Log auditing method and device
By constructing and correlating time distribution charts of user operation logs, regular user behavior can be identified, solving the problem of inaccurate identification of abnormal operations in existing technologies and achieving efficient log auditing and security risk monitoring.
Patent Information
- Application Number
- CN202410595384.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-14
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-05-14
AI Technical Summary
Existing log auditing methods cannot accurately identify abnormal user operations within their authorized scope, resulting in low log auditing efficiency, and users can mitigate risks by changing access policies.
By constructing and correlating time distribution charts of user operation logs, we can identify users' regular operational behaviors, use image analysis methods to determine the regularity of operation frequency, and identify abnormal users.
It improves log analysis efficiency, accurately identifies patterns in user behavior, avoids inefficiencies caused by processing large amounts of log content, and promptly detects potential security risks.
Smart Images

Figure CN118802470B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer, and particularly relates to a log auditing method and device. BACKGROUND
[0002] Log auditing can help users to find security risks existing in the network in time, accurately perform post-evidence collection, and thus can more effectively guarantee the safe operation of the network. Related log auditing methods mainly include two types: one type is based on the auditing of operation contents of operation logs, and the other type is by processing original logs collected from various data platform components.
[0003] However, the log auditing method of the related art is usually based on the legality of operation contents to determine whether the operation of a user is in violation, but if the user is operating within the permission range, it is impossible to accurately determine whether the operation of the user is abnormal, so that the log auditing efficiency of the related art is low. SUMMARY
[0004] The present disclosure provides a log auditing method and device.
[0005] According to a first aspect of the present disclosure, a log auditing method is provided, and the method comprises:
[0006] obtaining an operation log of a target user, the operation log comprising operation times of the target user in a target time period, the target time period comprising a plurality of unit time periods, each unit time period comprising a plurality of sub-unit time periods;
[0007] based on the operation times of the target user in each unit time period, in a case where it is determined that the operation times of the target user in adjacent M unit time periods in the target time period have regularity, counting the operation times of the target user in each sub-unit time period;
[0008] based on the operation times of the target user in each sub-unit time period, in a case where it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, determining that the target user is an abnormal user; wherein M and N are both positive integers.
[0009] According to a second aspect of the present disclosure, a log auditing device is provided, and the device comprises:
[0010] a log obtaining module configured to obtain an operation log of a target user, the operation log comprising operation times of the target user in a target time period, the target time period comprising a plurality of unit time periods, each unit time period comprising a plurality of sub-unit time periods;
[0011] The operation frequency counting module is configured to count operation frequencies of the target user in each sub-unit time period based on operation frequencies of the target user in each unit time period, in a case where it is determined that the operation frequencies of the target user in adjacent M unit time periods in a target time period have regularity.
[0012] The abnormal user determining module is configured to determine that the target user is an abnormal user based on the operation frequencies of the target user in each sub-unit time period, in a case where it is determined that the operation frequencies of the target user in adjacent N sub-unit time periods in each unit time period have regularity. M and N are both positive integers.
[0013] According to a third aspect of the present disclosure, an electronic device is provided. The electronic device includes a memory and a processor, the memory having stored thereon a computer program, the processor implementing the method as described above when executing the program.
[0014] According to a fourth aspect of the present disclosure, a computer readable storage medium is provided, having stored thereon a computer program, the program being executed by a processor to implement the method as described above.
[0015] The log auditing method and device provided by the embodiments of the present disclosure count operation frequencies of a target user in each sub-unit time period based on operation frequencies of the target user in each unit time period, in a case where it is determined that the operation frequencies of the target user in adjacent M unit time periods in a target time period have regularity. The target user is determined to be an abnormal user based on the operation frequencies of the target user in each sub-unit time period, in a case where it is determined that the operation frequencies of the target user in adjacent N sub-unit time periods in each unit time period have regularity. Thus, by counting operation frequencies in user operation logs, regular behaviors of user operation behaviors can be accurately determined, and the situation of low log analysis efficiency caused by processing a large amount of log content can be avoided. BRIEF DESCRIPTION OF DRAWINGS
[0016] More details, features and advantages of the present disclosure are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:
[0017] Figure 1 A schematic diagram of a graph corresponding to counting operation frequencies by day is provided for an exemplary embodiment of the present disclosure;
[0018] Figure 2 A schematic diagram of a graph corresponding to counting operation frequencies by hour is provided for an exemplary embodiment of the present disclosure;
[0019] Figure 3 A time matrix schematic diagram is provided for an exemplary embodiment of the present disclosure;
[0020] Figure 4 Time matrix division diagram provided for an exemplary embodiment of the present disclosure;
[0021] Figure 5 Non-empty matrix comparison diagram provided for an exemplary embodiment of the present disclosure;
[0022] Figure 6 Flow chart of log auditing method provided for an exemplary embodiment of the present disclosure;
[0023] Figure 7 Functional module schematic block diagram of log auditing device provided for an exemplary embodiment of the present disclosure;
[0024] Figure 8 Structural block diagram of electronic device provided for an exemplary embodiment of the present disclosure;
[0025] Figure 9 Structural block diagram of computer system provided for an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0026] Embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein, but rather the embodiments are provided so that the present disclosure can be more thoroughly and completely understood. It should be understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.
[0027] It should be understood that each step recited in the method embodiments of the present disclosure can be executed in different order and / or in parallel. In addition, the method embodiments can include additional steps and / or omit the execution of the steps shown. The scope of the present disclosure is not limited in this respect.
[0028] The term "comprising" and variations thereof as used herein are open-ended, that is, "comprising but not limited to". The term "based on" is "based, at least in part, on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Related definitions are given below in the description of the application. It should be noted that the concepts of "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units.
[0029] It should be noted that the modification of "one", "multiple" mentioned in the present disclosure is illustrative but not restrictive, and those skilled in the art should understand that "one or more" should be understood unless otherwise explicitly indicated in the context.
[0030] The names of the messages or information exchanged between the plurality of devices in the embodiments of the present disclosure are only for illustrative purposes, and are not used to limit the scope of the messages or information.
[0031] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario, etc. of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0032] For example, in response to receiving the active request of the user, the user is sent prompt information to explicitly prompt the user that the operation requested to be performed will require obtaining and using the personal information of the user. Thus, the user can voluntarily choose whether to provide the personal information to the software or hardware such as electronic device, application program, server or storage medium, etc. that performs the operation of the technical solutions of the present disclosure according to the prompt information.
[0033] As an optional but not limited implementation manner, in response to receiving the active request of the user, the prompt information can be sent to the user in the form of a pop-up window, and the prompt information can be presented in the form of text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide personal information to the electronic device. It can be understood that the above notification and obtaining of user authorization process is only illustrative, and does not limit the implementation manner of the present disclosure, and other ways that meet the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0034] In order to maintain network security, the log audit manner of the related art is mainly divided into the following categories: one category is based on the audit of the operation content of the operation log record, the operation command is decomposed, when illegal operation is detected, a warning information is issued, and the illegal operation is extracted, so as to find the user operation risk behavior existing in the operation log. One category is to parse the original log collected from various data platform components, field standardization mapping, and log operation type and operation item division processing, standardize the initial log, and then use corresponding audit rules and analysis strategies to automatically audit and analyze the standardized log. One category is to use user basic information data, user behavior data and business data as user behavior feature data to construct a user behavior prediction model, when the user behavior log does not match the prediction model, an alarm is issued in time, or relevant measures are taken to stop the user from continuing abnormal operation in time.
[0035] The log auditing strategy in the related art needs to define the abnormal behavior content in advance, or use the method of machine learning to train the model of the normal operation behavior of the user, and then discover the abnormal risk existing in the log according to the rules of the auditing strategy. However, the related art has the problems of poor discovery effect of the regular operation of the user, high model training cost, and poor applicability to a large number of users.
[0036] Specifically, the log auditing manner of the related art, regardless of what key content is audited, ultimately judges whether the user operation is illegal according to the legality of the operation content. However, if the user operates within the permission range, regardless of whether the operation is performed multiple times (such as frequently, uninterruptedly, or in batches), whether the operation is reasonable and meets the actual needs of the business, the problem cannot be audited, so that illegal operation of the user within the permission range still occurs in the related art.
[0037] In addition, the manner of identifying the regular operation of the related art generally has very fixed rules, such as consistent operation times within a certain time range or consistent operation time intervals. However, after the rules are identified once, the user can quickly change the access strategy to avoid the risk of being audited again after receiving the feedback of the limitation. In addition, after setting the automatic program to operate, the user inserts the manual operation behavior in the automatic operation, the regularity of the log record is broken, and the identification failure occurs, so that the related art has low identification efficiency for the regular operation.
[0038] Therefore, to solve the above technical problems, the embodiments of the present disclosure point the time of the operation log of the unified user, form the operation time distribution graph of the unit time, and identify the regular operation behavior of the user through the correlation analysis of the time distribution graph. When analyzing the operation log, only the operation type, the username, and the operation time in the operation log can be extracted, which can improve the log analysis efficiency to a great extent when processing a large number of logs.
[0039] It should be noted that the user involved in the embodiments of the present disclosure can be an operator user, that is, a person who can log in to the system, operate the system, and help the ordinary user of the system to perform transaction processing and other related work. The user can log in to the system to query the personal data or business data of the ordinary user, and the embodiments are not limited thereto.
[0040] The operation log in the embodiments can be the log recorded by the system when the user operates the system, and the content thereof can at least include the username, operation time, and operation content. The key information can be the username, operation time, and operation content in the user operation log recorded by the system, such as login information, query information, and download content.
[0041] Specifically, in the embodiments, the operation log of the user in a period of time can be acquired, and the key information of the operation log of the user is extracted and processed, and the operation time of each user is extracted according to the operation type. The operation type can be data downloading or data viewing, and the embodiments are not limited thereto.
[0042] In order to identify that some users download or view the user data of the personal user by writing scripts and other means by using the user's own user rights, and then obtain illegal benefits, it is necessary to identify the regularity of the operation behavior of the user. By acquiring the operation log of the user, whether the operation behavior of the user exists regular behavior is identified.
[0043] Specifically, the operation times of the user are acquired through the operation log of the user, for example, the operation times per day can be counted, and the operation times per day of the user in a period of time can be D1, D2, D3, …, D x , and the operation times per day of the user are converted into a column chart, as shown in Figure 1 , and taking 30 as an example for illustration, and by using the image analysis method, whether the pattern composed of the maximum adjacent days m (m is greater than or equal to 2) repeatedly appears in the column chart is judged, and d times of error per day is allowed, and generally d is set to a certain proportion of the operation times of m days. The same pattern appears, that is, the operation of the m adjacent days is regular, such as D4-D8. Wherein, x, m and d are integers.
[0044] Similarly, after it is determined that the operation of the m adjacent days is regular, D x -D (x+m) need to be further analyzed and determined. The operation times of D x are counted by hours, and the times are H1, H2, H3, …, H x , and the operation times of D x are converted into a column chart, as shown in Figure 2 , and by using the image analysis method, whether the pattern composed of the maximum adjacent hours n (n is greater than or equal to 2 and less than or equal to 12) repeatedly appears in the column chart is judged (h times of error per hour is allowed, and generally h is set to a certain proportion of the operation times of n hours), and the same pattern appears, that is, the operation of the n adjacent hours is regular, such as H7-H9. Wherein, n and h are integers.
[0045] In the embodiments, by the above-mentioned manner, it can be determined that the operation of the n adjacent hours in more than y days in x days is regular, and it can be determined that the operation behavior of the user exists regular behavior in the hour dimension. Wherein, y is an integer greater than zero and less than x, and y can be a threshold value set according to the need.
[0046] Through the judgment of the above embodiment, in the case where it is determined that the operation behavior of the user has regular behavior in the hour dimension, the operation log in the hour dimension can be further analyzed, and the operation time of the user per hour is mapped in a 60*60 matrix T with the vertical axis as minutes and the horizontal axis as seconds, as shown in Figure 3 If there are multiple operation logs of the user in 1 second, 1 is counted, and the user operation time matrix T0-T 23 is formed. Among them, Figure 3 The horizontal axis represents 1 second from left to right, that is, the horizontal axis represents 0-59 seconds. Each grid in the vertical axis represents 1 minute, that is, the horizontal axis represents 0-59 minutes. T ab in the matrix represents the operation log of the user in the a-th minute and the b-th second. If T ab is not empty, it can be set to 1, otherwise it is set to 0, Figure 3 The empty space filled in the matrix indicates that there is a corresponding operation log.
[0047] For a non-empty matrix, as shown in Figure 4 T x can be divided into 9 sub-regions: T x00 , T x01 , T x02 , T x10 , T x11 , T x12 , T x20 , T x21 and T x22 .
[0048] In the embodiment, it can be judged in turn whether the above 9 sub-regions are empty. If they are empty, they are not considered (such as Tx20 and Tx21), and the non-empty sub-regions are checked and judged. For example, the non-empty sub-regions in each hour can be compared to determine whether there is a similar case. If there is a case where the non-empty sub-region of a certain hour has a similarity greater than a threshold value with the non-empty sub-regions of other C hours, it can be determined that the operation log of the user has regularity.
[0049] For example, as shown in Figure 5 The non-empty sub-regions in the matrix are moved up, down, left and right, and it is determined whether the sub-region appears in the operation time matrix of the user. If it exists (such as Tx00), it means that the operation has regularity.
[0050] Based on the above embodiment, the present embodiment also provides a log auditing method, as shown in Figure 6 The method can include the following steps:
[0051] In step S610, the operation log of the target user is obtained, and the operation log includes the operation times of the target user in the target time period.
[0052] The target time period includes multiple unit time periods, and each unit time period includes multiple sub-unit time periods.
[0053] In this embodiment, the target time period can be set as needed, for example, it can be 30 days, but the embodiment is not limited to this. The target time period includes multiple unit time periods, which can specifically be 1 day or 1 week, etc., and can be set as needed. Each unit time period includes multiple sub-unit time periods. If the unit time period is 1 week, then the sub-unit time period can specifically be 1 day; if the unit time period is 1 day, the sub-unit time period can specifically be 1 hour, and can be set as needed, but the embodiment is not limited to this.
[0054] In step S620, based on the number of operations performed by the target user within each unit time period, and after determining that the number of operations performed by the target user within M adjacent unit time periods in the target time period is regular, the number of operations performed by the target user within each sub-unit time period is counted.
[0055] In this embodiment, by obtaining the number of operations performed by the target user within each unit time period, if the number of operations performed by the user occurs repeatedly every M unit time periods, it indicates that the number of operations performed by the target user within adjacent M unit time periods in the target time period is regular. This allows for further statistical analysis of the number of operations performed by the target user within each sub-unit time period.
[0056] Specifically, the number of operations performed by the target user within each time unit can be counted and converted into target graphics. By obtaining the similarity between target graphics in M adjacent time units, and if the similarity is greater than a first threshold, it can be determined that the number of operations performed by the target user in the M adjacent time units within the target time period exhibits a regularity.
[0057] like Figure 1 As shown, the target graph can specifically be a bar chart. Taking a target time period of 30 days as an example, by counting the number of user operations each day, a sliding window containing M days can be set. This sliding window is then slid across the target graph, and M can start from 1 and increase incrementally. When the similarity between the bar chart corresponding to the number of operations in the first M days and the bar chart corresponding to the number of operations in the last M days is greater than a first threshold during the sliding process of the window, it indicates that the number of operations by the target user in adjacent M unit time periods within the target time period is regular.
[0058] In step S630, based on the operation times of the target user in each sub-unit time period, in a case where it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, the target user is determined to be an abnormal user. M and N are both positive integers.
[0059] In the embodiment, in a case where it is determined that the operation times of the target user in adjacent M unit time periods in the target time period have regularity, the operation times of the target user in each sub-unit time period can be further counted, and it is determined whether the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity. In a case where it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, the target user can be determined to be an abnormal user.
[0060] Specifically, the operation times of the target user in each sub-unit time period in the target unit time period can be counted, and the operation times in each sub-unit time period can be converted into a target graph. The similarity between the target graphs in adjacent N sub-unit time periods can be obtained, and in a case where the similarity is greater than a second threshold, it is determined that the operation times of the target user in adjacent N sub-unit time periods in the target unit time period have regularity. In this way, the number of target unit time periods in which the regularity exists can be counted, and in a case where the proportion of the target time period is greater than a preset proportion, it can be determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, and thus the target user can be determined to be an abnormal user. At this time, a warning can be issued so as to take reasonable measures to avoid further risks such as data leakage.
[0061] may be combined Figure 2 As shown in FIG. 6, the target graph can be a column chart, and the operation times of the user per hour can be counted and converted into a column chart. Similarly, a sliding window containing N hours can be set, and the sliding window can be slid on the target graph. When the similarity between the column chart corresponding to the operation times of the previous N hours and the column chart corresponding to the operation times of the subsequent N hours in the window sliding process is greater than a second threshold, it indicates that the operation times of the target user in adjacent N unit time periods in the target time period have regularity. The N can be increased from 1, and if there is no operation time with the above regularity, the value contained in the sliding window is increased by 1, and the maximum can be 60, until the operation times of the target user in adjacent N unit time periods in the target time period have regularity.
[0062] The log auditing method provided by the embodiments of the present disclosure can obtain the operation log of a target user, and based on the operation times of the target user in each unit time period, when it is determined that the operation times of the target user in adjacent M unit time periods in a target time period have regularity, the operation times of the target user in each sub-unit time period are counted. Based on the operation times of the target user in each sub-unit time period, when it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, the target user is determined to be an abnormal user. In this way, by counting the operation times in the user operation log, the regularity of the user operation behavior can be accurately determined, and the situation of low log analysis efficiency caused by processing a large amount of log content can be avoided.
[0063] Based on the above embodiments, when it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, the method can further include the following steps:
[0064] In step S640, it is determined whether the operation times of the target user in a target sub-unit time period in a target unit time period have regularity.
[0065] In step S650, when the operation times of the target user in the target sub-unit time period in the target unit time period have regularity, the target user is determined to be an abnormal user.
[0066] In the embodiments, when it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, in order to more accurately determine whether the target user is an abnormal user, the operation times of the target user in a target sub-unit time period in a target unit time period can be further determined to have regularity. If the operation times of the target user in the target sub-unit time period in the target unit time period have regularity, the target user can be determined to be an abnormal user, which can improve the accuracy of abnormal user determination.
[0067] Specifically, in the embodiments, the operation times of the target user in a target sub-unit time period in a target unit time period can be obtained, and a target matrix can be generated based on the operation times in the target sub-unit time period. The rows of the target matrix represent the operation times of the target user per minute, and the columns of the target matrix represent the operation times of the target user per second. The target matrix can be divided into multiple sub-regions, and the similarity between the multiple sub-regions can be calculated. When it is determined based on the similarity that there is a sub-region with a similarity greater than a third threshold value in the multiple sub-regions, it is determined that the operation times of the target user in the target sub-unit time period have regularity.
[0068] In the embodiment, the target sub-unit time period can be specifically 1 day, or several hours, or 1 hour, etc., and can be set according to actual needs, and the embodiment is not limited thereto.
[0069] By obtaining the operation times of the target user in the target unit time period, the operation times can be converted into a target matrix. For example, in the case that the target unit sub-time period is 1 day, the operation times of the user per second in 24 hours in the 1 day can be obtained. By generating a target matrix containing the operation times of the user in the 24 hours, the positions of the target matrix that do not contain the operation times of the user can be set to be empty or 0, and the target matrix can be divided into a plurality of sub-regions. By judging whether the similarity between the corresponding patterns of the sub-regions is greater than a third threshold value, for example, by translation or up and down movement, it can be determined whether the operation times of the target user in the target sub-unit time period have regularity in combination with Figure 5 If the operation times of the target user in the target sub-unit time period have regularity, it can be determined that the operation times of the target user in the target sub-unit time period have regularity.
[0070] In the embodiment, it can be specifically detected whether there is an empty sub-region that does not contain operation times in the plurality of sub-regions. If there is an empty sub-region that does not contain operation times in the plurality of sub-regions, the empty sub-region is removed from the plurality of sub-regions. By comparing the similarity between the non-empty sub-regions, the interference caused by the empty sub-region can be avoided, so that the detection efficiency of whether the operation times of the target user in the target sub-unit time period have regularity can be improved.
[0071] In the case of dividing the function modules corresponding to the functions, the log auditing device provided by an example embodiment of the present disclosure is a server, a terminal, or a chip applied to a server. Figure 7 A functional module schematic diagram of the log auditing device provided by an example embodiment of the present disclosure is shown in FIG. 2. Figure 7 As shown in FIG. 2, the log auditing device includes:
[0072] A log obtaining module 10 is configured to obtain an operation log of a target user, the operation log including operation times of the target user in a target time period, the target time period including a plurality of unit time periods, and each unit time period including a plurality of sub-unit time periods.
[0073] An operation time counting module 20 is configured to count operation times of the target user in each sub-unit time period based on the operation times of the target user in each unit time period, in a case where it is determined that the operation times of the target user in adjacent M unit time periods in the target time period have regularity.
[0074] The abnormal user determination module 30 is configured to determine the target user as an abnormal user in a case that the target user has regularity in the operation times in the adjacent N sub-unit time periods in each unit time period based on the operation times of the target user in each sub-unit time period, wherein M and N are positive integers.
[0075] In another embodiment provided by the present disclosure, the device further comprises:
[0076] The first graph conversion module is configured to count the operation times of the target user in each unit time period and convert the operation times of the target user in each unit time period into a target graph.
[0077] The second regularity determination module is configured to obtain the similarity between the target graphs in the adjacent M unit time periods and determine that the target user has regularity in the operation times in the adjacent M unit time periods in the target time period in a case that the similarity is greater than a first threshold.
[0078] In another embodiment provided by the present disclosure, the device further comprises:
[0079] The second graph conversion module is configured to count the operation times of the target user in each sub-unit time period in the target unit time period and convert the operation times in each sub-unit time period into a target graph.
[0080] The second regularity determination module is configured to obtain the similarity between the target graphs in the adjacent N sub-unit time periods and determine that the target user has regularity in the operation times in the adjacent N sub-unit time periods in the target unit time period in a case that the similarity is greater than a second threshold.
[0081] The third regularity determination module is configured to determine that the target user has regularity in the operation times in the adjacent N sub-unit time periods in each unit time period in a case that the proportion of the target time period is greater than a preset proportion.
[0082] In another embodiment provided by the present disclosure, in the case that the target user has regularity in the operation times in the adjacent N sub-unit time periods in each unit time period, the device further comprises:
[0083] The regularity judgment module is configured to judge whether the target user has regularity in the operation times in the target sub-unit time period in the target unit time period.
[0084] The abnormal user determination module is further configured to determine the target user as an abnormal user in a case that the target user has regularity in the operation times in the target sub-unit time period in the target unit time period.
[0085] In a further embodiment provided by the present disclosure, the device further comprises a fourth regularity determining module, specifically configured to:
[0086] obtaining the operation times of the target user in the target unit time period;
[0087] generating a target matrix based on the operation times in the target subunit time period, wherein a row of the target matrix represents the operation times per minute of the target user, and a column of the target matrix represents the operation times per second of the target user;
[0088] dividing the target matrix into a plurality of subareas, and calculating the similarity between the plurality of subareas;
[0089] when it is determined that there is a subarea with a similarity greater than a third threshold value in the plurality of subareas based on the similarity, determining that the operation times of the target user in the target subunit time period have regularity.
[0090] In a further embodiment provided by the present disclosure, the device further comprises a subarea processing module, specifically configured to:
[0091] detecting whether there is an empty subarea that does not contain operation times in the plurality of subareas;
[0092] when there is an empty subarea that does not contain operation times in the plurality of subareas, removing the empty subarea from the plurality of subareas.
[0093] The device part will be described in the method embodiment, and will not be described here.
[0094] The log audit device provided by the embodiment of the present disclosure obtains the operation log of the target user, and based on the operation times of the target user in each unit time period, when it is determined that the operation times of the target user in adjacent M unit time periods in a target time period have regularity, the operation times of the target user in each subunit time period are counted. Based on the operation times of the target user in each subunit time period, when it is determined that the operation times of the target user in adjacent N subunit time periods in each unit time period have regularity, the target user is determined to be an abnormal user.
[0095] The embodiment of the present disclosure also provides an electronic device, comprising: at least one processor; a memory for storing instructions executable by the at least one processor; wherein the at least one processor is configured to execute the instructions to implement the above-mentioned method disclosed by the embodiment of the present disclosure.
[0096] Figure 8 The structural schematic diagram of the electronic device provided by an exemplary embodiment of the present disclosure is shown in FIG. 1. Figure 8As shown, the electronic device 1800 includes at least one processor 1801 and a memory 1802 coupled to the processor 1801, which can perform the corresponding steps in the above-described method disclosed by the embodiments of the present disclosure.
[0097] The processor 1801 described above can also be referred to as a central processing unit (CPU), which can be an integrated circuit chip with a processing capability of signals. Each step in the above-described method disclosed by the embodiments of the present disclosure can be completed by the integrated logic circuit of hardware or the instructions in the form of software in the processor 1801. The processor 1801 described above can be a general-purpose processor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a ready-to-program gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present disclosure can be directly embodied as a hardware decoding processor for execution, or a combination of hardware and software modules in the decoding processor for execution. The software module can be located in the memory 1802, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register or other mature storage medium in the art. The processor 1801 reads the information in the memory 1802 and completes the steps of the above-described method in conjunction with the hardware thereof.
[0098] In addition, various operations / processes according to the present disclosure are implemented by software and / or firmware, which can be loaded from a storage medium or a network to a computer system with a special hardware structure, such as a general-purpose computer system. Figure 9 The computer system 1900 shown is installed with programs constituting the software, and when various programs are installed, the computer system can perform various functions, including functions such as those described above. Figure 9 The structural block diagram of the computer system provided for an exemplary embodiment of the present disclosure is shown.
[0099] The computer system 1900 is intended to represent various forms of digital electronic computer devices, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the present disclosure described and / or claimed in this document.
[0100] As shown in Figure 9 The computer system 1900 includes a computing unit 1901 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 1902 or a computer program loaded from a storage unit 1908 into a random access memory (RAM) 1903. Various programs and data required for the operation of the computer system 1900 can also be stored in the RAM 1903. The computing unit 1901, the ROM 1902, and the RAM 1903 are connected to each other through a bus 1904. An input / output (I / O) interface 1905 is also connected to the bus 1904.
[0101] Various components in the computer system 1900 are connected to the I / O interface 1905, including an input unit 1906, an output unit 1907, the storage unit 1908, and a communication unit 1909. The input unit 1906 can be any type of device that can input information to the computer system 1900, and can receive inputted digital or character information, and generate key signal inputs related to user settings and / or function controls of the electronic device. The output unit 1907 can be any type of device that can present information, and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 1908 can include, but is not limited to, a magnetic disk, an optical disk. The communication unit 1909 allows the computer system 1900 to exchange information / data with other devices through a network such as the Internet, and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth™ device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0102] The computing unit 1901 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 1901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 1901 performs various methods and processes described above. For example, in some embodiments, the above-described methods disclosed by the embodiments of the present disclosure can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 1908. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device via the ROM 1902 and / or the communication unit 1909. In some embodiments, the computing unit 1901 can be configured to perform the above-described methods disclosed by the embodiments of the present disclosure by any other appropriate means (e.g., by means of firmware).
[0103] The embodiments of the present disclosure also provide a computer-readable storage medium, wherein when instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the above-described methods disclosed by the embodiments of the present disclosure.
[0104] The computer-readable storage medium in the embodiments of the present disclosure can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The above-described computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any appropriate combination thereof. More specifically, the above-described computer-readable storage medium can include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or a flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof.
[0105] The above-described computer-readable medium can be contained in the above-described electronic device; or can exist separately without being assembled into the electronic device.
[0106] The embodiments of the present disclosure also provide a computer program product, comprising a computer program, wherein the computer program is executed by a processor to implement the above-described methods disclosed by the embodiments of the present disclosure.
[0107] Computer program code for carrying out operations of the present disclosure can be written in any one or more of a variety of programming languages or combinations of languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0108] The flow diagrams and the block diagrams in the drawings are meant as possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow diagrams and the block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flow diagrams, and combinations thereof, can be implemented by special purpose hardware-based systems that perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.
[0109] The modules, components or units described in the embodiments of the present disclosure can be implemented by software or by hardware. In some cases, the name of the module, component or unit does not constitute a limitation on the module, component or unit itself.
[0110] The functions described above in the detailed description of embodiments of the present disclosure can be implemented in one or more hardware logic components or by computer instructions that are executed in a hardware logic component. For example, and without limitation, illustrative hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-Chip (SOCs), Complex Programmable Logic Devices (CPLDs), etc.
[0111] The above description is merely exemplary of some embodiments of the present disclosure and of the principles thereof. It is to be understood that the disclosure is not limited in scope to the particular embodiments described herein, which are intended as examples only, and that the scope of the disclosure is, instead, defined by the appended claims, along with the full range of equivalents to which such claims are entitled. For example, the features of the various embodiments described above can be combined with each other, unless expressly prohibited by the above description.
[0112] While some specific embodiments of the present disclosure have been described in detail, those skilled in the art should understand that the above examples are merely exemplary and are not intended to limit the scope of the present disclosure. Those skilled in the art should understand that the above embodiments can be modified without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.
Claims
1. A log auditing method characterized by, The method comprises: obtaining an operation log of a target user, the operation log comprising operation times of the target user in a target time period, the target time period comprising a plurality of unit time periods, each unit time period comprising a plurality of sub-unit time periods; based on the operation times of the target user in each unit time period, in a case where it is determined that the operation times of the target user in adjacent M unit time periods in the target time period have regularity, counting the operation times of the target user in each sub-unit time period; based on the operation times of the target user in each sub-unit time period, in a case where it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, determining that the target user is an abnormal user; wherein M and N are both positive integers.
2. The method of claim 1, wherein, The method further comprises: counting the operation times of the target user in each unit time period, and converting the operation times of the target user in each unit time period into a target graph; obtaining the similarity between target graphs in adjacent M unit time periods, and in a case where the similarity is greater than a first threshold, determining that the operation times of the target user in adjacent M unit time periods in the target time period have regularity.
3. The method of claim 1, wherein, The method further comprises: counting the operation times of the target user in each sub-unit time period in a target unit time period, and converting the operation times in each sub-unit time period into a target graph; obtaining the similarity between target graphs in adjacent N sub-unit time periods, and in a case where the similarity is greater than a second threshold, determining that the operation times of the target user in adjacent N sub-unit time periods in the target unit time period have regularity; in a case where the proportion of the target time period is greater than a preset proportion, determining that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity.
4. The method of claim 3, wherein, In the case where it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have regularity, the method further comprises: determining whether the operation times of the target user in a target sub-unit time period in the target unit time period have regularity; in a case where the operation times of the target user in the target sub-unit time period in the target unit time period have regularity, determining that the target user is an abnormal user.
5. The method of claim 4, wherein, The method further comprises: obtaining the operation times of the target user in the target unit time period; generating a target matrix based on the operation times in a target sub-unit time period, the rows of the target matrix representing the operation times of the target user per minute, and the columns of the target matrix representing the operation times of the target user per second; dividing the target matrix into a plurality of sub-regions, and calculating the similarity between the plurality of sub-regions; in a case where it is determined based on the similarity that there is a sub-region in the plurality of sub-regions with a similarity greater than a third threshold, determining that the operation times of the target user in the target sub-unit time period have regularity.
6. The method of claim 5, wherein, The method further comprises: detecting whether there is an empty sub-region in the plurality of sub-regions that does not contain operation times; There is an empty sub-region not containing the operation times in the plurality of sub-regions, and the empty sub-region is removed from the plurality of sub-regions.
7. A log auditing apparatus characterized by comprising: The device comprises: a log obtaining module, configured to obtain an operation log of a target user, the operation log comprising operation times of the target user in a target time period, the target time period comprising a plurality of unit time periods, and each unit time period comprising a plurality of sub-unit time periods; an operation time counting module, configured to count operation times of the target user in each sub-unit time period based on the operation times of the target user in each unit time period, in a case where it is determined that the operation times of the target user in adjacent M unit time periods in the target time period have a regularity; an abnormal user determining module, configured to determine the target user as an abnormal user based on the operation times of the target user in each sub-unit time period, in a case where it is determined that the operation times of the target user in adjacent N sub-unit time periods in each unit time period have a regularity; wherein M and N are both positive integers.
8. An electronic device, comprising: comprise: at least one processor; a memory for storing instructions executable by the at least one processor; wherein the at least one processor is configured to execute the instructions to implement the method of any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is enabled to perform the method of any one of claims 1-6.
10. A computer program product, characterised in that, comprise a computer program, which, when executed by a processor, implements the method of any one of claims 1-6.
Citation Information
Patent Citations
Risk detection method and device
CN111818066A
Abnormal behavior detection method and device and electronic device
CN112491779A