Deep Learning-Based Risk Behavior Perception Method and Device

Through a deep learning-based risk behavior perception method, combined with the spatio-temporal feature extraction of multi-source behavior data and protocol analysis of network access records, and the pre-trained risk assessment neural network is used for joint encoding, which solves the problem of difficult to identify complex risk scenarios in the prior art, and achieves high-accuracy risk assessment and intelligent early warning response.

CN119939576BActive Publication Date: 2025-06-13BIG DATA SECURITY ENG RES CENT (GUIZHOU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510428728.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-06-13
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

The existing technology fails to fully consider the intrinsic connections and mutual influences between different data sources in the field of risk behavior perception, making it difficult to accurately identify comprehensive risks in complex and changing risk scenarios, and the accuracy and reliability of risk assessment are low.

Method used

The risk behavior perception method based on deep learning is adopted, and by collecting multi-source behavior data, spatial-temporal feature extraction and protocol analysis of network access records is carried out, behavior trajectory feature vectors and network behavior feature vectors are generated, and the two feature vectors are jointly encoded by a pre-trained risk assessment neural network to generate behavior risk probability distribution.

Benefits of technology

It achieves a more accurate assessment of the risk level of user behavior, improves the accuracy and reliability of risk assessment, supports the automation and intelligence of the entire process from risk assessment to early warning response, and improves the efficiency and response speed of security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939576B_ABST
    Figure CN119939576B_ABST
Patent Text Reader

Abstract

The present invention provides a risk behavior perception method and device based on deep learning. First, multi-source behavior data including network access records, terminal operation logs, and application program interface call sequences within a preset time window of a target user is collected. Then, spatio-temporal features of the multi-source behavior data are extracted to generate behavior trajectory feature vectors, and network behavior feature vectors are obtained by protocol parsing of the network access records. After that, the two are input into a pre-trained risk assessment neural network for joint encoding to obtain a behavior risk probability distribution. Then, the risk level is determined based on the risk categories exceeding the preset threshold, and a warning signal is generated. Finally, according to the warning signal, a real-time alarm module is triggered to send a risk description text and a risk mitigation strategy to a security management terminal, realizing comprehensive analysis of multi-source data, accurately evaluating risks and giving timely and effective warnings, and improving the risk perception ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of deep learning technology, and in particular to a risk behavior perception method and device based on deep learning. Background Art

[0002] In today's digital age, various systems and platforms face increasingly complex security threats, and effective perception of user risk behaviors has become crucial.

[0003] At present, in the field of risk behavior perception, relevant technologies have not fully taken into account the possible intrinsic connections and mutual influences between different data sources, making it difficult to accurately identify the comprehensive risks hidden behind multiple behaviors when faced with complex and changing risk scenarios, resulting in low accuracy and reliability of risk assessment.

[0004] In addition, most existing risk assessment methods use manually designed features and traditional machine learning models. Manually designed features not only consume a lot of manpower and time, but also have difficulty covering all possible risk scenarios. In addition, due to the limitations of human factors, it is difficult to mine deep features in the data. Traditional machine learning models have limited processing capabilities for complex nonlinear relationships, cannot automatically learn complex patterns and laws in data, and have difficulty adapting to changing risk behavior patterns. Summary of the invention

[0005] In view of the above-mentioned problems, in combination with the first aspect of the present invention, an embodiment of the present invention provides a risk behavior perception method based on deep learning, the method comprising:

[0006] Collecting multi-source behavior data of the target user within a preset time window, wherein the multi-source behavior data includes network access records, terminal operation logs, and application program interface call sequences;

[0007] Extracting spatiotemporal features from the multi-source behavior data to generate a behavior trajectory feature vector of the target user, and performing protocol parsing on the network access record to obtain a network behavior feature vector;

[0008] Inputting the behavior trajectory feature vector and the network behavior feature vector into a pre-trained risk assessment neural network, and jointly encoding the behavior trajectory feature vector and the network behavior feature vector through the risk assessment neural network to generate a behavior risk probability distribution of the target user;

[0009] Determine the risk level of the target user based on the risk category exceeding a preset threshold in the behavior risk probability distribution, and generate a warning signal corresponding to the risk level;

[0010] Trigger the real-time alarm module according to the warning signal, and send the risk description text and risk mitigation strategy corresponding to the risk level to the security management terminal.

[0011] In another aspect, an embodiment of the present invention further provides a risk behavior perception device based on deep learning, including a processor and a machine-readable storage medium. The machine-readable storage medium is connected to the processor. The machine-readable storage medium is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the machine-readable storage medium to implement the above method.

[0012] Based on the above aspects, the embodiments of the present application collect multi-source behavior data, extract spatio-temporal features from the multi-source behavior data and combine protocol parsing of network access records to generate behavior trajectory feature vectors and network behavior feature vectors. The pre-trained risk assessment neural network is used to jointly encode the two feature vectors to generate a behavior risk probability distribution, giving full play to the powerful feature learning and data analysis capabilities of the deep learning model. The joint encoding mechanism breaks the isolated mode of separately processing different features in traditional methods and can automatically learn the complex interaction relationships between different features, thereby more accurately evaluating the risk level of user behavior and improving the accuracy and reliability of risk assessment. Determine the risk level based on the behavior risk probability distribution and generate a warning signal, and then trigger the real-time alarm module according to the warning signal and send the risk description text and risk mitigation strategy, realizing the full-process automation and intelligence from risk assessment to warning response, being able to respond to potential risks in a very short time, timely inform the security management terminal of relevant information, and provide targeted countermeasures, greatly improving the efficiency and response speed of security management. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a schematic execution flow diagram of a risk behavior perception method based on deep learning provided by an embodiment of the present invention.

[0014] Figure 2 is a schematic diagram of exemplary hardware and software components of a risk behavior perception device based on deep learning provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0015] The present invention will be specifically described below with reference to the accompanying drawings of the specification. Figure 1 is a schematic flow diagram of a risk behavior perception method based on deep learning provided by an embodiment of the present invention. The risk behavior perception method based on deep learning will be introduced in detail below.

[0016] Step S110, collect multi-source behavior data of the target user within a preset time window, where the multi-source behavior data includes network access records, terminal operation logs, and application program interface call sequences.

[0017] In this embodiment, taking the e-commerce field as an example, there are a large number of user interaction behaviors in the e-commerce platform, and it is crucial to ensure user data security and identify risks in user behaviors. Specifically, on the e-commerce platform, assume that the preset time window is one day. For the target user, their network access records contain information related to the pages of the e-commerce platform visited by the user within this day. For example, the user visited the electronic product classification page at 10 am, entered the details page of a certain mobile phone product at 10:15 am, and then visited the shopping cart page at 10:30 am, etc. The above access records contain detailed information such as the accessed website addresses and the time sequence of access.

[0018] Regarding the terminal operation logs, assume that the user accesses the e-commerce platform using a mobile phone client. The operation logs record various operations of the user on the mobile phone, such as the user clicked on the product picture to enlarge and view it at 11 am, performed a screen sliding operation to view more product reviews at 11:10 am, and entered the product search keywords at 11:30 am, etc. These operation logs detail the types of operations and the times when they occurred.

[0019] Regarding the application programming interface (API) call sequences, when the user performs various operations on the e-commerce platform, different API calls will be triggered. For example, when the user views the product inventory, the API for querying inventory will be called; when the user places an order, a series of APIs such as creating an order, calculating the price, and verifying the payment method will be called. The order and frequency of these API calls, etc., constitute the application programming interface call sequences. By collecting the above multi-source behavior data such as network access records, terminal operation logs, and application programming interface call sequences, the behavior patterns of the target user on the e-commerce platform can be comprehensively understood.

[0020] Step S120: Extract spatio-temporal features from the multi-source behavior data to generate the behavior trajectory feature vector of the target user, and perform protocol parsing on the network access records to obtain the network behavior feature vector.

[0021] Specifically, for the spatio-temporal feature extraction of multi-source behavior data, the timestamp sequence and operation type labels of operation events are extracted from the terminal operation logs. For example, according to the operation logs mentioned above, the timestamp sequence is 11 o'clock, 11:10, 11:30, etc., and the operation type labels are click on picture, screen swipe, input search keyword, etc. The timestamp sequence is converted into a time interval distribution histogram. For example, calculate the time intervals between adjacent operations. The interval from 11 o'clock to 11:10 is 10 minutes, and the interval from 11:10 to 11:30 is 20 minutes. Based on these time intervals, the distribution of different interval times is statistically obtained to form a histogram. The operation type labels are mapped to operation semantic vectors. Suppose clicking on a picture corresponds to the vector [0.1, 0.2, 0.3], screen swiping corresponds to [0.4, 0.5, 0.6], inputting a search keyword corresponds to [0.7, 0.8, 0.9], etc.

[0022] Next, the interface call frequency matrix is extracted from the application programming interface call sequence. Suppose the inventory query API is called 5 times and the order creation API is called 1 time within a day, etc., to form a matrix reflecting the call frequencies of each API. Then, a sliding window statistic is performed on this interface call frequency matrix. For example, with a 1-hour sliding window, the API call pattern features within each window are statistically analyzed, such as some APIs being frequently called within a certain 1-hour period and rarely called at other times.

[0023] Then, the obtained time interval distribution histogram, operation semantic vectors, and API call pattern features are concatenated to obtain the initial behavior trajectory features. After that, dimensionality reduction processing is performed on the initial behavior trajectory features. Suppose the initial behavior trajectory features have 10 dimensions. Some redundant dimensions are removed through methods such as principal component analysis. For example, it is compressed to 5 dimensions to generate the compressed intermediate behavior trajectory features. Finally, the intermediate behavior trajectory features are input into the spatio-temporal attention module. The spatio-temporal attention module performs weighted fusion according to the time dependence relationship and spatial correlation relationship between the features. For example, higher weights are given to the operations and API calls related to the order placement operation, thereby generating the behavior trajectory feature vector.

[0024] For the protocol parsing of network access records, parse the target protocol field in the network access records. For example, in an e-commerce platform, the HTTP protocol is used when a user accesses a page. Extract the source address (assuming the IP address of the user's mobile phone is 192.168.1.100), the target address (the e-commerce platform server address is 202.100.100.100), the protocol type (HTTP), and the packet length (assuming the packet length for each access varies from 100 to 500 bytes) from the HTTP protocol. Generate address pair features based on the source address and the target address. For example, combine 192.168.1.100 and 202.100.100.100 into a specific address pair feature. Perform one-hot encoding on the protocol type. The HTTP protocol is encoded as [1, 0, 0] (assuming only three protocol types, namely HTTP, HTTPS, and FTP, are encoded). Segment and count the packet length. For example, divide the 100 - 500 bytes into four segments: 100 - 200, 200 - 300, 300 - 400, and 400 - 500. Count the number of packets in each segment to form a packet length distribution histogram, and convert it into a frequency domain feature vector. Fuse the address pair features, the protocol type encoding vector, and the frequency domain feature vector to obtain the original network behavior features. Then, input the original network behavior features into a convolutional neural network for local pattern extraction. For example, extract specific patterns of interaction between the source address and the target address, etc., so as to generate a network behavior feature vector.

[0025] Step S130: Input the behavior trace feature vector and the network behavior feature vector into a pre-trained risk assessment neural network. Through the risk assessment neural network, jointly encode the behavior trace feature vector and the network behavior feature vector to generate the behavior risk probability distribution of the target user.

[0026] In the e-commerce field, the pre-trained risk assessment neural network has been trained using a large amount of historical e-commerce user behavior data. Input the previously generated behavior trace feature vector and network behavior feature vector into this risk assessment neural network. The behavior trace encoding branch and the network behavior encoding branch of the risk assessment neural network start to work. The behavior trace encoding branch processes the behavior trace feature vector, and the network behavior encoding branch processes the network behavior feature vector. For example, the behavior trace encoding branch encodes based on information such as the user's operation sequence and operation type, and the network behavior encoding branch encodes jointly based on information such as the source address, target address, and protocol type of the network access.

[0027] During the joint encoding process, when the behavioral trajectory feature vector shows that the user frequently modifies the order content within a short period of time, and at the same time the network behavior feature vector shows access from an abnormal source address (which can be an IP address marked as a risk source), the neural network will assign a relatively high risk weight to this situation. Through the calculation of the neural network, the behavioral risk probability distribution of the target user is generated. Suppose the risk categories are divided into account theft risk, payment risk, commodity information leakage risk, etc. The behavioral risk probability distribution output by the neural network may be that the account theft risk probability is 0.1, the payment risk probability is 0.05, the commodity information leakage risk probability is 0.03, etc., indicating the likelihood of different risk categories.

[0028] Step S140, based on the risk categories in the behavioral risk probability distribution that exceed the preset threshold, determine the risk level of the target user and generate a warning signal corresponding to the risk level.

[0029] Suppose the preset threshold is 0.05. In the previously obtained behavioral risk probability distribution, the account theft risk probability of 0.1 exceeds the preset threshold. First, traverse each risk category in the behavioral risk probability distribution, extract the risk category identifier whose probability value exceeds the preset threshold. Here, it is the account theft risk, and a candidate risk set is generated.

[0030] Obtain the weight factor corresponding to the account theft risk (assumed to be 0.8, indicating a relatively high importance of this risk) and the associated impact matrix from the predefined risk meta-database. In the associated impact matrix, if there are both account theft risk and payment risk at the same time, it may be that the account theft will lead to an increase in payment risk, so the superposition effect intensity between them is relatively high. Multiply the weight factor 0.8 of the account theft risk by its probability value 0.1 to obtain an independent risk contribution value of 0.08. Suppose the collaborative risk gain value calculated according to the associated impact matrix is 0.02 (considering the associated impact with other possible risks). Add the independent risk contribution value and the collaborative risk gain value to obtain a comprehensive risk evaluation value of 0.1.

[0031] Input the comprehensive risk evaluation value of 0.1 into the piecewise mapping function to determine the corresponding discretized risk level number according to the preset level division interval. Suppose 0 - 0.05 is the low risk level number 1, 0.05 - 0.15 is the medium risk level number 2, and above 0.15 is the high risk level number 3. Here, the medium risk level number 2 is obtained.

[0032] Query the early warning signal template library according to the discretized risk level number 2, and extract the early warning signal format framework and filling field rules that match this number. Obtain the description text of the account theft risk (such as "It is detected that there may be a risk of account theft, and there may be abnormal login behavior") and mitigation strategy entries (such as "Prompt the user to modify the password and increase the login verification method") from the risk knowledge base. Insert the description text into the corresponding placeholder of the early warning signal format framework according to the filling field rules to generate the original early warning signal text. Check the syntax structure of the original early warning signal text, and correct possible semantic conflicts and logical breakpoints to generate compliant early warning signal content. Encode the current timestamp (for example, 15:00 on October 1, 2023) and the risk level number 2 into the protocol header identification segment, and splice the compliant early warning signal content with the protocol header identification segment to generate the final early warning signal with an integrity label.

[0033] Step S150, trigger the real-time alarm module according to the early warning signal, and send the risk description text and risk mitigation strategy corresponding to the risk level to the security management terminal.

[0034] Specifically, the risk level number 2 and the embedded timestamp 15:00 on October 1, 2023 can be parsed from the protocol header identification segment of the early warning signal. Based on the risk level number 2, extract the corresponding transmission protocol type (assumed to be the Secure Sockets Layer protocol SSL) and priority encoding (assumed to be the medium priority encoding 2) from the risk policy library.

[0035] Then, verify the validity of the digital signature of the final early warning signal. If it is detected that the signature verification fails, trigger a data integrity alarm and terminate the transmission process. Here, it is assumed that the digital signature verification passes. Then extract the risk description text field ("It is detected that there may be a risk of account theft, and there may be abnormal login behavior") and the risk mitigation strategy field ("Prompt the user to modify the password and increase the login verification method") in the compliant early warning signal content.

[0036] Next, convert the risk description text field into a formatted text stream that conforms to the SSL protocol according to the SSL transmission protocol type, and split the risk mitigation strategy field into independent strategy entries and number them according to the execution order, such as "1. Prompt the user to modify the password; 2. Increase the login verification method". Package the formatted text stream and the numbered strategy entries to generate an alarm transmission data packet containing the protocol header identification segment, the risk level number 2, and the timestamp 15:00 on October 1, 2023, and append a checksum field to the end of the alarm transmission data packet.

[0037] Finally, according to the priority encoding 2, activate the corresponding transmission channel in the real-time alarm module, and load the alarm transmission data packet into the send buffer of the transmission channel. Perform byte-stream sharding on the alarm transmission data packet in the send buffer. Assume that it is divided into 3 equal-length data shards and add shard sequence identifiers 1, 2, and 3 to each data shard. Based on the retransmission mechanism rules defined by the SSL transmission protocol type, inject the data shards into the network interface queue of the transmission channel in the order of the sequence identifiers, triggering the network interface queue to initiate an asynchronous transmission request to the preset receiving port of the security management terminal, so as to send the risk description text and risk mitigation strategy to the security management terminal, so that security managers can take corresponding measures to ensure the safety of e-commerce platform users.

[0038] Based on the above steps, the embodiment of the present application generates a behavior trajectory feature vector and a network behavior feature vector by collecting multi-source behavior data, extracting spatio-temporal features from the multi-source behavior data and combining protocol parsing of network access records, and uses a pre-trained risk assessment neural network to jointly encode the two feature vectors to generate a behavior risk probability distribution, giving full play to the powerful feature learning and data analysis capabilities of the deep learning model. The joint encoding mechanism breaks the isolated mode of separately processing different features in traditional methods and can automatically learn the interaction relationships between different features, thereby more accurately evaluating the risk level of user behavior and improving the accuracy and reliability of risk assessment. Determine the risk level based on the behavior risk probability distribution and generate a warning signal, and then trigger the real-time alarm module according to the warning signal and send the risk description text and risk mitigation strategy, realizing the full-process automation and intelligence from risk assessment to warning response, being able to respond to potential risks in a very short time, timely inform the security management terminal of relevant information, and provide targeted countermeasures, greatly improving the efficiency and response speed of security management.

[0039] In a possible implementation manner, step S120 includes:

[0040] Step S121, extract the timestamp sequence and operation type label of the operation event from the terminal operation log, convert the timestamp sequence into a time interval distribution histogram, and map the operation type label to an operation semantic vector.

[0041] For example, a target user operates using a mobile client on an e-commerce platform, and the terminal operation log records detailed information. The timestamp sequence of operation events may be starting to view the product list at 10:10 am, viewing product details at 10:15 am, adding the product to the shopping cart at 10:25 am, viewing the shopping cart at 10:30 am, etc. Calculate the time intervals. The interval from 10:10 am to 10:15 am is 5 minutes, the interval from 10:15 am to 10:25 am is 10 minutes, and the interval from 10:25 am to 10:30 am is 5 minutes. Based on these time intervals, count the distribution of different interval times to form a time interval distribution histogram. For example, the 5-minute interval appears 2 times, the 10-minute interval appears 1 time, etc. Operation type tags such as viewing the product list, viewing product details, adding to the shopping cart, viewing the shopping cart, etc. Map these operation type tags to operation semantic vectors. Assume that viewing the product list corresponds to the vector [0.1, 0.2, 0.3], viewing product details corresponds to [0.2, 0.3, 0.4], adding to the shopping cart corresponds to [0.3, 0.4, 0.5], and viewing the shopping cart corresponds to [0.4, 0.5, 0.6].

[0042] Step S122: Extract an interface call frequency matrix from the application program interface call sequence, and perform a sliding window statistic on the interface call frequency matrix to generate interface call pattern features.

[0043] On an e-commerce platform, when a user performs various operations, API calls are triggered. Assume that within one hour, the API for querying product information is called 3 times, the API for querying inventory is called 2 times, the API for placing an order is called 1 time, etc., and an interface call frequency matrix is constructed accordingly. Then perform a sliding window statistic, for example, with a 15-minute sliding window. Within the first 15-minute window, the API for querying product information is called 2 times, the API for querying inventory is called 1 time, and the API for placing an order is not called; within the second 15-minute window, the API for querying product information is called 1 time, the API for querying inventory is called 1 time, and the API for placing an order is called 1 time, etc. Generate interface call pattern features based on these statistical information. For example, situations where certain APIs are intensively called within a specific window and rarely called in other windows are recorded.

[0044] Step S123: Concatenate the time interval distribution histogram, the operation semantic vector, and the interface call pattern features to obtain initial behavior trajectory features.

[0045] In this embodiment, the time interval distribution information in the previously obtained time interval distribution histogram, the operation semantic information in the operation semantic vector, and the API call pattern information in the interface call pattern features are combined together in a set order to form an initial behavior trajectory feature containing various information.

[0046] Step S124: Perform dimensionality reduction on the initial behavioral trajectory features, remove redundant dimensions in the initial behavioral trajectory features, and generate compressed intermediate behavioral trajectory features.

[0047] Suppose the initial behavioral trajectory features contain information in 10 dimensions. Through dimensionality reduction methods such as principal component analysis, calculate the contribution of each dimension to the overall features. For example, the contribution of dimension 1 is 0.1, the contribution of dimension 2 is 0.05, etc. According to the set threshold or importance ranking, remove the dimensions with lower contributions, such as removing dimension 2, dimension 4, etc., and compress the features to 6 dimensions to generate compressed intermediate behavioral trajectory features.

[0048] Step S125: Input the intermediate behavioral trajectory features into the spatio-temporal attention module, and through the spatio-temporal attention module, perform weighted fusion on the time-dependent relationship and spatial correlation relationship in the intermediate behavioral trajectory features to generate the behavioral trajectory feature vector.

[0049] For example, in a possible implementation, step S125 includes:

[0050] Step S1251: Input the intermediate behavioral trajectory features into the time embedding layer, and through the time embedding layer, extract the change rate between adjacent time steps in the intermediate behavioral trajectory features to generate a time embedding vector. Also, input the intermediate behavioral trajectory features into the spatial embedding layer, and through the spatial embedding layer, extract the co-occurrence frequency of different operation types in the intermediate behavioral trajectory features to generate a spatial embedding vector.

[0051] For example, the time-related part in the intermediate behavioral trajectory features records the sequence and interval of user operations in time. If the change from the previous operation to the next operation is relatively sudden, such as from viewing product details to directly placing an order, this change rate is relatively large; while the change rate from viewing product details to viewing more reviews is relatively small. According to these different change rate situations, generate a time embedding vector. Suppose the element values of the time embedding vector range from 0 to 1 according to the change rate magnitude, with values close to 1 for large change rates and values close to 0 for small change rates.

[0052] On an e-commerce platform, different operation types such as viewing products, adding to the shopping cart, placing an order, etc. Calculate their co-occurrence frequencies. For example, the co-occurrence frequency of viewing products and adding to the shopping cart is relatively high, perhaps 0.6, indicating that these two operations often occur together in multiple operations; while the co-occurrence frequency of viewing products and canceling an order is relatively low, perhaps 0.1. According to these co-occurrence frequencies, generate a spatial embedding vector, and the vector element values reflect the co-occurrence frequency situations of different operation types.

[0053] Step S1252: Concatenate the time embedding vector and the space embedding vector along the channel dimension to generate a spatio-temporal joint vector, and input the spatio-temporal joint vector into the multi-head attention layer. Through the multi-head attention layer, parallelly calculate the association strength between each feature position and other feature positions in the spatio-temporal joint vector to generate multiple spatio-temporal attention weight matrices.

[0054] For example, if the time embedding vector is [0.2, 0.3, 0.4] and the space embedding vector is [0.3, 0.4, 0.5], after concatenation, the spatio-temporal joint vector [0.2, 0.3, 0.4, 0.3, 0.4, 0.5] is obtained. Input the spatio-temporal joint vector into the multi-head attention layer, and through the multi-head attention layer, parallelly calculate the association strength between each feature position and other feature positions in the spatio-temporal joint vector to generate multiple spatio-temporal attention weight matrices. For example, for the first element in the spatio-temporal joint vector, calculate its association strength with other elements. Suppose the association strength with the second element is 0.3, and the association strength with the third element is 0.2, and so on. Calculate multiple such association strength values to form a spatio-temporal attention weight matrix. Since it is a multi-head attention layer, multiple such spatio-temporal attention weight matrices will be calculated in parallel.

[0055] Step S1253: Concatenate the multiple spatio-temporal attention weight matrices along the attention head dimension and then input them into the normalization layer. Through the normalization layer, perform scaling and smoothing processing on the concatenated matrix to generate a standardized spatio-temporal attention coefficient matrix. Perform matrix multiplication on the standardized spatio-temporal attention coefficient matrix and the intermediate behavior trajectory feature to obtain a weighted spatio-temporal feature matrix, and input the weighted spatio-temporal feature matrix into the gated recurrent unit layer.

[0056] Suppose the concatenated matrix is a 3×3 matrix, and the normalization layer performs scaling and smoothing according to the element value distribution in the matrix. For example, if the matrix element values are between 0 and 1, the normalization layer may appropriately shrink the larger values and appropriately enlarge the smaller values to make the matrix element value distribution more uniform, obtaining a standardized spatio-temporal attention coefficient matrix.

[0057] Suppose the intermediate behavior trajectory feature is a 2×3 matrix and the standardized spatio-temporal attention coefficient matrix is a 3×3 matrix. Calculate according to the matrix multiplication rule. First, calculate the element in the first row and first column of the weighted spatio-temporal feature matrix. Multiply each element in the first row of the intermediate behavior trajectory feature by the corresponding element in the first column of the spatio-temporal attention coefficient matrix and then sum them to obtain the element value in the first row and first column of the weighted spatio-temporal feature matrix. Calculate all the elements of the entire weighted spatio-temporal feature matrix in this way.

[0058] Step S1254: Iteratively update the time series dependencies in the weighted spatio-temporal feature matrix through the gated recurrent unit layer to generate a time series enhanced feature vector. Input the time series enhanced feature vector into the spatial graph convolutional layer, and perform neighborhood feature aggregation on the time series enhanced feature vector through the spatial graph convolutional layer based on the predefined operation type association graph to generate a spatial enhanced feature vector.

[0059] The gated recurrent unit layer performs iterative feature updates based on the time series dependencies in the weighted spatio-temporal feature matrix. Assume that the elements in the weighted spatio-temporal feature matrix reflect the operation feature relationships at different time points. The gated recurrent unit layer updates the features at each time step based on the information at the current time step and the previous time step. For example, the value of an element at the current time step is adjusted according to the relevant element values at the previous time step and the input at the current time step. After multiple iterative updates, a time series enhanced feature vector is generated.

[0060] In an e-commerce platform, the operation type association graph defines the relationships between different operation types. For example, viewing a product and viewing reviews are neighborhood relationships. The spatial graph convolutional layer performs an aggregation operation on the elements in the time series enhanced feature vector according to the operation type association graph. For example, the feature elements related to viewing reviews for a viewed product are aggregated together to generate a spatial enhanced feature vector, enabling the fusion and enhancement of related operation features.

[0061] Step S1255: Perform an element-wise addition operation on the time series enhanced feature vector and the spatial enhanced feature vector to generate a fused spatio-temporal feature vector. Input the fused spatio-temporal feature vector into the residual connection layer, and perform cross-layer feature superposition on the fused spatio-temporal feature vector and the intermediate behavior trajectory feature through the residual connection layer to generate an enhanced behavior trajectory feature with residual correction.

[0062] For example, if the time series enhanced feature vector is [0.1, 0.2, 0.3] and the spatial enhanced feature vector is [0.2, 0.3, 0.4], the fused spatio-temporal feature vector [0.3, 0.5, 0.7] is obtained after element-wise addition.

[0063] Assume that the intermediate behavior trajectory feature is [0.1, 0.2, 0.3] and the fused spatio-temporal feature vector is [0.3, 0.5, 0.7]. The enhanced behavior trajectory feature with residual correction [0.4, 0.7, 1.0] is obtained by adding their corresponding elements.

[0064] Step S1256: Input the enhanced behavior trajectory features into the feature projection layer. Through the feature projection layer, compress the dimension of the enhanced behavior trajectory features to the preset embedding space dimension to generate compressed behavior trajectory features after dimension reduction. Input the compressed behavior trajectory features into the activation function layer, and perform a non-linear transformation on the compressed behavior trajectory features through the activation function layer to generate a behavior trajectory feature vector in the form of a normalized probability distribution.

[0065] Assume that the preset embedding space dimension is 3D and the enhanced behavior trajectory features are 4D. Through the calculation of the feature projection layer, compress the 4D features to 3D to obtain the compressed behavior trajectory features after dimension reduction.

[0066] Exemplarily, the activation function layer adopts the Sigmoid function, and substitute each element value in the compressed behavior trajectory features into the Sigmoid function for calculation. Assume that the compressed behavior trajectory features are [0.2, 0.3, 0.4]. After calculation by the Sigmoid function, the behavior trajectory feature vector [0.5498, 0.5744, 0.6065] is obtained. These values are between 0 and 1, forming a behavior trajectory feature vector in the form of a normalized probability distribution, representing the probability distribution of different features in the entire behavior trajectory.

[0067] In a possible implementation manner, step S120 includes:

[0068] Step S126: Parse the target protocol field in the network access record, and extract the source address, target address, protocol type, and packet length in the target protocol field.

[0069] In an e-commerce platform, users access the e-commerce website through the network and use the HTTP protocol. From the network access record, the source address can be extracted. For example, the IP address of the user's mobile phone is 192.168.1.100, which is the identifier of the user device in the network. The target address is the IP address of the e-commerce platform server, assumed to be 202.100.100.100, which is the source of the user's requested data. The protocol type is HTTP, which stipulates the rules and formats of data transmission. The packet length is the size of the data in each network interaction process. For example, in a request to load a product picture, the packet length may be 300 bytes, and in a request to query an order, the packet length may be 500 bytes, etc.

[0070] Step S127: Generate address pair features based on the source address and the target address, and perform one-hot encoding on the protocol type to generate a protocol type encoding vector.

[0071] For example, combining the source address 192.168.1.100 and the destination address 202.100.100.100 to generate an address pair feature, which may include certain relationship features between the two addresses, such as the network segment difference of the addresses, the network area relationship, etc. One-hot encoding is performed on the protocol type. Since the protocol type is HTTP, assuming that three protocol types are set, namely HTTP, HTTPS, and FTP. HTTP is encoded as [1, 0, 0], indicating that the HTTP type is selected, while HTTPS and FTP are not selected. This encoding method can convert the protocol type into a vector form that can be processed by a computer for subsequent calculations.

[0072] Step S128, perform segmented statistics on the packet length to generate a packet length distribution histogram, and convert the packet length distribution histogram into a frequency domain feature vector.

[0073] Exemplarily, the packet length can be divided into different intervals. For example, 0 - 100 bytes is an interval, 101 - 200 bytes is an interval, 201 - 300 bytes is an interval, etc. Count the number of packets that appear in each interval. Assume that within a certain period of time, there are 5 times in the 0 - 100 byte interval, 10 times in the 101 - 200 byte interval, 8 times in the 201 - 300 byte interval, etc. Generate a packet length distribution histogram based on these statistical results. Then convert the packet length distribution histogram into a frequency domain feature vector, and this process requires operations such as discrete Fourier transform on the data in the histogram. For example, for the above histogram data, first calculate the frequency of each interval, and then convert these frequency values into a frequency domain feature vector through a specific algorithm. Specifically, calculate the proportion of the frequency of each interval in the total frequency. For example, the frequency proportion of the 0 - 100 byte interval is 5 / (5 + 10 + 8) = 5 / 23, the frequency proportion of the 101 - 200 byte interval is 10 / 23, the frequency proportion of the 201 - 300 byte interval is 8 / 23, etc. Combine these proportion values in a set order to form a frequency domain feature vector.

[0074] Step S129, perform feature fusion on the address pair feature, the protocol type encoding vector, and the frequency domain feature vector to obtain the original network behavior feature, and input the original network behavior feature into a convolutional neural network for local pattern extraction to generate the network behavior feature vector.

[0075] For example, the address pair feature can be a vector containing multiple elements, the protocol type encoding vector is [1, 0, 0], and the frequency domain feature vector is a vector calculated based on the packet length distribution. Add their corresponding elements or combine them according to other fusion rules to obtain the original network behavior feature, which contains comprehensive information related to the address, protocol type, and packet length in network access.

[0076] For example, in a possible implementation manner, step S129 includes:

[0077] Step S1291: Input the original network behavior features into a feature tensor conversion layer, and through the feature tensor conversion layer, align the address pair features, protocol type encoding vectors, and frequency domain feature vectors in the original network behavior features according to the feature dimensions and then convert them into a three-dimensional feature tensor.

[0078] Assume that the address pair feature is a 5-dimensional vector, the protocol type encoding vector is 3-dimensional, and the frequency domain feature vector is 4-dimensional. Align them according to the meaning and order of the features through the feature tensor conversion layer, and then convert them into a three-dimensional feature tensor, such as a three-dimensional tensor with a shape of (1, 5 + 3 + 4, 1). The first dimension 1 represents the batch size, here it is 1 sample, the second dimension is the combined feature dimension, and the third dimension 1 represents the number of channels is 1.

[0079] Step S1292: Input the three-dimensional feature tensor into a channel expansion layer, and through the channel expansion layer, perform a linear projection expansion on the channel dimension of the three-dimensional feature tensor to generate a channel expansion feature with a preset number of channels. Input the channel expansion feature into a first convolutional layer, and through the first convolutional layer, use multi-scale convolutional kernels to capture cross-channel local patterns of the channel expansion feature to generate a primary convolutional feature containing multi-scale spatial features. Input the primary convolutional feature into a spatial pyramid pooling layer, and through the spatial pyramid pooling layer, perform an adaptive pooling operation on the primary convolutional feature at different spatial resolutions to generate a downsampled feature with a fixed size. Input the downsampled feature into a depthwise separable convolutional layer, and through the depthwise separable convolutional layer, perform a separable feature extraction of spatial convolution in the depth direction and pointwise channel convolution on the downsampled feature to generate a depth feature. Input the depth feature into an atrous convolutional layer, and through the atrous convolutional layer, capture the context information with a stride based on a preset dilation rate for the depth feature to generate a context feature containing long-range dependencies.

[0080] Assume that the preset number of channels is 8. The channel expansion layer converts the three-dimensional feature tensor with the original number of channels 1 into a feature with 8 channels through a linear transformation. In this process, according to a preset linear transformation matrix, multiply each element by the coefficients in the matrix and add them to obtain the new element values, thereby expanding the channel dimension.

[0081] On this basis, convolution kernels of two scales, 3×3 and 5×5, are used. For the 3×3 convolution kernel, the convolution kernel is slid over each channel of the channel-expanded feature to calculate the convolution result. Taking a local area of the channel-expanded feature as an example, each element in the 3×3 convolution kernel is multiplied by the corresponding element of the channel-expanded feature at the corresponding position and then added together to obtain a new element value. Such an operation is performed on the entire channel-expanded feature to obtain a convolution result. Similarly, a 5×5 convolution kernel is used for a similar operation, and the results obtained by these two-scale convolution kernels are combined to generate primary convolution features containing multi-scale spatial features.

[0082] The spatial pyramid pooling layer can perform pooling on the primary convolution features according to different set resolutions, such as 1×1, 2×2, 4×4, etc. For 1×1 pooling, the maximum or average value of each 1×1 area of the primary convolution feature is taken as the downsampled element value; for 2×2 pooling, the elements in each 2×2 area of the primary convolution feature are processed to obtain a new element value; the same applies to 4×4 pooling. The results obtained by pooling at these different resolutions are combined to generate downsampled features with a fixed size.

[0083] After that, first, spatial convolution in the depth direction is performed, and convolution operations are independently performed on each channel of the downsampled feature. For example, a 3×3 convolution kernel is used for convolution on each channel to obtain the convolution result in the depth direction. Then, pointwise channel convolution is performed, and each element of the convolution result in the depth direction is convolved with a 1×1 convolution kernel. The results obtained from these two steps are combined to generate depth features.

[0084] Furthermore, assuming that the preset dilation rate is 2, there will be a gap between the elements of the convolution kernel when the dilated convolution layer performs convolution operations. Taking a 3×3 dilated convolution kernel as an example, the elements of the normal convolution kernel are closely adjacent, while there is a gap between the elements of the dilated convolution kernel. By performing convolution operations on the depth features in this way, long-range dependencies can be captured, and context features containing long-range dependencies are generated.

[0085] Step S1293: Concatenate the context features and the downsampled features in the channel dimension to generate enhanced context features, and input the enhanced context features into the batch normalization layer. The batch normalization layer performs mean-variance normalization processing on each channel of the enhanced context features to generate normalized features. The normalized features are input into the second convolution layer, and the second convolution layer uses a 1×1 convolution kernel to perform inter-channel non-linear interaction on the normalized features to generate high-dimensional interaction features.

[0086] For example, the context feature is a feature with 5 channels, and the downsampled feature is a feature with 3 channels. They are concatenated in the channel dimension to obtain an enhanced context feature with 8 channels. Then, the mean and variance of each channel of the enhanced context feature are calculated. For example, the element values of a certain channel are [1, 2, 3, 4, 5], the mean is 3, and the variance is 2. Then, each element is normalized according to the mean and variance. The new element value is (original element - mean) / standard deviation, where the standard deviation is the square root of the variance. Such an operation is performed on each channel to generate a normalized feature.

[0087] Further, the 1×1 convolutional kernel performs a convolution operation with the elements of the normalized feature on each channel. Since the size of the convolutional kernel is 1×1, it can achieve information interaction between channels. For example, for a certain element of the normalized feature, it is multiplied by the elements in the 1×1 convolutional kernel and then added together to obtain a new element value. Such an operation is performed on the entire normalized feature to generate a high-dimensional interaction feature.

[0088] Step S1294: Input the high-dimensional interaction feature into the global average pooling layer. The global average pooling layer compresses the spatial dimension of the high-dimensional interaction feature to generate a spatial aggregation feature vector. Input the spatial aggregation feature vector into the fully connected layer. The fully connected layer maps the dimension of the spatial aggregation feature vector to a preset semantic space dimension to generate a linear projection feature. Input the linear projection feature into the activation function layer. The activation function layer performs non-linear activation and probability normalization processing on the linear projection feature to generate the network behavior feature vector.

[0089] Assume that the high-dimensional interaction feature is a feature with a shape of (1, 4, 4). The global average pooling layer will calculate the average value of all elements on each channel to obtain a spatial aggregation feature vector with a shape of (1, 1, 1). Each element of this spatial aggregation feature vector is the average value of all elements on the corresponding channel.

[0090] Then, assume that the preset semantic space dimension is 3. The fully connected layer linearly combines the elements of the spatial aggregation feature vector through a preset weight matrix. For example, the spatial aggregation feature vector is [0.5], and the weight matrix is [[0.1, 0.2, 0.3]]. The calculation of the linear projection feature is 0.5×0.1 + 0.5×0.2 + 0.5×0.3 = 0.3, obtaining a linear projection feature with a dimension of 3.

[0091] Further, assume that the activation function is the Sigmoid function. For each element in the linear projection feature, such as the linear projection feature being [0.3, 0.4, 0.5], substitute each element into the Sigmoid function for calculation. The Sigmoid function is f(x) = 1 / (1 + exp(-x)). For the element 0.3, the calculation gives 1 / (1 + exp(-0.3)) ≈ 0.5744. Similarly, calculate other elements to obtain the network behavior feature vector. The element values of this network behavior feature vector are between 0 and 1, representing the probability situations of different features.

[0092] In a possible implementation manner, the risk assessment neural network is trained through the following steps:

[0093] Step S210, obtain a historical behavior data set, where the historical behavior data set includes historical multi-source behavior data of multiple users and corresponding risk labels.

[0094] In an e-commerce platform, the historical behavior data set covers historical multi-source behavior data of numerous users and corresponding risk labels. These historical multi-source behavior data include information such as the network access records, terminal operation logs, and application programming interface call sequences of users in the past period (such as in the past year). For example, the network access records contain the time, frequency, and source IP address of users accessing different product pages and promotion pages; the terminal operation logs record the operations of users on mobile or computer clients, such as the specific time and sequence of operations like searching for products, viewing product details, adding to the shopping cart, placing an order, and modifying an order; the application programming interface call sequences record the API calls involved in these operations, such as the call sequence and frequency of APIs like querying product inventory, calculating order prices, and verifying payment methods. The corresponding risk labels are marked according to the actual situation. For example, if a user account has had a risk of being stolen, it may be marked as "account theft risk"; if there has been a payment anomaly, it may be marked as "payment risk", etc.

[0095] Step S220, perform data cleaning on the historical multi-source behavior data, remove invalid data containing missing values or outliers, and perform normalization processing on the remaining valid data.

[0096] In a possible implementation manner, step S220 includes:

[0097] Step S221, detect the timestamp continuity in the historical multi-source behavior data, and perform interpolation repair on the log segments with time jumps.

[0098] In the terminal operation logs of an e-commerce platform, timestamps record the order and time intervals of user operations. For example, under normal circumstances, after a user views product details, they may add the product to the shopping cart or perform other related operations within a short period (such as within a few seconds to a few minutes). However, if there is a time jump, for instance, the time interval from one operation to the next suddenly changes from a few minutes to several days, this could be a data recording error or an abnormal situation. After detecting such a discontinuous timestamp, interpolation repair is required. Suppose a user views product details at 10 am, and the timestamp of the next operation record is 10 am the next day, with a time jump in between. Interpolation can be performed based on the types of the previous and subsequent operations and the average operation time interval. If the average time interval from viewing product details to adding to the shopping cart is 5 minutes, then a possible add-to-cart operation can be inserted around 10:05 am (assuming this operation conforms to the general user behavior pattern) to repair the continuity of the timestamp.

[0099] Step S222: Analyze the integrity of the protocol fields in the network access records and discard abnormal records that do not contain the necessary protocol headers.

[0100] In the network access of an e-commerce platform, the HTTP protocol is a commonly used protocol. The protocol fields contain important information such as the source address, destination address, protocol version, request method, etc. If a network access record does not contain the necessary protocol headers, such as lacking the source address, then this record is abnormal. For example, when analyzing a large number of network access records, it is found that a certain record only contains the destination address and partial request content, but no source address information. Such a record cannot accurately reflect the source and nature of the network access, so it needs to be discarded.

[0101] Step S223: Statistically analyze the distribution of operation types in the terminal operation logs and remove rare operation events whose occurrence frequencies are lower than a preset threshold.

[0102] For the operation types in the terminal operation logs, such as searching for products, viewing product details, placing orders, etc., count their occurrence frequencies in all user operations. Suppose the preset threshold is 1%. If there is an operation type, such as "customizing product evaluations (this operation may be relatively complex and rarely performed by users)", whose occurrence frequency in all operations is only 0.5%, lower than the preset threshold, then this operation event may be abnormal or unimportant and should be removed from the historical behavior data. Because such rare operations may be caused by system errors or individual special circumstances, they have a relatively small impact on the overall risk assessment and may interfere with model training.

[0103] Step S224: Verify the legality of the call sequence of the application program interface calls and delete abnormal sequences containing illegal call patterns.

[0104] In the application program interface call sequence of an e-commerce platform, there is a set logical order. For example, a normal order placement process could be to first call the API for querying product inventory, then call the API for calculating the order price, and then call the API for verifying the payment method, etc. If there is a call order such as first calling the API for verifying the payment method and then calling the API for querying product inventory, this is an illegal call pattern that does not conform to the normal business logic. When verifying the application program interface call sequence, if such an abnormal sequence containing an illegal call pattern is found, it will be deleted from the historical behavior data to ensure the accuracy and rationality of the data.

[0105] Step S225: Add a data integrity check code to the historical multi-source behavior data after cleaning, and mark the data that passes the check as valid data.

[0106] After completing the above cleaning steps, add a data integrity check code to each piece of historical multi-source behavior data. For example, the cyclic redundancy check (CRC) method can be used. For a piece of data combined with a cleaned network access record, terminal operation log, and application program interface call sequence, a check code is calculated through a specific CRC algorithm. When using the data later, the check code can be calculated again and compared with the previously added check code. If the check codes are the same, it indicates that the data is complete and has not been tampered with, and this kind of data is marked as valid data for subsequent model training.

[0107] Step S230: Divide the standardized valid data into a training set and a validation set, and construct an initial neural network model. The initial neural network model includes a behavior trajectory encoding branch and a network behavior encoding branch.

[0108] In an e-commerce scenario, the valid data after data cleaning and standardization is divided according to a set ratio (such as 80% for the training set and 20% for the validation set). Suppose there are a total of 1000 pieces of valid data, then 800 pieces will be used as the training set and 200 pieces as the validation set. The training set is used to train the neural network to enable the initial neural network model to learn the relationship between user behavior characteristics and risks; the validation set is used to evaluate the performance of the initial neural network model during the training process to prevent overfitting.

[0109] The constructed initial neural network model includes a behavioral trajectory encoding branch and a network behavior encoding branch. The behavioral trajectory encoding branch mainly processes features related to the user's behavioral trajectory extracted from the terminal operation logs and application programming interface call sequences, such as information about the user's operation order, operation frequency, etc. Its purpose is to predict user behavior risk categories, such as account theft risk, payment risk, etc. The network behavior encoding branch mainly processes features extracted from network access records, such as source address, target address, protocol type, etc. Its purpose is to predict network attack types, such as DDoS attacks, SQL injection attacks, etc. (Although in an e-commerce platform, a DDoS attack can be a malicious behavior targeting the server, and an SQL injection attack can be a malicious behavior such as attempting to steal database information, which is associated with user behavior risks).

[0110] Step S240, perform multi-task joint training on the initial neural network model using the training set, where the behavioral trajectory encoding branch is used to predict user behavior risk categories, and the network behavior encoding branch is used to predict network attack types.

[0111] In a possible implementation manner, step S240 includes:

[0112] Step S241, randomly sample a batch of multi-source behavior data samples from the training set, and input the multi-source behavior data samples into the behavioral trajectory encoding branch and the network behavior encoding branch respectively.

[0113] For example, during training, randomly sample a batch of data from an 800-item training set, assuming the batch size is 32. These 32 multi-source behavior data samples contain information such as network access records, terminal operation logs, and application programming interface call sequences. Input these 32 samples into the behavioral trajectory encoding branch and the network behavior encoding branch respectively. For example, for a sample, the operation order and operation frequency information in its terminal operation log are sent to the behavioral trajectory encoding branch, and the source address, target address, etc. information in the network access record are sent to the network behavior encoding branch.

[0114] Step S242, extract sample behavioral trajectory features through the behavioral trajectory encoding branch, and input the sample behavioral trajectory features into the first fully connected layer to generate the first risk prediction probability.

[0115] The behavioral trajectory encoding branch extracts features from information such as the input terminal operation logs and application programming interface call sequences. For example, for the operation sequence in the terminal operation logs, the operation sequence is transformed into a vector form through a certain encoding method. For the operation frequency, normalization processing is performed, etc., to obtain the sample behavioral trajectory features. Assume that the sample behavioral trajectory features are a vector with a dimension of 10. This vector is input into the first fully connected layer. The first fully connected layer has a set number of neurons (assume 5), and by calculating the weighted sum between each neuron and the elements of the input vector and passing through an activation function (such as the ReLU function), the first risk prediction probability is obtained. For example, for predicting the risk of account theft in the user behavior risk category, the calculated first risk prediction probability is 0.1, indicating that the model initially believes the probability of the sample having the risk of account theft is 0.1. This calculation process multiplies each element of the sample behavioral trajectory feature vector by the weight of the neurons in the first fully connected layer, then sums them up, and finally passes through the activation function to obtain the final probability value.

[0116] Step S243, extract the sample network behavior features through the network behavior encoding branch, and input the sample network behavior features into the second fully connected layer to generate the second risk prediction probability.

[0117] The network behavior encoding branch extracts features from network access records. For example, for the source address in the network access records, it is transformed into a feature vector through a certain mapping method. For the protocol type, one-hot encoding is performed, etc., to obtain the sample network behavior features. Assume that the sample network behavior features are a vector with a dimension of 8. This vector is input into the second fully connected layer. The second fully connected layer has a set number of neurons (assume 4), and through a similar calculation (the weighted sum between each neuron and the elements of the input vector and passing through the activation function), the second risk prediction probability is obtained. For example, for predicting the risk of DDoS attack in the network attack type, the calculated second risk prediction probability is 0.05, indicating that the model initially believes the probability of the sample having the risk of DDoS attack is 0.05.

[0118] Step S244, calculate the cross-entropy loss between the first risk prediction probability and the true risk label, and calculate the focal loss between the second risk prediction probability and the true attack type label.

[0119] Calculation of the cross-entropy loss between the first risk prediction probability and the true risk label. Assume that the risk of account theft in the true risk label is 1 (indicating risk), while the first risk prediction probability is 0.1. The calculation of the cross-entropy loss is based on the logarithmic function. First, calculate the logarithm when the prediction probability is 0.1, that is, -log(0.1) ≈ 2.3026. If the prediction probability is 1 (completely correct prediction), then -log(1) = 0. Therefore, the cross-entropy loss reflects the degree of difference between the prediction probability and the true label. Here, the cross-entropy loss is relatively large, indicating a large gap between the prediction result and the true result.

[0120] Calculation of the focal loss between the second risk prediction probability and the true attack type label. The focal loss is an improved loss function used to handle the problem of data imbalance. Assume that the DDoS attack in the true attack type label is 1, while the second risk prediction probability is 0.05. The calculation of the focal loss is relatively complex, which takes into account the relationship between the prediction probability and the true label as well as a modulation factor. The focal loss will be adjusted according to the proximity between the prediction probability and the true label, making the model pay more attention to difficult-to-classify samples during training.

[0121] Step S245: Perform weighted summation on the cross-entropy loss and the focal loss to obtain the total loss function, and update the weight parameters of the initial neural network model according to the backpropagation of the total loss function.

[0122] Assume that the weight of the cross-entropy loss is 0.6 and the weight of the focal loss is 0.4. Multiply the cross-entropy loss by 0.6, multiply the focal loss by 0.4, and then add them to obtain the total loss function. For example, if the cross-entropy loss is 2.3026 and the focal loss is 1.5 (assumed value), then the total loss function is 2.3026×0.6 + 1.5×0.4 = 1.3816 + 0.6 = 1.9816. Update the weight parameters of the initial neural network model according to the backpropagation of the total loss function. Backpropagation propagates the error from the output layer (where the loss is calculated) towards the input layer direction, and adjusts the weight parameters of each layer according to the error. For example, for the first fully connected layer in the behavioral trajectory encoding branch, calculate the gradient of each weight parameter according to the total loss function (this calculation process involves taking the partial derivative of the total loss function with respect to each weight parameter), and then according to the gradient descent algorithm, update the weight parameters according to the set learning rate (assume the learning rate is 0.01), that is, the new weight parameter = the old weight parameter - the learning rate × the gradient. Similar weight parameter update operations are also performed on the second fully connected layer in the network behavior encoding branch.

[0123] Step S250: Calculate the classification loss function and the adversarial loss function of the initial neural network model after multi-task joint training on the validation set, and optimize the parameters of the initial neural network model through the gradient descent algorithm until the classification loss function and the adversarial loss function converge, obtaining the trained risk assessment neural network.

[0124] In a possible implementation manner, step S250 includes:

[0125] Step S251: Input the sample behavior trajectory features into the adversarial discriminator, and output the discrimination probability that the sample behavior trajectory features belong to real user behaviors through the adversarial discriminator.

[0126] For example, among the 200 pieces of data in the validation set, take the sample behavior trajectory features of one piece of data (this feature was extracted by the behavior trajectory encoding branch during the previous training process), and input it into the adversarial discriminator. The adversarial discriminator is a module specifically used to determine whether a sample is real user behavior. For example, the adversarial discriminator makes a judgment based on information such as the operation sequence and operation frequency in the sample behavior trajectory features. If the operation sequence conforms to the shopping process of a normal user and the operation frequency is also within a reasonable range, then it may output a relatively high discrimination probability, assumed to be 0.8, indicating that the discriminator believes the probability that the sample behavior trajectory features belong to real user behavior is 0.8.

[0127] Step S252: Input the sample network behavior features into the adversarial discriminator, and output the discrimination probability that the sample network behavior features belong to normal network activities through the adversarial discriminator.

[0128] Similarly, take the sample network behavior features of one piece of data in the validation set (extracted by the network behavior encoding branch), and input it into the adversarial discriminator. The adversarial discriminator makes a judgment based on information such as the source address, target address, and protocol type in the sample network behavior features. If the source address is a normal user IP address, the target address is a legal e-commerce platform server address, and the protocol type is also the normal HTTP protocol, etc., then it may output a relatively high discrimination probability, assumed to be 0.9, indicating that the discriminator believes the probability that the sample network behavior features belong to normal network activities is 0.9.

[0129] Step S253: Calculate the mean square error between the discrimination probability and the preset true label to obtain the discrimination loss of the adversarial discriminator.

[0130] Regarding the discrimination probability of the sample behavior trajectory features, assume that the preset true label is 1 (indicating real user behavior) and the discrimination probability is 0.8. The mean squared error is calculated by first calculating the square of the difference, i.e., (0.8 - 1)^2 = 0.04. Regarding the discrimination probability of the sample network behavior features, assume that the preset true label is 1 (indicating normal network activity) and the discrimination probability is 0.9, and the mean squared error is (0.9 - 1)^2 = 0.01. Add these two mean squared errors (if there are more samples, it needs to be averaged according to the number of samples) to obtain the discrimination loss of the adversarial discriminator. Here, the discrimination loss is 0.04 + 0.01 = 0.05.

[0131] Step S254, generate the adversarial gradient output by the gradient reversal layer according to the discrimination loss, and backpropagate the adversarial gradient to the behavior trajectory encoding branch and the network behavior encoding branch.

[0132] Calculate the adversarial gradient output by the gradient reversal layer according to the discrimination loss (this calculation process involves taking partial derivatives of the discrimination loss with respect to the parameters of the behavior trajectory encoding branch and the network behavior encoding branch). Assume that the calculated adversarial gradient is a vector containing the parameter adjustment values related to the behavior trajectory encoding branch and the network behavior encoding branch. Backpropagate this adversarial gradient to the behavior trajectory encoding branch and the network behavior encoding branch. For example, for the weight parameter of a certain neuron in the behavior trajectory encoding branch, adjust it according to the corresponding value in the adversarial gradient, and make a similar adjustment for the weight parameter of a certain neuron in the network behavior encoding branch.

[0133] Step S255, adjust the feature extraction parameters of the behavior trajectory encoding branch and the network behavior encoding branch through the adversarial gradient to reduce the sensitivity of the risk assessment neural network to adversarial samples.

[0134] In the behavior trajectory encoding branch, adjust the feature extraction parameters according to the backpropagated adversarial gradient. For example, if the weight parameter in the encoding method of a certain operation sequence needs to be adjusted, then modify it according to the value of the adversarial gradient. If the adversarial gradient indicates that a certain weight parameter should be decreased, then decrease it appropriately. Similar operations are also performed in the network behavior encoding branch. This can enable the model to more accurately identify when facing possible adversarial samples (such as maliciously constructed samples that are close to normal but have risks), reduce the sensitivity to adversarial samples, and improve the robustness of the model. By continuously repeating the above calculation and adjustment process on the validation set until the classification loss function and the adversarial loss function converge, a trained risk assessment neural network is obtained.

[0135] In a possible implementation manner, step S140 includes:

[0136] Step S141: Traverse each risk category in the behavioral risk probability distribution, extract the risk category identifiers with probability values exceeding the preset threshold, and generate a candidate risk set.

[0137] In the risk assessment scenario of an e-commerce platform, assume that the behavioral risk probability distribution includes categories such as account theft risk, payment risk, and commodity information leakage risk. The preset threshold is set to 0.05. After traversing the behavioral risk probability distribution, if the probability value of the account theft risk is 0.1, the probability value of the payment risk is 0.06, and the probability value of the commodity information leakage risk is 0.03, then the probability values of the account theft risk and the payment risk exceed the preset threshold, and their risk category identifiers are extracted, thus generating a candidate risk set containing the account theft risk and the payment risk.

[0138] Step S142: According to each risk category identifier in the candidate risk set, obtain the corresponding weight factor and association impact matrix from the predefined risk metadata database. The association impact matrix represents the superposition effect intensity between different risk categories.

[0139] For example, for the account theft risk, its weight factor is found to be 0.8 in the risk metadata database, indicating that this risk has a relatively high importance in the overall risk assessment. For the payment risk, its weight factor is 0.6. The association impact matrix represents the superposition effect intensity between different risk categories. In the e-commerce environment, there is a strong association between the account theft risk and the payment risk. For example, an account theft may directly lead to an increase in the payment risk. Therefore, in the association impact matrix, the superposition effect intensity between them may be 0.5, indicating a relatively high degree of mutual influence between the two.

[0140] Step S143: Perform weighted calculation on the weight factor of each risk category identifier and its probability value to generate an independent risk contribution value, and calculate the collaborative risk gain value based on the interaction relationship between the risk categories in the candidate risk set in the association impact matrix.

[0141] For example, for the account theft risk, its probability value is 0.1 and the weight factor is 0.8. The weighted calculation gives an independent risk contribution value of 0.1×0.8 = 0.08. For the payment risk, the probability value is 0.06 and the weight factor is 0.6, and the independent risk contribution value is 0.06×0.6 = 0.036. When calculating the collaborative risk gain value, since the superposition effect intensity between the account theft risk and the payment risk is 0.5, first calculate the product of their independent risk contribution values, that is, 0.08×0.036 = 0.00288, and then multiply it by the superposition effect intensity 0.5 to obtain a collaborative risk gain value of 0.00288×0.5 = 0.00144.

[0142] Step S144: Add all the independent risk contribution values to the collaborative risk gain value to obtain a comprehensive risk evaluation value, and input the comprehensive risk evaluation value into a piecewise mapping function to determine the corresponding discretized risk level number according to the preset level division intervals.

[0143] Here, the independent risk contribution values are 0.08 and 0.036 respectively, and the collaborative risk gain value is 0.00144. The sum is the comprehensive risk evaluation value 0.08 + 0.036 + 0.00144 = 0.11744. Then input the comprehensive risk evaluation value into the piecewise mapping function to determine the corresponding discretized risk level number according to the preset level division intervals. Suppose the preset level division intervals are: 0 - 0.05 is the low risk level number 1, 0.05 - 0.15 is the medium risk level number 2, and above 0.15 is the high risk level number 3. Since the comprehensive risk evaluation value 0.11744 is between 0.05 and 0.15, the corresponding discretized risk level number is determined to be 2.

[0144] Step S145: Query the early warning signal template library according to the discretized risk level number, and extract the early warning signal format framework and filling field rules that match the discretized risk level number.

[0145] For example, for the risk level number 2, the early warning signal format framework queried from the early warning signal template library may be "Risk description: [risk description text], Mitigation strategy: [mitigation strategy items], Risk level: [risk level number]". The filling field rules specify the filling method for each field. For example, the risk description text needs to accurately describe the risk content, and the mitigation strategy items need to list the countermeasures in the set order, etc.

[0146] Step S146: Obtain the description text and mitigation strategy items of each risk category in the candidate risk set from the risk knowledge base, and insert the description text into the corresponding placeholder of the early warning signal format framework according to the filling field rules to generate the original early warning signal text.

[0147] For example, for the risk of account theft, the description text may be "Abnormal login behavior of the account is detected. It may have been stolen, and there are unauthorized access attempts", and the mitigation strategy entry is "Immediately freeze the account, notify the user to modify the password, and add login verification methods (such as SMS verification codes or fingerprint recognition)". For payment risks, the description text is "There are abnormalities in the payment process, and there may be a risk of financial loss", and the mitigation strategy entry is "Suspend unfinished payment transactions, check the security of the payment channels, and notify the user to verify the payment information". Insert the description text into the corresponding placeholders of the warning signal format framework according to the filling field rules to generate the original warning signal text. According to the previous format framework and filling rules, the original warning signal text is "Risk description: Abnormal login behavior of the account is detected. It may have been stolen, and there are unauthorized access attempts; there are abnormalities in the payment process, and there may be a risk of financial loss. Mitigation strategy: Immediately freeze the account, notify the user to modify the password, and add login verification methods (such as SMS verification codes or fingerprint recognition); suspend unfinished payment transactions, check the security of the payment channels, and notify the user to verify the payment information. Risk level: 2".

[0148] Step S147, perform a syntax structure check on the original warning signal text, correct semantic conflicts and logical breakpoints, and generate compliant warning signal content.

[0149] In the original warning signal text, there may be some grammar or logical problems. For example, the sentence structure may not be clear enough, or the logical coherence is insufficient when describing multiple risks. Through the syntax structure check, the sentences are adjusted and optimized. If it is found that the description "Abnormal login behavior of the account is detected. It may have been stolen, and there are unauthorized access attempts; there are abnormalities in the payment process, and there may be a risk of financial loss" is somewhat complex and unclear semantically, it can be adjusted to "Abnormal login behavior of the account is detected. It may have been stolen and there are unauthorized access attempts, and at the same time there are abnormalities in the payment process, and there may be a risk of financial loss". After such correction, compliant warning signal content is generated.

[0150] Step S148, encode the current timestamp and the risk level number into the protocol header identification segment, and splice the compliant warning signal content with the protocol header identification segment to generate the final warning signal carrying the integrity label.

[0151] Assume the current timestamp is 15:30 on October 1, 2023. It is encoded with the risk level number 2 according to a specific encoding method. For example, the timestamp is converted into a numerical form and then combined with the risk level number to form the protocol header identification segment. Assume the encoded protocol header identification segment is "202310011530_2". The protocol header identification segment is concatenated with the content of the compliance warning signal, and an integrity tag is added during the concatenation process. The integrity tag can be a check value calculated through a certain encryption algorithm, which is used to ensure the integrity of the signal during transmission. The final warning signal carrying the integrity tag includes the protocol header identification segment, the content of the compliance warning signal, and the integrity tag, so as to accurately convey risk information and ensure the integrity and accuracy of the information in the security management system of the e-commerce platform.

[0152] In a possible implementation manner, step S150 includes:

[0153] Step S151, parse out the risk level number and the embedded timestamp from the protocol header identification segment of the warning signal, and extract the corresponding transmission protocol type and priority encoding from the risk policy library based on the risk level number.

[0154] In this embodiment, assume the protocol header identification segment of the warning signal is "202310011530_2". Through a specific parsing algorithm, the risk level number 2 and the timestamp 15:30 on October 1, 2023 are decomposed. Then, based on the risk level number 2, the corresponding information is searched in the risk policy library. The risk policy library contains information such as the transmission protocol type and priority encoding under different risk levels. For the risk level number 2 (medium risk level), the corresponding transmission protocol type is found to be the Secure Sockets Layer protocol (SSL), which is a protocol commonly used to ensure secure data transmission in the e-commerce environment. At the same time, the priority encoding is found to be 2, indicating medium priority.

[0155] Step S152, verify the validity of the digital signature of the final warning signal. If the signature verification fails, trigger a data integrity alarm and terminate the transmission process. Otherwise, extract the risk description text field and the risk mitigation strategy field from the content of the compliance warning signal.

[0156] In an e-commerce platform, a digital signature of a warning signal is generated using a specific digital signature algorithm. During verification, the same algorithm and key are used to calculate the warning signal, obtaining a calculation result, which is then compared with the original digital signature. If the two are consistent, it indicates that the digital signature is valid; if they are inconsistent, for example, there are differences between the calculation result and the original digital signature, this indicates that the warning signal may have been tampered with during transmission. At this time, a data integrity alarm is triggered and the transmission process is terminated. In this scenario, assume that the digital signature verification passes and subsequent operations are continued. The risk description text field and the risk mitigation strategy field in the content of the compliant warning signal are extracted. For example, the content of the compliant warning signal is "Risk description: Abnormal login behavior of the account is detected, it may have been stolen and there are unauthorized access attempts. At the same time, there are abnormalities in the payment process, and there may be a risk of financial loss. Mitigation strategy: Immediately freeze the account, notify the user to modify the password, and increase the login verification method (such as SMS verification code or fingerprint recognition); Pause the unfinished payment transaction, check the security of the payment channel, and notify the user to verify the payment information. Risk level: 2". From this, the risk description text field "Abnormal login behavior of the account is detected, it may have been stolen and there are unauthorized access attempts. At the same time, there are abnormalities in the payment process, and there may be a risk of financial loss" and the risk mitigation strategy field "Immediately freeze the account, notify the user to modify the password, and increase the login verification method (such as SMS verification code or fingerprint recognition); Pause the unfinished payment transaction, check the security of the payment channel, and notify the user to verify the payment information" are extracted.

[0157] Step S153, convert the risk description text field into a formatted text stream that conforms to the target communication protocol according to the type of the transmission protocol, and split the risk mitigation strategy field into independent policy entries and number them according to the execution order.

[0158] For example, since the type of the transmission protocol is SSL, the risk description text field needs to be formatted according to the requirements of the SSL protocol. For example, the SSL protocol may require specific encoding and format adjustments for the text, convert the characters in the risk description text into the encoding format specified by the SSL protocol, such as UTF-8 encoding, and organize them according to the set text structure to form a formatted text stream. For the risk mitigation strategy field, it is split into independent policy entries. For example, "Immediately freeze the account" is the first entry, numbered 1; "Notify the user to modify the password" is the second entry, numbered 2; "Increase the login verification method (such as SMS verification code or fingerprint recognition)" is the third entry, numbered 3; "Pause the unfinished payment transaction" is the fourth entry, numbered 4; "Check the security of the payment channel" is the fifth entry, numbered 5; "Notify the user to verify the payment information" is the sixth entry, numbered 6.

[0159] Step S154, encapsulate the formatted text stream and the numbered policy entries to generate an alarm transmission data packet containing a protocol header identification segment, a risk level number, and a timestamp, and append a checksum field to the end of the alarm transmission data packet.

[0160] Specifically, the formatted risk description text stream and the numbered risk mitigation policy entries can be combined according to a set structure. For example, first place the formatted text stream, and then successively place the numbered policy entries. Then add the protocol header identification segment "202310011530_2", the risk level number 2, and the timestamp 15:30 on October 1, 2023 to form an alarm transmission data packet. To ensure the accuracy of data transmission, a checksum field is appended to the end of the alarm transmission data packet. The process of calculating the checksum is to calculate all the data in the data packet (including the protocol header identification segment, risk description text, risk mitigation policy, risk level number, and timestamp, etc.) according to a specific algorithm (such as the cyclic redundancy check algorithm CRC) to obtain a checksum value, and add it to the end of the data packet.

[0161] Step S155, activate the corresponding transmission channel in the real-time alarm module according to the priority encoding, and load the alarm transmission data packet into the send buffer of the transmission channel.

[0162] For example, since the priority encoding is 2 (medium priority), in the real-time alarm module, there are transmission channels corresponding to different priorities. Find the transmission channel corresponding to medium priority and load the generated alarm transmission data packet into the send buffer of this transmission channel. This send buffer is a temporary storage area for preprocessing data before sending.

[0163] Step S156, perform byte stream fragmentation processing on the alarm transmission data packet in the send buffer to generate multiple equal-length data fragments and add a fragment sequence identifier to each data fragment.

[0164] Suppose the total length of the alarm transmission data packet is 1000 bytes. According to the requirements of the transmission protocol, it is divided into equal-length data fragments. For example, the length of each data fragment is 100 bytes, so 10 data fragments can be obtained. For each data fragment, add a fragment sequence identifier from 1 to 10 so that the data fragments can be reassembled in the correct order at the receiving end.

[0165] Step S157, based on the retransmission mechanism rules defined by the transmission protocol type, inject the data fragments into the network interface queue of the transmission channel in the order of sequence identifiers, and trigger the network interface queue to initiate an asynchronous transmission request to the preset receiving port of the security management terminal.

[0166] For example, for the SSL protocol, its retransmission mechanism rules specify how to perform retransmission when a data fragment is lost or transmitted incorrectly during data transmission. In the order of the fragment sequence identifiers, the data fragments are injected into the network interface queue of the transmission channel one by one. For example, first inject the data fragment with the identifier 1, then inject the data fragment with the identifier 2, and so on. After all the data fragments are injected into the network interface queue, an asynchronous transmission request is triggered from the network interface queue to the preset receiving port of the security management terminal. The asynchronous transmission request means that while sending data, it is not necessary to wait for the response from the receiving end and other operations can be continued, which can improve the efficiency of data transmission and ensure that the risk description text and risk mitigation strategies can be transmitted to the security management terminal in a timely and accurate manner so that security administrators can take corresponding measures in the e-commerce platform to deal with risks.

[0167] Figure 2 FIG. shows a schematic diagram of exemplary hardware and software components of a deep learning-based risk behavior perception device 100 that can implement the ideas of the present application provided by some embodiments of the present application. For example, the processor 120 can be used on the deep learning-based risk behavior perception device 100 and is used to execute the functions in the present application.

[0168] The deep learning-based risk behavior perception device 100 can be a general-purpose server or a special-purpose server, both of which can be used to implement the deep learning-based risk behavior perception method of the present application. Although only one server is shown in the present application, for convenience, the functions described in the present application can be implemented in a distributed manner on multiple similar platforms to balance the processing load.

[0169] For example, the deep learning-based risk behavior perception device 100 can include a network port 110 connected to the network, one or more processors 120 for executing program instructions, a communication bus 130, and different forms of storage media 140, such as disks, ROM, or RAM, or any combination thereof. Exemplarily, the deep learning-based risk behavior perception device 100 can also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The method of the present application can be implemented according to these program instructions. The deep learning-based risk behavior perception device 100 also includes an input / output (I / O) interface 150 between the computer and other input / output devices.

[0170] For ease of explanation, only one processor is described in the deep learning-based risk behavior perception device 100. However, it should be noted that the deep learning-based risk behavior perception device 100 in the present application may also include multiple processors. Therefore, the steps performed by one processor described in the present application may also be jointly performed or separately performed by multiple processors. For example, if the processor of the deep learning-based risk behavior perception device 100 performs step A and step B, it should be understood that step A and step B may also be jointly performed by two different processors or separately performed in one processor. For example, the first processor performs step A, the second processor performs step B, or the first processor and the second processor jointly perform steps A and B.

[0171] In addition, an embodiment of the present invention further provides a readable storage medium, in which computer-executable instructions are preset. When the processor executes the computer-executable instructions, the above deep learning-based risk behavior perception method is implemented.

[0172] It should be noted that, in order to simplify the description of the present invention disclosure and thus help the understanding of one or more embodiments of the invention, in the foregoing description of the embodiments of the present invention, sometimes multiple features are merged into one embodiment, drawing, or description thereof.

Claims

1. A risk behavior perception method based on deep learning, characterized in that: The method comprises: Collecting multi-source behavior data of the target user within a preset time window, wherein the multi-source behavior data includes network access records, terminal operation logs, and application program interface call sequences; Extracting spatiotemporal features from the multi-source behavior data to generate a behavior trajectory feature vector of the target user, and performing protocol parsing on the network access record to obtain a network behavior feature vector; Inputting the behavior trajectory feature vector and the network behavior feature vector into a pre-trained risk assessment neural network, and jointly encoding the behavior trajectory feature vector and the network behavior feature vector through the risk assessment neural network to generate a behavior risk probability distribution of the target user; Determine the risk level of the target user based on the risk category exceeding a preset threshold in the behavior risk probability distribution, and generate a warning signal corresponding to the risk level; Triggering a real-time alarm module according to the early warning signal, sending a risk description text and a risk mitigation strategy corresponding to the risk level to the security management terminal; The extracting spatiotemporal features of the multi-source behavior data to generate a behavior trajectory feature vector of the target user includes: Extracting a timestamp sequence and an operation type label of an operation event from the terminal operation log, converting the timestamp sequence into a time interval distribution histogram, and mapping the operation type label into an operation semantic vector; Extracting an interface call frequency matrix from the application program interface call sequence, and performing sliding window statistics on the interface call frequency matrix to generate interface call pattern features; Performing feature splicing on the time interval distribution histogram, the operation semantic vector and the interface call pattern feature to obtain an initial behavior trajectory feature; Performing dimensionality reduction processing on the initial behavior trajectory features, removing redundant dimensions in the initial behavior trajectory features, and generating compressed intermediate behavior trajectory features; Inputting the intermediate behavior trajectory features into a spatiotemporal attention module, and performing weighted fusion of the temporal dependency and spatial correlation in the intermediate behavior trajectory features through the spatiotemporal attention module to generate the behavior trajectory feature vector; The performing protocol parsing on the network access record to obtain a network behavior feature vector includes: Parsing the target protocol field in the network access record, extracting the source address, target address, protocol type and data packet length in the target protocol field; Generate an address pair feature according to the source address and the target address, and perform one-hot encoding on the protocol type to generate a protocol type encoding vector; Performing segmented statistics on the length of the data packet to generate a data packet length distribution histogram, and converting the data packet length distribution histogram into a frequency domain feature vector; Performing feature fusion on the address pair feature, the protocol type encoding vector and the frequency domain feature vector to obtain the original network behavior feature; The original network behavior features are input into a convolutional neural network to extract local patterns, thereby generating the network behavior feature vector.

2. The risk behavior perception method based on deep learning according to claim 1 is characterized in that: The risk assessment neural network is trained by the following steps: Acquire a historical behavior data set, wherein the historical behavior data set includes historical multi-source behavior data of multiple users and corresponding risk labels; Performing data cleaning on the historical multi-source behavior data, removing invalid data containing missing values ​​or outliers, and standardizing the remaining valid data; Dividing the standardized valid data into a training set and a validation set, and constructing an initial neural network model, wherein the initial neural network model includes a behavior trajectory encoding branch and a network behavior encoding branch; Performing multi-task joint training on the initial neural network model through the training set, wherein the behavior trajectory encoding branch is used to predict the user behavior risk category, and the network behavior encoding branch is used to predict the network attack type; The classification loss function and the adversarial loss function of the initial neural network model after multi-task joint training are calculated on the verification set, and the parameters of the initial neural network model are optimized by the gradient descent algorithm until the classification loss function and the adversarial loss function converge, thereby obtaining the trained risk assessment neural network.

3. The risk behavior perception method based on deep learning according to claim 2 is characterized in that: The data cleaning of the historical multi-source behavior data to remove invalid data containing missing values ​​or abnormal values ​​includes: Detecting the continuity of timestamps in the historical multi-source behavior data, and performing interpolation repair on log segments with time jumps; Analyzing the integrity of the protocol fields in the network access records and discarding abnormal records that do not contain necessary protocol headers; Counting the distribution of operation types in the terminal operation log, and removing rare operation events whose occurrence frequency is lower than a preset threshold; Verify the legality of the calling sequence of the application program interface calling sequence, and delete abnormal sequences containing illegal calling patterns; Add data integrity check codes to the cleaned historical multi-source behavior data, and mark the data that passes the check as valid data.

4. The risk behavior perception method based on deep learning according to claim 2 is characterized in that: The performing multi-task joint training on the initial neural network model through the training set includes: Randomly sampling a batch of multi-source behavior data samples from the training set, and inputting the multi-source behavior data samples into the behavior trajectory encoding branch and the network behavior encoding branch respectively; Extracting sample behavior trajectory features through the behavior trajectory encoding branch, and inputting the sample behavior trajectory features into a first fully connected layer to generate a first risk prediction probability; Extracting sample network behavior features through the network behavior encoding branch, and inputting the sample network behavior features into the second fully connected layer to generate a second risk prediction probability; Calculating the cross entropy loss between the first risk prediction probability and the true risk label, and calculating the focal loss between the second risk prediction probability and the true attack type label; The cross entropy loss and the focal loss are weightedly summed to obtain a total loss function, and the weight parameters of the initial neural network model are updated by backpropagation according to the total loss function.

5. The risk behavior perception method based on deep learning according to claim 4 is characterized in that: The step of calculating the classification loss function and the adversarial loss function of the initial neural network model after multi-task joint training on the verification set includes: Inputting the sample behavior trajectory feature into an adversarial discriminator, and outputting the discrimination probability that the sample behavior trajectory feature belongs to the real user behavior through the adversarial discriminator; Inputting the sample network behavior feature into the adversarial discriminator, and outputting the discrimination probability that the sample network behavior feature belongs to normal network activity through the adversarial discriminator; Calculate the mean square error between the discrimination probability and the preset true label to obtain the discrimination loss of the adversarial discriminator; Generate an adversarial gradient output by a gradient reversal layer according to the discriminant loss, and back-propagate the adversarial gradient to the behavior trajectory encoding branch and the network behavior encoding branch; The feature extraction parameters of the behavior trajectory encoding branch and the network behavior encoding branch are adjusted by the adversarial gradient to reduce the sensitivity of the risk assessment neural network to adversarial samples.

6. The risk behavior perception method based on deep learning according to claim 1 is characterized in that: The step of determining the risk level of the target user based on the risk category exceeding a preset threshold in the behavior risk probability distribution, and generating a warning signal corresponding to the risk level, includes: Traversing each risk category in the behavior risk probability distribution, extracting risk category identifiers whose probability values ​​exceed the preset threshold, and generating a candidate risk set; According to each risk category identifier in the candidate risk set, a corresponding weight factor and an association influence matrix are obtained from a predefined risk metadata database, wherein the association influence matrix represents the superposition intensity between different risk categories; The weight factor and probability value of each risk category identifier are weighted and calculated to generate an independent risk contribution value, and the collaborative risk gain value is calculated based on the interaction relationship between each risk category in the candidate risk set in the association impact matrix; Add all independent risk contribution values ​​to the collaborative risk gain value to obtain a comprehensive risk evaluation value, and input the comprehensive risk evaluation value into a segmented mapping function to determine the corresponding discretized risk level number according to a preset level division interval; Querying the warning signal template library according to the discretized risk level number, extracting the warning signal format framework and filling field rules matching the discretized risk level number; Obtaining description text and mitigation strategy entries of each risk category in the candidate risk set from the risk knowledge base, inserting the description text into corresponding placeholders of the warning signal format framework according to the fill field rule, and generating original warning signal text; Performing grammatical structure check on the original warning signal text, correcting semantic conflicts and logical breakpoints, and generating compliant warning signal content; The current timestamp and the risk level number are encoded as a protocol header identification segment, and the compliance warning signal content is data-joined with the protocol header identification segment to generate a final warning signal carrying an integrity tag.

7. The risk behavior perception method based on deep learning according to claim 6 is characterized in that: The triggering of the real-time alarm module according to the early warning signal to send the risk description text and risk mitigation strategy corresponding to the risk level to the security management terminal includes: Parsing the risk level number and the embedded timestamp from the protocol header identification segment of the warning signal, and extracting the corresponding transmission protocol type and priority code from the risk policy library based on the risk level number; Verify the validity of the digital signature of the final warning signal, and if a signature verification failure is detected, trigger a data integrity alarm and terminate the transmission process, otherwise extract the risk description text field and risk mitigation strategy field in the content of the compliance warning signal; converting the risk description text field into a formatted text stream that complies with the target communication protocol according to the transmission protocol type, and splitting the risk mitigation strategy field into independent strategy entries and numbering them in execution order; Data encapsulation is performed on the formatted text stream and the numbered policy entries to generate an alarm transmission data packet including a protocol header identification segment, a risk level number and a timestamp, and a checksum field is appended to the end of the alarm transmission data packet; activating a corresponding transmission channel in a real-time alarm module according to the priority code, and loading the alarm transmission data packet into a sending buffer of the transmission channel; Performing byte stream slicing processing on the alarm transmission data packet in the sending buffer to generate a plurality of data slices of equal length and adding a slice sequence identifier to each data slice; Based on the retransmission mechanism rules defined by the transmission protocol type, the data fragments are injected into the network interface queue of the transmission channel in sequence identifier order, triggering the network interface queue to initiate an asynchronous transmission request to the preset receiving port of the security management terminal.

8. A risk behavior perception device based on deep learning, characterized in that: The risk behavior perception device based on deep learning includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the risk behavior perception method based on deep learning as described in any one of claims 1 to 7 above.

Citation Information

Patent Citations

  • Behavior characteristics-based network attack detection method and device

    CN105471882A

  • Abnormity detection method and apparatus based on log graph modeling

    CN108833348A