Method, device and electronic equipment for determining a risk state
By acquiring operational and behavioral data of virtual terminals and utilizing decision trees and time-series analysis, the risk status of virtual terminals is quantified, addressing the shortcomings of virtual cloud computer risk analysis. This enables accurate analysis of the health status and security risks of virtual terminals, improving customer perception and security.
Patent Information
- Application Number
- CN202210911761.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-28
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2042-07-28
AI Technical Summary
Existing technologies fail to perform targeted analysis of the behavior, system operation status, and system data of virtual cloud computers, making it impossible to determine whether virtual computer business products pose any risks.
By acquiring the operational data of virtual terminals and the behavioral data of target objects, and using decision tree and time series analysis methods, the risk category and status of virtual terminals are determined. Combined with indicators such as CPU, memory, disk, and network utilization, risk information is quantified.
It enables accurate analysis of the health status and security risks of virtual terminals, early detection of potential risks, reduction of information leakage and data loss, improvement of customer perception and security, and reduction of operation and maintenance costs.
Smart Images

Figure CN115270137B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of risk judgment, in particular to a risk state determination method and device and electronic equipment. BACKGROUND
[0002] In recent years, with the continuous development and maturity of virtualization technology, virtual personal computers have become a popular product. The product quality and service quality are largely dependent on customer perception and user safety in using the product. The user perception and product safety of the virtual personal computer product are different from those of the traditional product, and the personalized requirements are also different. The health state judgment and risk prediction of the user virtual computer are multi-dimensional, including whether the virtual personal computer is running stably, whether the product can be normally used, whether various application software is healthy, risk judgment of virus attack, virtual computer theft prediction, unsafe operation analysis of using the virtual computer, whether there is sensitive information leakage, etc. The customer perception in these aspects is not only improved by user return visit, user fault complaint, fault repair and other services. We need to perform necessary risk analysis through leading parameter collection technology, multi-factor analysis, etc. to realize the risk and health state prediction of the virtual computer. The prior art does not perform targeted analysis on the behavior, system running state and system data of the virtual platform itself of the virtual cloud computer, resulting in that the risk of the virtual computer business product cannot be obtained.
[0003] For the above problems, no effective solution has been proposed so far. SUMMARY
[0004] The embodiments of the present application provide a risk state determination method and device and electronic equipment, to at least solve the technical problem that the prior art does not perform targeted analysis on the behavior, system running state and system data of the virtual platform itself of the virtual cloud computer, resulting in that the risk of the virtual computer business product cannot be obtained.
[0005] According to an aspect of an embodiment of the present application, a risk state determination method is provided, including: obtaining running data of a virtual terminal, and obtaining behavior data of a target object, wherein the behavior data is data obtained when the target object operates the virtual terminal; determining a risk category to which the virtual terminal belongs according to the behavior data; determining a risk state of the virtual terminal according to a change trend of the running data; and determining risk information of the virtual terminal according to the risk category and the risk state.
[0006] Optionally, the risk category to which the virtual terminal belongs is determined according to the behavior data, including: judging whether the behavior data satisfies preset risk information, wherein the behavior data includes at least one of the following: login behavior of the target object, software used by the target object, browsing content of the target object, and games opened by the target object; in a case where the behavior data satisfies the preset risk information, determining a feature label corresponding to the behavior data; and determining the risk category of the virtual terminal according to the feature label.
[0007] Optionally, before the feature label corresponding to the behavior data is determined, the method further includes: collecting historical behavior data of the target object at a preset time interval, wherein the historical behavior data includes a plurality of normal historical behavior data and a plurality of abnormal historical behavior data; training a decision tree according to the historical behavior data to obtain a target decision tree, wherein the target decision tree is used to judge whether the behavior data is at risk; and determining a risk value of the virtual terminal according to the target decision tree, wherein the risk value is used to quantitatively represent a degree of the risk state of the virtual terminal, and the risk value is positively correlated with the risk state.
[0008] Optionally, the risk state of the virtual terminal is determined according to the change trend of the running data, including: obtaining a change trend and a use duration of to-be-monitored data in the running data, wherein the to-be-monitored data includes at least one of the following: CPU usage, memory usage, disk space usage, disk I / O usage, and network usage; determining a time point corresponding to when the to-be-monitored data exceeds a use threshold according to the change trend; and determining a health degree of the virtual terminal according to the use duration, wherein the health degree is used to quantitatively represent the risk state of the virtual terminal, and the health degree is negatively correlated with the risk state.
[0009] Optionally, the health degree of the virtual terminal is determined according to the use duration, including: adding a first score to a target set when the use duration is greater than a first threshold and the CPU usage is greater than a preset percentage; adding a second score to the target set when the use duration is greater than a second threshold and the memory usage is greater than the preset percentage, wherein the second threshold is greater than the first threshold, and the second score is greater than the first score; adding the second score to the target set when the disk space usage is greater than the preset percentage; adding the first score to the target set when the use duration is greater than the second threshold and the disk I / O usage is greater than the preset percentage; adding a third score to the target set when the use duration is greater than the second threshold and the network usage is greater than the preset percentage, wherein the third score is less than the second score; and calculating a total score in the target set, and determining the health degree of the virtual terminal according to the initial score and the total score.
[0010] Optionally, the method further comprises: monitoring the file directory, determining that the label type of the application program is the first label type when it is monitored that the file directory is operated by the application program; determining that the label type of the application program is the second label type when it is monitored that more than a preset number of file directories are operated by the application program; determining that the label type of the application program is the third label type when it is monitored that the registry is changed by the application program; determining that the label type of the application program that initiates the connection request is the fourth label type when the number of connections to at least one port in the target port set exceeds a third threshold; and determining the type of the application program according to the label type to which the application program belongs.
[0011] Optionally, the method further comprises: obtaining the application program with the label to obtain a target application program, sorting the target application program according to the calling time; monitoring the interface calling information of the target application program, constructing a calling matrix according to the number of the interface calling information; clustering the target application program according to the feature vector of the calling matrix to obtain a target sequence; and determining the probability of the target application program being of a target type according to the target sequence, and determining the application program whose probability is greater than a fourth threshold as the application program of the target type.
[0012] According to another aspect of the embodiments of the present application, a risk state determination apparatus is further provided, comprising: an obtaining module, configured to obtain running data of a virtual terminal and behavior data of a target object, wherein the behavior data is data obtained when the target object operates the virtual terminal; a first determining module, configured to determine a risk category to which the virtual terminal belongs according to the behavior data; a second determining module, configured to determine a risk state of the virtual terminal according to a variation trend of the running data; and a third determining module, configured to determine risk information of the virtual terminal according to the risk category and the risk state.
[0013] According to still another aspect of the embodiments of the present application, an electronic device is further provided, comprising: a memory, configured to store program instructions; and a processor, connected with the memory, configured to execute the program instructions to realize the following functions: obtaining running data of a virtual terminal and behavior data of a target object, wherein the behavior data is data obtained when the target object operates the virtual terminal; determining a risk category to which the virtual terminal belongs according to the behavior data; determining a risk state of the virtual terminal according to a variation trend of the running data; and determining risk information of the virtual terminal according to the risk category and the risk state.
[0014] According to still another aspect of the embodiments of the present application, a non-volatile storage medium is further provided, comprising a stored program, wherein when the program is running, the non-volatile storage medium controls a device in which the non-volatile storage medium is located to execute the risk state determination method.
[0015] In the embodiment of the present application, the running data of the virtual terminal is acquired, and the behavior data of the target object is acquired; according to the behavior data, the risk category to which the virtual terminal belongs is determined; according to the change trend of the running data, the risk state of the virtual terminal is determined; and according to the risk category and the risk state, the risk information of the virtual terminal is determined, so as to achieve the purpose of determining the health state of the virtual terminal, thereby realizing the technical effect of analyzing the security risk of the virtual terminal, and further solving the technical problem that the prior art does not perform targeted analysis on the behavior, system running state and system data of the virtual platform itself of the virtual cloud computer, so that it is impossible to acquire whether the virtual computer business product has a risk. BRIEF DESCRIPTION OF DRAWINGS
[0016] The drawings described herein are used to provide further understanding of the present application, and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation on the present application. In the drawings:
[0017] Figure 1 is a hardware structure block diagram of a computer terminal (or electronic equipment) for implementing a risk state determination method according to an embodiment of the present application;
[0018] Figure 2 is a flowchart of a risk state determination method according to an embodiment of the present application;
[0019] Figure 3a is a process schematic diagram of CNN classification according to an embodiment of the present application;
[0020] Figure 3b is a schematic diagram of a training process according to an embodiment of the present application;
[0021] Figure 4 is a structure diagram of a risk state determination apparatus according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In order to enable personnel in the technical field to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present application.
[0023] It should be noted that the terms "first", "second" and the like in the description and in the claims of the present application are used to distinguish between similar objects and not necessarily for describing a specific sequential or chronological order. It is to be understood that the use of the terms so used herein is interchangeable under appropriate circumstances such that the embodiments of the application described herein are, for example, capable of efficient implementation in other than the order illustrated or other than the order described herein. Moreover, the terms "comprise", "have" and any variations thereof are intended to cover a non-exclusive inclusion, for example, a process, method, article, or apparatus that comprises a list of steps or units can not necessarily be limited to those steps or units, but can include other not expressly listed or inherent to such process, method, article, or apparatus.
[0024] The embodiments of the present application establish corresponding analysis methods according to the behavior data of the user, the running data of the virtual computer system, and the system data of the virtual platform itself, to judge the health value of the virtual personal computer of the customer and predict the potential risk. The following will be described in detail.
[0025] The risk state determination method provided by the embodiments of the present application can be executed in a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or an electronic device) for implementing the risk state determination method is shown. As shown in Figure 1 The computer terminal 10 (or the electronic device 10) can include one or more processors (the processor can include but is not limited to a microprocessor MCU or a programmable logic device FPGA processing device), a memory 104 for storing data, and a transmission module 106 for communication function. In addition, it can also include a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the I / O interface), a network interface, a power supply and / or a camera. Those skilled in the art can understand that Figure 1 The structure shown is only schematic, which does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 can include more or less components than those shown in Figure 1 or have a different configuration from Figure 1 the structure shown.
[0026] It should be noted that the one or more processors and / or other data processing circuitry described above can be referred to herein generally as "data processing circuitry". The data processing circuitry can be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuitry can be a single standalone processing module, or incorporated in whole or in part within any one of other elements of the computer terminal 10 (or electronic device). As referred to in the embodiments of the present application, the data processing circuitry serves as a processor to control, for example, the selection of the variable resistance terminal path connected with the interface.
[0027] The memory 104 can be used to store software programs of application software and modules, such as program instructions / data storage means corresponding to the risk state determination method in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, i.e. implements the risk state determination method described above. The memory 104 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor, which can be connected to the computer terminal 10 through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0028] The transmission module 106 is configured to receive or send data via a network. Specific examples of the network can include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF) module, which is configured to communicate with the Internet in a wireless manner.
[0029] The display can be, for example, a touch screen type liquid crystal display (LCD), which can enable a user to interact with the user interface of the computer terminal 10 (or electronic device).
[0030] It should be noted that in some optional embodiments, the above-mentioned Figure 1 The computer device (or electronic device) shown can include hardware elements (including circuitry), software elements (including computer code stored on a computer readable medium), or a combination of both hardware and software elements. It should be noted that in some embodiments, the functions of the computer device (or electronic device) can be performed by software and / or firmware that is executable by one or more processors, although these functions can also be embodied, fully or in part, in hardware (e.g., an application-specific integrated circuit [ASIC]) or in some other hardware elements. Figure 1Only one instance of a particular concrete example and is intended to show the types of components that can be present in the above-described computer device (or electronic device).
[0031] In the above operating environment, the embodiment of the present application provides a risk state determination method embodiment. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0032] Figure 2 is a flowchart of a risk state determination method according to an embodiment of the present application, as shown in Figure 2 The method comprises the following steps:
[0033] Step S202, obtaining running data of a virtual terminal, and obtaining behavior data of a target object, wherein the behavior data is data obtained when the target object operates the virtual terminal;
[0034] Step S204, determining a risk category to which the virtual terminal belongs according to the behavior data;
[0035] Step S206, determining a risk state of the virtual terminal according to a change trend of the running data;
[0036] Step S208, determining risk information of the virtual terminal according to the risk category and the risk state.
[0037] In step S204 of the above risk state determination method, the risk category to which the virtual terminal belongs is determined according to the behavior data, specifically comprising the following steps: judging whether the behavior data satisfies preset risk information, wherein the behavior data comprises at least one of the following: login behavior of the target object, software used by the target object, browsing content of the target object, and game opened by the target object; in the case that the behavior data satisfies the preset risk information, determining a feature label corresponding to the behavior data; determining the risk category of the virtual terminal according to the feature label, which is corresponding to the above four types of behavior data, such as judging that the target object has an abnormality in the login behavior, then the risk category corresponding to the virtual terminal is login abnormality.
[0038] Specifically, the behavior data of the target object is analyzed to preset the risk information, including the following four aspects: analyzing login behavior, software used, content read by the browser, and game four types of behavior, by establishing a decision tree judgment method, inputting the feature labels corresponding to the four types of behavior, judging the risk category and behavior risk value of the virtual terminal under different user behaviors.
[0039] The necessary user operation behavior data of using the virtual terminal is collected through system logs, network transmission and the like, and by comparing preset risk information of the system, analysis labels are set according to categories, and the trend of using the virtual terminal and the strong correlation of risk analysis can be used to increase or decrease the category labels. The preset risk information of the system includes: login IP change frequency, failure rate, online duration; sensitive software and applications; search content high-risk keywords; non-healthy or state-prohibited games; suspected dangerous behaviors of software operation (such as information leakage and Trojan program download), and the like. Such risk information can be dynamically maintained and set in the system.
[0040] The following introduces the above four types of behaviors:
[0041] (1) Login behavior: According to the login IP change frequency, combined with the historical login information, the IP change trend is analyzed; the login failure rate and trend are analyzed to judge the risk of password cracking; the change of user online operation duration is analyzed. By comparing the preset risk information of the system, the analysis label of the login behavior is set.
[0042] (2) Software used: The software used by the user and the use duration are collected at a preset collection interval, the preset software risk information is compared, the historical behavior data in time sequence is established, and the software use feature label is established from multiple dimensions such as mutation, dispersion, comparison with historical use records and frequency.
[0043] (3) Browser reading content: The content read by the user in the browser and the browsing duration are collected at a preset collection interval, the preset browser risk information is compared, the historical behavior data is established, and the browser use feature label is established from multiple dimensions such as mutation, dispersion, and historical record comparison.
[0044] (4) Game: The category and duration of the game played by the user are collected at a preset collection interval, the preset game risk information is compared, the historical behavior data is established, and the game use feature label is established from multiple dimensions such as mutation, dispersion, and historical record comparison.
[0045] For example, when determining the risk information of the virtual terminal according to the risk category and the risk state, the risk type and the risk state can be directly used as the above risk information, or different weights can be assigned to the evaluation indexes corresponding to the risk category and the risk state respectively, and the final risk information is determined based on the evaluation indexes and the corresponding weights of the two, for example, the risk information is a risk score, and different risk scores correspond to different processing strategies. In specific implementation, different risk categories correspond to different scores (i.e. evaluation indexes), and different risk states also correspond to different scores (i.e. evaluation indexes), so that the final quantifiable risk information can be determined according to the above two types of parameters.
[0046] In the above steps, before determining the feature label corresponding to the behavior data, the method further comprises the following steps: collecting historical behavior data of the target object according to a preset time interval, wherein the historical behavior data comprises a plurality of normal historical behavior data and a plurality of abnormal historical behavior data; training a decision tree according to the historical behavior data to obtain a target decision tree, wherein the target decision tree is used to judge whether the behavior data is at risk; and determining a risk value of the virtual terminal according to the target decision tree, wherein the risk value is used to quantitatively represent the degree of the virtual terminal being in a risk state, and the risk value is positively correlated with the risk state.
[0047] Specifically, the decision tree judgment method is established by historical behavior data, the feature labels corresponding to four types of behaviors are input, and the category and behavior risk value of the user behavior at risk are judged. First, a decision tree is formed according to the training set data, the training set data is composed of historical behavior data, if the decision tree cannot give correct classification to all objects, then some exceptions are selected to join the training set data, and the process is repeated until a correct decision set is formed. The decision tree judgment method established by the embodiment of the application, for example, uses 10,000 historical behavior data (8,000 risky behavior information and 2,000 normal behavior information), through cross-validation and evaluation index comparison, finally determines the determination rule with an accuracy of 95%. According to the decision tree judgment rule, a pre-judgment method is established to judge the risk value of the virtual personal computer (i.e. virtual terminal) according to the system type user behavior and historical data.
[0048] In step S206 of the above risk state determination method, the risk state of the virtual terminal is determined according to the change trend of the running data, and specifically comprises the following steps: obtaining the change trend and usage time length of the to-be-monitored data in the running data, wherein the to-be-monitored data comprises at least one of the following: CPU usage rate, memory usage rate, disk space usage rate, disk I / O usage rate, and network usage rate; determining the time point corresponding to when the to-be-monitored data exceeds the usage threshold according to the change trend; and determining the health degree of the virtual terminal according to the usage time length, wherein the health degree is used to quantitatively represent the risk state of the virtual terminal, and the health degree is negatively correlated with the risk state.
[0049] Specifically, the running data refers to the running data of the system, and the system running data is divided into two categories: the running data of the virtual machine operating system and the system data of the virtual platform itself. The system data of the virtual platform itself needs to be collected through the interface of the virtual platform, including the running parameters of the CPU, memory, hard disk, network, and graphics card of the host, the frequency and trajectory record of the virtual machine drift, etc.
[0050] The detection factor is determined from the above operation parameters, that is, the to-be-monitored data is determined, and the health state of the virtual terminal is preliminarily profiled and predicted in combination with the change trend of the to-be-monitored data. The prediction manner is that: the LSTM is used to analyze a plurality of to-be-monitored data to obtain the use time length of the plurality of to-be-monitored data, and a method capable of predicting the health at a future time point is determined, that is, the time point at which the to-be-monitored data may exceed the health use threshold is predicted.
[0051] In determining the health degree of the virtual terminal, the health degree of the virtual terminal needs to be preliminarily predicted and estimated. Specifically, a plurality of to-be-monitored data that can be used to help judge the health state of the virtual terminal is determined, including: CPU usage rate, memory usage rate, disk space usage rate, disk IO usage rate, network usage rate, mutation point detection, system data of the virtual platform itself, and the like. In terms of virtual machine operating system, system data that needs to be monitored is collected at regular intervals (the default interval is 10 seconds); at the same time, the interfaces of the virtual platform are also used to collect various running parameters of the host computer in association with the virtual machine ID. For example, statistics can be taken in units of days, and in combination with the change trend of a plurality of to-be-monitored data, the health state of the virtual terminal is preliminarily profiled and predicted.
[0052] In the above steps, the health degree of the virtual terminal is determined according to the use time length, and specifically includes the following steps: when the use time length is greater than a first threshold value and the CPU usage rate is greater than a preset percentage, a first score is added to a target set; when the use time length is greater than a second threshold value and the memory usage rate is greater than a preset percentage, a second score is added to the target set, wherein the second threshold value is greater than the first threshold value, and the second score is greater than the first score; when the disk space usage rate is greater than a preset percentage, the second score is added to the target set; when the use time length is greater than the second threshold value and the disk I / O usage rate is greater than a preset percentage, the first score is added to the target set; when the use time length is greater than the second threshold value and the network usage rate is greater than a preset percentage, a third score is added to the target set, wherein the third score is less than the second score; the total score in the target set is calculated, and the health degree of the virtual terminal is determined according to the initial score and the total score.
[0053] Specifically, the initial score is 10 points (the higher the score, the higher the health degree), that is, the total health degree.
[0054] When the CPU usage rate is greater than 80% in more than 30% of the use time, the first score is added to the target set, and the value stored in the target set is used to represent the score deducted from the total health degree. For example, in this case, the first threshold value is set to 30%, the preset percentage is set to 80%, and the first score is set to 1, that is, the health degree is reduced by 1 point.
[0055] When the memory usage rate is greater than 80% for more than 60% of the usage time, a second score is added to the target set, and in this case, the second threshold is set to 60%, the preset percentage is set to 80%, and the second score can be set to 3, that is, the health degree is reduced by 3 points.
[0056] When the disk space usage rate is greater than 80%, a second score is added to the target set, and in this case, the preset percentage is set to 80%, and the second score can be set to 3, that is, the health degree is reduced by 3 points.
[0057] When the disk IO usage rate is greater than 80% for more than 60% of the usage time, a first score is added to the target set, and in this case, the first score can be set to 1, that is, the health degree is reduced by 1 point.
[0058] When the network usage rate is greater than 80% for more than 60% of the usage time, a third score is added to the target set, and in this case, the third score can be set to 2, that is, the health degree is reduced by 2 points.
[0059] By calculating the total score in the target set, the health degree of the virtual terminal is determined according to the initial score and the total score. It should be noted that the above first threshold, second threshold, preset percentage, first score, second score, and third score can be set according to actual conditions, and the above are only examples and do not limit the specific values.
[0060] The data set established by the historical to-be-monitored data is analyzed by a long short-term memory model (LSTM) to establish an accurate prediction method to predict future time points, and to predict time points that may exceed the health use threshold, such as CPU usage rate, memory usage rate, disk space usage rate, disk IO usage rate, network usage rate, mutation point detection, and host stable operation, so as to predict the health status of the virtual terminal.
[0061] In the above risk state determination method, further comprising the following steps: monitoring the file directory, when it is monitored that the file directory is operated by the application program, determining that the label type of the application program is a first label type; when it is monitored that more than a preset number of file directories are operated by the application program, determining that the label type of the application program is a second label type; when it is monitored that the registry is changed by the application program, determining that the label type of the application program is a third label type; when the number of connections to at least one port in the target port set exceeds a third threshold, determining that the label type of the application program initiating the connection request is a fourth label type; and determining the type of the application program according to the label type to which the application program belongs.
[0062] In the embodiments of the present application, the health status of the virtual terminal is determined by analyzing whether the virtual terminal has high-risk activities, which mainly refers to the analysis of malicious software. The target type of software is identified by detecting the following aspects of software activities, i.e., the malicious software is identified.
[0063] File system activity: According to research data, about 70% of malicious software will operate on the file system, of which about 23% will select the Windows directory for file operation, and about 15% will operate on the user directory. A knowledge base of file directories that can be operated by malicious software is established, and the file directories are monitored. When a program operates on the monitored directory, the program is tagged with a sensitive directory tag, i.e., a first type of tag. The application program also has a regular file operation. If the application operates on more than 1000 directories, the application is tagged with a frequent file operation tag, i.e., a second type of tag.
[0064] Registry activity: The operation on the registry is sensitive because it will change the configuration of the system, such as trusted certificates, firewall status, etc. Software that changes the registry is tagged with a registry operation tag, and software that changes the key registry such as Windows\CurrentVersion\Policies\System is tagged with a high-risk registry operation tag, i.e., a third type of tag.
[0065] Network activity: Malicious software usually scans the network. These scans are mainly for scanning specific Windows ports, such as 139, 445, or ports related to backdoors, such as 9988. A malicious port knowledge base is established based on this feature. Many malicious software attempts to initiate an SSL connection but mostly fails to complete the handshake.
[0066] The number of connections of the software usually maintains a normal level. Through the statistics of past data, the software is tagged with a high connection number tag, i.e., a fourth type of tag, when the number of connections suddenly increases. When the software performs specific Windows port scanning, it is tagged with a network scanning tag, and when the software scans the ports contained in the malicious port knowledge base, it is tagged with a sensitive scanning tag.
[0067] The IPs accessed by normal software are generally concentrated, and malicious software will attempt to scan the network and initiate connections to a large number of IPs. The dispersion of the IP data accessed by the software is analyzed, and the result is counted into an IP dispersion tag.
[0068] The Botnet risk is marked by detecting the typical NICKNAME, PRIVMSG, and TOPIC modes used in IRC communication.
[0069] Based on the Markov model, the software clustering is performed on the software windows api call to identify the malicious software. The random time sequence of each activity of the software is used to predict the risk of the virtual terminal.
[0070] In the above steps, the type of the application program is determined, specifically including the following steps: obtaining an application program with a label, obtaining a target application program, and sorting the target application program according to the calling time; monitoring the interface calling information of the target application program, constructing a calling matrix according to the number of interface calling information; clustering the target application program according to the characteristic vector of the calling matrix to obtain a target sequence; determining the probability of the target application program being of a target type according to the target sequence, and determining the application program whose probability is greater than a fourth threshold value as the application program of the target type.
[0071] Each activity of the software needs the support of the operating system level. By monitoring the windows api call of the software, the activities of the software can be understood. Based on the above different types of labeling of the software, the windows api call of the software is monitored, the windows api call of the software is grouped into a sequence according to time, an N×N matrix is established with the total number N of the monitored windows api, the matrix of the software call is established, the spectral clustering is performed on the matrix characteristic vector, the Markov chain is constructed for the clustered sequence, the target sequence is obtained, the probability calculation is performed on the software to be detected by using the constructed Markov chain, and the software with a confidence interval of 3 sigma or more is classified into a category, so that the potential malicious software is identified.
[0072] By analyzing the behavior data of the user and the system running data, in an optional embodiment, different weights are set for the two kinds of data to determine which kind of data has a greater impact on the health status of the virtual terminal. The two kinds of data are used to determine the user behavior risk value according to the decision tree method; the virtual terminal running information and the multiple features of the associated host running information are extracted through the time series data processing method to determine the potential malicious software, and the method for predicting the health status of the virtual terminal is established. A data set composed of monitoring data of a plurality of virtual computers within a period of time is obtained; a mutation point detection method is used to select the running index; the fault time point and the normal running result are used to extract the feature set of the training set and the test set; dimensionality reduction clustering is used to reduce the sampling of the majority of positive samples, the classification method is trained, and the current virtual terminal is tested to belong to the healthy or unhealthy state.
[0073] Specifically, (1) the time series data classification processing of the multiple features of the virtual computer information is performed by the CNN classifier to establish a classification method; in Figure 3aThe process schematic diagram of the shown CNN classification is shown in the figure. The obtained time series data is preprocessed, including dimension reduction, normalization and other processing. The preprocessed time series data is classified using a CNN classifier. The time series data can be classified according to the periodic stationary type and the irregular fluctuation type. (2) By collecting fault time points and normal operation results, dimension reduction clustering is used to reduce the sampling of the majority of positive samples, and the feature set of the training set and the test set is extracted; (3) Obtain the monitoring data of a plurality of cloud computers in a period of time to form data, and use a supervised learning method to comb out a pre-judgment method, such as Figure 3b The schematic diagram is shown in the figure, wherein (x1, y1), (x2, y2), …, (x n , y n ) is a training data set, and a learning system learns a classifier P(Y|X) or Y=f(X) from the training data. The classification system classifies new input instances x n+1 by using the learned classifier, and predicts the output class y n+1 .
[0074] According to the rules of the above judgment method, the virtual terminal judged as risky or unhealthy is reminded. On the one hand, the customer can repair the virtual terminal in advance according to the reminder, or apply for remote technical support from the telecom company; on the other hand, the product operator can limit the virtual terminal with the risk of violating the operation according to the judgment.
[0075] The embodiment of the application uses the preliminary portrait and health degree score of the health status of the virtual terminal, and combines the random time series of each activity of the software to predict the risk point of the virtual terminal. The method effectively associates the user perception, device operation, and device maintenance operation, avoids the after-the-fact remedial maintenance process of handling complaints, discovers and handles problems in advance, and further improves customer perception.
[0076] The embodiment of the present application establishes a risk state determination method, and determines whether a virtual personal computer exists risks based on multiple factors such as virtual platform system running data; the method establishes a risk analysis method based on collected virtual computer running information and virtual platform system data, and predicts the health state of the cloud computer; and the security risks of the virtual personal computer are analyzed according to the change trend of each information and data. The method provided by the present application belongs to the risk prediction of the user's virtual personal computer product, and can timely curb the harm caused by risk operation and computer poisoning, reduce the risk of information leakage and data loss, and reduce the loss caused by the risk. At the same time, because the system data of the virtual platform is added, the blank of the correlation host factor analysis is filled, the accuracy of the prediction method is improved, the result of the judgment is more comprehensive for the maintenance support of the virtual terminal, the work guidance for the maintenance engineer is more accurate, the efficiency of the support is improved, the cost of the virtual terminal operation and maintenance is saved, the security of the customer's virtual personal computer is improved, the perception and safety of the customer using the virtual terminal are improved, the retention of the existing users is realized, and the promotion of new business of high-value users is realized.
[0077] Figure 4 The structure diagram of a risk state determination device according to the embodiment of the present application is shown in FIG. 1, and the device comprises: Figure 4
[0078] The acquisition module 402 is configured to acquire running data of the virtual terminal and behavior data of the target object, wherein the behavior data is data obtained when the target object operates the virtual terminal.
[0079] The first determination module 404 is configured to determine a risk category to which the virtual terminal belongs according to the behavior data.
[0080] The second determination module 406 is configured to determine a risk state of the virtual terminal according to a change trend of the running data.
[0081] The third determination module 408 is configured to determine risk information of the virtual terminal according to the risk category and the risk state.
[0082] In the first determination module in the above risk state determination device, the risk category to which the virtual terminal belongs is determined according to the behavior data, and the specific process comprises the following steps: it is judged whether the behavior data satisfies preset risk information, wherein the behavior data comprises at least one of the following: login behavior of the target object, software used by the target object, browsing content of the target object, and game opened by the target object; in the case that the behavior data satisfies the preset risk information, a feature label corresponding to the behavior data is determined; and the risk category of the virtual terminal is determined according to the feature label.
[0083] Before the above determining the feature label corresponding to the behavior data, the first determining module further comprises the following process: collecting historical behavior data of the target object according to a preset time interval, wherein the historical behavior data comprises a plurality of normal historical behavior data and a plurality of abnormal historical behavior data; training a decision tree according to the historical behavior data to obtain a target decision tree, wherein the target decision tree is used to judge whether the behavior data is at risk; and determining a risk value of the virtual terminal according to the target decision tree, wherein the risk value is used to quantitatively represent the degree of the virtual terminal being in a risk state, and the risk value is positively correlated with the risk state.
[0084] In the second determining module in the above risk state determining device, the risk state of the virtual terminal is determined according to the change trend of the running data, and specifically comprises the following process: obtaining the change trend and the use time length of the to-be-monitored data in the running data, wherein the to-be-monitored data comprises at least one of the following: CPU usage, memory usage, disk space usage, disk I / O usage, and network usage; determining the time point corresponding to when the to-be-monitored data exceeds the use threshold according to the change trend; and determining the health degree of the virtual terminal according to the use time length, wherein the health degree is used to quantitatively represent the risk state of the virtual terminal, and the health degree is negatively correlated with the risk state.
[0085] In the second determining module, the health degree of the virtual terminal is determined according to the use time length, and specifically comprises the following process: when the use time length is greater than a first threshold and the CPU usage is greater than a preset percentage, a first score is added to a target set; when the use time length is greater than a second threshold and the memory usage is greater than a preset percentage, a second score is added to the target set, wherein the second threshold is greater than the first threshold, and the second score is greater than the first score; when the disk space usage is greater than a preset percentage, the second score is added to the target set; when the use time length is greater than the second threshold and the disk I / O usage is greater than a preset percentage, the first score is added to the target set; when the use time length is greater than the second threshold and the network usage is greater than a preset percentage, a third score is added to the target set, wherein the third score is less than the second score; the total score in the target set is calculated, and the health degree of the virtual terminal is determined according to the initial score and the total score.
[0086] In the aforementioned risk status determination device, the device further includes a monitoring module, which monitors file directories. When an application is detected operating on a file directory, the module determines the application's tag type as a first-class tag; when more than a preset number of file directories are detected being operated on by the application, the module determines the application's tag type as a second-class tag; when the application modifies the registry, the module determines the application's tag type as a third-class tag; when the number of connections to at least one port in the target port set exceeds a third threshold, the module determines the application that initiated the connection request as a fourth-class tag; and based on the application's tag type, the module determines the application's type.
[0087] In the aforementioned monitoring module, determining the type of an application specifically includes the following process: acquiring tagged applications to obtain target applications, and sorting the target applications according to their call times; monitoring the interface call information of the target applications, and constructing a call matrix based on the number of interface call information; clustering the target applications based on the feature vectors of the call matrix to obtain a target sequence; determining the probability that a target application belongs to the target type based on the target sequence, and identifying applications with a probability greater than a fourth threshold as applications of the target type.
[0088] It should be noted that, Figure 4 The risk status determination device shown is used to perform... Figure 2 The method for determining the risk status shown above is also applicable to the device for determining the risk status, and will not be repeated here.
[0089] This application embodiment also provides a non-volatile storage medium, which includes a stored program. During program execution, the device containing the non-volatile storage medium performs the following risk state determination method: acquiring runtime data of a virtual terminal and acquiring behavioral data of a target object, wherein the behavioral data is data obtained when the target object operates on the virtual terminal; determining the risk category of the virtual terminal based on the behavioral data; determining the risk state of the virtual terminal based on the changing trend of the runtime data; and determining the risk information of the virtual terminal based on the risk category and risk state.
[0090] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0091] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0092] In several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented by other ways. Among them, the above-mentioned device embodiments are only schematic, for example, the division of the units can be a logical function division, and actual implementation can have another division mode, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.
[0093] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e. they can be located in one place or distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0094] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0095] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various program code storage media.
[0096] The above is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should be considered as the protection scope of the present application.
Claims
1. A method for determining a risk state, characterized in that, include: The system acquires the running data of the virtual terminal and the behavioral data of the target object, wherein the behavioral data is the data obtained when the target object operates on the virtual terminal. Based on the behavioral data, the risk category of the virtual terminal is determined, wherein it is determined whether the behavioral data meets preset risk information, wherein the behavioral data includes at least one of the following: the login behavior of the target object, the software used by the target object, the browsing content of the target object, and the game opened by the target object; if the behavioral data meets the preset risk information, a feature tag corresponding to the behavioral data is determined; based on the feature tag, the risk category of the virtual terminal is determined. Based on the changing trends of the operational data, the risk status of the virtual terminal is determined. This includes acquiring the changing trends and usage duration of the data to be monitored within the operational data. The data to be monitored includes at least one of the following: CPU usage, memory usage, disk space usage, disk I / O usage, and network usage of the virtual terminal. Based on the changing trends, the time point corresponding to when the data to be monitored exceeds a usage threshold is determined. Based on the usage duration, the health of the virtual terminal is determined. Specifically, when the usage duration exceeds a first threshold and the CPU usage exceeds a preset percentage, a first score is added to the target set. When the usage duration exceeds a second threshold and the memory usage exceeds a preset percentage, a second score is added to the target set. The second threshold is greater than the first threshold, and the second score is greater than the first score; when the disk space utilization rate is greater than the preset percentage, the second score is added to the target set; when the usage time is greater than the second threshold and the disk I / O utilization rate is greater than the preset percentage, the first score is added to the target set; when the usage time is greater than the second threshold and the network utilization rate is greater than the preset percentage, a third score is added to the target set, wherein the third score is less than the second score; the total score in the target set is calculated, and the health of the virtual terminal is determined based on the initial score and the total score; the health is used to quantify the risk status of the virtual terminal, and the health is negatively correlated with the risk status; The risk information of the virtual terminal is determined based on the risk category and the risk status.
2. The method according to claim 1, characterized in that, Before determining the feature label corresponding to the behavioral data, the method further includes: Historical behavior data of the target object is collected at preset time intervals, wherein the historical behavior data includes multiple normal historical behavior data and multiple abnormal historical behavior data; A decision tree is trained based on the historical behavior data to obtain a target decision tree, wherein the target decision tree is used to determine whether the behavior data poses a risk; Based on the target decision tree, the risk value of the virtual terminal is determined, wherein the risk value is used to quantify the degree to which the virtual terminal is in the risk state, and the risk value is positively correlated with the risk state.
3. The method according to claim 1, characterized in that, The method further includes: Monitor the file directory, and when the file directory is detected to be operated by an application, determine that the application's tag type is the first type of tag; When the application detects that more than a preset number of file directories have been accessed by the application, the application's tag type is determined to be the second type of tag; When the registry is detected to have been modified by the application, the application's tag type is determined to be a third-class tag; When the number of connections to at least one port in the target port set exceeds the third threshold, the label type of the application that initiated the connection request is determined to be the fourth label type. The type of the application is determined based on the tag type to which the application belongs.
4. The method according to claim 3, characterized in that, Determining the type of the application includes: Obtain applications with tags to obtain target applications, and sort the target applications according to their call time; Monitor the interface call information of the target application, and construct a call matrix based on the number of interface call information; Cluster the target application based on the feature vectors of the call matrix to obtain the target sequence; Based on the target sequence, the probability that the target application is of the target type is determined, and applications with a probability greater than a fourth threshold are identified as applications of the target type.
5. A risk status determination apparatus, applicable to the risk status determination method according to any one of claims 1-4, characterized in that, include: The acquisition module is used to acquire the running data of the virtual terminal and the behavior data of the target object, wherein the behavior data is the data obtained when the target object operates on the virtual terminal; The first determining module is used to determine the risk category to which the virtual terminal belongs based on the behavioral data; The second determining module is used to determine the risk status of the virtual terminal based on the changing trend of the operating data; The third determining module is used to determine the risk information of the virtual terminal based on the risk category and the risk status.
6. An electronic device, applicable to the method for determining the risk status according to any one of claims 1-4, characterized in that, include: Memory, used to store program instructions; A processor, connected to the memory, is configured to execute program instructions that perform the following functions: acquiring runtime data of a virtual terminal and acquiring behavioral data of a target object, wherein the behavioral data is data obtained when the target object operates on the virtual terminal; determining the risk category to which the virtual terminal belongs based on the behavioral data; determining the risk status of the virtual terminal based on the changing trend of the runtime data; and determining the risk information of the virtual terminal based on the risk category and the risk status.
7. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, wherein, when the program is executed, it controls the device containing the non-volatile storage medium to perform the risk status determination method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Electronic device, cloud platform abnormity confirmation method and storage medium
CN109634813A