Detection Method and Detection Device for Abnormal Operation Behaviors

By using a classification model based on mutual information classification method and Pearson correlation coefficient method in the cloud management platform, combined with the user type relationship table, it detects and alerts abnormal operation behaviors, and solves the problem of difficult to efficiently detect abnormal operation behaviors that users do not need for work in the existing technology, and improves the security of the cloud management platform.

CN114780358BActive Publication Date: 2025-07-04INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111507474.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-10
Publication Date
2025-07-04
Estimated Expiration
2041-12-10

AI Technical Summary

Technical Problem

Existing cloud management platforms are difficult to efficiently detect users' abnormal operation behaviors that are not required by work, resulting in lower security.

Method used

By obtaining user operation behavior information, using a classification model based on mutual information classification method and Pearson correlation coefficient method, combined with the user type relationship table, determine whether the operation behavior is an abnormal behavior and alert it.

Benefits of technology

It realizes efficient detection of abnormal operation behaviors that users do not need to work, improves the security of the cloud management platform, and reduces the losses of the enterprise.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114780358B_ABST
    Figure CN114780358B_ABST
Patent Text Reader

Abstract

The present application provides a method for detecting abnormal operation behaviors and a device for detecting abnormal operation behaviors, which relate to the fields of artificial intelligence and information security, and are conducive to realizing the efficient detection of abnormal operation behaviors of users that are not required for work, and improving the security of the cloud management platform. The method includes: obtaining operation behavior information of a target user; inputting the operation behavior information into a classification model to obtain a classification result of the operation behavior information, where the classification model is trained with sample data obtained after feature filtering based on the mutual information classification method and the Pearson correlation coefficient method; determining whether the operation behavior corresponding to the operation behavior information is an abnormal behavior based on the above classification result, the user identifier of the above target user, and a pre-stored user type relationship table, where the user type relationship table is used to represent the corresponding relationship between user types and user identifiers; and sending an alarm message when the operation behavior corresponding to the operation behavior information is an abnormal behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of artificial intelligence and information security, and in particular, to a method and device for detecting abnormal operation behaviors. Background Art

[0002] With the rapid development of cloud computing technology, more and more enterprises choose to move their businesses to the cloud. A large number of enterprises choose to build private clouds based on their own business characteristics and technical capabilities. Users can achieve the periodic management and basic operation and maintenance of cloud services through the self-service interface of the cloud management platform. Currently, to prevent users from performing illegal operations with potential security risks, the cloud management platform can mainly analyze and detect the deviation of the user's actual operations from normal operations based on the user's access frequency, duration, common login time periods, access data volume of specific content, etc., and then determine whether there are abnormal operations.

[0003] However, the above methods are difficult to specifically detect abnormal operation behaviors such as information queries and device operations that are not required for work by users, resulting in a low security level of the cloud management platform. Summary of the Invention

[0004] The present application provides a method and device for detecting abnormal operation behaviors, which associates user types with operation events, facilitating the efficient detection of abnormal operation behaviors that are not required for work by users and improving the security level of the cloud management platform.

[0005] In a first aspect, a method for detecting abnormal operation behaviors is provided, which can be executed by a detection device for abnormal operation behaviors. The method includes: obtaining operation behavior information of a target user; inputting the operation behavior information into a classification model to obtain a classification result of the operation behavior information, where the classification model is trained with sample data obtained by filtering features based on the mutual information classification method and the Pearson correlation coefficient method; and determining whether the operation behavior corresponding to the operation behavior information is an abnormal behavior based on the classification result, the user identifier of the target user, and a pre-stored user type relationship table, where the user type relationship table is used to represent the corresponding relationship between user types and user identifiers.

[0006] In this application, when the user type is associated with the user operation behavior, the detection device for abnormal operation behavior can obtain the types of different operation behaviors through a classification model. It should be understood that the user type can be the functional type of the user, such as a system user or a network user, and different types of users can correspond to different operation behaviors. When the type of the above operation behavior is different from the type of the corresponding user, the detection device for abnormal operation behavior can determine that the operation behavior may be an abnormal operation behavior and issue an alarm, so that the management personnel can intervene and manage the abnormal operation behavior, realizing the efficient detection of abnormal operation behaviors that are not required for work by users, improving the security of the cloud management platform, and thus reducing the losses of the enterprise.

[0007] In combination with the first aspect, in some implementation manners of the first aspect, determining whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior based on the above classification result, the user identifier of the above target user, and the pre-stored user type relationship table includes: using the above classification result as the predicted user type of the above target user; obtaining, based on the user identifier of the above target user, the user type corresponding to the user identifier of the above target user in the above user type relationship table; comparing the above predicted user type with the user type corresponding to the user identifier of the above target user to determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0008] In combination with the first aspect, in some implementation manners of the first aspect, the above further includes: obtaining at least one predicted user identifier based on the above classification result; comparing the user identifier of the above target user with the above at least one predicted user identifier to determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0009] In combination with the first aspect, in some implementations of the first aspect, before obtaining the operation behavior information of the target user, the above method further includes: obtaining the data to be processed, where the data to be processed includes the operation behavior information of the user within a period of time, the occurrence times of the operation behaviors corresponding to the operation behavior information, the user types and user identifiers corresponding to the operation behavior information; performing normalization and variance filtering on the data to be processed to obtain data with a variance greater than or equal to a first preset threshold; performing filter-based feature selection on the data with a variance greater than or equal to the first preset threshold to obtain data with a relevant statistic greater than or equal to a second preset threshold; based on the mutual information classification method and the Pearson correlation coefficient method, performing feature filtering on the other data in the data with a variance greater than or equal to the first preset threshold except for the data with a relevant statistic greater than or equal to the second preset threshold to obtain data with an estimated mutual information value greater than or equal to a third preset threshold and a Pearson correlation coefficient greater than or equal to a fourth preset threshold; determining the data with a relevant statistic greater than or equal to the second preset threshold and the data with an estimated mutual information value greater than or equal to the third preset threshold and the Pearson correlation coefficient greater than or equal to the fourth preset threshold as the above sample data; inputting the sample data into a pre-trained model for training to obtain the above classification model.

[0010] In combination with the first aspect, in some implementations of the first aspect, the above performing normalization and variance filtering on the data to be processed to obtain data with a variance greater than or equal to a first preset threshold includes: performing normalization on the sum of the occurrence times of the same operation behaviors corresponding to the operation behavior information of the same user within the above period of time in the data to be processed to obtain the result after normalization; performing variance filtering on the result after normalization to obtain data with a variance greater than or equal to the first preset threshold.

[0011] In combination with the first aspect, in some implementations of the first aspect, the above sample data includes training data and test data; the above inputting the sample data into a pre-trained model for training to obtain the above classification model includes: inputting the training data into the pre-trained model for training to obtain the above classification model; after obtaining the classification model, the above method further includes: inputting the test data into the classification model to obtain the test classification result of the operation behavior information in the test data; optimizing the classification model according to the test classification result.

[0012] In combination with the first aspect, in some implementations of the first aspect, the above method further includes: sending an alarm message when the operation behavior corresponding to the operation behavior information is an abnormal behavior.

[0013] In a second aspect, a detection device for abnormal operation behaviors is provided, including an acquisition module and a processing module. The acquisition module is configured to: acquire operation behavior information of a target user; The processing module is configured to: input the operation behavior information into a classification model to obtain a classification result of the operation behavior information. The classification model is trained with sample data obtained by feature filtering based on the mutual information classification method and the Pearson correlation coefficient method; and, based on the classification result, the user identifier of the target user, and a pre-stored user type relationship table, determine whether the operation behavior corresponding to the operation behavior information is an abnormal behavior. The user type relationship table is used to represent the corresponding relationship between user types and user identifiers.

[0014] In combination with the second aspect, in some implementation manners of the second aspect, the processing module is configured to: use the classification result as the predicted user type of the target user; based on the user identifier of the target user, obtain the user type corresponding to the user identifier of the target user in the user type relationship table; compare the predicted user type with the user type corresponding to the user identifier of the target user to determine whether the operation behavior corresponding to the operation behavior information is an abnormal behavior.

[0015] In combination with the second aspect, in some implementation manners of the second aspect, the processing module is configured to: based on the classification result, obtain at least one predicted user identifier; compare the user identifier of the target user with the at least one predicted user identifier to determine whether the operation behavior corresponding to the operation behavior information is an abnormal behavior.

[0016] In combination with the second aspect, in some implementations of the second aspect, the obtaining module is configured to: obtain data to be processed, where the data to be processed includes the operation behavior information of a user within a period of time, the occurrence times of the operation behaviors corresponding to the operation behavior information, the user type and user identifier corresponding to the operation behavior information; the processing module is configured to: perform normalization and variance filtering on the data to be processed to obtain data with a variance greater than or equal to a first preset threshold; perform filter-based feature selection on the data with a variance greater than or equal to the first preset threshold to obtain data with a relevant statistic greater than or equal to a second preset threshold; based on the mutual information classification method and the Pearson correlation coefficient method, perform feature filtering on the other data in the data with a variance greater than or equal to the first preset threshold except for the data with a relevant statistic greater than or equal to the second preset threshold to obtain data with an estimated mutual information value greater than or equal to a third preset threshold and a Pearson correlation coefficient greater than or equal to a fourth preset threshold; determine the data with a relevant statistic greater than or equal to the second preset threshold and the data with an estimated mutual information value greater than or equal to the third preset threshold and the Pearson correlation coefficient greater than or equal to the fourth preset threshold as the sample data; input the sample data into a pre-trained model for training to obtain the classification model.

[0017] In combination with the second aspect, in some implementations of the second aspect, the processing module is configured to: perform normalization on the sum of the occurrence times of the same operation behaviors corresponding to the operation behavior information of the same user within the period of time in the data to be processed to obtain a normalized result; perform variance filtering on the normalized result to obtain data with a variance greater than or equal to the first preset threshold.

[0018] In combination with the second aspect, in some implementations of the second aspect, the sample data includes training data and test data; the processing module is configured to: input the training data into the pre-trained model for training to obtain the classification model; input the test data into the classification model to obtain the test classification result of the operation behavior information in the test data; optimize the classification model according to the test classification result.

[0019] In combination with the second aspect, in some implementations of the second aspect, the processing module is configured to: send an alarm message when the operation behavior corresponding to the operation behavior information is an abnormal behavior.

[0020] In a third aspect, a processor is provided, including: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit the signal through the output circuit, so that the processor executes the method in any possible implementation manner of the first aspect.

[0021] In the specific implementation process, the above-mentioned processor can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be transistors, gate circuits, flip-flops, and various logic circuits, etc. The input signal received by the input circuit can be received and input by, for example, but not limited to, a receiver. The signal output by the output circuit can be output to, for example, but not limited to, a transmitter and transmitted by the transmitter. Moreover, the input circuit and the output circuit can be the same circuit, which is used as the input circuit and the output circuit at different times respectively. The embodiments of the present application do not limit the specific implementation manners of the processor and various circuits.

[0022] In a fourth aspect, a processing device is provided, including a processor and a memory. The processor is used to read instructions stored in the memory, and can receive signals through a receiver and transmit signals through a transmitter to execute the method in any possible implementation manner in the above-mentioned first aspect.

[0023] Optionally, there is one or more processors, and one or more memories.

[0024] Optionally, the memory can be integrated with the processor, or the memory is separately arranged from the processor.

[0025] In the specific implementation process, the memory can be a non-transitory memory, such as a read only memory (ROM). It can be integrated with the processor on the same chip, or can be separately arranged on different chips. The embodiments of the present application do not limit the type of the memory and the setting manner of the memory and the processor.

[0026] The processing device in the above-mentioned fourth aspect can be a chip. The processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in the memory. The memory can be integrated in the processor or can be located outside the processor and exist independently.

[0027] In a fifth aspect, a computer program product is provided. The computer program product includes: a computer program (which can also be called code, or instruction). When the computer program is run, it causes the computer to execute the method in any possible implementation manner in the above-mentioned first aspect.

[0028] In a sixth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (which can also be called code, or instruction). When it runs on a computer, it causes the computer to execute the method in any possible implementation manner in the above-mentioned first aspect. Brief Description of the Drawings

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0030] Figure 1 It is a schematic flowchart of a method for detecting abnormal operation behaviors provided by an embodiment of the present application;

[0031] Figure 2 It is a schematic flowchart of a method for training a classification model provided by an embodiment of the present application;

[0032] Figure 3 It is a schematic diagram of a device for detecting abnormal operation behaviors provided by an embodiment of the present application;

[0033] Figure 4 It is a schematic diagram of another device for detecting abnormal operation behaviors provided by an embodiment of the present application. Detailed Embodiments

[0034] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art under the inspiration of this embodiment belong to the scope protected by the present application.

[0035] It should be noted that the method for detecting abnormal operation behaviors and the device for detecting abnormal operation behaviors of the present disclosure can be used in the fields of artificial intelligence and information security, and can also be used in any field other than the fields of artificial intelligence and information security. The data processing method and data processing device of the present disclosure do not limit the application field.

[0036] With the rapid development of cloud computing technology, more and more enterprises choose to move their businesses to the cloud. Based on their own business characteristics and technical capabilities, a large number of enterprises choose to build private clouds. Users can achieve the periodic management and basic operation and maintenance of cloud services through the self-service interface of the cloud management platform. In the actual operation and maintenance process, many enterprises will carry out certain personnel division of labor for operations on systems (including computing and storage) and networks, resulting in possible illegal network queries and other operations by system operators, and illegal virtual machine viewing and other operations by network operators, leading to potential security hazards.

[0037] Currently, the cloud management platform mainly analyzes and detects the deviation of the user's actual activities from normal operations based on the access frequency, duration, common login time periods, and the amount of access data for specific content in the user's operation logs, and then determines whether there are abnormal operations.

[0038] However, it is difficult for the above method to specifically discover abnormal operation behaviors such as information queries and device operations that are not for work needs by the user, resulting in a relatively low security level of the cloud management platform.

[0039] In view of this, the present application provides a method for detecting abnormal operation behaviors and a device for detecting abnormal operation behaviors. When the user type is associated with the user operation behavior, the device for detecting abnormal operation behaviors can obtain the types of different operation behaviors through a classification model. It should be understood that the user type can be the functional type of the user, such as a system user or a network user, and different types of users can correspond to different operation behaviors. When the type of the above operation behavior is different from the corresponding user type, the device for detecting abnormal operation behaviors can determine that the operation behavior may be an abnormal operation behavior and perform intervention management, which is beneficial to the efficient detection of abnormal operation behaviors that are not for work needs by the user, improves the security level of the cloud management platform, and thereby reduces the losses of the enterprise.

[0040] Before introducing the method for detecting abnormal operation behaviors and the detection device provided by the embodiments of the present application, the following points are explained first.

[0041] First, in the embodiments shown below, each term and English abbreviation are exemplary examples given for convenience of description, and should not constitute any limitation to the present application. The present application does not exclude the possibility of defining other terms that can achieve the same or similar functions in existing or future protocols.

[0042] Second, in the embodiments shown below, the first, second, and various numerical numbers are only for the convenience of description and are not used to limit the scope of the embodiments of the present application.

[0043] Third, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (item)" or its similar expression below refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b, and c, where a, b, and c can be single or multiple.

[0044] To make the objectives and technical solutions of this application clearer and more intuitive, the following will, in conjunction with the accompanying drawings and embodiments, provide a detailed description of the method for detecting abnormal operation behaviors and the device for detecting abnormal operation behaviors provided by this application. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0045] Figure 1 FIG. 6 is a schematic flowchart of the method 100 for detecting abnormal operation behaviors provided by an embodiment of this application. This method can be executed by any device with data processing capabilities. For the convenience of description, this application refers to it as the "device for detecting abnormal operation behaviors". As Figure 1 shown, this method 100 may include the following steps:

[0046] S101. The device for detecting abnormal operation behaviors obtains the operation behavior information of the target user.

[0047] Optionally, the above operation behavior information of the target user may be an operation behavior corresponding to a single operation of the target user, or may be multiple operation behaviors of the above user within a period of time. The operation behavior may be behaviors such as binding an IP, creating a subnet, creating a cloud server, etc. This application does not make any limitations thereto.

[0048] It should be understood that the above target user may be one or multiple, and this application does not make any limitations thereto.

[0049] S102. The device for detecting abnormal operation behaviors inputs the above operation behavior information into the classification model to obtain the classification result of the above operation behavior information.

[0050] Optionally, the classification result of the above operation behavior information may include two categories: system type and network type. Among them, the system type may be represented by "1", and the network type may be represented by "-1", that is, the classification result of the above operation behavior information may be "1" or "-1".

[0051] It should be understood that the above classification model is trained with sample data obtained after feature filtering based on the mutual information classification method and the Pearson correlation coefficient method.

[0052] S103. The device for detecting abnormal operation behaviors determines whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior based on the above classification result, the user identification of the above target user, and the pre-stored user type relationship table.

[0053] In a possible implementation, the detection device for abnormal operation behaviors may use the above classification result as the predicted user type of the above target user, obtain, based on the user identifier of the above target user, the user type corresponding to the user identifier of the target user in the user type relationship table, and compare the above predicted user type with the user type corresponding to the user identifier of the target user to determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0054] In another possible implementation, the detection device for abnormal operation behaviors may, based on the above classification result, obtain at least one user identifier (which may also be referred to as a predicted user identifier) corresponding to the classification result in the user type relationship table, and compare the user identifier of the target user with the above at least one user identifier to determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0055] It should be understood that the above user type relationship table is used to represent the corresponding relationship between user types and user identifiers.

[0056] Table 1 is the user type relationship table.

[0057] Table 1

[0058] User ID User type Zhang San System class (1) Li Si Network class (-1) Wang Wu System class (1)

[0059] As shown in Table 1, the user types are the same as the classification of the above operation behavior information, and may include two categories: system type "1" and network type "-1". Among them, the users with user identifiers "Zhang San" and "Wang Wu" are system type users, and the user with user identifier "Li Si" is a network type user.

[0060] It should be understood that the above user type may be determined by the job functions of the users corresponding to the user identifiers. Or, it may also be determined by analyzing the historical operation behaviors of the users corresponding to the user identifiers through expert experience. This application does not make any limitations in this regard.

[0061] Optionally, when the operation behavior corresponding to the above operation behavior information is an abnormal behavior, the detection device for abnormal operation behaviors may further send an alarm message.

[0062] In a possible implementation, the detection device for abnormal operation behaviors may determine that the operation behavior corresponding to the above operation behavior information is an abnormal behavior and send an alarm message when it determines that the above predicted user type is different from the user type corresponding to the user identifier of the target user.

[0063] In another possible implementation, the detection device for abnormal operation behaviors may determine that the operation behavior corresponding to the above operation behavior information is an abnormal behavior and send an alarm message when it determines that the user identifier of the target user is not among the above at least one user identifier.

[0064] For example, when it is determined that the operation behavior corresponding to the above operation behavior information is abnormal behavior, the detection device of abnormal operation behavior can send a warning message such as a text message or an email to the relevant classification result reviewer. The reviewer can review and, when it is determined that the above classification result is correct, that is, the operation behavior corresponding to the above operation behavior information is abnormal behavior, freeze the user for the user who does have abnormal operation to reduce the loss of the enterprise. Alternatively, when it is determined that the above classification result is wrong, the classification model can be retrained to optimize the classification model.

[0065] Optionally, when the abnormal operation behavior detection device determines that the predicted user type is the same as the user type corresponding to the user identifier of the target user, or when it is determined that the user identifier of the target user is in at least one of the above-mentioned user identifiers, it can determine that the operation behavior corresponding to the above-mentioned operation behavior information is not abnormal behavior, and the abnormal operation behavior detection device may not perform any operation.

[0066] In an embodiment of the present application, when the user type and the user operation behavior are associated, the detection device of abnormal operation behavior can obtain the types of different operation behaviors through the classification model. It should be understood that the user type can be the functional type of the user, such as a system user or a network user, and different types of users can correspond to different operation behaviors. In the case where the type of the above-mentioned operation behavior is different from the type of its corresponding user, the detection device of abnormal operation behavior can determine that the operation behavior may be an abnormal operation behavior and issue an alarm so that the management personnel can intervene and manage the abnormal operation behavior, which is conducive to the efficient detection of abnormal operation behaviors of users that are not required for work, improve the security of the cloud management platform, and thus reduce corporate losses.

[0067] It should be understood that in order to ensure that the above classification model can output accurate classification results, the classification model is trained by inputting sample data into a pre-trained model. Figure 2 The training method of the classification model of this application is introduced in detail.

[0068] Figure 2 It is a schematic flow chart of the training method 200 of the classification model provided in the embodiment of the present application. In one possible implementation, the method 200 can be performed by the above-mentioned abnormal operation behavior detection device. Optionally, the abnormal operation behavior detection device can first execute method 200, and after obtaining the classification model, execute method 100 to detect the operation behavior information of the target user. In another possible implementation, the method 200 can be executed by another device different from the abnormal operation behavior detection device, and the embodiment of the present application is not limited to this.

[0069] For ease of description, the following uses the detection device for abnormal operation behaviors as the execution subject of Method 200 as an example for illustration. As Figure 2 shown, this Method 200 may include the following steps:

[0070] S201. The detection device for abnormal operation behaviors obtains data to be processed, where the data to be processed includes the operation behavior information of a user within a period of time, the occurrence times of the operation behaviors corresponding to the operation behavior information, the user type and user identifier corresponding to the operation behavior information.

[0071] Table 2 is the above data to be processed.

[0072] Table 2

[0073]

[0074] As shown in Table 2, the data to be processed includes the operation behavior information of three users with user identifiers of "Zhang San", "Li Si", and "Wang Wu" within a period of time. Among them, the operation behaviors corresponding to the operation behavior information include downloading files, modifying passwords, creating cloud servers, creating empty cloud hard disks, creating bare metal servers, binding IPs, creating subnets, and applying for firewalls. The user type of the user with the user identifier of "Zhang San" is system type (1), the user type of the user with the user identifier of "Li Si" is network type (-1), and the user type of the user with the user identifier of "Wang Wu" is also system type (1). The occurrence times of the operation behaviors corresponding to the operation behavior information are shown in Table 2, and this application will not elaborate on this.

[0075] Optionally, the above data to be processed can also be represented by vectors.

[0076] Exemplarily, corresponding to Table 1 above, the data to be processed can be represented as the following vectors:

[0077] x1 = [0, 0, 3, 1, 0, 2, 0, 0] y1 = 1

[0078] x2 = [0, 1, 0, 0, 2, 2, 0, 0] y2 = 1

[0079] x3 = [1, 1, 10, 0, 0, 0, 0, 0] y3 = 1

[0080] x4 = [1, 1, 0, 0, 0, 0, 4, 0] y4 = -1

[0081] x5 = [0, 0, 0, 0, 0, 0, 1, 2] y5 = -1

[0082] x6 = [1, 0, 10, 8, 1, 16, 0, 0] y6 = 1

[0083] Among them, x1 = [0, 0, 3, 1, 0, 2, 0, 0], y1 = 1, x2 = [0, 1, 0, 0, 2, 2, 0, 0], y2 = 1, and x3 = [1, 1, 10, 0, 0, 0, 0, 0], y3 = 1 are used to represent the operation behavior information of a user with the user ID of "Zhang San" and the user type of system class (1) at different sub - times within the above - mentioned period of time. x4 = [1, 1, 0, 0, 0, 0, 4, 0], y4 = - 1 and x5 = [0, 0, 0, 0, 0, 0, 1, 2], y5 = - 1 are used to represent the operation behavior information of a user with the user ID of "Li Si" and the user type of network class (- 1) at different sub - times within the above - mentioned period of time. x6 = [1, 0, 10, 8, 1, 16, 0, 0], y6 = 1 is used to represent the operation behavior information of a user with the user ID of "Wang Wu" and the user type of system class (1) at different sub - times within the above - mentioned period of time.

[0084] Taking x1 = [0, 0, 3, 1, 0, 2, 0, 0], y1 = 1 as an example, from left to right, the first "0" is used to represent the number of times of the above - mentioned download file operation behavior, the second "0" is used to represent the number of times of the above - mentioned modify password operation behavior, "3" is used to represent the number of times of the above - mentioned create cloud server operation behavior, "1" is used to represent the number of times of the above - mentioned create empty white cloud hard disk operation behavior, the third "0" is used to represent the number of times of the above - mentioned create bare - metal server operation behavior, "2" is used to represent the number of times of the above - mentioned bind IP operation behavior, the fourth "0" is used to represent the number of times of the above - mentioned create subnet operation behavior, and the fifth "0" is used to represent the number of times of the above - mentioned apply for firewall operation behavior.

[0085] It should be understood that the above - shown download file operation behavior, modify password operation behavior, create cloud server operation behavior, create empty white cloud hard disk operation behavior, create bare - metal server operation behavior, bind IP operation behavior, create subnet operation behavior, and apply for firewall operation behavior are only exemplary, and this application does not limit them.

[0086] S202. The detection device for abnormal operation behavior performs normalization and variance filtering on the above - mentioned data to be processed, and obtains data with a variance greater than or equal to the first preset threshold.

[0087] In a possible implementation manner, the detection device for abnormal operation behavior can perform normalization processing on the sum of the occurrence times of the same operation behavior corresponding to the operation behavior information of the same user within the above - mentioned period of time in the above - mentioned data to be processed, obtain the result after normalization processing, and perform variance filtering on the result after normalization processing to obtain the data with the variance greater than or equal to the first preset threshold.

[0088] Exemplarily, the detection device for abnormal operation behaviors sums up the occurrence times of the same operation behaviors corresponding to the operation behavior information of the user with the user identification of "Zhang San" in the above-mentioned period of time in the above-mentioned data to be processed.

[0089]

[0090] A summation vector can be obtained where n represents the number of vectors corresponding to the preprocessed data of the user "Zhang San", and, from left to right, the first "1" can represent the sum of the occurrence times of downloading files by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0091] The first "2" can represent the sum of the occurrence times of modifying passwords by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0092] "13" can represent the sum of the occurrence times of creating cloud servers by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0093] The second "1" can represent the sum of the occurrence times of creating empty white cloud hard disks by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0094] The second "2" can represent the sum of the occurrence times of creating bare metal servers by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0095] "4" can represent the sum of the occurrence times of binding IPs by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0096] The first "0" can represent the sum of the occurrence times of creating subnets by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0097] The second "0" can represent the sum of the occurrence times of applying for firewalls by the user "Zhang San" in different sub-time periods within the above-mentioned period of time.

[0098] Similarly, the detection device for abnormal operation behaviors sums up the occurrence times of the same operation behaviors corresponding to the operation behavior information of the user with the user identification of "Li Si" in a period of time in the above-mentioned data to be processed, where n represents the number of vectors corresponding to the preprocessed data of the user "Li Si".

[0099]

[0100] Similarly, the detection device for abnormal operation behaviors can also sum up the occurrence times of the same operation behaviors corresponding to the operation behavior information of the users with the user identifier of "Wang Wu" in the to-be-processed data for a period of time, where n represents the number of vectors corresponding to the preprocessed data of the user "Wang Wu".

[0101]

[0102] Exemplarily, the detection device for abnormal operation behaviors can set the values greater than or equal to 1 in the above summation vector to 1 and keep the values of 0 unchanged, obtaining the normalized vectors X1 = [1, 1, 1, 1, 1, 1, 0, 0], X2 = [1, 1, 0, 0, 0, 0, 1, 1] and X3 = [1, 0, 1, 1, 1, 1, 0, 0], and can perform variance filtering processing on the above normalized vectors to obtain the data with the variance greater than or equal to the first preset threshold.

[0103] Optionally, in addition to being represented by the above normalized vectors, the data after the above normalization processing can also be presented in a table.

[0104] Table 3 shows the data after normalization provided by the embodiments of the present application.

[0105] Table 3

[0106]

[0107] Taking the download file corresponding to the operation behavior information of the above users as an example below, that is, calculating the variance of the array [1, 1, 1] composed of .

[0108] Assuming that the variance corresponding to the above download file is less than the first set threshold, that is, it can be considered that the download file is a useless feature, and the detection device for abnormal operation behaviors will remove it from the above preprocessed data to obtain the following new data, that is, the data with the variance greater than or equal to the first preset threshold.

[0109] x1' = [0, 3, 1, 0, 2, 0, 0] y1 = 1

[0110] x2' = [1, 0, 0, 2, 2, 0, 0] y2 = 1

[0111] x3' = [1, 10, 0, 0, 0, 0, 0] y3 = 1

[0112] x4' = [1, 0, 0, 0, 0, 4, 0] y4 = -1

[0113] x5' = [0, 0, 0, 0, 0, 1, 2] y5 = -1

[0114] x6′ = [0, 10, 8, 1, 16, 0, 0] y6 = 1

[0115] S203. The detection device for abnormal operation behaviors performs a filtering feature selection process on the data with the above variance greater than or equal to the first preset threshold, and obtains the data with the relevant statistic greater than or equal to the second preset threshold.

[0116] In a possible implementation manner, the detection device for abnormal operation behaviors can use the formula to calculate the data with the relevant statistic greater than or equal to the second preset threshold. Wherein, δ j is the relevant statistic of the j-th feature (i.e., the j-th operation behavior), i represents the number of data with the above variance greater than or equal to the first preset threshold, and in this application, i = 1, 2, 3, 4, 5, 6. represents the value of the j-th feature in x i . is the data related to "near-hit" is the data related to "near-miss".

[0117] Exemplarily, taking the above x1′ = [0, 3, 1, 0, 2, 0, 0] y1 = 1 as an example, the near-hit x1′ of x1′ ,nh is the data closest to x1′ among all the data with y = 1, and the near-miss x′ of x1′ 1,nm is the data closest to x1′ among all the data with y = -1. represents the value of the j-th feature in x1′ = [0, 3, 1, 0, 2, 0, 0] y1 = 1, that is Similarly, the detection device for abnormal operation behaviors can obtain the near-hits and near-misses of x2′, x3′, x4′, x5′ and x6′, and can use the formula to calculate the relevant statistics δ j of the corresponding features of x1′, x2′, x3′, x4′, x5′ and x6′. Taking δ 1 as an example, if δ 1 is less than the second preset threshold, the detection device for abnormal operation behaviors can remove the first feature (i.e., the operation behavior) in x1′, x2′, x3′, x4′, x5′ and x6′ to obtain the following new data.

[0118] x1″ = [3, 1, 0, 2, 0, 0] y1 = 1

[0119] x2″ = [0, 0, 2, 2, 0, 0] y2 = 1

[0120] x3″ = [10, 0, 0, 0, 0, 0] y3 = 1

[0121] x4″ = [0, 0, 0, 0, 4, 0] y4 = -1

[0122] x5″ = [0, 0, 0, 0, 1, 2] y5 = -1

[0123] x6″ = [10, 8, 1, 16, 0, 0] y6 = 1

[0124] Similarly, judge δ 2 , δ 3 , δ 4 , δ 5 , δ 6 and δ 7 , and determine whether to eliminate the corresponding features. To avoid repetition, it will not be elaborated here.

[0125] S204. The detection device for abnormal operation behaviors filters the features of other data except the data with the above-mentioned correlation statistics greater than or equal to the second preset threshold in the data with the variance greater than or equal to the first preset threshold based on the mutual information classification method and the Pearson correlation coefficient method, and obtains the data with the estimated value of mutual information greater than or equal to the third preset threshold and the Pearson correlation coefficient greater than or equal to the fourth preset threshold.

[0126] It should be understood that the other data except the data with the above-mentioned correlation statistics greater than or equal to the second preset threshold in the data with the variance greater than or equal to the first preset threshold can also be understood as the data with the correlation statistics less than the second preset threshold in the data with the variance greater than or equal to the first preset threshold.

[0127] Optionally, the range of the estimated value of the mutual information can be [0, 1], and the range of the Pearson correlation coefficient can be [-1, 1].

[0128] Exemplarily, the data with the variance greater than or equal to the first preset threshold includes x1′, x2′, x3′, x4′, x5′ and x6′. Among them, the data with the correlation statistics less than the second preset threshold in x1′ is The detection device for abnormal operation behaviors can obtain the estimated value of the mutual information and the Pearson correlation coefficient of the data based on the mutual information classification method and the Pearson correlation coefficient method, and when the estimated value of the mutual information is greater than or equal to the third preset threshold 0.6 and the Pearson correlation coefficient is greater than or equal to the fourth preset threshold 0.55 for the data, the data is The corresponding feature, that is, the above-mentioned downloaded file, is determined as an important feature.

[0129] Similarly, the estimated mutual information value and Pearson correlation coefficient of the data with the above variance greater than or equal to the first preset threshold and the relevant statistic less than the second preset threshold are obtained through the above mutual information classification method and Pearson correlation coefficient method, and then it is determined whether there are other important features. To avoid repetition, no further elaboration is provided here.

[0130] S205. The abnormal operation behavior detection device determines the above data with the relevant statistic greater than or equal to the second preset threshold, and the data with the estimated mutual information value greater than or equal to the third preset threshold and the Pearson correlation coefficient greater than or equal to the fourth preset threshold as the above sample data.

[0131] Exemplarily, the abnormal operation behavior detection device processes the data x1' of user "Zhang San" through a filter feature selection method to obtain new data x1'', and determines the corresponding features through the mutual information classification method and Pearson correlation coefficient method, that is, the above downloaded file is determined as an important feature. The abnormal operation behavior detection device can fill it back into x1'', and obtain the sample data x1''' = [0, 3, 1, 0, 2,] of user "Zhang San". 0, 0

[0132] Similarly, through the above method, the other two sample data x2''' and x3''' of user "Zhang San", the sample data x4''' and x5''' of user "Li Si", and the sample data x6''' of user "Wang Wu" are obtained.

[0133] S206. The abnormal operation behavior detection device inputs the above sample data into a pre-trained model for training to obtain the above classification model.

[0134] Exemplarily, the abnormal operation behavior detection device can input the above sample data x1''', x2''', x3''', x4''', and x6''' into the pre-trained model for training, and when the output classification result of the pre-trained model is the same as the corresponding type in the above sample data, the modeling is successful, and the above classification model is obtained.

[0135] Optionally, the above pre-trained model can be a support vector machine (SVM) model. To improve the generalization ability and recognition accuracy of the SVM model, the kernel function in this solution can select the radial basis function (RBF). Among them, the penalty coefficient and the kernel function coefficient (gamma) can be exhaustively searched within a certain range using the grid method, and it is determined whether it is the best parameter combination according to the recognition rate.

[0136] ​Exemplarily, the above penalty coefficient can be exhaustively enumerated at intervals of 1 within the range of (1, 100), and gamma can be exhaustively enumerated between (0.001, 0.2).

[0137] In the embodiments of the present application, the detection device for abnormal operation behaviors eliminates irrelevant features (i.e., operation behaviors that occur for different types of users) in the preprocessed data through user-level variance. The detection device for abnormal operation behaviors can select a filtering feature selection method to perform feature selection on the data from which the irrelevant features have been eliminated. Moreover, to avoid the problem that important features are not selected during the feature filtering and selection process in the filtering feature selection method based on distance measurement, the present application can also process the features that are not selected by the filtering feature selection method through the mutual information classification method and the Pearson correlation coefficient method, avoiding the omission of important features, greatly alleviating the curse of dimensionality problem, and improving the accuracy of model training.

[0138] Optionally, the above sample data includes training data and test data. The detection device for abnormal operation behaviors can input the training data into a pre-trained model for training to obtain the above classification model.

[0139] Exemplarily, the detection device for abnormal operation behaviors can divide the above sample data into training data and test data according to a ratio of 8:2.

[0140] Optionally, after obtaining the above classification model, the detection device for abnormal operation behaviors can also input the above test data into the above classification model to obtain a test classification result of the operation behavior information in the test data, and can optimize the above classification model according to the test classification result.

[0141] In a possible implementation manner, the detection device for abnormal operation behaviors can compare the test classification result with the actual type of the operation behavior information in the test data, and when it is determined that the test classification result is different from the actual type of the operation behavior information in the test data, it is determined that the accuracy rate of the classification model is relatively low, and then the above classification model can be optimized.

[0142] Optionally, when the detection device for abnormal operation behaviors determines that the test classification result is the same as the actual type of the operation behavior information in the test data, it can be considered that the accuracy rate of the classification model is relatively high, and an accurate classification result can be output. The detection device for abnormal operation behaviors can not perform any operation.

[0143] It should be understood that the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0144] To implement each function in the method provided in the embodiments of the present application above, the detection device for abnormal operation behaviors may include a hardware structure and / or software modules, and implement the above functions in the form of a hardware structure, software modules, or a combination of a hardware structure and software modules. Whether a certain function among the above functions is executed in the form of a hardware structure, software modules, or a combination of a hardware structure and software modules depends on the specific application and design constraints of the technical solution.

[0145] In the above text, in combination with Figure 1 and Figure 2 , the detection method for abnormal operation behaviors provided in the embodiments of the present application has been described in detail. Next, in combination with Figure 3 and Figure 4 , the detection device for abnormal operation behaviors provided in the embodiments of the present application will be described in detail.

[0146] Figure 3 FIG. shows the detection device 300 for abnormal operation behaviors provided in the embodiments of the present application, including: an acquisition module 301 and a processing module 302.

[0147] Among them, the acquisition module 301 is used to: acquire the operation behavior information of the target user; the processing module 302 is used to: input the above operation behavior information into a classification model to obtain a classification result of the above operation behavior information, and the above classification model is trained with sample data obtained by feature filtering based on the mutual information classification method and the Pearson correlation coefficient method; and, based on the above classification result, the user identifier of the above target user, and a pre-stored user type relationship table, determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior, and the above user type relationship table is used to represent the corresponding relationship between user types and user identifiers.

[0148] Optionally, the processing module 302 is used to: use the above classification result as the predicted user type of the above target user; based on the user identifier of the above target user, obtain the user type corresponding to the user identifier of the above target user in the above user type relationship table; compare the above predicted user type with the user type corresponding to the user identifier of the above target user to determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0149] Optionally, the processing module 302 is used to: based on the above classification result, obtain at least one predicted user identifier; compare the user identifier of the above target user with the above at least one predicted user identifier to determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0150] Optionally, the obtaining module 301 is configured to: obtain data to be processed, where the data to be processed includes the operation behavior information of a user within a period of time, the occurrence times of the operation behaviors corresponding to the operation behavior information, the user type and user identifier corresponding to the operation behavior information; the processing module 302 is configured to: perform normalization and variance filtering on the data to be processed to obtain data with a variance greater than or equal to a first preset threshold; perform filter-based feature selection on the data with a variance greater than or equal to the first preset threshold to obtain data with a correlation statistic greater than or equal to a second preset threshold; based on the mutual information classification method and the Pearson correlation coefficient method, perform feature filtering on the other data in the data with a variance greater than or equal to the first preset threshold except for the data with a correlation statistic greater than or equal to the second preset threshold to obtain data with an estimated mutual information value greater than or equal to a third preset threshold and a Pearson correlation coefficient greater than or equal to a fourth preset threshold; determine the data with a correlation statistic greater than or equal to the second preset threshold and the data with an estimated mutual information value greater than or equal to the third preset threshold and the Pearson correlation coefficient greater than or equal to the fourth preset threshold as the sample data; input the sample data into a pre-trained model for training to obtain the classification model.

[0151] Optionally, the processing module 302 is configured to: perform normalization processing on the sum of the occurrence times of the same operation behaviors corresponding to the operation behavior information of the same user within the period of time in the data to be processed to obtain a normalized result; perform variance filtering on the normalized result to obtain data with a variance greater than or equal to the first preset threshold.

[0152] Optionally, the sample data includes training data and test data; the processing module 302 is configured to: input the training data into the pre-trained model for training to obtain the classification model; input the test data into the classification model to obtain a test classification result of the operation behavior information in the test data; optimize the classification model according to the test classification result.

[0153] Optionally, the processing module 302 is configured to: send an alarm message when the operation behavior corresponding to the operation behavior information is an abnormal behavior.

[0154] It should be understood that the device 300 here is embodied in the form of functional modules. The term "module" here may refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a proprietary processor or a group of processors, etc.) for executing one or more software or firmware programs, and a memory, a combined logic circuit and / or other suitable components that support the described functions. In an alternative example, those skilled in the art can understand that the device 300 can specifically be the detection device for abnormal operation behaviors in the above embodiments, or the functions of the detection device for abnormal operation behaviors in the above embodiments can be integrated in the device 300. The device 300 can be used to execute each process and / or step corresponding to the detection device for abnormal operation behaviors in the above method embodiments. To avoid repetition, it will not be described in detail here. The above device 300 has the function of implementing the corresponding steps executed by the detection device for abnormal operation behaviors in the above method; the above function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0155] In the embodiments of the present application, Figure 3 the device 300 therein can also be a chip or a chip system, for example: a system on chip (SoC).

[0156] Figure 4 Another detection device 400 for abnormal operation behaviors provided by the embodiments of the present application is shown. The device 400 includes: a processor 401, a memory 402, a communication interface 403 and a bus 404. Among them, the memory 402 is used to store instructions, and the processor 401 is used to execute the instructions stored in the memory 402. The processor 401, the memory 402 and the communication interface 403 are communicatively connected to each other through the bus 404.

[0157] Among them, the processor 401 is used to: obtain the operation behavior information of the target user; input the above operation behavior information into a classification model to obtain the classification result of the above operation behavior information, and the above classification model is trained with sample data obtained by feature filtering based on the mutual information classification method and the Pearson correlation coefficient method; and, based on the above classification result, the user identifier of the above target user and a pre-stored user type relationship table, determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior, and the above user type relationship table is used to represent the corresponding relationship between the user type and the user identifier.

[0158] Optionally, the processor 401 is configured to: use the above classification result as the predicted user type of the above target user; obtain, based on the user identifier of the above target user, the user type corresponding to the user identifier of the above target user in the above user type relationship table; compare the above predicted user type with the user type corresponding to the user identifier of the above target user, and determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0159] Optionally, the processor 401 is configured to: obtain at least one predicted user identifier based on the above classification result; compare the user identifier of the above target user with the above at least one predicted user identifier, and determine whether the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0160] Optionally, the processor 401 is configured to: obtain data to be processed, where the data to be processed includes the operation behavior information of a user within a period of time, the occurrence times of the operation behavior corresponding to the above operation behavior information, the user type and user identifier corresponding to the above operation behavior information; perform normalization and variance filtering processing on the above data to be processed to obtain data with a variance greater than or equal to a first preset threshold; perform filter-based feature selection processing on the data with a variance greater than or equal to the first preset threshold to obtain data with a correlation statistic greater than or equal to a second preset threshold; based on the mutual information classification method and the Pearson correlation coefficient method, perform feature filtering on the other data in the data with a variance greater than or equal to the first preset threshold except for the data with a correlation statistic greater than or equal to the second preset threshold to obtain data with an estimated mutual information value greater than or equal to a third preset threshold and a Pearson correlation coefficient greater than or equal to a fourth preset threshold; determine the data with a correlation statistic greater than or equal to the second preset threshold and the data with an estimated mutual information value greater than or equal to the third preset threshold and the Pearson correlation coefficient greater than or equal to the fourth preset threshold as the above sample data; input the above sample data into a pre-trained model for training to obtain the above classification model.

[0161] Optionally, the processor 401 is configured to: perform normalization processing on the sum of the occurrence times of the same operation behavior corresponding to the operation behavior information of the same user within the above period of time in the above data to be processed to obtain a normalized result; perform variance filtering processing on the above normalized result to obtain data with a variance greater than or equal to the first preset threshold.

[0162] Optionally, the processor 401 is configured to: the above sample data includes training data and test data; input the above training data into the above pre-trained model for training to obtain the above classification model; input the above test data into the above classification model to obtain a test classification result of the operation behavior information in the above test data; optimize the above classification model according to the above test classification result.

[0163] Optionally, the processor 401 is configured to: send an alarm message when the operation behavior corresponding to the above operation behavior information is an abnormal behavior.

[0164] It should be understood that the apparatus 400 may specifically be the detection device for abnormal operation behaviors in the above embodiments, or the functions of the detection device for abnormal operation behaviors in the above embodiments may be integrated in the apparatus 400. The apparatus 400 may be configured to execute each step and / or process corresponding to the detection device for abnormal operation behaviors in the above method embodiments. Optionally, the memory 403 may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may further include a non-volatile random access memory. For example, the memory may further store information about the device type. The processor 401 may be configured to execute the instructions stored in the memory, and when the processor executes the instructions, the processor may execute each step and / or process corresponding to the detection device for abnormal operation behaviors in the above method embodiments.

[0165] It should be understood that in the embodiments of the present application, the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0166] In the implementation process, each step of the above method may be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed and completed by the hardware processor, or executed and completed by a combination of the hardware and software modules in the processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor executes the instructions in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0167] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0168] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0169] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0170] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0171] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0172] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0173] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.

Claims

1. A detection method for abnormal operation behaviors, characterized in that, Including: Obtaining operation behavior information of a target user; Inputting the operation behavior information into a classification model to obtain a classification result of the operation behavior information, where the classification model is trained with sample data obtained by performing feature filtering based on the mutual information classification method and the Pearson correlation coefficient method; Based on the classification result, the user identifier of the target user, and a pre-stored user type relationship table, determining whether the operation corresponding to the operation behavior information is an abnormal behavior, where the user type relationship table is used to represent the corresponding relationship between user types and user identifiers; Before obtaining the operation behavior information of the target user, the method further includes: Obtaining data to be processed, where the data to be processed includes operation behavior information of a user within a period of time, the occurrence times of the operations corresponding to the operation behavior information, the user types corresponding to the operation behavior information, and user identifiers; Performing normalization processing on the sum of the occurrence times of the same operations corresponding to the operation behavior information of the same user within the period of time in the data to be processed to obtain a result after normalization processing; Performing variance filtering processing on the result after normalization processing to obtain data with a variance greater than or equal to a first preset threshold; Performing filter-based feature selection processing on the data with a variance greater than or equal to the first preset threshold to obtain data with a correlation statistic greater than or equal to a second preset threshold; Based on the mutual information classification method and the Pearson correlation coefficient method, performing feature filtering on the other data in the data with a variance greater than or equal to the first preset threshold except for the data with a correlation statistic greater than or equal to the second preset threshold to obtain data with an estimated mutual information value greater than or equal to a third preset threshold and a Pearson correlation coefficient greater than or equal to a fourth preset threshold; Determining the data with a correlation statistic greater than or equal to the second preset threshold and the data with an estimated mutual information value greater than or equal to the third preset threshold and a Pearson correlation coefficient greater than or equal to the fourth preset threshold as the sample data; Inputting the sample data into a pre-trained model for training to obtain the classification model.

2. The method according to claim 1, characterized in that, The determining whether the operation corresponding to the operation behavior information is an abnormal behavior based on the classification result, the user identifier of the target user, and the pre-stored user type relationship table includes: Taking the classification result as the predicted user type of the target user; Based on the user identifier of the target user, obtaining the user type corresponding to the user identifier of the target user in the user type relationship table; Comparing the predicted user type with the user type corresponding to the user identifier of the target user to determine whether the operation corresponding to the operation behavior information is an abnormal behavior.

3. The method according to claim 2, wherein The method further includes: Based on the classification result, obtaining at least one predicted user identifier; Comparing the user identifier of the target user with the at least one predicted user identifier to determine whether the operation corresponding to the operation behavior information is an abnormal behavior.

4. The method according to claim 1, wherein The sample data includes training data and test data; The inputting the sample data into a pre-trained model for training to obtain the classification model includes: Input the training data into the pre-trained model for training to obtain the classification model; After obtaining the classification model, the method further includes: Input the test data into the classification model to obtain the test classification result of the operation behavior information in the test data; Optimize the classification model according to the test classification result.

5. The method according to any one of claims 1 to 4, characterized in that The method further includes: Send an alarm message when the operation behavior corresponding to the operation behavior information is an abnormal behavior.

6. A detection device for abnormal operation behavior, characterized in that, Includes: An acquisition module for acquiring the operation behavior information of the target user; A processing module for inputting the operation behavior information into a classification model to obtain a classification result of the operation behavior information. The classification model is trained with sample data obtained by feature filtering based on the mutual information classification method and the Pearson correlation coefficient method; And, based on the classification result, the user identifier of the target user, and a pre-stored user type relationship table, determine whether the operation behavior corresponding to the operation behavior information is an abnormal behavior. The user type relationship table is used to represent the corresponding relationship between the user type and the user identifier; The acquisition module is further configured to acquire data to be processed, where the data to be processed includes the operation behavior information of the user within a period of time, the occurrence times of the operation behavior corresponding to the operation behavior information, the user type corresponding to the operation behavior information, and the user identifier; The processing module is further configured to perform normalization processing on the sum of the occurrence times of the same operation behavior corresponding to the operation behavior information of the same user within the period of time in the data to be processed to obtain a normalized result; Perform variance filtering processing on the normalized result to obtain data with a variance greater than or equal to a first preset threshold; Perform filtering feature selection processing on the data with a variance greater than or equal to the first preset threshold to obtain data with a correlation statistic greater than or equal to a second preset threshold; Based on the mutual information classification method and the Pearson correlation coefficient method, perform feature filtering on the other data in the data with a variance greater than or equal to the first preset threshold except for the data with a correlation statistic greater than or equal to the second preset threshold to obtain data with an estimated mutual information value greater than or equal to a third preset threshold and a Pearson correlation coefficient greater than or equal to a fourth preset threshold; Determine the data with a correlation statistic greater than or equal to the second preset threshold and the data with an estimated mutual information value greater than or equal to the third preset threshold and a Pearson correlation coefficient greater than or equal to the fourth preset threshold as the sample data; Input the sample data into the pre-trained model for training to obtain the classification model.

7. A detection device for abnormal operation behaviors, characterized in that Includes: A processor, the processor is coupled with a memory, and the memory is used to store a computer program. When the processor calls the computer program, the device executes the detection method for abnormal operation behaviors according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, For storing a computer program, the computer program includes instructions for implementing the detection method for abnormal operation behaviors according to any one of claims 1 to 5.

9. A computer program product, characterized in that, Comprising a computer program which, when executed by a processor, implements the method for detecting abnormal operation behaviors according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Internal threat detection method and device

    CN110909348A

  • Self-learning-based power network probe flow anomaly detection method

    CN112651435A