Abnormal data determination method, device, computer equipment and storage medium

By receiving and identifying the data to be detected by the motor monitoring host, using deep analysis models and feature extraction technology, the problem of identifying abnormal data in the power system is solved, and network security and power system stability are improved.

CN115567279BActive Publication Date: 2025-08-15SHENZHEN POWER SUPPLY BUREAU
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211154558.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-22
Publication Date
2025-08-15
Estimated Expiration
2042-09-22

AI Technical Summary

Technical Problem

In the prior art, intelligent monitoring and supervision of motor monitoring hosts is difficult to prevent and identify abnormal data with attack purposes, resulting in security threats to the power system.

Method used

By receiving the data to be detected sent by the target client, malicious behavior and the identification of attack objects are carried out, abnormal data detection is performed using the in-depth analysis model and preset expected thresholds, and abnormal data is screened out.

Benefits of technology

It realizes sufficient detection of the detection data, prevents abnormal data from affecting network security, improves network security, and ensures the stable operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567279B_ABST
    Figure CN115567279B_ABST
Patent Text Reader

Abstract

The present application relates to the field of information security technology, and more particularly to a method, apparatus, computer device, and storage medium for determining abnormal data. The method comprises: receiving data to be detected from a target client; identifying malicious behavior and attack targets in the data to be detected; and performing abnormal data detection on the data to be detected based on the identification results. The present application achieves comprehensive detection of the data to be detected, further screening for abnormal data in the data to be detected, improving network security, and preventing abnormal data from impacting network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a method, apparatus, computer device, and storage medium for determining abnormal data. Background Art

[0002] With the continuous development of social economy, electricity has become an indispensable energy source in production and life. The power system has therefore been continuously reformed, which has led to an increasing demand for network intelligence in the power system.

[0003] In the existing technology, the safety operation of the motor monitoring host has been transformed from traditional manual monitoring and supervision to intelligent automatic monitoring and supervision, which greatly improves the efficiency of power monitoring and reduces the manpower consumed by power monitoring.

[0004] However, in the existing technology, it is difficult for the intelligent monitoring and supervision of the motor monitoring host to prevent and identify abnormal data with attack purposes, resulting in security threats to the power system. Summary of the Invention

[0005] Based on this, it is necessary to provide a method, device, computer equipment and storage medium that can realize abnormal data detection and abnormal data determination in response to the above technical problems.

[0006] In a first aspect, the present application provides a method for detecting abnormal data. The method comprises:

[0007] Receive the data to be detected sent by the target client;

[0008] Identify malicious behaviors and attack targets in the data to be detected;

[0009] According to the recognition results, abnormal data detection is performed on the data to be detected.

[0010] In one embodiment, identifying malicious behavior on the data to be detected includes:

[0011] Standardize the data to be detected to obtain target detection data;

[0012] Through the deep analysis model, according to the data feature map corresponding to the target detection data, the expected value corresponding to the target detection data is determined;

[0013] Based on the preset expected threshold and expected value, the malicious behavior identification result corresponding to the data to be detected is determined.

[0014] In one embodiment, the data to be detected is normalized to obtain target detection data, including:

[0015] Based on the pre-set base conversion rules, the base conversion is performed on the data to be tested, and the converted data to be tested is determined;

[0016] The converted data to be detected is normalized to obtain target detection data.

[0017] In one embodiment, the method further comprises:

[0018] Input the test data set in the training sample into the original analysis model to obtain the malicious behavior prediction results corresponding to the test data set;

[0019] Determine the target test data based on the malicious behavior prediction results and malicious behavior labels corresponding to the test dataset;

[0020] Optimize the training data set in the training sample according to the target test data;

[0021] The original analysis model is trained based on the optimized training sample set to obtain a deep analysis model.

[0022] In one embodiment, identifying attack targets of the data to be detected includes:

[0023] Perform feature extraction on the data to be detected to obtain data features of the data to be detected;

[0024] According to the characteristics of the attack target and the data characteristics of the data to be detected, the attack target is identified in the data to be detected.

[0025] In one embodiment, before receiving the data to be detected sent by the target client, the method further includes:

[0026] A target client is determined from the candidate clients according to a startup frequency and / or a data upload amount of the candidate clients.

[0027] In a second aspect, the present application also provides a device for determining abnormal data. The device includes:

[0028] A receiving module, used for receiving the data to be detected sent by the target client;

[0029] Identification module, used to identify malicious behaviors and attack targets in the data to be detected;

[0030] The detection module is used to perform abnormal data detection on the data to be detected based on the recognition results.

[0031] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the abnormal data detection method of the first aspect when executing the computer program.

[0032] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the abnormal data detection method of the first aspect.

[0033] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the abnormal data detection method of the first aspect.

[0034] According to the technical solution of the present application, malicious behavior is identified by the data to be detected, which ensures that the access intention and behavior of the data to be detected can be judged, and the preliminary screening of abnormal data in the data to be detected is realized, preventing the abnormal data in the data to be detected from affecting network security; by identifying the attack object of the data to be detected, it is ensured that the data features in the data to be detected are identified, preventing the existence of attack object features in the data to be detected, achieving sufficient detection of the data to be detected, and further screening of abnormal data in the data to be detected, thereby improving network security and preventing abnormal data from affecting network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 A diagram illustrating an application environment of a method for obtaining abnormal data in one embodiment;

[0036] Figure 2 A flowchart of a method for detecting abnormal data provided in an embodiment of the present application;

[0037] Figure 3 A flowchart of the steps for identifying malicious behavior in data to be detected provided in an embodiment of the present application;

[0038] Figure 4 A flowchart of the steps for identifying attack targets in data to be detected provided in an embodiment of the present application;

[0039] Figure 5 A flowchart of another abnormal data determination method provided in an embodiment of the present application;

[0040] Figure 6 A logic block diagram of a method for determining abnormal data provided in an embodiment of the present application;

[0041] Figure 7 A structural block diagram of an abnormal data detection device provided in an embodiment of the present application;

[0042] Figure 8 A structural block diagram of another abnormal data detection device provided in an embodiment of the present application;

[0043] Figure 9 A structural block diagram of another abnormal data detection device provided in an embodiment of the present application;

[0044] Figure 10 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0045] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0046] In the description of the present application, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0047] With the continuous development of social economy and the deepening of power system reform, "Internet +" technology has brought about tremendous changes in the consumption patterns and usage habits of power customers. In existing technologies, the State Grid Corporation of China has shifted its safety operations of substations and main distribution lines from traditional purely manual monitoring and supervision to a new technological and intelligent model, and therefore the security requirements for power monitoring hosts have also increased accordingly.

[0048] However, in the process of transforming the safety operation of the motor monitoring host from traditional manual monitoring and supervision to intelligent automated monitoring and supervision, there is a lack of effective monitoring of abnormal data. This leads to the security risk of the network system being attacked by abnormal data when monitoring and supervising the motor monitoring host.

[0049] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 1As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data for obtaining abnormal data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a method for obtaining abnormal data is implemented.

[0050] Figure 2 A flowchart of a method for detecting abnormal data provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the abnormal data detection method includes the following steps:

[0051] Step 201: Receive data to be detected sent by a target client.

[0052] It should be noted that the target client receives feedback data sent by multiple target motor monitoring hosts and obtains the data to be detected by summarizing the feedback data; it should be further noted that before the target client receives feedback data sent by multiple target motor monitoring hosts, it can screen out the target motor monitoring host from multiple candidate motor monitoring hosts based on a pre-set host blacklist.

[0053] In one embodiment of the present application, when a target client needs to receive feedback data sent by multiple target motor monitoring hosts, multiple candidate motor monitoring hosts are screened based on the host blacklist to determine the target motor monitoring host. Specifically, the target client screens the identity information of the candidate motor monitoring hosts, and compares the identity information of the candidate motor monitoring hosts with the blacklist information recorded in the host blacklist. If the identity information of the candidate motor monitoring host is the same as the blacklist information recorded in the host blacklist, then the candidate motor monitoring host is not the target motor monitoring host; if the identity information of the candidate motor monitoring host is different from the blacklist information recorded in the host blacklist, then the candidate motor monitoring host is the target motor monitoring host.

[0054] The identity information refers to information that can be used to distinguish candidate motor monitoring hosts. Specifically, each candidate motor monitoring host has unique identity information, and different candidate motor monitoring hosts have different identity information. The identity information can include, for example, the license agreement corresponding to the motor monitoring host.

[0055] In one embodiment of the present application, when the target client needs to receive feedback data sent by multiple target motor monitoring hosts, multiple candidate motor monitoring hosts are screened based on the host blacklist and the host whitelist, thereby determining the target motor monitoring host. Specifically, the target client screens the identity information of the candidate motor monitoring host. If the identity information of the candidate motor monitoring host is the same as the blacklist information recorded in the host blacklist, then the candidate motor monitoring host is not the target motor monitoring host; if the identity information of the candidate motor monitoring host is the same as the blacklist information recorded in the host whitelist, then the candidate motor monitoring host is the target motor monitoring host; further explanation, if the identity information of the candidate motor monitoring host is recorded in both the host blacklist and the host whitelist, then the identity information of the candidate motor monitoring host is transferred to manual review, and the staff is asked to judge the identity information of the candidate motor monitoring host.

[0056] It should be noted that before receiving the data to be detected sent by the target client, the target client needs to be determined from the candidate clients. Further, the activity of the candidate clients can be screened to determine the target client whose activity meets the adjustment requirements.

[0057] In one embodiment of the present application, when it is necessary to determine a target client from candidate clients, an activity threshold is determined in advance; the activity corresponding to the candidate client is obtained, and the relationship between the activity corresponding to the candidate client and the activity threshold is determined, and then the target client is determined from the candidate clients; specifically, if the activity corresponding to the candidate client is less than the activity threshold, it means that the activity of the candidate client is low, and in order to prevent the candidate client with low activity from occupying system memory resources, the candidate client is not used as the target client; if the activity corresponding to the candidate client is greater than or equal to the activity threshold, it means that the activity of the candidate client is high, and the candidate client is not used as the target client.

[0058] Step 202: Identify malicious behaviors and attack targets on the data to be detected.

[0059] It should be noted that the expected value corresponding to the data to be detected can be obtained by obtaining a data feature map corresponding to the data to be detected and processing the data feature map; based on the expected value, malicious behavior identification can be performed on the data to be detected.

[0060] In one embodiment of the present application, a predetermined expected threshold value is used to represent the expected critical value of the data to be detected. Specifically, the expected value corresponding to the data to be detected is obtained by obtaining a data feature map corresponding to the data to be detected and processing the data feature map; the relationship between the expected value and the expected threshold value is judged. If the expected value of the traffic data to be detected is less than the expected threshold value, it indicates that the data to be detected contains malicious behavior; if the expected value of the traffic data to be detected is greater than or equal to the expected threshold value, it indicates that the data to be detected does not contain malicious behavior.

[0061] It should be noted that the attack target can be identified based on the data features corresponding to the data to be detected by determining the data features corresponding to the data to be detected.

[0062] In one embodiment of the present application, an attack feature database is predetermined, wherein the attack feature database records a number of features containing attack intent data; data features corresponding to the data to be detected are determined, and the data features corresponding to the data to be detected are compared with the features in the attack feature database; if the attack feature database contains features identical to the data features corresponding to the data to be detected, it indicates that an attack target exists in the data to be detected; if the attack feature database does not contain features identical to the data features corresponding to the data to be detected, it indicates that an attack target does not exist in the data to be detected.

[0063] Step 203: Perform abnormal data detection on the data to be detected based on the recognition result.

[0064] It should be noted that the identification results include malicious behavior identification results and attack target identification results. According to the malicious behavior identification results, attack target identification results and pre-set detection rules, abnormal data detection is performed on the data to be detected.

[0065] In one embodiment of the present application, if the pre-set detection rule indicates that any result of the malicious behavior identification result and the attack object identification result indicates that the data to be detected is abnormal, then the data to be detected is determined to be abnormal data. Further explanation: If the malicious behavior identification result of the data to be detected A is the presence of malicious behavior, but the attack object identification result is the absence of an attack object, then based on the detection rule, the data to be detected A is determined to be abnormal data; or, if the malicious behavior identification result of the data to be detected A is the absence of malicious behavior, but the attack object identification result is the presence of an attack object, then based on the detection rule, the data to be detected A is determined to be abnormal data; or, if the malicious behavior identification result of the data to be detected A is the presence of malicious behavior, and the attack object identification result is the presence of an attack object, then based on the detection rule, the data to be detected A is determined to be abnormal data.

[0066] In one embodiment of the present application, if the pre-set detection rule is that the data to be detected is abnormal if and only if the malicious behavior identification result and the attack object identification result both indicate that the data to be detected is abnormal. Further explanation: If the malicious behavior identification result of the data to be detected A is that malicious behavior exists, but the attack object identification result is that there is no attack object, then based on the detection rule, the data to be detected A is determined to be normal data; or, if the malicious behavior identification result of the data to be detected A is that there is no malicious behavior, but the attack object identification result is that there is an attack object, then based on the detection rule, the data to be detected A is determined to be normal data; or, if the malicious behavior identification result of the data to be detected A is that malicious behavior exists, and the attack object identification result is that there is an attack object, then based on the detection rule, the data to be detected A is determined to be abnormal data.

[0067] According to the abnormal data detection method of the present application, malicious behavior is identified by the data to be detected, which ensures that the access intention and behavior of the data to be detected can be judged, and the preliminary screening of abnormal data in the data to be detected is realized, preventing the abnormal data in the data to be detected from affecting network security; by identifying the attack object of the data to be detected, it is guaranteed that the data features in the data to be detected are identified, preventing the existence of attack object features in the data to be detected, achieving sufficient detection of the data to be detected, and further screening of abnormal data in the data to be detected, thereby improving network security and preventing abnormal data from affecting network security.

[0068] It should be noted that the expected value of the data to be detected can be used to identify malicious behavior of the data to be detected. Specifically, Figure 3 As shown, Figure 3 A flowchart of the steps for identifying malicious behavior in data to be detected is provided in an embodiment of the present application. The method for identifying malicious behavior in data to be detected may include the following steps:

[0069] Step 301: normalize the data to be detected to obtain target detection data.

[0070] It should be noted that, based on a pre-set base conversion rule, the base conversion is performed on the data to be detected to determine the converted data to be detected; and the converted data to be detected is normalized to obtain target detection data.

[0071] As an implementation method, the converted data to be detected can be normalized by performing a minimum value of the converted data to be detected and a maximum value of the converted data to be detected. Specifically, the minimum value of the converted data to be detected and the maximum value of the converted data to be detected can be substituted into a normalization expression to obtain normalized target detection data, wherein the normalization expression is shown as follows:

[0072]

[0073] Among them, x new The normalized target detection data, x refers to the data to be detected after the change, x min Refers to the minimum value of the data to be detected after conversion, x max Refers to the maximum value of the data to be detected after conversion.

[0074] Step 302: Determine the expected value corresponding to the target detection data based on the data feature map corresponding to the target detection data through the depth analysis model.

[0075] In one embodiment of the present application, a data feature graph corresponding to the target detection data is determined based on the target detection data, and the data feature graph can clearly present the target detection data; according to a predetermined processing method, the data feature graph is processed to determine the expected value corresponding to the target detection data.

[0076] The predetermined processing method may include, but is not limited to, convolution processing, pooling processing, and fully connected processing, etc. Specifically, the processing method includes at least one of convolution processing, pooling processing, and fully connected processing.

[0077] Step 303: Determine the malicious behavior recognition result corresponding to the data to be detected based on the preset expected threshold and expected value.

[0078] In one embodiment of the present application, a predetermined expected threshold is used to obtain a data feature graph corresponding to the data to be detected, and the data feature graph is processed to obtain an expected value corresponding to the data to be detected; the relationship between the expected value and the expected threshold is judged. If the expected value of the traffic data to be detected is less than the expected threshold, it indicates that the data to be detected contains malicious behavior; if the expected value of the traffic data to be detected is greater than or equal to the expected threshold, it indicates that the data to be detected does not contain malicious behavior.

[0079] It should be noted that when the original analysis model needs to be trained to obtain a deep analysis model, the specific steps are: determine the target test data based on the malicious behavior prediction results and malicious behavior labels corresponding to the test data set; optimize the training data set in the training sample based on the target test data; train the original analysis model based on the optimized training sample set to obtain a deep analysis model.

[0080] In one embodiment of the present application, when it is necessary to train the original analysis model to obtain a deep analysis model: multiple sets of simulation data are automatically generated based on manual settings or system default data, wherein the simulation data are divided into a test data set and a training data set; the test data set is input into the original analysis model to verify its own analysis accuracy, and the corresponding error of the test data set is statistically analyzed, and the target test data in the test data set is determined according to the corresponding error of the test data set, and the training data set is optimized based on the target test data so that the training data set can be close to the target test data, and the original analysis model is trained and optimized in real time according to the optimized training sample set to obtain a deep analysis model.

[0081] Further explanation: the focus loss function is used to calculate the loss of the deep analysis model, and the performance of the deep analysis model is evaluated, that is, the accuracy, detection rate and false alarm rate of the deep analysis model are evaluated, and the corresponding curve trend chart is generated for staff to view. The specific calculation formula of the focus loss function is as follows (2):

[0082] FL(pi)=-α(1-pi) γ log(pi)......(2)

[0083] Here, FL(pi) refers to the focal loss function, pi refers to the predicted value, α refers to the weight factor, and γ refers to the focusing parameter.

[0084] According to the abnormal data detection method of the present application, by determining the expected value and the expected threshold, the malicious behavior of the data to be detected is judged, which ensures that the access intention and behavior of the data to be detected can be judged, and the preliminary screening of abnormal data in the data to be detected is achieved, preventing the abnormal data in the data to be detected from affecting the network security, improving the network security, and preventing the abnormal data from affecting the network security. The uniformity of the format of the data to be detected is ensured by normalization processing, and better malicious behavior identification of the data to be detected is achieved. By training the original analysis model, a deep analysis model is obtained, which ensures the accuracy of the subsequent malicious behavior identification of the material to be detected, and improves the efficiency of the subsequent malicious behavior identification of the material to be detected.

[0085] It should be noted that the attack target identification is performed on the data to be detected based on the data characteristics of the data to be detected. Specifically, Figure 4 As shown, Figure 4 A flowchart of the steps for identifying attack targets in data to be detected is provided in an embodiment of the present application. The method for identifying attack targets in data to be detected may include the following steps:

[0086] Step 401 : extract features from the data to be detected to obtain data features of the data to be detected.

[0087] The data feature may be a feature code corresponding to the data to be detected.

[0088] It should be noted that when feature extraction is required for the data to be detected, data analysis is required to obtain the analyzed data to be detected; feature extraction is performed on the analyzed data to obtain data features corresponding to the data to be detected.

[0089] Step 402: Identify the attack target of the data to be detected based on the attack target characteristics and the data characteristics of the data to be detected.

[0090] In one embodiment of the present application, attack targets are identified for data to be detected based on predetermined attack target features. The predetermined attack target features record a number of features containing attack intent data; data features corresponding to the data to be detected are determined, and the data features corresponding to the data to be detected are compared with features in the attack target features. If the attack target features contain features identical to those corresponding to the data to be detected, then an attack target exists in the data to be detected; if the attack target features do not contain features identical to those corresponding to the data to be detected, then an attack target does not exist in the data to be detected.

[0091] As an implementation method, the attack object characteristics can be a virus sharing database. When it is necessary to identify the attack object of the data to be detected, the data characteristics corresponding to the data to be detected are retrieved based on the virus sharing database. If the virus sharing database contains the same characteristics as the data characteristics corresponding to the data to be detected, the data characteristics in the data to be detected are blocked and detected based on the file automatic detection and killing technology. At the same time, the target client identity address corresponding to the data to be detected is collected, and the target client is prohibited from subsequent operations.

[0092] Furthermore, if the virus sharing database does not contain the same data features as those corresponding to the data to be detected, an infection simulation is performed on the data to be detected based on the cloud virtual machine, and based on the pre-set virus definition, virus identification is performed on the data to be detected after the infection simulation. If the virus identification result is that the data to be detected does not contain a virus, it is determined that there is no attack target in the data to be detected; if the virus identification result is that the data to be detected contains a virus, the automatic file detection and killing technology blocks and detects the virus in the data to be detected, and at the same time collects the target client identity address corresponding to the data to be detected, and prohibits the target client from subsequent operations.

[0093] According to the abnormal data detection method of the present application, by extracting features from the data to be detected, data features corresponding to the data to be detected are obtained, providing a data basis for subsequent identification of attack objects in the data to be detected, thereby ensuring the accuracy of identification of attack objects in the data to be detected; identifying attack objects based on the data features of the data to be detected based on the attack object features, realizing the positioning and analysis of attack objects in the data to be detected, preventing the presence of attack object features in the data to be detected, realizing sufficient detection of the data to be detected, realizing further screening of abnormal data in the data to be detected, improving network security, and preventing abnormal data from affecting network security.

[0094] It should be noted that before receiving the data to be detected sent by the target client, the target client is determined from the candidate clients according to the startup frequency and / or data upload volume of the candidate clients.

[0095] In one embodiment of the present application, a startup unit corresponding to each candidate client is determined, and a startup frequency corresponding to each candidate client is obtained. The candidate clients are sorted based on the startup frequency, and the startup units corresponding to each candidate client are determined and connected in sequence to obtain a startup linked list connected with multiple candidate clients; if the candidate client at the head of the startup linked list is set to be the least active client, that is, the candidate client with the smallest startup frequency, a preset target client data volume is given, and the candidate client at the head of the startup linked list is deleted, and the order of deletion is from the head to the tail of the startup linked list until the number of candidate clients in the startup linked list is the same as the number of target clients. At this time, the candidate client in the startup linked list is the target client.

[0096] According to the abnormal data detection method of the present application, by deleting candidate clients with low startup frequency, a reasonable allocation of system operating resources is achieved, preventing candidate clients with low startup frequency from occupying system memory resources, and improving the efficiency of abnormal data detection for data to be detected.

[0097] In one embodiment of the present application, Figure 5 As shown, Figure 5 A flowchart of another abnormal data determination method provided in an embodiment of the present application. Specifically, performing abnormal data detection on the data to be detected may include:

[0098] Step 501: Receive data to be detected sent by a target client.

[0099] Step 502 : performing base conversion on the data to be detected based on a preset base conversion rule to determine the converted data to be detected.

[0100] Step 503 : normalize the converted data to be detected to obtain target detection data.

[0101] Step 504 : Determine the expected value corresponding to the target detection data based on the data feature graph corresponding to the target detection data through the depth analysis model.

[0102] Step 505: Determine the malicious behavior identification result corresponding to the data to be detected based on the preset expected threshold and the expected value.

[0103] In one embodiment of the present application, a test data set in a training sample is input into the original analysis model to obtain a malicious behavior prediction result corresponding to the test data set; target test data is determined based on the malicious behavior prediction result and malicious behavior label corresponding to the test data set; based on the target test data, the training data set in the training sample is optimized; based on the optimized training sample set, the original analysis model is trained to obtain a deep analysis model.

[0104] Step 506: extract features from the data to be detected to obtain data features of the data to be detected;

[0105] Step 507: Identify the attack target on the data to be detected based on the attack target characteristics and the data characteristics of the data to be detected, and determine the attack target identification result.

[0106] Step 508: Perform abnormal data detection on the data to be detected based on the malicious behavior identification result and the attack target identification result.

[0107] In one embodiment of the present application, Figure 6 As shown, Figure 6 A logic block diagram of an abnormal data determination method provided in an embodiment of the present application, wherein the target client collects feedback data from the motor monitoring host, summarizes the feedback data to obtain data to be detected, and sends the input to be detected to the local server. The local server performs abnormal data detection on the data to be detected through a deep analysis model and an object recognition model. It is further explained that if the abnormal data detection result is that the detection fails, an alarm is given to the staff according to a pre-set alarm module, and based on a pre-set interrupt recording module, the target client identity address corresponding to the number to be detected whose abnormal data detection result is that the detection fails is obtained, and subsequent operations of the target client are prohibited.

[0108] According to the abnormal data detection method of the present application, malicious behavior is identified by the data to be detected, which ensures that the access intention and behavior of the data to be detected can be judged, and the preliminary screening of abnormal data in the data to be detected is realized, preventing the abnormal data in the data to be detected from affecting network security; by identifying the attack object of the data to be detected, it is guaranteed that the data features in the data to be detected are identified, preventing the existence of attack object features in the data to be detected, achieving sufficient detection of the data to be detected, and further screening of abnormal data in the data to be detected, thereby improving network security and preventing abnormal data from affecting network security.

[0109] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0110] Based on the same inventive concept, embodiments of the present application also provide an abnormal data detection device for implementing the abnormal data detection method described above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations of the one or more abnormal data detection device embodiments provided below can be found in the above-mentioned limitations of the abnormal data detection method and will not be repeated here.

[0111] In one embodiment, Figure 7 As shown, Figure 7 This is a structural block diagram of an abnormal data detection device provided in an embodiment of the present application, which provides an abnormal data detection device, including: a receiving module 710, an identification module 720 and a detection module 730, wherein:

[0112] The receiving module 710 is configured to receive the data to be detected sent by the target client.

[0113] It should be noted that, before receiving the data to be detected sent by the target client, the process further includes: determining the target client from the candidate clients according to the startup frequency and / or data upload volume of the candidate clients.

[0114] The identification module 720 is used to identify malicious behaviors and attack targets in the data to be detected.

[0115] The detection module 730 is used to perform abnormal data detection on the data to be detected based on the recognition result.

[0116] According to the abnormal data detection device of the present application, malicious behavior is identified by the data to be detected, which ensures that the access intention and behavior of the data to be detected can be judged, and the preliminary screening of abnormal data in the data to be detected is realized, preventing the abnormal data in the data to be detected from affecting network security; by identifying the attack object of the data to be detected, it is guaranteed that the data features in the data to be detected are identified, preventing the presence of attack object features in the data to be detected, achieving sufficient detection of the data to be detected, and further screening of abnormal data in the data to be detected, thereby improving network security and preventing abnormal data from affecting network security.

[0117] In one embodiment, Figure 8 As shown, Figure 8 This is a structural block diagram of another abnormal data detection device provided in an embodiment of the present application. A device for detecting abnormal data is provided. In the device for detecting abnormal data, an identification module 820 includes: a processing unit 821, a first determination unit 822, and a second determination unit 823, wherein:

[0118] The processing unit 821 is used to perform standardization processing on the data to be detected to obtain target detection data.

[0119] It should be noted that, based on a pre-set base conversion rule, the base conversion is performed on the data to be detected to determine the converted data to be detected; and the converted data to be detected is normalized to obtain target detection data.

[0120] The first determination unit 822 is configured to determine an expected value corresponding to the target detection data based on a data feature graph corresponding to the target detection data through a depth analysis model.

[0121] The second determining unit 823 is configured to determine a malicious behavior recognition result corresponding to the data to be detected based on a preset expected threshold and an expected value.

[0122] In one embodiment of the present application, a test data set in a training sample is input into the original analysis model to obtain a malicious behavior prediction result corresponding to the test data set; target test data is determined based on the malicious behavior prediction result and malicious behavior label corresponding to the test data set; based on the target test data, the training data set in the training sample is optimized; based on the optimized training sample set, the original analysis model is trained to obtain a deep analysis model.

[0123] According to the abnormal data detection device of the present application, by determining the expected value and the expected threshold, the malicious behavior of the data to be detected is judged, which ensures that the access intention and behavior of the data to be detected can be judged, and the preliminary screening of abnormal data in the data to be detected is achieved, preventing the abnormal data in the data to be detected from affecting the network security, improving the network security, and preventing the abnormal data from affecting the network security. The uniformity of the format of the data to be detected is ensured by normalization processing, and better malicious behavior identification of the data to be detected is achieved. By training the original analysis model, a deep analysis model is obtained, which ensures the accuracy of the subsequent malicious behavior identification of the material to be detected, and improves the efficiency of the subsequent malicious behavior identification of the material to be detected.

[0124] In one embodiment, Figure 9 As shown, Figure 9 This is a structural block diagram of another abnormal data detection device provided in an embodiment of the present application. A device for detecting abnormal data is provided. In the abnormal data detection device, the identification module 920 includes: an extraction unit 924 and an identification unit 925, wherein:

[0125] The extraction unit 924 is used to extract features from the data to be detected to obtain data features of the data to be detected.

[0126] The identification unit 925 is configured to identify the attack target of the data to be detected based on the attack target characteristics and the data characteristics of the data to be detected.

[0127] According to the abnormal data detection device of the present application, by extracting features from the data to be detected, data features corresponding to the data to be detected are obtained, providing a data basis for subsequent identification of attack objects for the data to be detected, thereby ensuring the accuracy of identification of attack objects for the data to be detected; identifying attack objects based on the data features of the data to be detected based on the attack object features, realizing the positioning and analysis of attack objects in the data to be detected, preventing the presence of attack object features in the data to be detected, realizing sufficient detection of the data to be detected, realizing further screening of abnormal data in the data to be detected, improving network security, and preventing abnormal data from affecting network security.

[0128] Each module in the abnormal data determination device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0129] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 10As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, an abnormal data determination method is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse.

[0130] Those skilled in the art will understand that Figure 10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0131] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:

[0132] Receive the data to be detected sent by the target client;

[0133] Identify malicious behaviors and attack targets in the data to be detected;

[0134] According to the recognition results, abnormal data detection is performed on the data to be detected.

[0135] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0136] Standardize the data to be detected to obtain target detection data;

[0137] Through the deep analysis model, according to the data feature map corresponding to the target detection data, the expected value corresponding to the target detection data is determined;

[0138] Based on the preset expected threshold and expected value, the malicious behavior identification result corresponding to the data to be detected is determined.

[0139] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0140] Based on the pre-set base conversion rules, the base conversion is performed on the data to be tested, and the converted data to be tested is determined;

[0141] The converted data to be detected is normalized to obtain target detection data.

[0142] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0143] Input the test data set in the training sample into the original analysis model to obtain the malicious behavior prediction results corresponding to the test data set;

[0144] Determine the target test data based on the malicious behavior prediction results and malicious behavior labels corresponding to the test dataset;

[0145] Optimize the training data set in the training sample according to the target test data;

[0146] The original analysis model is trained based on the optimized training sample set to obtain a deep analysis model.

[0147] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0148] Perform feature extraction on the data to be detected to obtain data features of the data to be detected;

[0149] According to the characteristics of the attack target and the data characteristics of the data to be detected, the attack target is identified in the data to be detected.

[0150] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:

[0151] A target client is determined from the candidate clients according to a startup frequency and / or a data upload amount of the candidate clients.

[0152] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0153] Receive the data to be detected sent by the target client;

[0154] Identify malicious behaviors and attack targets in the data to be detected;

[0155] According to the recognition results, abnormal data detection is performed on the data to be detected.

[0156] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0157] Standardize the data to be detected to obtain target detection data;

[0158] Through the deep analysis model, according to the data feature map corresponding to the target detection data, the expected value corresponding to the target detection data is determined;

[0159] Based on the preset expected threshold and expected value, the malicious behavior identification result corresponding to the data to be detected is determined.

[0160] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0161] Based on the pre-set base conversion rules, the base conversion is performed on the data to be tested, and the converted data to be tested is determined;

[0162] The converted data to be detected is normalized to obtain target detection data.

[0163] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0164] Input the test data set in the training sample into the original analysis model to obtain the malicious behavior prediction results corresponding to the test data set;

[0165] Determine the target test data based on the malicious behavior prediction results and malicious behavior labels corresponding to the test dataset;

[0166] Optimize the training data set in the training sample according to the target test data;

[0167] The original analysis model is trained based on the optimized training sample set to obtain a deep analysis model.

[0168] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0169] Perform feature extraction on the data to be detected to obtain data features of the data to be detected;

[0170] According to the characteristics of the attack target and the data characteristics of the data to be detected, the attack target is identified in the data to be detected.

[0171] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0172] A target client is determined from the candidate clients according to a startup frequency and / or a data upload amount of the candidate clients.

[0173] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:

[0174] Receive the data to be detected sent by the target client;

[0175] Identify malicious behaviors and attack targets in the data to be detected;

[0176] According to the recognition results, abnormal data detection is performed on the data to be detected.

[0177] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0178] Standardize the data to be detected to obtain target detection data;

[0179] Through the deep analysis model, according to the data feature map corresponding to the target detection data, the expected value corresponding to the target detection data is determined;

[0180] Based on the preset expected threshold and expected value, the malicious behavior identification result corresponding to the data to be detected is determined.

[0181] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0182] Based on the pre-set base conversion rules, the base conversion is performed on the data to be tested, and the converted data to be tested is determined;

[0183] The converted data to be detected is normalized to obtain target detection data.

[0184] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0185] Input the test data set in the training sample into the original analysis model to obtain the malicious behavior prediction results corresponding to the test data set;

[0186] Determine the target test data based on the malicious behavior prediction results and malicious behavior labels corresponding to the test dataset;

[0187] Optimize the training data set in the training sample according to the target test data;

[0188] The original analysis model is trained based on the optimized training sample set to obtain a deep analysis model.

[0189] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0190] Perform feature extraction on the data to be detected to obtain data features of the data to be detected;

[0191] According to the characteristics of the attack target and the data characteristics of the data to be detected, the attack target is identified in the data to be detected.

[0192] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0193] A target client is determined from the candidate clients according to a startup frequency and / or a data upload amount of the candidate clients.

[0194] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0195] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0196] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0197] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for detecting abnormal data, characterized in that: Applied to the process of automated monitoring and supervision of safe operation of a motor monitoring host, the method includes: Receive the data to be detected sent by the target client; the data to be detected is feedback data sent by multiple target motor monitoring hosts; Standardizing the data to be detected to obtain target detection data; Determining, based on the target detection data, a data feature graph corresponding to the target detection data; Processing the data feature map using a deep analysis model according to a predetermined processing method to determine an expected value corresponding to the target detection data; the processing method includes at least one of convolution processing, pooling processing, and full connection processing; Determining a malicious behavior identification result corresponding to the data to be detected based on a preset expected threshold and the expected value; Performing feature extraction on the data to be detected to obtain data features of the data to be detected; Identify the attack target on the data to be detected based on the attack target characteristics and the data characteristics of the data to be detected, and obtain an attack target identification result corresponding to the data to be detected; Performing abnormal data detection on the data to be detected based on the malicious behavior identification result, the attack target identification result and pre-set detection rules; The attack target feature is a feature included in the virus sharing database; accordingly, identifying the attack target of the data to be detected based on the attack target feature and the data feature of the data to be detected includes: The data features corresponding to the data to be detected are compared with the features in the attack object features. If the attack object features contain the same features as the data features corresponding to the data to be detected, it indicates that an attack object exists in the data to be detected; if the attack object features do not contain the same features as the data features corresponding to the data to be detected, it indicates that no attack object exists in the data to be detected.

2. The method according to claim 1, characterized in that The step of normalizing the data to be detected to obtain target detection data includes: Based on a preset base conversion rule, performing base conversion on the data to be detected to determine the converted data to be detected; The converted data to be detected is normalized to obtain the target detection data.

3. The method according to claim 1, characterized in that The method further comprises: Inputting the test data set in the training sample into the original analysis model to obtain the malicious behavior prediction result corresponding to the test data set; Determining target test data based on the malicious behavior prediction results and malicious behavior labels corresponding to the test data set; Optimizing the training data set in the training sample according to the target test data; The original analysis model is trained according to the optimized training sample set to obtain a deep analysis model.

4. The method according to any one of claims 1 to 3, characterized in that Before receiving the data to be detected sent by the target client, the method further includes: A target client is determined from the candidate clients according to the startup frequency and / or data upload volume of the candidate clients.

5. The method according to claim 4, characterized in that Determining a target client from the candidate clients according to a startup frequency of the candidate clients includes: Determine the startup unit corresponding to each candidate client, and obtain the startup frequency corresponding to each candidate client; Sorting the candidate clients based on the startup frequencies, determining and sequentially connecting startup units corresponding to each candidate client, and obtaining a startup linked list connected to a plurality of the candidate clients; If the candidate client at the head of the startup list is set as the least active client, the candidate client at the head of the startup list is deleted based on the preset target client data volume, and the order of deletion is from the head to the tail of the startup list until the number of candidate clients in the startup list is the same as the number of target clients. At this time, the candidate client in the startup list is the target client.

6. The method according to claim 1, characterized in that Before receiving the data to be detected sent by the target client, the method further includes: According to a preset host blacklist, a target motor monitoring host is screened out from multiple candidate motor monitoring hosts.

7. An abnormal data determination device, characterized in that: Applied to the process of automated monitoring and supervision of the safe operation of a motor monitoring host, the device comprises: A receiving module is used to receive the data to be detected sent by the target client; the data to be detected is feedback data sent by multiple target motor monitoring hosts; The identification module is used to perform standardization processing on the data to be detected to obtain target detection data; determine a data feature map corresponding to the target detection data based on the target detection data; process the data feature map through a deep analysis model according to a predetermined processing method to determine an expected value corresponding to the target detection data; the processing method includes at least one of convolution processing, pooling processing and full connection processing; determine a malicious behavior recognition result corresponding to the data to be detected based on a preset expected threshold and the expected value; perform feature extraction on the data to be detected to obtain data features of the data to be detected; and extract the malicious behavior recognition result corresponding to the data to be detected based on the attack target features and the data features of the data to be detected. According to the attack object identification, an attack object identification result corresponding to the data to be detected is obtained; the attack object feature is a feature included in the virus sharing database; accordingly, the attack object identification of the data to be detected based on the attack object feature and the data feature of the data to be detected includes: comparing the data feature corresponding to the data to be detected with the feature in the attack object feature, if the attack object feature contains the same feature as the data feature corresponding to the data to be detected, it indicates that the attack object exists in the data to be detected; if the attack object feature does not contain the same feature as the data feature corresponding to the data to be detected, it indicates that the attack object does not exist in the data to be detected; The detection module is used to perform abnormal data detection on the data to be detected based on the malicious behavior identification result, the attack target identification result and pre-set detection rules.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Abnormal access detection method, device and equipment and computer readable storage medium

    CN108446546A