Abnormal user detection method, device and computer program product

By analyzing the heterogeneous data source and behavior sequence information associated with the account, we can determine whether the user is abnormal, and solve the shortcomings of the detection of internal account abnormalities in the existing technology, achieve a lower false alarm rate and missed alarm rate, and improve the internal threat protection capability of network security.

CN115834124BActive Publication Date: 2025-05-13HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211283795.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-05-13
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

Existing network security products are difficult to detect and protect against abnormal threats from internal accounts, and the false alarm rate and underreport rate are high, resulting in high average cost of internal threat events.

Method used

By determining the heterogeneous data source associated with the account, obtaining the data to be detected associated with the user, analyzing the sequence information of each behavior sequence, and determining whether the user is abnormal based on the threshold, thereby realizing adaptive abnormality detection.

Benefits of technology

It reduces the false alarm rate and missed rate of internal account abnormal detection, improves the detection efficiency and reliability of abnormal threats to internal account abnormal threats, and effectively protects against internal threat events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834124B_ABST
    Figure CN115834124B_ABST
Patent Text Reader

Abstract

The present application relates to an abnormal user detection method, device and computer program product. The method comprises: determining the heterogeneous data source associated with the account; based on the account, obtaining the data to be detected associated with the user from the corresponding heterogeneous data source; based on the data to be detected, determining the sequence information of each behavior sequence contained therein; based on each sequence information and the threshold corresponding to each behavior sequence, determining whether the user is abnormal. The use of this method makes up for the lack of abnormal detection and security protection for internal accounts in network security products, realizes adaptive user abnormal detection, and reduces the false alarm rate and missed alarm rate of abnormal detection of internal accounts.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to an abnormal user detection method, device and computer program product. Background Art

[0002] It can be seen from the data that most security incidents in the field of network security technology are caused by internal personnel, and the average cost of internal threat incidents is as high as tens of millions. However, most of the current network security-related products are targeted at network boundaries and malware, and cannot detect internal threats such as account sharing, account theft, internal user abuse and other related security risks.

[0003] In traditional technologies, some traditional detection methods based on single data source rules not only have a high false alarm rate but also a large number of missed alarms. They have low efficiency and low reliability in detecting anomalies for internal users. Summary of the invention

[0004] Based on this, it is necessary to provide an abnormal user detection method, device and computer program product that can detect abnormal threats to internal accounts and achieve lower false alarm rate and missed alarm rate in response to the above technical problems.

[0005] In a first aspect, the present application provides a method for detecting abnormal users. The method comprises:

[0006] Determine the heterogeneous data sources associated with the account;

[0007] Based on the account, obtaining the to-be-detected data associated with the user from the corresponding heterogeneous data source;

[0008] Based on the data to be detected, determining sequence information of each behavior sequence included;

[0009] Based on each of the sequence information and a threshold corresponding to each behavior sequence, it is determined whether the user is abnormal.

[0010] In one embodiment, the determining the heterogeneous data source associated with the account includes:

[0011] Collecting heterogeneous data from the heterogeneous data sources;

[0012] Parsing the heterogeneous data to obtain field information; the field information includes account information of the corresponding account;

[0013] Based on the field information, determine whether the accounts belong to the same user.

[0014] In one embodiment, determining whether the accounts belong to the same user based on the field information includes:

[0015] Acquire the field information in the first historical time; the field information includes an information pair of a source user name and a source IP;

[0016] Divide the first historical time into N segments; obtain the number of times Q that the heterogeneous data source account corresponding to the same IP appears in each segment;

[0017] Based on the number Q, count the number M of simultaneous appearances of the heterogeneous data source accounts in different time periods;

[0018] Determine whether the ratio of the number of times M that the heterogeneous data source accounts appear simultaneously to the N segments is greater than a set first threshold;

[0019] If it is greater, then the accounts belong to the same user.

[0020] In one embodiment, determining the sequence information of each behavior sequence respectively included based on each of the to-be-detected data includes:

[0021] Customize the behavior sequences of the account based on the different behaviors of following the account;

[0022] The behavior sequences include a single data source behavior sequence and a multi-data source combined behavior sequence.

[0023] In one embodiment, the step of obtaining the to-be-detected data associated with the user from the corresponding heterogeneous data source based on the account includes:

[0024] Based on the account, acquiring historical data associated with the user from corresponding heterogeneous data sources;

[0025] Based on the historical data, a threshold corresponding to each behavior sequence included is determined.

[0026] In one embodiment, determining the threshold corresponding to each behavior sequence included based on the historical data includes:

[0027] The historical data is data of each behavior sequence within the second historical time;

[0028] Dividing the second historical time into T segments;

[0029] Count the frequency W of the behaviors of each behavior sequence occurring in each interval;

[0030] A threshold corresponding to each behavior sequence within a period of T is obtained; the threshold includes at least one of the following: an average value, a maximum value, a minimum value, a variance, and a standard deviation.

[0031] In one embodiment, the determining whether the user is abnormal based on each of the sequence information and the threshold corresponding to each of the behavior sequences includes:

[0032] Setting different weights for each behavior sequence;

[0033] Based on the weight, measuring the degree of deviation of the sequence information from the threshold corresponding to each behavior sequence to obtain an abnormality score for each behavior sequence;

[0034] The abnormal scores of the various behavior sequences of the user are summed to obtain a comprehensive abnormal score of the user, and determine whether the user is abnormal.

[0035] In one embodiment, after summing up the abnormality scores of the behavior sequences of the user to obtain the comprehensive abnormality score of the user, the method further includes:

[0036] Based on the comprehensive anomaly score, the users are sorted from high to low, and the users with the highest ranking are marked as abnormal users.

[0037] In a second aspect, the present application also provides an abnormal user detection device. The device comprises:

[0038] A determination module is used to determine the heterogeneous data sources associated with the account;

[0039] An acquisition module, used to acquire the data to be detected associated with the user from the corresponding heterogeneous data source based on the account; and determine the sequence information of each behavior sequence contained in the data to be detected based on the data to be detected;

[0040] The judgment module is used to determine whether the user is abnormal based on the sequence information and the threshold corresponding to each behavior sequence.

[0041] In a third aspect, the present application further provides a computer program product, wherein the computer program product comprises a computer program, and when the computer program is executed by a processor, the content of the first aspect is implemented.

[0042] The above-mentioned abnormal user detection method, device, and computer program product, by determining the heterogeneous data source associated with the account; based on the account, obtaining the data to be detected associated with the user from the corresponding heterogeneous data source; based on the data to be detected, determining the sequence information of each behavior sequence contained therein; based on the sequence information and the threshold value corresponding to each behavior sequence, determining whether the user is abnormal, makes up for the lack of abnormal detection and security protection for internal accounts in network security products, realizes adaptive abnormal detection, and reduces the false alarm rate and missed alarm rate of abnormal detection of internal accounts. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 1 is a flow chart of an abnormal user detection method in one embodiment;

[0044] Figure 2 A schematic diagram of a process for a method for aggregating accounts of heterogeneous data sources in one embodiment;

[0045] Figure 3 A flowchart of the steps of an automatic account association algorithm in one embodiment;

[0046] Figure 4 A schematic diagram of a process for determining a threshold value of each behavior sequence in one embodiment;

[0047] Figure 5 Schematic diagram of the process of determining the threshold of each behavior sequence in step S404 in one embodiment;

[0048] Figure 6 A flowchart of an abnormal user detection method according to an exemplary embodiment;

[0049] Figure 7 FIG. 4 is a structural block diagram of an abnormal user detection device in an embodiment. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0051] Reference to "embodiments" in this application means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those of ordinary skill in the art that the embodiments described in this application may be combined with other embodiments without conflict.

[0052] Unless otherwise defined, the technical terms or scientific terms involved in this application should be understood by people with ordinary skills in the technical field to which this application belongs. The words "one", "a", "a", "the" and the like involved in this application do not indicate a quantitative limitation, and may represent the singular or plural. The terms "include", "comprise", "have" and any of their variations involved in this application are intended to cover non-exclusive inclusions; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units that are not listed, or may also include other steps or units inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "multiple" involved in this application refers to greater than or equal to two. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships, for example, "A and / or B" can represent: A exists alone, A and B exist at the same time, and B exists alone. The terms "first", "second", "third" and the like involved in the present application are merely used to distinguish similar objects and do not represent a specific ordering of the objects.

[0053] In one embodiment, Figure 1 As shown, an abnormal user detection method is provided. This embodiment uses the method applied to a terminal as an example for illustration. It can be understood that the method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. Among them, the terminal can be but is not limited to various personal computers, laptops, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server can be implemented as an independent server or a server cluster consisting of multiple servers. In this embodiment, the method includes the following steps:

[0054] S102, determining the heterogeneous data source associated with the account;

[0055] Among them, the heterogeneous data source is a multi-source heterogeneous data source, including but not limited to the following logs: OA logs, AD domain logs, bastion host logs, email logs, host logs, and web browsing logs.

[0056] S104, based on the account, obtaining the to-be-detected data associated with the user from the corresponding heterogeneous data source.

[0057] The data to be detected are all new behaviors under each heterogeneous data source account.

[0058] Optionally, each heterogeneous data source has a corresponding account. Users have accounts of these heterogeneous data sources and leave personal data when using these accounts. Obtaining the data to be detected associated with the user is a key step in determining whether the user has abnormalities.

[0059] S106: Determine the sequence information of each behavior sequence included based on the data to be detected.

[0060] The behavior sequence is derived from the customization of the behavior sequence characteristics for the concerned behaviors or key behaviors in the scenario of internal user threats.

[0061] Optionally, the data to be detected is divided according to the definition of each behavior sequence, and sequence information of different behavior sequences is obtained from the divided data to be detected, wherein the sequence information may be the number of OA logins within 30 minutes.

[0062] S108: Determine whether the user is abnormal based on each sequence information and the threshold corresponding to each behavior sequence.

[0063] Among them, the threshold corresponding to each behavior sequence needs to be obtained based on the historical data of each heterogeneous data source.

[0064] Optionally, by comparing the sequence information of each behavior sequence of the data to be analyzed with the threshold value corresponding to each behavior sequence, it is determined whether the data to be analyzed has an abnormality, so as to know whether the current user has an abnormality, which is beneficial for operation and maintenance personnel to perform security maintenance on the account of abnormal users.

[0065] In the above abnormal user detection method, the heterogeneous data source associated with the account is determined, and based on the account, the data to be detected associated with the user is obtained from the corresponding heterogeneous data source; based on the data to be detected, the sequence information of each behavior sequence contained is determined; based on each sequence information and the threshold corresponding to each behavior sequence, it is determined whether the user is abnormal, which makes up for the lack of abnormal detection and security protection for internal accounts in network security products, and reduces the false alarm rate and missed alarm rate of abnormal detection of internal accounts.

[0066] In one embodiment, Figure 2 As shown, the process of determining the heterogeneous data source associated with the account includes:

[0067] S202: Collect heterogeneous data from the heterogeneous data sources.

[0068] Among them, heterogeneous data includes OA log data, AD domain log data, bastion host log data, email log data, host log data and web browsing log data.

[0069] S204, parsing the heterogeneous data to obtain field information.

[0070] Optionally, the field information includes account information of the corresponding account and important fields under different operations, such as start time, source user name, destination user name, source IP, source port, destination IP, destination port, transmission protocol, request URL, return result, operation and operation result. Among them, different operations include logging in to OA, downloading files, accessing servers and sending emails.

[0071] S206: Determine whether the accounts belong to the same user based on the field information.

[0072] Optionally, based on the account automatic association algorithm, the account can be associated with the user according to the source user name and source IP in the field information. During the association process, the association threshold can be set according to the needs.

[0073] In the above steps, based on the account automatic association algorithm, by obtaining the field information of heterogeneous data sources, the accounts of heterogeneous data sources are grouped into the same user according to the field information, thereby realizing the automatic association of accounts from multiple data sources, and solving the problem of easy association errors when there are too many internal systems and the accounts have no account ledgers.

[0074] In one embodiment, Figure 3 As shown, based on the field information, the automatic account association algorithm for determining whether the account belongs to the same user includes the following steps:

[0075] S302, obtaining field information within a first historical period.

[0076] The first historical time may select a time span as needed, and the field information obtained here includes an information pair consisting of a source user name and a source IP.

[0077] S304, divide the first historical time into N sections; obtain the number of times Q that the heterogeneous data source account corresponding to the same IP appears in each section.

[0078] Optionally, the time intervals of heterogeneous data within the first historical time period are divided into N segments, where the principle of dividing the time intervals is: if the allocation of internal IP addresses is adjusted rapidly and dynamically, for example, the IP is changed once for each login verification or once a day, then a shorter time interval needs to be divided, such as 6 hours or one day; if the allocation of internal IP addresses is relatively fixed, for example, the IP is changed once a week or is a fixedly allocated IP, then a longer time interval can be divided, such as three days or seven days.

[0079] Optionally, after obtaining the number of times Q that the heterogeneous data source accounts corresponding to the same IP appear in each time period, it is also necessary to screen the number Q for valid times and eliminate interference, including excluding source user name and source IP information pairs that appear too few times in each time interval, such as information pairs that only appear once; excluding records corresponding to public IPs, where the public IP is identified as follows: if a certain IP has many corresponding source user names in multiple time intervals and they are almost equal to the number of internal accounts, then this IP is considered to be a public IP and does not participate in subsequent operations.

[0080] S306, based on the number Q, counting the number M of simultaneous appearances of heterogeneous data source accounts in different time periods.

[0081] Optionally, in the above step S304, based on the number Q, after valid number screening is performed to eliminate interference, the number of times M that heterogeneous data source accounts appear simultaneously in different time periods is counted. For example, in one time interval, the source accounts corresponding to a certain IP are A, B and C; in another time interval, the source accounts corresponding to a certain IP (which may be different from the previous IP) are B, C and D. In these two time intervals, the number of times B and C appear simultaneously is 2, and the number of times C and D or C and A appear simultaneously is 1.

[0082] S308, determining whether the ratio of the number of times M and N segments of heterogeneous data source accounts appear simultaneously is greater than a set first threshold.

[0083] The first threshold value can be set according to detection requirements.

[0084] S310: If it is greater than, the accounts belong to the same user.

[0085] Optionally, when accounts with heterogeneous data sources cannot be associated with users through the above-mentioned account automatic association algorithm, more heterogeneous data of the relevant accounts in the first historical time can be extracted for analysis to obtain more field information, and then associated through the above-mentioned account automatic association algorithm. If the association still cannot be made at this time, the relevant account may be an associated anomaly caused by personal access behavior. Since personal access behavior only accesses certain data sources, only the data of some data sources can be used to participate in the subsequent abnormal behavior discovery and scoring.

[0086] In this embodiment, by obtaining the field information within the first historical time, the first historical time is divided into N segments, and the number of times Q that the heterogeneous data source account corresponding to the same IP appears in each time period is obtained; based on the number Q, the number of times M that the heterogeneous data source account appears simultaneously in different time periods is counted; it is determined whether the ratio of the number of times M that the heterogeneous data source account appears simultaneously to the N segments is greater than a set first threshold; if greater, the account belongs to the same user, so that the heterogeneous data source accounts can be grouped together into the same user, thereby realizing automatic association of accounts.

[0087] In one embodiment, based on each to-be-detected data, determining the sequence information of each behavior sequence respectively included includes:

[0088] Based on the different account attention behaviors, each behavior sequence of the account is customized; each behavior sequence includes a single data source behavior sequence and a multi-data source combined behavior sequence.

[0089] Optional, single data source behavior sequence is a behavior sequence defined for a single data source, which can be created based on actual data and behavior. For example, a single source IP address logs in to multiple OA accounts and then downloads a large number of files; an AD domain account that has been dormant for a month suddenly logs in and changes its password; an email is suddenly sent to all accounts in the group; a bastion host account logs in during non-working hours and accesses a large number of servers; company financial personnel frequently access R&D intranet data; host accounts are brute-force cracked; OA accounts are sprayed and brute-force cracked, etc.

[0090] Optional, a multi-data source combined behavior sequence is a behavior sequence defined under multiple data sources, which can be created based on actual data and behavior. For example, after logging into the host, enter the personal mail system to check mails, access the OA system and then access the R&D database, browse the recruitment website and then send emails, access the bastion host and then log in to the AD domain server and modify a large number of passwords.

[0091] In one embodiment, Figure 4 As shown, after obtaining the data to be detected associated with the user from the corresponding heterogeneous data source based on the account, the following steps are included:

[0092] S402, based on the account, obtaining historical data associated with the user from corresponding heterogeneous data sources.

[0093] Optionally, according to the definition of each behavior sequence, required historical data is filtered out from the heterogeneous data of each heterogeneous data source.

[0094] S404: Determine the threshold corresponding to each behavior sequence included based on the historical data.

[0095] In one embodiment, Figure 5As shown, the above step S404 includes the following steps:

[0096] S502: Divide the second historical time into T segments.

[0097] The historical data is data of each behavior sequence within the second historical time, and the time span of the second historical time can be selected as needed.

[0098] Optionally, the data of each behavior sequence within the second historical time period is divided into T time intervals, where the principle of dividing the time intervals is: select a suitable interval time according to the frequency of occurrence of the specific behavior. For example, for a brute force cracking behavior sequence, a shorter time interval such as 10 minutes or 30 minutes can be selected; for a log volume trend behavior sequence, a longer time interval such as 6 hours or 1 day can be selected.

[0099] S504, counting the frequency W of the behaviors of each behavior sequence occurring in each interval time.

[0100] S506: Obtain the threshold corresponding to each behavior sequence within a period of T.

[0101] The threshold value includes at least one of the following: average value, maximum value, minimum value, variance and standard deviation. It should be noted that the threshold value corresponding to each behavior sequence is dynamically updated.

[0102] In the above Figure 4 , Figure 5 In the steps of the illustrated embodiment, by obtaining the historical data of each behavior sequence of the account and the second historical time, and dividing the second historical time according to the definition of each behavior sequence, the frequency of occurrence of the behavior of each behavior sequence in each time interval is counted, and the threshold of each behavior sequence is calculated to obtain different benchmarks for different behavior sequences, thereby improving the accuracy of detection.

[0103] In one embodiment, based on each of the sequence information and the threshold corresponding to each of the behavior sequences, determining whether the user is abnormal includes:

[0104] Different weights are set for each behavior sequence. Different weight values ​​are set from high to low according to the degree of attention or importance of each behavior sequence, and the larger the weight, the greater the threat level.

[0105] Based on the weight, the degree of deviation of the sequence information from the threshold corresponding to each behavior sequence is measured to obtain the abnormal score of each behavior sequence.

[0106] Sum the anomaly scores of each user's behavior sequence to obtain the user's comprehensive anomaly score and determine whether the user is abnormal.

[0107] Optionally, after summing up the abnormality scores of each behavior sequence of the user to obtain the comprehensive abnormality score of the user, the method further includes sorting the users from high to low based on the comprehensive abnormality score and marking the top-ranked users as abnormal users.

[0108] Optionally, manually check the abnormal users marked as abnormal to confirm whether the abnormal users are abnormal.

[0109] In the above embodiment, different weights are set for each behavior sequence, and anomaly scores of the degree of deviation between sequence information and corresponding thresholds are calculated based on the weights. The anomaly scores of each behavior sequence of the user are summed to obtain a comprehensive anomaly score for the user. Finally, the comprehensive anomaly scores are sorted, and the top-ranked users are marked as abnormal users, thereby further improving the accuracy of abnormal user detection. In addition, the false alarm rate of abnormal users is reduced by manually troubleshooting the marked abnormal users and performing secondary detection of the abnormal results.

[0110] In an example embodiment, if Figure 6 As shown, the following steps are included:

[0111] S601, collecting heterogeneous data from various heterogeneous data sources of the accounts that need to be monitored in real time.

[0112] Among them, heterogeneous data sources include OA logs, AD domain logs, bastion host logs, email logs, host logs, and web browsing logs. Collect the log content of each heterogeneous data source, that is, heterogeneous data.

[0113] Parse heterogeneous data to obtain field information under different operations. Different operations include: logging in to OA, downloading files, accessing servers, and sending emails. Field information includes: start time, source user name, destination user name, source IP, source port, destination IP, destination port, transmission protocol, request URL, return result, operation, and operation result.

[0114] S602, based on the account automatic association algorithm, the heterogeneous data from various heterogeneous data sources are aggregated to the same user.

[0115] According to various heterogeneous data sources, extract the information pairs of <source user name, source IP> in the past three months from the field information. Divide the three-month time interval into N, where the principle of dividing the time interval is: if the allocation of internal IP addresses is adjusted quickly and dynamically, such as changing the IP once for each login verification or changing the IP once a day, then a shorter time interval is required, such as 6 hours or one day; if the allocation of internal IP addresses is relatively fixed, such as changing the IP once a week or a fixed IP, then the time interval needs to be longer, such as three days or seven days.

[0116] After dividing the time intervals, obtain the number of times Q that the heterogeneous data source accounts corresponding to the same IP appear in each time period, and then exclude the <source user name, source IP> information pairs that appear too few times in each interval, for example, only appearing once; exclude the records corresponding to public IPs. The way to identify public IPs is that if a certain IP has many corresponding source account names in multiple intervals and they are almost the same as the number of internal accounts, then the IP is identified as a public IP and does not participate in subsequent operations.

[0117] After eliminating the above influences, count the number of times heterogeneous data source accounts appear simultaneously in different time periods M. Determine whether the ratio of the number of times heterogeneous data source accounts appear simultaneously M to N is greater than the set first threshold. If so, the heterogeneous data source accounts can be grouped together with the user.

[0118] The first threshold is set to 80% here, and the first threshold can be set according to the platform detection requirements.

[0119] If the remaining accounts cannot be associated according to the above rules, the following processing methods can be adopted: extract more historical data of the relevant accounts for the above processing;

[0120] If the above solution is ineffective, the remaining accounts may be caused by personal access behavior, such as only accessing certain data sources and using only data from some data sources to participate in subsequent abnormal behavior discovery and scoring.

[0121] S603, customizing the behavior sequence and setting the weight.

[0122] For the scenario of internal user threats, you can customize the behavior sequence characteristics of user attention behaviors or key behavior sequences. And assign different weights to the behavior sequences according to their attention or importance. The weights range from 1 to 10, and are divided into 10 different levels. The larger the weight, the greater the threat level.

[0123] S604: Calculate corresponding thresholds for each behavior sequence.

[0124] For each behavior sequence, filter out the historical data of the past three months according to the definition of the behavior sequence; divide the time interval of the historical data of three months into T segments; select a suitable interval time according to the frequency of occurrence of specific behaviors, for example, for brute force cracking behavior sequences, you can choose a shorter time such as 10 minutes, 30 minutes, etc.; for log volume trends, you can choose a longer time such as 6 hours, 1 day, etc.; count the frequency W of occurrence of the behaviors of each behavior sequence in each interval time; obtain the threshold value corresponding to each behavior sequence within the T period, where the threshold value includes at least one of the following: mean value, maximum value, minimum value, variance and standard deviation.

[0125] It should be emphasized that the threshold corresponding to each behavior sequence is dynamically updated, and the historical data of the past three months is for the current time.

[0126] S605, based on the account, obtaining the to-be-detected data associated with the user from the corresponding heterogeneous data source.

[0127] Obtain the data to be detected from each user's account in each heterogeneous data source, classify them according to the definition of each behavior sequence, and parse the data to be detected for each behavior sequence.

[0128] S606: Determine sequence information of each behavior sequence included based on the data to be detected.

[0129] After parsing the data to be detected of each behavior sequence, sequence information of the data to be detected of each behavior sequence is extracted therefrom.

[0130] S607, performing anomaly scoring on each heterogeneous data source account according to the threshold to determine the abnormal situation of the user.

[0131] The degree of abnormality of each sequence information and the threshold of the corresponding behavior sequence deviating from the baseline is measured. The algorithms including K nearest neighbor, 3sigma criterion and box plot method are used, and the abnormality score of each behavior sequence of the data to be detected is obtained by combining the weights. The abnormality scores of each behavior sequence of each user are summed to obtain the comprehensive abnormality score of each user. Each user is sorted from high to low according to the comprehensive abnormality score, and the top three users are manually checked to confirm whether there are abnormalities.

[0132] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0133] Based on the same inventive concept, the embodiment of the present application also provides an abnormal user detection device for implementing the abnormal user detection method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more abnormal user detection device embodiments provided below can refer to the limitations on the abnormal user detection method above, and will not be repeated here.

[0134] In one embodiment, Figure 7 As shown, an abnormal user detection device is provided, including: a determination module 72, an acquisition module 74 and a judgment module 76, wherein:

[0135] A determination module 72, used to determine the heterogeneous data source associated with the account;

[0136] The acquisition module 74 is used to acquire the data to be detected associated with the user from the corresponding heterogeneous data source based on the account; and determine the sequence information of each behavior sequence contained in the data to be detected based on the data to be detected;

[0137] The judgment module 76 is used to determine whether the user is abnormal based on each sequence information and the threshold value corresponding to each behavior sequence.

[0138] In one embodiment, the determining module includes:

[0139] Collect heterogeneous data from the heterogeneous data sources; parse the heterogeneous data to obtain field information; the field information includes account information of corresponding accounts; based on the field information, determine whether the accounts belong to the same user.

[0140] In one embodiment, the determining module further includes:

[0141] Acquire the field information within a first historical time; the field information includes an information pair of a source user name and a source IP; divide the first historical time into N segments; acquire the number of times Q that the heterogeneous data source account corresponding to the same IP appears within each time period; based on the number Q, count the number of times M that the heterogeneous data source account appears simultaneously within different time periods; determine whether the ratio of the number of times M that the heterogeneous data source account appears simultaneously to the N segments is greater than a set first threshold; if so, the accounts belong to the same user.

[0142] In one embodiment, the acquisition module includes:

[0143] Based on the different behaviors of following the account, the behavior sequences of the account are customized; the behavior sequences include a single data source behavior sequence and a multi-data source combined behavior sequence.

[0144] In one embodiment, the acquisition module further includes:

[0145] Based on the account, historical data associated with the user is obtained from a corresponding heterogeneous data source; based on the historical data, a threshold corresponding to each behavior sequence included is determined.

[0146] In one embodiment, the acquisition module further includes:

[0147] The historical data is the data of each behavior sequence within the second historical time; the second historical time is divided into T segments; the frequency W of occurrence of the behavior of each behavior sequence in each interval is counted; the threshold corresponding to each behavior sequence within the T segment is obtained; the threshold includes at least one of the following: mean value, maximum value, minimum value, variance and standard deviation.

[0148] In one embodiment, the determination module includes:

[0149] Different weights are set for the behavior sequences; based on the weights, the deviation degree of the sequence information from the threshold corresponding to the behavior sequences is measured to obtain the abnormality score of each behavior sequence; the abnormality scores of the behavior sequences of the user are summed to obtain the comprehensive abnormality score of the user, and determine whether the user is abnormal.

[0150] In one embodiment, the determination module further includes:

[0151] Based on the comprehensive anomaly score, the users are sorted from high to low, and the users with the highest ranking are marked as abnormal users.

[0152] Each module in the abnormal user detection device can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module.

[0153] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the following steps:

[0154] Step A: Determine the heterogeneous data sources associated with the account;

[0155] Step B: Based on the account, obtaining the to-be-detected data associated with the user from the corresponding heterogeneous data source;

[0156] Step C: determining the sequence information of each behavior sequence contained therein based on the data to be detected;

[0157] Step D: Determine whether the user is abnormal based on the sequence information and the threshold corresponding to each behavior sequence.

[0158] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0159] Collect heterogeneous data from the heterogeneous data sources; parse the heterogeneous data to obtain field information; the field information includes account information of corresponding accounts; based on the field information, determine whether the accounts belong to the same user.

[0160] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0161] Acquire the field information within a first historical time; the field information includes an information pair of a source user name and a source IP; divide the first historical time into N segments; acquire the number of times Q that the heterogeneous data source account corresponding to the same IP appears within each time period; based on the number Q, count the number of times M that the heterogeneous data source account appears simultaneously within different time periods; determine whether the ratio of the number of times M that the heterogeneous data source account appears simultaneously to the N segments is greater than a set first threshold; if so, the accounts belong to the same user.

[0162] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0163] Based on the different behaviors of following the account, the behavior sequences of the account are customized; the behavior sequences include a single data source behavior sequence and a multi-data source combined behavior sequence.

[0164] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0165] Based on the account, historical data associated with the user is obtained from a corresponding heterogeneous data source; based on the historical data, a threshold corresponding to each behavior sequence included is determined.

[0166] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0167] The historical data is the data of each behavior sequence within the second historical time; the second historical time is divided into T segments; the frequency W of occurrence of the behavior of each behavior sequence in each interval is counted; the threshold corresponding to each behavior sequence within the T segment is obtained; the threshold includes at least one of the following: mean value, maximum value, minimum value, variance and standard deviation.

[0168] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0169] Different weights are set for the behavior sequences; based on the weights, the deviation degree of the sequence information from the threshold corresponding to the behavior sequences is measured to obtain the abnormality score of each behavior sequence; the abnormality scores of the behavior sequences of the user are summed to obtain the comprehensive abnormality score of the user, and determine whether the user is abnormal.

[0170] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:

[0171] Based on the comprehensive anomaly score, the users are sorted from high to low, and the users with the highest ranking are marked as abnormal users.

[0172] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0173] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0174] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0175] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for detecting abnormal users, characterized in that: The method comprises: Determine the heterogeneous data sources associated with the account; Based on the account, obtaining the data to be detected associated with the user from the corresponding heterogeneous data source; the data to be detected is all new behaviors under each heterogeneous data source account; Based on the data to be detected, determining sequence information of each behavior sequence included; Determining whether the user is abnormal based on each of the sequence information and a threshold corresponding to each behavior sequence; The step of determining the heterogeneous data source associated with the account includes: Collecting heterogeneous data from the heterogeneous data sources; Parsing the heterogeneous data to obtain field information; the field information includes account information of the corresponding account; Based on the field information, determine whether the accounts belong to the same user.

2. The abnormal user detection method according to claim 1, characterized in that: The determining, based on the field information, whether the accounts belong to the same user comprises: Acquire the field information in the first historical time; the field information includes an information pair of a source user name and a source IP; Divide the first historical time into N segments; obtain the number of times Q that the heterogeneous data source account corresponding to the same IP appears in each segment; Based on the number Q, count the number M of simultaneous appearances of the heterogeneous data source accounts in different time periods; Determine whether the ratio of the number of times M that the heterogeneous data source accounts appear simultaneously to the N segments is greater than a set first threshold; If it is greater, then the accounts belong to the same user.

3. The abnormal user detection method according to claim 1, characterized in that: The determining, based on each of the to-be-detected data, the sequence information of each behavior sequence respectively included comprises: Customize the behavior sequences of the account based on the different behaviors of following the account; The behavior sequences include a single data source behavior sequence and a multi-data source combined behavior sequence.

4. The abnormal user detection method according to claim 1, characterized in that: The method of obtaining the to-be-detected data associated with the user from the corresponding heterogeneous data source based on the account number includes: Based on the account, acquiring historical data associated with the user from corresponding heterogeneous data sources; Based on the historical data, a threshold corresponding to each behavior sequence included is determined.

5. The abnormal user detection method according to claim 4, characterized in that: The determining, based on the historical data, the thresholds corresponding to the included behavior sequences includes: The historical data is data of each behavior sequence within the second historical time; Dividing the second historical time into T segments; Count the frequency W of the behaviors of each behavior sequence occurring in each interval; A threshold corresponding to each behavior sequence within a period of T is obtained; the threshold includes at least one of the following: an average value, a maximum value, a minimum value, a variance, and a standard deviation.

6. The abnormal user detection method according to claim 1, characterized in that: The determining whether the user is abnormal based on each of the sequence information and the threshold corresponding to each of the behavior sequences includes: Setting different weights for each behavior sequence; Based on the weight, measuring the degree of deviation of the sequence information from the threshold corresponding to each behavior sequence to obtain an abnormality score for each behavior sequence; The abnormal scores of the various behavior sequences of the user are summed to obtain a comprehensive abnormal score of the user, and determine whether the user is abnormal.

7. The abnormal user detection method according to claim 6, characterized in that: After summing up the abnormal scores of the behavior sequences of the user to obtain the comprehensive abnormal score of the user, the method further includes: Based on the comprehensive anomaly score, the users are sorted from high to low, and the users with the highest ranking are marked as abnormal users.

8. An abnormal user detection device, characterized in that: The device comprises: A determination module is used to determine the heterogeneous data sources associated with the account; An acquisition module is used to acquire the data to be detected associated with the user from the corresponding heterogeneous data source based on the account; based on the data to be detected, determine the sequence information of each behavior sequence contained therein; the data to be detected is all new behaviors under each heterogeneous data source account; A judgment module, used for determining whether the user is abnormal based on the sequence information and the threshold value corresponding to each behavior sequence; The determination module includes: collecting heterogeneous data from the heterogeneous data sources; parsing the heterogeneous data to obtain field information; the field information includes account information of the corresponding account; based on the field information, determining whether the account belongs to the same user.

9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • User behavior anomaly detection method and device

    CN111291015A

  • User account loss detection method and device, electronic equipment and storage medium

    CN115146263A