User Security Behavior Analysis Method Based on Multi-Data Fusion
By setting monitoring periods and sample periods in user safety behavior analysis, analyzing the frequency and duration of early warning signal, dividing user types and sorting applications, the problem of insufficient accuracy and targetedness of user behavior analysis in the prior art is solved, and more efficient abnormal behavior recognition is achieved.
Patent Information
- Application Number
- CN202411583813.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-07
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2044-11-07
AI Technical Summary
The existing user safety behavior analysis methods lack in-depth analysis of user behavior patterns, cannot effectively identify abnormal behaviors, and lack targeting.
By setting the safety behavior monitoring period and multiple sample monitoring periods, the warning frequency and average signal warning time of the characteristic warning signal are analyzed, the preliminary analysis coefficients of safety behavior and sample analysis coefficients are obtained, the users are divided into the first and second types of safety users, and the application is sorted and analyzed, the program run time ratio and quantity ratio are obtained, and the safety behavior is analyzed and judged based on user behavior data.
It improves the accuracy of identification of user abnormal behavior and the pertinence of analysis, and can more accurately judge the user's behavior in the operating system.
Smart Images

Figure CN119513929B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security, relates to multi-data fusion technology, and specifically is a method for analyzing user security behavior based on multi-data fusion. Background Art
[0002] When analyzing user behavior security using existing user security behavior analysis methods, the following defects exist:
[0003] 1. Existing user security behavior analysis methods only give security reminders through the virus prevention software built into the operating system. The anti-virus software built into the operating system generally focuses on the security of files and programs, thus lacking in-depth analysis of user behavior patterns and being unable to effectively identify abnormal behaviors;
[0004] 2. Existing security behavior analysis tools usually use fixed detection modes to detect security behaviors, and are unable to analyze security behaviors according to the behavior habits of users in the operating system, resulting in the lack of pertinence of user security behavior analysis methods;
[0005] Therefore, we propose a method for analyzing user security behavior based on multi-data fusion. Summary of the Invention
[0006] Aiming at the deficiencies of the existing technology, the object of the present invention is to provide a method for analyzing user security behavior based on multi-data fusion. The present invention is based on separately setting a security behavior monitoring period and multiple sample monitoring periods, respectively analyzing the warning frequency and average warning duration of feature warning signals in each monitoring period, and obtaining a preliminary security behavior analysis coefficient and multiple sample analysis coefficients to obtain user behavior monitoring data. By analyzing the user behavior monitoring data, a preliminary security behavior analysis threshold is obtained. The preliminary security behavior analysis threshold is numerically compared with the preliminary security behavior analysis coefficient, and users in the security behavior monitoring period are divided into first-type secure users and second-type secure users to obtain preliminary user behavior classification data. In multiple sample monitoring periods, the application programs running by users in the operating system are sorted to obtain multiple common-order programs. The application programs run by the second-type secure users in the security behavior monitoring period are analyzed for running order and running duration with the multiple common-order programs to obtain the ratio of the number of unconventional programs and the ratio of program running duration. The ratio of program running duration and the ratio of the number of unconventional programs are defined as user behavior analysis data. Abnormal behavior warnings are directly issued to the first-type secure users, and for the second-type secure users, security behavior judgment is carried out by combining user behavior monitoring data and user behavior analysis data, and security behavior warnings are issued according to the judgment results.
[0007] To achieve the above object, the present invention adopts the following technical solutions: The method for analyzing user security behavior based on multi-data fusion specifically includes the following steps:
[0008] Step S1: Set the security behavior monitoring period and multiple sample monitoring periods, analyze the warning frequency and average warning duration of the feature warning signals in each monitoring period, obtain the preliminary security behavior analysis coefficient and multiple sample analysis coefficients, and obtain the user behavior monitoring data;
[0009] Step S2: Obtain the preliminary security behavior analysis threshold by analyzing the user behavior monitoring data, compare the numerical values of the preliminary security behavior analysis threshold and the preliminary security behavior analysis coefficient, and divide the users in the security behavior monitoring period into the first type of secure users and the second type of secure users to obtain the preliminary user behavior classification data;
[0010] Step S3: In multiple sample monitoring periods, sort the application programs running by the user in the operating system to obtain multiple common programs in order. Analyze the running order and running duration of the application programs run by the second type of secure users during the security behavior monitoring period compared with the multiple common programs in order to obtain the ratio of the number of non-conventional programs and the ratio of program running duration. Define the ratio of program running duration and the ratio of the number of non-conventional programs as the user behavior analysis data;
[0011] Step S4: Directly issue an abnormal behavior warning to the first type of secure users, and conduct a security behavior judgment on the second type of secure users by combining the user behavior monitoring data and the user behavior analysis data, and issue a security behavior warning according to the judgment result.
[0012] Further, in the step S1, the following specific steps are further included:
[0013] Step S11: Use the time value corresponding to the current moment as the reference time point, and use the previous feature duration before the reference time point as the security behavior monitoring period;
[0014] Step S12: Obtain multiple sample monitoring periods with a duration of the feature duration before the security behavior monitoring period, and name them the first sample monitoring period to the b-th sample monitoring period respectively;
[0015] Step S13: Conduct a preliminary security behavior analysis on the security behavior monitoring period to obtain the preliminary security behavior analysis coefficient;
[0016] Step S14: Obtain the preliminary security behavior analysis coefficients corresponding to the first sample monitoring period to the b-th sample monitoring period respectively to obtain the first sample analysis coefficient to the b-th sample analysis coefficient;
[0017] Step S15: define the safety behavior monitoring period, the first sample monitoring period to the bth sample monitoring period, the first sample analysis coefficient to the bth sample analysis coefficient, and the safety behavior preliminary analysis coefficient as user behavior monitoring data, and proceed to step S2.
[0018] Furthermore, the step S13 further includes the following specific steps:
[0019] Step S131: selecting c abnormal behavior warning signals of the operating system as characteristic warning signals during the safety behavior monitoring period, and naming them as the first characteristic warning signal to the cth characteristic warning signal respectively;
[0020] Step S132: Obtain the cumulative number of occurrences of the first characteristic warning signal during the safety behavior monitoring period to obtain the number of occurrences of the first signal, obtain the duration value corresponding to the safety behavior monitoring period to obtain the characteristic duration value, calculate the ratio of the number of occurrences of the first signal to the characteristic duration value, obtain the warning frequency value corresponding to the first characteristic warning signal, and name it as the first warning frequency value;
[0021] Step S133: respectively acquiring the warning frequency values corresponding to the second characteristic warning signal to the cth characteristic warning signal, to obtain the second warning frequency value to the cth warning frequency value;
[0022] Step S134: Obtain the warning duration corresponding to each occurrence of the first characteristic warning signal during the safety behavior monitoring period, obtain multiple signal warning durations, and average the obtained multiple signal warning durations to obtain the average warning duration corresponding to the first characteristic warning signal, and name it the first signal average warning duration;
[0023] Step S135: Obtain the average warning durations corresponding to the second characteristic warning signal to the cth characteristic warning signal, and obtain the average warning duration of the second signal to the cth signal;
[0024] Step S136: Calculate the safety behavior preliminary analysis coefficient by combining the first warning frequency value to the cth warning frequency value and the first signal average warning duration to the cth signal average warning duration;
[0025] Calculate the preliminary analysis coefficient of safety behavior. The specific formula is as follows:
[0026]
[0027] Among them, Aqf is the preliminary analysis coefficient of safety behavior, Yjp1 to Yjpc are the values of the first warning frequency to the cth warning frequency, Ysc1 to Yscc are the average warning duration of the first signal to the cth signal, and c is the number of types corresponding to the characteristic warning signal.
[0028] Furthermore, the step S2 further includes the following specific steps:
[0029] Step S21: Obtain user behavior monitoring data, and obtain a preliminary safety behavior analysis coefficient and first to bth sample analysis coefficients based on the user behavior monitoring data;
[0030] Step S22: Obtaining a preliminary safety behavior analysis threshold value based on the first sample analysis coefficient to the bth sample analysis coefficient;
[0031] The step S22 further includes the following specific steps:
[0032] Step S221: Calculate the average of the first sample analysis coefficient to the bth sample analysis coefficient to obtain the average value of the sample analysis coefficients;
[0033] Step S222: performing variance calculation on the first sample analysis coefficient to the bth sample analysis coefficient to obtain the sample average analysis variance;
[0034] Step S223: Calculate the sample analysis coefficient average and the sample average analysis variance to obtain a preliminary safety behavior analysis threshold;
[0035] Calculate the threshold for preliminary analysis of security behavior. The specific formula is as follows:
[0036]
[0037] Among them, Aqy is the preliminary analysis threshold of safety behavior, Ypf is the average value of sample analysis coefficient, and Fcf is the sample average analysis variance;
[0038] Step S23: numerically comparing the safety behavior preliminary analysis coefficient with the safety behavior preliminary analysis threshold, and defining the numerical comparison result as safety behavior preliminary classification data;
[0039] The step S23 further includes the following specific steps:
[0040] Step S231: When the safety behavior preliminary analysis coefficient is greater than or equal to the safety behavior preliminary analysis threshold, the user in the safety behavior monitoring period is classified as a first type of safe user;
[0041] Step S232: When the preliminary safety behavior analysis coefficient is less than the preliminary safety behavior analysis threshold, the users during the safety behavior monitoring period are classified as second-type safe users;
[0042] Step S24: Define the preliminary safety behavior analysis threshold and the preliminary safety behavior classification data as the preliminary user behavior classification data, and enter Step S3.
[0043] Furthermore, in the said Step S3, it further includes the following specific steps:
[0044] Step S31: Obtain the user behavior monitoring data, and based on the user behavior monitoring data, obtain the safety behavior monitoring period, the first sample monitoring period to the b-th sample monitoring period, and the preliminary safety behavior classification data;
[0045] Step S32: Sort the application programs run by the user in the operating system during the first sample monitoring period to the b-th sample monitoring period to obtain the first-ranked common program to the d-th ranked common program;
[0046] Step S33: Obtain the ratio of the number of unconventional programs based on the first-ranked common program to the d-th ranked common program;
[0047] Step S34: Obtain the ratio of the program running duration based on the first-ranked common program to the d-th ranked common program;
[0048] Step S35: Define the ratio of the program running duration and the ratio of the number of unconventional programs as the user behavior analysis data.
[0049] Furthermore, in the said Step S32, it further includes the following specific steps:
[0050] Step S321: During the first sample monitoring period, obtain the application program that the user starts running first in the operating system, and use it as the first-ranked running program. Obtain the first-ranked running programs corresponding to the second to the b-th sample monitoring periods respectively to get b first-ranked running programs;
[0051] Step S322: Conduct name statistics on each of the first-ranked running programs respectively to obtain multiple programs with different names, and conduct name occurrence frequency statistics on each program with a different name. Mark the maximum occurrence frequency as the peak statistics frequency. When the peak statistics frequency is greater than the effective statistics frequency, mark the first-ranked running program corresponding to the peak statistics frequency as the first-ranked common program;
[0052] Step S323: During the first sample monitoring period, obtain the application programs that the user runs after the first-rank common program in the operating system, and use them as the second-rank running programs. Obtain the second-rank running programs corresponding to the second to the b-th sample monitoring periods respectively, and obtain b first-rank running programs;
[0053] Step S324: Conduct name statistics for each of the second-rank running programs respectively to obtain multiple programs with different names, and conduct frequency statistics on the occurrences of each different name. Mark the highest occurrence frequency as the peak statistical frequency. When the peak statistical frequency is greater than the effective statistical frequency, mark the running program corresponding to the peak statistical frequency as the second-rank common program;
[0054] Step S325: Obtain the third-rank common program to the d-th rank common program respectively.
[0055] Furthermore, in the said step S33, it further includes the following specific steps:
[0056] Step S331: Obtain the application program that the user starts running first during the security behavior monitoring period to obtain the first actual running program, obtain the application program that runs after the first actual running program to obtain the second actual running program, and obtain the third actual running program to the d-th actual running program respectively;
[0057] Step S332: Conduct program name character matching between the first actual running program to the d-th actual running program and the first-rank common program to the d-th rank common program. If the character matching results are the same, mark the corresponding application program as a regular order application program; if the character matching results are different, mark the corresponding application program as an irregular order application program;
[0058] Step S333: Conduct quantity statistics on the irregular order application programs to obtain the irregular program quantity value, and calculate the ratio of the irregular program quantity value to d to obtain the irregular program quantity ratio.
[0059] Furthermore, in the said step S34, it further includes the following specific steps:
[0060] Step S341: Obtain the average single-run duration of the first-rank common program in each sample monitoring period to obtain multiple first-program single-run durations, and calculate the average of the obtained multiple first-program single-run durations to obtain the first-program single average run duration;
[0061] Step S342: Obtain the program single average run durations corresponding to the second-rank common program to the d-th rank common program respectively to obtain the second-program single average run duration to the d-th program single average run duration;
[0062] Step S343: During the security behavior monitoring period, obtain the actual running durations corresponding to the first-rank common program to the d-rank common program respectively, and obtain the first program actual running duration to the d program actual running duration;
[0063] Step S345: Calculate the program running duration ratio by calculating the first program actual running duration to the d program actual running duration and the first program single average running duration to the d program single average running duration;
[0064] Calculate the program running duration ratio, and the specific formula configuration is as follows:
[0065]
[0066] Among them, Cyb is the program running duration ratio, Sjs1 to Sjsd are the first program actual running duration to the d program actual running duration respectively, and Pjs1 to Pjsd are the first program single average running duration to the d program single average running duration respectively.
[0067] Furthermore, in the step S4, the following specific steps are further included:
[0068] Step S41: Obtain the preliminary user behavior classification data, and issue an abnormal behavior warning to the first type of secure users during the security behavior monitoring period;
[0069] Step S42: Conduct a security behavior study and judgment on the second type of secure users during the security behavior monitoring period.
[0070] Furthermore, in the step S42, the following specific steps are further included:
[0071] Step S421: Obtain the preliminary security behavior analysis coefficient according to the user behavior monitoring data, and obtain the program running duration ratio and the non-conventional program quantity ratio according to the user behavior analysis data;
[0072] Step S422: Calculate the user security behavior study and judgment coefficient by calculating the preliminary security behavior analysis coefficient, the program running duration ratio and the non-conventional program quantity ratio;
[0073] Calculate the user security behavior study and judgment coefficient, and the specific formula is as follows:
[0074] Ypx = Aqf + Cyb + Fcg;
[0075] Among them, Ypx is the user security behavior study and judgment coefficient, Aqf is the preliminary security behavior analysis coefficient, Cyb is the program running duration ratio, and Fcg is the non-conventional program quantity ratio;
[0076] Step S423: Based on user behavior, preliminarily divide the preliminary analysis threshold of data acquisition security behavior, and obtain the threshold of program running duration ratio and the threshold of the ratio of the number of unconventional programs respectively;
[0077] Step S424: Calculate the user security behavior judgment coefficient threshold through the preliminary analysis threshold of security behavior, the program running duration ratio threshold, and the ratio threshold of the number of unconventional programs;
[0078] Step S425: When the user security behavior judgment coefficient is greater than or equal to the user security behavior judgment coefficient threshold, issue a security behavior warning to the user;
[0079] Step S426: When the user security behavior judgment coefficient is less than the user security behavior judgment coefficient threshold, continue to monitor the user's security behavior.
[0080] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are as follows:
[0081] 1. While conducting security analysis through traditional built-in antivirus software, the present invention collects the user's behavior in the operating system, obtains the user security behavior judgment coefficient to further complete the security behavior judgment, and can effectively improve the recognition accuracy of user abnormal behavior;
[0082] 2. The present invention obtains the user behavior habits of the user in the historical monitoring period and compares them with the user behavior analysis data in the monitoring period. Through historical data, the system can identify the user's unique behavior patterns, including specific activity times, frequencies, and behavior types, so as to analyze the user's behavior in the monitoring period specifically, and can more accurately judge abnormal behavior, thereby improving the pertinence of the user security behavior analysis method. BRIEF DESCRIPTION OF THE DRAWINGS
[0083] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.
[0084] Figure 1 It is the implementation step diagram of the present invention;
[0085] Figure 2 It is the overall system block diagram of the present invention;
[0086] Figure 3 It is the schematic diagram of program name matching in the invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0087] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative work belong to the scope of protection of the present invention.
[0088] Embodiment 1:
[0089] Please refer to Figure 1 , the present invention provides a technical solution: a user security behavior analysis method based on multi-data fusion, including the following specific steps:
[0090] Step S1: Obtain the security behavior monitoring period, multiple sample monitoring periods, multiple sample analysis coefficients, and the preliminary security behavior analysis coefficient respectively to obtain user behavior monitoring data;
[0091] In step S11: Take the time value corresponding to the current moment as the reference time point, and take the previous characteristic duration before the reference time point as the security behavior monitoring period;
[0092] In step S12: Obtain multiple sample monitoring periods with a duration of the characteristic duration before the security behavior monitoring period, and name them the first sample monitoring period to the b-th sample monitoring period respectively;
[0093] In step S13: Conduct a preliminary security behavior analysis on the security behavior monitoring period to obtain the preliminary security behavior analysis coefficient;
[0094] In the above step S13, it further includes the following specific steps:
[0095] In step S131: Select c abnormal behavior warning signals provided by the operating system as characteristic warning signals in the security behavior monitoring period, and name them the first characteristic warning signal to the c-th characteristic warning signal respectively;
[0096] In step S132: Obtain the cumulative occurrence times of the first characteristic warning signal in the security behavior monitoring period to obtain the first signal occurrence times, obtain the duration value corresponding to the security behavior monitoring period to obtain the characteristic duration value, calculate the ratio of the first signal occurrence times to the characteristic duration value, obtain the warning frequency value corresponding to the first characteristic warning signal, and name it the first warning frequency value;
[0097] In step S133: Obtain the warning frequency values corresponding to the second characteristic warning signal to the c-th characteristic warning signal respectively to obtain the second warning frequency value to the c-th warning frequency value;
[0098] Step S134: Obtain the warning duration corresponding to each occurrence of the first feature warning signal during the safety behavior monitoring period, obtaining multiple signal warning durations, calculate the average of the obtained multiple signal warning durations, obtain the average warning duration corresponding to the first feature warning signal, and name it the first signal average warning duration;
[0099] Step S135: Respectively obtain the average warning durations corresponding to the second feature warning signal to the c-th feature warning signal, obtaining the second signal average warning duration to the c-th signal average warning duration;
[0100] Step S136: Calculate the preliminary safety behavior analysis coefficient from the first warning frequency value to the c-th warning frequency value and the first signal average warning duration to the c-th signal average warning duration;
[0101] Calculate the preliminary safety behavior analysis coefficient, and the specific formula configuration is as follows:
[0102]
[0103] Among them, Aqf is the preliminary safety behavior analysis coefficient, Yjp1 to Yjpc are the first warning frequency value to the c-th warning frequency value respectively, Ysc1 to Yscc are the first signal average warning duration to the c-th signal average warning duration respectively, and c is the type quantity value corresponding to the feature warning signal;
[0104] Step S14: Respectively obtain the preliminary safety behavior analysis coefficients corresponding to the first sample monitoring period to the b-th sample monitoring period, obtaining the first sample analysis coefficient to the b-th sample analysis coefficient;
[0105] Step S15: Define the safety behavior monitoring period, the first sample monitoring period to the b-th sample monitoring period, the first sample analysis coefficient to the b-th sample analysis coefficient, and the preliminary safety behavior analysis coefficient as user behavior monitoring data;
[0106] Step S2: Obtain the preliminary safety behavior analysis threshold according to the user behavior monitoring data, compare the preliminary safety behavior analysis coefficient with the preliminary safety behavior analysis threshold, and obtain the preliminary user behavior classification data;
[0107] Step S21: Obtain the user behavior monitoring data, and obtain the preliminary safety behavior analysis coefficient and the first sample analysis coefficient to the b-th sample analysis coefficient according to the user behavior monitoring data;
[0108] Step S22: Obtain the preliminary safety behavior analysis threshold according to the first sample analysis coefficient to the b-th sample analysis coefficient;
[0109] In the said step S22, the following specific steps are further included:
[0110] Step S221: Calculate the average of the first sample analysis coefficient to the b-th sample analysis coefficient to obtain the average value of the sample analysis coefficient;
[0111] Step S222: Calculate the variance of the first sample analysis coefficient to the b-th sample analysis coefficient to obtain the average analysis variance of the sample;
[0112] Step S223: Calculate the preliminary analysis threshold for safe behavior by calculating the average value of the sample analysis coefficient and the average analysis variance of the sample;
[0113] Calculate the preliminary analysis threshold for safe behavior, and the specific formula configuration is as follows:
[0114]
[0115] Among them, Aqy is the preliminary analysis threshold for safe behavior, Ypf is the average value of the sample analysis coefficient, and Fcf is the average analysis variance of the sample;
[0116] Step S23: Compare the preliminary analysis coefficient of safe behavior with the preliminary analysis threshold for safe behavior, and define the result of the numerical comparison as the preliminary classification data of safe behavior;
[0117] In the said step S23, the following specific steps are further included:
[0118] Step S231: When the preliminary analysis coefficient of safe behavior is greater than or equal to the preliminary analysis threshold for safe behavior, classify the users in the safe behavior monitoring period as the first type of safe users;
[0119] Step S232: When the preliminary analysis coefficient of safe behavior is less than the preliminary analysis threshold for safe behavior, classify the users in the safe behavior monitoring period as the second type of safe users;
[0120] Step S24: Define the preliminary analysis threshold for safe behavior and the preliminary classification data of safe behavior as the preliminary classification data of user behavior;
[0121] Step S3: Monitor the safe behavior of the second type of safe users according to the user behavior monitoring data, and obtain the program running duration ratio and the non-conventional program quantity ratio to obtain the user behavior analysis data;
[0122] Step S31: Obtain the user behavior monitoring data, and obtain the safe behavior monitoring period, the first sample monitoring period to the b-th sample monitoring period, and the preliminary classification data of safe behavior according to the user behavior monitoring data;
[0123] Step S32: Sort the application programs run by the user in the operating system within the first sample monitoring period to the b-th sample monitoring period to obtain the first-ranked common program to the d-th ranked common program;
[0124] In step S32, the following specific steps are further included:
[0125] Step S321: During the first sample monitoring period, obtain the application program that the user first starts running in the operating system, and use it as the first-rank running program. Respectively obtain the first-rank running programs corresponding to the second to the b-th sample monitoring periods to obtain b first-rank running programs;
[0126] Step S322: Respectively perform name statistics on each first-rank running program to obtain multiple programs with different names, and perform name occurrence frequency statistics on each program with a different name. Mark the maximum occurrence frequency value as the peak statistics frequency. When the peak statistics frequency is greater than the effective statistics frequency, mark the first-rank running program corresponding to the peak statistics frequency as the first-rank common program;
[0127] Step S323: During the first sample monitoring period, obtain the application program that the user runs after the first-rank common program in the operating system, and use it as the second-rank running program. Respectively obtain the second-rank running programs corresponding to the second to the b-th sample monitoring periods to obtain b first-rank running programs;
[0128] Step S324: Respectively perform name statistics on each second-rank running program to obtain multiple programs with different names, and perform name occurrence frequency statistics on each program with a different name. Mark the maximum occurrence frequency value as the peak statistics frequency. When the peak statistics frequency is greater than the effective statistics frequency, mark the running program corresponding to the peak statistics frequency as the second-rank common program;
[0129] Step S325: Repeat steps S321 to S324 to respectively obtain the third-rank common program to the d-th rank common program;
[0130] Step S33: Obtain the non-conventional program quantity ratio according to the first-rank common program to the d-th rank common program;
[0131] In step S33, the following specific steps are further included:
[0132] Step S331: Obtain the application program that the user first starts running during the security behavior monitoring period to obtain the first actual running program, obtain the application program that the user runs after the first actual running program of the first-started running program to obtain the second actual running program, and respectively obtain the third to the d-th actual running;
[0133] Step S332: When the first actual running program performs program name character matching with the d-th actual running program and the d-th common program in the first order, if the character matching results are the same, mark the corresponding application program as a regular order application program; if the character matching results are different, mark the corresponding application program as an irregular order application program.
[0134] Step S333: Count the number of irregular order application programs to obtain the value of the number of irregular programs, and calculate the ratio of the value of the number of irregular programs to d to obtain the ratio of the number of irregular programs.
[0135] Step S34: Obtain the program running duration ratio according to the d-th common program in the first order to the d-th common program.
[0136] In the said Step S34, the following specific steps are further included:
[0137] Step S341: Obtain the average single running duration of the first common program in each sample monitoring period to obtain multiple single running durations of the first program, and calculate the average of the obtained multiple single running durations of the first program to obtain the average single running duration of the first program.
[0138] Step S342: Respectively obtain the average single running duration of the program corresponding to the second common program to the d-th common program to obtain the average single running duration of the second program to the average single running duration of the d-th program.
[0139] Step S343: In the security behavior monitoring period, respectively obtain the actual running duration of the first common program to the d-th common program to obtain the actual running duration of the first program to the actual running duration of the d-th program.
[0140] Step S345: Calculate the actual running duration of the first program to the actual running duration of the d-th program and the average single running duration of the first program to the average single running duration of the d-th program to obtain the program running duration ratio.
[0141] Calculate the program running duration ratio, and the specific formula configuration is as follows:
[0142]
[0143] Among them, Cyb is the program running duration ratio, Sjs1 to Sjsd are respectively the actual running duration of the first program to the actual running duration of the d-th program, and Pjs1 to Pjsd are respectively the average single running duration of the first program to the average single running duration of the d-th program.
[0144] Step S35: Define the program running duration ratio and the ratio of the number of irregular programs as user behavior analysis data.
[0145] Step S4: Conduct a security behavior judgment on users during the security behavior monitoring period based on the user behavior monitoring data, the preliminary user behavior classification data, and the user behavior analysis data, and issue a security behavior warning according to the judgment result;
[0146] Step S41: Obtain the preliminary user behavior classification data. When the user during the security behavior monitoring period is a first-type secure user, issue an abnormal behavior warning;
[0147] Step S42: When the user during the security behavior monitoring period is a second-type secure user, conduct a security behavior judgment on the user;
[0148] In the said Step S42, the following specific steps are further included:
[0149] Step S421: Obtain the preliminary security behavior analysis coefficient according to the user behavior monitoring data, and obtain the program running duration ratio and the non-conventional program quantity ratio according to the user behavior analysis data;
[0150] Step S422: Calculate the user security behavior judgment coefficient by using the preliminary security behavior analysis coefficient, the program running duration ratio, and the non-conventional program quantity ratio;
[0151] Calculate the user security behavior judgment coefficient, and the specific formula is as follows:
[0152] Ypx = Aqf + Cyb + Fcg;
[0153] Wherein, Ypx is the user security behavior judgment coefficient, Aqf is the preliminary security behavior analysis coefficient, Cyb is the program running duration ratio, and Fcg is the non-conventional program quantity ratio;
[0154] Step S423: Obtain the preliminary security behavior analysis threshold according to the preliminary user behavior classification data, and respectively obtain the program running duration ratio threshold and the non-conventional program quantity ratio threshold;
[0155] Step S424: Calculate the user security behavior judgment coefficient threshold by using the preliminary security behavior analysis threshold, the program running duration ratio threshold, and the non-conventional program quantity ratio threshold;
[0156] Step S425: When the user security behavior judgment coefficient is greater than or equal to the user security behavior judgment coefficient threshold, issue a security behavior warning to the user;
[0157] Step S426: When the user security behavior judgment coefficient is less than the user security behavior judgment coefficient threshold, continue to conduct security behavior monitoring on the user.
[0158] In this application, if there are corresponding calculation formulas, the above calculation formulas are all dimensionless and take their numerical values for calculation. The coefficients such as weight coefficients and proportionality coefficients in the formulas are set to obtain a result value by quantifying each parameter. Regarding the magnitudes of the weight coefficients and proportionality coefficients, as long as the proportional relationship between the parameters and the result value is not affected.
[0159] Example Two
[0160] Please refer to Figure 2 , based on another concept of the same invention, a user security behavior analysis system based on multi - data fusion applicable to a user security behavior analysis method based on multi - data fusion is proposed. The user security behavior analysis system includes a data acquisition module, a primary division module, a behavior analysis module, a security judgment module, and a server. The data acquisition module, the primary division module, the behavior analysis module, and the security judgment module are respectively connected to the server, and the server controls the data acquisition module, the primary division module, the behavior analysis module, and the security judgment module respectively;
[0161] The data acquisition module respectively acquires the security behavior monitoring time period, and conducts a preliminary security behavior analysis on the user behavior during the security behavior monitoring time period to obtain a preliminary security behavior analysis coefficient. It acquires the first sample monitoring time period to the b - th sample monitoring time period, and conducts a preliminary security behavior analysis on the first sample monitoring time period to the b - th sample monitoring time period through analysis to obtain the first sample analysis coefficient to the b - th sample analysis coefficient. The security behavior monitoring time period, the first sample monitoring time period to the b - th sample monitoring time period, the first sample analysis coefficient to the b - th sample analysis coefficient, and the preliminary security behavior analysis coefficient are defined as user behavior monitoring data;
[0162] The time value corresponding to the current moment is used as the reference time point, and a characteristic time period before the reference time point is used as the security behavior monitoring time period;
[0163] Before the security behavior monitoring time period, multiple sample monitoring time periods with a duration of the characteristic time period are acquired and named the first sample monitoring time period to the b - th sample monitoring time period respectively;
[0164] It should be noted here that:
[0165] The b involved here is the numerical value corresponding to the number of sample monitoring time periods, and b is an integer greater than 0, and there are no security hazards in the user behavior corresponding to each sample monitoring time period;
[0166] It should be noted here that:
[0167] The security behavior monitoring time period involved here is specifically the time period when the user performs more fixed operations on the operating system, which can be the working time period here;
[0168] The duration corresponding to the safe behavior monitoring period can be 9 hours, and in this application, as the time value corresponding to the current moment changes, the reference time point also changes accordingly, so as to realize the dynamic update of the safe behavior monitoring period;
[0169] Perform a preliminary safe behavior analysis on the safe behavior monitoring period to obtain a preliminary safe behavior analysis coefficient;
[0170] Specifically as follows:
[0171] During the safe behavior monitoring period, c abnormal behavior warning signals provided by the operating system are respectively selected as characteristic warning signals, and they are respectively named the first characteristic warning signal to the c-th characteristic warning signal;
[0172] It should be noted here that:
[0173] In this application, the first characteristic warning signal involved here can be a Ddos abnormal warning signal, the second characteristic warning signal can be a traffic abnormal fluctuation signal, the third characteristic warning signal can be a network connection abnormal warning signal. Here, c is the type quantity value corresponding to the characteristic warning signal, and c is an integer greater than 0. In actual applications, the specific types corresponding to the characteristic warning signals can be specifically set according to the actual situation;
[0174] Obtain the cumulative occurrence times of the first characteristic warning signal during the safe behavior monitoring period to get the first signal occurrence times, obtain the duration value corresponding to the safe behavior monitoring period to get the characteristic duration value, calculate the ratio of the first signal occurrence times to the characteristic duration value to get the warning frequency value corresponding to the first characteristic warning signal, and name it the first warning frequency value;
[0175] Obtain the warning frequency values corresponding to the second characteristic warning signal to the c-th characteristic warning signal respectively to get the second warning frequency value to the c-th warning frequency value;
[0176] Obtain the warning duration corresponding to each occurrence of the first characteristic warning signal during the safe behavior monitoring period to get multiple signal warning durations, and calculate the average of the obtained multiple signal warning durations to get the average warning duration corresponding to the first characteristic warning signal, and name it the first signal average warning duration;
[0177] Obtain the average warning durations corresponding to the second characteristic warning signal to the c-th characteristic warning signal respectively to get the second signal average warning duration to the c-th signal average warning duration;
[0178] Calculate the first warning frequency value to the c-th warning frequency value and the first signal average warning duration to the c-th signal average warning duration to obtain a preliminary safe behavior analysis coefficient;
[0179] Calculate the preliminary analysis coefficient of safety behavior, and the specific formula configuration is as follows:
[0180]
[0181] Among them, Aqf is the preliminary analysis coefficient of safety behavior, Yjp1 to Yjpc are the first warning frequency value to the cth warning frequency value respectively, Ysc1 to Yscc are the first signal average warning duration to the cth signal average warning duration respectively, and c is the type quantity value corresponding to the characteristic warning signal;
[0182] Obtain the preliminary analysis coefficients of safety behavior corresponding to the first sample monitoring period to the bth sample monitoring period respectively, and obtain the first sample analysis coefficient to the bth sample analysis coefficient;
[0183] It should be noted here that:
[0184] The first sample analysis coefficient to the bth sample analysis coefficient involved here correspond one-to-one with the preliminary analysis coefficients of safety behavior corresponding to the first sample monitoring period to the bth sample monitoring period, that is, the first sample analysis coefficient is the preliminary analysis coefficient of safety behavior corresponding to the first sample monitoring period, and the second sample analysis coefficient is the preliminary analysis coefficient of safety behavior corresponding to the second sample monitoring period;
[0185] Define the safety behavior monitoring period, the first sample monitoring period to the bth sample monitoring period, the first sample analysis coefficient to the bth sample analysis coefficient, and the preliminary analysis coefficient of safety behavior as user behavior monitoring data;
[0186] The data acquisition module acquires the user behavior monitoring data and transmits it to the initial division module;
[0187] The initial division module obtains the preliminary analysis threshold of safety behavior according to the user behavior monitoring data, compares the preliminary analysis coefficient of safety behavior with the preliminary analysis threshold of safety behavior, and obtains the preliminary division data of user behavior;
[0188] Calculate the average of the first sample analysis coefficient to the bth sample analysis coefficient to obtain the average value of the sample analysis coefficient;
[0189] Calculate the variance of the first sample analysis coefficient to the bth sample analysis coefficient to obtain the average analysis variance of the sample;
[0190] Obtain the preliminary analysis threshold of safety behavior by calculating the average value of the sample analysis coefficient and the average analysis variance of the sample;
[0191] Calculate the preliminary analysis threshold of safety behavior, and the specific formula configuration is as follows:
[0192]
[0193] Among them, Aqy is the preliminary analysis threshold of safety behavior, Ypf is the average value of sample analysis coefficients, and Fcf is the average analysis variance of samples;
[0194] Compare the preliminary analysis coefficient of safety behavior with the preliminary analysis threshold of safety behavior, and define the result of the numerical comparison as the preliminary classification data of safety behavior;
[0195] The specific process of numerical comparison is as follows:
[0196] When the preliminary analysis coefficient of safety behavior is greater than or equal to the preliminary analysis threshold of safety behavior, the users in the safety behavior monitoring period are classified as the first type of safe users;
[0197] When the preliminary analysis coefficient of safety behavior is less than the preliminary analysis threshold of safety behavior, the users in the safety behavior monitoring period are classified as the second type of safe users;
[0198] The initial classification module defines the preliminary analysis threshold of safety behavior and the preliminary classification data of safety behavior as the preliminary classification data of user behavior;
[0199] The initial classification module obtains the preliminary classification data of user behavior and transports it to the behavior analysis module and the safety judgment module;
[0200] The behavior analysis module monitors the safety behavior of the second type of safe users according to the user behavior monitoring data, and obtains the program running duration ratio and the non-conventional program quantity ratio to obtain the user behavior analysis data;
[0201] Obtain the user behavior monitoring data, and obtain the safety behavior monitoring period, the first sample monitoring period to the b-th sample monitoring period, and the preliminary classification data of safety behavior according to the user behavior monitoring data;
[0202] Within the first sample monitoring period to the b-th sample monitoring period, sort the application programs run by the user in the operating system to obtain the first-ranked common program to the d-th ranked common program;
[0203] Specifically as follows:
[0204] It should be noted here that:
[0205] The d involved here is the numerical value corresponding to the ranked running program, and d is an integer greater than 0;
[0206] Within the first sample monitoring period, obtain the application program that the user starts running first in the operating system, and use it as the first-ranked running program, and obtain the first-ranked running programs corresponding to the second to the b-th sample monitoring periods respectively to obtain b first-ranked running programs;
[0207] Statistically count the names of each first - order running program to obtain multiple programs with different names, and statistically count the frequency of occurrence of each different - named program. Mark the numerically largest frequency of occurrence as the peak statistical frequency. When the peak statistical frequency is greater than the effective statistical frequency, mark the first - order running program corresponding to the peak statistical frequency as the first - order common program;
[0208] It should be noted here that:
[0209] Suppose there are three first - order running programs currently. The frequency of occurrence of the name "WPS" is 20, the frequency of occurrence of the name "WeChat" is 28, and the frequency of occurrence of the name "Edge Browser" is 30. Since 30 > 28 > 20, mark Edge Browser as the first - order common program;
[0210] During the first - sample monitoring period, obtain the application programs that the user runs after the first - order common program in the operating system, and use them as the second - order running programs. Obtain the second - order running programs corresponding to the second to the b - th sample monitoring periods respectively to get b first - order running programs;
[0211] Statistically count the names of each second - order running program to obtain multiple programs with different names, and statistically count the frequency of occurrence of each different - named program. Mark the numerically largest frequency of occurrence as the peak statistical frequency. When the peak statistical frequency is greater than the effective statistical frequency, mark the running program corresponding to the peak statistical frequency as the second - order common program;
[0212] Repeat the process of obtaining the first - order common program and the second - order common program, and obtain the third - order common program to the d - th order common program respectively;
[0213] Obtain the ratio of the number of non - conventional programs according to the first - order common program to the d - th order common program;
[0214] Specifically as follows:
[0215] Obtain the application program that the user starts running first during the security behavior monitoring period to get the first actual running program. Obtain the application program that runs after the first actual running program of the application program that starts running first to get the second actual running program, and obtain the third to the d - th actual running programs respectively;
[0216] Please refer to Figure 3 , when the first actual running program to the d - th actual running program perform program name character matching with the first - order common program to the d - th order common program, if the character matching results are the same, mark the corresponding application program as a regular - order application program, if the character matching results are different, mark the corresponding application program as an irregular - order application program;
[0217] Count the number of unconventional order applications to obtain the value of the number of unconventional programs, and calculate the ratio of the value of the number of unconventional programs to d to obtain the ratio of the number of unconventional programs;
[0218] Obtain the program running duration ratio according to the first-order common program to the d-order common program;
[0219] Specifically as follows:
[0220] Obtain the average single running duration of the first-order common program in each sample monitoring period to obtain multiple single running durations of the first program, and calculate the average of the obtained multiple single running durations of the first program to obtain the average single running duration of the first program;
[0221] Obtain the average single running duration of the program corresponding to the second-order common program to the d-order common program respectively to obtain the average single running duration of the second program to the average single running duration of the d-th program;
[0222] During the safety behavior monitoring period, obtain the actual running durations of the first-order common program to the d-order common program respectively to obtain the actual running duration of the first program to the actual running duration of the d-th program;
[0223] Calculate the program running duration ratio by dividing the actual running duration of the first program to the d-th program by the average single running duration of the first program to the d-th program;
[0224] Calculate the program running duration ratio, and the specific formula configuration is as follows:
[0225]
[0226] Among them, Cyb is the program running duration ratio, Sjs1 to Sjsd are the actual running durations of the first program to the d-th program respectively, and Pjs1 to Pjsd are the average single running durations of the first program to the d-th program respectively;
[0227] Define the program running duration ratio and the ratio of the number of unconventional programs as user behavior analysis data;
[0228] The behavior analysis module obtains the user behavior analysis data and transmits it to the safety judgment module;
[0229] The safety judgment module conducts safety behavior judgment on the users in the safety behavior monitoring period according to the user behavior monitoring data, the preliminary classification data of user behavior, and the user behavior analysis data, and issues a safety behavior warning according to the judgment result;
[0230] Obtain the preliminary classification data of user behavior. When the user during the safe behavior monitoring period is a first-type safe user, an abnormal behavior warning is issued;
[0231] When the user during the safe behavior monitoring period is a second-type safe user, conduct a judgment on the user's safe behavior as follows:
[0232] Obtain the preliminary analysis coefficient of safe behavior according to the user behavior monitoring data, and obtain the program running duration ratio and the ratio of the number of non-conventional programs according to the user behavior analysis data;
[0233] Calculate the user safe behavior judgment coefficient through the preliminary analysis coefficient of safe behavior, the program running duration ratio, and the ratio of the number of non-conventional programs;
[0234] Calculate the user safe behavior judgment coefficient, and the specific formula is as follows:
[0235] Ypx = Aqf + Cyb + Fcg;
[0236] Among them, Ypx is the user safe behavior judgment coefficient, Aqf is the preliminary analysis coefficient of safe behavior, Cyb is the program running duration ratio, and Fcg is the ratio of the number of non-conventional programs;
[0237] Obtain the preliminary analysis threshold of safe behavior according to the preliminary classification data of user behavior, and obtain the program running duration ratio threshold and the ratio of the number of non-conventional programs threshold respectively;
[0238] It should be noted here that:
[0239] The program running duration ratio threshold involved here is the maximum program running duration ratio of the second-type safe user during the safe behavior monitoring period, and the ratio of the number of non-conventional programs threshold is the ratio of the number of non-conventional programs of the second-type safe user during the safe behavior monitoring period;
[0240] Calculate the user safe behavior judgment coefficient threshold through the preliminary analysis threshold of safe behavior, the program running duration ratio threshold, and the ratio of the number of non-conventional programs threshold;
[0241] Calculate the user safe behavior judgment coefficient threshold, and the specific formula is as follows:
[0242] Ypxy = Aqy + Cyy + Fcy;
[0243] Among them, Ypxy is the user safe behavior judgment coefficient threshold, Aqy is the preliminary analysis threshold of safe behavior, Cyy is the program running duration ratio threshold, and Fcy is the ratio of the number of non-conventional programs threshold;
[0244] When the user safe behavior judgment coefficient is greater than or equal to the user safe behavior judgment coefficient threshold, a safe behavior warning is issued to the user;
[0245] When the user's security behavior judgment coefficient is less than the user's security behavior judgment coefficient threshold, continue to monitor the user's security behavior;
[0246] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the present invention to only the specific implementation manners. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A user security behavior analysis method based on multi-data fusion, characterized in that, The method includes the following steps: Step S1: Set a security behavior monitoring period and multiple sample monitoring periods, analyze the warning frequency and the average warning duration of the feature warning signals in each monitoring period, obtain the preliminary security behavior analysis coefficient and multiple sample analysis coefficients, and obtain the user behavior monitoring data; Step S2: Obtain the preliminary security behavior analysis threshold by analyzing the user behavior monitoring data, compare the numerical values of the preliminary security behavior analysis threshold and the preliminary security behavior analysis coefficient, and divide the users in the security behavior monitoring period into the first type of secure users and the second type of secure users, and obtain the preliminary user behavior classification data; Step S3: In multiple sample monitoring periods, sort the application programs running by the user in the operating system to obtain multiple common programs in sequence. Analyze the running order and running duration of the application programs run by the second type of secure users during the security behavior monitoring period and the multiple common programs in sequence to obtain the ratio of the number of unconventional programs and the ratio of the program running duration, and define the ratio of the program running duration and the ratio of the number of unconventional programs as the user behavior analysis data; Step S4: Directly issue an abnormal behavior warning to the first type of secure users, and conduct a security behavior judgment on the second type of secure users by combining the user behavior monitoring data and the user behavior analysis data, and issue a security behavior warning according to the judgment result.
2. The user security behavior analysis method based on multi-data fusion according to claim 1, wherein, In the said Step S1, the following specific steps are further included: Step S11: Use the time value corresponding to the current moment as the reference time point, and use a feature duration before the reference time point as the security behavior monitoring period; Step S12: Obtain multiple sample monitoring periods with a duration of the feature duration before the security behavior monitoring period, and name them the first sample monitoring period to the b-th sample monitoring period respectively; Step S13: Conduct a preliminary security behavior analysis on the security behavior monitoring period to obtain the preliminary security behavior analysis coefficient; Step S14: Obtain the preliminary security behavior analysis coefficients corresponding to the first sample monitoring period to the b-th sample monitoring period respectively to obtain the first sample analysis coefficient to the b-th sample analysis coefficient; Step S15: Define the security behavior monitoring period, the first sample monitoring period to the b-th sample monitoring period, the first sample analysis coefficient to the b-th sample analysis coefficient, and the preliminary security behavior analysis coefficient as the user behavior monitoring data, and enter Step S2.
3. The user security behavior analysis method based on multi-data fusion according to claim 2, wherein In the said Step S13, the following specific steps are further included: Step S131: Select c abnormal behavior warning signals provided by the operating system as the feature warning signals in the security behavior monitoring period, and name them the first feature warning signal to the c-th feature warning signal respectively; Step S132: Obtain the cumulative occurrence times of the first feature warning signal in the security behavior monitoring period to obtain the first signal occurrence times, obtain the duration value corresponding to the security behavior monitoring period to obtain the feature duration value, calculate the ratio of the first signal occurrence times to the feature duration value to obtain the warning frequency value corresponding to the first feature warning signal, and name it the first warning frequency value; Step S133: Obtain the warning frequency values corresponding to the second feature warning signal to the c-th feature warning signal respectively, to obtain the second warning frequency value to the c-th warning frequency value; Step S134: Obtain the warning duration corresponding to each occurrence of the first feature warning signal during the safe behavior monitoring period, to obtain multiple signal warning durations, and calculate the average of the obtained multiple signal warning durations, to obtain the average warning duration corresponding to the first feature warning signal, and name it the first signal average warning duration; Step S135: Obtain the average warning durations corresponding to the second feature warning signal to the c-th feature warning signal respectively, to obtain the second signal average warning duration to the c-th signal average warning duration; Step S136: Calculate the preliminary analysis coefficient of safe behavior by calculating the first warning frequency value to the c-th warning frequency value and the first signal average warning duration to the c-th signal average warning duration; Calculate the preliminary analysis coefficient of safe behavior, and the specific formula configuration is as follows: Among them, Aqf is the preliminary analysis coefficient of safe behavior, Yjp1 to Yjpc are the first warning frequency value to the c-th warning frequency value respectively, Ysc1 to Yscc are the first signal average warning duration to the c-th signal average warning duration respectively, and c is the type quantity value corresponding to the feature warning signal.
4. The user security behavior analysis method based on multi-data fusion according to claim 2, characterized in that, In the said step S2, it further includes the following specific steps: Step S21: Obtain the user behavior monitoring data, and obtain the preliminary analysis coefficient of safe behavior and the first sample analysis coefficient to the b-th sample analysis coefficient according to the user behavior monitoring data; Step S22: Obtain the preliminary analysis threshold of safe behavior according to the first sample analysis coefficient to the b-th sample analysis coefficient; In the said step S22, it further includes the following specific steps: Step S221: Calculate the average of the first sample analysis coefficient to the b-th sample analysis coefficient, to obtain the average value of the sample analysis coefficient; Step S222: Calculate the variance of the first sample analysis coefficient to the b-th sample analysis coefficient, to obtain the average sample analysis variance; Step S223: Calculate the preliminary analysis threshold of safe behavior by calculating the average value of the sample analysis coefficient and the average sample analysis variance; Calculate the preliminary analysis threshold of safe behavior, and the specific formula configuration is as follows: Among them, Aqy is the preliminary analysis threshold of safe behavior, Ypf is the average value of the sample analysis coefficient, and Fcf is the average sample analysis variance; Step S23: Compare the numerical values of the preliminary analysis coefficient of safe behavior and the preliminary analysis threshold of safe behavior, and define the numerical comparison result as the preliminary classification data of safe behavior; In the said step S23, it further includes the following specific steps: Step S231: When the preliminary analysis coefficient of safe behavior is greater than or equal to the preliminary analysis threshold of safe behavior, classify the user in the safe behavior monitoring period as the first type of safe user; Step S232: When the preliminary analysis coefficient of safe behavior is less than the preliminary analysis threshold of safe behavior, classify the user in the safe behavior monitoring period as the second type of safe user; Step S24: Define the preliminary analysis threshold of safe behavior and the preliminary classification data of safe behavior as the preliminary classification data of user behavior, and enter step S3.
5. The user security behavior analysis method based on multi-data fusion according to claim 4, characterized in that In step S3, the following specific steps are further included: Step S31: Obtain user behavior monitoring data, and based on the user behavior monitoring data, obtain a security behavior monitoring period, a first sample monitoring period to a b-th sample monitoring period, and preliminary security behavior classification data; Step S32: During the first sample monitoring period to the b-th sample monitoring period, sort the application programs running by the user in the operating system to obtain a first-ranked common program to a d-th ranked common program; Step S33: Obtain the ratio of the number of unconventional programs according to the first-ranked common program to the d-th ranked common program; Step S34: Obtain the ratio of program running durations according to the first-ranked common program to the d-th ranked common program; Step S35: Define the ratio of program running durations and the ratio of the number of unconventional programs as user behavior analysis data.
6. The user security behavior analysis method based on multi-data fusion according to claim 5, wherein In step S32, the following specific steps are further included: Step S321: During the first sample monitoring period, obtain the application program that the user first starts running in the operating system, and use it as the first-ranked running program. Obtain the first-ranked running programs corresponding to the second to b-th sample monitoring periods respectively to obtain b first-ranked running programs; Step S322: Conduct name statistics on each of the first-ranked running programs respectively to obtain multiple programs with different names, and conduct name occurrence frequency statistics on each program with a different name. Mark the maximum occurrence frequency value as the peak statistics frequency. When the peak statistics frequency is greater than the effective statistics frequency, mark the first-ranked running program corresponding to the peak statistics frequency as the first-ranked common program; Step S323: During the first sample monitoring period, obtain the application program that the user runs after the first-ranked common program in the operating system, and use it as the second-ranked running program. Obtain the first-ranked running programs corresponding to the second to b-th sample monitoring periods respectively to obtain b first-ranked running programs; Step S324: Conduct name statistics on each of the second-ranked running programs respectively to obtain multiple programs with different names, and conduct name occurrence frequency statistics on each program with a different name. Mark the maximum occurrence frequency value as the peak statistics frequency. When the peak statistics frequency is greater than the effective statistics frequency, mark the running program corresponding to the peak statistics frequency as the second-ranked common program; Step S325: Obtain the third-ranked common program to the d-th ranked common program respectively.
7. The user security behavior analysis method based on multi-data fusion according to claim 5, characterized in that, In step S33, the following specific steps are further included: Step S331: Obtain the application program that the user first starts running during the security behavior monitoring period to obtain a first actual running program, obtain the application program that runs after the first actual running program to obtain a second actual running program, and obtain the third actual running program to the d-th actual running program respectively; Step S332: Conduct program name character matching between the first actual running program to the d-th actual running program and the first-ranked common program to the d-th ranked common program. If the character matching results are the same, mark the corresponding application program as a regular sequence application program. If the character matching results are different, mark the corresponding application program as an unconventional sequence application program; Step S333: Count the number of unconventional sequence applications to obtain the value of the number of unconventional programs, and calculate the ratio of the value of the number of unconventional programs to d to obtain the ratio of the number of unconventional programs.
8. The user security behavior analysis method based on multi-data fusion according to claim 5, characterized in that In the said step S34, the following specific steps are further included: Step S341: Obtain the average single-run duration of the first-priority common programs in each sample monitoring period to obtain multiple single-run durations of the first programs, and calculate the average of the obtained multiple single-run durations of the first programs to obtain the average single-run duration of the first programs; Step S342: Respectively obtain the average single-run durations of the programs corresponding to the second-priority common programs to the d-priority common programs to obtain the average single-run duration of the second programs to the average single-run duration of the d programs; Step S343: In the safety behavior monitoring period, respectively obtain the actual running durations of the first-priority common programs to the d-priority common programs to obtain the actual running duration of the first programs to the actual running duration of the d programs; Step S345: Calculate the ratio of the actual running duration of the first programs to the d programs to the average single-run duration of the first programs to the d programs to obtain the ratio of the program running duration; Calculate the ratio of the program running duration, and the specific formula configuration is as follows: Among them, Cyb is the ratio of the program running duration, Sjs1 to Sjsd are respectively the actual running duration of the first programs to the actual running duration of the d programs, and Pjs1 to Pjsd are respectively the average single-run duration of the first programs to the average single-run duration of the d programs.
9. The user security behavior analysis method based on multi-data fusion according to claim 1, wherein In the said step S4, the following specific steps are further included: Step S41: Obtain the preliminary classification data of user behaviors, and issue an early warning of abnormal behaviors to the first type of safe users in the safety behavior monitoring period; Step S42: Conduct a study and judgment on the safety behaviors of the second type of safe users in the safety behavior monitoring period.
10. The method for analyzing user's security behavior based on multi-data fusion according to claim 9, characterized in that, In the said step S42, the following specific steps are further included: Step S421: Obtain the preliminary analysis coefficient of safety behaviors according to the user behavior monitoring data, and obtain the ratio of the program running duration and the ratio of the number of unconventional programs according to the user behavior analysis data; Step S422: Calculate the preliminary analysis coefficient of safety behaviors, the ratio of the program running duration, and the ratio of the number of unconventional programs to obtain the user safety behavior study and judgment coefficient; Calculate the user safety behavior study and judgment coefficient, and the specific formula is as follows: Ypx = Aqf + Cyb + Fcg; Among them, Ypx is the user safety behavior study and judgment coefficient, Aqf is the preliminary analysis coefficient of safety behaviors, Cyb is the ratio of the program running duration, and Fcg is the ratio of the number of unconventional programs; Step S423: Obtain the preliminary analysis threshold of safety behaviors according to the preliminary classification data of user behaviors, and respectively obtain the threshold of the ratio of the program running duration and the threshold of the ratio of the number of unconventional programs; Step S424: Calculate the preliminary analysis threshold of safety behaviors, the threshold of the ratio of the program running duration, and the threshold of the ratio of the number of unconventional programs to obtain the threshold of the user safety behavior study and judgment coefficient; Step S425: When the user safety behavior study and judgment coefficient is greater than or equal to the user safety behavior study and judgment coefficient threshold, issue an early warning of safety behaviors to the user; Step S426: When the user's security behavior judgment coefficient is less than the user's security behavior judgment coefficient threshold, continue to monitor the user's security behavior.
Citation Information
Patent Citations
User behavior abnormality detection method under Hadoop cluster
CN107222472A
An abnormal behavior detection method and device
CN109842628A