Abnormal monitoring method and device, electronic equipment, storage medium and chip
By acquiring and verifying user behavior and terminal data, the problem of malicious modifications in the prior art is solved, and more efficient security protection and system reliability are achieved.
Patent Information
- Application Number
- CN202510105695.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-06
AI Technical Summary
Existing terminal security prevention and control methods can only monitor key data without changes, and cannot identify whether the changed key data has been maliciously modified.
By obtaining the current user behavior, determining whether there is an exception based on the baseline user behavior, and verifying the full amount of sensitive data to determine whether the key data and code are abnormal.
It improves the efficiency and effectiveness of security protection, can actively discover and respond to security threats, adapt to different security environments, and enhances the reliability of the system.
Smart Images

Figure CN119939575A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of terminal technology, and in particular to an abnormality monitoring method, device, electronic device, storage medium and chip. Background Art
[0002] With the popularization of smart terminal devices, users have put forward higher requirements for terminal security. At present, the common terminal security prevention and control method is to ensure the integrity of key data by performing hash calculation on key data at regular intervals and comparing the calculation result of hash calculation with the hash value obtained by the first calculation; this prevention and control method can only monitor key data that has not changed, and cannot identify whether the key data that has changed has been maliciously modified. Summary of the invention
[0003] The present disclosure provides an abnormality monitoring method and device, an electronic device, a storage medium and a chip to solve the problems in the related technology, drive the measurement of key data with user behavior, can adapt to different security environments, and improve the efficiency of security protection.
[0004] A first aspect of the present disclosure provides an abnormality monitoring method, the method comprising:
[0005] Get current user behavior;
[0006] Determining whether the current user behavior is abnormal based on a baseline user behavior, wherein the baseline user behavior is generated and updated by a normal user behavior;
[0007] When it is determined that the current user behavior is abnormal, the full amount of sensitive data is verified to determine whether the key data and code are abnormal, and the full amount of sensitive data is pre-marked key data and code.
[0008] In some embodiments of the present disclosure, the method further includes:
[0009] Obtain user behavior data generated when the user operates the terminal;
[0010] generating the baseline user behavior according to the user behavior data;
[0011] The key data and the code are marked to obtain the full amount of sensitive data.
[0012] In some embodiments of the present disclosure, obtaining user behavior data generated when a user operates a terminal includes:
[0013] The user behavior data sent by the first processor is received, where the user behavior data is acquired by the first processor through a preset sensor.
[0014] In some embodiments of the present disclosure, generating the baseline user behavior according to the user behavior data includes:
[0015] Establishing a corresponding relationship between the baseline user behavior and the second processor;
[0016] Storing the baseline user behavior in a storage area;
[0017] Performing hash calculation on the key data and code to obtain a reference hash value;
[0018] The reference hash value is stored in the storage area.
[0019] In some embodiments of the present disclosure, verifying the full amount of sensitive data includes:
[0020] Acquire the full amount of sensitive data from the storage area;
[0021] Performing hash calculation on the key data and code to obtain a verification hash value;
[0022] An integrity check is performed on the verification hash value based on the reference hash value.
[0023] In some embodiments of the present disclosure, verifying the full amount of sensitive data to determine whether key data and code are abnormal includes:
[0024] If the reference hash value is inconsistent with the verification hash value, the current user behavior is determined to be abnormal user behavior.
[0025] In some embodiments of the present disclosure, performing hash calculation on the key data and code to obtain a verification hash value includes:
[0026] Controlling an encryption and decryption engine to perform hash calculation on the key data and the code to obtain the verification hash value, wherein the encryption and decryption engine is configured in the second processor;
[0027] In some embodiments of the present disclosure, after verifying the full amount of sensitive data to determine whether the key data and code are abnormal, the method further includes:
[0028] Determining the service type of the abnormal user behavior, and determining the abnormality level according to the service type;
[0029] The abnormal level of the abnormal user behavior is sent to the first processor, so that the first processor outputs a corresponding early warning strategy according to the abnormal level.
[0030] A second aspect of the present disclosure provides an abnormality monitoring device, the device comprising:
[0031] A first acquisition unit, used to acquire current user behavior;
[0032] A first determining unit, configured to determine whether the current user behavior is abnormal according to a baseline user behavior, wherein the baseline user behavior is generated and updated by a normal user behavior;
[0033] A verification unit is used to verify the full amount of sensitive data to determine whether the key data and code are abnormal when it is determined that the current user behavior is abnormal, and the full amount of sensitive data includes pre-marked key data and codes.
[0034] In some embodiments of the present disclosure, the device further comprises:
[0035] A second acquisition unit, used to acquire user behavior data generated when the user operates the terminal;
[0036] A generating unit, configured to generate the baseline user behavior according to the user behavior data;
[0037] A marking unit is used to mark key data and codes in the baseline user behavior.
[0038] In some embodiments of the present disclosure, the second acquisition unit is further used to receive user behavior data sent by the first processor, and the user behavior data is acquired by the first processor through a preset sensor.
[0039] In some embodiments of the present disclosure, the generating unit is further configured to:
[0040] Establishing a corresponding relationship between the baseline user behavior and the second processor;
[0041] Storing the baseline user behavior in a storage area;
[0042] Performing hash calculation on the key data and code to obtain a reference hash value;
[0043] The reference hash value is stored in the storage area.
[0044] In some embodiments of the present disclosure, the verification unit includes:
[0045] An acquisition module, used to acquire the full amount of sensitive data from the storage area;
[0046] A calculation module, used to perform hash calculation on the key data and code to obtain a verification hash value;
[0047] A verification module is used to perform integrity verification on the verification hash value based on the reference hash value.
[0048] In some embodiments of the present disclosure, the second determining unit is further configured to determine that the current user behavior is abnormal user behavior if the reference hash value is inconsistent with the verification hash value.
[0049] In some embodiments of the present disclosure, the computing module is further used to control the encryption and decryption engine to perform hash calculation on the key data and the code to obtain the verification hash value, wherein the encryption and decryption engine is configured in the second processor;
[0050] In some embodiments of the present disclosure, the device further comprises:
[0051] A second determination unit is used to determine the business type of the abnormal user behavior after the second determination unit verifies the full amount of sensitive data to determine whether the key data and the code are abnormal, and determine the abnormality level according to the business type;
[0052] A sending unit is used to send the abnormal level of the abnormal user behavior to the first processor, so that the first processor outputs a corresponding early warning strategy according to the abnormal level.
[0053] The third aspect embodiment of the present disclosure proposes an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described in the first aspect embodiment of the present disclosure.
[0054] The fourth aspect embodiment of the present disclosure proposes a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to execute the method described in the first aspect embodiment of the present disclosure.
[0055] The fifth aspect embodiment of the present disclosure proposes a chip, which includes one or more interfaces and one or more processors; the interface is used to receive signals from a memory of an electronic device and send signals to the processor, the signals include computer instructions stored in the memory, and when the processor executes the computer instructions, the electronic device executes the method described in the first aspect embodiment of the present disclosure.
[0056] In summary, according to the abnormality monitoring method proposed in the present disclosure, the method includes obtaining the current user behavior, determining whether the current user behavior is abnormal based on the baseline user behavior, wherein the baseline user behavior is generated and updated by the normal behavior of the user, and in the case of determining that the current user behavior is abnormal, verifying the full amount of sensitive data to determine whether the key data and code are abnormal, and the full amount of sensitive data includes pre-marked key data and code. By continuously generating and updating the baseline user behavior, adapting to different security environments, and improving the reliability of the system, in addition, after determining that the current user behavior is abnormal, using abnormal user behavior to drive active measurement technology (based on verification of the full amount of sensitive data) can actively discover and respond to security threats, and improve the efficiency and effectiveness of security protection.
[0057] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the description are used to explain the principles of the present disclosure, and do not constitute improper limitations on the present disclosure.
[0059] Figure 1 A schematic diagram of an abnormality monitoring system provided by an embodiment of the present disclosure;
[0060] Figure 2 A flowchart of an abnormality monitoring method provided by an embodiment of the present disclosure;
[0061] Figure 3 A flowchart of an abnormality monitoring method provided by an embodiment of the present disclosure;
[0062] Figure 4 A flowchart of an abnormality monitoring method provided by an embodiment of the present disclosure;
[0063] Figure 5 A flowchart of an abnormality monitoring method provided by an embodiment of the present disclosure;
[0064] Figure 6 A flowchart of an abnormality monitoring method provided by an embodiment of the present disclosure;
[0065] Figure 7 A schematic diagram of an abnormality monitoring method provided by an embodiment of the present disclosure;
[0066] Figure 8 A schematic diagram of the structure of an abnormality monitoring device provided in an embodiment of the present disclosure;
[0067] Fig. 9A schematic diagram of the structure of an abnormality monitoring device provided in an embodiment of the present disclosure;
[0068] Fig.10 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure;
[0069] Fig.11 A schematic diagram of the structure of a chip provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0070] Embodiments of the present disclosure are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present disclosure, and should not be construed as limiting the present disclosure.
[0071] The collection, storage, use, processing, transmission, provision and application of user personal information involved in this application are in compliance with relevant laws and regulations and do not violate public order and good morals.
[0072] It should be noted that personal information from users should be collected for legitimate and reasonable purposes and should not be shared or sold outside of these legitimate uses. In addition, such collection / sharing should be carried out after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign the agreement / authorization including authorization of relevant user information before the user uses the function. In addition, any necessary steps should be taken to protect and safeguard access to such personal information data and ensure that others who have access to personal information data comply with its privacy policy and procedures.
[0073] With the popularization of smart terminal devices, users have put forward higher requirements for terminal security. At present, the common terminal security prevention and control method is to ensure the integrity of key data by performing hash calculation on key data at regular intervals and comparing the calculation result of hash calculation with the hash value obtained by the first calculation; this prevention and control method can only monitor key data that has not changed, and cannot identify whether the key data that has changed has been maliciously modified.
[0074] Therefore, in order to solve the problems existing in the related technology, the present disclosure proposes an abnormality monitoring method, which obtains the current user behavior, and determines whether the current user behavior is abnormal based on the baseline user behavior, wherein the baseline user behavior is generated and updated by the user's normal behavior. When it is determined that the current user behavior is abnormal, the full amount of sensitive data is verified to determine whether the key data and code are abnormal, and the full amount of sensitive data includes pre-marked key data and code.
[0075] This solution adapts to different security environments and improves system reliability by continuously generating and updating baseline user behaviors. In addition, after determining that the current user behavior is abnormal, the abnormal user behavior-driven active measurement technology (based on verification of the full amount of sensitive data) can proactively discover and respond to security threats, thereby improving the efficiency and effectiveness of security protection.
[0076] The embodiments of the present disclosure are not exhaustive, but are only illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined, for example, some or all of the steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0077] In each embodiment of the present disclosure, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form a new embodiment based on their internal logical relationships.
[0078] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0079] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular form, such as "a", "an", "the", "above", "said", "aforementioned", "this", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun after the article may be understood as a singular expression or a plural expression.
[0080] In some embodiments, terms such as "in response to ...", "in response to determining ...", "in the case of ...", "at the time of ...", "when ...", "if ...", "if ...", etc. can be used interchangeably.
[0081] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "no more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0082] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only for distinguishing different description objects and do not constitute any restrictions on the position, order, priority, quantity or content of the description objects. For the statement of the description objects, please refer to the description in the context of the claims or embodiments, and no unnecessary restrictions should be constituted due to the use of prefixes.
[0083] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0084] In the embodiments of the present disclosure, terms such as "import", "input", and "read in" can be used interchangeably.
[0085] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0086] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal" "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device (mobile device), wireless device (wireless device), wireless communication device (wireless communication device), remote device (remote device), mobile subscriber station (mobile subscriber station), access terminal (access terminal), mobile terminal (mobile terminal), wireless terminal (wireless terminal), remote terminal (remote terminal), handset (handset), user agent (user agent), mobile client (mobile client), client (client) and the like can be used interchangeably.
[0087] The method described in the embodiments of the present disclosure is applied to an abnormal monitoring system, such as Figure 1 As shown, Figure 1 A schematic diagram of an abnormality monitoring system provided for an embodiment of the present disclosure includes: a sensor module 11, a first processor 12, a second processor 13, and a storage area 14, wherein the sensor module 11 is used to collect user behavior and transmit the collected user behavior to the first processor 12 through the sensorhub processor, the first processor 12 enables a safe mode to send user behavior data to the second processor 13, registers a baseline user behavior in the second processor 13, and stores the baseline user behavior in the storage area 14.
[0088] The second processor 13 also includes an encryption and decryption engine 131. After the second processor 13 detects that the user behavior is abnormal based on the baseline user behavior, the encryption and decryption engine 131 is called. The encryption and decryption engine 131 uses a hash algorithm to perform integrity verification on the sensitive data and code stored in the storage area 14, and reports the abnormal result and abnormal level to the second processor 13.
[0089] The second processor 13 reports the abnormal result and abnormal level of the abnormal user behavior to the first processor 12, and the first processor 12 takes different security response measures.
[0090] Figure 2 This is a flow chart of an abnormality monitoring method provided by an embodiment of the present disclosure. The method can be applicable to application scenarios such as smart terminals, for example, executed by a terminal with an integrated abnormality monitoring function or a processor in the terminal, or by an intelligent device in the field of the Internet of Things suitable for behavior monitoring, and the present disclosure is not limited thereto. Figure 2 As shown, the abnormality monitoring method includes steps 201-203.
[0091] Step 201, obtaining current user behavior.
[0092] The current user behavior refers to the user's operations on various functions of the terminal, such as screen unlocking mode (such as password unlocking, fingerprint unlocking, iris unlocking, face unlocking, etc.), input habits (such as keyboard layout, touch pressure, sliding speed, etc.), file operations (time and frequency of creation, modification, and deletion), and switching modes between different applications, etc.
[0093] In another implementation of the disclosed embodiment, in addition to obtaining the current user behavior, some system status is also obtained. By real-time monitoring of the current user behavior and system status, abnormal user behavior can be discovered in a timely manner, and corresponding security measures can be taken to effectively prevent the occurrence of malware and attack behaviors, thereby providing terminal security.
[0094] Corresponds to Figure 1 , the current user behavior can be collected through the sensor module 11, and the current user behavior can be transmitted to the first processor 12 through the Sensorhub. The first processor 12 enables the safety mode to send the current user behavior to the second processor 13.
[0095] Step 202: determining whether the current user behavior is abnormal based on the baseline user behavior, wherein the baseline user behavior is generated and updated based on the normal behavior of the user.
[0096] The current user behavior is compared with the baseline user behavior to determine whether there is a deviation between the current user behavior and the baseline user behavior. If the deviation between the two is greater than or equal to the preset deviation threshold, it is determined that the current user behavior is abnormal. If the deviation between the two is less than the preset deviation threshold, it is determined that the current user behavior is not abnormal.
[0097] It should be noted that the baseline user behavior is not fixed, but is adapted to different security environments and improves the reliability of the system through continuous learning and updating of the baseline user behavior. As an implementable method of the embodiment of the present disclosure, the baseline user behavior can also exist in the form of a normal behavior model.
[0098] In some embodiments, when calculating whether there is a deviation between the current user behavior and the baseline user behavior, a statistical analysis method can be used for calculation, including but not limited to calculating statistical indicators such as the standard deviation and variance of the two. Specifically, the embodiments of the present disclosure do not limit the specific method for calculating the deviation between the current user behavior and the baseline user behavior.
[0099] This step corresponds to Figure 1 The second processor 13 in the embodiment determines whether the current user behavior is abnormal according to the baseline user behavior.
[0100] Step 203, when it is determined that the current user behavior is abnormal, the full amount of sensitive data is verified to determine whether the key data and code are abnormal, and the full amount of sensitive data includes pre-marked key data and codes.
[0101] Compared with traditional passive protection technology, after the embodiment of the present disclosure detects abnormal user behavior, the behavior-driven active measurement can actively discover and respond to security threats, thereby improving the efficiency and effectiveness of security protection.
[0102] During the verification process, all sensitive data needs to be verified, rather than just some key data or codes. This way, missed detections and missed reports can be prevented.
[0103] When the user behavior is registered to the second processor 13, the key data and code will be marked. The full amount of sensitive data described in the embodiment of the present disclosure includes pre-marked key data and code. In actual applications, the marking of key data and code can be completed when the system is initialized.
[0104] The specific marking of key data and codes can be based on business needs and the security control strategy of the system. The embodiments of the present disclosure do not specifically limit the marked key data and codes.
[0105] Corresponds to Figure 1 After the second processor 13 detects that the user behavior is abnormal based on the baseline user behavior, the encryption and decryption engine 131 is called, and the encryption and decryption engine 131 uses a hash algorithm to perform integrity verification on the sensitive data and code stored in the storage area 14.
[0106] When performing verification, you can use but are not limited to integrity checks on the full amount of sensitive data, such as hash calculations, etc. If the integrity check of the full amount of sensitive data passes, it means that the key data and code have not been tampered with, that is, the current user behavior is normal user behavior. If the integrity check of the full amount of sensitive data fails, it means that the key data and code have been tampered with, that is, the current user behavior is abnormal user behavior.
[0107] In summary, according to the abnormality monitoring method proposed in the present disclosure, the method includes obtaining the current user behavior, determining whether the current user behavior is abnormal based on the baseline user behavior, wherein the baseline user behavior is generated and updated by the normal behavior of the user, and in the case of determining that the current user behavior is abnormal, verifying the full amount of sensitive data to determine whether the key data and code are abnormal, and the full amount of sensitive data includes pre-marked key data and code. By continuously generating and updating the baseline user behavior, adapting to different security environments, and improving the reliability of the system, in addition, after determining that the current user behavior is abnormal, using abnormal user behavior to drive active measurement technology (based on verification of the full amount of sensitive data) can actively discover and respond to security threats, and improve the efficiency and effectiveness of security protection.
[0108] Figure 3 The following is a flowchart of an abnormal monitoring method proposed in the present disclosure. The following steps may be included:
[0109] Step 301: Acquire user behavior data generated when a user operates a terminal.
[0110] After the terminal is started, it continuously monitors all user operations on the terminal and the operating status of the system, such as application usage, network connection status, screen unlock mode, input habits, file operations, and switching modes between different applications, etc. All user behavior data.
[0111] In some embodiments, when obtaining user behavior data, the following methods may be used but are not limited to: Figure 1 The user behavior data is sent by the first processor 12), and the user behavior data is obtained by the first processor through a preset sensor. The first processor can also be called an application processor.
[0112] The preset sensors are used to collect user behavior data. The embodiments of the present disclosure do not limit the types and quantities of the preset sensors, which can be set according to needs.
[0113] Step 302: Generate the baseline user behavior based on the user behavior data.
[0114] The baseline user behavior is used as a reference for identifying abnormal user behavior, and the baseline user behavior can be generated by any method in the relevant technology.
[0115] Step 303: mark the key data and the code to obtain the full amount of sensitive data.
[0116] Key data and codes can be marked according to different business scenarios. For example, in a payment scenario, a payment password can be marked as key data, and in an authorization scenario, authorization verification can be marked as key data, etc. The disclosed embodiments do not limit the type and quantity of key data.
[0117] Figure 4 The following further shows a flow chart of an abnormal monitoring method proposed in the present disclosure. Figure 4 The embodiment shown further explains step 302. Figure 4 The following steps may be included:
[0118] Step 401: Establish a corresponding relationship between the baseline user behavior and the second processor.
[0119] The second processor, also called the security processor, first performs anomaly detection based on the baseline user behavior registered to the second processor according to the received current user behavior. After the baseline user behavior is registered to the second processor, a binding relationship between the baseline user behavior and the second processor is established.
[0120] Step 402: Store the baseline user behavior in a storage area.
[0121] The baseline user behavior is stored in a storage area, which is only accessible to the second processor and not to other processing areas, to prevent the baseline user behavior from being maliciously tampered with. In practical applications, the storage area can be a double data rate SDRAM (DDR) or other forms of storage area, etc., which is not limited in the embodiments of the present disclosure.
[0122] Step 403, performing hash calculation on the key data and code to obtain a reference hash value.
[0123] The specific calculation steps of hash calculation are not described in detail in the present embodiment, and reference may be made to the relevant description of the related technology.
[0124] Step 404: store the reference hash value in the storage area.
[0125] Since the storage area only supports access by the second processor, storing the reference hash value in the storage area can ensure its security. In addition, the disclosed embodiment stores the reference hash value instead of just storing the key data, which can prevent the inability to perform hash calculations due to address changes of the key data. When performing subsequent verification, the reference hash value can be directly obtained from the storage area, which not only improves the verification speed, but also avoids the calculation difficulties caused by address changes of the key data.
[0126] Figure 5The following further shows a flow chart of an abnormal monitoring method proposed in the present disclosure. Figure 5 The embodiment shown further explains step 203. Figure 5 The following steps may be included:
[0127] Step 501, obtaining all sensitive data from the storage area.
[0128] Step 502: Perform hash calculation on the key data and code to obtain a verification hash value.
[0129] As an implementable method of the embodiment of the present disclosure, the second processor 13 is configured with a control encryption and decryption engine 131. After the second processor 13 determines that the current user behavior is abnormal, the encryption and decryption engine 13 is scheduled, and the encryption and decryption engine 13 performs hash calculation on the key data and the code to obtain the verification hash value. The calculation process of the verification hash value is consistent with the calculation process of the reference hash value, and the embodiment of the present disclosure will not be repeated.
[0130] Step 503: Perform integrity check on the verification hash value based on the reference hash value.
[0131] If the reference hash value is inconsistent with the verification hash value, the current user behavior is determined to be abnormal user behavior; if the reference hash value is consistent with the verification hash value, the current user behavior is determined to be normal user behavior.
[0132] In some embodiments, Figure 6 As shown, after verifying the full amount of sensitive data to determine whether the key data and code are abnormal, the method further includes:
[0133] Step 601, determining the service type of the abnormal user behavior, and determining the abnormality level according to the service type.
[0134] After determining that the current user behavior is abnormal user behavior, the second processor obtains the business type of the abnormal user behavior. The business types described in the embodiments of the present disclosure include but are not limited to payment business types, link jump business types, system upgrade business types, etc. Each business type is configured with the same or different abnormality levels.
[0135] In actual applications, in order to ensure user rights and interests and protect user interests from infringement, the payment business type can be configured with high-level exceptions.
[0136] Step 602: Send the abnormal level of the abnormal user behavior to the first processor, so that the first processor outputs a corresponding early warning strategy according to the abnormal level.
[0137] The warning strategy and exception level can be set as needed. Taking the high exception level (payment) as an example, the corresponding warning strategy is to lock the terminal, prohibit the user from continuing the operation, and send a remote processing request to the security management center; for medium-level exceptions, the corresponding warning strategy can be set to isolate suspicious applications or restrict network connections; for low-level exceptions, the corresponding warning strategy issues a warning to the user to remind the user to pay attention to abnormal behavior.
[0138] The embodiments of the present disclosure do not limit the classification of abnormal levels and corresponding warning strategies.
[0139] For ease of understanding, the present disclosure provides the following scenario description, which is a mobile payment scenario. Please continue to refer to Figure 1 and Figure 7 , the sensor module 11 collects the user behavior of the mobile terminal in real time, collects information such as transaction frequency, transaction time, and transaction location for behavior monitoring, and generates a baseline user behavior in the second processor 13. When the second processor 13 identifies that such information is abnormal, such as too frequent transaction behavior, or an unrelated processor has active behavior during a certain transaction, it will report the abnormality to trigger active measurement, and the encryption and decryption engine 131 needs to be scheduled. The encryption and decryption engine 131 will take the initiative to measure, and report the abnormal behavior to the second processor 13 according to the measurement result of the encryption and decryption engine 131. The second processor 13 reports the abnormal behavior and abnormal level to the first processor 12, and the first processor 12 performs corresponding abnormal processing according to different abnormal levels.
[0140] In summary, the embodiments of the present disclosure can achieve the following beneficial effects:
[0141] 1. Adapt to the changing security environment
[0142] As user behaviors and attack methods continue to change, behavior-driven active measurement technology can adapt to different security environments and improve system reliability by continuously learning and updating baseline user behaviors.
[0143] 2. Enhance the proactiveness of security protection
[0144] Compared with traditional passive protection technology, behavior-driven active measurement technology can proactively discover and respond to security threats, improving the efficiency and effectiveness of security protection.
[0145] 3. Improve the security of mobile phone systems
[0146] By monitoring user behavior and system status in real time, abnormal behavior can be discovered in a timely manner, and corresponding security measures can be taken to effectively prevent the occurrence of malware and attacks.
[0147] Corresponding to the above-mentioned abnormality monitoring method, the present invention also provides an abnormality monitoring device. Since the device embodiment of the present invention corresponds to the above-mentioned method embodiment, details not disclosed in the device embodiment can be referred to the above-mentioned method embodiment, and will not be repeated in the present invention.
[0148] Figure 8 The present invention provides a schematic diagram of the structure of an abnormality monitoring device 800, which includes:
[0149] A first acquisition unit 81, used to acquire current user behavior;
[0150] A first determining unit 82, configured to determine whether the current user behavior is abnormal according to a baseline user behavior, wherein the baseline user behavior is generated and updated by a normal user behavior;
[0151] The verification unit 83 is used to verify the full amount of sensitive data to determine whether the key data and code are abnormal when it is determined that the current user behavior is abnormal, and the full amount of sensitive data includes pre-marked key data and codes.
[0152] In summary, according to the abnormality monitoring device proposed in the present disclosure, the device includes obtaining the current user behavior, determining whether the current user behavior is abnormal based on the baseline user behavior, wherein the baseline user behavior is generated and updated by the normal behavior of the user, and in the case of determining that the current user behavior is abnormal, verifying the full amount of sensitive data to determine whether the key data and code are abnormal, and the full amount of sensitive data includes pre-marked key data and code. By continuously generating and updating the baseline user behavior, adapting to different security environments, and improving the reliability of the system, in addition, after determining that the current user behavior is abnormal, using abnormal user behavior to drive active measurement technology (based on verification of the full amount of sensitive data) can actively discover and respond to security threats, and improve the efficiency and effectiveness of security protection.
[0153] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the device also includes:
[0154] The second acquisition unit 84 is used to acquire user behavior data generated when the user operates the terminal;
[0155] A generating unit 85, configured to generate the baseline user behavior according to the user behavior data;
[0156] The marking unit 86 is used to mark the key data and codes in the baseline user behavior to obtain the full amount of sensitive data.
[0157] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the second acquisition unit 84 is further used to receive user behavior data sent by the first processor, and the user behavior data is acquired by the first processor through a preset sensor.
[0158] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the generating unit 85 is also used for:
[0159] Establishing a corresponding relationship between the baseline user behavior and the second processor;
[0160] Storing the baseline user behavior in a storage area;
[0161] Performing hash calculation on the key data and code to obtain a reference hash value;
[0162] The reference hash value is stored in the storage area.
[0163] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the verification unit 83 includes:
[0164] An acquisition module 831 is used to acquire the full amount of sensitive data from the storage area;
[0165] A calculation module 832 is used to perform hash calculation on the full amount of sensitive data and code to obtain a verification hash value;
[0166] The verification module 833 is used to perform integrity verification on the verification hash value based on the reference hash value.
[0167] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the second determining unit 84 is further configured to determine that the current user behavior is an abnormal user behavior if the reference hash value is inconsistent with the verification hash value.
[0168] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the calculation module 832 is also used to control the encryption and decryption engine to perform hash calculation on the full amount of sensitive data and the code to obtain the verification hash value, wherein the encryption and decryption engine is configured in the second processor.
[0169] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Fig. 9 As shown, the device also includes:
[0170] A second determination unit 87 is used to determine the business type of the abnormal user behavior after the second determination unit 84 verifies the full amount of sensitive data to determine whether the key data and code are abnormal, and determine the abnormality level according to the business type;
[0171] The sending unit 88 is used to send the abnormal level of the abnormal user behavior to the first processor, so that the first processor outputs a corresponding early warning strategy according to the abnormal level.
[0172] Since the device provided in the embodiment of the present disclosure corresponds to the methods provided in the above-mentioned embodiments, the implementation of the method is also applicable to the device provided in the embodiment and will not be described in detail in this embodiment.
[0173] In the embodiments provided in the present application, the methods and devices provided in the embodiments of the present application are introduced. In order to implement the functions in the methods provided in the embodiments of the present application, the electronic device may include a hardware structure and a software module, and implement the functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. A function of the functions may be executed in the form of a hardware structure, a software module, or a hardware structure plus a software module.
[0174] Fig.10 1 is a block diagram of an electronic device 1000 for implementing the above-mentioned abnormal monitoring method according to an exemplary embodiment. For example, the electronic device 1000 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
[0175] Reference Fig.10 , the electronic device 1000 may include one or more of the following components: a processing component 1002 , a memory 1004 , a power component 1006 , a multimedia component 1008 , an audio component 1010 , an input / output (I / O) interface 1012 , a sensor component 1014 , and a communication component 1016 .
[0176] The processing component 1002 generally controls the overall operation of the electronic device 1000, such as operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 1002 may include one or more processors 1020 to execute instructions to complete all or part of the steps of the above-mentioned method. In addition, the processing component 1002 may include one or more modules to facilitate the interaction between the processing component 1002 and other components. For example, the processing component 1002 may include a multimedia module to facilitate the interaction between the multimedia component 1008 and the processing component 1002.
[0177] The memory 1004 is configured to store various types of data to support operations on the electronic device 1000. Examples of such data include instructions for any application or method operating on the electronic device 1000, contact data, phone book data, messages, pictures, videos, etc. The memory 1004 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0178] The power supply component 1006 provides power to various components of the electronic device 1000. The power supply component 1006 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 1000.
[0179] The multimedia component 1008 includes a screen that provides an output interface between the electronic device 1000 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 1008 includes a front camera and / or a rear camera. When the electronic device 1000 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each front camera and rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.
[0180] The audio component 1010 is configured to output and / or input audio signals. For example, the audio component 1010 includes a microphone (MIC), and when the electronic device 1000 is in an operation mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive an external audio signal. The received audio signal can be further stored in the memory 1004 or sent via the communication component 1016. In some embodiments, the audio component 1010 also includes a speaker for outputting audio signals.
[0181] I / O interface 1012 provides an interface between processing component 1002 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include but are not limited to: home button, volume button, start button, and lock button.
[0182] The sensor assembly 1014 includes one or more sensors for providing various aspects of status assessment for the electronic device 1000. For example, the sensor assembly 1014 can detect the open / closed state of the electronic device 1000, the relative positioning of components, such as the display and keypad of the electronic device 1000, and the sensor assembly 1014 can also detect the position change of the electronic device 1000 or a component of the electronic device 1000, the presence or absence of user contact with the electronic device 1000, the orientation or acceleration / deceleration of the electronic device 1000, and the temperature change of the electronic device 1000. The sensor assembly 1014 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 1014 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 1014 may also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0183] The communication component 1016 is configured to facilitate wired or wireless communication between the electronic device 1000 and other devices. The electronic device 1000 can access a wireless network based on a communication standard, such as WiFi, 2G or 3G, 4G LTE, 5G NR (NewRadio) or a combination thereof. In an exemplary embodiment, the communication component 1016 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 1016 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0184] In an exemplary embodiment, the electronic device 1000 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above methods.
[0185] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 1004 including instructions, and the instructions can be executed by the processor 1020 of the electronic device 1000 to perform the above method for image processing. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0186] The embodiments of the present disclosure further provide a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to execute the method described in the above embodiments of the present disclosure.
[0187] For electronic devices that may be chips or chip systems, see Fig.11 Schematic diagram of the chip structure shown. Fig.11 The chip shown includes a processor 1101 and an interface 1102. The number of the processor 1101 may be one or more, and the number of the interface 1102 may be multiple.
[0188] Optionally, the chip further includes a memory 1103, and the memory 1103 is used to store necessary computer programs and data.
[0189] Those skilled in the art may also appreciate that the various illustrative logic blocks and steps listed in the embodiments of the present application may be implemented by electronic hardware, computer software, or a combination of the two. Whether such functions are implemented by hardware or software depends on the design requirements of the specific application and the entire system. Those skilled in the art may use various methods to implement the functions for each specific application, but such implementation should not be understood as exceeding the scope of protection of the embodiments of the present application.
[0190] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0191] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "illustrative embodiments", "examples", "specific examples" or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiments or examples are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0192] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code that includes one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present invention includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present invention belong.
[0193] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processing module, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (control method), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or otherwise processing in a suitable manner if necessary, and then stored in a computer memory.
[0194] It should be understood that the various parts of the embodiments of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0195] A person of ordinary skill in the art may understand that all or part of the steps of the method for implementing the above-mentioned embodiment may be completed by instructing the relevant hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one of the steps of the method embodiment or a combination thereof.
[0196] In addition, each functional unit in each embodiment of the present invention may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium. The above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0197] Although the embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and are not to be construed as limitations of the present invention. A person skilled in the art may make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. An abnormality monitoring method, characterized in that: The method comprises: Get current user behavior; Determining whether the current user behavior is abnormal based on a baseline user behavior, wherein the baseline user behavior is generated and updated by a normal user behavior; When it is determined that the current user behavior is abnormal, the full amount of sensitive data is verified to determine whether the key data and code are abnormal, and the full amount of sensitive data includes pre-marked key data and codes.
2. The method according to claim 1, characterized in that The method further comprises: Obtain user behavior data generated when the user operates the terminal; generating the baseline user behavior according to the user behavior data; The key data and the code are marked to obtain the full amount of sensitive data.
3. The method according to claim 2, characterized in that The obtaining of user behavior data generated when the user operates the terminal includes: The user behavior data sent by the first processor is received, where the user behavior data is acquired by the first processor through a preset sensor.
4. The method according to claim 2, characterized in that: Generating the baseline user behavior according to the user behavior data includes: Establishing a corresponding relationship between the baseline user behavior and the second processor; Storing the baseline user behavior, the corresponding key data and the code in a storage area; Performing hash calculation on the key data and code to obtain a reference hash value; The reference hash value is stored in the storage area.
5. The method according to claim 4, characterized in that The verification of the full amount of sensitive data includes: Acquire the full amount of sensitive data from the storage area; Performing hash calculation on the key data and code to obtain a verification hash value; An integrity check is performed on the verification hash value based on the reference hash value.
6. The method according to claim 5, characterized in that The verification of the entire amount of sensitive data to determine whether the key data and code are abnormal includes: If the reference hash value is inconsistent with the verification hash value, the current user behavior is determined to be abnormal user behavior.
7. The method according to claim 5, characterized in that The performing hash calculation on the key data and code to obtain a verification hash value comprises: Controlling the encryption and decryption engine to perform hash calculation on the key data and the code to obtain the verification hash value, wherein the encryption and decryption engine is configured in the second processor.
8. The method according to claim 3, characterized in that After verifying the entire amount of sensitive data to determine whether the key data and code are abnormal, the method further includes: Determining the service type of the abnormal user behavior, and determining the abnormality level according to the service type; The abnormal level of the abnormal user behavior is sent to the first processor, so that the first processor outputs a corresponding early warning strategy according to the abnormal level.
9. An abnormality monitoring device, characterized in that: The device comprises: A first acquisition unit, used to acquire current user behavior; A first determining unit, configured to determine whether the current user behavior is abnormal according to a baseline user behavior, wherein the baseline user behavior is generated and updated by a normal user behavior; A verification unit is used to verify the full amount of sensitive data to determine whether the key data and code are abnormal when it is determined that the current user behavior is abnormal, and the full amount of sensitive data includes pre-marked key data and codes.
10. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.
11. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-8.
12. A chip, characterized in that: It comprises one or more interfaces and one or more processors; the interface is used to receive a signal from a memory of an electronic device and send the signal to the processor, the signal includes a computer instruction stored in the memory, and when the processor executes the computer instruction, the electronic device executes the method described in any one of claims 1 to 8.
Citation Information
Patent Citations
Abnormal computer user behavior detection method
CN106998334A
Service scene disposal risk evaluation method and system for power monitoring system
CN111723367A
Remodification, identification and alarm system and method for sensitive archives
CN119046933A
Data monitoring system of RTU voltage regulating station based on security chip
CN208766497U