Behavior profile construction method, device, electronic device and storage medium

Through the server, the characteristic baseline correlation analysis and correction of the behavioral portrait model reported by the terminal is analyzed and corrected, and the corrected behavioral portrait model is generated and distributed, which solves the problem of high cost of abnormal behavior detection in virtual network scenarios, and realizes accurate identification of abnormal behavior and effective filtering of normal behaviors.

CN115664822BActive Publication Date: 2025-08-08SANGFOR TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211327684.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-27
Publication Date
2025-08-08
Estimated Expiration
2042-10-27

AI Technical Summary

Technical Problem

In virtual network scenarios, electronic devices use behavioral models to filter out abnormal behaviors from behavioral data is costly.

Method used

The server receives the behavioral portrait model reported by the terminal, extracts and analyzes the characteristic baseline of each process, makes corrections and adjustments, generates the corrected behavioral portrait model, and distributes it to the terminal to optimize local anomaly detection.

Benefits of technology

The missed-report rate of abnormal behavior and the false-report rate of normal behavior are reduced, and effective update and optimization of the terminal's local behavior portrait model is realized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664822B_ABST
    Figure CN115664822B_ABST
Patent Text Reader

Abstract

The present application discloses a behavior portrait construction method, device, electronic device and storage medium, wherein the method includes: receiving a behavior portrait model reported by each terminal of at least two terminals in a first cluster; the behavior portrait model represents a model for identifying behavior anomalies obtained by local learning of the terminal; based on each received behavior portrait model, extracting a feature baseline corresponding to each process; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data; performing correlation analysis on the feature baselines extracted from each behavior portrait model, and correcting and adjusting the feature baseline corresponding to each process, thereby obtaining a corrected behavior portrait model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a behavior profile construction method, device, electronic device and storage medium. Background Art

[0002] In virtual network scenarios, electronic devices use behavioral models to filter out abnormal behaviors from behavioral data, and the detection cost of behavior recognition is high. Summary of the Invention

[0003] In view of this, the embodiments of the present application provide a behavior portrait construction method, device, electronic device and storage medium to at least solve the problem of high detection cost in related technologies during behavior recognition.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] This embodiment of the present application provides a behavior profile construction method, which is applied to a server and includes:

[0006] Receiving a behavior profile model reported by each of at least two terminals in the first cluster; the behavior profile model represents a model for identifying abnormal behavior obtained by local learning of the terminal;

[0007] Based on each received behavior profile model, a feature baseline corresponding to each process is extracted; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data;

[0008] Perform correlation analysis on the feature baselines extracted from each behavior profile model, and correct and adjust the feature baseline corresponding to each process to obtain a corrected behavior profile model.

[0009] In the above solution, the corrected behavior profile model includes:

[0010] Determine the process type;

[0011] The feature baseline of the modified process is stored in the behavior profile library of the corresponding process type;

[0012] The process type is one of the following:

[0013] System processes;

[0014] Key business processes;

[0015] other business processes;

[0016] Behavioral profile models include one of the following:

[0017] System process behavior portrait model;

[0018] Key business process behavior portrait model;

[0019] Other business process behavior portrait models.

[0020] In the above solution, the method further includes:

[0021] Distribute the corrected behavior profile model or the corrected behavior profile model patch to the terminals in the first cluster.

[0022] In the above solution, the method further includes:

[0023] When the set conditions are met, the current behavior profile model continues to be updated;

[0024] The set condition indicates that the abnormal behavior omission rate corresponding to the current behavior portrait model is greater than a first set threshold, and / or the normal behavior false alarm rate corresponding to the current behavior portrait model is greater than a second set threshold.

[0025] This embodiment of the present application further provides a behavior profile construction method, which is applied to terminals in a first cluster, and the method includes:

[0026] Reporting a behavior profile model to the server; the behavior profile model represents a model for identifying abnormal behavior learned locally by the terminal, so as to instruct the server to perform correlation analysis on each received behavior profile model to obtain a corrected behavior profile model;

[0027] Based on the modified behavior profile model, abnormality detection is performed on abnormal behavior of the terminal.

[0028] In the above solution, the abnormality detection of the abnormal behavior of the terminal based on the modified behavior profile model includes:

[0029] Receiving the revised behavior profile model or behavior profile model patch issued by the server to update the local behavior profile model;

[0030] Anomaly detection is performed on local abnormal behaviors based on the locally updated behavior profile model.

[0031] The present application also provides a behavior profile construction device, including:

[0032] A receiving unit, configured to receive a behavior profile model reported by each of at least two terminals in the first cluster; the behavior profile model represents a model for identifying behavior anomalies obtained by local learning of the terminal;

[0033] An extraction unit is configured to extract a feature baseline corresponding to each process based on each received behavior profile model; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data;

[0034] The generation unit is used to perform correlation analysis on the feature baselines extracted by each behavior profile model, and to correct and adjust the feature baseline corresponding to each process, so as to obtain a corrected behavior profile model.

[0035] The present application also provides a behavior profile construction device, including:

[0036] A reporting unit, configured to report a behavior profile model to a server; the behavior profile model represents a model for identifying abnormal behavior learned locally by the terminal, and instructs the server to perform correlation analysis on each received behavior profile model to obtain a corrected behavior profile model;

[0037] The detection unit is used to perform anomaly detection on abnormal behavior of the terminal based on the modified behavior profile model.

[0038] An embodiment of the present application further provides an electronic device, comprising: a processor and a memory for storing a computer program that can be run on the processor,

[0039] Wherein, the processor is used to execute the steps of the above-mentioned behavior profile construction method when running the computer program.

[0040] An embodiment of the present application also provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned behavior profile construction method are implemented.

[0041] The solution provided by the embodiment of the present application is that the server receives a behavior portrait model reported by each of at least two terminals in the first cluster; the behavior portrait model represents a model for identifying behavioral anomalies obtained by local learning of the terminal; based on each received behavior portrait model, a feature baseline corresponding to each process is extracted; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data; correlation analysis is performed on the feature baselines extracted by each behavior portrait model, and the feature baseline corresponding to each process is corrected and adjusted to obtain a corrected behavior portrait model. The terminals in the first cluster report behavior portrait models to the server; the behavior portrait model represents a model for identifying behavioral anomalies obtained by local learning of the terminal, so as to instruct the server to perform correlation analysis on each received behavior portrait model to obtain a corrected behavior portrait model; based on the corrected behavior portrait model, anomaly detection is performed on abnormal behavior of the terminal locally. Based on the solution provided in the embodiment of the present application, the server corrects and adjusts the feature baseline corresponding to each process to obtain a corrected behavior portrait model. The terminal performs anomaly detection on the local abnormal behavior of the terminal based on the corrected behavior portrait model, thereby achieving effective updating and optimization of the local behavior portrait model of the terminal, solving the problem of attack behavior mixed in during the terminal learning the behavior portrait model, reducing the missed reporting rate of abnormal behavior, and at the same time, enriching the local behavior portrait model of the terminal and reducing the false alarm rate of normal behavior. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 A schematic diagram of the implementation process of the behavior profile construction method provided in the embodiment of the present application;

[0043] Figure 2 A schematic diagram of a process flow for implementing a behavior profile construction method provided in another embodiment of the present application;

[0044] Figure 3 A schematic diagram of the implementation process of the cloud behavior profile construction method provided in the application embodiment of this application;

[0045] Figure 4 A schematic diagram of the structure of a behavior profile construction device provided in an embodiment of the present application;

[0046] Figure 5 A schematic diagram of the structure of a behavior profile building device provided in another embodiment of the present application;

[0047] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0048] In virtual network scenarios, electronic devices use behavioral models to filter out abnormal behaviors from behavioral data, and the detection cost of behavior recognition is high.

[0049] Based on this, in various embodiments of the present application, the server receives a behavior portrait model reported by each of at least two terminals in the first cluster; the behavior portrait model represents a model for identifying behavioral anomalies obtained by local learning of the terminal; based on each received behavior portrait model, a feature baseline corresponding to each process is extracted; the feature baseline is used to determine whether the behavioral data of the corresponding process is normal behavior data; correlation analysis is performed on the feature baselines extracted by each behavior portrait model, and the feature baseline corresponding to each process is corrected and adjusted to obtain a corrected behavior portrait model. The terminals in the first cluster report behavior portrait models to the server; the behavior portrait model represents a model for identifying behavioral anomalies obtained by local learning of the terminal, instructing the server to perform correlation analysis on each received behavior portrait model to obtain a corrected behavior portrait model; based on the corrected behavior portrait model, anomaly detection is performed on the abnormal behavior of the terminal locally. Based on the solution provided in the embodiment of the present application, the server corrects and adjusts the feature baseline corresponding to each process to obtain a corrected behavior portrait model. The terminal performs anomaly detection on the local abnormal behavior of the terminal based on the corrected behavior portrait model, thereby achieving effective updating and optimization of the local behavior portrait model of the terminal, solving the problem of attack behavior mixed in during the terminal learning the behavior portrait model, reducing the missed reporting rate of abnormal behavior, and at the same time, enriching the local behavior portrait model of the terminal and reducing the false alarm rate of normal behavior.

[0050] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0051] Figure 1 This is a schematic diagram of the implementation process of the behavior portrait construction method provided in the embodiment of the present application. The embodiment of the present application provides a behavior portrait construction method applied to a server. The method includes:

[0052] Step 101: Receive a behavior profile model reported by each of at least two terminals in a first cluster.

[0053] The behavior profile model represents a model obtained by local learning of the terminal for identifying abnormal behavior.

[0054] Step 102: Based on each received behavior profile model, extract the feature baseline corresponding to each process.

[0055] The feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data.

[0056] Step 103: Perform correlation analysis on the feature baselines extracted from each behavior profile model, and correct and adjust the feature baseline corresponding to each process to obtain a corrected behavior profile model.

[0057] In a virtual network scenario, the first cluster typically includes two or more terminals, including but not limited to servers, mobile terminals, and other electronic devices. These terminals run processes that generate behavioral data. Based on this behavioral data, the terminals learn behavioral profile models and send them to the server. The servers can be within or outside the first cluster, without limitation.

[0058] In step 101, a behavior profile model is learned locally by the terminal. Each behavior profile model represents a set of normal behavior data corresponding to each process in at least one process determined by the terminal. This model can be used to filter behavior data corresponding to abnormal behavior events from the terminal's local behavior data. The behavior data can be in the form of executable file paths, etc.

[0059] Here, the terminal reporting the behavior portrait model to the server can be understood as the terminal reporting normal behavior data corresponding to each process determined by the terminal to the server.

[0060] In step 102, the feature baseline includes features that can determine whether the behavior data of the corresponding process is normal behavior data and the numerical values corresponding to the features (referred to as feature values). Here, each behavior profile model includes normal behavior data corresponding to each process in at least one process determined by the terminal, each process corresponds to at least one feature, and the feature baseline corresponding to each process may include at least one feature and a feature value. In the embodiment of the present application, the server extracts the feature baseline (i.e., at least one feature and the numerical value corresponding to the feature) corresponding to each process in each behavior profile model.

[0061] It should be noted that the feature baseline corresponding to each process extracted from each behavior portrait model is used to help the terminal corresponding to each behavior portrait model determine whether the behavior data generated by the corresponding process locally on the terminal is normal behavior data.

[0062] For example, the behavior portrait model reported by terminal 1 includes the normal behavior data corresponding to process a determined by terminal 1. The feature that can determine whether the behavior data of process a is normal behavior data is feature A, and the numerical value corresponding to feature A is n. Then the feature baseline corresponding to process a (that is, feature A and the numerical value corresponding to feature A is n) is used to help terminal 1 determine whether the behavior data generated by process a locally in terminal 1 is normal behavior data.

[0063] In practical applications, the types of features include, but are not limited to: process activity, file owner, issuer of file signature, threat intelligence information of file, and behavior information of process.

[0064] In practical applications, the activity of a process can be obtained based on the number of occurrences of certain operations in the behavior data of the process. Assume that software A is installed on a terminal. When software A is clicked once, software A will run, and at this time, one executable file path of software A is obtained. When software A is clicked 10 times, 10 executable file paths of software A will be obtained. At this time, the activity of the software A process can be extracted from the behavior data of software A as 10.

[0065] In practical applications, after receiving the behavior data reported by the terminal, the behavior data can be converted in data format into a data format that can be recognized and processed by the server.

[0066] In step 103, corresponding thresholds will be set for the feature values corresponding to the processes extracted in step 102. Based on each process's corresponding features and feature value thresholds, the feature baselines corresponding to each process respectively extracted from each behavior portrait model are integrated together and subjected to correlation analysis. The feature values included in the feature baselines corresponding to each process obtained by integration are screened, and the feature values that meet the requirements are selected to generate a feature baseline that meets the requirements for each process. Finally, based on the behavior data corresponding to the generated feature baseline that meets the requirements, a corrected behavior portrait model is obtained.

[0067] The threshold can be set according to the experience of developers, or roughly selected according to the received behavior data, or calculated according to a certain formula based on the received behavior data, etc. It can be understood that the threshold can be a single value such as x, and when the feature value is greater than x or less than x, the value-taking condition is met; the feature baseline can also be two values such as x and y (x < y), and when the feature value is greater than x and less than y, or less than x, or greater than y, the value-taking condition is met.

[0068] In practical applications, the behavior portrait models reported by different terminals may include the normal behavior data of the same process determined by them respectively. That is, there may be multiple feature values of the same feature included in the feature baseline corresponding to the same process obtained by integration. At this time, there are two ways to screen the feature values that meet the requirements according to the feature value threshold. One is to randomly or sequentially judge the feature values. As long as one feature value meets the value-taking condition, the feature value that meets the value-taking condition is selected as the feature value that meets the requirements, and the remaining feature values are no longer judged; the other is to remove the maximum and minimum values of the feature values, and judge each of the remaining feature values. All the feature values that meet the value-taking condition are feature values that meet the requirements.

[0069] For example, the feature baseline corresponding to process a includes process activity. The process activity of process a extracted from the behavior profile model reported by terminal A is 5, the process activity of process a extracted from the behavior profile model reported by terminal B is 11, the process activity of process a extracted from the behavior profile model reported by terminal C is 15, and the process activity of process a extracted from the behavior profile model reported by terminal D is 20. Assuming the process activity threshold is greater than 10, one method is to determine that the process activity of process a reported by terminal A, 5, does not meet the value condition, while the process activity of process a reported by terminal B, 11, meets the value condition. In this case, the process activity of process a reported by terminal B meets the required feature value. Another method is to remove the maximum value of 20 and the minimum value of 5 of the process activity, and determine that the process activity of process a reported by terminal B, 11, meets the value condition, and the process activity of process a reported by terminal C, 15, meets the value condition. In this case, the process activity of process a reported by both terminals B and C meets the required feature value.

[0070] In an embodiment of the present application, the server corrects and adjusts the feature baseline corresponding to each process to obtain a corrected behavior portrait model. The terminal performs anomaly detection on the local abnormal behavior of the terminal based on the corrected behavior portrait model, thereby achieving effective updating and optimization of the local behavior portrait model of the terminal, solving the problem of attack behavior mixed in during the terminal learning the behavior portrait model, reducing the missed reporting rate of abnormal behavior, and at the same time, enriching the local behavior portrait model of the terminal and reducing the false alarm rate of normal behavior.

[0071] In one embodiment, the modified behavior profile model includes:

[0072] Determine the process type;

[0073] The feature baseline of the modified process is stored in the behavior profile library of the corresponding process type;

[0074] The process type is one of the following:

[0075] System processes;

[0076] Key business processes;

[0077] other business processes;

[0078] Behavioral profile models include one of the following:

[0079] System process behavior portrait model;

[0080] Key business process behavior portrait model;

[0081] Other business process behavior portrait models.

[0082] Here, the characteristic baseline of a process can be understood as the behavioral profile of the process.

[0083] The system process behavior profile library is also known as the system process behavior profile model. By analyzing the system process behavior data, the server can identify the terminal's service type and distribute it to the terminal as a behavioral whitelist of system default software. Based on this whitelist, the terminal will identify the behavior data on the whitelist as white behavior. This shortens the time spent filtering behavior data and reduces the false positive rate for normal behavior. In actual applications, if the terminal's system default behavior profile for a particular system process does not converge, the server distributes the behavior profile of that process, reducing the learning difficulty for the terminal.

[0084] The behavior profile library for key business processes is the behavior profile model for key business processes. The server determines the security behavior boundaries of the business by analyzing the key business processes of the terminal (usually a server, such as a web server). This can be used to filter and detect unknown behaviors. It can also be distributed to terminals as a public whitelist, allowing terminals that cannot learn business behaviors to obtain behavior profiles. The behavior profiles distributed by the server are used to filter abnormal behavior data, improving the phenomenon of misreporting normal behavior as abnormal behavior and reducing the false alarm rate. The values of some features of abnormal behavior events are different from those of normal behavior events. Corresponding alarm rules are set for these features, so abnormal behavior events will trigger alarms and generate alarm logs.

[0085] The behavioral profile library for other business processes is the behavioral profile model for other business processes. Here, other business processes can be understood as application processes. By analyzing the behavioral data corresponding to the whitelist behaviors of application processes, the server can identify normal behavior generated by the application during operation. By building and distributing an application-specific whitelist, the terminal identifies the behavior data generated by applications on the whitelist as whitelist behavior based on the distributed application whitelist. This shortens the time spent filtering behavioral data and reduces the false positive rate for normal behavior.

[0086] Since there is usually a certain degree of division of labor among the terminals within a cluster, in other words, the types of processes supported by the terminals may be different. In this embodiment, the terminals within the first cluster run processes of at least one process type, and the feature baselines corresponding to the processes are classified according to the process types. The feature baselines corresponding to processes of the same type are stored in the same behavior portrait library, which facilitates the subsequent targeted distribution of behavior portraits to the terminals of the first cluster. It can also reduce the memory space occupied by each behavior portrait, so that the behavior portrait can be loaded into the terminal's memory, thereby making the behavior portrait universally applicable to various types of terminals and meeting the application of various virtual network scenarios.

[0087] In one embodiment, the method further comprises:

[0088] Distribute the corrected behavior profile model or the corrected behavior profile model patch to the terminals in the first cluster.

[0089] Here, the server can implement the distribution of the corrected behavior portrait model or the corrected behavior portrait model patch through software interfaces, hardware interfaces, etc. It should be noted that the server's generation and distribution of the corrected behavior portrait model or the corrected behavior portrait model patch can be two discontinuous behaviors, that is, the server's distribution behavior can be broadcasting to the terminals of the first cluster after obtaining the corrected behavior portrait model or the corrected behavior portrait model patch, or storing the corrected behavior portrait model or the corrected behavior portrait model patch and then sending it to the terminal when the trigger condition is met (for example, receiving a request from the terminal or a terminal joining the first cluster), which is not limited here.

[0090] Furthermore, the terminal that receives the revised behavior profile model or the revised behavior profile model patch may or may not be the terminal that reported the behavior profile model. In an embodiment of the present application, the server performs correlation analysis on the behavior profile models reported by the terminals in the first cluster to obtain a revised behavior profile model, enabling the terminals in the first cluster to use the revised behavior profile model or the revised behavior profile model patch to update their local behavior profile models and use the locally updated behavior profile model to filter out abnormal behavior data from the local behavior data.

[0091] The server distributes the revised behavior profile model or a revised behavior profile model patch to the terminals in the first cluster, and the terminals obtain or update the behavior profile model used to filter abnormal behavior data. This reduces the number of terminals in the cluster that need to learn the behavior profile model. For example, terminals that join the cluster later do not need to learn the behavior profile model, thereby reducing the detection cost during behavior recognition. At the same time, for terminals that cannot learn or have a short learning period, using the behavior profile model distributed by the server to filter abnormal behavior data can reduce the false alarm rate of misreporting normal behavior as abnormal behavior.

[0092] In one embodiment, the server can determine the process running on the terminal based on the behavioral profile model reported by the terminal and send a modified behavioral profile model or a modified behavioral profile model patch corresponding to the running process to the terminal. Using the modified behavioral profile model to filter abnormal behavior data can improve the phenomenon of false positives caused by insufficient learning period and reduce the false positive rate of normal behavior.

[0093] In one embodiment, the server can obtain, through the management plane of the first cluster, the processes supported by the terminal's operating environment and / or newly installed processes on the terminal, and send to the terminal a revised behavior profile model or a revised behavior profile model patch corresponding to the processes supported by the terminal and / or newly installed processes on the terminal. Using the revised behavior profile model to filter abnormal behavior data can improve the phenomenon of false positives caused by insufficient learning period and reduce the false positive rate of normal behavior.

[0094] In one embodiment, the server can send a corresponding modified behavior profile model or a modified behavior profile model patch to the terminal in response to an update request from the terminal (e.g., updating a local system process behavior profile model). Using the modified behavior profile model to filter abnormal behavior data can improve the phenomenon of false positives caused by insufficient learning period and reduce the false positive rate of normal behavior.

[0095] In one embodiment, the method further comprises:

[0096] When the set conditions are met, the current behavior profile model continues to be updated;

[0097] The set condition indicates that the abnormal behavior omission rate corresponding to the current behavior portrait model is greater than a first set threshold, and / or the normal behavior false alarm rate corresponding to the current behavior portrait model is greater than a second set threshold.

[0098] After obtaining the revised behavior model, the server determines whether the revised behavior profile model satisfies the set conditions. If so, the server determines that the revised behavior profile model needs to be updated and updates the revised behavior profile model based on the results of filtering the behavior data obtained for the revised behavior profile model. The filtering and processing of the behavior data can be performed by operations and maintenance personnel or by a server or other electronic device.

[0099] Here, it is possible to continue to determine whether the updated behavior portrait model satisfies the set conditions, and update the behavior portrait model again if the set conditions are met, until the updated behavior portrait model does not satisfy the set conditions.

[0100] Behavior profile models that meet the specified conditions have a higher rate of missed detections of abnormal behavior and / or a higher rate of false positives of normal behavior. In the above solution, the server uses the filtered behavioral data to update these behavior profile models. This can exclude some or all behavioral data related to abnormal behavior events, improve the ability of abnormal behavior to be learned by the behavior profile model, and thus reduce the abnormal behavior missed detection rate of the behavior profile model. Furthermore, by excluding behavioral data that may cause false positives of normal behavior, the behavior profile model can reduce the false positive rate of normal behavior.

[0101] Figure 2 This is a schematic diagram of the implementation process of the behavior profile construction method provided in the embodiment of the present application. The embodiment of the present application provides a behavior profile construction method, which is applied to terminals in the first cluster, where the terminals include but are not limited to electronic devices such as servers and mobile terminals. The method includes:

[0102] Step 201: Report the behavior profile model to the server.

[0103] The behavior portrait model represents a model for identifying behavior anomalies obtained by local learning of the terminal, so as to instruct the server to perform correlation analysis on each received behavior portrait model to obtain a corrected behavior portrait model.

[0104] Step 202: Based on the modified behavior profile model, perform anomaly detection on abnormal behavior of the terminal.

[0105] In one embodiment, the performing of abnormality detection on the terminal's local abnormal behavior based on the modified behavior profile model includes:

[0106] Receiving the revised behavior profile model or behavior profile model patch issued by the server to update the local behavior profile model;

[0107] Anomaly detection is performed on local abnormal behaviors based on the locally updated behavior profile model.

[0108] In a virtual network scenario, the first cluster typically includes two or more terminals, each of which runs a process that generates behavioral data. The server can be a server within the first cluster or a server outside the first cluster, without limitation.

[0109] The server performs correlation analysis on the behavior portrait models reported by the terminals in the first cluster to obtain a corrected behavior portrait model, and distributes the corrected behavior portrait model or a corrected behavior portrait model patch to the terminals in the first cluster. The terminals receive the corrected behavior portrait model or the corrected behavior portrait model patch issued by the server and update the local behavior portrait model. Using the locally updated behavior portrait model, the terminals can filter out abnormal behavior data from the local behavior data.

[0110] Among them, the terminal that receives the corrected behavior portrait model or the corrected behavior portrait model patch may be the terminal that reported the behavior portrait model, or it may not be. The behavior portrait model is learned locally by the terminal, and each behavior portrait model represents a set of normal behavior data corresponding to each process in at least one process determined by the terminal, and can be used to filter out behavior data corresponding to abnormal behavior events from the behavior data generated by the process on the terminal. The behavior data can be data in the form of executable file paths, etc. Here, the corrected behavior portrait model or the corrected behavior portrait model patch can be used by one or more terminals in the first cluster. The terminal can receive the corrected behavior portrait model or the corrected behavior portrait model patch sent by the server through software interfaces, hardware interfaces, etc.

[0111] The server distributes the revised behavior profile model or a revised behavior profile model patch to the terminals in the first cluster, and the terminals obtain or update the behavior profile model used to filter abnormal behavior data. This reduces the number of terminals in the cluster that need to learn the behavior profile model. For example, terminals that join the cluster later do not need to learn the behavior profile model, thereby reducing the detection cost during behavior recognition. At the same time, for terminals that cannot learn or have a short learning period, using the behavior profile model distributed by the server to filter abnormal behavior data can reduce the false alarm rate of misreporting normal behavior as abnormal behavior.

[0112] The present application will be described in further detail below in conjunction with application examples.

[0113] Currently, expert rules are defined to filter behavioral models (same as behavioral profiling models) running on servers. Expert rules are rules designed by experts using their expertise in a specific field that are computer-recognizable and can be used for detection. Expert rules are generally divided into white rules and black rules. The effectiveness of behavioral recognition depends on the quality of the rules extracted by security experts. Actual testing results show that it is difficult to achieve a balance between false positives and false negatives, and relying on security experts for maintenance is relatively inefficient. Furthermore, the effectiveness of detecting zero-day attacks is also limited. Zero-day attacks are attacks in which hackers exploit undisclosed vulnerabilities or tools to attack customer servers. Here, a server can be understood as a computer that provides users with various high-performance services, such as a supercomputer used for scientific computing tasks.

[0114] The behavior model used in abnormal behavior detection methods has at least one of the following problems:

[0115] 1) The behavior model can only learn a limited number of behaviors, and normal behaviors are falsely reported.

[0116] 2) Attack behaviors are mixed in during the learning period, and some malicious behaviors are missed.

[0117] 3) For hosts that cannot learn or have a short learning period, the baseline of the behavioral model cannot converge.

[0118] Based on this, this application embodiment proposes a method and system for constructing a terminal cluster behavior portrait library, which constructs a cloud-based behavior portrait library from three dimensions: application portrait, system background portrait, and business portrait. The behavior portrait library mainly obtains characteristic values that can be used to determine white behavior by analyzing the terminal behavior model, such as the activity level of the process, the black and white determination results of the process that generates the behavior, the running events of the behavior, the threat intelligence information of related files, the owner of the file, the issuer of the file signature, the behavior information of the process, etc., and judges the behavior data based on these characteristic values. The behavior data determined to be white behavior is sent to the portrait construction module. According to the corresponding process type, a behavior portrait of the corresponding process type is generated based on the behavior data.

[0119] The behavioral profile of the system process is also known as the system background profile. By analyzing the behavioral data of the system process, the server can identify the terminal's service type and distribute it to the terminal as a behavioral whitelist for the system's default software. Based on the distributed behavioral whitelist, the terminal will identify the behavioral data on the whitelist as white behavior. This shortens the time spent filtering behavioral data and reduces the false positive rate for normal behavior. In actual applications, if the behavioral model of the terminal's system default process does not converge, the server distributes the behavioral profile of the system process, reducing the learning difficulty for the terminal.

[0120] Behavioral profiles corresponding to business processes, also known as business profiles, are analyzed by the server (usually a server, such as a web server) to determine the security behavior boundaries of the business. This can be used to filter and detect unknown behaviors. It also serves as a public whitelist for the cluster, allowing terminals that cannot learn business behaviors to obtain behavioral profiles. The behavioral profiles distributed by the server filter abnormal behavior data, improving the phenomenon of misreporting normal behavior as abnormal behavior and reducing the false positive rate of normal behavior.

[0121] The behavioral profile corresponding to the application process, also known as the application profile, is the most granular of the three profile types. By analyzing the behavioral data corresponding to the whitelist behaviors of the application process, the server can identify normal behavior generated by the application during operation. By building and distributing a whitelist at the application granularity, the terminal will identify the behavioral data generated by the applications on the whitelist as whitelist behavior based on the issued application whitelist. This shortens the time spent on behavioral data filtering and reduces the false positive rate of normal behavior.

[0122] The above solution, as a supplement to the host dynamic behavior baseline algorithm, can effectively solve the three problems mentioned above. The server uses the behavior data reported to the cloud to generate a cluster-wide behavior profile model for terminals of the same business process type in a cluster, and builds a behavior profile library for the terminal cluster, achieving the following: (1) accelerating the learning progress of the terminal behavior model and reducing the number of terminals that need to be learned; (2) solving the problem of attack behaviors being mixed into the model learning period; and (3) enriching the terminal behavior profile and alleviating the problem of false positives.

[0123] Figure 3 The following is a schematic diagram of the implementation process of the cloud behavior profile construction method provided by the application embodiment of the present application, which at least includes:

[0124] agent-model: The single-machine behavior model learned by the terminal, used to filter and detect unknown behaviors on the host.

[0125] Terminal behavior model reporting: This function reports the learned single-device behavior model of a terminal to the cloud. This model can serve as input to the terminal cluster behavior profile library, contributing to normal behavior. Furthermore, the terminal cluster behavior profile library can identify flaws in the model and issue targeted behavior profiles.

[0126] Model information parsing: Parse the model data into the features required by the feature extraction module.

[0127] Feature Extraction Module: This module primarily extracts features that can be used for whitelisting, such as process activity, file owner, file signature issuer, file threat intelligence, process behavior, and process activity. Any file executed in the operating system is referred to as a process.

[0128] Process white behavior identification and filtering module: Based on the above characteristics, the process behavior is judged and filtered. Only white behaviors related to the process can enter the process type identification module.

[0129] Process type identification module: Based on the process type, we classify the process's daily behavior into system background portraits, business portraits, and application portraits to facilitate subsequent targeted data distribution.

[0130] Manual identification and operation and maintenance module: Security experts can optimize the model's behavioral model to solve the problem of infiltration attacks during the learning period and the problem of high false positives.

[0131] Update and distribution module: The cloud-based terminal cluster behavior portrait library distributes corresponding portraits in a targeted manner based on the problems and needs of the terminal's behavior model.

[0132] This application embodiment proposes a method and system for building a cloud-based behavioral profile library. By maintaining behavioral profiles across three dimensions: system context, business, and application profiles, this method fully leverages the cloud's processing power for clustered terminals, effectively achieving a positive iteration of terminal-cloud linkage. Furthermore, the method's automated process allows for effective updates to behavioral models with minimal effort from security experts, improving maintenance efficiency.

[0133] Any computational method that is similar to the method or architecture of the present invention but uses other similar detection modules to construct and process behavioral data profiles is within the scope of protection of this application.

[0134] Any solution similar to the method or architecture of the present invention but used on different operating systems is within the scope of protection of this application.

[0135] Any solution that is similar to the method or architecture of the present invention but uses a different specific language model is within the scope of protection of this application.

[0136] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides a behavior portrait construction device, such as Figure 4 As shown, the device includes:

[0137] The receiving unit 401 is configured to receive a behavior profile model reported by each of at least two terminals in the first cluster; the behavior profile model represents a model for identifying behavior anomalies obtained by local learning of the terminal;

[0138] Extraction unit 402, configured to extract a feature baseline corresponding to each process based on each received behavior profile model; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data;

[0139] The generating unit 403 is configured to perform correlation analysis on the feature baselines extracted from each behavior profile model, and to correct and adjust the feature baseline corresponding to each process, thereby obtaining a corrected behavior profile model.

[0140] In one embodiment, when obtaining the modified behavior profile model, the generating unit 403 is configured to:

[0141] Determine the process type;

[0142] The feature baseline of the modified process is stored in the behavior profile library of the corresponding process type;

[0143] The process type is one of the following:

[0144] System processes;

[0145] Key business processes;

[0146] other business processes;

[0147] Behavioral profile models include one of the following:

[0148] System process behavior portrait model;

[0149] Key business process behavior portrait model;

[0150] Other business process behavior portrait models.

[0151] In one embodiment, the apparatus further comprises:

[0152] A distribution unit is used to distribute the corrected behavior profile model or the corrected behavior profile model patch to the terminals in the first cluster.

[0153] In one embodiment, the apparatus further comprises:

[0154] The updating unit is used to continue updating the current behavior profile model when the set conditions are met; wherein,

[0155] The set condition indicates that the abnormal behavior omission rate corresponding to the current behavior portrait model is greater than a first set threshold, and / or the normal behavior false alarm rate corresponding to the current behavior portrait model is greater than a second set threshold.

[0156] In actual application, the receiving unit 401 can be implemented by a communication interface in a behavior portrait construction device, the extraction unit 402, the generation unit 403, and the update unit can be implemented by a processor in a behavior portrait construction device, and the distribution unit can be implemented by a processor in a behavior portrait construction device combined with a communication interface.

[0157] It should be noted that the behavior portrait construction device provided in the above embodiment only uses the division of the above program modules as an example to illustrate the construction of the behavior portrait. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the behavior portrait construction device provided in the above embodiment and the behavior portrait construction method embodiment belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0158] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides a behavior portrait construction device, such as Figure 5 As shown, the device includes:

[0159] Reporting unit 501 is used to report a behavior profile model to the server; the behavior profile model represents a model for identifying abnormal behavior learned locally by the terminal, and instructs the server to perform correlation analysis on each received behavior profile model to obtain a corrected behavior profile model;

[0160] The detection unit 502 is used to perform anomaly detection on abnormal behaviors of the terminal based on the modified behavior profile model.

[0161] In one embodiment, the detection unit 502 is configured to:

[0162] Receiving the revised behavior profile model or behavior profile model patch issued by the server to update the local behavior profile model;

[0163] Anomaly detection is performed on local abnormal behaviors based on the locally updated behavior profile model.

[0164] In actual application, the reporting unit 501 can be implemented by a communication interface in the device based on behavior profile construction, and the detection unit 502 can be implemented by a processor in the device based on behavior profile construction.

[0165] It should be noted that the behavior portrait construction device provided in the above embodiment only uses the division of the above program modules as an example to illustrate the construction of the behavior portrait. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the behavior portrait construction device provided in the above embodiment and the behavior portrait construction method embodiment belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0166] Based on the hardware implementation of the above-mentioned program modules, and in order to implement the behavior portrait construction method of the embodiment of the present application, the embodiment of the present application also provides an electronic device. Figure 6 This is a schematic diagram of the hardware structure of the electronic device according to the embodiment of the present application. Figure 6 As shown, the electronic equipment includes:

[0167] Communication interface 1, capable of exchanging information with other devices such as network devices;

[0168] The processor 2 is connected to the communication interface 1 to implement information exchange with other devices and is used to execute the method provided by one or more of the above technical solutions when running a computer program. The computer program is stored in the memory 3.

[0169] Of course, in actual application, the various components in the electronic device are coupled together through the bus system 4. It can be understood that the bus system 4 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 4 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 6 Various buses are labeled as bus system 4.

[0170] The memory 3 in the embodiment of the present application is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program used to operate on the electronic device.

[0171] It is understood that the memory 3 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a magnetic disk memory or a magnetic tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 2 described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memory.

[0172] The method disclosed in the above-mentioned embodiment of the present application can be applied to processor 2 or implemented by processor 2. Processor 2 may be an integrated circuit chip with signal processing capabilities. During the implementation process, each step of the above-mentioned method can be completed by the integrated logic circuit of the hardware in processor 2 or instructions in the form of software. The above-mentioned processor 2 can be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 2 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiment of the present application can be directly embodied as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in memory 3. Processor 2 reads the program in memory 3 and completes the steps of the above-mentioned method in combination with its hardware.

[0173] When the processor 2 executes the program, the corresponding processes in the various methods of the embodiments of the present application are implemented. For the sake of brevity, they are not repeated here.

[0174] In an exemplary embodiment, the present application also provides a storage medium, namely, a computer storage medium, specifically a computer-readable storage medium, such as a memory 3 storing a computer program. The computer program can be executed by a processor 2 to perform the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0175] In the several embodiments provided in this application, it should be understood that the disclosed devices, electronic devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0176] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0177] In addition, all functional units in the embodiments of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.

[0178] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: mobile storage devices, ROM, RAM, disks or optical disks, etc. Various media that can store program codes.

[0179] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

[0180] It is understandable that in the embodiments of the present application, when user information is involved, when the embodiments of the present application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0181] It should be noted that the technical solutions described in the embodiments of this application can be arbitrarily combined without conflict. Unless otherwise specified or limited, the term "connection" should be understood in a broad sense. For example, it can be an electrical connection or internal communication between two components. It can be a direct connection or an indirect connection through an intermediate medium. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.

[0182] Additionally, in the examples of this application, "first," "second," etc., are used to distinguish similar objects, and are not necessarily used to describe a specific order or precedence. It should be understood that the objects distinguished by "first," "second," and "third" can be interchanged where appropriate, such that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0183] The term "and / or" herein simply describes an association relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can represent the existence of three situations: A alone, A and B simultaneously, and B alone. In addition, the term "at least one" herein refers to any combination of at least two of any one or more of a plurality. For example, "at least one of A, B, and C" can represent any one or more elements selected from the set consisting of A, B, and C.

[0184] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0185] The various specific technical features in the various embodiments described in the specific implementation methods can be combined in various ways without contradiction. For example, different implementation methods can be formed by combining different specific technical features. In order to avoid unnecessary repetition, the various possible combinations of the specific technical features in this application will not be described separately.

Claims

1. A behavior profile construction method, characterized in that: Applied to a server, the method includes: Receiving a behavior profile model reported by each of at least two terminals in the first cluster; the behavior profile model represents a model for identifying abnormal behavior obtained by local learning of the terminal; Based on each received behavior profile model, a feature baseline corresponding to each process is extracted; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data; The feature baselines extracted from each behavior profile model are subjected to correlation analysis, and the feature baseline corresponding to each process is corrected and adjusted to obtain a corrected behavior profile model; the corrected behavior profile model is used by the terminal to perform anomaly detection on abnormal behaviors locally in the terminal.

2. The method according to claim 1, characterized in that The modified behavior profile model includes: Determine the process type; The feature baseline of the modified process is stored in the behavior profile library of the corresponding process type; The process type is one of the following: System processes; Key business processes; other business processes; Behavioral profile models include one of the following: System process behavior portrait model; Key business process behavior portrait model; Other business process behavior portrait models.

3. The method according to claim 1, characterized in that The method further comprises: Distribute the corrected behavior profile model or the corrected behavior profile model patch to the terminals in the first cluster.

4. The method according to claim 1, wherein The method further comprises: When the set conditions are met, the current behavior profile model continues to be updated; The set condition indicates that the abnormal behavior omission rate corresponding to the current behavior portrait model is greater than a first set threshold, and / or the normal behavior false alarm rate corresponding to the current behavior portrait model is greater than a second set threshold.

5. A behavior profile construction method, characterized in that: Applied to a terminal in a first cluster, the method includes: Reporting a behavior profile model to the server; the behavior profile model represents a model for identifying abnormal behavior learned locally by the terminal, instructing the server to extract a feature baseline corresponding to each process based on each received behavior profile model, perform correlation analysis on the feature baselines extracted by each behavior profile model, and modify and adjust the feature baseline corresponding to each process to obtain a modified behavior profile model; wherein the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data; Based on the modified behavior profile model, abnormality detection is performed on abnormal behavior of the terminal.

6. The method according to claim 5, characterized in that The performing abnormality detection on the abnormal behavior of the terminal based on the modified behavior profile model includes: Receiving the revised behavior profile model or behavior profile model patch issued by the server to update the local behavior profile model; Anomaly detection is performed on local abnormal behaviors based on the locally updated behavior profile model.

7. A behavior profile construction device, characterized in that: include: a receiving unit, configured to receive a behavior portrait model reported by each of the at least two terminals in the first cluster; The behavior profile model represents a model for identifying abnormal behavior obtained by local learning of the terminal; An extraction unit is configured to extract a feature baseline corresponding to each process based on each received behavior profile model; the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data; The generation unit is used to perform correlation analysis on the feature baselines extracted by each behavior profile model, and to correct and adjust the feature baseline corresponding to each process, so as to obtain a corrected behavior profile model; the corrected behavior profile model is used by the terminal to perform anomaly detection on abnormal behavior of the terminal locally.

8. A behavior profile construction device, characterized in that: include: A reporting unit is configured to report a behavior profile model to a server; the behavior profile model represents a model for identifying abnormal behavior learned locally by the terminal, instructing the server to extract a feature baseline corresponding to each process based on each received behavior profile model, perform correlation analysis on the feature baselines extracted by each behavior profile model, and modify and adjust the feature baseline corresponding to each process to obtain a modified behavior profile model; wherein the feature baseline is used to determine whether the behavior data of the corresponding process is normal behavior data; The detection unit is used to perform anomaly detection on abnormal behavior of the terminal based on the modified behavior profile model.

9. An electronic device, characterized in that: include: a processor and a memory for storing a computer program capable of being executed on the processor, Wherein, when the processor is used to run the computer program, it executes the steps of the method according to any one of claims 1 to 4, or executes the steps of the method according to claim 5 or 6.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4, or the steps of the method according to claim 5 or 6 are implemented.

Citation Information

Patent Citations

  • Network flow anomaly detection method based on space-time IP address portrait

    CN114050922A

  • User account loss detection method and device, electronic equipment and storage medium

    CN115146263A