A network security verification method, device and storage medium
By calculating the preference differences between the user's commonly used and current login information and device usage information, the problem of inadequate monitoring of abnormal behavior in the prior art is solved, and the accuracy and reliability of network security verification are improved.
Patent Information
- Application Number
- CN202411097632.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-12
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-08-12
AI Technical Summary
Existing authentication technologies do not monitor abnormal behaviors properly, resulting in insecure network communications.
By obtaining the commonly used login information and device usage information of the communication user, a first preference vector is established; obtaining the current login information and device usage information, a second preference vector is established; calculating the preference difference between the two, and determining whether the user's identity is passed based on the difference.
It improves the accuracy and reliability of network security verification, and can effectively monitor and detect abnormal behaviors of user identity during use.
Smart Images

Figure CN118677697B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technologies, and in particular, to a network security verification method, apparatus, and storage medium. Background Art
[0002] Network security authentication refers to the process of verifying the authenticity and legitimacy of users through specific technologies and methods in a network environment. It is the foundation of network security, aiming to ensure that network resources and data can only be accessed by authorized users. Authentication technology is a key component for protecting digital assets and ensuring the security of the network environment, and is crucial for the information security of individual users, enterprises, and the entire society.
[0003] Currently, the main authentication technologies include password-based authentication, hardware-based authentication, and biometric-based authentication. Password-based authentication is the most traditional method, but it is vulnerable to password guessing and leakage threats. Hardware-based authentication enhances security through password algorithms built into the hardware. Biometric authentication, such as fingerprint recognition, iris recognition, etc., provides a certain level of security due to its uniqueness and difficulty of replication.
[0004] However, the above authentication technologies have certain limitations. For example, hardware-based authentication requires specific hardware devices, which brings certain burdens to the flexibility and economy of security verification in terms of deployment and update. If the hardware device is damaged, it will also affect user access, and it requires specific verification algorithms, which will cause energy consumption of the device and consumption of storage resources. Although biometric authentication brings the advantages of uniqueness and difficulty of replication, it depends on identity recognition devices such as cameras and is not friendly to devices such as desktop computers and laptops. In addition, existing technologies often focus on the verification stage and lack monitoring of user identities during use, and cannot effectively detect abnormal behaviors that may occur after authentication, and this defect is more obvious in the case of identity information being stolen.
[0005] In summary, the existing authentication technologies do not monitor abnormal behaviors well, which easily leads to insecure network communication. Summary of the Invention
[0006] The present invention provides a network security verification method, apparatus, and storage medium, which can verify the user's login information and monitor abnormal behaviors during the process of the user using the device, achieving the purpose of authenticating the user's identity and improving the accuracy and reliability of network security verification.
[0007] In a first aspect, to solve the above technical problems, the present invention provides a network security verification method, including:
[0008] Obtain the common login information, common device usage information, current login information, and current device usage information of the communication user;
[0009] Obtain a first preference vector based on the common login information and the common device usage information;
[0010] Obtain a second preference vector based on the current login information and the current device usage information;
[0011] Perform a difference calculation based on the first preference vector and the second preference vector to obtain a preference difference degree;
[0012] Judge whether the identity of the communication user passes according to the preference difference degree. When the preference difference degree exceeds the threshold, it is judged as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is judged as a normal user and the user identity passes.
[0013] Preferably, the common login information includes the common login time, common login device, and common login geographical location, and the common device usage information includes the common device traffic information and common access resource types;
[0014] The current login information includes the current login time, current login device, and current login geographical location, and the current device usage information includes the current device traffic information and current access resource types. Preferably, the obtaining of the first preference vector according to the common login information and the common device usage information includes:
[0015] Perform a priority setting according to the common login information and the common device usage information to obtain a first preference priority;
[0016] Obtain the first preference vector according to the first preference priority.
[0017] Preferably, the obtaining of the first preference vector according to the common login information and the common device usage information is specifically:
[0018] Within a preset number of time periods, sort the multiple time periods from high to low according to the number of user logins in each time period to obtain a first preference priority including the sorted multiple time periods; or
[0019] Sort the multiple login devices from high to low according to the number of logins corresponding to each login device to obtain a first preference priority including the sorted multiple login devices; or
[0020] Sort the multiple login geographical locations from high to low according to the number of logins corresponding to each login geographical location to obtain a first preference priority including the sorted multiple login geographical locations; or
[0021] Among a preset plurality of traffic usage ranges, sort them in descending order according to the number of times reached corresponding to each traffic usage range, to obtain a first preference priority including the sorted plurality of traffic usage ranges; or
[0022] Sort them in descending order according to the number of access times corresponding to each resource type, to obtain a first preference priority including the sorted plurality of resource types;
[0023] According to the first preference priority, obtain a first preference vector.
[0024] Preferably, the obtaining of the second preference vector according to the current login information and the current device usage information includes:
[0025] Perform priority setting according to the current login information and the current device usage information, to obtain a second preference priority;
[0026] According to the second preference priority, obtain a second preference vector.
[0027] Preferably, performing priority setting according to the current login information and the current device usage information to obtain a second preference priority specifically includes:
[0028] Match the first preference priority corresponding to the login time according to the time period in which the login time is located, to obtain a first dimension priority;
[0029] Match the first preference priority corresponding to the login device according to the login device type, to obtain a second dimension priority;
[0030] Match the first preference priority corresponding to the login geographical location according to the login geographical location, to obtain a third dimension priority;
[0031] Match the first preference priority corresponding to the traffic usage range according to the traffic usage situation, to obtain a fourth dimension priority;
[0032] Match the first preference priority corresponding to the resource type according to the number of times of accessing the resource type, to obtain a fifth dimension priority;
[0033] Wherein, the second preference priority includes the first dimension priority, the second dimension priority, the third dimension priority, the fourth dimension priority, and the fifth dimension priority.
[0034] Preferably, the first preference vector and the second preference vector are five-dimensional vectors, each dimension of the first preference vector is sorted according to the maximum value of the first preference priority, and each dimension of the second preference vector is sorted according to the second preference priority.
[0035] Preferably, according to the first preference vector and the second preference vector, a difference calculation is performed to obtain a preference difference degree, specifically:
[0036] Calculate the average value of the priority values in the y-th dimension according to the current login information, current device usage information, common login information, and common device usage information , and the calculation formula is:
[0037]
[0038] In the formula, represents the -th preference vector composed of priorities, represents the set of login information and device usage information, represents the current login information and current device usage information, represents the common login information and common device usage information;
[0039] According to the current login information, current device usage information, common login information, and common device usage information, the standard deviation of the priority values in the y-th dimension The calculation formula is:
[0040]
[0041] Calculate the sum of the five-dimensional mean square deviations according to the standard deviation of the priority values in the y-th dimension , and use the sum of the five-dimensional mean square deviations as the preference difference degree, and the calculation formula is:
[0042]
[0043] In a second aspect, the present invention provides a network security communication device, including:
[0044] Obtain the common login information, common device usage information, current login information, and current device usage information of the communication user;
[0045] A preference setting module, configured to obtain a first preference vector according to the common login information and the common device usage information;
[0046] An information matching module, configured to perform priority matching according to the current login information and current device usage information to obtain a first preference vector;
[0047] A difference calculation module, configured to perform difference calculation according to the first preference vector and the second preference vector to obtain a preference difference degree;
[0048] An authentication module, configured to determine whether the identity of a communication user passes according to the preference difference degree. When the preference difference degree exceeds a threshold, it is determined as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is determined as a normal user and the user identity passes.
[0049] In a third aspect, the present invention further provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the network security verification method described in any one of the above is implemented.
[0050] In a fourth aspect, the present invention further provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the network security verification method described in any one of the above.
[0051] Compared with the prior art, the present invention has the following beneficial effects: The embodiments of the present invention provide a network security verification method, device, and storage medium. The method includes obtaining the common login information, common device usage information, current login information, and current device usage information of a communication user; obtaining a first preference vector according to the common login information and the common device usage information; obtaining a second preference vector according to the current login information and the current device usage information; performing difference calculation according to the first preference vector and the second preference vector to obtain a preference difference degree; and determining whether the identity of the communication user passes according to the preference difference degree. When the preference difference degree exceeds a threshold, it is determined as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is determined as a normal user and the user identity passes.
[0052] In the present invention, the method obtains the historical common login information and device usage information of the logged-in user, sets the priority of the user's historical preferences to obtain a first preference vector, and then obtains the current login information and device usage information of the user, and matches them with the set priority to obtain a second preference vector; performs difference calculation on the first preference vector and the second preference vector to obtain the difference degree between the two vectors, that is, compares the login information and device usage information of the user with the correct identity and the currently logged-in user to obtain the difference between the two. If the difference does not exceed the preset threshold, it is determined as the correct user identity information. If the difference exceeds the preset threshold, it is determined as abnormal user information, achieving the purpose of determining the correctness of the current user's identity and improving the accuracy and reliability of network security verification. Description of the Drawings
[0053] Figure 1It is a schematic flowchart of the network security verification method provided by the first embodiment of the present invention;
[0054] Figure 2 It is a schematic structural diagram of the network security verification device provided by the second embodiment of the present invention. Detailed implementation manners
[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0056] Refer to Figure 1 , the first embodiment of the present invention provides a network security verification method, including the following steps:
[0057] S11, obtain the common login information, common device usage information, current login information, and current device usage information of the communication user;
[0058] S12, obtain a first preference vector according to the common login information and the common device usage information;
[0059] S13, obtain a second preference vector according to the current login information and the current device usage information;
[0060] S14, perform a difference calculation according to the first preference vector and the second preference vector to obtain a preference difference degree;
[0061] S15, judge whether the identity of the communication user passes according to the preference difference degree. When the preference difference degree exceeds the threshold, it is judged as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is judged as a normal user and the user identity passes.
[0062] It should be noted that network security authentication refers to the process of verifying the authenticity and legality of users through specific technologies and methods in a network environment. It is the foundation of network security, aiming to ensure that network resources and data can only be accessed by authorized users. Authentication technology is a key component in protecting digital assets and ensuring the security of the network environment, and is crucial for the information security of individual users, enterprises, and society as a whole. Currently, the main authentication technologies include password-based authentication, hardware-based authentication, and biometric-based authentication. Password-based authentication is the most traditional method, but it is vulnerable to password guessing and leakage threats. Hardware-based authentication enhances security through password algorithms built into the hardware. Biometric authentication, such as fingerprint recognition and iris recognition, provides a certain level of security due to its uniqueness and difficulty of replication. However, existing technologies often focus on the authentication stage and lack monitoring of user identities during use, and cannot effectively detect abnormal behaviors that may occur after authentication, which is more obvious in the case of identity information theft.
[0063] In summary, the existing authentication technologies do not monitor abnormal behaviors effectively, which easily leads to insecure network communication.
[0064] To facilitate the understanding of the present invention, some preferred embodiments of the present invention will be further described below.
[0065] In step S11, the common login information includes common login time, common login device, and common login geographical location, and the common device usage information includes common device traffic information and common accessed resource types. Specifically, the common login information refers to the time when the user most commonly logged in historically, the device where the user most commonly logged in, and the geographical location where the user most commonly logged in; the common device usage information refers to the user's most common traffic usage situation and the types of resources most commonly accessed historically.
[0066] The current login information includes current login time, current login device, and current login geographical location, and the current device usage information includes current device traffic information and current accessed resource types. Specifically, the current login information refers to the user login time, login device, and login geographical location that are obtained by the system in real time when the current communication user performs a login operation; the current device usage information refers to the user's traffic usage information and the types of resources accessed that are obtained by the system in real time when the current communication user uses the device.
[0067] In step S12, according to the common login information and the common device usage information, a first preference vector is obtained, including: setting priorities according to the common login information and the common device usage information to obtain a first preference priority; obtaining a first preference vector according to the first preference priority.
[0068] Specifically, the specific method for setting the first preference priority is as follows: within a preset plurality of time periods, sort the plurality of time periods from high to low according to the number of user logins in each time period to obtain a first preference priority including the sorted plurality of time periods; or
[0069] sort the plurality of login devices from high to low according to the number of logins corresponding to each login device to obtain a first preference priority including the sorted plurality of login devices; or
[0070] sort the plurality of login geographical locations from high to low according to the number of logins corresponding to each login geographical location to obtain a first preference priority including the sorted plurality of login geographical locations; or
[0071] within a preset plurality of traffic usage ranges, sort the plurality of traffic usage ranges from high to low according to the number of times reached corresponding to each traffic usage range to obtain a first preference priority including the sorted plurality of traffic usage ranges; or
[0072] sort the plurality of resource types from high to low according to the number of accesses corresponding to each resource type to obtain a first preference priority including the sorted plurality of resource types;
[0073] It should be noted that the first preference vector is a five-dimensional vector, and each dimension thereof is composed of the first preference priorities obtained above. Exemplarily, the first dimension of the first preference vector is the preference priority of the login time, the second dimension of the first preference vector is the preference priority of the login device, the third dimension of the first preference vector is the preference priority of the login geographical location, the fourth dimension of the first preference vector is the preference priority of the traffic usage range, and the fifth dimension of the first preference vector is the preference priority of the resource access type.
[0074] It should be noted that in addition to setting the priority according to the user's historical login preferences and usage preferences in this step, the specific value of the first preference vector is also determined.
[0075] Exemplarily, when determining the priority of the login time, the system can preset multiple time periods: 8:00 am - 10:00 am is time period A, 10:00 am - 12:00 pm is time period B, 12:00 pm - 2:00 pm is time period C, and the subsequent time periods are in two-hour intervals and so on. If the number of logins of the user in time period A is 3 times, the number of logins in time period B is 2, and the number of logins in time period C is 1 within a set past period of time, then the priority of time period A is greater than that of time period B, and the priority of time period B is greater than that of C. In this example, only three time periods are taken as an example, so the priority of time period A can be set to 3, the priority of time period B can be set to 2, and the priority of time period C can be set to 1.
[0076] Exemplarily, when determining the priority of the logged-in device, the logged-in device can be common communication devices available for users to log in, including tablets, mobile phones, computers, and servers. If within a set past period of time, the number of times the user logged in using a tablet is 4, the number of times using a mobile phone is 5, the number of times using a computer is 6, and the number of times using a server is 2, then the priority setting is computer > mobile phone > tablet > server. Therefore, the priority of the computer can be set to 4, the priority of the mobile phone to 3, the priority of the tablet to 2, and the priority of the server to 1.
[0077] Exemplarily, when determining the priority of the logged-in geographical location, the logged-in geographical location can be the regions logged in within a past period of time, designated as Region A, Region B, Region C, and Region D. If within a set past period of time, the number of times the user logged in at Region A is 4, the number of times at Region B is 3, the number of times at Region C is 2, and the number of times at Region D is 1, then the priority setting is Region A > Region B > Region C > Region D. Therefore, the priority of Region A can be set to 4, the priority of Region B to 3, the priority of Region C to 2, and the priority of Region D to 1.
[0078] Exemplarily, when determining the priority of the traffic usage range, the system can preset multiple traffic ranges: within a period of time, when the traffic usage is between 0M - 1G, it is designated as Traffic Range Segment A; when the traffic usage is between 1G - 2G, it is designated as Traffic Range Segment B; when the traffic usage is between 2G - 3G, it is designated as Traffic Range Segment C; and so on for subsequent traffic range segments. If within a set past period of time, the number of times the user's used traffic size is within Traffic Range Segment A is 3, the number of times within Traffic Range Segment B is 2, and the number of times within Traffic Range Segment C is 1, then the priority setting is Traffic Range Segment A > Traffic Range Segment B > Traffic Range Segment C. Therefore, the priority of Traffic Range Segment A can be set to 3, the priority of Traffic Range Segment B to 2, and the priority of Traffic Range Segment C to 1.
[0079] Exemplarily, when determining the priority of the resource type, the resource type can be documents, pictures, databases accessed by the user within a past period of time, designated as Resource A, Resource B, and Resource C. If within a set past period of time, the number of times the user accessed Resource A is 6, the number of times accessed Resource B is 3, and the number of times accessed Resource C is 1, then the priority setting is Resource A > Resource B > Resource C. Therefore, the priority of Resource A can be set to 3, the priority of Resource B to 2, and the priority of Resource C to 1.
[0080] It should be noted that each dimension of the first preference vector is the maximum value of the corresponding priority, that is, the most common login behavior and device usage behavior of the user's history. Exemplarily, according to the values set in the above example, the first preference vector can be set to [3, 4, 4, 3, 3].
[0081] In step S13, according to the current login information and the current device usage information, a second preference vector is obtained, including: setting priorities according to the current login information and the current device usage information to obtain a second preference priority; and obtaining a second preference vector according to the second preference priority.
[0082] Specifically, the specific method for setting the second preference priority value is:
[0083] According to the time period in which the login time is located, match the first preference priority corresponding to the login time to obtain a first dimension priority;
[0084] According to the login device type, match the first preference priority corresponding to the login device to obtain a second dimension priority;
[0085] According to the login geographical location, match the first preference priority corresponding to the login geographical location to obtain a third dimension priority;
[0086] According to the traffic usage situation, match the first preference priority corresponding to the traffic usage range to obtain a fourth dimension priority;
[0087] According to the number of times of accessing resource types, match the first preference priority corresponding to the resource type to obtain a fifth dimension priority;
[0088] It should be noted that the second preference vector is also a five-dimensional vector, and each dimension of it is composed of the second preference priorities obtained above.
[0089] Exemplarily, as described in the example of step S12, if the current login time of the user is 8:30, the corresponding login time period is period A, then the matched first preference priority is 3, and the value 3 is used as the first dimension priority; if the device currently logged in by the user is a mobile phone, then the matched first preference priority is 3, and the value 3 is used as the second dimension priority; if the current login geographical location of the user is region C, then the matched first preference priority is 2, and the value 2 is used as the third dimension priority; if the amount of traffic used by the current user within a period of time is 1.5G, then the matched first preference priority is 2, and the value 2 is used as the fourth dimension priority; if the current user accesses resource C the most times within a period of time, then the matched first preference priority is 1, and the value 1 is used as the fifth dimension priority.
[0090] According to the above login preferences and usage preferences of the current user, the second preference vector can be set as [3, 3, 2, 2, 1].
[0091] In step S14, according to the first preference vector and the second preference vector, a difference calculation is performed to obtain a preference difference degree, specifically:
[0092] Calculate the average value of the priority value in the y dimension according to the current login information, current device usage information, common login information, and common device usage information , and the calculation formula is:
[0093]
[0094] In the formula, represents the preference vector composed of priorities, represents the set of login information and device usage information, represents the current login information and current device usage information, represents the common login information and common device usage information;
[0095] According to the current login information, current device usage information, common login information, and common device usage information, the standard deviation of the priority value in the y dimension The calculation formula is:
[0096]
[0097] Calculate the sum of the five-dimensional mean square errors according to the standard deviation of the priority value in the y dimension , and use the sum of the five-dimensional mean square errors as the preference difference degree, and the calculation formula is:
[0098]
[0099] It should be noted that represents the degree of difference between the current login information, current device usage information and the common login information, common device usage information, that is, the preference difference degree. If the standard deviation calculated for each dimension is larger, it indicates that the corresponding dimension values are more discrete, indicating that the current user's preference is more different from the historical preference. When the difference between the two is too large, it may mean that the currently logged-in and used user is not the correct user identity, and at this time, identity verification needs to be performed again.
[0100] In step S15, according to the preference difference degree, determine whether the identity of the communication user passes. Specifically: the preference difference degree is the sum of the five-dimensional mean square errors, which represents the degree of difference between the current login information, current device usage information and the common login information, common device usage information. The larger the preference difference degree, the lower the possibility of being the correct identity user.
[0101] When the preference difference exceeds the threshold, it is determined as an abnormal user and the user identity fails; when the preference difference is within the threshold, it is determined as a normal user and the user identity passes. In one implementation, the threshold can be determined in the following ways: by statistical analysis, by analyzing user behavior data, using statistical methods to determine the distribution of normal behavior and setting the threshold; by historical behavior analysis, considering the user's past login and usage patterns, using historical data to define the range of normal behavior; by machine learning methods, by analyzing historical data to dynamically adjust the threshold. In short, the set value of the threshold cannot be too low, otherwise it will lead to misjudgment and affect the user experience; the set value of the threshold cannot be too high, otherwise it will lead to insensitive authentication and the network communication security cannot be guaranteed.
[0102] The working process of the present invention is described below by taking a relatively common scenario as an example. The working process is as follows:
[0103] The system first sets priorities based on the common login information and common device usage information of communication users. Exemplarily: The system presets multiple time periods: 00:00 - 08:00 is set as time period A, 08:00 - 16:00 is set as time period B, and 16:00 - 24:00 is set as time period C. Among them, the number of logins in time period A is 3 times, the number of logins in time period B is 2 times, and the number of logins in time period C is 1 time. Then, the priority of time period A is set to 3, the priority of time period B is set to 2, and the priority of time period C is set to 1; The system presets three login devices: tablet, mobile phone, and computer. In the past period of time, the number of times of logging in with a tablet is 1, the number of times of logging in with a mobile phone is 2, and the number of times of logging in with a computer is 3. Then, the priority of the computer is set to 3, the priority of the mobile phone is set to 2, and the priority of the tablet is set to 1; In the past period of time, the number of times the user logged in in region A is 4, the number of times the user logged in in region B is 3, and the number of times the user logged in in region C is 2. Then, the priority of region A is set to 3, the priority of region B is set to 2, and the priority of region C is set to 1; The system presets multiple traffic ranges. When the traffic usage is between 0M - 1G, it is set as traffic range segment A. When the traffic usage is between 1G - 2G, it is set as traffic range segment B. When the traffic usage is between 2G - 3G, it is set as traffic range segment C. Among them, in the past period of time, the number of times the traffic size used is within traffic range segment A is 3, the number of times the traffic size used is within traffic range segment B is 2, and the number of times the traffic size used is within traffic range segment C is 1. Then, the priority of traffic range segment A is set to 3, the priority of traffic range segment B is set to 2, and the priority of traffic range segment C is set to 1; The system presets multiple resource types. Documents are set as resource A, pictures are set as resource B, and databases are set as resource C. Among them, in the past period of time, the number of times of accessing resource A is 6, the number of times of accessing resource B is 3, and the number of times of accessing resource C is 1. Then, the priority of resource A is set to 3, the priority of resource B is set to 2, and the priority of resource C is set to 1. Thus, the first preference vector obtained is [3, 3, 3, 3, 3].
[0104] When a user attempts to log in and use the network system, the system obtains the current login information and the current device usage information in real time. Exemplarily: The user logs in from region B using a mobile phone at 2 pm, uses 1.5G of traffic to access the database, and the number of times of accessing the database is the most. The system matches the current time period, device type, geographical location, traffic usage, and accessed resource type with the first preference vector in the historical data, and obtains the second preference vector as [2, 2, 2, 2, 3].
[0105] The system calculates the preference difference degree according to the obtained first preference vector [3, 3, 3, 3, 3] and the second preference vector [2, 2, 2, 2, 3]. Exemplarily, the calculation of the preference difference degree takes the fifth dimension as an example of the present invention:
[0106] Calculate the average value of the first - dimension preference values :
[0107]
[0108] Calculate the standard deviation of the first - dimension preference values , that is, the preference difference degree of the first dimension
[0109]
[0110] By analogy, calculate the standard deviations of the first to fourth dimensions, and finally calculate the sum of the standard deviations of the five dimensions , and determine whether the identity of the communication user passes according to the preference difference degree. When the preference difference degree exceeds the threshold, it is determined as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is determined as a normal user and the user identity passes.
[0111] In summary, the embodiment of the present invention provides a network security verification method, including obtaining the common login information, common device usage information, current login information, and current device usage information of a communication user; obtaining a first preference vector according to the common login information and the common device usage information; obtaining a second preference vector according to the current login information and the current device usage information; performing difference calculation according to the first preference vector and the second preference vector to obtain a preference difference degree; and determining whether the identity of the communication user passes according to the preference difference degree. When the preference difference degree exceeds the threshold, it is determined as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is determined as a normal user and the user identity passes. In the present invention, the method obtains the historical common login information and device usage information of the logged - in user, sets priorities for the user's historical preferences to obtain a first preference vector, then obtains the current login information and device usage information of the user, and matches them with the set priorities to obtain a second preference vector; performs difference calculation on the first preference vector and the second preference vector to obtain the difference degree between the two vectors, that is, compares the login information and device usage information of the user with the correct identity and the currently logged - in user to obtain the difference between the two. If the difference does not exceed the preset threshold, it is determined as the correct user identity information; if the difference exceeds the preset threshold, it is determined as abnormal user information, achieving the purpose of determining the correctness of the current user's identity. The monitoring method is not limited to the identity verification when the user logs in, but conducts identity verification throughout the two stages from user login to usage, improving the accuracy and reliability of network security verification.
[0112] Refer to Figure 2 , the second embodiment of the present invention provides a network security verification device, including:
[0113] An information acquisition module that acquires the common login information, common device usage information, current login information, and current device usage information of a communication user;
[0114] A preference setting module that, based on the common login information and the common device usage information, obtains a first preference vector;
[0115] An information matching module that, based on the current login information and the current device usage information, obtains a second preference vector;
[0116] A difference calculation module that performs difference calculation based on the first preference vector and the second preference vector to obtain a preference difference degree;
[0117] An identity authentication module that, based on the preference difference degree, determines whether the identity of the communication user passes. When the preference difference degree exceeds the threshold, it is determined as an abnormal user and the user identity does not pass; when the preference difference degree is within the threshold, it is determined as a normal user and the user identity passes.
[0118] In an alternative embodiment, the information acquisition module is specifically configured to:
[0119] Acquire the common login time, common login device, common login geographical location, device traffic information, common access resource types, current login time, current login device, current login geographical location, current device traffic information, and current access resource types.
[0120] In an alternative embodiment, the preference setting module is specifically configured to:
[0121] Perform priority setting based on the common login information and the common device usage information to obtain a first preference priority;
[0122] Based on the first preference priority, obtain a first preference vector.
[0123] Specifically, the preference setting module is configured to:
[0124] Within a preset plurality of time periods, sort the plurality of time periods from high to low according to the number of user logins in each time period to obtain a first preference priority including the sorted plurality of time periods; or
[0125] Sort the plurality of login devices from high to low according to the number of logins corresponding to each login device to obtain a first preference priority including the sorted plurality of login devices; or
[0126] Sort the plurality of login geographical locations from high to low according to the number of logins corresponding to each login geographical location to obtain a first preference priority including the sorted plurality of login geographical locations; or
[0127] Within a preset multiple traffic usage ranges, sort them in descending order according to the number of times reached corresponding to each traffic usage range, and obtain a first preference priority including the sorted multiple traffic usage ranges; or
[0128] Sort them in descending order according to the number of accesses corresponding to each resource type, and obtain a first preference priority including the sorted multiple resource types;
[0129] In an alternative embodiment, the information matching module is configured to:
[0130] Perform priority setting according to the current login information and the current device usage information, and obtain a second preference priority;
[0131] Obtain a second preference vector according to the second preference priority.
[0132] Specifically, the information matching module is configured to:
[0133] Match the first preference priority corresponding to the login time according to the time period in which the login time is located, and obtain a first dimension priority;
[0134] Match the first preference priority corresponding to the login device type according to the login device type, and obtain a second dimension priority;
[0135] Match the first preference priority corresponding to the login geographical location according to the login geographical location, and obtain a third dimension priority;
[0136] Match the first preference priority corresponding to the traffic usage range according to the traffic usage situation, and obtain a fourth dimension priority;
[0137] Match the first preference priority corresponding to the resource type according to the number of times of accessing the resource type, and obtain a fifth dimension priority;
[0138] In an alternative embodiment, the difference calculation module is specifically configured to:
[0139] Calculate the average value of the priority values of the y-th dimension according to the current login information, the current device usage information, the common login information, and the common device usage information , and the calculation formula is:
[0140]
[0141] In the formula, represents the th preference vector composed of priorities, represents the set of login information and device usage information, represents the current login information and the current device usage information, Indicates common login information and common device usage information;
[0142] According to the current login information, current device usage information, common login information, and common device usage information, the standard deviation of the priority value in the y-th dimension The calculation formula is:
[0143]
[0144] Based on the standard deviation of the priority value in the y-th dimension, calculate the sum of the five-dimensional mean square deviations , and use the sum of the five-dimensional mean square deviations as the preference difference degree. The calculation formula is:
[0145]
[0146] It should be noted that a network security verification device provided in an embodiment of the present invention is used to execute all the process steps of a network security verification method in the above embodiment. The working principles and beneficial effects of the two correspond one by one, so they will not be elaborated here.
[0147] An embodiment of the present invention also provides a terminal device. The terminal device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a network security verification program. When the processor executes the computer program, it implements the steps in each of the above-mentioned network security verification method embodiments, such as Figure 1 the step S11 shown. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in each of the above device embodiments, such as the information acquisition module.
[0148] Exemplarily, the computer program can be divided into one or more modules / units. The one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the terminal device.
[0149] The terminal device can be a desktop computer, a notebook, a palm computer, a smart tablet, and other computing devices. The terminal device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above components are only examples of the terminal device and do not constitute a limitation on the terminal device. It may include more or fewer components than the above, or combine some components, or different components. For example, the terminal device may further include input / output devices, network access devices, a bus, etc.
[0150] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device, connecting various parts of the entire terminal device through various interfaces and circuits.
[0151] The memory can be used to store the computer programs and / or modules. The processor realizes various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, at least one magnetic disk storage device, flash device, or other volatile solid-state storage devices.
[0152] Among them, if the modules / units integrated in the terminal device are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0153] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement it without creative effort.
[0154] The specific embodiments described above further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. It is particularly pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A network security verification method, characterized in that: include: Obtain the communication user's common login information, common device usage information, current login information, and current device usage information; Priority setting is performed according to the common login information and the common device usage information to obtain a first preference priority, and a first preference vector is obtained according to the first preference priority; Priority setting is performed according to the current login information and the current device usage information to obtain a second preference priority, and a second preference vector is obtained according to the second preference priority; The first preference vector and the second preference vector are five-dimensional vectors, each dimension of the first preference vector is sorted according to the maximum value of the first preference priority, and each dimension of the second preference vector is sorted according to the second preference priority; A difference calculation is performed based on the first preference vector and the second preference vector to obtain a preference difference degree, which is specifically: Calculate the average value of the priority value of the yth dimension based on the current login information, current device usage information, common login information, and common device usage information and the standard deviation of the priority value of the y dimension , the calculation formula is: In the formula, Indicates the priority level preference vector, Represents a collection of login information and device usage information. Indicates the current login information and current device usage information. Indicates common login information and common device usage information; Calculate the sum of the five-dimensional mean square errors based on the standard deviation of the priority value of the y-th dimension , the sum of the five-dimensional mean square errors is taken as the preference difference, and the calculation formula is: ; According to the preference difference, it is determined whether the communication user identity is passed. When the preference difference exceeds a threshold, it is determined to be an abnormal user and the user identity is not passed; when the preference difference is within the threshold, it is determined to be a normal user and the user identity is passed.
2. The network security verification method according to claim 1, characterized in that: The commonly used login information includes commonly used login time, commonly used login device, and commonly used login geographical location; the commonly used device usage information includes commonly used device traffic information and commonly accessed resource types; The current login information includes the current login time, the current login device, and the current login geographic location; the current device usage information includes the current device traffic information and the current access resource type.
3. The network security verification method according to claim 1, characterized in that: The priority is set according to the common login information and the common device usage information to obtain a first preference priority, which is specifically: In a plurality of preset time periods, the plurality of time periods are sorted from high to low according to the number of user logins in each time period, to obtain a first preference priority of the plurality of time periods after sorting; Sorting the login times corresponding to each login device from high to low to obtain a first preference priority of the sorted plurality of login devices; Sorting the number of logins corresponding to each login geographical location from high to low to obtain a first preference priority including the sorted plurality of login geographical locations; In the preset multiple flow usage ranges, sorting is performed from high to low according to the number of times each flow usage range is reached, so as to obtain a first preference priority including the sorted multiple flow usage ranges; Sorting the resource types from high to low according to the number of accesses corresponding to each resource type, to obtain a first preference priority of the sorted plurality of resource types; A first preference vector is obtained according to the first preference priority.
4. The network security verification method according to claim 1, characterized in that: The priority is set according to the current login information and the current device usage information to obtain a second preference priority, specifically: According to the time period of the login time, the first preference priority of the corresponding login time is matched to obtain the first dimension priority; According to the login device type, the first preference priority of the corresponding login device is matched to obtain the second dimension priority; According to the login geographic location, the first preference priority of the corresponding login geographic location is matched to obtain the third dimension priority; According to the traffic usage, the first preference priority of the corresponding traffic usage range is matched to obtain the fourth dimension priority; According to the number of times the resource type is accessed, the first preference priority of the corresponding resource type is matched to obtain the fifth dimension priority; The second preference priority includes the first dimension priority, the second dimension priority, the third dimension priority, the fourth dimension priority and the fifth dimension priority.
5. A network security communication device, characterized in that: The method for implementing the network security verification method according to any one of claims 1 to 4 comprises: An information acquisition module is used to acquire the communication user's common login information, common device usage information, current login information, and current device usage information; A preference setting module, configured to obtain a first preference vector according to the common login information and the common device usage information; An information matching module, obtaining a second preference vector according to the current login information and the current device usage information; a difference calculation module, configured to perform difference calculation based on the first preference vector and the second preference vector to obtain a preference difference degree; The identity authentication module is used to determine whether the communication user identity is passed according to the preference difference. When the preference difference exceeds a threshold, it is determined to be an abnormal user and the user identity is not passed; when the preference difference is within the threshold, it is determined to be a normal user and the user identity is passed.
6. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the network security verification method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Abnormal detection method and device for user behavior, equipment and medium
CN116956250A