Method for Identifying User Deviant Behaviors Based on Domain Name Access and Recommending Similar Behaviors

By building a domain name evaluation index system and an outlier feature matrix for user access domain names, combining Tukey's Test and machine learning algorithms, identifying extreme outlier behaviors and recommending users of similar behaviors, the problem of insufficient adaptability of traditional methods in the face of network protocols and encryption technology updates is solved, and more accurate and efficient abnormal behavior recognition and personalized recommendations are achieved.

CN119254538BActive Publication Date: 2025-06-20NANJING FIBERHOME STARRYSKY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411765925.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-04
Publication Date
2025-06-20
Estimated Expiration
2044-12-04

AI Technical Summary

Technical Problem

Traditional traffic anomaly recognition methods based on content analysis are insufficient in the face of the updates of network protocols and encryption technologies, making it difficult to effectively identify user outliers.

Method used

The user outlier behavior recognition and similar behavior recommendation method based on the global domain name access system is adopted. By constructing a domain name evaluation index system and an outlier feature matrix for user access domain names, combining Tukey's Test and machine learning algorithms, extreme outlier behaviors and recommending users of similar behaviors.

Benefits of technology

It realizes more accurately identifying potential abnormal behaviors, adapting to high-speed changes in network traffic, reducing dependence on labeled training set data, improving the efficiency and accuracy of abnormal user behavior recognition, and providing accurate personalized recommendations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254538B_ABST
    Figure CN119254538B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for identifying user outlier behavior based on domain name access and recommending similar behaviors, belonging to the field of network security technology. Specifically, it includes: constructing a domain name evaluation index system according to behavioral characteristics such as the frequency of user access to domain names and the frequency of accessing domain names, and quantifying the concentration and dispersion degrees of the domain name access behaviors of all users from multi-dimensional features; based on the domain name evaluation system, quantifying the outlier degree of user domain name access behaviors through an outlier detection method, and thus building a system for identifying extreme outlier behaviors of user domain name access; using domain names as a bridge to associate users with common domain name access behaviors, depicting the behavioral characteristics of user domain name access with an outlier degree feature matrix, and combining machine learning algorithms to conduct in-depth similarity analysis on user behaviors; thereby identifying potential abnormal behavior patterns and users with similar behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to a method for identifying user outlier behavior and recommending similar behavior based on a global domain name access system. Background Art

[0002] With the rapid development of Internet technology, the network has become the core platform for information transmission and exchange. The analysis of enterprise user traffic is of great significance for maintaining network order and ensuring data security. However, with the continuous progress of network technology, the encryption and anonymization of user traffic are becoming more and more common, and the diversity and complexity of user behavior are increasing continuously, which poses great challenges to the traditional content analysis-based traffic anomaly identification methods. Traditional anomaly detection technologies, such as system identification relying on fixed rules or traffic data payload analysis methods, usually show insufficient adaptability when facing the update of network protocols and encryption technologies. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide a method for identifying user outlier behavior and recommending similar behavior based on a global domain name system in view of the deficiencies of the background art, which identifies abnormal behavior and recommends similar behavior for the access domain name-related traffic generated by the user's Internet border gateway.

[0004] The present invention adopts the following technical solutions to solve the above technical problems:

[0005] A method for identifying user outlier behavior and recommending similar behavior based on domain name access specifically includes the following steps;

[0006] Step 1, construct a domain name evaluation index system according to the user access domain name frequency and the access domain name frequency behavior characteristics, and quantify the concentration degree and dispersion degree of the global user access domain name behavior from multi-dimensional features;

[0007] Step 2, based on the domain name evaluation system, quantify the outlier degree of the user access domain name behavior through the Tukey's Test outlier detection method, and thus build a user access domain name extreme outlier behavior identification system; wherein, Tukey's Test is the Tukey test;

[0008] Step 3, associate users with common domain name access behaviors with the domain name as a bridge, describe the user access domain name behavior characteristics with the outlier degree feature matrix, and conduct in-depth similarity analysis on the user behavior in combination with machine learning algorithms; thereby identifying potential abnormal behavior patterns and similar behavior users.

[0009] As a further preferred solution of the method for identifying user outlier behaviors and recommending similar behaviors based on domain name access of the present invention, in step 1, the collected message data is merged into session communication data, and a domain name evaluation index system is constructed based on the hypertext transfer protocol HTTP and secure hypertext transfer protocol HTTPS application layer protocol related traffic in the global ultra-large-scale network traffic;

[0010] Filter the session communication data and extract the session domain information. Each session flow is represented as follows:

[0011] ,in, is the user sequence of the i-th session traffic; is the source IP; is the destination IP; is the source port; is the sink port; is the domain name; Capture time for the session.

[0012] As a further preferred solution of the method for identifying user outlier behaviors and recommending similar behaviors based on domain name access of the present invention, in step 2, a domain name evaluation index system is established, which is specifically as follows: based on HTTP and HTTPS application layer protocol session data, from each peer accessed by the user Let's consider any , the user sequence set that communicates with it within a day is ,Will access Behavioral features form an ordered feature sequence according to size, thus constructing A 15-dimensional evaluation index system for the object.

[0013] As a further preferred solution of the method for identifying user outlier behaviors and recommending similar behaviors based on domain name access of the present invention, in step 2, the domain name evaluation index system specifically includes the following:

[0014] 1) Domain name overall attributes: by calculating the specified date Inside The number of peer users is used to quantify the user access to the domain name.

[0015] Based on the number of user visits, we design a secondary derived indicator, namely, the popularity of the domain name, which is to use the cumulative distribution curve to Divide domain names into super unpopular domain names, unpopular domain names, popular domain names, and popular domain names according to the number of user visits; calculate the number of host IPs associated with the domain name to indicate the number of server IP distribution of the domain name; form a three-dimensional indicator of the overall attributes of the domain name;

[0016] Number of users accessing the domain name: ,

[0017] Number of server IP addresses associated with the domain name: ,

[0018] Domain popularity: ,

[0019] in, is a distinct count function;

[0020] 2) Domain name access characteristics: specify the date Inside access Frequency characteristics, frequent characteristics,

[0021] The IP number features of the associated server are formed into an ordered feature sequence according to size, which is used to quantify The first and third digits, mean, standard deviation, and coefficient of variation of the session frequency when the user visits the session are related statistics to characterize the user visit The overall preference, central tendency and discrete tendency of session frequency form 12-dimensional indicators of domain name access characteristics; the statistical characteristics of user access domain names and the calculation formula of domain name indicators are as follows:

[0022] Frequency of visiting domain name: ;

[0023] Visit frequency quantile: ;

[0024] Average visit frequency: ;

[0025] Visit frequency standard deviation: ;

[0026] Coefficient of variation of access frequency: ;

[0027] Frequency of visiting domain names: ;

[0028] Visit frequency quantile: ;

[0029] Average access frequency: ;

[0030] Standard deviation of access frequency: ;

[0031] Coefficient of variation of access frequency: ;

[0032] Number of IP addresses associated with the domain name: ;

[0033] Quantile of associated IP numbers: ;

[0034] Mean of associated IP numbers: ;

[0035] Standard deviation of associated IP numbers: ;

[0036] Coefficient of variation of associated IP numbers: ;

[0037] is a quantile function, is a tri - quantile function; is a counting function, is a mean function, is a standard deviation function, is a coefficient of dispersion function.

[0038] As a further preferred solution of the method for identifying user outlier behavior and recommending similar behavior based on domain - name access in the present invention, in step 3, constructing the user outlier feature matrix: Based on the domain - name behavior index system and user access domain - name feature indexes built in step 2, the Tukey's test outlier identification method is used to quantify the degree of user outlier. Its principle is to judge the degree of data outlier by calculating the difference between the quartiles and the inter - quartile range IQR of the data set, that is, the tri - quantile and the quantile ;

[0039] Combining the Tukey outlier identification method and the IQR rule, the data distributed in is regarded as a positive mild outlier point, and the data in is regarded as a positive extreme outlier point; The present invention focuses on the identification of extreme outlier points;

[0040] Quantifying the outlier degree value of the user access behavior characteristics. For any domain name , calculate the positive extreme outlier degree value of the behavior characteristics of user accessing within one day. When , it is determined that has extreme outlier behavior characteristics when accessing ;

[0041] Sequence skewness correction: Considering the problem of data distribution skewness in the feature sequence in the non - experimental environment, perform a logarithmic skewness correction with base 10 on the involved feature sequence, denoted as ; Combining with the domain name evaluation index system, the calculation formulas for the outlier degree values of the frequency of user access to the domain name, the frequency, and the number of associated server IPs after correction are as follows: 1) The outlier degree value of the frequency of user access to the domain name: ; 2) The outlier degree value of the frequency of user access to the domain name: ; 3) The outlier degree value of the number of server IPs associated with the user access to the domain name: ; For n users , m domain names , the present invention constructs an n*m*3-dimensional user outlier feature matrix.

[0042] As a further preferred solution of the method for identifying user outlier behavior and recommending similar behavior based on domain name access of the present invention, for the user outlier feature matrix of user access to the domain name constructed according to Tukey’s test outlier data detection method, when the outlier degree value of the frequency of user access to the domain name, the outlier degree value of the frequency of user access to the domain name, and the outlier degree value of the number of server IPs associated with the user access to the domain name are greater than a specified threshold in a certain dimension, that is , then in this dimension, the behavior degree of this user accessing this domain name is higher than the level of other users accessing this domain name, and it is determined that there is an extreme outlier behavior when this user accesses this domain name; the present invention comprehensively considers multiple factors such as the number of users, the data distribution, and the domain name service category, and sets different outlier judgment thresholds .

[0043] As a further preferred solution of the method for identifying user outlier behavior and recommending similar behavior based on domain name access of the present invention, in step 3, based on the constructed n*m*3-dimensional user outlier feature matrix of user access to the domain name, for the fed-in user , extract the domain name set D accessed by the user within the specified time range and the user outlier feature matrix A, and use as a bridge to associate the users who have the behavior of accessing the domain name set D and the corresponding user outlier feature matrix , adopt the cosine similarity (Cosine Similarity) as the measurement standard for feature similarity, and recommend users with high similarity to the domain name access behavior of the fed-in user by calculating the cosine similarity distance between the fed-in user outlier feature matrix A and the associated user outlier feature matrix .

[0044] The present invention adopts the above technical solutions and has the following technical effects compared with the prior art:

[0045] By deeply mining the behavioral characteristics in the border gateway user traffic data, and using advanced statistical and machine learning algorithms to conduct a detailed outlier analysis of user behaviors, the present invention can more accurately discover potential abnormal behaviors by identifying outliers that are significantly different from the behaviors of most users.

[0046] From the perspective of user session behaviors, the present invention constructs a user traffic behavior feature system based on the global domain names, without decrypting the payload of the user traffic data, effectively protecting the privacy of user data, and at the same time solving the problem that the security transmission protocol messages cannot be cracked.

[0047] The present invention can effectively solve the problem that the protocol update leads to the need to retrain the model. By calculating the relative outlier behavior metrics based on the global user traffic, it can effectively adapt to the high-speed changes of network traffic, reduce the dependence on the labeled training set data, and improve the efficiency and accuracy of identifying abnormal user behaviors at the same time.

[0048] The present invention proposes a generalization recommendation algorithm, which can identify and recommend users with traffic behavior patterns similar to those of the target user, thus greatly simplifying the process of analyzing the network behavior characteristics of different users one by one. Through the outlier feature characterization based on the co-accessed domain names, the system can automatically calculate the similarity of the co-accessed domain name features and provide more accurate personalized recommendations; this method not only improves the efficiency of the recommendation system, but also enhances its applicability and accuracy in diverse user groups. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0050] Figure 1 It is the overall framework diagram of the user outlier behavior recognition and similar behavior recommendation technology based on the global domain name system of the present invention;

[0051] Figure 2 It is the flow chart of the user outlier behavior recognition and similar behavior recommendation based on the global domain name system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] The following will further elaborate on the technical solutions of the present invention in conjunction with the drawings:

[0053] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. The present invention will be described in detail below according to the accompanying drawings and preferred embodiments, and the purpose and effect of the present invention will become more apparent. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0054] The following will further elaborate on the specific implementation of this patent in conjunction with the accompanying drawings, and explain this patent with actual operation examples. Its ultimate purpose, advantages, and features will be better understood.

[0055] Figure 1 For the overall framework diagram of the user outlier behavior recognition and similar behavior recommendation technology based on the global domain name system, the recognition and recommendation system of the present invention is divided into four major parts. First, the global traffic data of a specified date is merged into session metadata, including relevant attributes. Secondly, the session traffic is initially filtered according to the application layer protocols HTTP and HTTP, and the session is filtered by the whitelist traffic using the popular domain name knowledge base, only retaining the non-whitelist session traffic generated by the user accessing the domain name. Then, a 15-dimensional index system of the domain name is characterized from two aspects of the overall domain name attributes and the accessed characteristics of the domain name, describing the attribute characteristics of the domain name and the concentration and dispersion degrees of user access in multiple dimensions. Based on the global domain name index system, combined with the outlier recognition algorithm, the outlier degree of the user's behavior in three dimensions when accessing the domain name is quantified, constructing a user access domain name outlier feature matrix, and filtering out users with extreme outlier behavior through the setting of the outlier threshold. Finally, based on the user access domain name outlier feature matrix, combined with the cosine similarity algorithm, a user similar behavior recommendation system is constructed, and by feeding in any user and date, the TOP10 users with similar domain name access behaviors are recommended.

[0056] When quantifying the outlier degree of the user's access behavior, the present invention adopts the Tukey's test outlier data detection technology. By serializing the user access domain name characteristics in different dimensions and combining the IQR rule to detect the data points with extreme outlier behavior in the sequence. The specific flow chart of the outlier detection and similarity recommendation of the user access domain name feature sequence is as Figure 2 shown;

[0057] There are two application technology services that can be realized by this system: extreme outlier behavior recognition based on the global domain name system and similar behavior user recommendation. The first application service can detect extreme outlier users accessing a specified domain name by feeding in the specified domain name and date, improving the system's computing performance; the second application service can narrow down the system's computing scope by feeding in the specified user and date, and recommend the top 10 users with the highest similarity in domain name access behavior to the fed-in user;

[0058] For application technology service 1, considering that there are large differences in the number of users accessing domain names with different popularity levels, when the system of the present invention detects whether a user has extreme access behavior, it adopts a differential threshold filtering principle for domain names with different popularity levels. For example, the outlier threshold for unpopular domain names is set to 1, the outlier threshold for popular domain names is set to 1.5, and the outlier threshold for highly popular domain names is set to 3;

[0059] For application technology service 2, when calculating the similarity between the fed-in user and the associated users of the bridge domain name, a weighted cosine similarity algorithm is introduced to adjust the similarity error caused by the difference in the magnitude of the bridge domain name between two users; for the difference in the nature of business domain names brought about by different application scenarios, this system provides similar recommendation strategies with different popularity levels. For example, in the similar recommendation strategy for unpopular domain names, when the relevant domain name in the business scenario is an unpopular domain name, only the unpopular domain names in the domain name set of the fed-in user are extracted for similar recommendation to achieve the calibration of the focus direction of the similar recommendation result.

[0060] The present invention relates to the field of network security, focusing on detecting abnormal behaviors and recommending similar behaviors of users accessing domain names in the user access domain names of ultra-large-scale organizational border gateways and network data. Based on the HTTP (HyperText Transfer Protocol) and HTTPS (HyperText Transfer Protocol Secure) traffic in the ultra-large-scale network traffic of the whole domain, a domain name evaluation index system is constructed to comprehensively and macroscopically describe the attribute characteristics of domain names and the concentration and dispersion degrees of users accessing domain names, and combined with the sequential outlier detection algorithm to quantify the outlier degree of users' behavior of accessing domain names, and combined with the cosine similarity algorithm to construct a user outlier behavior similar recommendation system, so as to identify potential abnormal behavior patterns and similar behavior users. It can be used to identify users with extreme behaviors in aspects such as malicious scanning, using group control software, and browsing pornographic, gambling, and other websites, and recommend user behaviors with similar traffic characteristics.

[0061] The purpose of this patent is to identify abnormal behaviors and recommend similar behaviors for the traffic related to accessed domain names generated by the user's Internet access border gateway in the context of Internet security. First, a domain name evaluation index system is constructed based on behavioral characteristics such as the frequency of user access to domain names and the frequency of accessing domain names, quantifying the concentration and dispersion degrees of the domain name access behaviors of all users from multi-dimensional characteristics. Second, based on the domain name evaluation system, the Tukey's Test outlier detection method is used to quantify the outlier degree of the user's domain name access behavior, thereby building a system for identifying extreme outlier behaviors of user access to domain names. Then, users with common domain name access behaviors are associated with each other through the domain name as a bridge, and the behavior characteristics of user access to domain names are described by the outlier degree feature matrix, and in-depth similarity analysis is carried out on user behaviors in combination with machine learning algorithms.

[0062] Therefore, the method system of this patent includes four major steps: building a domain name evaluation index system, constructing a user outlier feature matrix, an extreme outlier behavior detection technology, and a user similarity recommendation algorithm. The specific operation steps are as follows:

[0063] 1. Data collection and filtering: The collected packet data is merged into session connection data. The research object of this patent is the traffic related to the HTTP (HyperText Transfer Protocol) and HTTPS (HyperText Transfer Protocol Secure) application layer protocols. Therefore, the session connection data is filtered, and the session domain name information is extracted from the SNI. Each session traffic is expressed as follows: , and we define the frequency of the number of sessions for the user to access the domain name as , define the ten-minute mark, that is, the first 11 bits of the session occurrence time string, as the object of frequency measurement, and use to represent it. For example, the ten-minute mark of 202408301543 (15:44 on August 30, 2024) is 20240830154. The de-duplicated count of the ten-minute marks of the user's access to the domain name within a unit time is the access frequency. The one-to-one correspondence in the above session expression is: the user sequence, source IP, destination IP, source port, destination port, domain name, and session capture time of the i-th session traffic.

[0064] 2. Building a domain name evaluation index system: Based on the session data of the HTTP and HTTPS application layer protocols, starting from each peer accessed by the user, considering any one , record the set of user sequences that communicate with it within a day as , and arrange the access

[0065] behavioral characteristics in an ordered feature sequence according to size, thereby constructing a 15-dimensional evaluation index system with as the object. The details of the 15-dimensional indicators of the domain name evaluation index system are shown in Table 1 below:

[0066] Table 1

[0067] ,

[0068] Overall attributes of the domain name: By calculating the number of peer users within the specified date inside , the user access volume of the domain name is quantified, and a secondary derived indicator - the popularity of the domain name - is designed based on the user access volume. That is, by using the cumulative distribution curve, is divided into ultra-cold domain names, cold domain names, popular domain names, and hot domain names according to the user access volume; the number of server IPs associated with the domain name is calculated to represent the server IP distribution quantity of the domain name. A 3D indicator of the overall attributes of the domain name is formed.

[0069] Number of users accessing the domain name: , Number of server IPs associated with the domain name: , Popularity of the domain name: , is a non-repetitive counting function.

[0070] Access characteristics of the domain name: The frequency characteristics, frequency characteristics, inside access and the characteristics of the number of associated server IPs within the specified date are respectively formed into ordered characteristic sequences according to size, so as to quantify

[0071] the first and third quartiles, mean, standard deviation, and coefficient of variation of the session frequency when being accessed by users, and depict the overall preference, central tendency, and dispersion tendency of the user session frequency, forming a 12D indicator of the access characteristics of the domain name. The statistical characteristics of user access to the domain name and the calculation formulas of the domain name indicators are as follows:

[0072] Frequency of accessing the domain name: ;

[0073] Quantile of access frequency: ;

[0074] Mean of access frequency: ;

[0075] Standard deviation of access frequency: ;

[0076] Coefficient of variation of access frequency: ;

[0077] Frequency of accessing the domain name frequently: ;

[0078] Quantile of access frequency frequently: ​;

[0079] Mean access frequency: ;

[0080] Standard deviation of access frequency: ;

[0081] Coefficient of variation of access frequency: ;

[0082] Number of associated IPs for the accessed domain name: ;

[0083] Quantile of the number of associated IPs: ;

[0084] Mean of the number of associated IPs: ;

[0085] Standard deviation of the number of associated IPs: ;

[0086] Coefficient of variation of the number of associated IPs: ;

[0087] is a quantile function, is a trimean function, is a counting function, is a mean function, is a standard deviation function, is a coefficient of dispersion function.

[0088] Construction of the user outlier feature matrix: Based on the established domain name behavior index system and user access domain name feature indicators, the present invention uses Tukey's test outlier identification method to quantify the outlier degree of users. Its principle is to calculate the quartiles and interquartile range IQR (Interquartile Range) of the data set, that is, the trimean and the quantile difference to judge the outlier degree of the data. Combining Tukey's outlier identification method and the IQR rule, the data distributed in is regarded as a positive mild outlier point, and the data in is regarded as a positive extreme outlier point. The present invention focuses on the identification of extreme outlier points.

[0089] Quantify the outlier degree value of the user access behavior characteristics. For any domain name , calculate the positive extreme outlier degree value of the behavior characteristics accessed by users within one day. When , determine that accesses​ possesses extreme outlier behavior characteristics at that time.

[0090] Sequence skewness correction: Considering the problem of data distribution skewness in the feature sequence in the non-experimental environment, the logarithmic skewness correction with base 10 is performed on the feature sequence involved, denoted as . Combining with the domain name evaluation index system, the calculation formulas for the outlier degree values of the frequency, frequency, and associated server IP number of the user's accessed domain name after correction are as follows: 1) The outlier degree value of the frequency of the user's accessed domain name: ; 2) The outlier degree value of the frequency of the user's accessed domain name: ; 3) The outlier degree value of the number of associated server IPs of the user's accessed domain name: . For n users , m domain names , the present invention constructs an n*m*3-dimensional user outlier feature matrix.

[0091] Extreme outlier behavior detection technology: Based on the user's accessed domain name outlier feature matrix constructed according to the Tukey's test outlier data detection method in step 3, when the outlier degree value of the frequency of the user's accessed domain name, the outlier degree value of the frequency of the user's accessed domain name, and the outlier degree value of the number of associated server IPs of the user's accessed domain name are greater than the specified threshold in a certain dimension, that is , then in this dimension, the behavior degree of this user accessing this domain name is higher than the level of other users accessing this domain name, and it is determined that this user has extreme outlier behavior when accessing this domain name. The present invention comprehensively considers various factors such as the number of users, data distribution, and domain name service categories, and sets different outlier judgment thresholds .

[0092] User similarity recommendation algorithm: Based on the n*m*3-dimensional user's accessed domain name outlier feature matrix constructed in step 3, for the fed-in user , extract the domain name set D accessed by it within the specified time range and the user outlier feature matrix A. Taking as a bridge, associate the users who have the behavior of accessing the domain name set D and the corresponding user outlier feature matrix . The present invention uses cosine similarity (CosineSimilarity) as the measurement standard for feature similarity, and recommends users with high similarity to the domain name access behavior of the fed-in user by calculating the cosine similarity distance between the outlier feature matrix A of the fed-in user and the outlier feature matrix of the associated user.

[0093] The patented technology can be applied to a variety of business scenarios, including but not limited to the identification of extreme access behaviors on niche web pages, the identification of usage behaviors of special software such as group control, etc. It can identify extreme outlier behaviors in domain name access behaviors and can also be used in scenarios of similarity recommendation for domain name behaviors of specified users.

[0094] Those of ordinary skill in the art can understand that the above are only preferred examples of the invention and are not used to limit the invention. Although the invention has been described in detail with reference to the foregoing examples, for those skilled in the art, they can still modify the technical solutions described in the foregoing examples or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, etc. made within the spirit and principle of the invention shall be included within the protection scope of the invention. All technical features in this embodiment can be freely combined according to actual needs.

[0095] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for identifying user outlier behaviors and recommending similar behaviors based on domain name access, characterized by: The specific steps include: Step 1: construct a domain name evaluation index system based on the user's domain name access frequency, domain name access frequency and other behavioral characteristics; Step 2: Based on the domain name evaluation index system, the outlier degree of user access to domain names is quantified by using the Tukey's Test outlier detection method, and a user access to domain name outlier feature matrix is ​​constructed; wherein Tukey's Test is a Tukey test; Step 3: Conduct in-depth similarity analysis on user behaviors to identify potential abnormal behavior patterns and users with similar behaviors; In step 1, the collected message data is merged into session communication data, and a domain name evaluation index system is constructed based on the hypertext transfer protocol HTTP and secure hypertext transfer protocol HTTPS application layer protocol related traffic in the global ultra-large-scale network traffic; Filter the session communication data and extract the session domain information. Each session flow is represented as follows: Flow i (auth i ,sip i ,dip i ,sport i ,dport i ,domain i ,captime i ) Among them, auth i is the user sequence of the i-th session flow; sip i is the source IP; dip i Destination IP; sport i is the source port; dport i is the sink port; domain i is the domain name; captime i Capture time for the session; The domain name evaluation index system is built as follows: Based on the HTTP and HTTPS application layer protocol session data, starting from each peer domain visited by the user, consider any domain i , the user sequence set that communicates with it within one day is C = {auth1, auth2, auth3, ..., auth n }, and change auth i ∈C access domain i The behavioral features form an ordered feature sequence according to their size, thus constructing a domain i A 15-dimensional evaluation index system for the object; The domain name evaluation index system specifically includes the following: 1) Overall attributes of domain name: by calculating the specified date w i Internal domain i The number of peer users is used to quantify the user visits of the domain name, and a secondary derived indicator based on the user visits is designed - the popularity of the domain name, that is, the domain popularity is calculated through the cumulative distribution curve. i Divide domain names into super unpopular domain names, unpopular domain names, popular domain names, and popular domain names according to the number of user visits; calculate the number of host IPs associated with the domain name to indicate the number of server IP distribution of the domain name; form a three-dimensional indicator of the overall attributes of the domain name; Number of users accessing the domain name: C_u dm_nad (dm,w)=C_u({auth i |dm=domain i &&w=w i }) Number of server IP addresses associated with the domain name: C_u dm_nip (dm,w)=C_u({dip i |dm=domain i &&w=w i }) Domain popularity: Where, C_u(·) is a non-repeated counting function; 2) Domain name access characteristics: specify the date w i Internal auth i ∈C access domain i The frequency characteristics, frequentness characteristics, and associated server IP number characteristics are respectively formed into an ordered feature sequence according to size to quantify the domain i The first and third digits, mean, standard deviation, and coefficient of variation of the session frequency when accessed by the user characterize the user's access domain. i The overall preference, central tendency and discrete tendency of session frequency form 12-dimensional indicators of domain name access characteristics; the statistical characteristics of user access domain names and the calculation formula of domain name indicators are as follows: Frequency of visiting domain name: C f (ad,dm,w)=C({f i |ad=auth i &&dm=domain i &&w=w i }) Visit frequency quantile: F f (dm,w)={F 0.25 (C f (ad,dm,w)),F 0.75 (C f (ad,dm,w))} Average access frequency: M f (dm,w)=M(C f (ad,dm,w)) Access frequency standard deviation: Std f (dm,w)=M(C f (ad,dm,w)) Coefficient of variation of access frequency: Frequency of visiting domain name: C_u freq (ad,dm,w)=C_u({freq i |ad=auth i &&dm=domain i &&w=w i }) Access frequency quantile: F freq (dm,w)={F 0.25 (C_u freq (ad,dm,w)), F 0.75 (C_u freq (ad,dm,w))} Average access frequency: M freq (dm,w)=M(C_u freq (ad,dm,w)) Access frequency standard deviation: Std freq (dm,w)=M(C freq (ad,dm,w)) Coefficient of variation of access frequency: Number of IP addresses associated with the domain name: C_u dip (ad,dm,w)=C_u({dip i |ad=auth i &&dm=domain i &&w=w i }) Percentile of associated IP number: F dip (dm,w)={F 0.25 (C_u dip (ad,dm,w)),F 0.75 (C_u dip (ad,dm,w))} Average number of associated IP addresses: M dip (dm,w)=M(C_u dip (ad,dm,w)) Standard deviation of the number of associated IPs: Std dip (dm,w)=M(C dip (ad,dm,w)) Coefficient of variation of associated IP number: F 0.25 (·) is a quantile function, F 0.75 (·) is the tertile function, C(·) is the count function, M(·) is the mean function, Std(·) is the standard deviation function, and CV(·) is the coefficient of dispersion function; In step 2, Tukey's test outlier identification method is used to quantify the degree of user outlier. The principle is to calculate the quartile and interquartile range (IQR) of the data set, that is, the tertile F 0.75 (·) and the first quantile F 0.25 (·) to determine the degree of data outlier; Combining Tukey's outlier identification method and IQR rule, the distribution in [F 0.75 (·)+1.5*IQR,+∞] is considered as a positive mild outlier. 0.75 (·)+3*IQR,+∞] data are considered positive extreme outliers; Quantify the outlier value of user access behavior characteristics, for any domain name domain i , calculate the user auth within one day i ∈C access domain i Behavioral characteristics The positive extreme outlier degree value When k 正向 >1, determine auth i Visit domain i Possessing extreme outlier behavior characteristics; Sequence skewness correction: Considering the problem of data distribution skewness of feature sequences in non-experimental environments, a logarithmic skewness correction with a base of 10 is performed on the feature sequences involved, denoted as L[x]=log 10 x; combined with the domain name evaluation index system, the corrected user access domain name frequency, frequency, and outlier degree value calculation formula of the number of associated server IP addresses are as follows: 1) The frequency of users accessing domain names outliers: 2) User access frequency outlier value of domain name: 3) The outlier value of the number of server IP addresses associated with the domain name accessed by the user: For n user auth i 、m domain names domain i , construct an n*m*3 dimensional user outlier feature matrix; In step 3, based on the constructed n*m*3-dimensional user access domain name outlier feature matrix, when the user access domain name frequency outlier value, the user access domain name frequency outlier value, and the user access domain name associated server IP number outlier value exist in a certain dimension greater than the specified threshold situation, that is In this dimension, the user's level of access to the domain name is much higher than that of other users who access the domain name, and it is determined that the user has extreme outlier behavior when accessing the domain name; For input user auth i , extract the domain name set D visited within the specified time range and the user outlier feature matrix A, with domain i ∈D is a bridge, which associates users {auth1, auth2, ..., auth n } and the corresponding user outlier feature matrix B i ∈{B1,B2,......,B n }, using cosine similarity as the metric for feature similarity, by calculating the input user outlier feature matrix A and the associated user outlier feature matrix B i ∈{B1,B2,......,B n }, recommending users whose domain name access behavior is similar to the input user.

Citation Information

Patent Citations

  • Cc attack detection method based on statistical method

    CN110519266A

  • System and method for detecting anomaly

    WO2020210976A1