Network Behavior Detection Method, Device and Electronic Device Based on Network Behavior Portrait
By obtaining and preprocessing historical network behavior data, building network behavior portraits and detecting abnormal behaviors in real time, the problem of insufficient detection caused by lag in network behavior templates is solved, and effective control and security improvement of abnormal behaviors is achieved.
Patent Information
- Application Number
- CN202411010748.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-26
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-07-26
AI Technical Summary
In the prior art, network behavior template configuration is lagging, and abnormal network behavior cannot be detected and identified effectively and comprehensively, resulting in damage to network equipment such as servers and other network devices, and data tampering is prone to occur when abnormal network behavior is not effectively identified and intercepted.
By obtaining the historical network behavior data collected by the relay server, performing data preprocessing, using the network behavior portrait construction model to build user portraits, monitoring and generating behavior detection information in real time, and performing network behavior control and content access control based on behavior type and risk level.
It realizes effective detection of abnormal network behavior, reduces damage to network devices such as servers, improves the security of network devices, reduces false alarm rates and prevents data from being tampered with.
Smart Images

Figure CN118802354B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technologies, and more particularly, to a network behavior detection method, apparatus, and electronic device based on a network behavior portrait. Background Art
[0002] With the rapid development of mobile Internet technologies, people have entered the era of network informatization. At the same time, network security issues have become increasingly severe, especially network attack methods have become more complex and diverse. Currently, when performing network behavior detection, the commonly adopted method is, for example, to perform abnormal network behavior detection by means of network behavior matching through a configured network behavior template.
[0003] However, when adopting the above method, there is often the following technical problem 1:
[0004] The configuration of network behavior templates often has lag. At the same time, a large number of users often correspond to a large number of network behaviors with complex behavior types. The method of performing network behavior matching through network behavior templates cannot effectively and comprehensively detect and identify abnormal network behaviors, and thus may cause damage to network devices such as servers due to abnormal network behaviors (such as network intrusion behaviors, etc.).
[0005] In the process of adopting technical solutions to solve the above technical problem 1, there is often the following technical problem 2:
[0006] For abnormal network behaviors, especially data intrusion-based abnormal network behaviors, when they cannot be effectively identified and intercepted, it is extremely easy to have situations that affect data security such as data being tampered with.
[0007] The above information disclosed in this background art section is only used to enhance the understanding of the background of the inventive concept, and thus, it may include information that does not form the prior art known to those of ordinary skill in the art in this country. Summary of the Invention
[0008] This summary of the present disclosure is used to introduce concepts in a concise form, and these concepts will be described in detail in the subsequent detailed implementation section. This summary of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.
[0009] Some embodiments of the present disclosure propose a network behavior detection method, apparatus, and electronic device based on a network behavior portrait to solve one or more of the technical problems mentioned in the above background art section.
[0010] In a first aspect, some embodiments of the present disclosure provide a network behavior detection method based on a network behavior portrait. The method includes: obtaining historical network behavior data collected by a relay server for a target user, where the relay server is a server disposed between a target client and a service server for data forwarding and network behavior recording, the target user is a user who has not generated a corresponding network behavior portrait, and the target user communicates with the service server through the target client; performing data preprocessing on the historical network behavior data to generate processed network behavior data; constructing a network behavior portrait for the target user through a pre-constructed network behavior portrait construction model and the processed network behavior data to generate a network behavior portrait for the target user; in response to detecting real-time network behavior data, generating behavior detection information for the real-time network behavior data according to the real-time network behavior data, the network behavior portrait, and a pre-constructed network behavior recognition model, where the behavior detection information includes: behavior type, behavior danger level, and behavior-related content, and the behavior-related content represents the service data stored in the service server involved in the real-time network behavior data; in response to the behavior type indicating that the real-time network behavior data is abnormal network behavior data, performing the following processing steps: performing network behavior control on the target client according to the behavior danger level; performing content access control on the behavior-related content according to the behavior type and the behavior danger level.
[0011] Second aspect, some embodiments of the present disclosure provide a network behavior detection device based on network behavior portraits. The device includes: an acquisition unit configured to acquire historical network behavior data collected by a relay server for a target user, where the relay server is a server disposed between the target client and the service server for data forwarding and network behavior recording, the target user is a user who has not generated a corresponding network behavior portrait, and the target user communicates with the service server through the target client; a data preprocessing unit configured to perform data preprocessing on the historical network behavior data to generate processed network behavior data; a portrait construction unit configured to construct a network behavior portrait for the target user through a pre-constructed network behavior portrait construction model and the processed network behavior data to generate a network behavior portrait for the target user; a generation unit configured to, in response to detecting real-time network behavior data, generate behavior detection information for the real-time network behavior data according to the real-time network behavior data, the network behavior portrait, and a pre-constructed network behavior recognition model, where the behavior detection information includes: behavior type, behavior risk level, and behavior-related content, and the behavior-related content represents the service data stored in the service server involved in the real-time network behavior data; an execution unit configured to, in response to the behavior type indicating that the real-time network behavior data is abnormal network behavior data, perform the following processing steps: perform network behavior control on the target client according to the behavior risk level; perform content access control on the behavior-related content according to the behavior type and the behavior risk level.
[0012] Third aspect, some embodiments of the present disclosure provide an electronic device, including: one or more processors; a storage device having stored thereon one or more programs, which when executed by the one or more processors cause the one or more processors to implement the method described in any implementation manner of the first aspect above.
[0013] Fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having stored thereon a computer program, where the program when executed by a processor implements the method described in any implementation manner of the first aspect above.
[0014] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the network behavior detection method based on network behavior portraits in some embodiments of the present disclosure, effective detection of abnormal network behaviors is achieved, avoiding damage to network devices such as servers caused by abnormal network behaviors, and thus improving the network device security of network devices such as servers. Specifically, the reasons for the inability to effectively and comprehensively detect and identify abnormal network behaviors are as follows: The configuration of network behavior templates often has lag, and at the same time, a large number of users often correspond to a large number of network behaviors with complex behavior types. Using the method of network behavior matching with network behavior templates cannot effectively and comprehensively detect and identify abnormal network behaviors, and thus may cause damage to network devices such as servers due to abnormal network behaviors (such as network intrusion behaviors, etc.). Based on this, in some embodiments of the present disclosure, the network behavior detection method based on network behavior portraits first obtains the historical network behavior data collected by the relay server for the target user. Among them, the above relay server is a server set between the target client and the service server for data forwarding and network behavior recording. The above target user is a user who has not generated a corresponding network behavior portrait. The above target user communicates with the above service server through the above target client. By analyzing the historical network behavior data of the user, a user portrait is established, providing data for the subsequent construction of network behavior portraits. Secondly, the above historical network behavior data is preprocessed to generate processed network behavior data. In practice, the historical network behavior data is collected by the relay server, and during the collection process, there may be situations of data loss (such as the appearance of null values). Therefore, by preprocessing the historical network behavior data, it helps to improve the data quality. Then, through the pre-constructed network behavior portrait construction model and the above processed network behavior data, the network behavior portrait of the above target user is constructed to generate the network behavior portrait for the above target user. In practice, using the pre-constructed network behavior portrait construction model and the above processed network behavior data, the network behavior portrait for the above target user is generated. In this way, automatic and efficient feature extraction is achieved, improving the accuracy of network behavior portrait construction. The network behavior portrait is dynamically updated, can be adjusted and updated in real time as the user's behavior changes, and has better adaptability and response speed. Then, in response to detecting real-time network behavior data, according to the above real-time network behavior data, the above network behavior portrait, and the pre-constructed network behavior recognition model, behavior detection information for the above real-time network behavior data is generated. Among them, the above behavior detection information includes: behavior type, behavior danger level, and behavior-related content. The above behavior-related content represents the service data stored in the above service server involved in the above real-time network behavior data. In practice, the real-time network behavior detection method based on network behavior portraits can more accurately identify the normal and abnormal behaviors of users, thus effectively reducing the false alarm rate.Finally, in response to the above behavior type characterizing the above real-time network behavior data as abnormal network behavior data, the following processing steps are performed: the first step is to control the network behavior of the above target client according to the above behavior risk level. In practice, the behavior risk levels of different network behaviors are also different. Taking the same network behavior control may overreact. Therefore, it is necessary to perform different network behavior controls on the target client according to different behavior risk levels, so as to achieve the reasonable allocation and use of network resources. The second step is to perform content access control on the content involved in the above behavior according to the above behavior type and the above behavior risk level. In practice, when it fails to be effectively identified and intercepted, it is very easy for data to be tampered with and other situations that affect data security. Therefore, it is necessary to achieve effective content access control through classification. In this way, effective detection of abnormal network behavior is achieved, thereby timely controlling and reducing the damage of abnormal network behavior to network devices such as servers, thereby improving the network device security of network devices such as servers. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0016] Figure 1 is a flow chart of some embodiments of a network behavior detection method based on network behavior profiling according to the present disclosure;
[0017] Figure 2 It is a structural schematic diagram of some embodiments of a network behavior detection device based on network behavior profiling according to the present disclosure;
[0018] Figure 3 It is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION
[0019] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0020] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other.
[0021] It should be noted that concepts such as "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.
[0022] It should be noted that the modification of "one" and "multiple" mentioned in this disclosure is illustrative rather than restrictive. Those skilled in the art should understand that unless clearly specified otherwise in the context, it should be understood as "one or more".
[0023] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0024] Regarding operations such as collection, storage, and use of the user's personal information (such as historical network behavior data and real-time network behavior data) involved in this disclosure, before performing the corresponding operations, relevant organizations or individuals shall fulfill obligations including conducting a personal information security impact assessment, fulfilling the obligation of notification to the personal information subject, and obtaining the prior authorization and consent of the personal information subject.
[0025] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0026] Reference Figure 1 , which shows the flow 100 of some embodiments of a network behavior detection method based on a network behavior portrait according to the present disclosure. The network behavior detection method based on a network behavior portrait includes the following steps:
[0027] Step 101, obtaining historical network behavior data collected by a relay server for a target user.
[0028] In some embodiments, the execution subject (such as a computing device) of the network behavior detection method based on a network behavior portrait can obtain historical network behavior data collected by a relay server through a wired connection or a wireless connection. Among them, the above relay server is a server set between a target client and a service server for data forwarding and network behavior recording. The above target user is a user for whom no corresponding network behavior portrait has been generated. The above target user communicates with the above service server through the above target client. The above target client can be a web browser. The above service server is a server for processing service data. The above service data may include, but is not limited to, user basic information, access log data, and page interaction data. Among them, the above historical network behavior data is data generated based on the historical network behavior of the above target user before the current time. In practice, the above historical network behavior data can be browsing history data, search history data, and application usage data.
[0029] It should be noted that the above wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other wireless connection methods known now or developed in the future.
[0030] Step 102: Perform data preprocessing on the historical network behavior data to generate processed network behavior data.
[0031] In some embodiments, the above execution subject may perform data preprocessing on the above historical network behavior data to generate processed network behavior data. In practice, the above execution subject may perform standardization processing on the above historical network behavior data to generate processed network behavior data.
[0032] Optionally, the above historical network behavior data includes: static behavior data and dynamic behavior data. The above static behavior data includes: collection time, network behavior source address, and network behavior target address. The network behavior source address is the IP address where the network behavior is generated. The network behavior target address is the IP address to be accessed by the corresponding network behavior. The above dynamic behavior data is the attribute that dynamically changes in the above historical network behavior data.
[0033] In some alternative implementation manners of some embodiments, the above execution subject performs data preprocessing on the above historical network behavior data to generate processed network behavior data, which may include the following steps:
[0034] First step, in response to determining that the above collection time does not meet the first exclusion condition, perform time standardization on the above collection time to obtain the standardized collection time.
[0035] Among them, the above first exclusion condition may be that the collection time is an outlier. In practice, the above outlier may be a null value.
[0036] In practice, the above execution subject may perform time standardization on the above collection time by converting the above collection time into a preset time format to obtain the standardized collection time. For example, the preset time format may be the ISO 8601 format.
[0037] Second step, in response to determining that the address type of the above network behavior source address is the first address type, perform address mapping on the above network behavior source address to obtain the mapped network behavior source address.
[0038] Among them, the first address type may be the IPv4 type. In practice, the mapped network behavior source address may be a network behavior source address with an address type of IPv6 type.
[0039] In practice, the above-mentioned execution entity can perform address mapping on the source address of the above-mentioned network behavior through embedded IPv4 notation to obtain the source address of the network behavior after mapping.
[0040] In the third step, in response to the address type of the above-mentioned network behavior target address being the above-mentioned first address type, perform address mapping on the above-mentioned network behavior target address to obtain the target address of the network behavior after mapping. Among them, the target address of the network behavior after mapping can be the target address of the network behavior with the IPv6 type address type.
[0041] In practice, the above-mentioned execution entity can perform address mapping on the above-mentioned network behavior target address through embedded IPv4 notation to obtain the target address of the network behavior after mapping.
[0042] In the fourth step, determine the above-mentioned standardized acquisition time, the above-mentioned source address of the network behavior after mapping, and the above-mentioned destination address of the network behavior after mapping as the static behavior data after preprocessing.
[0043] In the fifth step, determine the above-mentioned static behavior data after preprocessing and the above-mentioned dynamic behavior data as the above-mentioned network behavior data after processing.
[0044] Step 103: Construct a network behavior portrait for the target user through a pre-constructed network behavior portrait construction model and the processed network behavior data, so as to generate a network behavior portrait for the target user.
[0045] In some embodiments, the above-mentioned execution entity can construct a network behavior portrait for the above-mentioned target user through a pre-constructed network behavior portrait construction model and the above-mentioned processed network behavior data, so as to generate a network behavior portrait for the above-mentioned target user. Among them, the above-mentioned network behavior portrait construction model can be used to construct a network behavior portrait, which is a model with the processed network behavior data as the input and the network behavior portrait for the target user as the output. In practice, the above-mentioned network behavior portrait construction model can be a neural network model based on the Transformer structure. The network behavior portrait represents the characterization of the target user's network behavior.
[0046] In practice, the above-mentioned execution entity can input the above-mentioned processed network behavior data into the above-mentioned network behavior portrait construction model to generate a network behavior portrait for the target user.
[0047] Optionally, the above-mentioned network behavior portrait construction model includes: a static behavior feature extraction model, a dynamic behavior feature extraction model, and a portrait generation model. Among them, the above-mentioned static behavior feature extraction model is used to extract features from the above-mentioned preprocessed static behavior data. The above-mentioned dynamic behavior feature extraction model is used to extract features from the above-mentioned dynamic behavior data. The above-mentioned portrait generation model is a model for generating behavior portraits. The portrait generation model takes the dimension-reduced static behavior feature information and the dimension-reduced dynamic behavior feature information as inputs, and outputs the network behavior portrait of the target user.
[0048] In some optional implementation manners of some embodiments, the above-mentioned execution subject constructs a network behavior portrait of the above-mentioned target user through a pre-constructed network behavior portrait construction model and the above-mentioned processed network behavior data, to generate a network behavior portrait of the above-mentioned target user, which may include the following steps:
[0049] In the first step, the above-mentioned preprocessed static behavior data is input into the above-mentioned static behavior feature extraction model to generate static behavior feature information.
[0050] Among them, the above-mentioned static behavior feature extraction model may use a convolutional neural network as the basic neural network structure. The network structure of the above-mentioned static behavior feature extraction model may include: a first convolutional layer, a second convolutional layer, a residual module layer, an attention mechanism layer, and a fully connected layer. The above-mentioned first convolutional layer may perform a first convolution process on the above-mentioned preprocessed static behavior data. The above-mentioned first convolutional layer may be composed of a preset number of 3×3 convolutional kernels with a stride of 1, BatchNormalization, and a ReLU activation function. The above-mentioned second convolutional layer may perform a second convolution process on the output of the first convolutional layer. The above-mentioned second convolutional layer may be composed of a preset number of 3×3 convolutional kernels with a stride of 2, BatchNormalization, and a ReLU activation function. The above-mentioned residual module layer may perform a depth convolution process on the output of the second convolutional layer. The above-mentioned residual module layer may be composed of two first convolutional layers and a skip connection layer. The above-mentioned skip connection layer may add the outputs of the two first convolutional layers and the output of the second convolutional layer. The above-mentioned attention mechanism layer may be a convolutional layer based on a spatial attention mechanism model. The above-mentioned fully connected layer may convert the output of the attention mechanism layer into static behavior feature information. For example, the above-mentioned preset number may be 32. The above-mentioned static behavior feature information is a feature vector extracted by the static behavior feature extraction model from the above-mentioned preprocessed static behavior data.
[0051] In the second step, the above-mentioned dynamic behavior data is input into the above-mentioned dynamic behavior feature extraction model to generate dynamic behavior feature information.
[0052] Among them, the above dynamic behavior feature extraction model can use a recurrent neural network as the basic neural network structure. In practice, the above dynamic behavior feature extraction model can be an LSTM (Long Short-Term Memory) model. The above dynamic behavior feature information is the feature vector extracted by the dynamic behavior feature extraction model from the dynamic behavior data.
[0053] In practice, the above execution entity can use the above dynamic behavior feature extraction model to extract features from the above dynamic behavior data to generate dynamic behavior feature information.
[0054] In the third step, dimensionality reduction processing is respectively performed on the above static behavior feature information and the above dynamic behavior feature information to obtain the dimensionality-reduced static behavior feature information and the dimensionality-reduced dynamic behavior feature information.
[0055] In practice, the above execution entity can first perform dimensionality reduction processing on the above static behavior feature information and the above dynamic behavior feature information through the principal component analysis (PCA) algorithm to obtain the dimensionality-reduced static behavior feature information. Then, dimensionality reduction processing can be performed on the above dynamic behavior feature information to obtain the dimensionality-reduced dynamic behavior feature information.
[0056] In the fourth step, according to the above portrait generation model, the above dimensionality-reduced static behavior feature information, and the above dimensionality-reduced dynamic behavior feature information, the above network behavior portrait is generated.
[0057] In practice, the above portrait generation model can be a deep autoencoder model.
[0058] In practice, the above execution entity can input the above dimensionality-reduced static behavior feature information and the above dimensionality-reduced dynamic behavior feature information into the above portrait generation model to generate the above network behavior portrait.
[0059] In step 104, in response to detecting real-time network behavior data, behavior detection information for the real-time network behavior data is generated according to the real-time network behavior data, the network behavior portrait, and a pre-constructed network behavior recognition model.
[0060] In some embodiments, the above-mentioned execution entity may, in response to detecting real-time network behavior data, generate behavior detection information for the real-time network behavior data according to the real-time network behavior data, the above-mentioned network behavior profile, and a pre-constructed network behavior recognition model. Among them, the above-mentioned behavior detection information includes: behavior type, behavior risk level, and behavior-related content. The above-mentioned behavior-related content represents the service data stored in the above-mentioned service server end involved in the above-mentioned real-time network behavior data. Among them, the above-mentioned behavior type may be the type of network behavior that generates the above-mentioned real-time network behavior data. In practice, the above-mentioned behavior type may include, but is not limited to, abnormal data access type, targeted attack type, and non-targeted attack type. Among them, the above-mentioned behavior risk level may represent the degree of influence of the network behavior corresponding to the above-mentioned real-time network behavior data on the client network security. In practice, the above-mentioned behavior risk level may include low risk, medium risk, or high risk. In practice, the above-mentioned execution entity may generate behavior detection information for the real-time network behavior data by inputting the real-time network behavior data and the network behavior profile into the network behavior recognition model.
[0061] Optionally, the above-mentioned network behavior recognition model includes: a feature extraction model and a feature recognition model. The above-mentioned network behavior profile includes: a set of historical behavior monitoring information. Each piece of historical behavior monitoring information in the above-mentioned set of historical behavior monitoring information includes: historical behavior type, historical behavior risk level, and historical behavior-related content. Among them, the above-mentioned feature extraction model is used to extract features from the above-mentioned real-time network behavior data. The above-mentioned feature recognition model is used to recognize features of the above-mentioned real-time network behavior feature information. The above-mentioned feature extraction model is a model that takes the above-mentioned real-time network behavior data as the model input and the real-time network behavior feature information as the model output. The feature recognition model is a model that takes the real-time network behavior feature information as the model input and the behavior-related content as the model output. The above-mentioned historical behavior type may be the behavior type of the historical behavior. The historical behavior risk level may be the risk level of the historical behavior. The historical behavior-related content represents the service data stored in the above-mentioned service server end involved in the historical behavior corresponding to the above-mentioned historical network behavior data.
[0062] In some alternative implementation manners of some embodiments, the above-mentioned execution entity's generation of behavior detection information for the real-time network behavior data in response to detecting the real-time network behavior data according to the real-time network behavior data, the above-mentioned network behavior profile, and the pre-constructed network behavior recognition model may include the following steps:
[0063] First step, use the above-mentioned feature extraction model to extract features from the above-mentioned real-time network behavior data to generate real-time network behavior feature information.
[0064] Among them, the real-time network behavior feature information is the feature vector extracted by the feature extraction model from the above real-time network behavior data. Among them, the feature extraction model may include K serially connected convolutional layers.
[0065] In practice, the above-mentioned execution entity may input the above real-time network behavior data into the above feature extraction model to generate real-time network behavior feature information.
[0066] In the second step, input the above real-time network behavior feature information into the above feature recognition model to generate the content involved in the behavior.
[0067] As an example, the above feature recognition model may be a convolutional neural network model.
[0068] In practice, the above-mentioned execution entity may perform feature recognition on the above real-time network behavior feature information through the feature recognition model to generate the content involved in the behavior.
[0069] In the third step, perform similarity matching between the content involved in the above behavior and the content involved in each historical behavior monitoring information included in the above historical behavior monitoring information set to generate the behavior information similarity.
[0070] Among them, the behavior information similarity characterizes the information similarity degree between the content involved in the above behavior and the content involved in each historical behavior monitoring information included in the above historical behavior monitoring information set.
[0071] In practice, for the content involved in each historical behavior monitoring information included in the above historical behavior monitoring information set, first, the above-mentioned execution entity may perform vector conversion on the content involved in the above behavior through a pre-trained language model (Generative Pre-trained Transformer, GPT) to generate a content-involved behavior vector. Then, the above-mentioned execution entity may perform vector conversion on the above historical behavior-involved content through a pre-trained language model (Generative Pre-trained Transformer, GPT) to generate a historical behavior-involved content vector. Finally, the above-mentioned execution entity may determine the cosine similarity between the content-involved behavior vector and the historical behavior-involved content vector as the behavior information similarity to obtain a set of behavior information similarities.
[0072] In the fourth step, determine the historical behavior monitoring information in the above historical behavior monitoring information set whose corresponding behavior information similarity meets the similarity matching condition as the above behavior detection information.
[0073] Among them, the similarity matching condition is the maximum behavior information similarity in the above behavior information similarity set.
[0074] In practice, the above-mentioned execution entity may determine the behavior type, behavior risk level, and content involved in the historical behavior included in the historical behavior monitoring information whose behavior information similarity in the above-mentioned historical behavior monitoring information set meets the similarity matching condition as the behavior type, behavior risk level, and content involved in the above-mentioned behavior detection information.
[0075] Step 105, in response to the behavior type characterizing that the real-time network behavior data is abnormal network behavior data, perform the following processing steps:
[0076] Step 1051, perform network behavior control on the target client according to the behavior risk level.
[0077] In some embodiments, the above-mentioned execution entity may perform network behavior control on the above-mentioned target client according to the above-mentioned behavior risk level. In practice, the above-mentioned execution entity may perform different network behavior control methods on the target client according to different behavior risk levels.
[0078] In some alternative implementation manners of some embodiments, the above-mentioned execution entity performing network behavior control on the above-mentioned target client according to the above-mentioned behavior risk level may include the following steps:
[0079] First step, in response to determining that the above-mentioned behavior risk level is the first risk level, perform the following first control steps, where the above-mentioned first risk level may be a low risk:
[0080] First sub-step, send the above-mentioned behavior detection information to the above-mentioned target client to give a behavior warning to the above-mentioned target user.
[0081] In practice, the above-mentioned execution entity may give a behavior warning to the above-mentioned target user by sending the above-mentioned behavior detection information to the above-mentioned target client in real time.
[0082] Second sub-step, send a random digital verification code to the above-mentioned target client for identity verification.
[0083] Among them, the above-mentioned random digital verification code may be a verification code composed of randomly generated digits with a preset number of digits.
[0084] In practice, the above-mentioned execution entity may send a random digital verification code to the above-mentioned target client in real time for identity verification.
[0085] Second step, in response to determining that the above-mentioned behavior risk level is the second risk level, perform the following second control steps, where the above-mentioned second risk level may be a medium risk:
[0086] First sub-step, determine the current time. In practice, the above-mentioned execution entity may determine the real-time system time as the current time.
[0087] The second sub-step is to determine the behavior restriction time according to the above current time and the preset restriction time.
[0088] Among them, the above preset restriction time can be a preset time length. The behavior restriction time can be the time after adding the above current time and the above preset restriction time. For example, the above current time can be "2024-07-15-14:26", and the preset restriction time can be "24h", then the behavior restriction time is "2024-07-16-14:26".
[0089] The third sub-step is to restrict the target network behavior of the above target client before the time node represented by the above behavior restriction time. Among them, the behavior type of the above target network behavior is the same as the behavior type included in the above behavior detection information.
[0090] In practice, the above execution entity restricts the target network behavior of the above target client before the time node represented by the above behavior restriction time.
[0091] As an example, if the above target network behavior is an access behavior, from 2024-07-15-14:26 to 2024-07-16-14:26, the above execution entity can prohibit the access behavior of the above target client.
[0092] The third step is to, in response to determining that the above behavior danger level is the third danger level, execute the following third control step, where the above third danger level can be a high risk:
[0093] The first sub-step is to perform a forced offline process on the above target client.
[0094] The second sub-step is to update the network behavior source address included in the above historical network behavior data to the device access blacklist.
[0095] In practice, the above execution entity can add the network behavior source address included in the above historical network behavior data to the device access blacklist.
[0096] Step 1052 is to perform content access control on the content involved in the behavior according to the behavior type and the behavior danger level.
[0097] In some embodiments, the above execution entity can perform content access control on the content involved in the behavior according to the above behavior type and the above behavior danger level.
[0098] In some alternative implementation manners of some embodiments, the above execution entity performing content access control on the content involved in the behavior according to the above behavior type and the above behavior danger level may include the following steps:
[0099] In the first step, in response to determining that the above-mentioned behavior type is a non-directed network attack behavior, content access control is performed on the content involved in the above-mentioned behavior through a low-interaction honeypot.
[0100] In the second step, in response to determining that the above-mentioned behavior type is a directed network attack behavior, the following attack processing steps are performed on the content involved in the above-mentioned behavior through a high-interaction honeypot:
[0101] The first sub-step is to deploy the high-interaction honeypot to the business server corresponding to the content involved in the above-mentioned behavior.
[0102] The second sub-step is to create decoy content in the above-mentioned high-interaction honeypot.
[0103] Among them, the above-mentioned decoy content can be fake user data, files or database entries.
[0104] The third sub-step is to generate a log file through the above-mentioned high-interaction honeypot.
[0105] Among them, the above-mentioned log file can be an IP address, a user agent, and an operation behavior.
[0106] The fourth sub-step is to parse the above-mentioned log file to obtain attack technology information.
[0107] Among them, the above-mentioned attack technology information can be vulnerability exploitation, command injection, and remote code execution attempted by the attacker.
[0108] The fifth sub-step is to perform real-time access control on the attack behavior corresponding to the above-mentioned attack technology information according to the above-mentioned attack technology information. Among them, the above-mentioned real-time access control includes: blocking the communication address of the attacker.
[0109] Among them, the above-mentioned communication address can be an IP address.
[0110] In the third step, in response to determining that the above-mentioned behavior type represents an abnormal data access behavior, the following access processing steps are performed:
[0111] The first sub-step is to perform data signature processing on the content involved in the above-mentioned behavior to obtain the content involved in the behavior after signature.
[0112] In practice, the above-mentioned execution entity can perform data signature processing on the content involved in the above-mentioned behavior through the Digital Signature Algorithm (DSA) to obtain the content involved in the behavior after signature.
[0113] The second sub-step is to isolate and store the content involved in the behavior after signature.
[0114] In practice, the above-mentioned execution entity may store the content involved in the above-mentioned post-signature behavior in another database to isolate and store the content involved in the above-mentioned post-signature behavior.
[0115] The content in "in some alternative implementation manners of some embodiments" above, as an inventive point of the present disclosure, solves Technical Problem 2 mentioned in the background art, that is, "abnormal network behaviors, especially data intrusion-type abnormal network behaviors, are extremely likely to cause situations affecting data security such as data tampering when they cannot be effectively identified and intercepted." Based on this, in order to prevent situations affecting data security such as data tampering that are extremely likely to occur when they cannot be effectively identified and intercepted, different access control policies are set according to different behavior types. First, when the behavior type is a non-directed network attack behavior, the above-mentioned execution entity uses low-interaction honeypot technology to perform content access control on the content involved in the behavior. In a non-directed network attack, the attack source is often an automated attack script. These attack scripts do not have a clear target object and scan and verify network applications on the Internet in batches. This attack mode presents the characteristics of non-direction and low interaction. Therefore, a low-interaction honeypot is selected to perform content access control on the content involved in the behavior. Second, when the behavior type is a directed network attack behavior, the above-mentioned execution entity uses high-interaction honeypot technology to perform content access control on the content involved in the behavior. In a directed network attack, the attack is mostly participated in by the attacker himself. This attack has a clear target object, such as the official website homepage or the secondary domain name website of a certain sub-department. This attack mode often presents the characteristics of direction and high interaction. Therefore, a high-interaction honeypot is selected to perform content access control on the content involved in the behavior. Finally, when the behavior type is an abnormal data access behavior, the above-mentioned execution entity first performs data signature processing on the content involved in the behavior to obtain the content involved in the post-signature behavior. Then, the above-mentioned execution entity performs isolated storage on the content involved in the post-signature behavior to prevent data from being tampered with. By this means, implementing differentiated measures for different network behavior types can effectively identify and intercept abnormal network behaviors, thereby avoiding the data involved in the behavior from being tampered with or attacked, and further improving the security of the data.
[0116] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the network behavior detection method based on network behavior portraits in some embodiments of the present disclosure, the effective detection of abnormal network behaviors is achieved, avoiding damage to network devices such as servers caused by abnormal network behaviors, thereby improving the network device security of network devices such as servers. Specifically, the reasons for the inability to effectively and comprehensively detect and identify abnormal network behaviors are as follows: The configuration of network behavior templates often has a lag. At the same time, a large number of users often correspond to a large number of network behaviors with complex behavior types. Using the method of matching network behaviors with network behavior templates cannot effectively and comprehensively detect and identify abnormal network behaviors, and may thus cause damage to network devices such as servers due to abnormal network behaviors (such as network intrusion behaviors, etc.). Based on this, in some embodiments of the present disclosure, the network behavior detection method based on network behavior portraits first obtains the historical network behavior data of the target user collected by the relay server. Among them, the above-mentioned relay server is a server set between the target client and the business server for data forwarding and network behavior recording. The above-mentioned target user is a user who has not generated a corresponding network behavior portrait. The above-mentioned target user communicates with the above-mentioned business server through the above-mentioned target client. By analyzing the historical network behavior data of the user, a user portrait is established, providing data for the subsequent construction of the network behavior portrait. Secondly, the above-mentioned historical network behavior data is preprocessed to generate processed network behavior data. In practice, the historical network behavior data is collected by the relay server, and during the collection process, there may be cases of data loss (such as the appearance of null values). Therefore, by preprocessing the historical network behavior data, the data quality is helped to be improved. Then, through the pre-constructed network behavior portrait construction model and the above-mentioned processed network behavior data, the network behavior portrait of the above-mentioned target user is constructed to generate the network behavior portrait of the above-mentioned target user. In practice, using the pre-constructed network behavior portrait construction model and the above-mentioned processed network behavior data, the network behavior portrait of the above-mentioned target user is generated. In this way, automatic and efficient feature extraction is achieved, improving the accuracy of network behavior portrait construction. The network behavior portrait is dynamically updated, can be adjusted and updated in real time as the user's behavior changes, and has better adaptability and response speed. Then, in response to detecting real-time network behavior data, according to the above-mentioned real-time network behavior data, the above-mentioned network behavior portrait, and the pre-constructed network behavior recognition model, behavior detection information for the above-mentioned real-time network behavior data is generated. Among them, the above-mentioned behavior detection information includes: behavior type, behavior risk level, and behavior-related content. The above-mentioned behavior-related content represents the business data stored in the above-mentioned business server end involved in the above-mentioned real-time network behavior data. In practice, the real-time network behavior detection method based on the network behavior portrait can more accurately identify the normal behavior and abnormal behavior of the user, thereby effectively reducing the false alarm rate.Finally, in response to the above behavior type characterizing the above real-time network behavior data as abnormal network behavior data, the following processing steps are performed: the first step is to control the network behavior of the above target client according to the above behavior risk level. In practice, the behavior risk levels of different network behaviors are also different. Taking the same network behavior control may overreact. Therefore, it is necessary to perform different network behavior controls on the target client according to different behavior risk levels, so as to achieve the reasonable allocation and use of network resources. The second step is to perform content access control on the content involved in the above behavior according to the above behavior type and the above behavior risk level. In practice, when it fails to be effectively identified and intercepted, it is very easy for data to be tampered with and other situations that affect data security. Therefore, it is necessary to achieve effective content access control through classification. In this way, effective detection of abnormal network behavior is achieved, thereby timely controlling and reducing the damage of abnormal network behavior to network devices such as servers, thereby improving the network device security of network devices such as servers.
[0117] Further references Figure 2 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a network behavior detection device based on network behavior profiling. These device embodiments are similar to Figure 1 Corresponding to the method embodiments shown, the network behavior profiling-based network behavior detection device can be specifically applied to various electronic devices.
[0118] like Figure 2As shown in the figure, the network behavior detection device 200 based on network behavior portraits in some embodiments includes: an acquisition unit 201, a data preprocessing unit 202, a portrait construction unit 203, a generation unit 204, and an execution unit 205. Among them, the acquisition unit 201 is configured to acquire historical network behavior data collected by a relay server for a target user. The relay server is a server disposed between the target client and the service server for data forwarding and network behavior recording. The target user is a user who has not generated a corresponding network behavior portrait, and the target user communicates with the service server through the target client; the data preprocessing unit 202 is configured to perform data preprocessing on the historical network behavior data to generate processed network behavior data; the portrait construction unit 203 is configured to construct a network behavior portrait for the target user through a pre-constructed network behavior portrait construction model and the processed network behavior data to generate a network behavior portrait for the target user; the generation unit 204 is configured to, in response to detecting real-time network behavior data, generate behavior detection information for the real-time network behavior data according to the real-time network behavior data, the network behavior portrait, and a pre-constructed network behavior recognition model. The behavior detection information includes: behavior type, behavior risk level, and behavior-related content, and the behavior-related content represents the service data stored in the service server involved in the real-time network behavior data; the execution unit 205 is configured to, in response to the behavior type indicating that the real-time network behavior data is abnormal network behavior data, perform the following processing steps: perform network behavior control on the target client according to the behavior risk level; perform content access control on the behavior-related content according to the behavior type and the behavior risk level.
[0119] It can be understood that the units described in the network behavior detection device 200 based on network security portraits correspond to the respective steps in the method described in the reference Figure 1 Therefore, the operations, features, and beneficial effects described above for the method also apply to the network behavior detection device 200 based on network security portraits and the units included therein, and will not be elaborated here.
[0120] Next, refer to Figure 3 , which shows a schematic structural diagram of an electronic device (e.g., a computing device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present disclosure.
[0121] As Figure 3As shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to a program stored in the read-only memory 302 or a program loaded from the storage device 308 into the random access memory 303. In the random access memory 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the read-only memory 302, and the random access memory 303 are connected to each other through a bus 304. The input / output interface 305 is also connected to the bus 304.
[0122] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 the electronic device 300 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be implemented or had alternatively. Figure 3 Each block shown in may represent one device or, as needed, multiple devices.
[0123] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such some embodiments, the computer program may be downloaded and installed from the network through the communication device 309, or installed from the storage device 308, or installed from the read-only memory 302. When the computer program is executed by the processing device 301, the above functions defined in the methods of some embodiments of the present disclosure are executed.
[0124] It should be noted that the computer-readable media described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0125] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (Hyper Text Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0126] The above computer-readable medium may be included in the above electronic device; or it may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to: obtain historical network behavior data collected by a relay server for a target user, where the relay server is a server disposed between a target client and a service server for data forwarding and network behavior recording, the target user is a user for whom no corresponding network behavior profile has been generated, and the target user communicates with the service server through the target client; perform data preprocessing on the historical network behavior data to generate processed network behavior data; construct a network behavior profile for the target user through a pre-constructed network behavior profile construction model and the processed network behavior data to generate a network behavior profile for the target user; in response to detecting real-time network behavior data, generate behavior detection information for the real-time network behavior data according to the real-time network behavior data, the network behavior profile, and a pre-constructed network behavior recognition model, where the behavior detection information includes: behavior type, behavior risk level, and behavior-related content, and the behavior-related content represents the service data stored in the service server involved in the real-time network behavior data; if the behavior type represents that the real-time network behavior data is abnormal network behavior data, perform the following processing steps: perform network behavior control on the target client according to the behavior risk level; perform content access control on the behavior-related content according to the behavior type and the behavior risk level.
[0127] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).
[0128] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0129] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes an acquisition unit, a data preprocessing unit, an image construction unit, a generation unit, and an execution unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the acquisition unit can also be described as "the unit that acquires the historical network behavior data of the target user collected by the relay server".
[0130] The functions described above can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0131] The above description is only some preferred embodiments of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A network behavior detection method based on network behavior profiling, comprising: Obtaining historical network behavior data collected by a relay server for a target user, wherein the relay server is a server disposed between a target client and a service server for data forwarding and network behavior recording, the target user is a user who has not generated a corresponding network behavior profile, and the target user communicates with the service server through the target client; Performing data preprocessing on the historical network behavior data to generate processed network behavior data; Constructing a network behavior profile for the target user through a pre-constructed network behavior profile construction model and the processed network behavior data to generate a network behavior profile for the target user; In response to detecting real-time network behavior data, generating behavior detection information for the real-time network behavior data according to the real-time network behavior data, the network behavior profile, and a pre-constructed network behavior recognition model, wherein the behavior detection information includes: behavior type, behavior risk level, and behavior-related content, and the behavior-related content represents business data stored in the service server involved in the real-time network behavior data; In response to the behavior type representing that the real-time network behavior data is abnormal network behavior data, performing the following processing steps: Performing network behavior control on the target client according to the behavior risk level; Performing content access control on the behavior-related content according to the behavior type and the behavior risk level, including: In response to determining that the behavior type is a non-directed network attack behavior, performing content access control on the behavior-related content through a low-interaction honeypot; In response to determining that the behavior type is a directed network attack behavior, performing the following attack processing steps on the behavior-related content through a high-interaction honeypot: Deploying the high-interaction honeypot to the service server corresponding to the behavior-related content; Creating decoy content in the high-interaction honeypot, wherein the decoy content is fake user data, files, or database entries; Generating a log file through the high-interaction honeypot; Parsing the log file to obtain attack technique information; Performing real-time access control on the attack behavior corresponding to the attack technique information according to the attack technique information, wherein the real-time access control includes: blocking the communication address of the attacker; In response to determining that the behavior type represents abnormal data access behavior, performing the following access processing steps: Performing data signature processing on the behavior-related content to obtain the behavior-related content after signature; Storing the behavior-related content after signature in isolation; Among them, the network behavior recognition model includes: a feature extraction model and a feature recognition model. The network behavior portrait includes: a historical behavior monitoring information set. Each historical behavior monitoring information in the historical behavior monitoring information set includes: a historical behavior type, a historical behavior risk level, and historical behavior-related content. And in response to detecting real-time network behavior data, according to the real-time network behavior data, the network behavior portrait, and a pre-constructed network behavior recognition model, behavior detection information for the real-time network behavior data is generated, including: Through the feature extraction model, feature extraction is performed on the real-time network behavior data to generate real-time network behavior feature information; Input the real-time network behavior feature information into the feature recognition model to generate behavior-related content; Perform similarity matching between the behavior-related content and the historical behavior-related content included in each historical behavior monitoring information in the historical behavior monitoring information set to generate a behavior information similarity; Determine the historical behavior monitoring information in the historical behavior monitoring information set whose corresponding behavior information similarity meets the similarity matching condition as the behavior detection information. Among them, determine the behavior type, behavior risk level, and behavior-related content included in the historical behavior monitoring information in the historical behavior monitoring information set whose corresponding behavior information similarity meets the similarity matching condition as the behavior type, behavior risk level, and behavior-related content included in the behavior detection information.
2. The method according to claim 1, wherein, The historical network behavior data includes: static behavior data and dynamic behavior data. The static behavior data includes: collection time, network behavior source address, and network behavior target address. And performing data preprocessing on the historical network behavior data to generate processed network behavior data includes: In response to determining that the collection time does not meet the first elimination condition, perform time standardization on the collection time to obtain the standardized collection time; In response to determining that the address type of the network behavior source address is the first address type, perform address mapping on the network behavior source address to obtain the mapped network behavior source address; In response to the address type of the network behavior target address being the first address type, perform address mapping on the network behavior target address to obtain the mapped network behavior target address; Determine the standardized collection time, the mapped network behavior source address, and the mapped network behavior destination address as the preprocessed static behavior data; Determine the preprocessed static behavior data and the dynamic behavior data as the processed network behavior data.
3. The method according to claim 2, wherein The network behavior portrait construction model includes: a static behavior feature extraction model, a dynamic behavior feature extraction model, and a portrait generation model. And constructing a network behavior portrait for the target user through a pre-constructed network behavior portrait construction model and the processed network behavior data to generate a network behavior portrait for the target user, including: Input the preprocessed static behavior data into the static behavior feature extraction model to generate static behavior feature information; Input the dynamic behavior data into the dynamic behavior feature extraction model to generate dynamic behavior feature information; Perform dimensionality reduction processing on the static behavior feature information and the dynamic behavior feature information respectively to obtain the dimensionality-reduced static behavior feature information and the dimensionality-reduced dynamic behavior feature information; Generate the network behavior portrait according to the portrait generation model, the dimensionality-reduced static behavior feature information, and the dimensionality-reduced dynamic behavior feature information.
4. The method according to claim 3, wherein, The network behavior control of the target client according to the behavior risk level includes: In response to determining that the behavior risk level is the first risk level, execute the following first control step: Send the behavior detection information to the target client to give a behavior warning to the target user; Send a random digital verification code to the target client for identity verification; In response to determining that the behavior risk level is the second risk level, execute the following second control step: Determine the current time; Determine the behavior restriction time according to the current time and the preset restriction time; Before the time node represented by the behavior restriction time, restrict the target network behavior of the target client, where the behavior type of the target network behavior is the same as the behavior type included in the behavior detection information; In response to determining that the behavior risk level is the third risk level, execute the following third control step: Perform a forced offline process on the target client; Update the network behavior source address included in the historical network behavior data to the device access blacklist.
5. A network behavior detection device based on a network behavior portrait, comprising: An acquisition unit configured to acquire historical network behavior data of a target user collected by a relay server, where the relay server is a server disposed between the target client and the service server for data forwarding and network behavior recording, the target user is a user who has not generated a corresponding network behavior portrait, and the target user communicates with the service server through the target client; A data preprocessing unit configured to perform data preprocessing on the historical network behavior data to generate processed network behavior data; A portrait construction unit configured to construct a network behavior portrait of the target user through a pre-constructed network behavior portrait construction model and the processed network behavior data to generate a network behavior portrait for the target user; A generation unit configured to, in response to detecting real-time network behavior data, generate behavior detection information for the real-time network behavior data according to the real-time network behavior data, the network behavior portrait, and a pre-constructed network behavior recognition model, where the behavior detection information includes: behavior type, behavior risk level, and behavior-related content, and the behavior-related content represents the service data stored in the service server involved in the real-time network behavior data; An execution unit configured to, in response to the behavior type indicating that the real-time network behavior data is abnormal network behavior data, execute the following processing steps: Perform network behavior control on the target client according to the behavior risk level; Perform content access control on the content involved in the behavior according to the behavior type and the behavior risk level, including: In response to determining that the behavior type is a non-directed network attack behavior, perform content access control on the content involved in the behavior through a low-interaction honeypot; In response to determining that the behavior type is a directed network attack behavior, perform the following attack processing steps on the content involved in the behavior through a high-interaction honeypot: Deploy the high-interaction honeypot to the business server corresponding to the content involved in the behavior; Create decoy content in the high-interaction honeypot, where the decoy content is fake user data, files, or database entries; Generate a log file through the high-interaction honeypot; Parse the log file to obtain attack technique information; Perform real-time access control on the attack behavior corresponding to the attack technique information according to the attack technique information, where the real-time access control includes: blocking the communication address of the attacker; In response to determining that the behavior type represents an abnormal data access behavior, perform the following access processing steps: Perform data signature processing on the content involved in the behavior to obtain the content involved in the behavior after signature; Isolate and store the content involved in the behavior after signature; Wherein, the network behavior recognition model includes: a feature extraction model and a feature recognition model, the network behavior portrait includes: a historical behavior monitoring information set, and each historical behavior monitoring information in the historical behavior monitoring information set includes: a historical behavior type, a historical behavior risk level, and historical content involved in the behavior; The generating unit is further configured to: Extract features from the real-time network behavior data through the feature extraction model to generate real-time network behavior feature information; Input the real-time network behavior feature information into the feature recognition model to generate content involved in the behavior; Perform similarity matching between the content involved in the behavior and the historical content involved in the behavior included in each historical behavior monitoring information in the historical behavior monitoring information set to generate a behavior information similarity; Determine the historical behavior monitoring information corresponding to the behavior information similarity in the historical behavior monitoring information set that meets the similarity matching condition as the behavior detection information, where determining the behavior type, behavior risk level, and content involved in the behavior included in the behavior detection information from the historical behavior type, historical behavior risk level, and historical content involved in the behavior included in the historical behavior monitoring information corresponding to the behavior information similarity in the historical behavior monitoring information set that meets the similarity matching condition.
6. An electronic device, including: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.
7. A computer-readable medium having a computer program stored thereon, wherein, The computer program, when executed by a processor, implements the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Method and device for identifying abnormal login
CN111400357A
Internet of Things equipment risk control method and system based on equipment portrait
CN111565390A