Abnormal access behavior detection method and device, electronic device and readable storage medium
By predicting and risk-level assessment of resource-sensitive traffic of the database, data leakage problems caused by the lack of effective security monitoring methods in the prior art are solved, and higher detection accuracy and security are achieved.
Patent Information
- Application Number
- CN202211316382.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-10-26
AI Technical Summary
The lack of effective security monitoring means for access behavior in the prior art, resulting in unsafe risks such as data leakage in the database.
By obtaining resource-sensitive traffic in the target subject, predicting resource-sensitive traffic based on the pre-trained risk detection model, determining the risk factor corresponding to abnormal access behavior, and determining the abnormal risk level based on the risk factor and business scenarios, thereby performing corresponding early warning and access restrictions.
It improves the accuracy of abnormal access behavior detection of resource-sensitive traffic, reduces the risk of sensitive data leakage, and solves the problem of unsafe risks such as data leakage in databases.
Smart Images

Figure CN115913652B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and in particular, to a method and device for detecting abnormal access behavior, an electronic device, and a readable storage medium. Background Art
[0002] Currently, there are a large number of sensitive data in enterprise network domain databases, and they are scattered. Data gradually flows across applications and networks, and traditional boundaries are gradually blurred, resulting in an increasing exposure surface of data security risks. If an enterprise does not have the ability to monitor and analyze the flow of sensitive data, it will lead to the leakage of the enterprise's sensitive data, affect the business continuity of the enterprise, and a series of problems that need to be solved urgently will emerge, such as the lack of dynamic sorting of data resources, incomplete scope of dynamic security monitoring of data, data leakage, and risk behaviors occurring from time to time.
[0003] In the prior art, there is a lack of active and effective traceability tracking and flow mapping analysis capabilities and means. Summary of the Invention
[0004] Embodiments of the present invention provide a method and device for detecting abnormal access behavior, an electronic device, and a readable storage medium, so as to solve the problem in the related art that there is a lack of effective security monitoring means for access behavior, resulting in unsafe risks such as data leakage in the database.
[0005] To solve the above technical problems, the present invention is implemented as follows:
[0006] In a first aspect, embodiments of the present invention provide a method for detecting abnormal access behavior, the method including: obtaining resource-sensitive traffic in a target entity; predicting the resource-sensitive traffic based on a risk detection model to determine a risk factor corresponding to an abnormal access behavior in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factor is the risk factor with the smallest granularity; determining a risk scenario and an abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the business scenario corresponding to the risk factor.
[0007] Further, the obtaining resource-sensitive traffic in the target entity includes: filtering the access traffic in the target entity according to resource information and sensitive data in the target entity to obtain the resource-sensitive traffic.
[0008] Further, before predicting the resource-sensitive traffic based on the risk detection model to determine the risk factor corresponding to the abnormal access behavior in the resource-sensitive traffic, it further includes: training a local factor algorithm according to historical traffic data in the target entity to obtain the risk detection model.
[0009] Further, after determining the risk scenario and the abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the business scenario corresponding to the risk factor, the following steps are also included: If the risk scenario is a non-business risk scenario, no warning is issued; if the risk scenario is a business risk scenario and the risk level is a low risk level, restricted access is imposed on the access subject of the abnormal access behavior; if the risk scenario is a business risk scenario and the risk level is a high risk level, a risk event warning is issued and restricted access is imposed on the access subject.
[0010] Further, determining the risk scenario and the abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the business scenario corresponding to the risk factor includes: performing baseline mapping on the risk scenario according to a baseline model to determine the abnormal risk level, where the baseline model is trained from the baseline values of historical risk scenarios in the target subject.
[0011] In a second aspect, an embodiment of the present invention further provides an abnormal access behavior detection device, which includes: an acquisition module for acquiring resource-sensitive traffic in a target subject; a prediction module for predicting the resource-sensitive traffic based on a risk detection model to determine a risk factor corresponding to an abnormal access behavior in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target subject, and the risk factor is the risk factor with the smallest granularity; a determination module for determining the risk scenario and the abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the business scenario corresponding to the risk factor.
[0012] Further, the acquisition module includes: a filtering unit for filtering the access traffic in the target subject according to the resource information and sensitive data in the target subject to obtain the resource-sensitive traffic.
[0013] Further, it also includes: a training module for training a local factor algorithm according to historical traffic data in the target subject to obtain the risk detection model before predicting the resource-sensitive traffic based on the risk detection model to determine the risk factor corresponding to the abnormal access behavior in the resource-sensitive traffic.
[0014] Further, it further includes an alarm module, which, after determining the risk scenario and the abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the service scenario corresponding to the risk factor, is further configured to: if the risk scenario is a non-service risk scenario, no warning is given; if the risk scenario is a service risk scenario and the risk level is a low risk level, restricted access is performed on the access subject of the abnormal access behavior; if the risk scenario is a service risk scenario and the risk level is a high risk level, a risk event warning is given and restricted access is performed on the access subject.
[0015] Further, the determining module includes: a determining unit, configured to perform baseline mapping on the risk scenario according to a baseline model to determine the abnormal risk level, where the baseline model is trained from the baseline values of historical risk scenarios in the target subject.
[0016] In a third aspect, an embodiment of the present invention further provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the computer program, when executed by the processor, implements the steps of the abnormal access behavior detection method as described in the first aspect above.
[0017] In a fourth aspect, an embodiment of the present invention further provides a readable storage medium, on which a computer program is stored, where the computer program, when executed by a processor, implements the steps of the abnormal access behavior detection method as described in the first aspect above.
[0018] In the embodiment of the present invention, resource-sensitive traffic in a target subject is obtained; the resource-sensitive traffic is predicted based on a risk detection model to determine risk factors corresponding to abnormal access behaviors in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target subject, and the risk factor is the risk factor at the smallest granularity; according to the risk factor and the service scenario in which the abnormal access behavior occurs, the abnormal risk level corresponding to the abnormal access behavior is determined. By predicting the resource-sensitive traffic through the risk detection model, the abnormal access behaviors and corresponding risk factors in the resource-sensitive traffic are determined, and then based on the risk factors and the service scenarios of the abnormal access behaviors, the abnormal risk levels corresponding to the abnormal access behaviors are determined, improving the detection accuracy of the abnormal access behaviors of the resource-sensitive traffic and reducing the risk of sensitive data leakage. The present invention solves the problem in the related art that there is a lack of effective security monitoring means for access behaviors, resulting in insecure risks such as data leakage in the database.
[0019] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are specifically exemplified below. Brief Description of the Drawings
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.
[0021] Figure 1 It is a schematic diagram of an application scenario of an abnormal access behavior detection method in an embodiment of the present invention;
[0022] Figure 2 It is a schematic diagram of a quantile point in a two-dimensional plane coordinate in an embodiment of the present invention;
[0023] Figure 3 It is a schematic diagram of an outlier in a two-dimensional plane coordinate in an embodiment of the present invention;
[0024] Figure 4 It is a schematic diagram of an abnormal factor algorithm in an embodiment of the present invention;
[0025] Figure 5 It is a schematic diagram of another abnormal factor algorithm in an embodiment of the present invention;
[0026] Figure 6 It is a schematic diagram of the structure of an abnormal access behavior detection device in an embodiment of the present invention. Detailed Embodiments
[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0028] Embodiment 1
[0029] According to an embodiment of the present invention, an abnormal access behavior detection method is provided, as Figure 1 shown, the method may specifically include the following steps:
[0030] S102, obtaining resource-sensitive traffic in a target entity;
[0031] S104, Predict resource-sensitive traffic based on a risk detection model to determine risk factors corresponding to abnormal access behaviors in the resource-sensitive traffic. The risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factors are risk factors at the smallest granularity;
[0032] S106, Determine the risk scenario and abnormal risk level corresponding to the abnormal access behavior according to the risk factors and the business scenarios corresponding to the risk factors.
[0033] In this embodiment, the target entity includes sensitive data of business resources. The access behavior for the sensitive data of business resources in the target entity is resource-sensitive traffic. Since the data accessed by the resource-sensitive traffic is relatively important data in the target entity, it is necessary to identify abnormal access behaviors in the resource-sensitive traffic.
[0034] The target entity in this embodiment includes, but is not limited to, entities such as databases, servers, and terminals.
[0035] Specifically, in this embodiment, sensitive data in the access traffic is identified according to preset rules. The preset rules include, but are not limited to, source IP address, access IP address, access time period, and access port limitation rules of the access traffic.
[0036] In this embodiment, the access time period, access frequency, access address, access data volume, port, and other parameters of the resource-sensitive traffic in the target entity are used to judge abnormal access behaviors and risk factors respectively.
[0037] The risk factors in this embodiment are risk factors at the smallest granularity. Essentially, the risk factors are composed of the smallest granularity of risk rules or risk conditions. For example, a single access frequency, access time, IP address of the access entity, etc. In this embodiment, the access traffic including risk factors is all abnormal access behaviors.
[0038] In this embodiment, the risk factors of the resource-sensitive traffic are identified to quickly identify various risk factors such as access at illegal times, access at illegal locations, excessive access involving sensitive information, and excessive access involving sensitive information in terms of quantity.
[0039] In actual application scenarios, since the risk factors are essentially composed of the smallest granularity of risk rules or risk conditions, the hit of a single risk factor cannot confirm the risk scenario corresponding to this abnormal access behavior and the abnormal risk level of the risk scenario.
[0040] The risk scenarios in this embodiment include the risk factors in abnormal access behaviors and the business scenarios corresponding to the risk factors. For example, the risk scenarios include combinations of multiple risk factors, and the risk scenarios corresponding to the abnormal access behaviors are determined based on the types and quantities of the risk factors in the abnormal access behaviors.
[0041] In this embodiment, one or more abnormal factors corresponding to the abnormal access behavior are obtained, and each abnormal factor corresponds to a business scenario; the risk scenario corresponding to the abnormal access behavior is determined according to the business scenarios corresponding to the one or more abnormal factors respectively. Then, the abnormal risk level corresponding to the risk scenario is determined.
[0042] In actual application scenarios, the identification and monitoring of risk scenarios. Risk scenarios are often complex, composed of multiple risk factors, and have a higher magnitude in terms of the probability of an accident and the severity of the harm. Therefore, active warnings will be triggered, and at the same time, forced supervision and isolation will be carried out on the triggered subjects. For example, "excessive and frequent access to sensitive data by an application account at illegal times" includes three risk factors: access at illegal times, excessive frequency, and excessive access.
[0043] It should be noted that through this embodiment, in the embodiment of the present invention, the resource-sensitive traffic in the target subject is obtained; the resource-sensitive traffic is predicted based on the risk detection model to determine the risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic, where the risk detection model is pre-trained according to the historical access behaviors in the target subject, and the risk factor is the risk factor at the smallest granularity; according to the risk factor and the business scenario where the abnormal access behavior is located, the abnormal risk level corresponding to the abnormal access behavior is determined. By predicting the resource-sensitive traffic through the risk detection model, the abnormal access behaviors and the corresponding risk factors in the resource-sensitive traffic are determined, and then based on the risk factors of the abnormal access behaviors and the business scenarios where they are located, the abnormal risk level corresponding to the abnormal access behavior is determined, improving the detection accuracy of the abnormal access behaviors of the resource-sensitive traffic and reducing the risk of sensitive data leakage. The present invention solves the problem in the related art that there is a lack of effective security monitoring means for access behaviors, resulting in unsafe risks such as data leakage in the database.
[0044] Optionally, in this embodiment, obtaining the resource-sensitive traffic in the target subject includes, but is not limited to: filtering the access traffic in the target subject according to the resource information and sensitive data in the target subject to obtain the resource-sensitive traffic.
[0045] Before the process of identifying abnormal access behaviors in the access traffic of the target subject, it is first necessary to identify the resource-sensitive traffic in the target subject.
[0046] Specifically, for the access traffic in the target entity, traffic filtering is performed. First, invalid traffic, resource-insensitive traffic, and resource-sensitive traffic are hierarchically processed. The invalid traffic such as impurity traffic and the traffic for calls between services of the server corresponding to the target entity is filtered, and the resource-sensitive traffic required for the service is retained.
[0047] Specifically, the business resources in the target entity are identified. According to the business information in the target entity, with the business resources as the unit carrier, sensitive data discovery is actively performed on the business resource data. For example, the resource information includes but is not limited to the specified IP address, specified port, etc. in the target entity.
[0048] Then, according to the preset rules, it is determined that the data of the access traffic to the business resources is sensitive data, and the access traffic corresponding to the sensitive data is resource-sensitive traffic.
[0049] Through the above example, according to the resource information and sensitive data in the target entity, the access traffic in the target entity is filtered to obtain the resource-sensitive traffic, realizing the filtering of the invalid traffic in the target entity.
[0050] Optionally, in this embodiment, before predicting the resource-sensitive traffic based on the risk detection model to determine the risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic, it further includes but is not limited to: training the local factor algorithm according to the historical traffic data in the target entity to obtain the risk detection model.
[0051] In this embodiment, the resource-sensitive traffic is predicted based on the risk detection model to determine the abnormal access behaviors in the resource-sensitive traffic and the risk factors corresponding to the abnormal access behaviors.
[0052] In one example, the abnormal behavior detection model in this embodiment includes the local outlier factor detection algorithm, and there are different implementation methods for different data forms. Commonly used are the detection models based on distribution, such as Figure 2 As shown, the values outside the upper and lower α quantiles are considered outliers, and this method is commonly used for attribute values. The detection model based on distance is applicable to the discrimination of outliers in a two-dimensional or high-dimensional coordinate system. For example, for the identification of outliers in a two-dimensional plane coordinate or longitude and latitude space coordinate, this method can be used.
[0053] For example Figure 3 As shown, for the points in the C1 set, the overall spacing, density, and dispersion are relatively uniform and consistent, and they can be considered as the same cluster; for the points in the C2 set, the same can be considered as a cluster. The points o1 and o2 are relatively isolated and can be considered as outliers or discrete points.
[0054] The following introduces the related definitions of the local outlier factor algorithm:
[0055] d(p,o): The distance between two points p and o;
[0056] The k-distance d k (p) of point p is defined as follows:
[0057] d k (p) = d(p,o)
[0058] And it satisfies: There are at least κ points o' ∈ C\{χ≠p} in the set, excluding p, such that d(p,o') ≤ d(p,o); There are at most κ - 1 points o' ∈ C\{χ≠p} in the set, excluding p, such that d(p,o') < d(p,o);
[0059] The k-distance of p, that is, the distance of the k-th farthest point from p, excluding p, as Figure 4 described.
[0060] The k-distance neighborhood of point p, N k (p), is all the points within the k-distance of p, including the k-distance.
[0061] Therefore, the number of k-neighborhood points of p, |N k (p)| ≥ k.
[0062] The reach-distance from point o to point p is defined as:
[0063] reach-distance k (p,o) = max{k-distance(o), d(p,o)}
[0064] That is, the reach-distance from point o to point p is at least the k-distance of o, or the actual distance between o and p.
[0065] This also means that for the k closest points to point o, the reach-distances from o to them are considered equal and all equal to d k (o).
[0066] As Figure 5 shown, the 5-reach-distance from o1 to p is d(p,o1), and the 5-reach-distance from o2 to p is d5(o2).
[0067] The local reachability density of point p is expressed as:
[0068]
[0069] It represents the reciprocal of the average reachability distance from the points within the k - th neighborhood of point p to p.
[0070] Specifically, for the neighborhood points N k (p) of p, the reachability distance to p represents a density. The higher the density, the more likely it belongs to the same cluster; the lower the density, the more likely it is an outlier. If p and its surrounding neighborhood points are in the same cluster, then the reachability distance is more likely to be a relatively small d k (o), resulting in a smaller sum of reachability distances and a higher density value; if p is far from its surrounding neighbor points, then the reachability distances are likely to all take larger values d(o, p), resulting in a smaller density and being more likely to be an outlier.
[0071] The local outlier factor of point p is expressed as:
[0072]
[0073] It represents the average of the ratio of the local reachability density of the neighborhood points N k (p) of point p to the local reachability density of point p.
[0074] If this ratio is closer to 1, it indicates that the density of the neighborhood points of p is similar, and p may belong to the same cluster as the neighborhood; if this ratio is less than 1, it indicates that the density of p is higher than that of its neighborhood points, and p is a dense point; if this ratio is greater than 1, it indicates that the density of p is less than that of its neighborhood points, and p is more likely to be an outlier.
[0075] The core idea of the local factor algorithm in this embodiment is mainly to determine whether a point is an outlier by comparing the density of each point p and its neighborhood points. If the density of point p is lower, it is more likely to be identified as an outlier. Among them, the density is calculated based on the distance between points. The farther the distance between points, the lower the density; the closer the distance, the higher the density.
[0076] It should be noted that in this embodiment, each risk factor corresponds to the model parameters of different risk detection models, and the risk detection models with different model parameters are used to detect the corresponding risk factors. For example, the risk detection model based on the model parameters corresponding to the access time point predicts the access time point of the access traffic and determines whether the access time point of the access traffic is a risk factor.
[0077] Optionally, in this embodiment, after determining the abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the business scenario where the abnormal access behavior is located, it further includes, but is not limited to: if the risk scenario is a non - business risk scenario, no warning is given; if the risk scenario is a business risk scenario and the risk level is a low - risk level, restricted access is imposed on the access subject of the abnormal access behavior; if the risk scenario is a business risk scenario and the risk level is a high - risk level, a risk event warning is given and restricted access is imposed on the access subject.
[0078] Specifically, if the risk scenario corresponding to the abnormal access behavior is a non-business risk scenario, no warning is issued.
[0079] On the other hand, if the risk scenario corresponding to the abnormal access behavior is a business risk scenario and the risk level is a low risk level, restricted access is performed on the access subject of the abnormal access behavior.
[0080] In an actual application scenario, the access subject triggering the risk factor is monitored and isolated. If there is no abnormal access behavior of the access subject within a subsequent preset time period, the isolation is lifted.
[0081] On the other hand, if the risk scenario is a business risk scenario and the risk level is a high risk level, a risk event warning is issued and restricted access is performed on the access subject.
[0082] Specifically, the access subject triggering the risk factor is monitored and isolated, and the access subject is restricted from accessing the sensitive resource data in the target subject. And a risk event warning is issued in the form of an email, text message, or application notification. The warning content includes, but is not limited to, the risk factor content of the abnormal access behavior, such as "excessive and frequent access to sensitive data by the application account at illegal times".
[0083] Optionally, in this embodiment, according to the risk factor and the business scenario corresponding to the risk factor, the risk scenario and the abnormal risk level corresponding to the abnormal access behavior are determined, including but not limited to: performing baseline mapping on the risk scenario according to the baseline model to determine the abnormal risk level, where the baseline model is trained from the baseline values of the historical risk scenarios in the target subject.
[0084] Specifically, in an actual application scenario, some risk scenarios are necessary accesses to the sensitive resources in the target subject according to actual work needs. Therefore, it is necessary to further judge the risk scenarios that meet the actual requirements.
[0085] In this embodiment, through the baseline model, the risk scenario of excessive and frequent access in the target subject is analyzed. The baseline model is an algorithm model used to judge the excessive and frequent access situation in the access traffic, and whether there is an abnormality is judged by comparing the access frequency and the level of the access data volume with the baseline value.
[0086] According to the excessive and frequent access situation in the actual business, the access frequency baseline and the access data volume baseline of the application, interface, account, and database corresponding to the target subject are actively modeled and analyzed, where the baseline model is trained from the baseline values of the access frequency and the historical risk scenarios of the access data volume in the historical records of the target subject.
[0087] Through the embodiments of the present invention, resource-sensitive traffic in a target entity is obtained; the resource-sensitive traffic is predicted based on a risk detection model to determine risk factors corresponding to abnormal access behaviors in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factors are risk factors at the smallest granularity; according to the risk factors and the business scenario in which the abnormal access behavior occurs, the abnormal risk level corresponding to the abnormal access behavior is determined. By predicting the resource-sensitive traffic through the risk detection model, the abnormal access behaviors and corresponding risk factors in the resource-sensitive traffic are determined, and then based on the risk factors of the abnormal access behaviors and the business scenarios, the abnormal risk level corresponding to the abnormal access behavior is determined, improving the detection accuracy of the abnormal access behaviors of the resource-sensitive traffic and reducing the risk of sensitive data leakage. The present invention solves the problem in the related art that there is a lack of effective security monitoring means for access behaviors, resulting in insecure risks such as data leakage in the database.
[0088] Embodiment 2
[0089] A detailed introduction is provided to an abnormal access behavior detection device according to the embodiments of the present invention.
[0090] Referring to Figure 6 , a structural schematic diagram of an abnormal access behavior detection device in the embodiments of the present invention is shown.
[0091] The abnormal access behavior detection device according to the embodiments of the present invention includes: an acquisition module 60, a prediction module 62, and a determination module 64.
[0092] The functions of each module and the interaction relationships between the modules are introduced in detail below.
[0093] The acquisition module 60 is configured to obtain resource-sensitive traffic in a target entity;
[0094] The prediction module 62 is configured to predict the resource-sensitive traffic based on a risk detection model to determine risk factors corresponding to abnormal access behaviors in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factors are risk factors at the smallest granularity;
[0095] The determination module 64 is configured to determine the risk scenario and the abnormal risk level corresponding to the abnormal access behavior according to the risk factors and the business scenario corresponding to the risk factors.
[0096] Optionally, in this embodiment, the acquisition module 60 includes:
[0097] A filtering unit, configured to filter the access traffic in the target entity according to the resource information and sensitive data in the target entity, so as to obtain the resource-sensitive traffic.
[0098] Optionally, in this embodiment, it further includes:
[0099] A training module, configured to train a local factor algorithm according to the historical traffic data in the target entity to obtain the risk detection model before predicting the resource-sensitive traffic based on the risk detection model to determine the risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic.
[0100] Optionally, in this embodiment, it further includes an alarm module, which is further configured to: after determining the risk scenario and the abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the service scenario corresponding to the risk factor
[0101] If the risk scenario is a non-service risk scenario, no early warning is given;
[0102] If the risk scenario is a service risk scenario and the risk level is a low risk level, restrict access to the access entity of the abnormal access behavior;
[0103] If the risk scenario is a service risk scenario and the risk level is a high risk level, give a risk event early warning and restrict access to the access entity.
[0104] Optionally, in this embodiment, the determination module 64 includes:
[0105] A determination unit, configured to perform baseline mapping on the risk scenario according to a baseline model to determine the abnormal risk level, where the baseline model is trained by the baseline values of the historical risk scenarios in the target entity.
[0106] Moreover, in the embodiments of the present invention, resource-sensitive traffic in the target entity is obtained; the resource-sensitive traffic is predicted based on a risk detection model to determine risk factors corresponding to abnormal access behaviors in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factors are risk factors at the smallest granularity; according to the risk factors and the business scenario in which the abnormal access behavior occurs, the abnormal risk level corresponding to the abnormal access behavior is determined. By predicting the resource-sensitive traffic through the risk detection model, the abnormal access behaviors and corresponding risk factors in the resource-sensitive traffic are determined, and then based on the risk factors of the abnormal access behaviors and the business scenarios in which they occur, the abnormal risk level corresponding to the abnormal access behavior is determined, improving the detection accuracy of abnormal access behaviors in resource-sensitive traffic and reducing the risk of sensitive data leakage. The present invention solves the problem in the related art that there is a lack of effective security monitoring means for access behaviors, resulting in insecure risks such as data leakage in the database.
[0107] Embodiment III
[0108] Preferably, an electronic device is further provided in the embodiments of the present invention, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the computer program is executed by the processor, the steps of the abnormal access behavior detection method described above are implemented.
[0109] Optionally, in this embodiment, the memory is configured to store program codes for executing the following steps:
[0110] S1, obtain resource-sensitive traffic in the target entity;
[0111] S2, predict the resource-sensitive traffic based on a risk detection model to determine risk factors corresponding to abnormal access behaviors in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factors are risk factors at the smallest granularity;
[0112] S3, determine the risk scenario and abnormal risk level corresponding to the abnormal access behavior according to the risk factors and the business scenario corresponding to the risk factors.
[0113] Optionally, the specific examples in this embodiment may refer to the examples described in Embodiment 1 above, and will not be elaborated here.
[0114] Embodiment IV
[0115] Embodiments of the present invention also provide a readable storage medium. Optionally, in this embodiment, a program or instruction is stored on the above-mentioned readable storage medium, and when the program or instruction is executed by a processor, the steps of the abnormal access behavior detection method described in Embodiment 1 are implemented.
[0116] Optionally, in this embodiment, the readable storage medium is configured to store program code for performing the following steps:
[0117] S1, obtain resource-sensitive traffic in the target entity;
[0118] S2, predict the resource-sensitive traffic based on a risk detection model to determine a risk factor corresponding to an abnormal access behavior in the resource-sensitive traffic, where the risk detection model is pre-trained according to historical access behaviors in the target entity, and the risk factor is the risk factor with the smallest granularity;
[0119] S3, determine a risk scenario and an abnormal risk level corresponding to the abnormal access behavior according to the risk factor and the business scenario corresponding to the risk factor.
[0120] Optionally, the readable storage medium is also configured to store program code for performing the steps included in the method in Embodiment 1 above, which will not be elaborated herein.
[0121] Optionally, in this embodiment, the above-mentioned readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc that can store program code.
[0122] Optionally, specific examples in this embodiment may refer to the examples described in Embodiment 1 above, which will not be elaborated herein.
[0123] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the element.
[0124] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to enable a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0125] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit and scope protected by the claims of the present invention, and all of them belong to the protection scope of the present invention.
[0126] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the embodiments of the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0127] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.
[0128] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.
[0129] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0130] In addition, in each embodiment of the present invention, each functional unit can be integrated in a processing unit, can also exist physically separately for each unit, or two or more units can be integrated in one unit.
[0131] If the described function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0132] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. An abnormal access behavior detection method, characterized in that, The method includes: Obtaining resource-sensitive traffic in the target entity; Filtering the access traffic in the target entity according to the resource information and sensitive data in the target entity to obtain the resource-sensitive traffic; Performing hierarchical processing on invalid traffic, resource-insensitive traffic, and resource-sensitive traffic; filtering invalid traffic such as impurity traffic and traffic between services of the server corresponding to the target entity, and retaining the resource-sensitive traffic required for the service; Predicting the resource-sensitive traffic based on a risk detection model, and respectively judging abnormal access behaviors and risk factors for parameters such as the access time period, access frequency, access address, access data volume, and port of the resource-sensitive traffic to determine one or more risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic, wherein the risk detection model is pre-trained according to the historical access behaviors in the target entity, and the risk factor is the risk factor with the smallest granularity; each type of risk factor corresponds to the model parameters of different risk detection models, and the risk detection models with different model parameters are used to detect the corresponding risk factors; Determining the risk scenario and abnormal risk level corresponding to the abnormal access behavior according to the type and quantity of the risk factors and the business scenario corresponding to the risk factors; If the risk scenario is a non-business risk scenario, no warning is given; If the risk scenario is a business risk scenario and the risk level is a low risk level, restricting access to the access entity of the abnormal access behavior; If the risk scenario is a business risk scenario and the risk level is a high risk level, giving a risk event warning and restricting access to the access entity.
2. The method according to claim 1, characterized in that, Before predicting the resource-sensitive traffic based on the risk detection model to determine the risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic, it further includes: Training the local factor algorithm according to the historical traffic data in the target entity to obtain the risk detection model.
3. The method according to claim 1, wherein The determining the risk scenario and abnormal risk level corresponding to the abnormal access behavior according to the risk factors and the business scenario corresponding to the risk factors includes: Performing baseline mapping on the risk scenario according to a baseline model to determine the abnormal risk level, wherein the baseline model is trained by the baseline values of the historical risk scenarios in the target entity.
4. An abnormal access behavior detection device, characterized in that, The device includes: An obtaining module, configured to obtain resource-sensitive traffic in the target entity; A filtering unit, configured to filter the access traffic in the target entity according to the resource information and sensitive data in the target entity, perform hierarchical processing on invalid traffic, resource-insensitive traffic, and resource-sensitive traffic; filter invalid traffic such as impurity traffic and traffic between services of the server corresponding to the target entity, and retain the resource-sensitive traffic required for the service; A prediction module, configured to predict the resource-sensitive traffic based on a risk detection model, and determine abnormal access behaviors and risk factors for parameters such as the access time period, access frequency, access address, access data volume, and port of the resource-sensitive traffic, respectively, so as to determine one or more risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic. The risk detection model is pre-trained according to the historical access behaviors in the target entity, and the risk factor is the risk factor with the smallest granularity; each type of risk factor corresponds to model parameters of different risk detection models, and the risk detection models with different model parameters are used to detect the corresponding risk factors; A determination module, configured to determine the risk scenario and abnormal risk level corresponding to the abnormal access behavior according to the type and quantity of the risk factors, and the business scenario corresponding to the risk factors; An alarm module: If the risk scenario is a non-business risk scenario, no early warning is made; If the risk scenario is a business risk scenario and the risk level is a low risk level, restrict access to the access entity of the abnormal access behavior; If the risk scenario is a business risk scenario and the risk level is a high risk level, give a risk event early warning and restrict access to the access entity.
5. The device according to claim 4, characterized in that, It further includes: A training module, configured to train a local factor algorithm according to the historical traffic data in the target entity to obtain the risk detection model before predicting the resource-sensitive traffic based on the risk detection model to determine the risk factors corresponding to the abnormal access behaviors in the resource-sensitive traffic.
6. The device according to claim 4, characterized in that, The determination module includes: A determination unit, configured to perform baseline mapping on the risk scenario according to a baseline model to determine the abnormal risk level, where the baseline model is trained by the baseline values of the historical risk scenarios in the target entity.
7. An electronic device, characterized in that, It includes: A memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the abnormal access behavior detection method according to any one of claims 1 to 3 are implemented.
8. A readable storage medium, characterized in that, A computer program is stored on the readable storage medium. When the computer program is executed by the processor, the steps of the abnormal access behavior detection method according to any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
Method for detecting database risk, server and storage medium
CN107888574A
A data monitoring and early warning method based on a neural network and user access behaviors
CN109861845A
Data security risk prediction method and device, computer equipment and medium
CN114579636A
Scalable risk-based authentication methods and systems
US10432605B1