Terminal user activity monitoring method and device, equipment and storage medium
The normal behavior baseline of end users is built through machine learning algorithms, and combined with the exception detection algorithm to identify abnormal behaviors, it solves the problem that traditional monitoring methods are difficult to deal with complex security threats, and achieves more accurate threat identification and security protection.
Patent Information
- Application Number
- CN202411969845.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
Traditional end-user behavior monitoring methods are difficult to deal with complex and changeable security threats, especially difficult to identify cunning new attacks and mutated malware.
Machine learning algorithms are used to analyze historical operation behavior data, build a normal behavior baseline, and compare real-time operation behavior data through an exception detection algorithm to identify abnormal behaviors. At the same time, analytical reports are generated for reference by enterprises and administrators.
Effectively identify different types of abnormal operation behaviors, improve the level of terminal security protection, optimize and adjust the system in a timely manner, and reduce security risks.
Smart Images

Figure CN119939574A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method, device, equipment and storage medium for monitoring terminal user activities. Background Art
[0002] With the widespread use of terminal devices, the behavior monitoring of terminal users has become an important topic in the field of network security. Traditional behavior monitoring methods mainly rely on rules and signatures, which are difficult to deal with complex and changing security threats. The limitation of this method is that it can only deal with known attack patterns, which are not suitable for those cunning new attacks or mutated malware. If artificial intelligence and machine learning technologies can be introduced, the monitoring system can automatically learn and identify abnormal behavior patterns, so that potential threats can be discovered more accurately. Summary of the invention
[0003] In view of the above-mentioned deficiencies in the prior art, the purpose of the present invention is to provide a terminal user activity monitoring method, device, equipment and storage medium, aiming to solve the technical problem that traditional behavior monitoring methods in the prior art are difficult to cope with abnormal behaviors initiated by complex patterns.
[0004] In order to achieve the above object, the present invention adopts the following technical solutions:
[0005] The first aspect of the present invention provides a terminal user activity monitoring method, comprising the following steps: obtaining historical operation behavior data of multiple users, using a machine learning algorithm to analyze the historical operation behavior data to obtain a normal behavior pattern, and constructing a normal behavior baseline based on the normal behavior pattern; obtaining the real-time operation behavior data of the user, using an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtaining the detection results, and processing the corresponding users according to the detection results; obtaining the operation behavior data and the detection results of all users within a specific time range, and generating an analysis report based on the operation behavior data and the detection results.
[0006] Optionally, in a first implementation method of the first aspect of the present invention, the historical operation behavior data of multiple users are obtained, the historical operation behavior data are analyzed using a machine learning algorithm to obtain a normal behavior pattern, and a normal behavior baseline is constructed based on the normal behavior pattern, specifically including: obtaining the historical operation behavior data of multiple users, cleaning and preprocessing the historical operation behavior data to obtain preprocessed data; analyzing the preprocessed data using a K-Means clustering algorithm and an association rule mining algorithm to obtain a normal behavior pattern; extracting key features from the normal behavior pattern, and constructing a normal behavior baseline based on the key features.
[0007] Optionally, in a second implementation method of the first aspect of the present invention, the real-time operation behavior data of the user is obtained, an anomaly detection algorithm is used to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, a detection result is obtained, and the corresponding user is processed according to the detection result, specifically including: obtaining the real-time operation behavior data of the user, an anomaly detection algorithm is used to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, and a detection result is obtained, wherein the detection result includes severity and type; according to a preset first processing scheme, automatic response measures are taken according to the severity of the detection result; the type of the detection result is compared with a pre-established threat feature database to obtain a comparison result, and the user is processed according to the comparison result and a preset second processing scheme.
[0008] Optionally, in a third implementation manner of the first aspect of the present invention, the real-time operation behavior data of the user is obtained, and an anomaly detection algorithm is used to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, and a detection result is obtained, and the detection result includes severity and type, specifically including: using the 3σ principle based on normal distribution to calculate the mean and standard deviation of each key feature in the normal behavior according to the normal behavior baseline; obtaining the real-time operation behavior data of the user, comparing the real-time operation behavior data with the mean and standard deviation of each key feature to obtain comparison data, and treating data exceeding the range of the mean ±3 times the standard deviation as abnormal data that is inconsistent with the normal behavior baseline; obtaining comparison data of the abnormal data, and generating a detection result based on the comparison data, and the detection result includes severity and type.
[0009] Optionally, in a fourth implementation method of the first aspect of the present invention, according to the preset first processing plan, automatic response measures are taken according to the severity of the detection results, specifically including: establishing a first processing plan, and setting corresponding automatic response measures according to the severity of the detection results; obtaining the detection results, and for abnormal operation behaviors with minor severity, generating and outputting email notification information; for abnormal operation behaviors with severe severity, generating and outputting emergency notification information.
[0010] Optionally, in a fifth implementation of the first aspect of the present invention, the type of the detection result is compared with a pre-established threat feature database to obtain a comparison result, and the user is processed according to the comparison result and a preset second processing scheme, specifically including: using a pattern matching algorithm to compare the type of the detection result with a pre-established threat feature database to obtain a comparison result; if the comparison result is that a security threat exists, processing is performed according to the preset second processing scheme, and for the type of abnormal login to the user account, the user is automatically locked; for the type of device being infected by malware, the device is isolated.
[0011] Optionally, in a sixth implementation manner of the first aspect of the present invention, the obtaining of the operation behavior data and the detection results thereof of all users within a specific time range, and generating an analysis report based on the operation behavior data and the detection results thereof, specifically includes: obtaining the operation behavior data and the detection results thereof of all users within a specific time range, and classifying the operation behavior data, wherein the classification types include: normal operation behavior data and abnormal operation behavior data; for abnormal operation behavior data, generating an abnormal behavior description based on its detection results, wherein the abnormal behavior description includes the time when the abnormality occurred, the operation content involved, the abnormal system commands, and the basis for determining the abnormality; generating security threat prompts and suggestions based on the abnormal behavior description to obtain a countermeasure description, and generating an analysis report based on the abnormal behavior description and the countermeasure description.
[0012] The second aspect of the present invention provides a terminal user activity monitoring device, including: an analysis module, used to obtain historical operation behavior data of multiple users, use a machine learning algorithm to analyze the historical operation behavior data to obtain a normal behavior pattern, and build a normal behavior baseline based on the normal behavior pattern; a detection module, used to obtain the real-time operation behavior data of the user, use an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtain the detection result, and process the corresponding user according to the detection result; a generation module, used to obtain the operation behavior data and the detection results of all users within a specific time range, and generate an analysis report based on the operation behavior data and the detection results.
[0013] Optionally, in a first implementation method of the second aspect of the present invention, the analysis module includes: a preprocessing unit, used to obtain historical operation behavior data of multiple users, and clean and preprocess the historical operation behavior data to obtain preprocessed data; an analysis unit, used to analyze the preprocessed data using a K-Means clustering algorithm and an association rule mining algorithm to obtain a normal behavior pattern; and a construction unit, used to extract key features from the normal behavior pattern and construct a normal behavior baseline based on the key features.
[0014] Optionally, in a second implementation of the second aspect of the present invention, the detection module includes: a detection submodule, used to obtain real-time operation behavior data of the user, using an anomaly detection algorithm to detect real-time operation behavior data that does not match the normal behavior baseline, and obtain a detection result, wherein the detection result includes severity and type; a processing submodule, used to take automatic response measures according to the severity of the detection result according to a preset first processing scheme; a comparison submodule, used to compare the type of the detection result with a pre-established threat feature database to obtain a comparison result, and process the user according to the comparison result and a preset second processing scheme.
[0015] Optionally, in a third implementation of the second aspect of the present invention, the detection submodule includes: a calculation unit, used to adopt the 3σ principle based on normal distribution to calculate the mean and standard deviation of each key feature in the normal behavior according to the normal behavior baseline; a comparison unit, used to obtain the user's real-time operation behavior data, compare the real-time operation behavior data with the mean and standard deviation of each key feature to obtain comparison data, and regard data exceeding the range of ±3 times the standard deviation of the mean as abnormal data that does not conform to the normal behavior baseline; a first generation unit, used to obtain comparison data of the abnormal data, and generate a detection result based on the comparison data, wherein the detection result includes severity and type.
[0016] Optionally, in a fourth implementation of the second aspect of the present invention, the processing submodule includes: an establishment unit, used to establish a first processing plan, and set corresponding automatic response measures according to the severity of the detection results; a second generation unit, used to obtain the detection results, and for abnormal operation behaviors with minor severity, generate and output email notification information; a third generation unit, used to generate and output emergency notification information for abnormal operation behaviors with severe severity.
[0017] Optionally, in a fifth implementation of the second aspect of the present invention, the comparison submodule includes: a comparison unit, used to use a pattern matching algorithm to compare the type of detection result with a pre-established threat feature database to obtain a comparison result; a first processing unit, used to process according to a preset second processing scheme if the comparison result is that a security threat exists, and automatically lock the user if the type is an abnormal login to a user account; a second processing unit, used to isolate the device if the type is that the device is infected by malware.
[0018] Optionally, in a sixth implementation of the second aspect of the present invention, the generation module includes: a classification unit, used to obtain the operation behavior data and detection results of all users within a specific time range, and classify the operation behavior data, and the classification types include: normal operation behavior data and abnormal operation behavior data; a fourth generation unit, used to generate an abnormal behavior description for the abnormal operation behavior data according to its detection results, and the abnormal behavior description includes the time when the abnormality occurred, the operation content involved, the abnormal system commands, and the basis for determining the abnormality; a fifth generation unit, used to generate security threat prompts and suggestions based on the abnormal behavior description to obtain a countermeasure description, and generate an analysis report based on the abnormal behavior description and the countermeasure description.
[0019] A third aspect of the present invention provides a terminal user activity monitoring device, comprising a memory and at least one processor, wherein the memory stores computer-readable instructions; the at least one processor calls the computer-readable instructions in the memory to execute the various steps of the terminal user activity monitoring method as described above.
[0020] A fourth aspect of the present invention provides a computer-readable storage medium having computer-readable instructions stored thereon, and the computer-readable instructions, when executed by a processor, implement the various steps of the terminal user activity monitoring method as described above.
[0021] Beneficial effects: The present invention provides a terminal user activity monitoring method, which first obtains historical operation behavior data of multiple users, uses a machine learning algorithm to analyze the historical operation behavior data to obtain a normal behavior pattern, and constructs a normal behavior baseline based on the normal behavior pattern, so as to obtain a normal behavior baseline from a large amount of data for subsequent comparison; then obtains the user's real-time operation behavior data, and uses an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtains the detection result, and processes the corresponding user according to the detection result, so as to effectively identify abnormal operation behaviors caused by different types and take corresponding measures respectively; finally, obtains the operation behavior data and the detection results of all users within a specific time range, and generates an analysis report based on the operation behavior data and the detection results, so that enterprises and administrators can optimize and adjust the system in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 A first flow chart of a method for monitoring terminal user activities provided by an embodiment of the present invention;
[0023] Figure 2 A second flow chart of the terminal user activity monitoring method provided by an embodiment of the present invention;
[0024] Figure 3 A third flow chart of the terminal user activity monitoring method provided by an embodiment of the present invention;
[0025] Figure 4 A fourth flow chart of the terminal user activity monitoring method provided by an embodiment of the present invention;
[0026] Figure 5 A fifth flow chart of the terminal user activity monitoring method provided by an embodiment of the present invention;
[0027] Figure 6 A sixth flow chart of the terminal user activity monitoring method provided by an embodiment of the present invention;
[0028] Figure 7 A seventh flow chart of the terminal user activity monitoring method provided by an embodiment of the present invention;
[0029] Figure 8 A schematic diagram of the structure of a terminal user activity monitoring device provided by an embodiment of the present invention;
[0030] Fig. 9 Another structural schematic diagram of a terminal user activity monitoring device provided by an embodiment of the present invention;
[0031] Fig.10 A schematic diagram of the structure of a terminal user activity monitoring device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0032] The present invention provides a terminal user activity monitoring method, device, equipment and storage medium. The present invention first obtains historical operation behavior data of multiple users, uses a machine learning algorithm to analyze the historical operation behavior data to obtain a normal behavior pattern, and constructs a normal behavior baseline based on the normal behavior pattern, so that the historical operation behavior data can be automatically sorted and analyzed and converted into a normal behavior baseline that is easy to compare and use; then, by obtaining the real-time operation behavior data of the user, using an anomaly detection algorithm, the real-time operation behavior data that does not match the normal behavior baseline is detected, and the detection result is obtained, which can effectively monitor user activities, identify potential threats, and improve the terminal security protection level, and then the corresponding user is processed according to the detection result; finally, by obtaining the operation behavior data and the detection results of all users within a specific time range, an analysis report is generated according to the operation behavior data and the detection results, for reference and suggestions by enterprises and administrators, so that enterprises can consciously improve prevention and control security risks in a targeted manner.
[0033] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" or "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0034] It should be noted that the following data collection about user devices is subject to prior permission from the user.
[0035] For ease of understanding, the specific process of the embodiment of the present invention is described below. Figure 1 , a first embodiment of the terminal user activity monitoring method in an embodiment of the present invention includes:
[0036] S101. Obtain historical operation behavior data of multiple users, analyze the historical operation behavior data using a machine learning algorithm to obtain a normal behavior pattern, and construct a normal behavior baseline based on the normal behavior pattern;
[0037] Specifically, in the acquisition of operation behavior data, you can choose appropriate monitoring agent software such as SolarWinds Server & Application Monitor, etc., and install and deploy it on terminal devices such as desktop computers, laptops, servers and other computing devices that can access the network and perform operations. For different operating systems, user operation behavior data can be captured through the corresponding underlying interface. In terms of collecting keyboard input, you can use the monitoring algorithm at the keyboard driver level to record the key values and key sequence of keys in real time; for mouse clicks, you can use the event capture algorithm based on the operating system graphical interface (GUI) to obtain the coordinate position of the mouse click, the number of clicks (such as single clicks, double clicks) and the corresponding window or application area data; for file access, you can use the file system monitoring algorithm such as the File System Watcher component under Windows or the inotify mechanism in Linux to track the opening, reading, writing, and deleting of files, and record the file name, path and corresponding timestamp of the operation; in network activity monitoring, you can use the relevant algorithm based on the libpcap library to capture the data packets transmitted on the network interface, and analyze the source IP, destination IP, port number, protocol type and transmitted data content of the data packets. The collected multi-dimensional data can be transmitted to the behavior analysis system in real time through the HTTPS protocol to ensure the encryption and integrity of data transmission. The behavior analysis system is generally built on a server cluster with powerful computing capabilities to facilitate the subsequent efficient processing of large amounts of data.
[0038] In this embodiment, by using a machine learning algorithm to analyze a huge amount of historical operation behavior data, the analysis results can be efficiently obtained, thereby obtaining relevant data on the user's normal behavior pattern, and further summarizing and aggregating these data to obtain a normal behavior baseline. The normal behavior baseline can be directly used for comparison with the real-time operation behavior data.
[0039] S102. Acquire the user's real-time operation behavior data, use an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtain the detection result, and process the corresponding user according to the detection result;
[0040] Specifically, the anomaly detection algorithm can be: an algorithm based on the 3σ principle of normal distribution or an isolation forest algorithm. Both can detect real-time operation behavior data that does not conform to the normal behavior baseline. When the real-time operation behavior data deviates greatly from the normal behavior baseline, it will be identified as abnormal operation data. Among them, the isolation forest algorithm identifies outliers by randomly splitting the data space. For the user's operation behavior data, each behavior event can be regarded as a data point, and the behavior characteristics can be regarded as the characteristics of the data point. The isolation forest algorithm identifies abnormal behavior events as those points that are easily isolated. In actual scenarios, there are many reasons for abnormal operations. Different reasons have different potential hazards. Different treatment measures need to be taken according to different types and hazards.
[0041] S103. Obtain the operation behavior data and the detection results of all users within a specific time range, and generate an analysis report based on the operation behavior data and the detection results.
[0042] Specifically, based on the massive user behavior data collected during the entire monitoring cycle and the results of anomaly detection, a user behavior analysis report can be generated using data analysis and visualization tools. The analysis report can effectively indicate the security threats faced by the enterprise and provide corresponding countermeasures.
[0043] See also Figure 2 , a second embodiment of the terminal user activity monitoring method in an embodiment of the present invention includes:
[0044] S201. Obtain historical operation behavior data of multiple users, clean and preprocess the historical operation behavior data to obtain preprocessed data;
[0045] Specifically, after receiving the collected historical operation behavior data, it is first necessary to clean and preprocess the historical operation behavior data to improve the quality of the data. This will help improve the accuracy of the normal behavior baseline obtained subsequently and reduce the subsequent misjudgment of abnormal operation behavior data.
[0046] Cleaning and preprocessing include operations such as removing duplicate data and filling missing values. Specifically, methods such as mean interpolation can be used to fill in missing values of numerical variables and mode filling can be used to handle missing values of categorical variables.
[0047] S202. Analyze the preprocessed data using K-Means clustering algorithm and association rule mining algorithm to obtain normal behavior patterns;
[0048] K-Means clustering algorithm and association rule mining algorithm can be used to mine the association between operation behaviors, for example, to analyze the daily operation mode of users based on the combination of files frequently accessed at the same time. When mining user operation behaviors, various operation behaviors of users (such as file access, application use, web browsing, etc.) can be used as features, and these features can be clustered using K-Means algorithm. Through the clustering results, we can find user groups with similar operation behaviors, and then analyze the common characteristics and behavior patterns of these groups. Association rule mining algorithms, such as Apriori algorithm or FP-Growth algorithm, can find interesting associations between item sets in the data set. Combining K-Means clustering algorithm and association rule mining algorithm, we can further analyze the daily operation mode of users. First, use K-Means algorithm to divide users into different groups, and then use association rule mining algorithm to find the internal behavior association of each group, so as to analyze the normal behavior pattern.
[0049] S203. Extract key features from the normal behavior pattern and construct a normal behavior baseline based on the key features.
[0050] As mentioned above, the K-Means clustering algorithm clusters data based on multiple features, and finally analyzes the normal behavior patterns in different time periods and different application scenarios. Based on the previously identified rules, feature engineering can be used to extract key features such as operation time distribution, operation frequency, and operation sequence to build a baseline model of normal user behavior.
[0051] See also Figure 3 , a third embodiment of the terminal user activity monitoring method in the embodiment of the present invention includes:
[0052] S301. Obtain the user's real-time operation behavior data, use an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, and obtain the detection result, which includes severity and type;
[0053] Specifically, the detection results are aimed at the severity and type of abnormal operation behavior. The severity can include minor and serious. The type can be diverse, such as abnormal login of user accounts, equipment infected with malware, etc. Different measures should be taken for different severity and types.
[0054] S302. According to the preset first processing scheme, automatic response measures are taken according to the severity of the detection results;
[0055] Specifically, in setting the first processing scheme, for abnormal operation behaviors with minor severity, a milder processing method, such as a general warning, can be used; and for abnormal operation behaviors with serious severity, an emergency warning can be used.
[0056] S303. Compare the type of the detection result with a pre-established threat feature database to obtain a comparison result, and process the user according to the comparison result and a preset second processing solution.
[0057] Specifically, when setting the second processing scheme, it is also necessary to set effective countermeasures for different types of abnormal operation behaviors in detail to reduce security risks. In this embodiment, the measures taken by the first processing scheme are mainly to remind the administrator, while the second processing scheme is a comprehensive protection measure taken by the system for users.
[0058] See also Figure 4 , a fourth embodiment of the terminal user activity monitoring method in the embodiment of the present invention includes:
[0059] S401. Using the 3σ principle based on normal distribution, calculate the mean and standard deviation of each key feature in normal behavior according to the normal behavior baseline;
[0060] S402. Obtain the user's real-time operation behavior data, compare the real-time operation behavior data with the mean and standard deviation of each key feature, obtain comparison data, and regard the data beyond the range of the mean ± 3 times the standard deviation as abnormal data that does not conform to the normal behavior baseline;
[0061] Specifically, as the historical operation behavior data continues to increase, the anomaly detection algorithm can be continuously iterated and optimized, so that the accuracy of the normal behavior baseline will become higher and higher, and the mean and standard deviation of each key feature calculated based on the 3σ principle of the normal distribution will be more in line with the actual situation.
[0062] S403. Obtain comparison data of the abnormal data, and generate a detection result according to the comparison data, wherein the detection result includes severity and type.
[0063] Specifically, the comparison data of abnormal data may include not only the severity and type of the abnormal operation behavior, but also key information such as the specific behavior and occurrence time of the abnormal operation behavior.
[0064] See also Figure 5 The fifth embodiment of the terminal user activity monitoring method in the embodiment of the present invention includes:
[0065] S501. Establish a first processing plan, and set corresponding automatic response measures according to the severity of the detection results;
[0066] By pre-establishing the first processing plan, the system can have a set program to perform corresponding operations when faced with various situations;
[0067] S502. Obtain the detection results, and generate and output email notification information for abnormal operation behaviors with a minor severity;
[0068] Specifically, the recipients of the email are the system administrators. Since minor abnormal operation behaviors usually do not cause security risks and may be a misjudgment of the system, minor abnormal operation behaviors only need to be notified by email or other means, and there is no need to check and handle them immediately.
[0069] S503. For abnormal operation behaviors with serious severity, emergency notification information is generated and output. Since serious abnormal operation behaviors have great security risks and may have caused damage to the operation of the system, emergency notification methods such as SMS notifications or sound and light alarms are needed to notify the administrator to intervene in time to repair the loopholes and ensure the normal operation of the system to reduce losses.
[0070] See also Figure 6 The sixth embodiment of the terminal user activity monitoring method in the embodiment of the present invention includes:
[0071] S601. Using a pattern matching algorithm, the type of detection result is compared with a pre-established threat feature database to obtain a comparison result;
[0072] S602. If the comparison result shows that there is a security threat, the second processing scheme is used for processing. If the user account is abnormally logged in, the user is automatically locked;
[0073] S603. If the device is infected by malware, isolate the device.
[0074] In this embodiment, the types of detection results corresponding to abnormal operation behavior data do not necessarily have major security risks, or do not necessarily cause immediate damage, and some types can be ignored. By using a pre-established threat feature database, the types that require immediate measures are included, and then compared according to the detection results, and targeted treatment is carried out on users with abnormal behavior operations that pose a threat, which can effectively avoid incorrect handling and reduce the impact on users. Among them, for the type of abnormal login to the user account, the user is automatically locked, which can effectively protect the rights and interests of the user. For the type of device infected by malware, timely isolation of the device can prevent the system from being continuously attacked.
[0075] See also Figure 7 The seventh embodiment of the terminal user activity monitoring method in the embodiment of the present invention includes:
[0076] S701. Obtaining the operation behavior data and detection results of all users within a specific time range, and classifying the operation behavior data, the classification types include: normal operation behavior data and abnormal operation behavior data;
[0077] S702. For abnormal operation behavior data, generate an abnormal behavior description according to the detection result, the abnormal behavior description includes the time when the abnormality occurred, the operation content involved, the abnormal system command and the basis for determining the abnormality;
[0078] S703. Generate security threat prompts and suggestions based on the abnormal behavior description to obtain countermeasure descriptions, and generate an analysis report based on the abnormal behavior description and the countermeasure description.
[0079] In the content of the analysis report, the part about the user's normal operating habits can present detailed operation frequency distribution charts for different time periods. For example, a bar chart can be used to show the number of times different software is used in each hour of the day, and a heat map and color depth can be used to indicate the frequency of access to different files. For abnormal behaviors detected, the time when the abnormality occurred and the operations involved will be listed, such as the access to the illegal network address, the execution of abnormal system commands, and the basis for determining the abnormality, the algorithm based on which the detection is based, and how it deviates from the normal behavior baseline.
[0080] In terms of potential security threats, we will analyze the security consequences that may be caused by abnormal behavior, such as data leakage risk, system paralysis risk, etc., and conduct an assessment based on the company's business architecture and security situation, and attach the corresponding threat intelligence sources.
[0081] The recommended response measures section will provide specific recommended actions based on the company's established security handling processes and strategies, such as resetting the password of an abnormal account, strengthening access control on specific network segments, etc. It will also provide subsequent suggestions for continuous monitoring and prevention of similar threats, such as regularly updating the threat signature library and strengthening employee security awareness training.
[0082] The above describes the terminal user activity monitoring method in the embodiment of the present invention. The following describes the terminal user activity monitoring device in the embodiment of the present invention. Figure 8 In one embodiment of the present invention, a terminal user activity monitoring device includes:
[0083] An analysis module 10 is used to obtain historical operation behavior data of multiple users, analyze the historical operation behavior data using a machine learning algorithm to obtain a normal behavior pattern, and construct a normal behavior baseline based on the normal behavior pattern;
[0084] The detection module 20 is used to obtain the real-time operation behavior data of the user, use an abnormality detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtain the detection result, and process the corresponding user according to the detection result;
[0085] The generating module 30 is used to obtain the operation behavior data and the detection results of all users within a specific time range, and generate an analysis report according to the operation behavior data and the detection results.
[0086] See also Fig. 9 In one embodiment of the present invention, a terminal user activity monitoring device includes:
[0087] An analysis module 10 is used to obtain historical operation behavior data of multiple users, analyze the historical operation behavior data using a machine learning algorithm to obtain a normal behavior pattern, and construct a normal behavior baseline based on the normal behavior pattern;
[0088] The detection module 20 is used to obtain the real-time operation behavior data of the user, use an abnormality detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtain the detection result, and process the corresponding user according to the detection result;
[0089] A generating module 30, for obtaining the operation behavior data and the detection results of all users within a specific time range, and generating an analysis report based on the operation behavior data and the detection results;
[0090] In this embodiment, the analysis module 10 includes:
[0091] A preprocessing unit 11 is used to obtain historical operation behavior data of multiple users, and clean and preprocess the historical operation behavior data to obtain preprocessed data;
[0092] An analysis unit 12, used to analyze the pre-processed data using a K-Means clustering algorithm and an association rule mining algorithm to obtain a normal behavior pattern;
[0093] A construction unit 13 is used to extract key features from the normal behavior pattern and construct a normal behavior baseline according to the key features;
[0094] In this embodiment, the detection module 20 includes:
[0095] The detection submodule 21 is used to obtain the real-time operation behavior data of the user, use an abnormality detection algorithm to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, and obtain a detection result, which includes severity and type;
[0096] The processing submodule 22 is used to take automatic response measures according to the severity of the detection result according to the preset first processing scheme;
[0097] A comparison submodule 23 is used to compare the type of the detection result with a pre-established threat feature database to obtain a comparison result, and process the user according to the comparison result and a preset second processing scheme;
[0098] In this embodiment, the detection submodule 21 includes:
[0099] A calculation unit 211 is used to calculate the mean and standard deviation of each key feature in the normal behavior according to the normal behavior baseline by using the 3σ principle based on normal distribution;
[0100] The comparison unit 212 is used to obtain the real-time operation behavior data of the user, compare the real-time operation behavior data with the mean and standard deviation of each key feature, obtain comparison data, and regard the data exceeding the range of the mean ± 3 times the standard deviation as abnormal data that does not conform to the normal behavior baseline;
[0101] A first generating unit 213 is used to obtain comparison data of abnormal data and generate a detection result according to the comparison data, wherein the detection result includes severity and type;
[0102] In this embodiment, the processing submodule 22 includes:
[0103] An establishing unit 221 is used to establish a first processing scheme and set corresponding automatic response measures according to the severity of the detection result;
[0104] The second generating unit 222 is used to obtain the detection result, and for the abnormal operation behavior with a minor severity, generate and output the email notification information;
[0105] The third generating unit 223 is used to generate and output emergency notification information for abnormal operation behaviors with serious severity;
[0106] In this embodiment, the comparison submodule 23 includes:
[0107] The comparison unit 231 is used to compare the type of the detection result with a pre-established threat feature database using a pattern matching algorithm to obtain a comparison result;
[0108] The first processing unit 232 is used to process according to a preset second processing scheme if the comparison result shows that there is a security threat, and automatically lock the user if the type is that the user account is logged in abnormally;
[0109] The second processing unit 233 is configured to isolate the device if the device is infected by malware;
[0110] In this embodiment, the generating module 30 includes:
[0111] A classification unit 31 is used to obtain the operation behavior data of all users within a specific time range and the detection results thereof, and classify the operation behavior data. The classification types include: normal operation behavior data and abnormal operation behavior data;
[0112] The fourth generating unit 32 is used to generate an abnormal behavior description for the abnormal operation behavior data according to the detection result thereof, wherein the abnormal behavior description includes the time when the abnormality occurs, the operation content involved, the abnormal system command and the basis for determining the abnormality;
[0113] The fifth generating unit 33 is used to generate security threat prompts and suggestions according to the abnormal behavior description to obtain a countermeasure description, and generate an analysis report according to the abnormal behavior description and the countermeasure description.
[0114] The terminal user activity monitoring device of the present invention firstly identifies normal behavior patterns based on historical operation behavior data by adopting a machine learning algorithm, and then further constructs a normal behavior baseline for a specific user. The normal behavior baseline may include the user's operation habits, file access frequency, network activity patterns, etc., and then compares the real-time operation behavior data with the normal behavior baseline, so as to effectively determine whether there are any abnormalities in the real-time operation behavior data of the current user, and further restrict the real-time operation behaviors with abnormalities. Through operation behavior judgment, it is possible to effectively respond to different types of abnormal situations, and perform effective processing to improve the terminal security protection level.
[0115] The above is a detailed description of the terminal user activity monitoring device in the embodiment of the present invention from the perspective of modular functional entities. The following is a detailed description of the terminal user activity monitoring device in the embodiment of the present invention from the perspective of hardware processing.
[0116] Fig.10A schematic diagram of the structure of a terminal user activity monitoring device provided in an embodiment of the present invention, the terminal user activity monitoring device 900 may have relatively large differences due to different configurations or performances, and may include one or more processors (central processing units, CPU) 910 (for example, one or more processors) and a memory 920, and one or more storage media 930 (for example, one or more mass storage devices) storing application programs 933 or data 932. Among them, the memory 920 and the storage medium 930 can be temporary storage or permanent storage. The program stored in the storage medium 930 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations in the terminal user activity monitoring device 900. Furthermore, the processor 910 can be configured to communicate with the storage medium 930, and execute a series of instruction operations in the storage medium 930 on the terminal user activity monitoring device 900 to implement the steps of the terminal user activity monitoring method provided in the above-mentioned method embodiments.
[0117] The end-user activity monitoring device 900 may also include one or more power supplies 940, one or more wired or wireless network interfaces 950, one or more input and output interfaces 960, and / or one or more operating systems 931, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc. It will be appreciated by those skilled in the art that Fig.10 The illustrated structure of the end-user activity monitoring device does not constitute a limitation on the end-user activity monitoring device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0118] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions are executed on a computer, the computer executes the steps of the terminal user activity monitoring method.
[0119] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the equipment or device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0120] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program codes.
[0121] It is understandable that those skilled in the art can make equivalent substitutions or changes based on the technical solution and inventive concept of the present invention, and all these changes or substitutions should fall within the protection scope of the claims attached to the present invention.
Claims
1. A method for monitoring terminal user activities, characterized in that: The steps include: Obtain historical operation behavior data of multiple users, use machine learning algorithms to analyze the historical operation behavior data to obtain normal behavior patterns, and build a normal behavior baseline based on the normal behavior patterns; Acquire the user's real-time operation behavior data, use an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtain the detection result, and process the corresponding user according to the detection result; Obtain the operation behavior data and detection results of all users within a specific time range, and generate an analysis report based on the operation behavior data and detection results.
2. The method for monitoring terminal user activities according to claim 1, characterized in that: The obtaining of historical operation behavior data of multiple users, analyzing the historical operation behavior data using a machine learning algorithm to obtain a normal behavior pattern, and constructing a normal behavior baseline according to the normal behavior pattern specifically includes: Acquire historical operation behavior data of multiple users, and clean and preprocess the historical operation behavior data to obtain preprocessed data; K-Means clustering algorithm and association rule mining algorithm are used to analyze the preprocessed data to obtain normal behavior patterns; Extract key features from normal behavior patterns and build a normal behavior baseline based on the key features.
3. The method for monitoring terminal user activities according to claim 1, characterized in that: The acquiring of the user's real-time operation behavior data, using an anomaly detection algorithm to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, obtaining a detection result, and processing the corresponding user according to the detection result specifically includes: Acquire the user's real-time operation behavior data, use an anomaly detection algorithm to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, and obtain a detection result, wherein the detection result includes severity and type; According to the preset first processing plan, automatic response measures are taken according to the severity of the detection results; The type of the detection result is compared with a pre-established threat feature database to obtain a comparison result, and the user is processed according to the comparison result and a preset second processing solution.
4. The method for monitoring terminal user activities according to claim 3, characterized in that: The real-time operation behavior data of the user is obtained, and an abnormal detection algorithm is used to detect the real-time operation behavior data that is inconsistent with the normal behavior baseline, and a detection result is obtained. The detection result includes severity and type, specifically including: The 3σ principle based on normal distribution is used to calculate the mean and standard deviation of each key feature in normal behavior according to the normal behavior baseline; Acquire the user's real-time operation behavior data, compare the real-time operation behavior data with the mean and standard deviation of each key feature, obtain comparison data, and regard data beyond the range of the mean ± 3 times the standard deviation as abnormal data that does not conform to the normal behavior baseline; Acquire comparison data of the abnormal data, and generate a detection result according to the comparison data, wherein the detection result includes severity and type.
5. The method for monitoring terminal user activities according to claim 3, characterized in that: The automatic response measures are taken according to the preset first processing scheme according to the severity of the detection result, specifically including: Establish a first processing plan and set corresponding automatic response measures according to the severity of the detection results; Obtain the detection results, and generate and output email notification information for abnormal operation behaviors with minor severity; For abnormal operation behaviors with serious severity, emergency notification information is generated and output.
6. The method for monitoring terminal user activities according to claim 3, characterized in that: The type of the detection result is compared with a pre-established threat feature database to obtain a comparison result, and the user is processed according to the comparison result and a preset second processing scheme, specifically including: Using a pattern matching algorithm, the type of detection result is compared with a pre-established threat feature database to obtain a comparison result; If the comparison result shows that there is a security threat, the second preset processing scheme is used for processing. If the type is that the user account is logged in abnormally, the user is automatically locked; If the device is infected by malware, the device is quarantined.
7. The method for monitoring terminal user activities according to claim 1, characterized in that: The obtaining of the operation behavior data and the detection results of all users within a specific time range and generating an analysis report based on the operation behavior data and the detection results specifically includes: Obtain the operation behavior data and detection results of all users within a specific time range, and classify the operation behavior data. The classification types include: normal operation behavior data and abnormal operation behavior data; For abnormal operation behavior data, generate an abnormal behavior description based on its detection results, the abnormal behavior description includes the time when the abnormality occurred, the operation content involved, the abnormal system command and the basis for determining the abnormality; Generate security threat prompts and suggestions based on the abnormal behavior description to obtain countermeasure instructions, and generate an analysis report based on the abnormal behavior description and the countermeasure instructions.
8. A terminal user activity monitoring device, characterized in that: include: An analysis module is used to obtain historical operation behavior data of multiple users, analyze the historical operation behavior data using a machine learning algorithm to obtain a normal behavior pattern, and build a normal behavior baseline based on the normal behavior pattern; A detection module is used to obtain the real-time operation behavior data of the user, use an anomaly detection algorithm to detect the real-time operation behavior data that does not match the normal behavior baseline, obtain the detection result, and process the corresponding user according to the detection result; The generation module is used to obtain the operation behavior data and the detection results of all users within a specific time range, and generate an analysis report based on the operation behavior data and the detection results.
9. A terminal user activity monitoring device, characterized in that: comprising a memory and at least one processor, wherein the memory has computer-readable instructions stored therein; The at least one processor calls the computer-readable instructions in the memory to execute the steps of the terminal user activity monitoring method according to any one of claims 1-7.
10. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the steps of the terminal user activity monitoring method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Intelligent data recovery management method and system for storage system
CN120523778A
Intelligent data recycling management method and system for storage system
CN120523778B