A method and device for detecting abnormal user behavior based on machine learning
Through the user behavior anomaly detection method based on machine learning, using user behavior characteristics, role characteristics and time series, combined with the CatBoost model, the problems of high missed and false alarm rates in the existing technology are solved, and efficient internal attack detection is achieved.
Patent Information
- Application Number
- CN202210999391.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-19
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-08-19
AI Technical Summary
The existing user behavior abnormality detection methods have too high misreport rates and false alarm rates in the internal network security of enterprises, and it is impossible to effectively detect internal personnel attacks.
Using a machine learning-based method, user behavior log information is collected and preprocessed, user behavior characteristics, user role behavior characteristics and user behavior time series are used as input features, and abnormal detection is performed in combination with the CatBoost model, and alarm information is generated.
It significantly improves the accuracy of user behavior abnormality detection, reduces the false alarm rate and missed alarm rate, and enables enterprise operation and maintenance personnel to detect internal attacks in a timely manner and take measures.
Smart Images

Figure CN115378698B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of intelligent automation, and particularly relates to a method and device for detecting abnormal user behaviors based on machine learning. Background Art
[0002] With the development of the digital transformation of enterprises, network security has also faced unprecedented challenges. Enterprises will face various network security attacks, and a large amount of data shows that attacks from insiders are more difficult to detect and prevent. According to research, the existing methods for detecting abnormal user behaviors cannot meet the requirements of enterprises. Due to excessive false alarms and missed alarms, enterprise operation and maintenance personnel cannot efficiently discover real abnormal user behaviors.
[0003] At present, most methods for detecting abnormal user behaviors use rules or clustering algorithms, with relatively high missed alarm rates and false alarm rates, and the effects are not ideal during use. There are also some methods that combine deep learning technologies, such as LSTM and Transformer, to judge whether there are abnormal user behaviors by predicting the future actions of users. However, only judging whether user behaviors are abnormal from the time series dimension of user behaviors still cannot meet the requirements of enterprises for low missed alarm rates and low false alarm rates. Summary of the Invention
[0004] The main purpose of the present invention is to overcome the disadvantages and deficiencies of the prior art, and provide a method and device for detecting abnormal user behaviors based on machine learning, which can improve the accuracy of detecting abnormal user behaviors, effectively reduce the false alarm rate and missed alarm rate, enabling enterprise operation and maintenance personnel to detect early when facing insider attacks and take early measures to reduce enterprise losses.
[0005] According to one aspect of the present invention, the present invention provides a method for detecting abnormal user behaviors based on machine learning, and the method includes the following steps:
[0006] S1: Collect user behavior log information, preprocess the user behavior log information to obtain user behavior log information in a preset format;
[0007] S2: Obtain parameters for detecting abnormal user behaviors from the user behavior log information in the preset format, input the parameters into the user behavior abnormal detection model, and detect whether the user behavior is abnormal;
[0008] S3: If the user behavior is detected as abnormal, automatically generate an alarm message according to a pre-set template in combination with user information and user behavior information.
[0009] Preferably, the parameters for user behavior anomaly detection include user behavior characteristics, and the user behavior characteristics include the user behavior in the user behavior log information and the corresponding numerical value of the user behavior.
[0010] Preferably, the parameters for user behavior anomaly detection include user role behavior characteristics. Obtaining the parameters for user behavior anomaly detection from the user behavior log information in the preset format includes:
[0011] Obtain the current user role information according to the user name in the user behavior log information, and calculate the average value of the user behavior characteristics of users belonging to the same role to obtain the average value of the user role behavior characteristics;
[0012] Subtract the average value of the user role behavior characteristics from the numerical value corresponding to the current user behavior characteristics to obtain the user role behavior characteristics.
[0013] Preferably, the parameters for user behavior anomaly detection include user behavior time series, and the user behavior time series is obtained by sorting user behaviors in the order of the occurrence time of user behaviors.
[0014] Preferably, the method includes:
[0015] Input the user behavior time series into a time series anomaly detection model to detect whether the user behavior time series is abnormal;
[0016] Inputting the parameters into the user behavior anomaly detection model to detect whether the user behavior is abnormal includes:
[0017] Input the user behavior characteristics, the user role behavior characteristics, and the user behavior time series into the CatBoost model to classify whether the user behavior is abnormal.
[0018] According to another aspect of the present invention, the present invention also provides a user behavior anomaly detection device based on machine learning. The device includes:
[0019] A processing module for collecting user behavior log information, preprocessing the user behavior log information to obtain user behavior log information in a preset format;
[0020] A detection module for obtaining parameters for user behavior anomaly detection from the user behavior log information in the preset format, inputting the parameters into the user behavior anomaly detection model to detect whether the user behavior is abnormal;
[0021] An alarm module for automatically generating alarm information according to a pre-set template in combination with user information and user behavior information if the user behavior is detected as abnormal.
[0022] Preferably, the parameters for user behavior anomaly detection include user behavior characteristics, and the user behavior characteristics include the user behaviors in the user behavior log information and the corresponding numerical values of the user behaviors.
[0023] Preferably, the parameters for user behavior anomaly detection include user role behavior characteristics. The detection module obtains the parameters for user behavior anomaly detection from the user behavior log information in the preset format, including:
[0024] Obtain the current user role information according to the user name in the user behavior log information, and calculate the average value of the user behavior characteristics of users belonging to the same role to obtain the average value of user role behavior characteristics;
[0025] Subtract the average value of the user role behavior characteristics from the numerical value corresponding to the current user behavior characteristics to obtain the user role behavior characteristics.
[0026] Preferably, the parameters for user behavior anomaly detection include user behavior time series, and the user behavior time series is obtained by sorting user behaviors in the order of the occurrence time of user behaviors.
[0027] Preferably, the detection module is further configured to:
[0028] Input the user behavior time series into a time series anomaly detection model to detect whether the user behavior time series is abnormal;
[0029] The detection module inputs the parameters into a user behavior anomaly detection model to detect whether the user behavior is abnormal, including:
[0030] Input the user behavior characteristics, the user role behavior characteristics, and the user behavior time series into a CatBoost model to classify whether the user behavior is abnormal.
[0031] Beneficial effects: By using the user behavior characteristics, user role behavior characteristics, and user behavior time series as features to feed into the CatBoost tree model to determine whether the user behavior is abnormal, the present invention greatly improves the accuracy of user behavior anomaly detection, effectively reduces the false alarm rate and missed alarm rate, enabling enterprise operation and maintenance personnel to discover attacks from within the enterprise in a timely manner and take effective measures.
[0032] The features and advantages of the present invention will become clear by referring to the following drawings and the detailed description of the specific embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a flowchart of a user behavior anomaly detection method based on machine learning;
[0034] Figure 2 is the flowchart of the method for detecting anomalies in user behavior time series;
[0035] Figure 3 is the schematic diagram of the device for detecting user behavior anomalies based on machine learning. Detailed implementation manners
[0036] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0037] Embodiment 1
[0038] Figure 1 is the flowchart of the method for detecting user behavior anomalies based on machine learning. As Figure 1 shown, this embodiment provides a method for detecting user behavior anomalies based on machine learning, and the method includes the following steps:
[0039] S1: Collect user behavior log information, preprocess the user behavior log information, and obtain user behavior log information in a preset format.
[0040] Specifically, collect user behavior log information, match the user behavior log according to a preset log template. After successful matching, the system will preprocess the user behavior log through the template and process the log into a preset format. The content of the preset format includes: username, occurrence time, behavior, and value.
[0041] S2: Obtain the parameters for detecting user behavior anomalies from the user behavior log information in the preset format, input the parameters into the user behavior anomaly detection model, and detect whether the user behavior is abnormal.
[0042] Preferably, the parameters for detecting user behavior anomalies include user behavior characteristics, and the user behavior characteristics include the user behavior in the user behavior log information and the value corresponding to the user behavior.
[0043] Preferably, the parameters for detecting user behavior anomalies include user role behavior characteristics, and obtaining the parameters for detecting user behavior anomalies from the user behavior log information in the preset format includes:
[0044] Obtain the current user role information according to the username in the user behavior log information, and calculate the average value of the user behavior characteristics of users belonging to the same role to obtain the average value of the user role behavior characteristics;
[0045] Subtract the average value of the user role behavior characteristics from the value corresponding to the current user behavior characteristics to obtain the user role behavior characteristics.
[0046] Specifically, there will be a statistic of behaviors for each role. For example, the number of emails sent by users in the human resources group every day, the size of email attachments, etc. These are all characteristics of this role. Calculating the average value of user role is, for example, if there are 5 people in the human resources group, then the total number of emails they send every day is added together and divided by 5, which is the average value of the behavior characteristics of this role.
[0047] It should be noted that the user role behavior characteristics are the behavior characteristics that this user role should have obtained through historical data statistics. And the user behavior characteristics are the user behavior characteristics obtained through logs. For example, a certain user in the human resources group downloaded a large amount of data from the internal network. This behavior does not belong to the user role behavior characteristics because this behavior should not exist in this user role behavior, but this belongs to the user behavior.
[0048] Preferably, the parameters for user behavior anomaly detection include the user behavior time series, and the user behavior time series is obtained by sorting user behaviors in the order of the occurrence time of user behaviors.
[0049] Specifically, sort user behaviors by time. For example, behavior 1 at 9:05, behavior 2 at 9:06, behavior 3 at 9:07, etc. In this way, the user behavior time series is obtained.
[0050] Preferably, the method includes:
[0051] Input the user behavior time series into a time series anomaly detection model to detect whether the user behavior time series is abnormal;
[0052] The inputting the parameters into the user behavior anomaly detection model to detect whether the user behavior is abnormal includes:
[0053] Input the user behavior characteristics, the user role behavior characteristics, and the user behavior time series into the CatBoost model to classify whether the user behavior is abnormal.
[0054] Specifically, refer to Figure 2, the user behavior time series is input into the time series anomaly detection model. The model is divided into two stages. In the first stage of the model, the inputs are loss error (initialized to 0), the complete sequence, and the window sequence. The complete sequence and the loss error are concatenated, then positional encoding is added, and then it enters the complete sequence encoder. The window sequence has positional encoding added and then enters the window sequence encoder. The complete sequence passes through LayerNorm (complete sequence + MultiHeadAtt(complete sequence, complete sequence, complete sequence)) to obtain the result of the complete sequence encoder process 1, and then passes through LayerNorm (result of the complete sequence encoder process 1 + FeedForwward(result of the complete sequence encoder process 1)) to obtain the result of the complete sequence encoder process 2. The window sequence passes through Mask(MultiHeadAtt(window sequence, window sequence, window sequence)) to obtain the result of the window sequence encoder process 1, and then passes through LayerNorm (window sequence + result of the window sequence encoder process 1) to obtain the result of the window sequence encoder process 2. Finally, together with the result of the complete sequence encoder process 2, it completes the window sequence encoder process 3 LayerNorm (result of the window sequence encoder process 2 + MultiHeadAtt(result of the complete sequence encoder process 2, result of the complete sequence encoder process 2, result of the window sequence encoder process 2)). After the above operations, the outputs are respectively given to two decoders with the same structure (Sigmoid(FeedForwward(result of the window sequence encoder process 3))). The output of decoder 1 and the window sequence are used to calculate the loss L1. The outputs of the first stage are O1, O2, L1, L2. Thus, the first stage ends.
[0055] Among them,
[0056] MultiHeadAtt(Q, K, V) = Concat(H1,..., H h )
[0057] where H i = Attention(Q i , K i , V i ).
[0058] [[ID=2,2]]
[0059]
[0060] In the formula, n is the number of training iterations, ∈ is a training parameter close to 1, O1 and O2 are the outputs of stage 1, is the output of stage 2, and W is the window sequence.
[0061] The inputs in the second stage are L1, the complete sequence, and the window sequence respectively. The remaining steps are the same as those in the first stage. The output of the second stage Determine whether the user behavior sequence is abnormal by calculating whether the result is greater than the threshold through the following formula.
[0062]
[0063] Among them, S is the score, is the input serial port data. If this score is greater than the threshold, it means there is a problem.
[0064] Catboost is an existing and maturely applied model. In this embodiment, the input features of the model are composed of user behavior characteristics, user role characteristics, and the results of the user behavior time series model. Input them into the model, and the output of the model is the classification of whether the user behavior is abnormal.
[0065] S3: If the user behavior is detected as abnormal, automatically generate an alarm message according to the pre-set template in combination with the user information and the user behavior information.
[0066] Specifically, if the user behavior is detected as abnormal by the model, an alarm message will be automatically generated according to the pre-set template in combination with the user information and the user behavior information, and the alarm message will be pushed to the relevant operation and maintenance personnel.
[0067] The technical solution of this embodiment detects the user behavior from three dimensions (the user's role, the user's behavior, and the user's behavior time series), which is completely different from the existing algorithms. Especially the user behavior time series model deeply reconstructs the traditional Transformer model, adopts the structure of an encoder, a window encoder, and a dual decoder, and incorporates the idea of an adversarial network, greatly improving the F1 value of the model. In addition, the detection method of this embodiment also uses the user role, the user behavior, and the user behavior time series as features to input into the CatBoost tree model to judge whether the user behavior is abnormal. Through the above steps, the accuracy of user behavior anomaly detection is greatly improved, and the false alarm rate and the missed alarm rate are effectively reduced, enabling the enterprise operation and maintenance personnel to discover the attacks from within the enterprise in a timely manner and take effective measures.
[0068] Embodiment 2
[0069] Figure 3 is a schematic diagram of a user behavior anomaly detection device based on machine learning. As Figure 3 shown, the present invention also provides a user behavior anomaly detection device based on machine learning. The device includes:
[0070] The processing module 301 is configured to collect user behavior log information, preprocess the user behavior log information, and obtain user behavior log information in a preset format;
[0071] The detection module 302 is configured to obtain parameters for user behavior anomaly detection from the user behavior log information in the preset format, input the parameters into a user behavior anomaly detection model, and detect whether the user behavior is abnormal;
[0072] The alarm module 303 is configured to, if the user behavior is detected as abnormal, automatically generate an alarm message according to a preset template in combination with user information and user behavior information.
[0073] Preferably, the parameters for user behavior anomaly detection include user behavior characteristics, and the user behavior characteristics include the user behavior in the user behavior log information and the corresponding numerical value of the user behavior.
[0074] Preferably, the parameters for user behavior anomaly detection include user role behavior characteristics. The detection module 302 obtains the parameters for user behavior anomaly detection from the user behavior log information in the preset format, including:
[0075] Obtain the current user role information according to the user name in the user behavior log information, and calculate the average value of the user behavior characteristics of users belonging to the same role to obtain the average value of the user role behavior characteristics;
[0076] Subtract the average value of the user role behavior characteristics from the numerical value corresponding to the current user behavior characteristics to obtain the user role behavior characteristics.
[0077] Preferably, the parameters for user behavior anomaly detection include user behavior time series, and the user behavior time series is obtained by sorting user behaviors in the order of the occurrence time of the user behaviors.
[0078] Preferably, the detection module 302 is further configured to:
[0079] Input the user behavior time series into a time series anomaly detection model to detect whether the user behavior time series is abnormal;
[0080] The detection module 302 inputs the parameters into a user behavior anomaly detection model to detect whether the user behavior is abnormal, including:
[0081] Input the user behavior characteristics, the user role behavior characteristics, and the user behavior time series into a CatBoost model to classify whether the user behavior is abnormal.
[0082] The specific implementation processes of the functions implemented by each module in this Embodiment 2 are the same as those of the steps in Embodiment 1, and will not be elaborated here.
[0083] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural transformation made under the concept of the present invention by using the content of the specification and drawings of the present invention, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present invention.
Claims
1. A method for detecting abnormal user behavior based on machine learning, characterized in that, The method includes the following steps: S1: Collect user behavior log information, preprocess the user behavior log information to obtain user behavior log information in a preset format; S2: Obtain parameters for user behavior anomaly detection from the user behavior log information in the preset format, input the parameters into a user behavior anomaly detection model, and detect whether the user behavior is abnormal; S3: If the user behavior is detected as abnormal, automatically generate an alarm message according to a preset template in combination with user information and user behavior information; Wherein, the parameters for user behavior anomaly detection include user behavior characteristics, and the user behavior characteristics include the user behavior in the user behavior log information and the corresponding value of the user behavior; Wherein, the parameters for user behavior anomaly detection include user role behavior characteristics, and obtaining the parameters for user behavior anomaly detection from the user behavior log information in the preset format includes: obtaining the current user role information according to the user name in the user behavior log information, calculating the average value of the user behavior characteristics of users belonging to the same role to obtain the average value of user role behavior characteristics; subtracting the value corresponding to the current user behavior characteristics from the average value of user role behavior characteristics to obtain the user role behavior characteristics; Wherein, the parameters for user behavior anomaly detection include user behavior time series, and the user behavior time series is obtained by sorting user behaviors in the order of the occurrence time of user behaviors; wherein, the user role behavior characteristics are the behavior characteristics that a user role should have statistically obtained from historical data; and the user behavior characteristics are the user behavior characteristics obtained from logs; Wherein, input the user behavior time series into a time series anomaly detection model to detect whether the user behavior time series is abnormal; The inputting the parameters into a user behavior anomaly detection model to detect whether the user behavior is abnormal includes: Input the user behavior characteristics, the user role behavior characteristics, and the user behavior time series into a CatBoost model to classify whether the user behavior is abnormal.
2. A user behavior anomaly detection device based on machine learning, characterized in that, The device includes: A processing module, configured to collect user behavior log information, preprocess the user behavior log information to obtain user behavior log information in a preset format; A detection module, configured to obtain parameters for user behavior anomaly detection from the user behavior log information in the preset format, input the parameters into a user behavior anomaly detection model, and detect whether the user behavior is abnormal; An alarm module, configured to automatically generate an alarm message according to a preset template in combination with user information and user behavior information if the user behavior is detected as abnormal; Wherein, the parameters for user behavior anomaly detection include user behavior characteristics, and the user behavior characteristics include the user behavior in the user behavior log information and the corresponding value of the user behavior; Among them, the parameters for user behavior anomaly detection include user role behavior characteristics. The detection module obtains the parameters for user behavior anomaly detection from the user behavior log information in the preset format, including: obtaining the current user role information according to the user name in the user behavior log information, and calculating the average value of the user behavior characteristics of users belonging to the same role to obtain the average value of user role behavior characteristics; subtracting the average value of user role behavior characteristics from the value corresponding to the current user behavior characteristics to obtain the user role behavior characteristics. Among them, the parameters for user behavior anomaly detection include the user behavior time series, which is obtained by sorting user behaviors in the order of the occurrence time of user behaviors; among them, the user role behavior characteristics are the behavior characteristics that a user role should have statistically obtained from historical data; and the user behavior characteristics are the user behavior characteristics obtained from logs. Among them, the user behavior time series is input into the time series anomaly detection model to detect whether the user behavior time series is abnormal. Inputting the parameters into the user behavior anomaly detection model to detect whether the user behavior is abnormal includes: Inputting the user behavior characteristics, the user role behavior characteristics, and the user behavior time series into the CatBoost model to classify whether the user behavior is abnormal.
Citation Information
Patent Citations
User operation behavior monitoring method, device and equipment and readable storage medium
CN113360354A
Internal threat intelligent detection method and system based on spatial-temporal feature fusion
CN113919239A
User behavior anomaly detection method and system of embedded tense
CN114416673A
Cited By
Log anomaly detection method based on machine learning
CN116910656A