete operation, update operation, query operation, and other operations. The preset keyword field corresponding to the insert operation can be set in advance as INSERT, the preset keyword field corresponding to the delete operation can be set as DELETE, the preset keyword field corresponding to the update operation can be set as UPDATE, the preset keyword field corresponding to the query operation can be set as SELECT, and the preset keyword field corresponding to other operations can be set as empty, and the corresponding relationship between each preset keyword field and various user operation behaviors is stored in the storage space in an associated manner.

[0094] Step S203: Determine the number of structured query statements including the preset keyword field in each unit time period as the number of various user operation behaviors in the corresponding unit time period.

[0095] Specifically, it can be determined whether the structured query statement contains a preset keyword field. If it contains a preset keyword field, it is determined that the target user has performed a corresponding user operation behavior. The number of structured query statements including the preset keyword field can be counted, and according to the corresponding relationship between each preset keyword field and various user operation behaviors, the number of corresponding various user operation behaviors is determined.

[0096] Exemplarily, it is determined whether the structured query statement contains INSERT, DELETE, UPDATE, SELECT. If not, it is determined that the target user performs an other operation once; if it contains INSERT, it is determined that the user performs a corresponding insert operation once; if it contains DELETE, it is determined that the user performs a corresponding delete operation once; if it contains UPDATE, it is determined that the user performs a corresponding update operation once; if it contains SELECT, it is determined that the user performs a corresponding query operation once.

[0097] Step S204: Substitute the number of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probabilities of various user operation behaviors in each unit time period.

[0098] Among them, the probability density function is a function that describes the possibility of various user operation behaviors in each unit time period near a certain determined value point.

[0099] In the embodiments of the present application, the kernel density estimation algorithm can be used according to the historical operation data of the target user to determine the probability density function corresponding to the number of various user operation behaviors in each unit time period; the normal distribution density function can also be used to determine the probability density function corresponding to the number of various user operation behaviors in each unit time period. The embodiments of the present application do not make specific limitations on this.

[0100] Exemplarily, the first time range can be 1 day, the unit time can be two hours, and each unit time period can include 0:00 - 2:00, 2:00 - 4:00, 4:00 - 6:00, 6:00 - 8:00, 8:00 - 10:00, 10:00 - 12:00, 12:00 - 14:00, 14:00 - 16:00, 16:00 - 18:00, 18:00 - 20:00, 20:00 - 22:00, 22:00 - 24:00. The user operation behaviors can include add operation, delete operation, modify operation, query operation and other operations. Substitute the number of times the target user performs add operation, delete operation, modify operation, query operation and other operations from 0:00 to 2:00 within a day into the corresponding probability density function respectively, and the probabilities of the target user performing add operation, delete operation, modify operation, query operation and other operations from 0:00 to 2:00 within a day can be obtained respectively. The method for obtaining the probabilities of various user operation behaviors in other unit time periods is similar to the above method, and 5 * 12 probabilities of 5 types of user operation behaviors in 12 unit time periods can be obtained.

[0101] Step S205: Determine the time period anomaly score of each unit time period by using the weighted average method according to the probabilities of various user operation behaviors in each unit time period.

[0102] Specifically, the probabilities of various user operation behaviors in each unit time period can be converted into corresponding anomaly scores, and the weighted average method is used for the scores of various user operation behaviors in each unit time period to determine the time period anomaly score of each unit time period.

[0103] Exemplarily, the lower the probability of various user operation behaviors in each unit time period, the higher the corresponding converted anomaly score, and the more abnormal the operation behavior of the target user with a higher anomaly score.

[0104] In the embodiments of the present application, a specific implementation manner for determining the time period anomaly score of each unit time period is as follows:

[0105] Step S2051: Convert the probabilities of various user operation behaviors in each unit time period into anomaly scores of various user operation behaviors in each unit time period according to the conversion algorithm.

[0106] The conversion algorithm is as follows:

[0107] S op,t = (1 - p op,t ) * 100

[0108] where S op,t is the anomaly score of various user operation behaviors in each unit time period, p op,t is the probability of various user operation behaviors in each unit time period, op represents the type of user operation behavior, and t represents the unit time period.

[0109] Exemplarily, the target user performs X delete operations from 10 o'clock to 12 o'clock, and the probability P D,10-12 of performing X delete operations from 10 o'clock to 12 o'clock is obtained according to the corresponding probability density function. Here, D represents the delete operation. Substituting P D,10-12 = 0.8 into the above formula, the anomaly score S D,10-12 of the target user performing X delete operations from 0 o'clock to 2 o'clock can be obtained as 20 points.

[0110] Step S2052: Weight the anomaly scores of various user operation behaviors in each unit time period to determine the time period anomaly score of each unit time period.

[0111] Specifically, the entropy weight method or other methods can be used to determine the operation weights of various user operation behaviors in each unit time period; the anomaly scores of various user operation behaviors in each unit time period are weighted and summed according to the operation weights of various user operation behaviors in each unit time period, and the weighted sum result is determined as the time period anomaly score of each unit time period.

[0112] In the embodiment of the present application, the calculation formula for weighted summation of the anomaly scores of various user operation behaviors in each unit time period is as follows:

[0113] S t = ∑w i * S op,t

[0114] where S t is the time period anomaly score of each unit time period, w i is the operation weight of various user operation behaviors in each unit time period, and the sum of w i is 1.

[0115] Exemplarily, the user operation behaviors include add operation, delete operation, modify operation, query operation, and other operations, w i = (wI , w D , w U , w S , w o ), where w I is the weight of the increment operation, w D is the weight of the deletion operation, w U is the weight of the deletion operation, w S is the weight of the query operation, w o is the weight of other operations. The operation weights of various user operation behaviors set in advance can be obtained. The greater the potential harm of the operation type, the higher the corresponding operation weight set in advance. Taking the first time range as 1 day and the unit time as two hours as an example, the abnormal scores of various user operation behaviors in 12 unit time periods are weighted and summed respectively to determine the time period abnormal scores of 12 unit time periods: S 0-2 , S 2-4 , S 4-6 , S 6-8 , S 8-10 , S 10-12 , S 12-14 , S 14-16 , S 16-18 , S 18-20 , S 20-22 , S 22-24 .

[0116] Optionally, the time period abnormal scores of each unit time period can be compared with the pre-set time period score threshold. If the time period abnormal score of a unit time period exceeds the pre-set time period score threshold, it can be confirmed that the target user has abnormal operation behavior in this unit time period within the first time range.

[0117] Step S206: Sort the time period abnormal scores in descending order.

[0118] In the embodiment of the present application, the time period abnormal scores S t are sorted in descending order of the numerical value of S t to obtain the sorted time period abnormal scores b j =(b1, b2,..., b n ), where b j is the j-th largest time period abnormal score S t , and n is the number of time period abnormal scores. The implementation manner of sorting in the embodiment of the present application is not specifically limited.

[0119] Step S207: Generate a time period weighted vector according to an arithmetic progression.

[0120] Among them, the time period weighted vector is sorted in descending order.

[0121] Specifically, the first term value A of a preset arithmetic progression can be obtained, and the first term value A and the number n of time period anomaly scores are substituted into the formula A*n + [n*(n - 1)*d] / 2 = 1 to solve for the common difference d, so as to obtain an arithmetic progression with a common difference of d and a first term value of A, and sort the arithmetic progression in descending order, and determine the arithmetic progression sorted in descending order as the time period weighted vector.

[0122] Exemplarily, the number n of time period anomaly scores is 12, the first term value A of the preset arithmetic progression is 0.001, and the obtained common difference d is 0.015, then the time period weighted vector sorted in descending order generated according to the arithmetic progression is w j =(0.164, 0.151, 0.136, 0.121, 0.106, 0.091, 0.076, 0.061, 0.046, 0.031, 0.016, 0.001).

[0123] Step S208: Perform an ordered weighted arithmetic mean on the sorted time period anomaly scores and the time period weighted vector, and determine the ordered weighted arithmetic mean result as the data anomaly score of the target user within the first time range.

[0124] In the embodiment of the present application, the method for performing an ordered weighted arithmetic mean to determine the data anomaly score of the target user within the first time range is similar to that in step S104, and will not be elaborated here one by one.

[0125] In the embodiment of the present application, by sorting the time period anomaly scores and using an ordered weighted average operator to perform an ordered weighted arithmetic mean on the time period anomaly scores, the effect of the abnormal time period anomaly scores on the data anomaly score can be amplified. When a certain time period anomaly score is abnormal, it will directly cause the data anomaly score of the target user as a whole to be abnormal, so as to more accurately detect abnormal operation behaviors.

[0126] Step S209: Determine whether the data anomaly score is greater than a preset score threshold.

[0127] Specifically, if the data anomaly score is less than or equal to the preset score threshold, then step S210 is executed; if the data anomaly score is greater than the preset score threshold, then step S211 is executed.

[0128] In the embodiment of the present application, the method for setting the preset score threshold is not specifically limited. Exemplarily, the preset score threshold can be determined according to the preset quantile of the data anomaly scores of the target user within a certain time range. For example, if the preset quantile is the 90% quantile and the 90% quantile of the data anomaly scores of the target user within a certain time range is Y, then Y is determined as the preset score threshold, and it is determined whether the data anomaly score of the target user within the first time range is greater than Y.

[0129] Step S210: If it is determined that the data anomaly score is less than or equal to the preset score threshold, it is determined that the target user does not have abnormal operation behavior.

[0130] In the embodiment of the present application, if the data anomaly score is less than or equal to the preset score threshold, the operation behavior of the target user within the first time range conforms to the behavior habit of the target user, and the target user does not have abnormal operation behavior.

[0131] Step S211: If it is determined that the data anomaly score is greater than the preset score threshold, it is determined that the target user has abnormal operation behavior.

[0132] In the embodiment of the present application, the higher the data anomaly score, the more abnormal the operation behavior of the target user within the first time range. If the data anomaly score is greater than the preset score threshold, it can be determined that the target user has abnormal operation behavior within the first time range.

[0133] Optionally, if it is determined that the data anomaly score is greater than the preset score threshold, the sorted time period anomaly score b j =(b1, b2,..., b n ) corresponding to b1 in the unit time period, and the anomaly score S op,t of various user operation behaviors in this unit time period can also be determined, so as to determine the time of the target user's abnormal operation behavior and the type of abnormal operation behavior.

[0134] In the embodiment of the present application, by converting the number of various user operation behaviors in each unit time period into a data anomaly score according to the probability density function, a data anomaly score that can more accurately reflect the abnormal degree of the target user's behavior can be obtained, and further the accuracy of detecting abnormal operation behavior can be improved. By sorting the time period anomaly scores and using an ordered weighted average operator to perform an ordered weighted arithmetic average on the time period anomaly scores, the effect of the abnormal time period anomaly score on the data anomaly score can be amplified. When a certain time period anomaly score is abnormal, it will directly cause the overall data anomaly score of the target user to be abnormal, so that abnormal operation behavior can be detected more accurately.

[0135] Embodiment III

[0136] Figure 4 This is a flowchart of the abnormal operation behavior detection method provided by the third embodiment of the present application. On the basis of the above-mentioned second embodiment, this embodiment relates to the specific process of determining the probability density function before substituting the number of various user operation behaviors in each unit time period into the corresponding probability density function in step S204 to obtain the probability of various user operation behaviors in each unit time period.

[0137] Such as Figure 4As shown in the figure, the specific steps of this method are as follows:

[0138] Step S301: Collect the second original log of the target user's operations on the database within the second time range.

[0139] Among them, the duration corresponding to the second time range is greater than the duration corresponding to the first time range. Exemplarily, the first time range is 1 day, and the second time range can be half a month or one month; the first time range is one week, and the second time range can be three months or half a year.

[0140] In the embodiment of the present application, modeling separately according to the second original log of the target user can realize personalized detection of the abnormal operation behavior of the target user and improve the accuracy of the detection result of the abnormal operation behavior. The method of collecting the second original log is similar to that in Embodiment 1 and will not be elaborated here one by one.

[0141] Optionally, the second original log can be collected periodically or regularly to update the probability density function; or the second original log can be collected and the probability density function can be updated in response to a model update instruction. Among them, the model update instruction can be manually triggered by an operator through the provided update control, or can be automatically triggered after the number of times that the abnormal score of the target user data is greater than the preset score threshold exceeds the preset number of times. For example, the preset number of times can be 3 times, and the first time range can be 1 day. If the abnormal score of the target user data is greater than the preset score threshold for 3 consecutive days, the model update instruction is triggered, the second original log of the target user is collected, and the corresponding probability density function is updated.

[0142] Step S302: Construct panel data of various user operation behaviors according to the structured query statements in the second original log.

[0143] Among them, the panel data includes the number of user operation behaviors after aggregation statistics with a time granularity. The panel data contains data in two dimensions: time and cross-section. The longitudinal direction of the panel data is the time dimension, indicating the time periods divided by the first time within the second time range; the horizontal direction of the panel data is the cross-sectional data, indicating the number of various user operation behaviors after aggregation statistics with a unit time period as the time granularity within the first time range.

[0144] Specifically, determine the number of various user operation behaviors after aggregation statistics with a unit time period as the time granularity within the time periods divided by the first time within the second time range according to the structured query statements in the first original log, and respectively generate the panel data corresponding to various user operation behaviors

[0145] Exemplarily, taking the user operation behaviors including addition operation, deletion operation, modification operation, query operation and other operations as an example, five panel data corresponding to the addition operation, deletion operation, modification operation, query operation and other operations are constructed. Taking the panel data PI corresponding to the addition operation as an example, the first time range is 1 day, the unit time period is two hours, and the overall performance of the panel data is a matrix. Any element PI(i,t) = x of the matrix represents that the user has performed a total of x database addition operations within the t unit time period on the day with the date i in history. Figure 5 The schematic diagram of the panel data corresponding to the query operation provided in the third embodiment of the present application is shown in Figure 5 As shown, the value 289 in the second column of the first row of the matrix indicates that the target user has performed 289 database query operations from 2 o'clock to 4 o'clock on April 28, 2020.

[0146] Step S303: Substitute the panel data of various user operation behaviors into the kernel density estimation algorithm to determine the probability density function corresponding to various user operation behaviors in each unit time period.

[0147] Among them, kernel density estimation is a non-parametric test method for estimating the unknown probability density function of a random variable.

[0148] Specifically, a column of data corresponding to the unit time period in the panel data of various user operation behaviors is determined as the sample x i =(x1, x2,..., x n ). Substitute the sample x i =(x1, x2,..., x n ) into the kernel density estimation algorithm, and the probability density function f h (x) of the user operation behavior type corresponding to the panel data in this unit time period can be determined. Among them, n is the number of time periods divided by the first time within the second time range, and the kernel density estimation algorithm is:

[0149]

[0150] Among them, K h is the kernel function, which is a non-negative function with an integral value of 1; h is the bandwidth, which is a smoothing parameter. The kernel density estimation algorithm can be simply understood as the weighted sum of the kernel functions corresponding to each sample as the center point.

[0151] Optionally, the kernel function K h can be a Gaussian kernel function. The fact that the kernel function K h is a Gaussian kernel function can make the estimated distribution smoother. The bandwidth h can be determined according to the Scott's rule of thumb, Silverman's rule of thumb, etc., or the hyperparameter automatic search module GridSearchCV in Python can be used to optimize the bandwidth h.

[0152] In the embodiment of the present application, the determined kernel function K h , bandwidth h, and sample x i =(x1, x2,..., x n ) are substituted into the kernel density estimation algorithm, and the obtained f h (x) can be determined as the probability density function corresponding to the user operation behavior type in the unit time period corresponding to the sample.

[0153] Exemplarily, Figure 5 the first column of data in i is determined as the sample x 14 =(x1, x2,..., x h ), and this sample is substituted into the kernel density estimation algorithm. The obtained f

[0154] In the embodiment of the present application, by using the kernel density estimation algorithm to determine the probability density function, it is not necessary to make a prior assumption about the data distribution, and a probability density function that more conforms to the probability density distribution law of the number of various user operation behaviors in each unit time period can be directly obtained through unsupervised training based on the second original log in the second time range; further, according to the probability density function determined by the kernel density estimation algorithm, the number of various user operation behaviors in each unit time period is converted into a data anomaly score, which can improve the accuracy of detecting abnormal operation behaviors. And by determining the probability density function with the target user as the dimension according to the second original log of the target user's operation on the database, personalized detection of abnormal operation behaviors can be realized, and the accuracy of the abnormal detection result can be improved.

[0155] Embodiment 4

[0156] Figure 6 FIG. is a schematic structural diagram of an abnormal operation behavior detection device provided in Embodiment 4 of the present application. The abnormal operation behavior detection device provided in the embodiment of the present application can execute the processing flow provided in the embodiment of the abnormal operation behavior detection method. As Figure 6 shown, the abnormal operation behavior detection device 60 includes: a log collection module 601, an operation count determination module 602, a first score determination module 603, a second score determination module 604, and a behavior determination module 605.

[0157] Specifically, the log collection module 601 is configured to collect the first original log of the target user's operation on the database within the first time range.

[0158] The operation count determination module 602 is configured to determine the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log.

[0159] The first score determination module 603 is configured to determine the time period anomaly score for each unit time period according to the number of various user operation behaviors in each unit time period.

[0160] The second score determination module 604 is configured to perform an ordered weighted arithmetic average on the time period anomaly scores by using an ordered weighted average operator to determine the data anomaly score of the target user within the first time range.

[0161] The behavior determination module 605 is configured to determine whether the target user has abnormal operation behaviors according to the data anomaly score.

[0162] The device provided by the embodiment of the present application can be specifically used to execute the method embodiment provided in the first embodiment above, and the specific functions are not described herein again.

[0163] Optionally, the operation number determination module 602 is specifically configured to: obtain the corresponding relationship between each preset keyword field and various user operation behaviors pre-constructed; determine the number of structured query statements including the preset keyword fields in each unit time period as the number of various user operation behaviors in the corresponding unit time periods.

[0164] Optionally, the first score determination module 603 includes: a probability determination unit and a score determination unit. The probability determination unit is configured to: substitute the number of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probability of various user operation behaviors in each unit time period; the score determination unit is configured to: determine the time period anomaly score for each unit time period by using the weighted average method according to the probability of various user operation behaviors in each unit time period.

[0165] Optionally, the abnormal operation behavior detection device 60 further includes: a function determination module. Before the probability determination unit substitutes the number of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probability of various user operation behaviors in each unit time period, the function determination module is configured to: collect the second original log of the target user's operation on the database within the second time range; the duration corresponding to the second time range is longer than the duration corresponding to the first time range; construct the panel data of various user operation behaviors according to the structured query statements in the second original log; the panel data includes the number of user operation behaviors after time granularity aggregation statistics; substitute the panel data of various user operation behaviors into the kernel density estimation algorithm to determine the probability density function corresponding to various user operation behaviors in each unit time period.

[0166] Optionally, the score determination unit is specifically configured to: convert the probabilities of various types of user operation behaviors in each unit time period into abnormal scores of various types of user operation behaviors in each unit time period according to a conversion algorithm; weight the abnormal scores of various types of user operation behaviors in each unit time period to determine the time period abnormal score of each unit time period; the conversion algorithm is:

[0167] S op,t =(1 - p op,t ) * 100

[0168] where S op,t is the abnormal score of various types of user operation behaviors in each unit time period, p op,t is the probability of various types of user operation behaviors in each unit time period, op represents the type of user operation behavior, and t represents the unit time period.

[0169] Optionally, the second score determination module 604 is specifically configured to: sort the time period abnormal scores in descending order; generate a time period weighting vector according to an arithmetic progression; sort the time period weighting vector in descending order; perform an ordered weighted arithmetic average according to the sorted time period abnormal scores and the time period weighting vector, and determine the ordered weighted arithmetic average result as the data abnormal score of the target user within the first time range.

[0170] Optionally, the behavior determination module 605 is specifically configured to: determine whether the data abnormal score is greater than a preset score threshold; if it is determined that the data abnormal score is greater than the preset score threshold, determine that the target user has an abnormal operation behavior; if it is determined that the data abnormal score is less than or equal to the preset score threshold, determine that the target user does not have an abnormal operation behavior.

[0171] The device provided in the embodiments of the present application can be specifically used to execute the above method embodiments, and the specific functions are not described herein again.

[0172] Embodiment Five

[0173] Figure 7 is a schematic structural diagram of an electronic device provided in Embodiment Five of the present application. As Figure 7 shown, the electronic device 70 includes: a processor 701, a memory 702, a transceiver 703, and computer execution instructions stored on the memory 702 and executable on the processor 701.

[0174] Among them, the processor 701, the memory 702 and the transceiver 703 are interconnected by circuits; the transceiver 703 is used for sending and receiving data; when the processor 701 runs the computer execution instructions, the abnormal operation behavior detection method provided in any of the above method embodiments is implemented.

[0175] An embodiment of this application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, the methods provided in any of the above method embodiments are implemented.

[0176] An embodiment of this application further provides a computer program product, which includes: computer-executable instructions. The computer-executable instructions are stored in a readable storage medium. At least one processor of an electronic device can read the computer-executable instructions from the readable storage medium, and the at least one processor executes the computer-executable instructions to enable the electronic device to execute the methods provided in any of the above method embodiments.

[0177] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the device described above can refer to the corresponding process in the foregoing method embodiments, and will not be elaborated here.

[0178] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily think of other implementation manners of this application. This application is intended to cover any variations, uses, or adaptations of this application, which follow the general principles of this application and include well-known common general knowledge or conventional technical means in the technical field not disclosed in this application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of this application are pointed out by the following claims.

[0179] It should be understood that this application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is only limited by the appended claims.

Claims

1. An abnormal operation behavior detection method, characterized in that, Including: Collecting the first original log of the target user's operations on the database within the first time range; Determining the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log; Determining the time period anomaly score of each unit time period according to the number of various user operation behaviors in each unit time period; Performing an ordered weighted arithmetic average on the time period anomaly scores using an ordered weighted average operator to determine the data anomaly score of the target user within the first time range; Determining whether the target user has abnormal operation behaviors according to the data anomaly score; The determining the time period anomaly score of each unit time period according to the number of various user operation behaviors in each unit time period includes: Substituting the number of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probabilities of various user operation behaviors in each unit time period; Converting the probabilities of various user operation behaviors in each unit time period into the anomaly scores of various user operation behaviors in each unit time period according to a conversion algorithm; Weighting the anomaly scores of various user operation behaviors in each unit time period to determine the time period anomaly score of each unit time period; The conversion algorithm is: Among them, is the anomaly score of various user operation behaviors in each unit time period, is the probability of various user operation behaviors in each unit time period, represents the type of user operation behavior, represents the unit time period.

2. The method according to claim 1, wherein The determining the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original log includes: Obtaining the corresponding relationship between each preset keyword field and various user operation behaviors pre - constructed; Determining the number of structured query statements containing the preset keyword field in each unit time period as the number of various user operation behaviors in the corresponding unit time period.

3. The method according to claim 1, characterized in that, Before the substituting the number of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probabilities of various user operation behaviors in each unit time period, it further includes: Collecting the second original log of the target user's operations on the database within the second time range; the duration corresponding to the second time range is greater than the duration corresponding to the first time range; Constructing panel data of various user operation behaviors according to the structured query statements in the second original log; the panel data includes the number of user operation behaviors after time - granularity aggregation statistics; Substituting the panel data of various user operation behaviors into the kernel density estimation algorithm to determine the probability density function corresponding to various user operation behaviors in each unit time period.

4. The method according to claim 1, characterized in that The performing an ordered weighted arithmetic average on the time period anomaly scores using an ordered weighted average operator to determine the data anomaly score of the target user within the first time range includes: Sorting the time period anomaly scores in descending order; Generating a time period weighted vector according to an arithmetic progression; the time period weighted vector is sorted in descending order; Performing an ordered weighted arithmetic average according to the sorted time period anomaly scores and the time period weighted vector, and determining the ordered weighted arithmetic average result as the data anomaly score of the target user within the first time range.

5. The method according to any one of claims 1-4, characterized in that, The determining whether the target user has abnormal operation behaviors according to the data anomaly score includes: Determine whether the data anomaly score is greater than a preset score threshold; If it is determined that the data anomaly score is greater than the preset score threshold, it is determined that the target user has abnormal operation behavior; If it is determined that the data anomaly score is less than or equal to the preset score threshold, it is determined that the target user does not have abnormal operation behavior.

6. An abnormal operation behavior detection device, characterized in that, It includes: A log collection module for collecting the first original logs of the operations of the target user on the database within the first time range; An operation count determination module for determining the number of various user operation behaviors in each unit time period within the first time range according to the structured query statements in the first original logs; A first score determination module for determining the time period anomaly score of each unit time period according to the number of various user operation behaviors in each unit time period; A second score determination module for performing an ordered weighted arithmetic average on the time period anomaly scores by using an ordered weighted average operator to determine the data anomaly score of the target user within the first time range; A behavior determination module for determining whether the target user has abnormal operation behavior according to the data anomaly score; The first score determination module includes: A probability determination unit for substituting the number of various user operation behaviors in each unit time period into the corresponding probability density function respectively to obtain the probability of various user operation behaviors in each unit time period; A score determination unit for converting the probability of various user operation behaviors in each unit time period into the anomaly score of various user operation behaviors in each unit time period according to a conversion algorithm; Weight the anomaly scores of various user operation behaviors in each unit time period to determine the time period anomaly score of each unit time period; The conversion algorithm is: Among them, is the anomaly score of various user operation behaviors in each unit time period, is the probability of various user operation behaviors in each unit time period, represents the type of user operation behavior, represents the unit time period.

7. An electronic device, characterized in that, It includes: A processor, and a memory and a transceiver communicatively connected to the processor; The processor, the memory and the transceiver are interconnected by circuits; The memory stores computer execution instructions; the transceiver is used for receiving and transmitting data; The processor executes the computer execution instructions stored in the memory to implement the method according to any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer execution instructions, and when the computer execution instructions are executed by the processor, they are used to implement the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Abnormal user detection method based on kernel density estimation and exponential smoothing algorithm

    CN113542236A

  • User abnormal behavior recognition method and device, equipment, storage medium and program

    CN113992340A