A method and device for detecting and analyzing network exception permissions
By constructing user vectors and graph data, dynamic adjustment of permission management is solved, and the problems of poor flexibility and difficulty in detection of traditional permission management methods are achieved, and fine-grained control of user permissions and effective detection of internal threats are achieved.
Patent Information
- Application Number
- CN202411794893.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-06
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-12-06
AI Technical Summary
Traditional permission management methods have poor flexibility, difficulty in detecting internal threats, lack refined control, and require manual auditing, which is inefficient and easy to miss details.
By constructing a two-dimensional wide table and user vector, calculating the similarity between users, organizing graph data to divide user groups, numerically representing the functional items of the business system, mapping the user and function items, calculating the similarity between users and groups, conducting over-authorized access detection, and identifying over-authorized and over-authorized access.
It realizes flexible dynamic adjustments based on changes in user behavior, effectively prevents excessive or insufficient user permissions, detects the abuse of permissions by internal users, and achieves finer granular control of user specific operations, reduces the cost of manual audits, and avoids omissions of details.
Smart Images

Figure CN119628927B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network permission analysis, and particularly relates to a method and device for detecting and analyzing network abnormal permissions. Background Art
[0002] In modern information systems, permission management is one of the important links to ensure data security. However, traditional permission management methods have some inherent limitations, which may lead to increased security vulnerabilities and risks of unauthorized access.
[0003] In traditional technologies, permission management systems often rely on static role assignments, which means that once permissions are granted, it is difficult to dynamically adjust according to changes in user behavior. Internal users may abuse their permissions, especially when they have too many permissions, which may pose internal threats, and traditional systems have limited detection capabilities for such threats. With the increase in business complexity, a single permission control model is difficult to meet diverse security requirements, especially when more fine-grained control of specific operations is required. Regular manual audits can detect some abnormal permissions, but this method is inefficient and prone to missing details, especially in large-scale systems. In addition, user roles and responsibilities often change, and if permissions are not updated in a timely manner, it may lead to problems of excessive or insufficient permissions. Summary of the Invention
[0004] Therefore, the present invention provides a method and device for detecting and analyzing network abnormal permissions to solve the problems of poor flexibility, difficulty in detecting internal threats, lack of refined control, and the need for manual audits in traditional technologies.
[0005] To achieve the above object, the present invention provides the following technical solution: A method for detecting and analyzing network abnormal permissions, comprising:
[0006] According to a set statistical interval, a two-dimensional wide table is constructed based on the access information of users accessing the business system within the statistical interval, and a user vector is constructed using the access information of each user in the two-dimensional wide table;
[0007] According to the user vector, the similarity between every two users among all users is calculated to obtain the similarity between every two users among all users;
[0008] Graph data is organized using the similarity between every two users among all users, and clustering algorithms are used to divide users into groups according to the graph data;
[0009] Through the access records of the business system, digital representation is performed on the function items of the business system; the mapping between users and authorized function items is performed, and users are represented as vectors of function items;
[0010] Calculate the similarity between the user and the group, and determine whether the user is overauthorized based on the similarity between the user and the group;
[0011] Detect unauthorized access by the user through parsing the URL address accessed by the user and comparing it with the mapping table of users and authorized URL access addresses already obtained in the business system;
[0012] For an overauthorized user, when the function accessed by the user belongs to the overauthorized function, it is identified as unauthorized access.
[0013] As an optimal solution for the network anomaly permission detection and analysis method, in the process of constructing a two-dimensional wide table based on the access information of users accessing the business system within the statistical interval:
[0014] Take all the URL addresses accessed by users within the statistical interval as column fields, each user as a row field, and use the number of times a user accesses the URL address divided by the total number of times the user accesses the system within the statistical interval as the value to form the two-dimensional wide table.
[0015] As an optimal solution for the network anomaly permission detection and analysis method, in the process of organizing graph data using the similarity between every two users among all users:
[0016] Create a graph data structure, which includes node objects and edge objects. The node object represents each user in the dataset, and the edge object represents the similarity between two users;
[0017] For each pair of nodes in the dataset, create an edge object using the pre-calculated similarity between every two users, and use the pair of node objects with similarity as the starting and ending points of the edge object; The edge object contains a similarity value, indicating the degree of similarity between the node objects connected by the edge object.
[0018] As an optimal solution for the network anomaly permission detection and analysis method, in the process of numerically representing the function items of the business system through the access records of the business system, calculate the term frequency TF and inverse document frequency IDF:
[0019] Term frequency TF = the number of times a specified function item appears in a specified user's access / the total number of all function items accessed by the specified user;
[0020] Inverse document frequency IDF = log(total number of users / (number of users accessing the specified function item + 1));
[0021] In the process of representing a user as a vector of function items:
[0022] Represent the function access of each user within a time interval using TF-IDF values to form a vector of the user's accessed function items.
[0023] As an optimal solution of the network anomaly permission detection and analysis method, during the process of calculating the similarity between a user and a group and determining whether the user is over - authorized based on the similarity between the user and the group:
[0024] Average each user vector within the user group to form a functional vector representation of the group;
[0025] Use cosine similarity to calculate the cosine similarity between each user and the group where the user belongs; determine whether the user is over - authorized based on the cosine similarity between each user and the group where the user belongs;
[0026] It also includes:
[0027] Calculate the outlier of the user cosine similarity and use the principle to give an alarm for user over - authorization;
[0028] For the alarmed users, calculate the generalized accard coefficient between the user's function items and the group's function items one by one. According to the principle of the Gaussian distribution, take the function items greater than 3 times the standard deviation of the average value as over - authorized function items and perform alarm processing for over - authorized function items.
[0029] As an optimal solution of the network anomaly permission detection and analysis method, during the process of detecting user unauthorized access by parsing the URL address accessed by the user and using the mapping table of users and authorized URL access addresses already obtained in the business system:
[0030] Construct a time - series analysis of the daily access volume of each user, and calculate whether the number of current accesses by the user exceeds the result of the time - series analysis; if the access volume exceeding the time - series prediction reaches the set access volume threshold, construct the user's access behavior on the current day into an access behavior vector and calculate the cosine similarity A with the user's access behavior vector in the recent week;
[0031] Calculate the cosine similarity B based on the user's current access behavior vector and the access behavior vector of the group in the recent week;
[0032] For those where both the cosine similarity A and the cosine similarity B exceed the set similarity threshold, give an early warning for unauthorized access behavior;
[0033] The steps of constructing a time - series analysis of the daily access volume of each user include:
[0034] Collect time - series data; pre - process time - series data; model selection and parameter estimation; model testing and diagnosis; model application and prediction.
[0035] As an optimal solution for the network abnormal privilege detection and analysis method, it further includes: when alarms occur for both user over-authorization and unauthorized access, using a security detection mechanism to identify the attack source to determine the authenticity of the alarms.
[0036] The present invention also provides a network abnormal privilege detection and analysis device, including: a user group division component, an over-authorization detection component, and an unauthorized access detection component;
[0037] The user group division component includes:
[0038] A user vector construction module, configured to construct a two-dimensional wide table according to the access information of users accessing the business system within a set statistical interval, and construct user vectors using the access information of each user in the two-dimensional wide table;
[0039] A user similarity calculation module, configured to calculate the similarity between every two users among all users according to the user vectors, and obtain the similarity between every two users among all users;
[0040] A graph data organization module, configured to organize graph data using the similarity between every two users among all users;
[0041] A group division module, configured to divide users into groups using a clustering algorithm according to the graph data;
[0042] The over-authorization detection component includes:
[0043] A function item representation module, configured to digitally represent the function items of the business system through the access records of the business system;
[0044] A user-function item mapping module, configured to map users to the authorized function items and represent users as vectors of function items;
[0045] An over-authorization judgment module, configured to calculate the similarity between a user and a group, and judge whether the user is over-authorized according to the similarity between the user and the group;
[0046] The unauthorized access detection component includes:
[0047] A user unauthorized access detection module, configured to perform user unauthorized access detection by parsing the URL address accessed by the user and using the mapping table of users and authorized URL access addresses already obtained in the business system;
[0048] An unauthorized access identification module, configured to, for an over-authorized user, when the function accessed by the user belongs to the over-authorized function, identify it as unauthorized access.
[0049] As an optimal solution for the network abnormal privilege detection and analysis device, in the user vector construction module:
[0050] Use the URL addresses accessed by users within all the statistical intervals as column fields, each user as a row field, and divide the number of times a user accesses the URL address by the total number of times the user accesses the system within the statistical interval as the value to form the two-dimensional wide table.
[0051] As an optimal solution for the network anomaly privilege detection and analysis device, in the graph data organization module:
[0052] Create a graph data structure, which includes node objects and edge objects. The node objects represent each user in the dataset, and the edge objects represent the similarity between two users;
[0053] For each pair of nodes in the dataset, create an edge object using the pre-computed similarity between pairwise users, and use the pair of node objects with similarity as the start and end points of the edge object; the edge object contains a similarity value, indicating the degree of similarity between the node objects connected by the edge object.
[0054] As an optimal solution for the network anomaly privilege detection and analysis device, in the function item representation module:
[0055] During the process of numerically representing the function items of the business system through the access records of the business system, calculate the term frequency TF and inverse document frequency IDF of the function items:
[0056] Term frequency TF = the number of times a specified function item appears in a specified user's access / the total number of all function items in the specified user's access;
[0057] Inverse document frequency IDF = log(total number of users / (number of users accessing the specified function item + 1));
[0058] In the user-function item mapping module:
[0059] Represent the function access of each user within a time interval using TF-IDF values to form a vector of user access to function items.
[0060] As an optimal solution for the network anomaly privilege detection and analysis device, in the over-authorization judgment module:
[0061] Average each user vector within the user group to form a functional vector representation of the group;
[0062] Use cosine similarity to calculate the cosine similarity between each user and the group they belong to; determine whether a user is over-authorized based on the cosine similarity between each user and the group they belong to.
[0063] As an optimal solution for the network anomaly privilege detection and analysis device, the over-authorization detection component further includes:
[0064] The user over-authorization warning module is used to calculate the outlier of the user cosine similarity and perform user over-authorization warning by using the principle.
[0065] The function item warning processing module is used to calculate the generalized accard coefficient between the user function item and the group function item for each warning user one by one. According to the principle of Gaussian distribution, the function item greater than 3 times the standard deviation of the average value is taken as the over-authorized function item, and the over-authorized function item warning processing is performed.
[0066] As an optimal solution of the network abnormal permission detection and analysis device, in the user over-privilege detection module:
[0067] Construct a time series analysis of the daily access volume of each user, and calculate whether the current access volume of the user exceeds the result of the time series analysis; if the access volume exceeding the time series prediction reaches the set access volume threshold, construct the user's daily access behavior into an access behavior vector, and calculate the cosine similarity A with the access behavior vector of the user in the recent week;
[0068] Calculate the cosine similarity B according to the current access behavior vector of the user and the access behavior vector of the group in the recent week.
[0069] For those with both cosine similarity A and cosine similarity B exceeding the set similarity threshold, a warning for unauthorized access behavior is given.
[0070] As an optimal solution of the network abnormal permission detection and analysis device, it further includes a discrimination component, and the discrimination component includes:
[0071] The attack source discrimination module is used to discriminate the attack source by using the security detection mechanism to determine the authenticity of the alarm when both user over-authorization and unauthorized access occur.
[0072] The beneficial effects of the present invention are as follows. According to the set statistical interval, a two-dimensional wide table is constructed based on the access information of users accessing the business system within the statistical interval, and user vectors are constructed using the access information of each user in the two-dimensional wide table. According to the user vectors, the similarity between every two users among all users is calculated to obtain the similarity between every two users among all users. The graph data is organized using the similarity between every two users among all users, and the users are grouped using a clustering algorithm according to the graph data. Through the access records of the business system, digital representation is performed on the function items of the business system. A mapping is made between the users and the authorized function items, and the users are represented as vectors of function items. The similarity between the users and the groups is calculated, and it is determined whether a user is over-authorized according to the similarity between the users and the groups. Through the analysis of the URL addresses accessed by the users and the mapping table of users and authorized URL access addresses already obtained in the business system, detection of unauthorized access by users is performed. For over-authorized users, when the function accessed by the user belongs to the over-authorized function, it is identified as unauthorized access. The present invention can perform flexible dynamic adjustment according to changes in user behavior, effectively prevent excess or insufficient user permissions; effectively detect the behavior of internal users abusing permissions, and achieve more fine-grained control over specific operations of users; without the need for manual auditing, reduce costs and are not easily prone to missing details. BRIEF DESCRIPTION OF THE DRAWINGS
[0073] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings described below are only exemplary, and for those of ordinary skill in the art, without creative efforts, other implementation drawings can also be obtained based on the provided drawings.
[0074] The structures, proportions, sizes, etc. illustrated in this specification are only used to cooperate with the content disclosed in the specification for those familiar with this technology to understand and read, and are not used to limit the limiting conditions under which the present invention can be implemented. Therefore, they do not have technical essence. Any modification of the structure, change of the proportional relationship, or adjustment of the size, without affecting the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed in the present invention.
[0075] Figure 1 It is a schematic flow chart of the network anomaly permission detection and analysis method provided by an embodiment of the present invention;
[0076] Figure 2 It is a schematic technical architecture diagram of the network anomaly permission detection and analysis method provided by an embodiment of the present invention;
[0077] Figure 3Schematic diagram of the verification and handling status conversion after the discovery of abnormal permissions in the network abnormal permission detection and analysis method provided by the embodiment of the present invention;
[0078] Figure 4 Schematic diagram of the architecture of the network abnormal permission detection and analysis device provided by the embodiment of the present invention. Detailed implementation manners
[0079] The following specific embodiments illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0080] Embodiment 1
[0081] Refer to Figure 1 and Figure 2 The embodiment of the present invention provides a network abnormal permission detection and analysis method, including the following steps:
[0082] S1. According to the set statistical interval, construct a two-dimensional wide table based on the access information of users accessing the business system within the statistical interval, and construct user vectors using the access information of each user in the two-dimensional wide table;
[0083] S2. Calculate the similarity between every two users among all users according to the user vectors to obtain the similarity between every two users among all users;
[0084] S3. Organize graph data using the similarity between every two users among all users, and divide users into groups using a clustering algorithm according to the graph data;
[0085] S4. Numerically represent the function items of the business system through the access records of the business system; map users to the authorized function items, and represent users as vectors of function items;
[0086] S5. Calculate the similarity between users and groups, and judge whether a user is overauthorized according to the similarity between users and groups;
[0087] S6. Detect unauthorized access of users by parsing the URL addresses accessed by users and mapping the obtained user and authorized URL access address mapping table in the business system;
[0088] S7. For overauthorized users, when the function accessed by the user belongs to the overauthorized function, it is identified as unauthorized access.
[0089] In this embodiment, in step S1, when constructing a two-dimensional wide table based on the access information of users accessing the business system within the statistical interval:
[0090] All the URL addresses accessed by users within the statistical interval are used as column fields, each user is used as a row field, and the number of times a user accesses the URL address is divided by the total number of times the user accesses the system within the statistical interval as the value, forming the two-dimensional wide table.
[0091] Specifically, a statistical interval is set through the user group division component, generally with a week or a month as the interval unit. Whether to choose a week or a month needs to be subdivided according to the usage frequency and confidentiality level of the business system. For business systems with high usage frequency and high confidentiality level, calculations are carried out on a weekly basis, and other systems are calculated on a monthly basis. All the URL addresses accessed by users within the statistical interval are used as column fields, each user is used as a row field, and each value is the number of times the user accesses the URL address divided by the total number of times the user accesses the system within the statistical interval as the value, forming a two-dimensional wide table. The final result is one piece of data for each user, forming a user vector.
[0092] In this embodiment, in step S2, according to the user vector, using the cosine distance as the formula for calculating similarity, the similarity between every two users among all users is calculated, and the similarity between every two users among all users is obtained. Among them, the cosine distance, also known as cosine similarity, is the cosine value of the angle between two vectors in the vector space as a measure of the size of the difference between two individuals. The cosine distance uses the cosine value of the angle between two vectors as a measure of the size of the difference between two individuals. Compared with the Euclidean distance, the cosine distance pays more attention to the difference in the direction of the two vectors.
[0093] In this embodiment, in step S3, when organizing graph data using the similarity between every two users among all users:
[0094] Create a graph data structure, which includes a node object and an edge object. The node object represents each user in the dataset, and the edge object represents the similarity between two users;
[0095] For each pair of nodes in the dataset, use the pre-calculated similarity between every two users to create an edge object, and use the pair of node objects with similarity as the starting point and ending point of the edge object; the edge object contains a similarity value, indicating the similarity degree between the node objects connected by the edge object.
[0096] Among them, in the process of grouping users using a clustering algorithm based on the graph data, a graph-based clustering algorithm is used. The main advantage of the graph-based clustering algorithm is that it can effectively process large-scale graph-structured data because it clusters the graph into smaller subgraphs, thereby reducing the computational complexity. When dividing user groups, the scale of users is generally not extremely large, and the graph data formed does not belong to a large graph, so this algorithm can be used for calculation.
[0097] In this embodiment, over-authorization behaviors mainly occur in scenarios such as improper authorization management in the business system, failure to modify permissions in a timely manner due to personnel flow, system upgrades or changes, etc. In the business system, over-authorization is manifested as a user being granted authorizations exceeding those of their position or role. To identify over-authorization behaviors, it is necessary to compare the authorization data of users with the groups they belong to. For those that deviate too much from the group authorization function, a warning needs to be sent to the system administrator, and access should also be blocked or denied according to the evaluation results of over-authorization when the user accesses. Therefore, in step S4, first, the function items of the business system are numerically represented through the access records of the business system; then, by mapping the user to the authorized function items, the user is represented as a vector of authorized function items; the cosine similarity between pairwise users is calculated to calculate the similarity of user authorizations; then, a single user is compared with group users, and for those with too large a deviation from the group, an alarm for user over-authorization is given. In addition, it is also necessary to calculate the average function authorization access vector of the group where the user is located, and compare it with the function authorization vector of the over-authorized user to calculate which functions have the risk of over-authorization.
[0098] Among them, in the process of numerically representing the function items of the business system through the access records of the business system, the term frequency TF and inverse document frequency IDF are calculated:
[0099] Term frequency TF = the number of times a specified function item appears in a specified user's access / the total number of all function items in the specified user's access;
[0100] Inverse document frequency IDF = log(total number of users / (number of users accessing the specified function item + 1));
[0101] In the process of representing a user as a vector of function items:
[0102] The function access of each user within a time interval is represented using TF-IDF values to form a vector of user-accessed function items.
[0103] In this embodiment, in step S5, when calculating the similarity between a user and a group and determining whether the user is over-authorized based on the similarity between the user and the group:
[0104] Average each user vector within the user group to form a functional vector representation of the group;
[0105] Use cosine similarity to calculate the cosine similarity between each user and the group they belong to; determine whether a user is overauthorized based on the cosine similarity between each user and the group they belong to. For users with a greater similarity, they are closer to the group, which means that in terms of authorization, the possibility of the user being overauthorized is smaller; for users with a smaller similarity, their authorization behavior is more distant from the group, and the possibility of the user being overauthorized is greater.
[0106] In addition, it also includes:
[0107] Calculate the outliers of the user cosine similarity and use the principle to give an alarm for user overauthorization;
[0108] For the alarmed users, calculate the generalized accard coefficient between the user's function items and the group's function items one by one. According to the principle of the Gaussian distribution, take the function items greater than 3 times the standard deviation of the average value as overauthorized function items and perform alarm processing for overauthorized function items.
[0109] Specifically, when the data follows a Gaussian distribution. Under the principle, if the outlier exceeds 3 times the standard deviation, then it can be regarded as an outlier. The probability of positive and negative is 99.7%, so the probability of a value outside the distance from the average value is which belongs to a very rare small probability event. Calculate the average value and standard deviation of each group, and compare the users within the group with the average value and standard deviation. For users less than the average value plus 3 times the standard deviation, give an alarm for overauthorization.
[0110] In this embodiment, in step S6, during the process of detecting unauthorized access by users through parsing the URL address accessed by the user and the user-authorization URL access address mapping table already obtained in the service system:
[0111] Construct a time series analysis of the daily access volume of each user, and calculate whether the current access volume of the user exceeds the result of the time series analysis; if the access volume exceeding the time series prediction reaches the set access volume threshold, construct the user's access behavior on the current day into an access behavior vector and calculate the cosine similarity A with the access behavior vector of the user in the recent week;
[0112] Calculate the cosine similarity B based on the user's current access behavior vector and the access behavior vector of the group in the recent week;
[0113] For those where both the cosine similarity A and the cosine similarity B exceed the set similarity threshold, give an early warning for unauthorized access behavior;
[0114] The steps for constructing a time series analysis of the daily access volume of each user include:
[0115] Collect time series data; preprocess the time series data; select a model and estimate parameters; test and diagnose the model; apply and predict with the model.
[0116] Specifically, the detection of unauthorized access and early warning by the unauthorized access detection component are divided into two methods: identification and early warning. The identification of unauthorized access is achieved through the analysis of the URL addresses accessed by users and the mapping table of users and authorized URL access addresses already obtained in the business system, realizing strong verification of unauthorized access; in addition, for users with excessive authorization, when the functions accessed by the user belong to the functions with excessive authorization, it is also identified as unauthorized access; for the system function access requests identified as unauthorized access, the system directly rejects the access. In addition to the above two clear identifications of unauthorized access, in order to minimize the unauthorized access behavior of users, by constructing a time series analysis of the daily access volume of each user, calculate whether the current access volume of the user significantly exceeds the result of the time series analysis. If it significantly exceeds the access volume predicted by the time series, construct the user's daily access behavior into an access behavior vector, and calculate the cosine similarity with the access behavior vector of the user in the most recent week; calculate the cosine similarity between the user's current access behavior vector and the access behavior vector of the group in the most recent week; for those with both cosine similarities exceeding a certain threshold, give an early warning of unauthorized access behavior.
[0117] Among them, the construction of the access behavior vector of the user's access to the system functions in the most recent week has the same processing logic and method as the construction method of the system access vector of a single user within a certain interval. To improve the calculation efficiency, generally, during the system idle time after 12 o'clock midnight on the same day, complete the construction operation of the user's vector in the most recent week, and save the construction result in the database, and directly read it through query during subsequent calculations. The construction of the access behavior vector of the group's access to the system functions in the most recent week has the same processing logic and method as the construction of the group vector space. The construction steps are to first construct the system access function vectors of all users in the most recent week; then take the average value of all users in the same group to complete the construction of the group vector.
[0118] Specifically, construct a time series model for the user access volume according to the following steps:
[0119] 1) Collect time series data. It is necessary to collect the time series data of user access, which are the observed variable values at consecutive time points. Ensure the accuracy and integrity of the data, which is crucial for establishing a reliable time series model.
[0120] 2) Data preprocessing. Before establishing a time series model, it is usually necessary to preprocess the original data. This may include checking whether the data is stationary. If it is not stationary, differencing may be required to eliminate trends and seasonality. In addition, it is also necessary to check whether the data is white noise, that is, whether there is useful information.
[0121] 3) Model selection and parameter estimation. According to the characteristics and purposes of the data, select a suitable time series model, such as ARIMA. Then use relevant information criteria and parameter estimation methods to determine the best parameters of the model.
[0122] 4) Model testing and diagnosis. After the model is established, it is also necessary to conduct model testing and diagnosis to ensure the effectiveness and predictive ability of the model. This may include using ACF plots and PACF plots to test whether the autocorrelation and partial autocorrelation of the model are appropriate, and using the ADF test to check whether the residuals are white noise, etc.
[0123] 5) Model application and prediction. When the model is proven to be effective and can be used for prediction, it can be used to predict the future user access volume. It should be noted that the prediction results are not absolutely accurate and may be affected by various factors, such as data randomness, model limitations, etc. Therefore, when judging that the user access volume is abnormal, a certain interval should be increased to reduce false alarms.
[0124] In this embodiment, in step S7, it further includes: when alarms occur for both user over-authorization and unauthorized access, use the security detection mechanism to discriminate the attack source to determine the authenticity of the alarm.
[0125] See Figure 3 , through the discrimination component, when alarms occur in the over-authorization detection component and the unauthorized access detection component, combined with the existing security detection mechanism, it is used to discriminate the attack source to determine the authenticity of the alarm.
[0126] Among them, when a permission anomaly is detected, the corresponding identity, device, or application enters an abnormal state. In this state, the system will alarm, and the abnormal identity, device, and application enter the gray observation state, and at the same time notify the administrator for handling. The administrator needs to retrieve the corresponding traffic context for the alarm and verify the alarm event through technical means. If no anomaly is detected after the detection, after manual confirmation, the abnormal entity is adjusted to the normal state; otherwise, it enters the compromised state. In the compromised state, the following things need to be done: report the realized entity to an external system, such as a trust assessment system; start policy calculation and perform policy handling according to the handling specifications.
[0127] In summary, in the embodiments of the present invention, according to a set statistical interval, a two-dimensional wide table is constructed based on the access information of users accessing the business system within the statistical interval, and user vectors are constructed using the access information of each user in the two-dimensional wide table; according to the user vectors, the similarity between every two users among all users is calculated to obtain the similarity between every two users among all users; the graph data is organized using the similarity between every two users among all users, and the users are grouped using a clustering algorithm according to the graph data; through the access records of the business system, digital representation is performed on the function items of the business system; mapping is performed between the users and the authorized function items, and the users are represented as vectors of function items; the similarity between the users and the groups is calculated, and whether a user is over-authorized is judged according to the similarity between the users and the groups; through the analysis of the URL addresses accessed by the users and the mapping table of the users and the authorized URL access addresses already obtained in the business system, detection of unauthorized access by the users is performed; for over-authorized users, when the function accessed by the user belongs to the over-authorized function, it is identified as unauthorized access. The present invention can perform flexible dynamic adjustment according to changes in user behavior, effectively prevent excessive or insufficient user permissions; effectively detect the behavior of internal users abusing permissions, and achieve finer-grained control over specific operations of users; without the need for manual auditing, reduce costs and are not easily prone to missing details.
[0128] It should be noted that the method in the embodiments of the present disclosure can be executed by a single device, such as a computer or a server, etc. The method in this embodiment can also be applied to a distributed scenario, and multiple devices cooperate with each other to complete it. In such a distributed scenario, one of the multiple devices can only execute one or more steps in the method in the embodiments of the present disclosure, and these multiple devices will interact with each other to complete the described method.
[0129] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order from that in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0130] Embodiment 2
[0131] See Figure 4 , Embodiment 2 of the present invention provides a network anomaly permission detection and analysis device, including: a user group division component, an over-authorized detection component, and an unauthorized access detection component;
[0132] The user group division component includes:
[0133] The user vector construction module 100 is configured to construct a two-dimensional wide table according to the set statistical interval based on the access information of users accessing the service system within the statistical interval, and construct user vectors by using the access information of each user in the two-dimensional wide table;
[0134] The user similarity calculation module 200 is configured to calculate the similarity between every two users among all users according to the user vectors, and obtain the similarity between every two users among all users;
[0135] The graph data organization module 300 is configured to organize graph data by using the similarity between every two users among all users;
[0136] The group division module 400 is configured to divide users into groups by using a clustering algorithm according to the graph data;
[0137] The over-authorization detection component includes:
[0138] The function item representation module 500 is configured to numerically represent the function items of the service system through the access records of the service system;
[0139] The user-function item mapping module 600 is configured to map users to authorized function items and represent users as vectors of function items;
[0140] The over-authorization judgment module 700 is configured to calculate the similarity between a user and a group, and judge whether the user is over-authorized according to the similarity between the user and the group;
[0141] The unauthorized access detection component includes:
[0142] The user unauthorized access detection module 800 is configured to detect unauthorized access of users by parsing the URL addresses accessed by users and using the mapping table of users and authorized URL access addresses already obtained in the service system;
[0143] The unauthorized access recognition module 900 is configured to, for an over-authorized user, when the function accessed by the user belongs to an over-authorized function, recognize it as unauthorized access.
[0144] In this embodiment, in the user vector construction module 100:
[0145] Taking all the URL addresses accessed by users within the statistical interval as column fields, each user as a row field, and using the number of times a user accesses the URL address divided by the total number of times the user accesses the system within the statistical interval as the value to form the two-dimensional wide table.
[0146] In this embodiment, in the graph data organization module 300:
[0147] Create a graph data structure, which includes node objects and edge objects. The node objects represent each user in the dataset, and the edge objects represent the similarity between two users;
[0148] For each pair of nodes in the dataset, create an edge object using the pre-computed pairwise user similarity, and use the pair of node objects with similarity as the start and end points of the edge object; the edge object contains a similarity value, indicating the degree of similarity between the node objects connected by the edge object.
[0149] In this embodiment, the functional item represents in module 500:
[0150] During the digital representation of the business system functional items through the access records of the business system, calculate the term frequency TF and inverse document frequency IDF of the functional items:
[0151] Term frequency TF = the number of times a specified functional item appears in a specified user's access / the total number of all functional items in the specified user's access;
[0152] Inverse document frequency IDF = log(total number of users / (number of users accessing the specified functional item + 1));
[0153] In the user-functional item mapping module 600:
[0154] Represent the functional access of each user within a time interval using TF-IDF values to form a vector of user-accessed functional items.
[0155] In this embodiment, in the over-authorization judgment module 700:
[0156] Average each user vector within the user group to form a functional vector representation of the group;
[0157] Use cosine similarity to calculate the cosine similarity between each user and the group they belong to; determine whether a user is over-authorized based on the cosine similarity between each user and the group they belong to.
[0158] In this embodiment, the over-authorization detection component further includes:
[0159] User over-authorization warning module 010, which is used to calculate the outlier of the user cosine similarity and use the principle to give a user over-authorization warning;
[0160] Functional item warning processing module 011, which is used to calculate the generalized accard coefficient between the user's functional items and the group's functional items one by one for the warned users, and according to the principle of the Gaussian distribution, take the functional items greater than 3 times the standard deviation of the average value as over-authorized functional items and perform over-authorized functional item warning processing.
[0161] In this embodiment, in the user over - authorization detection module 800:
[0162] Construct a time - series analysis of the daily access volume of each user, and calculate whether the number of current user accesses exceeds the result of the time - series analysis; if the access volume exceeding the time - series prediction reaches the set access volume threshold, construct the user's daily access behavior into an access behavior vector, and calculate the cosine similarity A with the access behavior vector of the user in the recent week.
[0163] Calculate the cosine similarity B based on the current access behavior vector of the user and the access behavior vector of the group where the user is located in the recent week.
[0164] For those where both the cosine similarity A and the cosine similarity B exceed the set similarity threshold, give a warning of unauthorized access behavior.
[0165] In this embodiment, it further includes a discrimination component, and the discrimination component includes:
[0166] An attack source discrimination module 012, which is used to determine the authenticity of the alarm by using a security detection mechanism to discriminate the attack source when alarms occur for both user over - authorization and unauthorized access.
[0167] It should be noted that for the information interaction, execution process, etc. between the above - mentioned device modules, since it is based on the same concept as the method embodiment in Embodiment 1 of this application, the technical effects brought by it are the same as those of the method embodiment of this application. For specific content, refer to the description in the method embodiment shown above in this application, and details will not be repeated here.
[0168] Embodiment 3
[0169] Embodiment 3 of the present invention provides a non - transitory computer - readable storage medium, in which a program code of a network exception permission detection and analysis method is stored, and the program code includes instructions for executing a network exception permission detection and analysis method according to Embodiment 1 or any possible implementation thereof.
[0170] The computer - readable storage medium can be any available medium that a computer can access or a data storage device such as a server or a data center that integrates one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid - state drive (SSD)).
[0171] Embodiment 4
[0172] Embodiment 4 of the present invention provides an electronic device, including: a memory and a processor;
[0173] The processor and the memory communicate with each other through a bus; the memory stores program instructions executable by the processor, and when the processor calls the program instructions, it can execute a network anomaly privilege detection and analysis method according to Embodiment 1 or any possible implementation thereof.
[0174] Specifically, the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in the memory. The memory can be integrated in the processor or can be located outside the processor and exist independently.
[0175] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.).
[0176] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program code executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.
[0177] Although the present invention has been described in detail above with general descriptions and specific embodiments, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.
Claims
1. A method for detecting and analyzing abnormal network permissions, characterized in that: include: According to the set statistical interval, a two-dimensional wide table is constructed according to the access information of users accessing the service system within the statistical interval, and a user vector is constructed using the access information of each user in the two-dimensional wide table; Calculating the similarity between any two users among all users based on the user vectors to obtain the similarity between any two users among all users; Utilize the similarity of two users among all users to organize graph data, and use a clustering algorithm to divide the users into groups according to the graph data; Digitally represent the function items of the business system through the access records of the business system; map the user and the authorized function items, and represent the user as a vector of the function items; Calculate the similarity between the user and the group, and determine whether the user is over-authorized based on the similarity between the user and the group; Detecting unauthorized access by users through parsing the URL address accessed by the user and the mapping table of users and authorized URL access addresses already obtained in the business system; For an over-authorized user, when the function accessed by the user belongs to the over-authorized function, it is identified as unauthorized access.
2. A method for detecting and analyzing abnormal network permissions according to claim 1, characterized in that: In the process of constructing a two-dimensional wide table based on the access information of users accessing the business system within the statistical interval: The two-dimensional wide table is formed by taking the URL addresses accessed by all users in the statistical interval as column fields, each user as a row field, and taking the number of times the user accesses the URL address divided by the total number of times the user accesses the system in the statistical interval as the value.
3. A method for detecting and analyzing abnormal network permissions according to claim 1, characterized in that: In the process of organizing graph data using the similarity of two users among all users: Create a graph data structure, which includes node objects and edge objects. The node object represents each user in the data set, and the edge object represents the similarity between two users. For each pair of nodes in the dataset, an edge object is created using the pre-calculated similarity between the two users, and the pair of node objects with similarity is used as the starting point and end point of the edge object; the edge object contains a similarity value, which indicates the degree of similarity between the node objects connected by the edge object.
4. A method for detecting and analyzing abnormal network permissions according to claim 1, characterized in that: In the process of digitally representing the function items of the business system through the access records of the business system, the function item frequency TF and the inverse function item frequency IDF are calculated: Function item frequency TF = the number of times a specified function item appears in a specified user's access / the total number of times a specified user accesses all function items; Inverse function item frequency IDF = log (total number of users / (number of users accessing the specified function item + 1)); In the process of representing users as vectors of functional terms: The function access of each user within a period of time is represented by the TF-IDF value to form a vector of user access function items.
5. A method for detecting and analyzing abnormal network permissions according to claim 4, characterized in that: Calculate the similarity between the user and the group, and determine whether the user is over-authorized based on the similarity between the user and the group: Average each user vector within the user group to form a functional vector representation of the group; Use cosine similarity to calculate the cosine similarity between each user and the group to which they belong; determine whether the user is over-authorized based on the cosine similarity between each user and the group to which they belong; Also includes: Calculate the outlier value of user cosine similarity, using In principle, user over-authorization warnings are issued; For the alarmed users, the generalized Accard coefficient between the user function items and the group function items is calculated one by one. According to the principle of Gaussian distribution, the function items with a standard deviation greater than 3 times the mean value are taken as over-authorized function items, and over-authorized function item alarm processing is performed.
6. A method for detecting and analyzing abnormal network permissions according to claim 1, characterized in that: In the process of detecting user unauthorized access by parsing the URL address accessed by the user and the mapping table of users and authorized URL access addresses already obtained in the business system: Construct a time series analysis of each user's daily visits and calculate whether the number of visits by the user currently exceeds the result of the time series analysis; If the number of visits exceeding the time series prediction reaches the set visit volume threshold, the user's visit behavior on that day is constructed into an visit behavior vector, and the cosine similarity A is calculated with the user's visit behavior vector in the past week; Calculate the cosine similarity B based on the user's current access behavior vector and the access behavior vector of the group in the past week; If both cosine similarity A and cosine similarity B exceed the set similarity threshold, an unauthorized access behavior warning is issued; The steps to construct a time series analysis of each user's daily visits include: Collect time series data; preprocess time series data; model selection and parameter estimation; model testing and diagnosis; model application and prediction.
7. A method for detecting and analyzing abnormal network permissions according to claim 1, characterized in that: Also includes: When alarms are triggered by both excessive user authorization and unauthorized access, the security detection mechanism is used to identify the attack source to determine the authenticity of the alarm.
8. A network abnormal authority detection and analysis device, characterized in that: include: User group classification component, over-authorization detection component, and unauthorized access detection component; The user group segmentation component includes: A user vector construction module is used to construct a two-dimensional wide table according to the access information of users accessing the service system within the set statistical interval, and construct a user vector using the access information of each user in the two-dimensional wide table; A user similarity calculation module, used to calculate the similarity between any two users among all users according to the user vectors, to obtain the similarity between any two users among all users; A graph data organization module, used to organize graph data using the similarity between two users among all users; A group division module, used to divide users into groups using a clustering algorithm according to the graph data; The over-authorization detection component includes: A function item representation module, used to digitally represent the function items of the business system through the access records of the business system; A user-function item mapping module is used to map users to authorized function items and represent users as vectors of function items; An over-authorization judgment module is used to calculate the similarity between the user and the group, and judge whether the user is over-authorized based on the similarity between the user and the group; The unauthorized access detection component includes: A user unauthorized access detection module, used to detect user unauthorized access through URL address resolution accessed by the user and a mapping table of users and authorized URL access addresses acquired in the business system; The unauthorized access identification module is used to identify unauthorized access for over-authorized users when the function accessed by the user belongs to the over-authorized function.
9. A network abnormal authority detection and analysis device according to claim 8, characterized in that: In the user vector construction module: The two-dimensional wide table is formed by taking the URL addresses accessed by all users in the statistical interval as column fields, each user as a row field, and taking the number of times the user accesses the URL address divided by the total number of times the user accesses the system in the statistical interval as the value; In the graph data organization module: Create a graph data structure, which includes node objects and edge objects. The node object represents each user in the data set, and the edge object represents the similarity between two users. For each pair of nodes in the data set, an edge object is created using the pre-calculated similarity between two users, and the pair of node objects with similarity is used as the starting point and end point of the edge object; the edge object contains a similarity value, which indicates the degree of similarity between the node objects connected by the edge object; The functional items represent modules: In the process of digitally representing the function items of the business system through the access records of the business system, the function item frequency TF and the inverse function item frequency IDF are calculated: Function item frequency TF = the number of times a specified function item appears in a specified user's access / the total number of times a specified user accesses all function items; Inverse function item frequency IDF = log (total number of users / (number of users accessing the specified function item + 1)); In the user-function item mapping module: The function access of each user within a certain period of time is represented by the TF-IDF value to form a vector of user access function items; In the over-authorization judgment module: Average each user vector within the user group to form a functional vector representation of the group; Use cosine similarity to calculate the cosine similarity between each user and the group to which they belong; determine whether the user is over-authorized based on the cosine similarity between each user and the group to which they belong; The over-authorization detection component further includes: The user over-authorization alarm module is used to calculate the abnormal value of the user cosine similarity and use In principle, user over-authorization warnings are issued; The function item alarm processing module is used to calculate the generalized accard coefficient between the user function item and the group function item for each alarmed user, and according to the Gaussian distribution principle, take the function item with a standard deviation greater than 3 times the mean value as the over-authorized function item, and perform over-authorized function item alarm processing; In the user unauthorized detection module: Construct a time series analysis of each user's daily visits and calculate whether the number of visits by the user currently exceeds the result of the time series analysis; If the number of visits exceeding the time series prediction reaches the set visit volume threshold, the user's visit behavior on that day is constructed into an visit behavior vector, and the cosine similarity A is calculated with the user's visit behavior vector in the past week; Calculate the cosine similarity B based on the user's current access behavior vector and the access behavior vector of the group in the past week; If both cosine similarity A and cosine similarity B exceed the set similarity threshold, an unauthorized access behavior warning is issued.
10. A network abnormal authority detection and analysis device according to claim 9, characterized in that: Also included is a discriminant component, the discriminant component comprising: The attack source identification module is used to identify the attack source by using the security detection mechanism to determine the authenticity of the alarm when an alarm occurs due to excessive user authorization and unauthorized access.
Citation Information
Patent Citations
Network acceleration method and device based on DNS protocol, storage medium and electronic equipment
CN117097698A
Access permission method and system based on cloud computing and medium
CN118842651A