An industrial internet identifier resolution-oriented malicious behavior detection method

CN116938538BActive Publication Date: 2026-08-21JINAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310818315.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-05
Publication Date
2026-08-21
Estimated Expiration
2043-07-05

AI Technical Summary

Technical Problem

[0004]当前的恶意检测方法中存在的不足主要有:1、恶意用户行为异常多变,恶意检测过程类似黑盒检测,在对当前实验的结果进行解释分析时有一定难度;2、常规的恶意用户行为多从时序特征、频率特征角度分析,特征分析所考虑的视角不够充分;3、恶意用户行为检测往往只能从结果来分析当前状态下用户行为是否存在异常,不具备一定的观察性;4、大多的恶意用户异常行为检查方法所提取的特征相对较少,很少考虑特征组合分析,往往直接将特征输入至模型进行分析

Benefits of technology

[0013] 1. This invention combines spatial, frequency, temporal, and directional feature information as the main features for detecting malicious user behavior. In the extraction of spatial feature information, this invention proposes to obtain spatial correlation information in the user's operation sequence, and for the first time combines the direction of the user's operation sequence with the spatial feature extraction method to extract forward and backward spatial correlation features, thereby obtaining more potential information about the user's operation sequence. This ensures a more accurate analysis of whether a user is engaging in malicious behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116938538B_ABST
    Figure CN116938538B_ABST
Patent Text Reader

Abstract

The application discloses a kind of malicious behavior detection methods for industrial internet identification resolution, comprising the following steps: S1, constructing malicious behavior detection classification model;S2, with the combination feature data STFD of user normal behavior operation as training set, train malicious behavior detection classification model;S3, the combination feature data STFD feature data of unknown normal, malicious behavior operation is input to malicious behavior detection classification model;S4, the normal, malicious classification result of the combination feature data STFD of unknown normal, malicious behavior operation is output by malicious behavior detection classification model.The application extracts four features of time sequence, frequency, space and direction, applies it to malicious behavior detection, accurately judges whether user behavior exists malicious behavior by analyzing multidimensional user operation behavior features.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of industrial internet security technology, specifically relating to a method for detecting malicious behavior in industrial internet identifier resolution. Background Technology

[0002] The Industrial Internet Identifier Resolution Service (IIRS) is a crucial component of the Industrial Internet network architecture, serving as a vital link supporting interconnectivity within the Industrial Internet. Internal threats to IIRS typically refer to security risks posed by internal personnel or partners. These individuals may intentionally or unintentionally leak confidential information, damage equipment or systems, or exploit system vulnerabilities for attacks. Malicious behavior is particularly common in IIR detection. Malicious attackers (external personnel, employees, former employees, contractors, etc.) use relevant technologies to steal information from internal members, maliciously impersonate internal users, and steal sensitive data or internal information from the organization.

[0003] Malicious behavior detection, as a key research area in internal malicious behavior detection, aims to identify malicious behaviors in user activities through detection models. For over a decade, numerous companies and scholars both domestically and internationally have focused their efforts on detecting malicious user behavior. Malicious behavior detection methods can be categorized based on different features and models. While various methods have achieved certain results, achieving high accuracy and a relatively low false positive rate remains a significant challenge.

[0004] The main shortcomings of current malicious detection methods are: 1. Malicious user behavior is highly variable, and the malicious detection process is similar to black-box detection, making it difficult to interpret and analyze the results of current experiments; 2. Conventional malicious user behavior is mostly analyzed from the perspective of time-series and frequency features, and the perspectives considered in feature analysis are not sufficient; 3. Malicious user behavior detection often can only analyze whether there are abnormalities in user behavior in the current state from the results, and lacks a certain degree of observation; 4. Most malicious user abnormal behavior inspection methods extract relatively few features, rarely consider feature combination analysis, and often directly input features into the model for analysis. Summary of the Invention

[0005] The main objective of this invention is to overcome the shortcomings and deficiencies of the existing technology and propose a malicious behavior detection method for industrial internet identifier resolution.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] A method for detecting malicious behavior in industrial internet identifier resolution includes the following steps:

[0008] S1. Construct a malicious behavior detection and classification model;

[0009] S2. Use STFD (Standardized Dynamic Data) of combined features of normal user behavior as the training set to train a malicious behavior detection and classification model.

[0010] S3. Input the combined feature data of unknown normal and malicious behavior operations, STFD feature data, into the malicious behavior detection and classification model;

[0011] S4. The malicious behavior detection and classification model outputs the normal and malicious classification results of the combined feature data of unknown normal and malicious behavior operations in STFD.

[0012] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0013] 1. This invention combines spatial, frequency, temporal, and directional feature information as the main features for detecting malicious user behavior. In the extraction of spatial feature information, this invention proposes to obtain spatial correlation information in the user's operation sequence, and for the first time combines the direction of the user's operation sequence with the spatial feature extraction method to extract forward and backward spatial correlation features, thereby obtaining more potential information about the user's operation sequence. This ensures a more accurate analysis of whether a user is engaging in malicious behavior.

[0014] 2. Based on the correlation analysis between multidimensional feature information and user behavior, this invention adopts a strategy of combining multidimensional feature information. The combined features can better analyze the degree to which the current user behavior is malicious, thereby ensuring that the internal system can respond to malicious behavior generated by user behavior more timely and accurately. Compared with directly inputting multidimensional features into the algorithm detection model, the combined features have the advantages of each feature and have high interpretability, and can more accurately reflect the degree of impact of the current user behavior.

[0015] 3. This invention also proposes a multi-dimensional feature visualization map. Considering that different features and combinations of features have different impacts on the results of user behavior analysis, the visualized feature map can discover potential malicious behaviors of users to a certain extent, thereby improving the intuitive observation capability of the entire internal system for monitoring user behavior. Attached Figure Description

[0016] Figure 1 This is a flowchart of the method of the present invention;

[0017] Figure 2 This is a diagram illustrating the user operation sequence in an embodiment of the present invention;

[0018] Figure 3 This is a schematic diagram of the architecture of the method of the present invention;

[0019] Figure 4 This is a visualization of multiple feature perspectives in an embodiment of the present invention;

[0020] Figure 5 This is a flowchart of malicious behavior detection in an embodiment of the present invention. Detailed Implementation

[0021] The present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0022] Example

[0023] like Figure 1 , Figure 3 and Figure 5 As shown, this invention provides a method for detecting malicious behavior in industrial internet identifier resolution, comprising the following steps:

[0024] S1. Construct a malicious behavior detection and classification model;

[0025] S2. Use STFD (Standardized Dynamic Data) of combined features of normal user behavior as the training set to train a malicious behavior detection and classification model.

[0026] S3. Input the combined feature data of unknown normal and malicious behavior operations, STFD feature data, into the malicious behavior detection and classification model;

[0027] S4. The malicious behavior detection and classification model outputs the normal and malicious classification results of the combined feature data of unknown normal and malicious behavior operations in STFD.

[0028] Among them, such as Figure 3 As shown, the combined feature data STFD is formed by extracting the frequency, temporal, spatial, and directional features of the user operation sequence and combining them.

[0029] Before extracting the frequency, temporal, spatial, and directional features of the user operation sequence, preprocessing of the user operation sequence is also included. This specifically includes user operation sequence information partitioning and generating operation sequence feature preprocessing information. The user operation sequence information partitioning is specifically as follows:

[0030] like Figure 2 As shown, for a certain user sequence S = (c1, c2, ..., c n ), where n is the total length of the user sequence, c n Let S be the user's nth action. The user actions are divided into action blocks, with S divided into action blocks of w actions each, resulting in S = (S1, S2, ..., S...). k ), k is the number of action blocks, S1 represents the user's first action block, S1=(c1,c2,…,c w ), c w This represents the w-th operation command in the sequence;

[0031] The relationships above are as follows:

[0032] S = (c1, c2, ..., c n )=(S1,S2,…,S k )

[0033] =(c1,c2,…,c w ,c w+1 ,c w+2 ,…,c 2w ,…c (k-1)w+1 ,c (k-1)w+2 ,…,c kw )

[0034] Where w represents the number of operation commands in the current action block, kw = n; let V = (v1, v2, ... v m V represents the set of commands that appear independently in the user sequence. m Let m be the m-th independent command, where m ≤ n.

[0035] The specific preprocessing information for generating operation sequence features is as follows:

[0036] Given a feature combination window of length j and a sliding step of 1, let S = (S1, S2, ..., S... k The behavior block is divided into the following forms:

[0037]

[0038] For operation block S1, it is divided into the following forms:

[0039]

[0040] Among them, S windows=j This indicates that the current user sequence is divided according to the window length, S 1,windows=j This represents the sequence segmentation result corresponding to the first line block.

[0041] In this embodiment, the frequency feature extraction method for user operation sequences specifically includes:

[0042] User operation frequency information extraction, specifically:

[0043] Based on the divided behavior block information, the frequency feature information of each operation command in the user behavior information block is extracted. The frequency feature information is extracted using TF-IDF, and the formula for frequency information feature extraction is as follows:

[0044]

[0045] in, This refers to the command c iFrequency of appearance in the document It is command c i The number of times it appears in a behavior block, where k is the number of behavior blocks;

[0046] Frequency information calculation based on window length is as follows:

[0047] When the frequency characteristics of commands in the user line block are calculated, the frequency statistics of commands in each window are calculated based on the window size j:

[0048]

[0049] For operation sequence extraction, different statistical frequency feature values ​​will be generated depending on the window size; for command block S 1,windows=j The frequency characteristic calculation result becomes:

[0050]

[0051] In this embodiment, the method for extracting the temporal features of a user operation sequence includes selecting temporal information parameters and generating temporal information features;

[0052] The timing information parameters are selected as follows:

[0053] Time-series information is generated using N-grams. In the N-gram model, different values ​​of N result in different calculation methods. N-gram is a text analysis method used to segment text into a sequence of N consecutive characters or words and calculate their frequencies or probabilities. N is the number of characters or words in each sequence. The N-gram calculation method is as follows:

[0054]

[0055] That is, it is assumed that the occurrence of a command is only related to the first n operation commands in the sequence;

[0056] We will analyze the first n operations that are related to the Wth operation:

[0057] p(c W |c1,c2,c3,…,c W-1 )≈p(c W |c W-n+1 ,…,c W-1 )

[0058] When N is 1:

[0059] p(c1,c2,c3,…,c W )≈p(c1)p(c2)p(c3)…p(c W )

[0060] When N is 2:

[0061] p(c1,c2,c3,…,c W )≈p(c1)p(c2|c1)p(c3…|c2)…p(c W |c W-1 )

[0062] Given that the time series characteristic information parameter is N=2, the formula for calculating the time series characteristic information is:

[0063] N-gram(S) = p(c1,c2,c3,…,c W )≈p(c1)p(c2|c1)p(c3|c2)…p(c W |c W-1 )

[0064] The generation of time-series information features is as follows:

[0065] For operation command block S 1,windows=j The feature generation result for the time series becomes:

[0066]

[0067] In this embodiment, the method for extracting spatial and directional features of user operation sequences includes generating a directional transition matrix, generating independent command PageRank values, and generating spatial feature values ​​of user operation behavior.

[0068] The directional transition matrix is ​​generated as follows:

[0069] V = (v1, v2, ... v) m The sequence S = (c1, c2, ..., c) is given by the sequence S = (c1, c2, ..., c) n User commands appearing independently in the sequence S are used to generate the forward transition matrix M = [t]. ij ] m×m The element t in the i-th row and j-th column ij The rules for determining the value are as follows:

[0070] If node j has k directed edges leading out, and node i is one of the nodes it leads out, then t ij =1 / k; otherwise t ij =0,i,j=1,2,…,m;

[0071] The transition matrix has the following properties:

[0072]

[0073] The positive directional transition matrix is: M Forward =[t ij ] m×mThe reverse directional transition matrix is: M Inverse =[t ji ] m×m .

[0074] The specific steps for generating PageRank values ​​using the independent command are as follows:

[0075] The formula for generating PageRank is:

[0076]

[0077] Where d is a coefficient, called the damping factor, 0≤d≤1, M is the transition matrix, and each component of R is called the Page-Rank value of each node:

[0078]

[0079] For the initial PR(v) i It has the following properties:

[0080] PR(v i )≥0, i=1,2,…,m

[0081]

[0082] in, M(v i ) indicates pointing to v i Node set, L(v) j ) represents node v i The number of directed edges that connect to the target;

[0083]

[0084] The specific process for generating user operation behavior spatial feature values ​​is as follows:

[0085] Positive PR Forward (S 1,windows=j The formula for generating the formula is as follows:

[0086]

[0087] Reverse Page-Rank Inverse (S 1,windows=j The formula for generating the formula is as follows:

[0088]

[0089] In this embodiment, the method for combining the frequency, temporal, spatial, and directional features of a user operation sequence includes combined feature processing and combined feature generation;

[0090] Combined feature processing, specifically:

[0091] Define STFD positive features STFD Forward STFD inverse features STFD Reverse Calculation formula extraction formula:

[0092]

[0093]

[0094] in, To statistically analyze the frequency characteristics of the current n operations, To statistically analyze the frequency characteristics of the current n operations, To statistically analyze the spatial inverse feature information of the current n operations, This is the spatial positive feature information of the current n operations;

[0095] STFD is a combination of feature data. When the STFD feature value is higher, the probability of malicious behavior is higher, while the lower the STFD value, the probability of the corresponding operation being normal is higher.

[0096] Considering TF-IDF(S) 1,windows=j ), N-GRAM(S 1,windows=j ), PR Forward (S 1,windows=j The range of the three values ​​is between (0,1), TF-IDF(S 1,windows=j The value of ) is much greater than that of N-GRAM(S 1,windows=j The value of ) and The range of values ​​is between (1, +∞). To avoid excessively large STFD values, the log function is introduced. When processing values ​​in (1, +∞), the log function can smooth the range of data variation and reduce experimental computational costs. For example, when the log function is base 10, if the input is [100, 1000, 10000, 100000], after passing through the log function, it will result in [2, 3, 4, 5]. The range is reduced, the difference is smaller, and it is more stable.

[0097] Combined feature generation, specifically:

[0098] According to the formula for generating combined features, for the behavior block S segmented according to the window size 1,windows=j The combined feature generation result is as follows:

[0099]

[0100]

[0101] In this embodiment, multi-feature perspective visualization of combined features is also implemented. Combined features are visualized as operation behavior blocks, and TF-IDF(S) is displayed. 1,windows=j ), N-GRAM (S 1,windows=j ), PR Reverse (S 1,windows=j ), PR Reverse (S 1,windows=j Features such as ) are included in the scope of visualization, and changes in relevant feature values ​​are observed visually.

[0102] During the visualization process, the SEA experimental dataset was used for data analysis. By displaying the 10th, 30th, 76th, and 83rd user behavior blocks of the 7th user in the SEA dataset, the potential normal and malicious behavior states of different user behavior blocks can be intuitively understood. For example... Figure 4 As shown, combined feature STFD can clearly detect whether malicious behavior has occurred.

[0103] The following is in conjunction with the appendix Figure 5 Further description of malicious behavior detection, such as Figure 5 As shown, malicious behavior detection is mainly divided into four stages:

[0104] The first stage involves selecting a malicious behavior detection and classification model. Commonly used machine learning algorithms can be employed, such as one-class support vector machine (OCSVM), K-nearest neighbors (KNN), and Naive Bayes (NB).

[0105] The second stage involves training the malicious behavior detection and classification model. This stage primarily uses STFD (Standardized Frequency Derivative) feature data combining normal user behavior as the training set for training the malicious behavior detection and classification model. During training, the input data consists of normal STFD feature information.

[0106] During the training phase, when the input is a behavior block segmented according to the window size, the known STFD feature data of the normal behavior block is STFD. Forward (S know,windows=j Taking OCSVM as an example, the labels input to the training model are: label(S) know,windows=j ) = OCSVM(S know,windows=j ) = {0, normal}, where 0 indicates that the training data consists entirely of normal behavioral data;

[0107] In the third stage, the combined feature data of unknown normal and malicious behavior operations, STFD feature data, are input into the malicious behavior detection and classification model.

[0108] In this phase, when the input is an unknown action block, STFD Forward (S unknown,windows=j), where S unknow,nwindow=sj This indicates that the sequence block is processed according to the window size j, but it is unknown whether the sequence is normal or malicious. In this case, the detection model output is:

[0109]

[0110] In the fourth stage, the malicious behavior detection classification model outputs the normal or malicious status information of the currently input STFD user behavior data block. When the output result is 0, it indicates that the current behavior block is a normal behavior block. When the output result is 1, it indicates that the current behavior block is a malicious behavior block.

[0111] This invention provides a malicious behavior detection method for industrial internet identifier resolution, comprising: extracting four features—temporal, frequency, spatial, and directional—and applying them to malicious behavior detection. By analyzing multi-dimensional user operation behavior features, it accurately determines whether a user is engaging in malicious behavior. Secondly, it analyzes the influence of different features on user behavior and proposes a multi-feature combination strategy to rationally combine feature information and achieve correlation between features, thereby further increasing the perspective for analyzing malicious behavior. Simultaneously, a visualized feature map is designed. By observing the changes in feature data values ​​in the feature map, the features become observable before entering the detection model, enabling security personnel to detect potential threats immediately. Furthermore, during the model's malicious identification process, it can be combined with the feature map, increasing the interpretability of the data and thus ensuring the overall security of the industrial internet system.

[0112] It should also be noted that, in this specification, terms such as "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0113] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting malicious behavior in industrial internet identifier resolution, characterized in that, Includes the following steps: S1. Construct a malicious behavior detection and classification model; S2. Use STFD (Standardized Dynamic Data) of combined features of normal user behavior as the training set to train a malicious behavior detection and classification model. S3. Input the combined feature data of unknown normal and malicious behavior operations, STFD feature data, into the malicious behavior detection classification model; S4. The malicious behavior detection and classification model outputs the normal and malicious classification results of the combined feature data of unknown normal and malicious behavior operations in STFD. STFD combines the frequency, temporal, spatial, and directional features of the user operation sequence based on the user operation sequence. Methods for combining the frequency, temporal, spatial, and directional features of user operation sequences include combined feature processing and combined feature generation; Combined feature processing, specifically: Define STFD positive features and STFD inverse features The formula for calculation is as follows: ; ; in, To statistically analyze the frequency characteristics of the current n operations, To statistically analyze the frequency characteristics of the current n operations, For the current statistics Spatial inverse feature information of each operation, For the current statistics Spatial positive feature information of each operation; STFD is a combination of feature data. When the STFD feature value is higher, the probability of malicious behavior is higher, while the lower the STFD value, the probability of the corresponding operation being normal is higher. Considering , , The range of the three values ​​is between (0, 1). The value is much greater than The value, and The range of values ​​is To avoid excessively large STFD values, the log function is introduced. The log function processes... When the value is set, it can smooth the range of data variation and reduce experimental computational overhead; Combined feature generation, specifically: Based on the formula for generating combined features, for behavior blocks segmented according to window size The combined feature generation result is as follows: ; 。 2. The malicious behavior detection method for industrial internet identifier resolution according to claim 1, characterized in that, Before extracting the frequency, temporal, spatial, and directional features of the user operation sequence, preprocessing of the user operation sequence is also included. This specifically includes user operation sequence information partitioning and generating operation sequence feature preprocessing information. The user operation sequence information partitioning is specifically as follows: For a certain user sequence ,in, The total length of the user sequence. For the user's first Each operation; user behavior is segmented according to behavior blocks, and... Divided into each Each operation behavior forms an action block, resulting in... , For the number of rows and blocks, This represents the user's first action block. , Represents the first in the sequence One operation command; The relationships above are as follows: ; in, This indicates the number of operation commands in the current action block. ;make , This represents the set of commands that appear independently in a user sequence. For the first A single command that appears. .

3. The malicious behavior detection method for industrial internet identifier resolution according to claim 2, characterized in that, The specific preprocessing information for generating operation sequence features is as follows: Given a feature combination window length of With a sliding step size of 1, Behavior blocks are divided into the following forms: ; For operation behavior blocks It can be divided into the following forms: ; in, This indicates that the current user sequence is divided according to the window length. This represents the sequence segmentation result corresponding to the first line block.

4. The malicious behavior detection method for industrial internet identifier resolution according to claim 3, characterized in that, The specific methods for extracting frequency features from user operation sequences include: User operation frequency information extraction, specifically: Based on the defined behavior blocks, the frequency features of each operation command within the user behavior block are extracted. TF-IDF is used for frequency feature extraction, and the formula for frequency feature extraction is as follows: ; in, This refers to the command c i Frequency of appearance in the document It is command c i The number of times it appears in a behavior block, where k is the number of behavior blocks; Frequency feature calculation based on window length is as follows: When the frequency characteristics of commands in the user line block are calculated, the frequency statistics of commands in each window are calculated based on the window size j: ; For operation sequence extraction, different statistical frequency feature values ​​will be generated depending on the window size; for command blocks... The frequency characteristic calculation result becomes: 。 5. The malicious behavior detection method for industrial internet identifier resolution according to claim 3, characterized in that, The method for extracting the temporal features of user operation sequences includes selecting temporal information parameters and generating temporal information features; The timing information parameters are selected as follows: Time series information is generated using N-grams. In the N-gram model, different values ​​of N will result in different calculation methods. ; Assume that the occurrence of a command is only related to the first n operation commands in the sequence; We will analyze the first n operations that are related to the Wth operation: ; When N is 1: ; When N is 2: ; Given that the time series characteristic information parameter is N=2, the formula for calculating the time series characteristic information is: ; The generation of time-series information features is as follows: For operation command blocks The feature generation result for the time series becomes: 。 6. The malicious behavior detection method for industrial internet identifier resolution according to claim 3, characterized in that, Methods for extracting spatial and directional features of user operation sequences include generating directional transition matrices, generating independent command PageRank values, and generating spatial feature values ​​of user operation behaviors; The directional transition matrix is ​​generated as follows: For sequence User commands that appear independently in the text, according to Proceed in a forward sequence to generate a forward transition matrix. , No. Line 1 Column elements The rules for determining the value are as follows: If node have A directed edge connects the nodes, and the nodes are connected. If it is a node that is connected to it, then ;otherwise , ; The transition matrix has the following properties: ; The positive directional transition matrix is: The reverse directional transition matrix is: .

7. A method for detecting malicious behavior in industrial internet identifier resolution according to claim 6, characterized in that, The specific steps for generating PageRank values ​​using the independent command are as follows: The formula for generating PageRank is: ; in, It is a coefficient, called the damping factor. , This is the transition matrix R, where each component of R is called the Page-Rank value of each node: ; For the initial It has the following properties: ; ; in, , Indicates pointing to Node set Represents a node The number of directed edges that connect to the target; 。 8. A method for detecting malicious behavior in industrial internet identifier resolution according to claim 6, characterized in that, The specific process for generating user operation behavior spatial feature values ​​is as follows: positive The formula for generating the formula is as follows: ; Reverse The formula for generating the formula is as follows: 。