A method and apparatus for risk assessment of a device

By combining the anomaly level and abnormal value of actions of the equipment in different business scenarios, as well as the number of times the actions are executed and the degree of change, the risk value of the equipment is comprehensively evaluated, which solves the problems of high false alarm rate and poor adaptability in the existing technology and achieves more accurate equipment risk assessment.

CN115913657BActive Publication Date: 2026-02-13NSFOCUS INFORMATION TECHNOLOGY CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211338534.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2026-02-13
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

Existing equipment risk assessment methods suffer from high false alarm rates and poor adaptability, especially when judging abnormal equipment behavior in different business scenarios, they cannot accurately distinguish between normal and abnormal operations.

Method used

By acquiring the equipment's operational data during the evaluation period, we can identify the multiple business scenarios and actions involved. By combining the anomaly level of the business scenarios, the anomaly value of the actions, the number of times the actions were executed, and the degree of change, we can comprehensively assess the risk value of the equipment.

Benefits of technology

It improves the accuracy of equipment risk assessment, reduces the false alarm rate, enhances the adaptability of equipment risk assessment, and can better identify abnormal behavior of equipment in different business scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913657B_ABST
    Figure CN115913657B_ABST
Patent Text Reader

Abstract

The application discloses a risk assessment method and device of equipment, which is used to improve the accuracy and comprehensiveness of the risk assessment of the equipment. The method comprises the following steps: obtaining operation data of the equipment to be evaluated in an evaluation period; determining at least one business scenario related to the equipment according to the operation data, and determining a plurality of actions performed by the equipment in the evaluation period; determining an abnormality level of each business scenario according to each action performed in each business scenario and a change degree of the execution information of each action compared with the execution information of each action in a previous period of the evaluation period; and determining a risk value of the equipment in combination with the abnormality level of the at least one business scenario and preset abnormality values of the plurality of actions.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, and in particular to a device risk assessment method and device. BACKGROUND

[0002] With the continuous improvement of enterprise informatization level, how to protect the network security and data security of enterprise internal becomes particularly important. At present, the internal network security problem or data leakage event is generally related to the abnormal operation behavior of enterprise user device. In order to improve the security protection of enterprise internal network, the related technology proposes to perform risk assessment on enterprise user device, so as to find the abnormal behavior of device in time and avoid the situation of affecting network security such as data leakage. There are two common risk assessment methods as follows:

[0003] The first method is to use a streaming engine to load the data flow of the device in real time, perform feature matching, and judge whether a feature of a field in the data is abnormal or malicious flow, such as judging whether the size of uplink and downlink flow packets or the payload field of flow data contains malicious commands. Although this method is simple to maintain and has good detection performance, the related field features for feature matching are static and will not change according to different network environments or different application scenarios. Therefore, the first risk assessment method has poor adaptability.

[0004] The second method is to use an offline analysis engine to count the features of each dimension of offline data as standard data for evaluation, compare the real-time data of the device with the standard data, and judge whether the device has risks according to the difference. This risk assessment method has good adaptability, but the false positive rate of single dimension anomaly is high. For example, a user device logs into different systems on two adjacent days, which is a normal operation, but the second risk assessment method will evaluate this normal behavior as a risk behavior. Therefore, the false positive rate of the second method is high. SUMMARY

[0005] The present application provides a device risk assessment method and device to solve the problem of high false positive rate and poor adaptability in the existing risk assessment method.

[0006] In a first aspect, the present application provides a device risk assessment method, comprising:

[0007] obtaining running data of a device to be evaluated in an evaluation period;

[0008] determining at least one business scenario related to the device according to the running data, and determining a plurality of actions performed by the device in the evaluation period;

[0009] determine an abnormality level of each business scenario according to the actions performed in the business scenario and a change degree of the action execution information of the actions compared to a previous period of the evaluation period;

[0010] determine a risk value of the device according to the abnormality level of the at least one business scenario and a preset abnormality value of the actions.

[0011] In some embodiments, the determination of the abnormality level of each business scenario according to the actions performed in the business scenario and a change degree of the action execution information of the actions compared to a previous period of the evaluation period comprises:

[0012] classify the actions according to at least one preset statistical condition;

[0013] generate a plurality of labels of the device in the evaluation period according to the action execution information of each type of action;

[0014] determine the labels associated with any business scenario according to the actions performed in the business scenario;

[0015] determine the abnormality level of the any business scenario according to a label value of each label and a weight corresponding to each label in the any business scenario; wherein the label value of any label is used to represent the change degree of the any label.

[0016] In some embodiments, before calculating the risk value of the device, the method further comprises:

[0017] obtain a first number and a second number of each action in the plurality of actions; the first number is a number of times of occurrence of the each action in the evaluation period, and the second number is a number of times of occurrence of the each action in a preset number of periods before the evaluation period;

[0018] In the calculation of the risk value of the device, specifically comprising:

[0019] determine a risk value of each action according to the first number and the second number of the each action, an abnormality value of the each action, and an abnormality level of a business scenario to which the each action belongs;

[0020] calculate the risk value of the device according to the risk values of the plurality of actions respectively.

[0021] In some embodiments, the label value of any label is determined in the following manner:

[0022] determine the change degree of the any label by comparing the any label with a standard label; the standard label is a label corresponding to the any label in a previous period of the evaluation period.

[0023] According to a pre-configured correspondence between a change degree and a label value, a label value of any label is determined.

[0024] In some embodiments, the operation data of the device to be evaluated in the evaluation period is obtained, including:

[0025] The log of the device in the evaluation period is obtained;

[0026] A pre-configured program corresponding to the format of the log is used to extract the operation data from the log.

[0027] In a second aspect, the present application provides a device risk assessment apparatus, comprising:

[0028] An obtaining unit is configured to obtain operation data of a device to be evaluated in an evaluation period;

[0029] A processing unit is configured to perform:

[0030] According to the operation data, at least one business scenario involving the device is determined, and a plurality of actions performed by the device in the evaluation period are determined;

[0031] According to each action performed in each business scenario and a change degree of execution information of the action compared to a previous period of the evaluation period, an abnormality level of each business scenario is determined;

[0032] In combination with the abnormality level of the at least one business scenario and a pre-set abnormality value of the plurality of actions, a risk value of the device is determined.

[0033] In some embodiments, the processing unit is specifically configured to:

[0034] The plurality of actions are classified according to a pre-set at least one statistical condition;

[0035] A plurality of labels of the device in the evaluation period are generated for execution information of each type of action;

[0036] According to each action performed in any business scenario, each label associated with the any business scenario is determined;

[0037] In combination with a label value of each label and a weight corresponding to each label in the any business scenario, respectively, an abnormality level of the any business scenario is determined; wherein the label value of any label is used to represent a change degree of the any label.

[0038] In some embodiments, the obtaining unit is further configured to:

[0039] acquire a first number and a second number of each action in the plurality of actions; the first number is a number of times that the each action occurs in an evaluation period, and the second number is a number of times that the each action occurs in a set number of periods before the evaluation period;

[0040] the processing unit, when calculating the risk value of the device, specifically configured to:

[0041] determine a risk value of each action according to the first number and the second number of the each action, the anomaly value of the each action, and an anomaly level of a business scenario to which the each action belongs;

[0042] calculate the risk value of the device according to the risk values of the plurality of actions respectively.

[0043] In some embodiments, the processing unit is further configured to:

[0044] determine a label value of any label; specifically configured to:

[0045] compare the any label with a standard label to determine a change degree of the any label; the standard label is a label corresponding to the any label in a period before the evaluation period;

[0046] determine the label value of the any label according to a preconfigured corresponding relationship between the change degree and the label value.

[0047] In some embodiments, the acquisition unit is specifically configured to:

[0048] acquire a log of the device in the evaluation period;

[0049] extract running data from the log by using a preconfigured program corresponding to a format of the log.

[0050] In a third aspect, an electronic device is provided, and the electronic device includes a controller and a memory. The memory is configured to store computer-executable instructions, and the controller is configured to execute the computer-executable instructions in the memory to perform the operation steps of the method of any possible implementation of the first aspect by using hardware resources in the controller.

[0051] In a fourth aspect, a computer-readable storage medium is provided, and the computer-readable storage medium stores instructions. When the instructions are executed on a computer, the computer is caused to perform the method of any of the aspects.

[0052] The embodiment of the present application proposes, when a device is risk evaluated, first determining actions performed by the device in multiple business scenarios involved. Then, according to the change degree of the execution information of each action in the current evaluation period and the previous period, the abnormality level of each business scenario is determined. Then, according to the abnormality levels of the multiple business scenarios involved by the device and the abnormality values of the multiple actions, the risk value of the device is determined. The scheme proposed by the present application can not only solve the problem of poor adaptability of the existing static detection scheme, but also solve the problem of high false alarm rate caused by using single dimension to evaluate the risk value of the device in the existing dynamic detection scheme. BRIEF DESCRIPTION OF DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0054] Figure 1 A flow chart of a device risk evaluation method provided by the embodiment of the present application is provided.

[0055] Figure 2 A flow chart of a label generation method provided by the embodiment of the present application is provided.

[0056] Figure 3 A flow chart of another device risk evaluation method provided by the embodiment of the present application is provided.

[0057] Figure 4 A structural schematic diagram of a device risk evaluation apparatus provided by the embodiment of the present application is provided.

[0058] Figure 5 A structural schematic diagram of an electronic device provided by the embodiment of the present application is provided. DETAILED DESCRIPTION

[0059] In order to make the purpose, technical scheme and advantages of the embodiments of the present application more clear, the technical scheme in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application.

[0060] It is to be understood that the terms "first", "second", and the like, used in the description and in the claims, are used as identifiers for distinguished objects and do not necessarily have an ordinal or chronological significance. Data described as being used in a certain order can be interchanged in appropriate circumstances so that the embodiments of the application described herein can be implemented in orders other than those illustrated or described herein. The implementations described in the following example embodiments are not meant to represent all implementations consistent with the present application. Rather, they are simply examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.

[0061] In order to achieve the security protection of the assets within the enterprise, it is particularly important to locate and analyze the abnormal behavior of the user equipment in a timely manner. In the related art, when performing risk assessment on the equipment, the risk value of the equipment is determined according to the degree of change of the action performed by the equipment in the current period compared with the action performed by the equipment in the previous period. The false positive rate of the risk value determined by using the degree of change of a single action is high. For example, due to business requirements, the user equipment logged into system A in the previous hour and logged into system B in the next hour, and the risk value evaluated according to the existing scheme will be large, resulting in false positives.

[0062] In order to solve this problem, the embodiments of the present application propose a device risk assessment method and device, which determines a plurality of business scenarios involved by the equipment in a set time period and actions performed by the equipment in each business scenario according to the operation data of the equipment, respectively calculates the degree of change of each action in different business scenarios, and determines the abnormal level of each business scenario, and finally performs risk assessment on the equipment according to the abnormal level of the business scenario and the preset abnormal values of a plurality of actions. The scheme of the present application no longer uses the change of a single action to perform risk assessment, but combines the two factors of different business scenarios and actions performed by the equipment to jointly determine the risk value of the equipment, reduces the risk false positives, and improves the accuracy of the risk assessment of the equipment.

[0063] The risk assessment method and device provided in the present application are described below. In the embodiments described below, "and / or" describes the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be singular or plural. The singular expressions "one", "a", "an", "said", "the above", "the", and "this" are intended to also include expressions such as "one or more", unless the context clearly indicates otherwise. In addition, unless otherwise stated, the ordinal numbers "first", "second", etc. mentioned in the embodiments of the present application are used to distinguish a plurality of objects, and are not used to limit the order, time sequence, priority or importance of the plurality of objects. For example, the first task execution device and the second task execution device are only used to distinguish different task execution devices, and do not represent the difference in priority or importance of the two task execution devices.

[0064] In the present application, the reference to "one embodiment" or "some embodiments" and the like means that the specific features, structures or characteristics described in connection with the embodiment are included in one or more embodiments of the present application. Therefore, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in other some embodiments" and the like appearing in different places in the specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "include", "contain", "have" and their variants mean "include but are not limited to", unless otherwise specifically emphasized.

[0065] The scheme provided by the present application is described below, see Figure 1 A risk assessment method for a device is provided in the embodiments of the present application. It should be noted that the present application does not limit the execution subject of the device risk assessment method, which can be executed by a terminal device such as a computer or a mobile phone, or by an electronic device with computing function such as a server, a server cluster or a processing chip, or by a cloud computing platform, and the present application does not limit this. Figure 1 The method flow shown specifically includes:

[0066] 101, obtaining running data of a device to be evaluated in an evaluation period.

[0067] Optionally, logs of the device to be evaluated in the evaluation period can be acquired, and running data of the device in the evaluation period can be determined according to the logs.

[0068] 102, according to the running data, at least one business scenario involved by the device is determined, and a plurality of actions performed by the device in the evaluation period are determined.

[0069] For example, the business scenario involved by the device can include a scenario in which the device logs in a system, a scenario in which the device organizes (deletes or moves) data in a storage space, or a scenario in which the device performs a certain business (such as checking the accuracy of document writing) in the system, etc. The actions performed by the device can include the action of logging in the system, the action of logging out of the system, the action of deleting, or the action of viewing, etc.

[0070] 103, according to each action performed in each business scenario, and the degree of change of the execution information of each action compared to the previous period of the evaluation period, the abnormality level of each business scenario is determined.

[0071] In the prior art, a single action abnormality is generally determined by a large degree of change of a single action, and then the device abnormality is determined. However, in many cases, a large degree of change of a single action does not mean that the device operation is abnormal, for example, due to business needs, the device accesses destination A in the previous hour and destination B in the next hour, which should be normal operation, but the existing scheme will judge it as an abnormal action. Moreover, the influence of different actions is different under different business scenarios. For example, in the data migration business scenario, the device needs to access different destination addresses to determine the migration progress, so the change of the accessed destination address in the data migration business scenario is normal and will not cause the abnormality of the business scenario.

[0072] Therefore, the present application proposes to determine the degree of change of the action in combination with different business scenarios. In one possible implementation, the actions performed in any one business scenario can be determined, the execution information of each action in the evaluation period and the previous period is compared, the degree of change of the execution information of each action in the business scenario is determined, and the abnormality level of the business scenario is determined according to the degree of change.

[0073] 104, in combination with the abnormality level of at least one business scenario, and the abnormality values of a plurality of actions preset, a risk value of the device is determined.

[0074] Optionally, different abnormality values can be set for different types of actions. For example, the abnormality value of the access type action can be set to be smaller than the abnormality value of the delete type action.

[0075] Optionally, after determining the abnormal level of at least one service scenario involved by the device, the risk value of the device can be determined jointly based on the abnormal level of the service scenario and the abnormal values of the multiple actions performed by the device, so as to avoid the problem of a large number of false positives caused by the traditional single-dimension abnormality outputting abnormality.

[0076] Based on the above scheme, the embodiment of the present application proposes, when performing risk assessment on a device, first determining actions performed by the device in multiple service scenarios involved by the device. Then, according to the change degree of the execution information of each action in the current evaluation period and the previous period, the abnormal level of each service scenario is determined. Then, according to the abnormal levels of the multiple service scenarios involved by the device and the abnormal values of the multiple actions, the risk value of the device is determined jointly. The scheme proposed by the present application not only can solve the problem of poor adaptability of the existing static detection scheme, but also can solve the problem of high false positive rate caused by the single-dimension evaluation of the risk value of the device in the existing dynamic detection scheme.

[0077] In one or more embodiments, when obtaining the running data of the device, the running data can be obtained according to the log of the device in the evaluation period. Since the logs generated by devices of different manufacturers or different formats are not the same, the embodiment of the present application proposes that different processing programs can be pre-configured for logs of different formats to process the logs to obtain running data in a unified format. Optionally, each type of log format can be connected and processed by a plug-in program, and the processing function library in the program can be continuously accumulated as the log format increases.

[0078] As an example, the running data obtained after processing the log by the corresponding program can be seen as follows:

[0079] content_length(Contents length): 0

[0080] protocol(TCP): TCP

[0081] timestamp(Timestamp): 1656926291000

[0082] log_type(Log type): web access

[0083] sip(Source address): 13.0.0.8

[0084] dip(Destination address): 189.22.106.127

[0085] domain(Domain name): wwww.test_11.com

[0086] sport: 8000

[0087] ret_code (redirect instruction): 200

[0088] method (way): get

[0089] user_agent (agent user): Mozilla / 4.0 (compatible; MSIE 6.0; Windows NT 5.1)

[0090] cookies (small text file): theme = Tabular

[0091] http_protocol (network protocol): 1.0

[0092] payload (payload): LS0 =

[0093] log_type_path (log type path): / normalized log type / network access / web access

[0094] content_type (content type): text / html

[0095] protocol_type (protocol type): http

[0096] log_id (log ID): 4723c941-bdd4-47ff-aed2-8a055ff7aefd

[0097] url (uniform resource locator): http: / / wwww.test_11.com:63047 / api / search?a=1

[0098] uri (universal resource indicator): / api / search?a=1

[0099] session_id (user ID): 5ea0f8f38f073800a708f8f33405673aa51602a0

[0100] dport (destination port): 63047

[0101] referer (link address): http: / / wwww.test_11.com:63047 / api / search

[0102] In some embodiments, after obtaining the running data, at least one business scenario involved by the device in the evaluation period and a plurality of actions performed by the device can be determined according to the running data. For example, according to the running data in the example in the above embodiments, it can be seen that the device performs an access action in the evaluation period. Further, the abnormality level of the business scenario can be determined according to the execution information of the actions performed in each business scenario.

[0103] In a possible scenario, when determining the abnormality level of the business scenario according to the execution information of each action, the execution information of each action in the current evaluation period and the previous period of the evaluation period can be compared to obtain the change degree of the execution information of each action. Then, the abnormality level of the business scenario can be determined according to the change degree of the execution information of each action and the weight of each action in any business scenario.

[0104] For example, it is assumed that two actions are performed in the data migration business scenario, which are action A and action B. Action A is an access action, and the weight of action A in the data migration business scenario is 30%, and the change degree of the execution information of action A compared with the previous period is 50% (assuming that the evaluation period and the previous period are to access different destination addresses from the same source address). Action B is a delete action, and the weight of action B in the data migration business scenario is 60%, and the change degree of the execution information of action B compared with the previous period is 100% (assuming that no delete action occurs in the previous period). Further, according to the above data, the abnormality level of the data migration scenario can be calculated as 75%.

[0105] In another possible scenario, when determining the abnormality level of each business scenario, a plurality of labels of the device in the evaluation period can also be generated according to the execution information of the plurality of actions performed by the device. Optionally, the plurality of actions can be classified according to at least one preset statistical condition, and the plurality of labels of the device in the evaluation period can be generated according to the execution information of each type of action. Further, each label associated with each business scenario can be determined according to the action performed in each business scenario. Optionally, the same label can be associated with different business scenarios. Further, the abnormality level of any business scenario can be determined according to the label value of each label associated with the business scenario and the corresponding weight of each label in the business scenario. The label value of the label is used to represent the change degree of the label relative to the previous period of the evaluation period.

[0106] In some embodiments, when generating a label according to a plurality of actions performed by a device in an evaluation period, a corresponding statistical condition can be determined according to a purpose of the label to be generated first. For example, if the label to be generated is used to represent a login action, the statistical condition can be a login action with a source address being a device address. Further, at least one action conforming to the statistical condition can be determined from the plurality of actions performed by the device according to the statistical condition and the running data. Further, the label can be generated according to the execution information of the action based on the generation logic of the label to be generated. For example, if the generation logic of the label to be generated is to obtain a set of destination addresses, the generated label is a set of destination addresses in the execution information of the action.

[0107] To facilitate understanding of the process of generating a label, specific embodiments will be introduced below. Referring to Figure 2 , a method flowchart for generating a label is provided in the embodiments of the present application. For ease of description, the label to be generated will be referred to as a first label hereinafter. Figure 2 The method flowchart for generating the first label specifically includes:

[0108] 201. Determine a plurality of actions performed by a device according to running data of the device in an evaluation period.

[0109] Optionally, the plurality of actions can include login, logout, deletion, viewing, injecting an alarm, or blasting an alarm, etc. Actions can also be divided according to different attributes, for example, when performing a login action, if the two login actions are performed on different operating systems, they can be distinguished as two actions.

[0110] 202. Determine a statistical condition for screening the plurality of actions according to a purpose of the first label.

[0111] 203. Screen at least one action conforming to the statistical condition from the plurality of actions according to the statistical condition and the running data.

[0112] For example, if the statistical condition is a login action with a source address being a device address, a login action with a source address being a device address can be determined from the login actions included in the plurality of actions.

[0113] 204. Generate the first label in combination with the generation logic of the first label and the execution information of the at least one action screened.

[0114] The generation logic of the first label can include an operation to be performed when generating the first label, and a specific feature of performing the operation. For example, the feature can be a destination address, a source address, or an access time, and the operation can be a set operation, a minimum value operation, a maximum value operation, an average operation, or a sum operation.

[0115] As an example, if the generating logic of the first label includes a feature of destination address, the operation is to find the set of destination addresses, and the filtered at least one action is all login actions, and the login destination addresses are 1.1.1.1, 2.2.2.2 and 3.3.3.3 respectively, then the first label is “1.1.1.1, 2.2.2.2 and 3.3.3.3”.

[0116] As another example, if the generating logic of the first label includes a feature of destination address, the operation is to find the sum of the number of times of destination addresses, and the filtered at least one action is all login actions, and the login destination addresses and the number of times of login are 1.1.1.1-3 times, 2.2.2.2-4 times and 3.3.3.3-5 times respectively, then the first label is “1.1.1.1-3 times, 2.2.2.2-4 times and 3.3.3.3-5 times”.

[0117] As an optional way, after determining the multiple labels of the device in the evaluation period, the label value of the multiple labels can be determined, and the label value is used to represent the degree of change of the label. Optionally, the degree of change of any label can be determined by comparing the any label with a standard label, wherein the standard label is a label corresponding to the any label in a previous period of the evaluation period. Further, the label value of the any label can be determined according to a preconfigured corresponding relationship between the degree of change and the label value.

[0118] Continuing the example in the above Figure 2 , the first label is “1.1.1.1, 2.2.2.2 and 3.3.3.3”, the first label in the previous period of the evaluation period is obtained, and it is assumed that the first label in the previous period is “1.1.1.1 and 2.2.2.2”. It can be seen that the first label in the evaluation period has one more destination address than the first label in the previous period. Therefore, the label value of the first label can be determined according to a preconfigured corresponding relationship between the number of changed labels and the label value. For example, if the number of destination addresses in the first label is one more than that in the previous period, the label value can be set to 1; if the number of destination addresses in the first label is nine more than that in the previous period, the label value can be set to 9. That is, the greater the degree of change of the label, the greater the corresponding label value.

[0119] Optionally, after determining the label values of the multiple labels of the device in the evaluation period, the label value associated with each business scenario involved by the device can be determined. Specifically, the label value associated with each business scenario can be determined according to the actions performed in each business scenario.

[0120] In some embodiments, after determining the label values of the labels associated with any one business scenario, the abnormality level of the business scenario can be calculated according to the weights of the labels in the business scenario and the label values of the labels. Optionally, the same label can be associated with multiple business scenarios, and the weight of the same label can be different in different business scenarios. For example, the weight of label 1 in business scenario A can be 80%, and the weight of label 1 in business scenario B can be 10%.

[0121] In related technologies, when performing risk assessment on a device, the indicators used include accuracy, precision, recall rate, and F-score value, etc. These evaluation indicators are only for the characteristics of a single dimension of the device, and for some specific business scenarios, a single dimension for evaluation is prone to false positives.

[0122] Based on this, the present application proposes that when performing risk assessment on a device, the abnormality value of the action performed by the device, the number of executions of each action in the evaluation period, the number of executions of each action before the evaluation period, and the abnormality level of each business scenario, etc. Factors are used to determine the risk value of the device together. The scheme of the present application not only evaluates the risk of the action in combination with different business scenarios, but also evaluates the risk value of the device from multiple dimensions such as the number of executions and the abnormality value of the action, thereby improving the accuracy of device evaluation.

[0123] As a possible implementation, the number of each action performed by the device in the evaluation period (hereinafter referred to as the first number) and the number of each action performed by the device in a set period before the evaluation period (hereinafter referred to as the second number) can be obtained. Optionally, the risk value of each action can be calculated according to the first number, the second number, the preset abnormality value, and the abnormality level of the business scenario to which each action belongs. Further, the risk value of the device can be calculated according to the risk values of multiple actions.

[0124] As an optional implementation, the abnormality increment value of any one action can be determined first in combination with the first number, the second number, and the abnormality level of the scene to which the action belongs. Further, the risk value of the action can be determined according to the abnormality increment value, the abnormality value, and the second number of the action. Further, the risk value of the device can be determined in combination with the risk values of multiple actions performed by the device.

[0125] As an example, the abnormality increment value of the action can be calculated using the following formula (1)-formula (2):

[0126]

[0127]

[0128] wherein mp a second number of actions E i p a repeat abnormality coefficient of actions E i an abnormality level of the business scenario of actions E i a first number of actions E i an abnormality value of actions E i an abnormality increment value of actions E i

[0129] Further, the risk value of the actions can be calculated by using the following formula (3):

[0130]

[0131] wherein γ p is a repeat abnormality coefficient of actions E i is an abnormality increment value of actions E i is an abnormality value of actions E i is a risk value of actions E i Optionally, γ p and in the formula (3) can be obtained by using the above formula (1)-(2).

[0132] Further, the risk value of the device can be calculated by using the following formula (4):

[0133]

[0134] wherein N E is a total number of actions performed by the device in an evaluation period, is a risk value of actions E i p is a risk value of the device. Optionally, N in the formula (4) can be obtained by using the above formula (3).

[0135] Exemplarily, referring to the following Table 1, the risk evaluation of the device under different business scenarios is shown:

[0136] Table 1

[0137]

[0138] In order to further understand the scheme proposed in the embodiments of the present application, the following specific embodiments are introduced, referring to Figure 3 ​​​​​​​​​​A risk assessment method of a device is provided for the embodiments of the present application, and specifically includes the following steps:

[0139] 301. Obtain running data of the device to be assessed in an assessment period.

[0140] 302. Determine at least one business scenario related to the device and a plurality of actions performed by the device in the assessment period according to the running data.

[0141] Optionally, the number of times each action is performed in the assessment period, i.e., the first number, can also be determined. Further, the number of times each action is performed in a set number of periods before the assessment period, i.e., the second number, can also be determined.

[0142] 303. Generate a plurality of labels of the device in the assessment period according to the execution information of the plurality of actions, and determine the labels associated with each business scenario.

[0143] The process of generating labels according to the execution information of actions can be referred to the description in the above embodiments, and will not be repeated here.

[0144] 304. Determine the label values of the plurality of labels in combination with the assessment period and the degree of change of the plurality of labels in the period before the assessment period.

[0145] 305. Determine the abnormality level of each business scenario according to the label values of the labels associated with each business scenario and the weights corresponding to each label.

[0146] 306. Calculate the risk value of the device in combination with the abnormality level of at least one business scenario, the abnormality values of the plurality of actions, the first number and the second number of each action.

[0147] The specific calculation process can be referred to the description in the above embodiments, and will not be repeated here.

[0148] Optionally, after determining the risk value of the device, it can be judged whether the risk value is greater than a preset threshold. If yes, a risk warning can also be issued.

[0149] Based on the same concept as the above method, see Figure 4 A device risk assessment apparatus 400 is provided for the embodiments of the present application. The apparatus 400 is used to perform each step in the above method, and will not be repeated here to avoid repetition. The apparatus 400 includes an obtaining unit 401 and a processing unit 402.

[0150] The obtaining unit 401 is configured to obtain running data of the device to be assessed in an assessment period.

[0151] The processing unit 402 is configured to perform:

[0152] determine at least one business scenario involved by the device according to the operation data, and determine a plurality of actions performed by the device in the evaluation period;

[0153] determine an abnormality level of each business scenario according to each action performed in the business scenario and a change degree of the execution information of the action compared with that of a previous period of the evaluation period;

[0154] determine a risk value of the device in combination with the abnormality level of the at least one business scenario and preset abnormality values of the plurality of actions.

[0155] In some embodiments, the processing unit 402 is specifically configured to:

[0156] classify the plurality of actions according to at least one preset statistical condition;

[0157] generate a plurality of labels of the device in the evaluation period for the execution information of each type of action;

[0158] determine labels associated with any business scenario according to each action performed in the business scenario;

[0159] determine an abnormality level of the any business scenario in combination with a label value of each label and a weight corresponding to each label in the any business scenario, wherein the label value of any label is used to represent a change degree of the any label.

[0160] In some embodiments, the acquisition unit 401 is further configured to:

[0161] acquire a first number and a second number of each action in the plurality of actions; the first number is a number of times of occurrence of the each action in the evaluation period, and the second number is a number of times of occurrence of the each action in a preset number of periods before the evaluation period;

[0162] When calculating the risk value of the device, the processing unit 402 is specifically configured to:

[0163] determine a risk value of each action according to the first number and the second number of the each action, an abnormality value of the each action, and an abnormality level of a business scenario to which the each action belongs;

[0164] calculate the risk value of the device according to the risk values of the plurality of actions respectively.

[0165] In some embodiments, the processing unit 402 is further configured to:

[0166] determine a label value of any label; and specifically configured to:

[0167] Determine a change degree of the any tag by comparing the any tag with a standard tag, the standard tag being a tag corresponding to the any tag in a previous period of the evaluation period;

[0168] Determine a tag value of the any tag according to a preconfigured corresponding relationship between the change degree and the tag value.

[0169] In some embodiments, the obtaining unit 401 is specifically configured to:

[0170] Obtain a log of the device in the evaluation period;

[0171] Extract the running data from the log by using a preconfigured program corresponding to a format of the log.

[0172] Figure 5 An electronic device 500 provided by an embodiment of the present application is shown. The electronic device 500 in the embodiment of the present application can further include a communication interface 503, for example, a network interface, and the electronic device can transmit data through the communication interface 503. For example, the electronic device 500 can obtain the running data of the device to be evaluated through the communication interface 503.

[0173] In the embodiment of the present application, the memory 502 stores instructions executable by the at least one controller 501. The at least one controller 501 can be configured to perform each step in the above method by executing the instructions stored in the memory 502. For example, the controller 501 can implement the functions of the processing unit 402 in the above method. Figure 4

[0174] The controller 501 is the control center of the electronic device, and can connect each part of the electronic device through various interfaces and lines, and run or execute the instructions stored in the memory 502 and call the data stored in the memory 502. Optionally, the controller 501 can include one or more processing units, and the controller 501 can integrate an application controller and a modem controller, wherein the application controller mainly processes the operating system and the application program, and the modem controller mainly processes the wireless communication. It can be understood that the above modem controller can also not be integrated into the controller 501. In some embodiments, the controller 501 and the memory 502 can be implemented on the same chip, and in some embodiments, they can also be implemented on separate chips respectively.

[0175] ​The controller 501 can be a general-purpose controller, such as a central processing unit (CPU), a digital signal controller, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic component, a discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose controller can be a microcontroller or any conventional controller. The steps performed by the data statistical platform disclosed in the embodiments of the present application can be directly executed by the hardware controller or by a combination of hardware and software modules in the controller.

[0176] The memory 502 is a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 502 can include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (RAM), a static random access memory (SRAM), a programmable read-only memory (PROM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic storage, a magnetic disk, an optical disk, and the like. The memory 502 can be any other medium capable of carrying or storing desired program codes in the form of instructions or data structures and capable of being accessed by a computer, but is not limited thereto. The memory 502 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0177] By designing and programming the controller 501, for example, the code corresponding to the training method of the neural network model introduced in the foregoing embodiments can be fixed in the chip, so that the chip can execute the steps of the foregoing neural network model training method during runtime. How to design and program the controller 501 is a technology known to those skilled in the art, and will not be described here.

[0178] Those skilled in the art will appreciate that embodiments of the present application can be readily used as software, hardware, or a combination of software and hardware. In one

[0179] The present application is described in reference to the flow diagrams and / or block diagrams of the methods, apparatus (systems) and computer program products according to this application. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks.

[0180] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks.

[0181] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks.

[0182] While preferred embodiments of the application have been described, those skilled in the art will appreciate that additional modifications and variations can be made to the described embodiments without departing from the inventive concepts. Accordingly, the appended claims are intended to cover all such modifications and variations as falling within the scope of the application.

[0183] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.

Claims

1. A risk assessment method for equipment, characterized in that, The method includes: Obtain operational data of the equipment to be evaluated within the evaluation period; Based on the operational data, at least one business scenario involving the device is determined, as well as multiple actions performed by the device during the evaluation period; The anomaly level of each business scenario is determined based on the actions performed in each business scenario and the degree of change in the execution information of each action compared to the previous period of the evaluation period. The risk value of the device is determined by combining the anomaly level of the at least one business scenario with the preset anomaly values ​​of the multiple actions. The step of determining the anomaly level of each business scenario based on the actions performed in each business scenario and the degree of change in the execution information of each action compared to the previous period of the evaluation period includes: The multiple actions are classified according to at least one preset statistical condition; Based on the execution information of various actions, multiple tags are generated for the device within the evaluation period; Based on the actions performed in any business scenario, determine the tags associated with that business scenario; By combining the tag values ​​of each tag and the weights corresponding to each tag in any given business scenario, the anomaly level of any business scenario is determined; wherein the tag value of any tag is used to characterize the degree of change of any tag.

2. The method according to claim 1, characterized in that, Before calculating the risk value of the device, the method further includes: Obtain a first quantity and a second quantity for each of the plurality of actions; the first quantity is the number of times each action occurs within the evaluation period, and the second quantity is the number of times each action occurs within a set number of periods prior to the evaluation period; The calculation of the risk value of the device specifically includes: The risk value of each action is determined based on the first and second quantities of each action, the outlier value of each action, and the anomaly level of the business scenario to which each action belongs. The risk value of the device is calculated based on the risk values ​​of the multiple actions respectively.

3. The method according to claim 1, characterized in that, The tag value of any tag is determined as follows: Compare any given label with a standard label to determine the degree of change of any given label; the standard label is the label corresponding to any given label in the previous period of the evaluation period. The tag value of any tag is determined based on the pre-configured correspondence between the degree of change and the tag value.

4. The method according to claim 1, characterized in that, The acquisition of operational data of the equipment to be evaluated within the evaluation period includes: Obtain the device's logs during the evaluation period; The program uses a pre-configured format corresponding to the log to extract runtime data from the log.

5. A risk assessment device for equipment, characterized in that, The device includes: The acquisition unit is used to acquire the operating data of the equipment to be evaluated during the evaluation period; The processing unit is configured to execute: Based on the operational data, at least one business scenario involving the device is determined, as well as multiple actions performed by the device during the evaluation period; The anomaly level of each business scenario is determined based on the actions performed in each business scenario and the degree of change in the execution information of each action compared to the previous period of the evaluation period. The risk value of the device is determined by combining the anomaly level of the at least one business scenario with the preset anomaly values ​​of the multiple actions. When determining the anomaly level of each business scenario based on the actions performed in each business scenario and the degree of change in the execution information of each action compared to the previous period of the evaluation period, the processing unit is specifically used for: The multiple actions are classified according to at least one preset statistical condition; Based on the execution information of various actions, multiple tags are generated for the device within the evaluation period; Based on the actions performed in any business scenario, determine the tags associated with that business scenario; By combining the tag values ​​of each tag and the weights corresponding to each tag in any given business scenario, the anomaly level of any business scenario is determined; wherein the tag value of any tag is used to characterize the degree of change of any tag.

6. The apparatus according to claim 5, characterized in that, The acquisition unit is further configured to: Obtain a first quantity and a second quantity for each of the plurality of actions; the first quantity is the number of times each action occurs within the evaluation period, and the second quantity is the number of times each action occurs within a set number of periods prior to the evaluation period; The processing unit, when calculating the risk value of the device, is specifically used for: The risk value of each action is determined based on the first and second quantities of each action, the outlier value of each action, and the anomaly level of the business scenario to which each action belongs. The risk value of the device is calculated based on the risk values ​​of the multiple actions respectively.

7. The apparatus according to claim 5, characterized in that, The processing unit is further configured to: Determines the tag value for any given tag; specifically used for: Compare any given label with a standard label to determine the degree of change of any given label; the standard label is the label corresponding to any given label in the previous period of the evaluation period. The tag value of any tag is determined based on the pre-configured correspondence between the degree of change and the tag value.

8. The apparatus according to claim 5, characterized in that, The acquisition unit is specifically used for: Obtain the device's logs during the evaluation period; The program uses a pre-configured format corresponding to the log to extract runtime data from the log.

9. An electronic device, characterized in that, include: Memory and controller; Memory, used to store program instructions; A controller is configured to invoke program instructions stored in the memory and execute the method of any one of claims 1-4 according to the obtained program.

10. A computer storage medium storing computer-executable instructions, characterized in that, The computer-executable instructions are used to perform the method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Network abnormal behavior detection method and device

    CN106789837A