Risk identification method and apparatus

By acquiring user network access data, generating time series and access anomaly tensors, encoding them, and fusing user attribute features, the problem of accurately identifying risky behaviors in user network access is solved, improving the accuracy and effectiveness of risk identification.

CN118827196BActive Publication Date: 2025-11-04CHINA MOBILE GROUP ZHEJIANG +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410922167.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-10
Publication Date
2025-11-04
Estimated Expiration
2044-07-10

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately identify risky behaviors by users accessing the network. Network threats are diverse and covert, posing challenges to network security.

Method used

By acquiring users' network access data, calculating time series indicator parameters and access anomaly parameters, generating time series tensors and access anomaly tensors, inputting them into an encoding network for encoding processing, fusing time series features and user attribute features, and using a risk identification model for risk identification.

Benefits of technology

It improves the accuracy and effectiveness of risk identification, enabling more precise identification of user risk categories and enhancing cybersecurity protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827196B_ABST
    Figure CN118827196B_ABST
Patent Text Reader

Abstract

One embodiment of the specification provides a risk identification method and device, which comprises: first acquiring network access data of a user, then calculating index parameters of the user under each time sequence index based on the network access data, generating a time sequence tensor according to the index parameters, determining access anomaly events of the user based on the network access data, and calculating anomaly parameters of the user under each access anomaly event according to the anomaly parameters, generating an access anomaly tensor, on this basis, inputting the time sequence tensor and the access anomaly tensor into an encoding network for encoding processing to obtain time sequence characteristics, finally splicing the time sequence characteristics and user attribute characteristics of the user to obtain input characteristics and inputting the input characteristics into a risk identification model for risk identification to obtain a risk category of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of data processing, and in particular to a risk identification method and apparatus. Background Technology

[0002] With the deepening penetration of Internet technology and the acceleration of digital transformation, cyberspace has become the core place for information exchange and business operations. While the development of the Internet has improved convenience, the challenges of cybersecurity are also increasing. Cyber ​​threats such as hacker attacks, data breaches, and the spread of malware not only pose a serious threat to personal privacy, but also cause huge economic losses, legal disputes, and trust crises for enterprises and organizations. Against this background, risk identification for users accessing the Internet is particularly important.

[0003] In the process of ensuring network security, network threats are constantly evolving and becoming more covert and diverse. How to improve network security is a key focus for both service providers and users. Summary of the Invention

[0004] The purpose of one embodiment of this specification is to provide a risk identification method and apparatus to solve the problem of how to accurately identify risky behaviors of users accessing networks.

[0005] To solve the above-mentioned technical problems, one embodiment of this specification is implemented as follows:

[0006] Firstly, one embodiment of this specification provides a risk identification method, including:

[0007] Obtain user's network access data;

[0008] Based on the network access data, the indicator parameters of the user under each time series indicator are calculated, and a time series tensor is generated according to the indicator parameters. Based on the network access data, the user's access anomaly events are determined, and the user's anomaly parameters under each access anomaly event are calculated. An access anomaly tensor is generated according to the anomaly parameters.

[0009] The time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features;

[0010] The time-series features and the user attribute features of the user are concatenated to obtain input features. These input features are then input into a risk identification model to identify the risk category of the user.

[0011] Secondly, another embodiment of this specification provides a risk identification device, comprising:

[0012] The data acquisition module is configured to acquire the user's network access data;

[0013] The tensor generation module is configured to calculate the indicator parameters of the user under each time series indicator based on the network access data, generate a time series tensor based on the indicator parameters, determine the user's access anomaly events based on the network access data, calculate the user's anomaly parameters under each access anomaly event, and generate an access anomaly tensor based on the anomaly parameters.

[0014] The encoding processing module is configured to input the time series tensor and the access anomaly tensor into the encoding network for encoding processing to obtain time series features;

[0015] The risk identification module is configured to concatenate the time-series features and the user's user attribute features to obtain input features, and then input the input features into the risk identification model to identify the risk category of the user.

[0016] Thirdly, another embodiment of this specification provides a risk identification device, including: a memory, a processor, and computer-executable instructions stored in the memory and executable on the processor, wherein the computer-executable instructions, when executed by the processor, implement the steps of the risk identification method as described in the first aspect above.

[0017] Fourthly, in another embodiment of this specification, a computer-readable storage medium is provided for storing computer-executable instructions that, when executed by a processor, implement the steps of the risk identification method as described in the first aspect above.

[0018] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the risk identification method as described in the first aspect.

[0019] The risk identification method provided in this embodiment first acquires the user's network access data, then calculates the user's indicator parameters under various time series indicators based on the network access data, generates a time series tensor based on the indicator parameters, and identifies the user's abnormal access events based on the network access data, calculating the abnormal parameters of the user under each abnormal access event, generating an access anomaly tensor based on the abnormal parameters. On this basis, the time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features. Thus, by acquiring the time series tensor and the access anomaly tensor from the network access data, the accuracy and comprehensiveness of the obtained time series features are improved. Finally, the time series features and the user's user attribute features are concatenated to obtain input features, which are then input into a risk identification model for risk identification to obtain the user's risk category. Therefore, by fusing time series features and user attribute features, the accuracy and effectiveness of user risk identification are improved. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in one or more embodiments of this specification, the accompanying drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A flowchart illustrating a risk identification method provided in one embodiment of this specification;

[0022] Figure 2 This specification provides a schematic diagram of network access data segmentation as an embodiment.

[0023] Figure 3 This specification provides a schematic diagram of a network implementation process as an embodiment.

[0024] Figure 4 A schematic diagram of a risk identification system provided in one embodiment of this specification;

[0025] Figure 5 This specification provides a flowchart of a risk identification method applied to real-time monitoring and early warning scenarios, as an embodiment of the present invention.

[0026] Figure 6 A schematic diagram of a risk identification device provided in one embodiment of this specification;

[0027] Figure 7 This is a schematic diagram of a risk identification device provided in one embodiment of this specification. Detailed Implementation

[0028] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.

[0029] This specification provides an example of a risk identification method:

[0030] Reference Figure 1 The diagram illustrates a process flow chart of a risk identification method provided in this embodiment. The risk identification method provided in this embodiment specifically includes the following steps S102 to S108.

[0031] Step S102: Obtain the user's network access data.

[0032] The network access data mentioned in this embodiment refers to the record of the amount of data transmitted when a user accesses the network within a certain period of time. Network access data can include website access records, user risk behaviors, historical behaviors, etc.

[0033] Network access data can be obtained through Deep Packet Inspection (DPI). First, this technology captures user network access data packets by setting up mirror ports or using packet capture technology. Then, it determines the application layer protocol of the user network access data packets. Based on this, it further analyzes the payload of the user network access data packets, extracts network access data, and finally summarizes, classifies and stores the analyzed network access data in a database.

[0034] Step S104: Calculate the indicator parameters of the user under each time series indicator based on the network access data, generate a time series tensor based on the indicator parameters, determine the user's access anomaly events based on the network access data, calculate the anomaly parameters of the user under each access anomaly event, and generate an access anomaly tensor based on the anomaly parameters.

[0035] The time series metrics described in this embodiment refer to a series of statistical quantities used in time series analysis based on network access data to describe, measure, and predict time series characteristics that change over time. Time series metrics can be, for example, the number of records for a bank's domain name in the current hour. For example, the time series metrics shown below:

[0036] Feature code Feature Name Feature meaning F1 bank_vist_count_1h Current hourly record count of bank domain names F2 bank_vist_count_lag2h Number of records for bank domains in the first hour … … …

[0037] Table 1

[0038] The access anomaly events described in this embodiment refer to a series of statistical measures used in time series analysis of network access data to describe, measure, and predict access anomaly characteristics that change over time, based on the difference between user risky behavior and historical behavior in network access data. Access anomalies can include abnormal distribution of access to overseas domain names over the past 24 hours. For example, the following access anomaly events are shown:

[0039]

[0040]

[0041] Table 2

[0042] After obtaining the user's network access data as described above, in this step, the indicator parameters of the user under each time series indicator are calculated based on the network access data, and a time series tensor is generated based on the indicator parameters. Additionally, the user's access anomaly events are determined based on the network access data, and the anomaly parameters of the user under each access anomaly event are calculated. An access anomaly tensor is generated based on the anomaly parameters.

[0043] In specific implementation, to improve the accuracy of feature extraction, the input data of the encoding network can be preprocessed to obtain time series tensors and access anomaly tensors. In one optional implementation of this embodiment, the step of calculating the user's indicator parameters under various time series indicators based on the network access data and generating a time series tensor based on the indicator parameters includes:

[0044] The network access data is segmented according to time slices to obtain network access data for each time period in at least one time period.

[0045] Based on network access data for each time period and at least one time series indicator, calculate the indicator parameters of the user under each time series indicator within each time period.

[0046] Construct an initial time series tensor based on the indicator parameters of the user under each time series indicator within each time period;

[0047] The initial time series tensor is standardized to obtain the time series tensor.

[0048] Specifically, after obtaining the user's network access data through deep packet parsing, the network access data can be segmented according to time slices using data segmentation to obtain network access data for each time period in at least one time period. Then, based on the network access data and at least one time series indicator, the indicator parameters of the user under each time series indicator are calculated. Finally, an initial time series tensor is constructed based on all indicator parameters and standardized to obtain the time series tensor.

[0049] For example, refer to Figure 2 For the user set D = {User1, User2, ..., User...} N First, the network access data for each user is segmented according to the time slice Δt. Each segmented time slice contains several deep packet parsing logs. This operation divides the original network access data into Q time periods. M time series indicators are extracted from the network access data. Based on the network access data and the M time series indicators, the indicator parameters for each user under the M time series indicators are calculated. Based on all indicator parameters, an initial time series tensor T is constructed. N×M×Q Then, it is standardized to obtain the time series tensor T′. N×M×Q (N is the number of users, M is the number of time series types, and Q is the time sampling step size). Furthermore, the user set described above can also contain only one user, and the same processing method can be used to obtain the time series tensor T′. 1×M×Q .

[0050] While obtaining the time series tensor based on network access data, it is also necessary to obtain the access anomaly tensor. In one optional implementation of this embodiment, the step of determining the user's access anomaly events based on the network access data, calculating the user's anomaly parameters under each access anomaly event, and generating the access anomaly tensor based on the anomaly parameters includes:

[0051] Calculate the abnormal parameters of the user under each abnormal access indicator based on the network access data;

[0052] If the abnormal parameter under each access anomaly indicator is greater than the corresponding parameter threshold, then an access anomaly event is determined based on the access anomaly characteristics corresponding to the abnormal parameter, and the abnormal parameter is determined as the abnormal parameter under the access anomaly event.

[0053] An initial access exception tensor is constructed based on the user's exception parameters under each access exception event, and the initial access exception tensor is standardized to obtain the access exception tensor.

[0054] Specifically, after obtaining the user's network access data through deep packet parsing, the network access data can be segmented according to time slices using data segmentation to obtain network access data for each time period within at least one time period. Then, based on the network access data, the abnormal parameters of the user under each access anomaly indicator are calculated. If the abnormal parameter is greater than the corresponding parameter threshold, the access anomaly event is determined based on the access anomaly characteristics corresponding to the abnormal parameter, and the abnormal parameter is determined as the abnormal parameter under the corresponding access anomaly event. Finally, an initial access anomaly tensor is constructed based on all the abnormal parameters and standardized to obtain the access anomaly tensor.

[0055] For example, given a user set D = {User1, User2, ..., User...} N First, the network access data for each user is segmented according to the time slice Δt. Each segmented time slice contains several deep packet parsing logs. This operation divides the original network access data into Q time periods. Anomaly parameters for each user under various access anomaly indicators are calculated from the network access data. If the anomaly parameter falls outside ±3 sigma, an access anomaly is determined based on the access anomaly characteristics corresponding to the anomaly parameter. P types of access anomaly events are extracted from the network access data. Based on the network access data and the P types of access anomaly events, the anomaly parameters for each user under the P types of access anomalies are calculated. An initial access anomaly tensor A is constructed based on all anomaly parameters. N ×P×Q Then, it is standardized to obtain the access exception tensor A′. N×P×Q (N is the number of users, M is the number of time series categories, and Q is the time sampling step size). Furthermore, the user set described above can also contain only one user, and the same processing method can be used to obtain the access anomaly tensor A′. 1×P×Q .

[0056] To further improve the accuracy of risk identification, user attribute features are obtained from user data. In one optional implementation of this embodiment, the user attribute features are obtained in the following manner:

[0057] Acquire user data and divide the user data into categorical variables and numerical variables;

[0058] The categorical variables are encoded to obtain attribute category features, and the numerical variables are binned, and the binning results are encoded to obtain attribute numerical features.

[0059] The attribute category feature and the attribute numerical feature are determined as the user attribute feature.

[0060] The user attribute features described in this embodiment can be, for example, the gender of the registered mobile phone user. For example, the following user attribute features are shown:

[0061] Feature code Feature Name Feature meaning F200 gender_mobile_user Gender of mobile phone registered users F201 age_mobile_user Mobile phone registered user age … … …

[0062] Table 3

[0063] Specifically, while obtaining network access data from users through deep packet analysis, user data is also obtained. The obtained user data is divided into categorical variables and numerical variables. The categorical variables are encoded, and the numerical variables are binned and encoded to obtain attribute category features and attribute numerical features. The attribute category features and attribute numerical features are then determined as user attribute features.

[0064] For example, user data is divided into two categories: categorical variables and numerical variables. Categorical variables are one-hot encoded, and numerical variables are binned and encoded to obtain attribute categorical features and attribute numerical features. Based on these categorical and numerical features, user attribute features E are determined. User .

[0065] In practice, during the risk identification process, time series tensors and access anomaly tensors are obtained from network access data to improve the accuracy of feature extraction from the input data of the encoded network. This avoids the problem of ignoring the time factor when using users or numbers as the smallest granularity of samples. Furthermore, the accuracy of risk identification is improved by obtaining user attribute features from user data.

[0066] Step S106: Input the time series tensor and the access anomaly tensor into the encoding network for encoding processing to obtain time series features.

[0067] The above steps involve calculating the user's index parameters under various time series indicators based on network access data to obtain a time series tensor, and determining the user's access anomaly events based on network access data and calculating the user's anomaly parameters under each access anomaly event to obtain an access anomaly tensor. In this step, the time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features.

[0068] In specific implementation, the encoding of time series tensors and access anomaly tensors can be performed based on Fully Convolutional Networks (FCNs) and Long Short-Term Memory Networks (LSTMs). In one optional implementation provided in this embodiment, the encoding process includes:

[0069] The time series tensor and the access anomaly tensor are input into a fully convolutional network for encoding to obtain the first temporal feature.

[0070] The time series tensor and the access anomaly tensor are input into a long short-term memory network for encoding to obtain the second time series feature.

[0071] The time series feature is obtained by concatenating the first time series feature and the second time series feature.

[0072] Specifically, firstly, the time series tensor and the access exception tensor are encoded using a fully convolutional network to obtain the first temporal feature. Then, the time series tensor and the access exception tensor are encoded using a long short-term memory network to obtain the second temporal feature. Finally, the first and second temporal features are concatenated to obtain the temporal feature.

[0073] For example: the time series tensor T′ N×M×Q and accessing the abnormal tensor A′ N×P×Q The input is processed by a fully convolutional network to obtain the first temporal feature E. FCN Transform the time series tensor T′ N×M×Q and accessing the abnormal tensor A′ N×P×Q The input is processed by a Long Short-Term Memory (LSTM) network to obtain the second temporal feature E. LSTM The first time-series feature E FCN Second time series feature E LSTM Temporal features E are obtained by concatenating features. FCN∪LSTM .

[0074] The process of obtaining temporal features described above is based on encoding processing using an encoding network. In an optional implementation provided in this embodiment, the encoding network is obtained in the following manner:

[0075] Model training parameters are determined based on optimization algorithms;

[0076] The encoding network is trained according to the model training parameters and training samples to obtain the encoding network.

[0077] Specifically, the model training parameters are first determined based on the optimization algorithm. Then, the training samples are input into the encoding network to be trained to obtain historical time-series features. Based on these features, the loss value of the encoding network to be trained is calculated using the historical time-series features and time-series feature labels. Finally, the parameters of the encoding network to be trained are adjusted according to the loss value to obtain the encoding network.

[0078] For example, the model training parameters are first determined using the firefly algorithm. Then, the historical time series tensor and the historical access anomaly tensor are input into the encoding network to be trained to obtain historical time series features. Finally, the loss value of the encoding network to be trained is calculated based on the historical time series features and time series feature labels, and the parameters of the encoding network to be trained are adjusted based on the loss value of the encoding network to be trained to obtain the encoding network.

[0079] The above-mentioned model training parameters are determined based on an optimization algorithm, which can be the Firefly algorithm. In one optional implementation provided in this embodiment, determining the model training parameters based on the optimization algorithm includes:

[0080] Calculate the fitness value for each candidate parameter combination;

[0081] Based on the fitness value and the accuracy of the training set, a target parameter combination is determined from at least one candidate parameter combination as the model training parameters.

[0082] Specifically, the optimal parameter combination is first found using the firefly algorithm and used as the model training parameters. Then, the fitness value of each candidate parameter combination is calculated based on the firefly algorithm. Finally, the target parameter combination is determined based on the fitness value and the accuracy of the training set as the model training parameters, thus realizing the parallel learning of the firefly algorithm and the encoding network.

[0083] For example, firstly, the parameter combinations to be optimized (learning rate lr, number of hidden layer neurons array num, number of iterations k) and the value range of each parameter are clearly defined. Then, an initial firefly swarm is randomly generated in the parameter space, with each firefly representing a parameter combination. Secondly, for each parameter configuration, the model performance is evaluated on the training data according to the evaluation metrics using methods such as cross-validation. The model performance is the fitness value of the fireflies; the higher the fitness, the better the model performance. Based on this, the parameter combinations are updated according to the fitness of each firefly and the accuracy of the training set, and a dynamic evolution mechanism and a directed mutation mechanism are executed. Finally, after reaching the preset stopping criterion, the parameter combination represented by the firefly with the highest brightness is selected as the optimal parameter combination. The encoding network to be trained is then trained based on the optimal parameter combination, realizing the parallel learning of the firefly algorithm and FCN-LSTM.

[0084] In practice, during the risk identification process, time series tensors and access anomaly tensors are input into an encoding network for encoding to obtain temporal features, thereby avoiding the problems of insufficient model feature diversity and poor model generalization performance.

[0085] Step S108: The time-series features and the user attribute features of the user are concatenated to obtain input features, and the input features are input into the risk identification model for risk identification to obtain the risk category of the user.

[0086] The risk identification model described in this embodiment is used to discover, analyze and assess potential risks to users when accessing the network. The sample risk model can be a model based on algorithms such as Support Vector Machines (SVM) or Random Forest, and the model can contain one or more algorithms.

[0087] The time series tensor and the access anomaly tensor are input into the encoding network for encoding processing to obtain time series features. In this step, the time series features and the user's user attribute features are concatenated to obtain input features. The input features are then input into the risk identification model for risk identification to obtain the risk category of the user.

[0088] In practice, time-series features and user attribute features are concatenated to obtain the input features of the risk identification model. The input features are then fed into the risk identification model to identify the user's risk category. This feature concatenation method greatly improves the accuracy of risk identification.

[0089] Reference Figure 3 In the process of identifying risks associated with user network access, the network access data and user data are first processed and feature-processed to obtain time series tensors, access anomaly tensors, and user attribute features. Then, the optimal parameter combination of FCN-LSTM is obtained based on the Firefly algorithm, which includes a firefly search process, a dynamic evolution mechanism, and a directed mutation mechanism. On this basis, the FCN-LSTM network is trained based on the optimal parameter combination to obtain the optimal time series features. Finally, the optimal time series features and user attribute features are concatenated to obtain the input features, which are then input into the risk identification model for risk identification.

[0090] In summary, the one or more risk identification methods provided in this embodiment improve the accuracy of extracting input data features by obtaining time series tensors and access anomaly tensors from network access data during the risk identification process of user access to the network, thus avoiding the problem of samples ignoring time factors. Furthermore, the time series tensors and access anomaly tensors are input into an encoding network for encoding processing to obtain time series features. The time series features and user attribute features are concatenated and input into the sample risk identification model to obtain the risk category. By incorporating user attribute features, the risk behavior identification of users has a stronger predictive ability.

[0091] The following combination Figure 4 and Figure 5 The risk identification method provided in this embodiment will be further explained below. (Refer to...) Figure 4 A risk identification system can be constructed based on risk identification methods. This system includes real-time data loading, multi-feature loading, coding network loading, and risk identification loading. (See reference...) Figure 5 The risk identification method applied to real-time monitoring and early warning scenarios specifically includes steps S502 to S512.

[0092] Step S502: Data extraction is performed through deep packet analysis to obtain network access data and user data.

[0093] Step S504: Extract data based on network access data to obtain time series tensors and access anomaly tensors; extract features based on user data to obtain user attribute features.

[0094] Step S506: Input the time series tensor and the access anomaly tensor into the encoding network for encoding processing to obtain the time series features.

[0095] Step S508: Concatenate the time-series features and user attribute features to obtain the input features.

[0096] Step S510: Input the input features into the risk identification model to identify the risk and obtain the user's risk category.

[0097] Step S512: Real-time monitoring and early warning are performed based on risk categories. If the abnormal risk parameters exceed the set threshold, an early warning is triggered and a warning message is sent to relevant personnel.

[0098] like Figure 4 As shown, in the risk identification system, real-time data loading is used to extract input data from historical data. The input data can be data obtained through deep message parsing. Real-time data loading can achieve step S502. Multi-feature loading is used to extract features from the input data from dimensions such as behavioral habits and overseas risks to obtain feature extraction results. Multi-feature loading can achieve step S504. Encoding network loading is used to perform encoding processing based on the feature extraction results to obtain encoded features. Encoding network loading can achieve step S506. Risk identification loading is used to perform risk identification based on encoded features. Risk identification loading can achieve steps S508 to S512.

[0099] The risk identification method provided in this embodiment first acquires the user's network access data, then calculates the user's indicator parameters under various time series indicators based on the network access data, generates a time series tensor based on the indicator parameters, and determines the user's access anomaly events based on the network access data, calculates the user's anomaly parameters under each access anomaly event, generates an access anomaly tensor based on the anomaly parameters, and then inputs the time series tensor and the access anomaly tensor into an encoding network for encoding processing to obtain time series features. Finally, the time series features and the user's user attribute features are concatenated to obtain input features, which are then input into a risk identification model for risk identification to obtain the user's risk category.

[0100] Figure 6 This is a schematic diagram of a risk identification device provided in an embodiment of the present invention, as shown below. Figure 6 As shown, the device includes:

[0101] Data acquisition module 602 is configured to acquire user network access data;

[0102] Tensor generation module 604 is configured to calculate the indicator parameters of the user under each time series indicator based on the network access data, generate a time series tensor based on the indicator parameters, determine the user's access anomaly events based on the network access data, calculate the user's anomaly parameters under each access anomaly event, and generate an access anomaly tensor based on the anomaly parameters.

[0103] The encoding processing module 606 is configured to input the time series tensor and the access anomaly tensor into an encoding network for encoding processing to obtain time series features;

[0104] The risk identification module 608 is configured to concatenate the time-series features and the user's user attribute features to obtain input features, and then input the input features into the risk identification model to identify the risk category of the user.

[0105] The risk identification device provided in this embodiment first acquires the user's network access data through the data acquisition module 602. Then, it runs the tensor generation module 604 to calculate the user's indicator parameters under various time series indicators based on the network access data, and generates a time series tensor based on the indicator parameters. It also determines the user's access anomaly events based on the network access data, calculates the user's anomaly parameters under each access anomaly event, and generates an access anomaly tensor based on the anomaly parameters. Next, it runs the encoding processing module 606 to input the time series tensor and the access anomaly tensor into an encoding network for encoding processing to obtain time series features. Finally, it runs the risk identification module 608 to concatenate the time series features and the user's user attribute features to obtain input features, and inputs these input features into a risk identification model for risk identification to obtain the user's risk category.

[0106] The risk identification device provided in one embodiment of this specification can realize the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0107] Furthermore, one embodiment of this specification also provides a risk identification device. Figure 7 This is a schematic diagram of the structure of a risk identification device provided in one embodiment of this specification, as shown below. Figure 7 As shown, the device includes a memory 701, a processor 702, a bus 703, and a communication interface 704. The memory 701, processor 702, and communication interface 704 communicate via the bus 703. The communication interface 704 may include input / output interfaces, including but not limited to a keyboard, mouse, monitor, microphone, and loudspeaker.

[0108] Figure 7 In the memory 701, computer-executable instructions that can run on the processor 702 are stored. When the processor 702 executes the computer-executable instructions, the following process is implemented:

[0109] Obtain user's network access data;

[0110] Based on the network access data, the indicator parameters of the user under each time series indicator are calculated, and a time series tensor is generated according to the indicator parameters. Based on the network access data, the user's access anomaly events are determined, and the user's anomaly parameters under each access anomaly event are calculated. An access anomaly tensor is generated according to the anomaly parameters.

[0111] The time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features;

[0112] The time-series features and the user attribute features of the user are concatenated to obtain input features. These input features are then input into a risk identification model to identify the risk category of the user.

[0113] The risk identification device provided in this embodiment, through the cooperation of a memory 701, a processor 702, a bus 703, and a communication interface 704, first acquires the user's network access data, then calculates the user's indicator parameters under various time series indicators based on the network access data, generates a time series tensor based on the indicator parameters, and determines the user's access anomaly events based on the network access data, calculates the user's anomaly parameters under each access anomaly event, generates an access anomaly tensor based on the anomaly parameters, and then inputs the time series tensor and the access anomaly tensor into an encoding network for encoding processing to obtain time series features. Finally, the time series features and the user's user attribute features are concatenated to obtain input features, which are then input into a risk identification model for risk identification to obtain the user's risk category.

[0114] The risk identification device provided in one embodiment of this specification can realize the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0115] Furthermore, another embodiment of this specification provides a computer-readable storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process:

[0116] Obtain user's network access data;

[0117] Based on the network access data, the indicator parameters of the user under each time series indicator are calculated, and a time series tensor is generated according to the indicator parameters. Based on the network access data, the user's access anomaly events are determined, and the user's anomaly parameters under each access anomaly event are calculated. An access anomaly tensor is generated according to the anomaly parameters.

[0118] The time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features;

[0119] The time-series features and the user attribute features of the user are concatenated to obtain input features. These input features are then input into a risk identification model to identify the risk category of the user.

[0120] The computer-readable storage medium provided in this embodiment first acquires the user's network access data, then calculates the user's indicator parameters under various time series indicators based on the network access data, generates a time series tensor based on the indicator parameters, and determines the user's access anomaly events based on the network access data, calculates the user's anomaly parameters under each access anomaly event, generates an access anomaly tensor based on the anomaly parameters, and then inputs the time series tensor and the access anomaly tensor into an encoding network for encoding processing to obtain time series features. Finally, the time series features and the user's user attribute features are concatenated to obtain input features, which are then input into a risk identification model for risk identification to obtain the user's risk category.

[0121] The computer-readable storage medium includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0122] The computer-readable storage medium provided in one embodiment of this specification can implement the various processes in the foregoing method embodiments and achieve the same functions and effects, which will not be repeated here.

[0123] Furthermore, another embodiment of this specification provides a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the following process:

[0124] Obtain user's network access data;

[0125] Based on the network access data, the indicator parameters of the user under each time series indicator are calculated, and a time series tensor is generated according to the indicator parameters. Based on the network access data, the user's access anomaly events are determined, and the user's anomaly parameters under each access anomaly event are calculated. An access anomaly tensor is generated according to the anomaly parameters.

[0126] The time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features;

[0127] The time-series features and the user attribute features of the user are concatenated to obtain input features. These input features are then input into a risk identification model to identify the risk category of the user.

[0128] The computer program product in this disclosure embodiment can implement the various processes of the above-described risk identification method embodiment and achieve the same effects and functions, which will not be repeated here.

[0129] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0130] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0131] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0132] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0133] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0134] Memory may include non-persistent storage in computer-readable storage media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable storage media.

[0135] Computer-readable storage media include both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer-readable storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable storage media does not include transient media, such as modulated data signals and carrier waves.

[0136] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0137] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0138] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.

Claims

1. A risk identification method, characterized in that, The method includes: Obtain user's network access data; Based on the network access data, the indicator parameters of the user under each time series indicator are calculated, and a time series tensor is generated according to the indicator parameters. Based on the network access data, the user's access anomaly events are determined, and the user's anomaly parameters under each access anomaly event are calculated. An access anomaly tensor is generated according to the anomaly parameters. The time series tensor and the access anomaly tensor are input into an encoding network for encoding processing to obtain time series features; The time-series features and the user attribute features of the user are concatenated to obtain input features. These input features are then input into a risk identification model to identify the risk category of the user.

2. The risk identification method according to claim 1, characterized in that, The step of calculating the user's indicator parameters under various time-series indicators based on the network access data, and generating a time-series tensor based on the indicator parameters, includes: The network access data is segmented according to time slices to obtain network access data for each time period in at least one time period. Based on network access data for each time period and at least one time series indicator, calculate the indicator parameters of the user under each time series indicator within each time period. Construct an initial time series tensor based on the indicator parameters of the user under each time series indicator within each time period; The initial time series tensor is standardized to obtain the time series tensor.

3. The risk identification method according to claim 1, characterized in that, The process of determining the user's access anomaly events based on the network access data, calculating the user's anomaly parameters under each access anomaly event, and generating an access anomaly tensor based on the anomaly parameters includes: Calculate the abnormal parameters of the user under each abnormal access indicator based on the network access data; If the abnormal parameter under each access anomaly indicator is greater than the corresponding parameter threshold, then an access anomaly event is determined based on the access anomaly characteristics corresponding to the abnormal parameter, and the abnormal parameter is determined as the abnormal parameter under the access anomaly event. An initial access exception tensor is constructed based on the user's exception parameters under each access exception event, and the initial access exception tensor is standardized to obtain the access exception tensor.

4. The risk identification method according to claim 1, characterized in that, The user attribute features are obtained in the following way: Acquire user data and divide the user data into categorical variables and numerical variables; The categorical variables are encoded to obtain attribute category features, and the numerical variables are binned, and the binning results are encoded to obtain attribute numerical features. The attribute category feature and the attribute numerical feature are determined as the user attribute feature.

5. The risk identification method according to claim 1, characterized in that, The encoding process includes: The time series tensor and the access anomaly tensor are input into a fully convolutional network for encoding to obtain the first temporal feature. The time series tensor and the access anomaly tensor are input into a long short-term memory network for encoding to obtain the second time series feature. The first time-series feature and the second time-series feature are concatenated to obtain the time-series feature.

6. The risk identification method according to claim 1, characterized in that, The coding network is obtained in the following way: Determine network training parameters based on optimization algorithms; The encoding network is trained according to the network training parameters and training samples to obtain the encoding network.

7. A risk identification device, characterized in that, The device includes: The data acquisition module is configured to acquire the user's network access data; The tensor generation module is configured to calculate the indicator parameters of the user under each time series indicator based on the network access data, generate a time series tensor based on the indicator parameters, determine the user's access anomaly events based on the network access data, calculate the user's anomaly parameters under each access anomaly event, and generate an access anomaly tensor based on the anomaly parameters. The encoding processing module is configured to input the time series tensor and the access anomaly tensor into the encoding network for encoding processing to obtain time series features; The risk identification module is configured to concatenate the time-series features and the user's user attribute features to obtain input features, and then input the input features into the risk identification model to identify the risk category of the user.

8. A risk identification device, characterized in that, The method includes a memory and a processor, wherein the memory stores computer-executable instructions that, when executed on the processor, enable the implementation of the steps of the method described in any one of claims 1-6.

9. A computer-readable storage medium storing computer-executable instructions, characterized in that, When the computer-executable instructions are executed by a processor, they can implement the steps of the method described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Risk level determination method, model training method and electronic equipment

    CN115936853A

  • Diagnosis method, device and equipment for abnormal event of multivariate time series data and storage medium

    CN116628621A