Risk Behavior Recognition Method and Device Based on Fingerprint Mouse
By using a fingerprint mouse-based risk behavior recognition method in the online office system, the user's fingerprint and access behavior are identified, and the problem of low information security in the online office system is solved, and the effect of automatic risk identification and improving information security is achieved.
Patent Information
- Application Number
- CN202510221612.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-02-27
AI Technical Summary
The information security of existing online office systems is low and there is a lack of effective risk identification solutions.
The risk behavior recognition method based on fingerprint mouse is adopted, and the user's fingerprint image and access operation behavior are collected through the fingerprint acquisition module, the substitution behavior and violation risk behavior are identified, the total risk score is calculated, and the risk warning operation is performed when the set threshold is reached.
It realizes automatic risk identification based on fingerprint authentication and access operation behavior during system use, improving information security.
Smart Images

Figure CN119696939B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence technology, and in particular, to a method and device for identifying risk behaviors based on a fingerprint mouse. Background Art
[0002] Network system security refers to the protection of the hardware, software, and data in the network system from being damaged, modified, or leaked due to accidental or malicious reasons, and the system runs continuously, reliably, and normally, and the network service is not interrupted.
[0003] For various types of network office systems, each subordinate department can transmit, query, and share various types of information in real time through the network office system. This networking method greatly improves the work efficiency of network office and strengthens the communication and collaboration between different regions and different levels; the information content in the network office system is very important, and it is of great significance to ensure the access and use of data under safe and legal conditions, as well as to prevent personal privacy leakage and data security risks.
[0004] Currently, there is a lack of an effective risk identification solution for network office systems, and the information security of network office systems is relatively low. Summary of the Invention
[0005] The present disclosure provides a method and device for identifying risk behaviors based on a fingerprint mouse to at least solve the problem of relatively low existing information security.
[0006] The technical solution of the present disclosure is as follows:
[0007] On the one hand, the present disclosure provides a method for identifying risk behaviors based on a fingerprint mouse, including:
[0008] Collecting a user fingerprint image by using a fingerprint collection module provided on the fingerprint mouse, and collecting a user access operation behavior by using a computer system;
[0009] Identifying a behavior of changing persons according to the fingerprint comparison result of the user fingerprint image;
[0010] Identifying existing illegal risk behaviors according to the access operation behavior;
[0011] Determining a total risk score according to each of the illegal risk behaviors;
[0012] Performing a risk warning operation when the total risk score is greater than or equal to a set score threshold.
[0013] Optionally, the violation risk behaviors include at least one of the following: injection attack, cross-site attack, malicious refresh, and data scraping; the access operation behaviors include at least one of the following: access frequency, access behavior, and access content; identifying the existing violation risk behaviors according to the access operation behaviors includes:
[0014] If the access content matches the set rule template successfully, it is determined that there is an injection attack;
[0015] Detect malicious code in the access content using regular expressions;
[0016] If the access frequency to the data interface is greater than the set frequency threshold, it is determined that there is a malicious refresh;
[0017] Determine that there is data scraping according to the non-browser access actions in the access log in the access content.
[0018] Optionally, determining the total risk score according to each violation risk behavior includes:
[0019] Count the number of occurrences of each violation risk behavior;
[0020] Determine the score of each violation risk behavior according to the number of occurrences of each violation risk behavior;
[0021] Determine the total risk score according to the score of each violation risk behavior and the weight of each violation risk behavior.
[0022] Optionally, when the total risk score is greater than or equal to the set score threshold, performing a risk warning operation includes:
[0023] When the total risk score is greater than or equal to the set score threshold, generate a warning message and record it in the warning database, and pop up and display the warning message; and / or,
[0024] Send the warning message to the management device, and the warning message includes the violation risk behavior.
[0025] Optionally, the user fingerprint image includes: a first fingerprint image and a second fingerprint image, and identifying a person substitution behavior according to the fingerprint comparison result of the user fingerprint image includes:
[0026] Perform a fingerprint comparison according to the first fingerprint image and the second fingerprint image to obtain a fingerprint comparison result; wherein, the first fingerprint image is an image collected by the fingerprint acquisition module during the process of logging in to the target system, and the second fingerprint image is an image collected by the fingerprint acquisition module during the process of using the target system.
[0027] Identify the behavior of personnel substitution based on the fingerprint comparison result.
[0028] Optionally, the fingerprint comparison based on the first fingerprint image and the second fingerprint image to obtain a fingerprint comparison result includes:
[0029] Perform preprocessing operations on the first fingerprint image and the second fingerprint image respectively to obtain a preprocessed first fingerprint image and a preprocessed second fingerprint image;
[0030] Perform alignment operations on the preprocessed first fingerprint image and the preprocessed second fingerprint image respectively to obtain an aligned first fingerprint image and an aligned second fingerprint image;
[0031] Perform feature extraction on the aligned first fingerprint image and the aligned second fingerprint image respectively to obtain a first texture feature and a first minutiae feature corresponding to the first fingerprint image, and a second texture feature and a second minutiae feature corresponding to the second fingerprint image;
[0032] Concatenate the first texture feature and the first minutiae feature into a first feature vector, and concatenate the second texture feature and the second minutiae feature into a second feature vector;
[0033] Perform fingerprint comparison based on the first feature vector and the second feature vector to obtain the fingerprint comparison result.
[0034] Optionally, the performing alignment operation on the preprocessed first fingerprint image to obtain an aligned first fingerprint image includes:
[0035] Input the preprocessed first fingerprint image into a positioning network for rotation and translation operations to obtain an aligned first fingerprint image.
[0036] Optionally, the performing feature extraction on the aligned first fingerprint image to obtain a first texture feature and a first minutiae feature includes:
[0037] Input the aligned first fingerprint image into a texture feature network to obtain the first texture feature;
[0038] Input the aligned first fingerprint image into a texture feature network to obtain the first minutiae feature.
[0039] Optionally, the performing fingerprint comparison based on the first feature vector and the second feature vector to obtain the fingerprint comparison result includes:
[0040] Calculate the similarity between the first feature vector and the second feature vector;
[0041] When the similarity is greater than or equal to the similarity threshold, it is determined that the fingerprint comparison result is a successful fingerprint authentication.
[0042] On the other hand, the present disclosure also provides a risk behavior recognition device based on a fingerprint mouse, including:
[0043] An information collection module that uses a fingerprint collection module provided on the fingerprint mouse to collect a user's fingerprint image and uses a computer system to collect the user's access operation behavior;
[0044] A person substitution recognition module for recognizing a person substitution behavior according to the fingerprint comparison result of the user's fingerprint image;
[0045] A violation recognition module for recognizing existing violation risk behaviors according to the access operation behavior;
[0046] A risk determination module for determining a total risk score according to each of the violation risk behaviors;
[0047] A warning execution module for performing a risk warning operation when the total risk score is greater than or equal to a set score threshold.
[0048] The technical solutions provided by the embodiments of the present disclosure at least bring the following beneficial effects:
[0049] In some embodiments of the present disclosure, a user's fingerprint image and access operation behavior are collected; a person substitution behavior is recognized according to the fingerprint comparison result of the user's fingerprint image; existing violation risk behaviors are recognized according to the access operation behavior; a total risk score is determined according to each violation risk behavior; and a risk warning operation is performed when the total risk score is greater than or equal to a set score threshold. During the use of the system, the present disclosure automatically performs risk recognition based on fingerprint authentication and access operation behavior, improving information security.
[0050] It should be understood that the above general description and subsequent detailed description are only exemplary and explanatory, and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure and do not constitute an undue limitation on the present disclosure.
[0052] Figure 1 A flowchart showing a risk behavior recognition method based on a fingerprint mouse provided by an exemplary embodiment of the present disclosure;
[0053] Figure 2 A structural diagram showing a risk behavior recognition device based on a fingerprint mouse provided by an exemplary embodiment of the present disclosure;
[0054] Figure 3 Schematic structural diagram of an electronic device provided for an exemplary embodiment of the present disclosure. Detailed implementation manners
[0055] In order to enable those of ordinary skill in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0056] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such used data may be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order different from those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure.
[0057] It should be noted that the user information involved in the present disclosure includes, but is not limited to: user device information and user personal information; the collection, storage, use, processing, transmission, provision, and disclosure of user information in the present disclosure and other processing are all in compliance with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0058] In view of the above technical problems, in some embodiments of the present disclosure, a user fingerprint image and access operation behaviors are collected; a behavior of replacing a person is identified according to the fingerprint comparison result of the user fingerprint image; a risk behavior of violation existing is identified according to the access operation behaviors; a total risk score is determined according to each risk behavior of violation; and a risk warning operation is executed when the total risk score is greater than or equal to a set score threshold; during the use of the system in the present disclosure, risk identification is automatically performed based on fingerprint authentication and access operation behaviors, improving information security.
[0059] The following will detail the technical solutions provided by each embodiment of the present disclosure with reference to the accompanying drawings.
[0060] Figure 1 Flow chart of a method for identifying risk behaviors based on a fingerprint mouse provided for an exemplary embodiment of the present disclosure. As Figure 1 shown, the method includes:
[0061] S101: Collect a user fingerprint image by using a fingerprint collection module provided on the fingerprint mouse, and collect user access operation behaviors by using a computer system;
[0062] S102: Identify a behavior of replacing a person according to the fingerprint comparison result of the user fingerprint image;
[0063] S103: Identify the existing illegal risk behaviors based on the access operation behaviors;
[0064] S104: Determine the total risk score according to each illegal risk behavior;
[0065] S105: Perform a risk warning operation when the total risk score is greater than or equal to the set score threshold.
[0066] In this embodiment, the execution subject of the above method is a terminal device. The types of terminal devices include but are not limited to: personal computers, notebooks, tablet computers, mobile phones, and smart screens.
[0067] In this embodiment, collect the user's fingerprint image and access operation behaviors; identify the behavior of replacing people according to the fingerprint comparison result of the user's fingerprint image; identify the existing illegal risk behaviors according to the access operation behaviors; determine the total risk score according to each illegal risk behavior; perform a risk warning operation when the total risk score is greater than or equal to the set score threshold; during the use of the system of the present disclosure, automatically perform risk identification based on fingerprint authentication and access operation behaviors to improve information security.
[0068] It should be noted that the target system can be any type of network office system. The present disclosure does not limit the target system, and the target system can also be an official website or an enterprise content website.
[0069] A fingerprint mouse is a mouse product that combines fingerprint recognition technology and optoelectronic positioning technology. It not only has all the functions of a traditional mouse, but also can achieve security functions such as computer login and file encryption through fingerprint recognition. The fingerprint mouse can perform identity verification when the user touches the mouse through the built-in fingerprint chip and live fingerprint recognition technology, ensuring that only authorized users can access the computer or related files. The working principle of the fingerprint mouse is based on fingerprint recognition technology. When the user touches the mouse, the built-in sensor will receive a high-frequency alternating magnetic field, which will then power the chip and identify the fingerprint information. The chip will compare the stored fingerprint information with the real-time collected fingerprint information, and perform corresponding operations such as computer login and file encryption after confirming the identity.
[0070] Access behaviors mainly refer to the behaviors of the user operating the mouse, such as mouse click, drag, double-click, right-click, scroll wheel sliding, scroll wheel click and other mouse events. Access content mainly refers to the click of function keys on the currently accessed page, content browsing, content input, triggering access behaviors, etc.
[0071] An injection attack refers to an attacker injecting carefully crafted attack code where an application receives user input, with the aim of performing arbitrary operations, tampering with data, or obtaining sensitive information. Injection attacks are one of the most common types of attacks on web applications. A successful injection attack can lead to risks in aspects such as the confidentiality, integrity, and availability of the application.
[0072] Cross-Site Scripting (XSS) is a common web security vulnerability. Attackers use this vulnerability to insert malicious scripts into the victim's web page, thereby obtaining the user's sensitive information, hijacking sessions, or carrying out other malicious activities. The main principle of an XSS attack is to take advantage of the incorrect processing of user input by a website, enabling malicious users to inject malicious scripts into the victim's web page. These scripts are executed in the user's browser, resulting in security risks.
[0073] Malicious refreshing refers to the act of repeatedly refreshing a web page or application interface through automated tools or scripts for some improper purpose. This behavior usually imposes an unnecessary load on the server, affects the access experience of normal users, and may even be used for fraud or other malicious activities.
[0074] Data Crawling refers to the process of obtaining and extracting data from the Internet through automated programs. It is also known as Web Spider or Web Scraping and is commonly used to collect, parse, and store information from sources such as web pages, API interfaces, and documents. The application areas of data crawling include: web content collection, where by crawling web page data, comprehensive data capture and analysis are achieved for applications such as public opinion monitoring, news aggregation, and search engines; data analysis and mining, where by crawling data sources to obtain a large amount of data, data cleaning, processing, and analysis are carried out to discover patterns, trends, and regularities hidden in the data; social media data collection, where by crawling user information, posts, and comments on social media, research such as user profiling, public opinion analysis, and social network analysis is conducted.
[0075] In some embodiments of the present disclosure, a fingerprint acquisition module provided on a fingerprint mouse is used to acquire a user fingerprint image, where the user fingerprint image includes: a first fingerprint image and a second fingerprint image; fingerprint comparison is performed based on the first fingerprint image and the second fingerprint image to obtain a fingerprint comparison result; and a behavior of user replacement is identified according to the fingerprint comparison result. The first fingerprint image is an image acquired by the fingerprint acquisition module during the process of logging in to a target system, and the second fingerprint image is an image acquired by the fingerprint acquisition module during the process of using the target system. Among them, when the fingerprint comparison result is that fingerprint authentication is passed, it is determined that there is no behavior of user replacement; when the fingerprint comparison result is that fingerprint authentication fails, it is determined that there is a behavior of user replacement.
[0076] It should be noted that the first fingerprint image may be the fingerprint image first acquired after successful login verification during the process of logging in to the target system, and the second fingerprint image is continuously acquired at intermittent set times during the process of using the target system to continuously perform fingerprint authentication during the process of using the target system to identify whether there is a problem of someone else using the system. The present disclosure uses a fingerprint mouse to perform fingerprint authentication on a target user, improving the security of network access. It should be noted that the present disclosure does not limit the set time, which can be adjusted according to actual situations. The set time, for example, is 10 seconds, 1 minute, etc.
[0077] In some embodiments of the present disclosure, fingerprint comparison is performed based on the first fingerprint image and the second fingerprint image to obtain a fingerprint comparison result. One feasible way is to perform preprocessing operations on the first fingerprint image and the second fingerprint image respectively to obtain a preprocessed first fingerprint image and a preprocessed second fingerprint image; perform alignment operations on the preprocessed first fingerprint image and the preprocessed second fingerprint image respectively to obtain an aligned first fingerprint image and an aligned second fingerprint image; perform feature extraction on the aligned first fingerprint image and the aligned second fingerprint image respectively to obtain a first texture feature and a first minutiae feature corresponding to the first fingerprint image and a second texture feature and a second minutiae feature corresponding to the second fingerprint image; splice the first texture feature and the first minutiae feature into a first feature vector, and splice the second texture feature and the second minutiae feature into a second feature vector; perform fingerprint comparison based on the first feature vector and the second feature vector to obtain a fingerprint comparison result.
[0078] In the above embodiment, a preprocessing operation is performed on the first fingerprint image to obtain a preprocessed first fingerprint image. Among them, preprocessing operations such as denoising and enhancement are performed on the first fingerprint image to improve the image quality.
[0079] In the above embodiments, an alignment operation is performed on the preprocessed first fingerprint image to obtain the aligned first fingerprint image. One possible implementation is to input the preprocessed first fingerprint image into a positioning network for rotation and translation operations to obtain the aligned first fingerprint image. Similarly, the preprocessed second fingerprint image is input into the positioning network for rotation and translation operations to obtain the aligned second fingerprint image.
[0080] Before using the positioning network, the positioning network needs to be trained first. The training process is as follows: it is necessary to collect sample fingerprint images and corresponding sample aligned fingerprint images of the sample fingerprint images, label the sample fingerprint images and the sample aligned fingerprint images to form a labeled data set, and use the labeled data set to train the initial model to obtain the trained positioning network.
[0081] In the above embodiments, feature extraction is performed on the aligned first fingerprint image to obtain texture features and minutiae features. One possible implementation is to input the aligned first fingerprint image into a texture feature network to obtain the first texture feature; input the aligned first fingerprint image into the texture feature network to obtain the first minutiae feature. It should be noted that the texture features mainly include global features and local features; the global features refer to those features that can be directly observed by the naked eye, such as ridge pattern, pattern area, core point, delta point, and ridge count, etc. The ridge pattern divides fingerprints into circular, arch, and spiral according to the direction and distribution of the ridge lines. The local features include parameters such as the direction, curvature, and position of the fingerprint ridge lines. The minutiae features refer to those specific feature points used for fingerprint recognition and comparison, including the endpoints, bifurcations, terminations, divergences, isolated points, loop points, short ridges, etc. of the ridge lines. These minutiae provide unique confirmation information of the fingerprint and are the key to distinguishing different fingerprints. The present disclosure uses a texture feature network and a minutiae feature network for feature extraction to more comprehensively describe fingerprint information and improve the feature expression ability. Among them, the types of the texture feature network and the minutiae feature network in the present disclosure are not limited. Similarly, the above method is used to perform feature extraction on the aligned second fingerprint image to obtain the second texture feature and the second minutiae feature, which will not be elaborated here.
[0082] In the above embodiments, the first texture feature and the first minutiae feature are concatenated into a first feature vector. Among them, the first texture feature is vectorized to obtain a first vector; the first minutiae feature is vectorized to obtain a second vector; the first vector and the second vector are directly concatenated to obtain a long feature vector, that is, the first feature vector, which is convenient for subsequent data processing. Similarly, the second texture feature and the second minutiae feature are concatenated into a second feature vector in the above manner.
[0083] In the above embodiments, fingerprint comparison is performed based on the first feature vector and the second feature vector to obtain a fingerprint comparison result. One achievable way is to calculate the similarity between the first feature vector and the second feature vector; when the similarity is greater than or equal to the similarity threshold, it is determined that the fingerprint comparison result is that fingerprint authentication is passed; when the similarity is less than the similarity threshold, it is determined that the fingerprint comparison result is that fingerprint authentication fails. It should be noted that the present disclosure does not limit the similarity threshold, and the similarity threshold can be adjusted according to the actual situation. The similarity threshold, for example, is 90, 95, etc.
[0084] In an exemplary embodiment, an encryption mechanism is used to encrypt and store and transmit fingerprint features to prevent the leakage of fingerprint information and ensure the privacy and security of users.
[0085] In some embodiments of the present disclosure, during the process of a target user using a target system, the access operation behaviors of the target user are collected. It is possible to identify the risk behaviors of violations existing during the user's use of the system. Among them, the access operation behaviors include, but are not limited to: user fingerprint information, user information, device information, user operation type, system name, function name, access address, access method, access content, access frequency, access parameters, access response code, access response content, and access time.
[0086] In some embodiments of the present disclosure, based on the access operation behaviors, the existing risk behaviors of violations are identified. Among them, the risk behaviors of violations in the present disclosure include at least one of the following: injection attack, cross-site attack, malicious refresh, and data crawling. The specific identification methods of the risk behaviors of violations are described in detail below.
[0087] Risk behavior identification method 1: When the access content matches the set rule template successfully, it is determined that there is an injection attack. The user access content is pre-judged by using the pattern matching method. The behaviors of the user access content containing SQL key element information, such as accesses containing conditions such as creating, deleting, modifying databases, data tables, data indexes, and related combined conditions of AND, OR, BETWEEN, etc. For example, injection_patterns = [ r"\b(select|insert|update|delete)\b", # Match common SQL keywords r"(\'|`).*?(\'|`)", # Match the content within quotes, which may be the parameters injected in parameterized queries r"(;|--|\ / \*|\*\ / )", # Match special characters such as semicolons and comment symbols that may be used for SQL injection ], it is recognized that there is an injection attack, and subsequent warning operations are performed.
[0088] Risk behavior identification method 2: Use regular expressions to detect malicious code in the accessed content. Cross-Site Scripting (XSS) is a common web security vulnerability where attackers inject malicious scripts into web pages to steal user information or perform other malicious operations. Use regular expressions on user input content to detect potential malicious code in the input content. For example,
[0089] xss_pattern = re.compile(r'<script|javascript:|on[a-zA-Z]+=|data:text / html;base64,') The rule is used to detect XSS attack behaviors, where <script>标签及其内容;javascript:开头的URL;on[a-zA-Z]+=形式的DOM事件处理程序。data:text / html;base64,编码的HTML内容。
[0090] 风险行为识别方式三:在对数据接口的访问频率大于设定频率阈值的情况下,则确定存在恶意刷新。依靠较短时间窗口内捕获用户对同一个资源不断的访问行为。需要说明的是,本公开对设定频率阈值不作限定,设定频率阈值可以根据实际情况作出调整。设定频率阈值,可以为50次,100次,或者200次。例如,用户在10秒内对数据接口进行访问达100次以上,则可判定用户行为是一个恶意刷新行为。
[0091] 风险行为识别方式四:根据访问内容中的访问日志中的非浏览器的访问动作,确定存在爬取数据。主要针对终端用户使用不当手段获取数据的手段,判断这种行为主要依靠用户的访问日志,从日志中提取非浏览器的访问动作,并且以查询数据为主的访问行为,作为主要判断依据。
[0092] 在本公开的一些实施例中,根据每种违规风险行为,确定总风险得分。一种可实现的方式为,统计每种违规风险行为出现的次数;根据每种违规风险行为出现的次数,确定每种违规风险行为的得分;根据每种违规风险行为的得分与每种违规风险行为的权重,确定总风险得分。其中,统计设定周期内每种违规风险行为出现的次数,基于出现次数计算每种违规风险行为的得分;再基于每种违规风险行为的得分与每种违规风险行为的权重,计算总风险得分;本公开通过违规风险行为出现的次数和权重,计算总风险得分,总风险得分的确定更加合理以及准确。
[0093] 例如,统计一天之内注入攻击、跨站攻击、恶意刷新、爬取数据分别出现的次数;其中,注入攻击行为每出现一次增加1分;跨站攻击行为每出现一次增加1分;恶意刷新行为每出现一次增加1分;爬取数据行为每出现一次增加1分。根据每种违规风险行为的危害程度,分别为四种违规风险行为赋予相应的权重系数;其中,注入攻击行为对应的权重系数为9,跨站攻击行为对应的权重系数为2,恶意刷新行为对应的权重系数为1,爬取数据行为对应的权重系数为5。总风险得分的计算公式如下:
[0094] 注入攻击行为次数*9+跨站攻击行为次数*2+恶意刷新行为次数*1+爬取数据行为次数*5=总风险得分。
[0095] 在本公开的一些实施例中,在总风险得分大于或者等于设定得分阈值的情况下,执行风险警示操作。其中,风险警示操作包括但不限于以下几种警示方式:
[0096] 风险警示方式一:在总风险得分大于或者等于设定得分阈值的情况下,生成警告信息记录至警告数据库,并弹窗显示警告信息。需要说明的是,本公开对设定得分阈值不作限定,设定得分阈值可以根据实际情况作出调整,设定得分阈值,例如,85分,90分等。本公开在总风险得分大于或者等于设定得分阈值的情况下,生成警告信息记录至警告数据库,以供后续查询警告信息记录进行维护工作;在目标用户所使用的用户终端弹窗显示警告信息,对目标用户起到警示作用。其中,本公开对警告信息的具体实现方式不作限定。
[0097] 风险警示方式二:向管理设备发送警告信息,警告信息包括违规风险行为。需要说明的是,在总风险得分大于或者等于设定得分阈值的情况下,向管理设备发送警告信息,以供管理用户查看警告信息进行后续风险处理操作。
[0098] 在本公开上述方法实施例中,采集用户指纹图像和访问操作行为;根据用户指纹图像的指纹比对结果,识别换人行为;根据访问操作行为,识别存在的违规风险行为;根据每种违规风险行为,确定总风险得分;在总风险得分大于或者等于设定得分阈值的情况下,执行风险警示操作;本公开在系统使用过程中,基于指纹认证及访问操作行为自动进行风险识别,提高信息安全性。
[0099] 图2为本公开示例性实施例提供的一种基于指纹鼠标的风险行为识别装置20的结构示意图。如图2所示,该基于指纹鼠标的风险行为识别装置20包括:信息采集模块21,换人识别模块22,违规识别模块23,风险确定模块24和警示执行模块25。
[0100] 信息采集模块21,利用指纹鼠标上设置的指纹采集模块采集用户指纹图像,利用计算机系统采集用户访问操作行为;
[0101] 换人识别模块22,用于根据用户指纹图像的指纹比对结果,识别换人行为;
[0102] 违规识别模块23,用于根据访问操作行为,识别存在的违规风险行为;
[0103] 风险确定模块24,用于根据每种违规风险行为,确定总风险得分;
[0104] 警示执行模块25,在总风险得分大于或者等于设定得分阈值的情况下,用于执行风险警示操作。
[0105] 可选地,违规风险行为包括以下至少一种:注入攻击、跨站攻击、恶意刷新和爬取数据;访问操作行为包括以下至少一种:访问频率、访问行为和访问内容;违规识别模块23在根据访问操作行为,识别存在的违规风险行为时,用于:
[0106] 在访问内容与设定规则模板匹配成功的情况下,则确定存在注入攻击;
[0107] 使用正则表达式检测访问内容中的恶意代码;
[0108] 在对数据接口的访问频率大于设定频率阈值的情况下,则确定存在恶意刷新;
[0109] 根据访问内容中的访问日志中的非浏览器的访问动作,确定存在爬取数据。
[0110] 可选地,风险确定模块24在根据每种违规风险行为,确定总风险得分时,用于:
[0111] 统计每种违规风险行为出现的次数;
[0112] 根据每种违规风险行为出现的次数,确定每种违规风险行为的得分;
[0113] 根据每种违规风险行为的得分与每种违规风险行为的权重,确定总风险得分。
[0114] 可选地,警示执行模块25在总风险得分大于或者等于设定得分阈值的情况下,执行风险警示操作时,用于:
[0115] 在总风险得分大于或者等于设定得分阈值的情况下,生成警告信息记录至警告数据库,并弹窗显示警告信息;和 / 或,
[0116] 向管理设备发送警告信息,警告信息包括违规风险行为。
[0117] 可选地,用户指纹图像包括:第一指纹图像和第二指纹图像,换人识别模块22在根据用户指纹图像的指纹比对结果,识别换人行为时,用于:
[0118] 根据第一指纹图像和第二指纹图像进行指纹比对,得到指纹比对结果;其中,第一指纹图像是在登录目标系统的过程中利用指纹采集模块采集到的图像,第二指纹图像是在使用目标系统的过程中利用指纹采集模块采集到的图像;
[0119] 根据指纹比对结果,识别换人行为。
[0120] 可选地,换人识别模块22在根据第一指纹图像和第二指纹图像进行指纹比对,得到指纹比对结果时,用于:
[0121] 对第一指纹图像和第二指纹图像分别进行预处理操作,得到预处理后的第一指纹图像和预处理后的第二指纹图像;
[0122] 对预处理后的第一指纹图像和预处理后的第二指纹图像分别进行对齐操作,得到对齐后的第一指纹图像和对齐后的第二指纹图像;
[0123] 对对齐后的第一指纹图像和对齐后的第二指纹图像分别进行特征提取,得到第一指纹图像对应的第一纹理特征和第一细节点特征以及第二指纹图像对应的第二纹理特征和第二细节点特征;
[0124] 将第一纹理特征和第一细节点特征拼接为第一特征向量,以及将第二纹理特征和第二细节点特征拼接为第二特征向量;
[0125] 根据第一特征向量和第二特征向量进行指纹比对,得到指纹比对结果。
[0126] 可选地,换人识别模块22在对预处理后的第一指纹图像进行对齐操作,得到对齐后的第一指纹图像时,用于:
[0127] 将预处理后的第一指纹图像输入定位网络中进行旋转和平移操作,得到对齐后的第一指纹图像。
[0128] 可选地,换人识别模块22在对对齐后的第一指纹图像进行特征提取,得到第一纹理特征和第一细节点特征时,用于:
[0129] 将对齐后的第一指纹图像输入纹理特征网络中,得到第一纹理特征;
[0130] 将对齐后的第一指纹图像输入纹理特征网络中,得到第一细节点特征。
[0131] 可选地,换人识别模块22在根据第一特征向量和第二特征向量进行指纹比对,得到指纹比对结果时,用于:
[0132] 计算第一特征向量和第二特征向量的相似度;
[0133] 在相似度大于或者等于相似度阈值的情况下,则确定指纹比对结果为指纹认证通过。
[0134] 关于上述实施例中的装置,其中各个模块执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。
[0135] 图3为本公开示例性实施例提供的一种电子设备的结构示意图。如图3所示,电子设备包括:存储器31和处理器32。另外,电子设备还包括电源组件33和通信组件34。
[0136] 存储器31,用于存储计算机程序,并可被配置为存储其它各种数据以支持在电子设备上的操作。这些数据的示例包括用于在电子设备上操作的任何应用程序或方法的指令。
[0137] 存储器31,可以由任何类型的易失性或非易失性存储设备或者它们的组合实现,如静态随机存取存储器(SRAM),电可擦除可编程只读存储器(EEPROM),可擦除可编程只读存储器(EPROM),可编程只读存储器(PROM),只读存储器(ROM),磁存储器,快闪存储器,磁盘或光盘。
[0138] 通信组件34,用于与其他设备进行数据传输。
[0139] 处理器32,可执行存储器31中存储的计算机指令,以用于:利用指纹鼠标上设置的指纹采集模块采集用户指纹图像,利用计算机系统采集用户访问操作行为;根据用户指纹图像的指纹比对结果,识别换人行为;根据访问操作行为,识别存在的违规风险行为;根据每种违规风险行为,确定总风险得分;在总风险得分大于或者等于设定得分阈值的情况下,执行风险警示操作。
[0140] 相应地,本公开实施例还提供一种存储有计算机程序的计算机可读存储介质。当计算机可读存储介质存储计算机程序,且计算机程序被一个或多个处理器执行时,致使一个或多个处理器执行图1方法实施例中的各步骤。
[0141] 相应地,本公开实施例还提供一种计算机程序产品,计算机程序产品包括计算机程序 / 指令,计算机程序 / 指令被处理器执行图1的方法实施例中的各步骤。
[0142] 上述图3中的通信组件被配置为便于通信组件所在设备和其他设备之间有线或无线方式的通信。通信组件所在设备可以接入基于通信标准的无线网络,如WiFi,2G、3G、4G / LTE、5G等移动通信网络,或它们的组合。在一个示例性实施例中,通信组件经由广播信道接收来自外部广播管理系统的广播信号或广播相关信息。在一个示例性实施例中,通信组件还包括近场通信(NFC)模块,以促进短程通信。例如,在NFC模块可基于射频识别(RFID)技术,红外数据协会(IrDA)技术,超宽带(UWB)技术,蓝牙(BT)技术和其他技术来实现。
[0143] 上述图3中的电源组件,为电源组件所在设备的各种组件提供电力。电源组件可以包括电源管理系统,一个或多个电源,及其他与为电源组件所在设备生成、管理和分配电力相关联的组件。
[0144] 上述电子设备还包括显示屏和音频组件。
[0145] 显示屏包括屏幕,其屏幕可以包括液晶显示屏(LCD)和触摸面板(TP)。如果屏幕包括触摸面板,屏幕可以被实现为触摸屏,以接收来自用户的输入信号。触摸面板包括一个或多个触摸传感器以感测触摸、滑动和触摸面板上的手势。触摸传感器可以不仅感测触摸或滑动动作的边界,而且还检测与触摸或滑动操作相关的持续时间和压力。
[0146] 音频组件,可被配置为输出和 / 或输入音频信号。例如,音频组件包括一个麦克风(MIC),当音频组件所在设备处于操作模式,如呼叫模式、记录模式和语音识别模式时,麦克风被配置为接收外部音频信号。所接收的音频信号可以被进一步存储在存储器或经由通信组件发送。在一些实施例中,音频组件还包括一个扬声器,用于输出音频信号。
[0147] 在本公开上述装置、设备、存储介质和计算机程序产品实施例中,采集用户指纹图像和访问操作行为;根据用户指纹图像的指纹比对结果,识别换人行为;根据访问操作行为,识别存在的违规风险行为;根据每种违规风险行为,确定总风险得分;在总风险得分大于或者等于设定得分阈值的情况下,执行风险警示操作;本公开在系统使用过程中,基于指纹认证及访问操作行为自动进行风险识别,提高信息安全性。
[0148] 本领域内的技术人员应明白,本公开的实施例可提供为方法、系统、或计算机程序产品。因此,本公开可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本公开可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
[0149] 本公开是参照根据本公开实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
[0150] 这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
[0151] 这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
[0152] 在一个典型的配置中,计算设备包括一个或多个处理器 (CPU)、输入 / 输出接口、网络接口和内存。
[0153] 内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器 (RAM) 和 / 或非易失性内存等形式,如只读存储器 (ROM) 或闪存(flash RAM)。内存是计算机可读介质的示例。
[0154] 计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存 (PRAM)、静态随机存取存储器 (SRAM)、动态随机存取存储器 (DRAM)、其他类型的随机存取存储器 (RAM)、只读存储器 (ROM)、电可擦除可编程只读存储器 (EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘 (DVD) 或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体 (transitory media),如调制的数据信号和载波。
[0155] 需要说明的是,在本文中,诸如"第一”和"第二”等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语"包括”、"包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句"包括一个……”限定的要素,并不排除在包括要素的过程、方法、物品或者设备中还存在另外的相同要素。
[0156] 以上仅是本公开的具体实施方式,使本领域技术人员能够理解或实现本公开。对这些实施例的多种修改对本领域的技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本公开的精神或范围的情况下,在其它实施例中实现。因此,本公开将不会被限制于本文的这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽的范围。< / script>
Claims
1. A risk behavior identification method based on fingerprint mouse, characterized in that: include: After the target system login verification is passed, the user's fingerprint image first collected by the fingerprint collection module set on the fingerprint mouse is used as the first fingerprint image, the user's fingerprint image collected by the fingerprint collection module during the use of the target system is used as the second fingerprint image, and the user's access operation behavior including access frequency and access content is collected by the computer system; Preprocessing the first fingerprint image and the second fingerprint image respectively, aligning the preprocessed first fingerprint image and the second fingerprint image respectively, and extracting features from the aligned first fingerprint image and the second fingerprint image respectively to obtain a first texture feature and a first minutiae feature corresponding to the first fingerprint image, and a second texture feature and a second minutiae feature corresponding to the second fingerprint image; splicing the first texture feature and the first detail point feature into a first feature vector, and splicing the second texture feature and the second detail point feature into a second feature vector; performing fingerprint comparison according to the first feature vector and the second feature vector to obtain a fingerprint comparison result; and identifying the substitution behavior according to the fingerprint comparison result; According to the access operation behavior, the existing risk behavior of violations is identified; wherein, when the access content successfully matches the set rule template, the risk behavior of violations is determined to be an injection attack; when the access frequency to the data interface is greater than the set frequency threshold, the risk behavior of violations is determined to be a malicious refresh; when there is an access action to a non-browser in the access log of the access content, the risk behavior of violations is determined to be crawling data; Determine the score of each violation risk behavior based on the number of times each violation risk behavior occurs; determine the total risk score based on the score and weight of each violation risk behavior; When the total risk score is greater than or equal to the set score threshold, a corresponding risk warning operation is performed.
2. The method according to claim 1, characterized in that The risk of violation behavior also includes cross-site attack; the access operation behavior also includes access behavior; and the identifying of the risk of violation behavior based on the access operation behavior also includes: Regular expressions are used to detect malicious code in the accessed content.
3. The method according to claim 1, characterized in that When the total risk score is greater than or equal to the set score threshold, executing a corresponding risk warning operation includes: When the total risk score is greater than or equal to the set score threshold, a warning message is generated and recorded in the warning database, and a pop-up window is displayed to display the warning message; and / or, The warning information is sent to a management device, where the warning information includes the risky violation behavior.
4. The method according to claim 1, characterized in that The step of performing an alignment operation on the preprocessed first fingerprint image to obtain an aligned first fingerprint image includes: The preprocessed first fingerprint image is input into the positioning network for rotation and translation operations to obtain an aligned first fingerprint image.
5. The method according to claim 1, characterized in that The step of extracting features from the aligned first fingerprint image to obtain a first texture feature and a first minutiae feature includes: Inputting the aligned first fingerprint image into a texture feature network to obtain the first texture feature; The aligned first fingerprint image is input into a texture feature network to obtain the first detail point feature.
6. The method according to claim 1, characterized in that The fingerprint comparison is performed according to the first feature vector and the second feature vector to obtain the fingerprint comparison result, including: Calculating the similarity between the first feature vector and the second feature vector; When the similarity is greater than or equal to the similarity threshold, the fingerprint comparison result is determined to be fingerprint authentication passed.
7. A risk behavior identification device based on fingerprint mouse, characterized in that: include: The information collection module is used to, after the target system login verification is passed, use the user fingerprint image first collected by the fingerprint collection module set on the fingerprint mouse as the first fingerprint image, use the user fingerprint image collected by the fingerprint collection module during the use of the target system as the second fingerprint image, and use the computer system to collect the user access operation behavior including access frequency and access content; a person-changing recognition module, configured to perform a preprocessing operation on the first fingerprint image and the second fingerprint image, respectively, perform an alignment operation on the preprocessed first fingerprint image and the second fingerprint image, respectively, perform feature extraction on the first fingerprint image and the second fingerprint image after the alignment operation, and obtain a first texture feature and a first minutiae feature corresponding to the first fingerprint image, and a second texture feature and a second minutiae feature corresponding to the second fingerprint image; splicing the first texture feature and the first detail point feature into a first feature vector, and splicing the second texture feature and the second detail point feature into a second feature vector; performing fingerprint comparison according to the first feature vector and the second feature vector to obtain a fingerprint comparison result; and identifying the substitution behavior according to the fingerprint comparison result; A violation identification module is used to identify existing violation risk behaviors according to the access operation behavior; wherein, when the access content successfully matches the set rule template, the violation risk behavior is determined to be an injection attack; when the access frequency to the data interface is greater than a set frequency threshold, the violation risk behavior is determined to be a malicious refresh; when there is an access action to a non-browser in the access log of the access content, the violation risk behavior is determined to be crawling data; The risk determination module is used to determine the score of each violation risk behavior according to the number of occurrences of each violation risk behavior; and to determine the total risk score according to the score and weight of each violation risk behavior; The warning execution module is used to execute the corresponding risk warning operation when the total risk score is greater than or equal to the set score threshold.
Citation Information
Patent Citations
Secure protection starting method and apparatus, and computer readable storage medium
CN107197075A
A method and apparatus for continuously authenticating an identity through a fingerprint mouse
CN109145562A
Data leakage risk analysis method and data leakage risk analysis system
CN116776363A