Microcomputer host system safety control method, device and medium

By analyzing the user log data collected by the microcomputer host system, combined with technical means such as FP-Tree, VAE, Mahayana distance and HMM, we can identify and distinguish between normal access and abnormal access, and solve the problem that traditional security protection methods are difficult to identify complex abnormal access patterns, achieving higher detection accuracy and response capabilities.

CN119939635AActive Publication Date: 2025-05-06SHENZHEN MEIGAO ELECTRONICS EQUIP CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510416919.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-05-06
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Traditional security protection methods based on static rules cannot effectively identify complex abnormal access patterns, and it is difficult to conduct intelligent abnormal detection based on user access behavior characteristics, resulting in the lack of an effective response mechanism when the system faces the threat of zero-day attacks and hidden penetration.

Method used

By collecting user log data, converting it into transaction data to calculate the frequency of occurrence, filtering the set of frequent items, calculating the support degree of the conditional pattern basis, using the FP-Tree algorithm for recursive expansion, calculating the confidence of different resource combinations, building access feature vectors, extracting probability density using VAE encoder, calculating Mahayana distance, applying hidden Markov model HMM and Viterbi algorithm to distinguish between normal access and abnormal access, and finally two-factor authentication is performed.

Benefits of technology

It improves detection accuracy, can automatically distinguish stable access modes and abnormal access modes, avoid local misjudgment, ensures that the final access status judgment is more accurate, and enhances the system's response ability in the face of zero-day attacks and hidden penetration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939635A_ABST
    Figure CN119939635A_ABST
Patent Text Reader

Abstract

The invention discloses a micro computer host system security control method and device and a medium, and relates to the technical field of security control, and the method comprises the steps: accessing a micro computer host system to collect user log data, converting a user access behavior into transaction data, and calculating the occurrence frequency; the frequent item set is screened, the support degree of a conditional pattern base is calculated through the conditional pattern base, recursive expansion is conducted according to an FP-Tree algorithm to calculate the superposition support degree, the confidence degree of different resource combinations is calculated, and the high-confidence-degree access sequence is screened. According to the method, the support degree of the conditional mode base is calculated through recursion, it is ensured that only access modes with high correlation are reserved in the FP-Tree structure, the probability density of the access modes is calculated based on standard normal distribution, it is ensured that the low-probability access modes obtain higher abnormal scores, and therefore the detection accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security control technology, and in particular to a microcomputer host system security control method, device and medium. Background Art

[0002] With the popularization of Internet technology and the increase in remote access needs, microcomputer host systems are facing increasingly severe security threats, including unauthorized access, malware attacks, data theft, identity fraud, and abnormal operation behaviors. These problems are emerging one after another, seriously threatening the normal operation of the system and data security. Existing security control technologies mainly rely on traditional access control lists (ACLs), static rule configurations, and intrusion detection systems (IDS) based on feature matching to manage user access rights. However, traditional security protection methods based on static rules cannot effectively identify complex abnormal access patterns. Secondly, existing technologies make it difficult to perform intelligent anomaly detection based on user access behavior characteristics, resulting in the system lacking an effective response mechanism when facing the threat of zero-day attacks and covert infiltration. Summary of the invention

[0003] In view of the above existing problems, the present invention is proposed.

[0004] Therefore, the present invention provides a microcomputer host system security control method to solve the problem that traditional static rule-based security protection methods cannot effectively identify complex abnormal access patterns. Secondly, the existing technology is difficult to perform intelligent anomaly detection based on user access behavior characteristics, resulting in the system lacking an effective response mechanism when facing the threat of zero-day attacks and covert infiltration.

[0005] In order to solve the above technical problems, the present invention provides the following technical solutions: In a first aspect, the present invention provides a microcomputer host system security control method, which comprises: Access the microcomputer host system to collect user log data, convert user access behavior into transaction data to calculate the frequency of occurrence, filter frequent item sets, calculate the support of the conditional pattern base through the conditional pattern base, recursively expand and calculate the superposition support according to the FP-Tree algorithm, calculate the confidence of different resource combinations, and filter high-confidence access sequences; Construct access feature vectors based on access time, use VAE encoder to extract the probability density of access feature vectors, and calculate the deviation value of access feature vectors using Mahalanobis distance MD algorithm by calculating the covariance matrix; The probability density and deviation value are screened separately, the hidden Markov model HMM is applied to define the hidden state, normal access and abnormal access are distinguished, the transition probability of the access state is calculated, the Viterbi algorithm is used to calculate the conditional probability of maximizing the observation sequence, and the optimal state sequence is determined; Based on the abnormal judgment of the state sequence, two-factor identity authentication is performed and abnormal access behavior data is recorded.

[0006] As a preferred solution of the microcomputer host system security control method of the present invention, wherein: the recursive expansion calculation is performed to calculate the confidence of different resource combinations to select high-confidence access sequences, including constructing a transaction data table for the log data file, converting the user access behavior into transaction data, and each transaction corresponds to the user's access record in different time periods; Set the user to access different resource data to form resource set X, and count the transaction data including resource set X And calculate the frequency of occurrence in all transactions; Determine the minimum support threshold based on historical data, and only retain the resource set X whose occurrence frequency is greater than the minimum support threshold as a frequent itemset; Sort the resources in the frequent item set from high to low in frequency, and select the access resource statistics to include the transaction data of the resource , determine all resource paths before the resource as the conditional pattern base CPB, and recursively calculate the support of the conditional pattern base; Determine the support threshold of the minimum conditional pattern base based on historical data, and retain support data greater than or equal to the threshold; According to the FP-Tree algorithm, recursive expansion is performed to continuously increase the number of frequent items, and the frequent items of the current expanded calculation number are combined to calculate the superposition support; Repeat the process of recursive expansion and calculating new superposition support until there is no new recursive expansion and the superposition support is greater than the minimum support threshold, and obtain different combinations of different resources that users visit in sequence in the same time window that meet the minimum support threshold. Each combination represents a group of resources that users visit in sequence in the same time window, and the frequency of occurrence of these combinations meets the support threshold requirement. For these resource combinations, the confidence of the resource combinations in two orders is calculated according to the order; Screening is performed based on the historical confidence threshold, and resource combinations that are greater than or equal to the historical confidence threshold are used as high-confidence access sequences.

[0007] As a preferred solution of the microcomputer host system security control method of the present invention, wherein: the access feature vector is constructed according to the access time, and the deviation value of the access feature vector is calculated, including calculating the mean and variance of the access window T according to the high confidence access sequence and the corresponding access time; The access feature vector constructed based on the resource combination order, mean and variance of the high-confidence access sequence ; Extract access feature vector using VAE encoder The implicit features of the data are used to calculate the probability density under the standard normal distribution based on the implicit features, and the negative logarithmic probability NLL conversion is used to access the feature vector The probability density of Extracting access feature vector based on VAE encoder The implicit feature output of The implicit mean and standard deviation of , and calculate the corresponding covariance matrix; Use Mahalanobis distance MD algorithm to calculate access feature vector The deviation value of the hidden feature.

[0008] As a preferred solution of the microcomputer host system security control method of the present invention, wherein: the screening probability density and deviation value define the hidden state, use the Viterbi algorithm to calculate the conditional probability of maximizing the observation sequence, and determine the optimal state sequence, including, within the time window, respectively recording the probability density and deviation value of the corresponding access feature vector of the access combination; The sum of the mean and standard deviation of the historical offset values ​​is used as the deviation threshold. If the deviation value is less than or equal to the deviation threshold, the access feature vector is determined. The corresponding access resource combination deviates less; Based on the sum of the mean and standard deviation of the historical probability density as the density threshold, if the probability density is greater than or equal to the density threshold, the access feature vector is judged The corresponding access resource combination has a high probability of belonging to the normal distribution; Apply the hidden Markov model HMM and define the hidden state , the user access resource combinations with higher probability and smaller deviation belonging to normal distribution are defined as the normal access states of users in hidden states, and the remaining user access states are defined as abnormal access states of hidden states; Conduct abnormal trend analysis and, through historical data learning, combine large deviation values ​​and low probability density into observed variables; Calculate the transition probability of access behavior from normal access state to abnormal access state; Statistics hidden state The probability of occurrence of the observed variables is calculated using the Viterbi algorithm to maximize the conditional probability of the observed sequence to determine the optimal state sequence.

[0009] As a preferred solution of the microcomputer host system security control method described in the present invention, wherein: the two-factor identity authentication is performed based on the abnormal judgment of the state sequence, which means that based on the optimal state sequence, if the state sequence is an abnormal access state, it is judged as a suspicious user and two-factor identity authentication is performed.

[0010] As a preferred solution of the microcomputer host system security control method of the present invention, wherein: the accessing the microcomputer host system to collect user log data includes accessing the log data file of the microcomputer host system, reading the user identification ID, access timestamp, access resource identification, access type, access success identification, access IP address and access device information; The user access frequency is calculated for outlier detection, and the sum of the mean and three times the standard deviation of the historical access frequency is used as the frequency threshold. If the user access frequency is greater than or equal to the frequency threshold, it is judged as abnormal data and removed.

[0011] As a preferred solution of the microcomputer host system security control method described in the present invention, the recording of abnormal access behavior data refers to recording all abnormal access behaviors under abnormal access status and generating access records, including access time, visitor identity and requested resource information.

[0012] In a second aspect, the present invention provides a system for a microcomputer host system security control method, comprising: A log data processing module collects user access log data from the microcomputer host system; Frequent item set mining module uses FP-Growth algorithm to mine frequent item sets on transaction data and calculates support through conditional pattern base CPB; The access feature vector module constructs an access feature vector based on the timestamp and resource combination of the user's access, uses VAE to extract the implicit features of the access behavior, and calculates the probability density of the access feature vector; The abnormal trend analysis module uses the Mahalanobis distance algorithm to calculate the deviation value of the vector, uses the hidden Markov model HMM to perform time series analysis on the high-confidence access sequence and the Mahalanobis distance, and uses the Viterbi algorithm to calculate the most likely state sequence by modeling the hidden state; The access control decision module makes real-time access control decisions based on the access state sequence output by the HMM and records abnormal access behavior data.

[0013] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the microcomputer host system security control method as described in the first aspect of the present invention is implemented.

[0014] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the microcomputer host system security control method as described in the first aspect of the present invention is implemented.

[0015] The beneficial effects of the present invention are as follows: by recursively calculating the support of the conditional pattern base, it is ensured that only access patterns with strong correlation are retained in the FP-Tree structure; the probability density of the access pattern is calculated based on the standard normal distribution to ensure that the access pattern with low probability obtains a higher anomaly score, thereby improving the detection accuracy; the hidden Markov model HMM is applied to take the user access resource combination with a high probability and a small deviation belonging to the normal distribution as the normal access state, so that the system can automatically distinguish between stable access patterns and abnormal access patterns; the Viterbi algorithm calculates the conditional probability of the maximized observation sequence to determine the optimal state sequence, so that the identification of abnormal access patterns is more accurate; through the optimal path search, the abnormal access detection errors caused by local misjudgment can be avoided, so that the final access state judgment is more accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0017] Figure 1 Schematic diagram of the flow of the microcomputer host system security control method in Example 1.

[0018] Figure 2 This is a schematic diagram of the structure of the microcomputer host system security control system in Example 1. DETAILED DESCRIPTION

[0019] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0020] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0021] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0022] Example 1, reference Figure 1 to Figure 2 , which is the first embodiment of the present invention, provides a microcomputer host system security control method, comprising the following steps: S1, access the microcomputer host system to collect user log data, convert user access behavior into transaction data to calculate the frequency of occurrence, filter frequent item sets, calculate the support of the conditional pattern base through the conditional pattern base, recursively expand and calculate the superposition support according to the FP-Tree algorithm, calculate the confidence of different resource combinations, and filter high-confidence access sequences; Preferably, accessing the microcomputer host system to collect user log data includes accessing the log data file of the microcomputer host system, and reading information including user identification ID, access timestamp, access resource identification, access type, access success identification, access IP address and access device information; The user access frequency is calculated for outlier detection, and the sum of the mean and three times the standard deviation of the historical access frequency is used as the frequency threshold. If the user access frequency is greater than or equal to the frequency threshold, it is judged as abnormal data and removed.

[0023] Multi-dimensional data collection can provide richer feature information, making subsequent access behavior analysis more accurate, and can combine multiple data sources to cross-validate abnormal behavior, improve detection reliability, calculate user access frequency and perform outlier detection, so that the system can identify those users with abnormally high frequency access, avoid potential abuse, crawling or attacks by certain malicious users or automated attack programs through ultra-high frequency access behavior, set frequency thresholds and filter abnormal access data, so that the data based on access behavior analysis is cleaner, and avoid extreme values ​​or outliers affecting the modeling and learning effects of normal user behavior.

[0024] Further, recursive expansion calculations are performed to calculate the confidence of different resource combinations and filter high-confidence access sequences, including constructing a transaction data table for the log data file and converting user access behavior into transaction data. Each transaction corresponds to the user's access record in different time periods, expressed as: ; in represents the time window, represents the i-th user, represents the user access to resources in the mth time window, and T represents transaction data; Set the user to access different resource data to form resource set X, and count the transaction data including resource set X And calculate the frequency of occurrence in all transactions, expressed as: ; in represents the occurrence frequency of resource set X, Represents transaction data containing X number of resource collections, Indicates the total number of transactions; Determine the minimum support threshold based on historical data and only retain the data with a frequency greater than the minimum support threshold. The resource set X is taken as a frequent item set; Sort the resources in the frequent item set from high to low in frequency, and select the access resource statistics to include the transaction data of the resource , determine all resource paths before the resource as the conditional pattern base CPB, and recursively calculate the support of the conditional pattern base, expressed as: ; ; in Indicates that it contains resources The conditional pattern base for all previous resource paths, Representation Resources The support of the conditional pattern base; Determine the support threshold of the minimum conditional pattern base based on historical data, and retain support data greater than or equal to the threshold; According to the FP-Tree algorithm, recursive expansion is performed, the number of frequent items is continuously increased, and the frequent items of the current expanded calculation number are combined to calculate the superposition support, which can be expressed as: ; in Representation Resources and The superposition support of the conditional pattern base, Representation Resources The conditional pattern base for all previous resource paths; Repeat the process of recursive expansion and calculating new superposition support until there is no new recursive expansion and the superposition support is greater than the minimum support threshold, and obtain different combinations of different resources that users visit in sequence in the same time window that meet the minimum support threshold. Each combination represents a group of resources that users visit in sequence in the same time window, and the frequency of occurrence of these combinations meets the support threshold requirement. For these resource combinations, the confidence of two resource combinations in sequence (i.e., a set of resources that the user first accesses and then accesses in the same time window) is calculated according to the sequence, expressed as: ; in Indicates a combination that meets the support threshold requirement and The confidence level, Indicates a combination that meets the support threshold requirement and The frequency of occurrence, Indicates a combination that meets the support threshold requirement The frequency of occurrence; Screening is performed based on the historical confidence threshold, and resource combinations that are greater than or equal to the historical confidence threshold are used as high-confidence access sequences.

[0025] By constructing a transaction data table, the user access behavior is converted into transaction data, so that the system can use frequent pattern mining methods to analyze the user's access habits and calculate the frequency of occurrence of resource set X to ensure that only those resource combinations that are statistically significant to the user's access pattern are analyzed, while ignoring low-frequency access behaviors. Based on the frequency of occurrence of resources in the frequent item set, the conditional pattern base CPB is constructed. Through FP-Tree, the computational complexity of access pattern mining is lower than that of the traditional Apriori method. The calculation of the conditional pattern base enables the frequent pattern expansion to be carried out in the local search space, reducing redundant calculations. By recursively calculating the support of the conditional pattern base, we ensure that only access patterns with strong correlation are retained in the FP-Tree structure, which improves the accuracy of data mining, further reduces irrelevant data, improves the efficiency of pattern mining, and ensures that the access patterns finally extracted represent the long-term trend of user behavior rather than some short-term, accidental access behaviors. Through the recursive expansion of FP-Tree, not only can simple access patterns be discovered, but more complex multi-step access paths can also be extracted, making the analysis results more comprehensive. Through strict support screening, the patterns finally extracted can accurately describe the user's access habits rather than accidental events. Confidence calculation can quantify the correlation between different access patterns and identify whether the sequence of user access behavior is regular, ensuring that the finally extracted patterns have long-term stability rather than only short-term effective behavior.

[0026] S2, construct an access feature vector according to the access time, use the VAE encoder to extract the probability density of the access feature vector, and calculate the deviation value of the access feature vector by calculating the covariance matrix using the Mahalanobis distance MD algorithm; Preferably, constructing an access feature vector according to the access time and calculating the deviation value of the access feature vector includes calculating the mean (indicating the time when the access pattern usually occurs) and the variance (indicating the volatility of the time when the access pattern occurs) of the access window T according to the high confidence access sequence and the corresponding access time; The access feature vector constructed based on the resource combination order of the high-confidence access sequence (which can be embedded using One-Hot Encoding) and the mean and variance can be expressed as: ; in The access feature vector representing the resource combination of the i-th access sequence, represents the resource combination of the ith access behavior that meets the support threshold requirement, represents the subsequent resource combination of the ith access behavior that meets the support threshold requirement, represents the mean access time of access window T, represents the access time variance of access window T; Extract access feature vector using VAE encoder The implicit features of the data are used to calculate the probability density under the standard normal distribution based on the implicit features, and the negative logarithmic probability NLL conversion is used to access the feature vector The probability density of is expressed as: ; in express The probability density of express The probability density of the implicit characteristic standard normal distribution; Extracting access feature vector based on VAE encoder The implicit feature output of The implicit mean and standard deviation of , and the corresponding covariance matrix is ​​calculated, expressed as: ; Where ∑ represents the covariance matrix, N represents the total number of accessed eigenvectors, Represents the resource combination of the i-th access sequence The corresponding implicit mean is, Represents the resource combination of all access sequences The corresponding implicit mean is, Represents the resource combination of the i-th access sequence The corresponding implicit standard deviation is calculated by transposition, J indicates the calculation is in transposition; Use Mahalanobis distance MD algorithm to calculate access feature vector The deviation value of the implicit feature is expressed as: ; in Represents access to feature vectors The deviation value of Represents access to feature vectors implicit features.

[0027] By calculating the mean and variance of the access window, the time distribution characteristics of high-confidence access sequences can be quantified to ensure the time stability analysis of access patterns. By constructing access feature vectors, the feature vectors can simultaneously reflect the structural information and time characteristics of access resources, thereby providing richer information than analyzing access resource combinations separately. The implicit features of the access feature vectors are extracted through the VAE encoder, so that the access patterns can be mapped to low-dimensional latent spaces, improving the data representation ability. The probability density of access patterns is calculated based on the standard normal distribution, which can measure the commonness of different access patterns. The negative logarithmic probability (NLL) is used to transform the probability density, making the scoring of abnormal access patterns more stable, ensuring that low-probability access patterns get higher abnormal scores, thereby improving detection accuracy. The calculation of the covariance matrix not only considers the changes in individual access patterns, but also captures the global correlation between different access sequences, improving the detection ability of abnormal access. The Mahalanobis distance is used to calculate the deviation value of the implicit features of the access feature vector, so that the system can measure the distance between a certain access pattern and the historical normal pattern, avoiding the misjudgment that may be caused by using only the Euclidean distance.

[0028] S3, respectively screen the probability density and deviation value, apply the hidden Markov model HMM to define the hidden state, distinguish normal access from abnormal access, calculate the transition probability of the access state, use the Viterbi algorithm to calculate the conditional probability of maximizing the observation sequence, and determine the optimal state sequence; Preferably, the probability density and deviation value are screened to define the hidden state, the conditional probability of maximizing the observation sequence is calculated using the Viterbi algorithm, and the optimal state sequence is determined, including, within the time window, respectively recording the probability density and deviation value of the corresponding access feature vector of the access combination; The sum of the mean and standard deviation of the historical offset values ​​is used as the deviation threshold. If the deviation value is less than or equal to the deviation threshold, the access feature vector is determined. The corresponding access resource combination deviates less; Based on the sum of the mean and standard deviation of the historical probability density as the density threshold, if the probability density is greater than or equal to the density threshold, the access feature vector is judged The corresponding access resource combination has a high probability of belonging to the normal distribution; Apply the hidden Markov model HMM and define the hidden state , the user access resource combinations with higher probability and smaller deviation belonging to normal distribution are defined as the normal access states of users in hidden states, and the remaining user access states are defined as abnormal access states of hidden states; To analyze the abnormal trend, through historical data learning, the larger deviation value and the probability density with lower probability are combined into observation variables, which are expressed as: ; in represents the observed variable, Indicates a lower probability Probability density, Indicates the access feature vector with large deviation Deviation value; Calculate the transition probability of access behavior from normal access state to abnormal access state, expressed as: ; in represents the access state transition probability at time t and t-1, It indicates the probability that if the previous access behavior is a normal access state, the next access is still a normal access state. It indicates the probability that the next access is an abnormal access state if the previous access behavior is a normal access state. It indicates the probability that the next access is a normal access state if the previous access behavior is an abnormal access state. It indicates the probability that if the previous access behavior is an abnormal access state, the next access will still be an abnormal access state; Statistics hidden state Observed variables The probability of occurrence (which can be determined by calculating the probability density of the Gaussian distribution) is calculated using the Viterbi algorithm to maximize the conditional probability of the observed sequence to determine the optimal state sequence, which is expressed as: ; in represents the optimal state sequence, Indicates that given an observed variable (i.e., access behavior within the time window 1 to t), the hidden state maximum probability.

[0029] By recording the probability density and deviation value of the access feature vector corresponding to the access combination in the time window, the system can analyze the changing trend of access behavior in a time series manner, rather than detecting a single access event in isolation. The hidden Markov model HMM is applied to treat the user access resource combination with a high probability of belonging to the normal distribution and a small deviation as the normal access state, so that the system can automatically distinguish between stable access patterns and abnormal access patterns. This method can effectively combine time series data, so that the detection of access patterns is not only based on static features, but also takes into account the evolution trend over time, thereby improving the overall detection capability. In addition, HMM allows the system to analyze the conversion law of access behavior through the time dimension, so that abnormal access detection is no longer based solely on current access behavior, but on the overall evolution trend of historical access patterns. Abnormal trend analysis enables the system to discover abnormal access patterns based on long-term monitoring, rather than relying solely on short-term access behavior judgments. The transition probability of access behavior from normal access state to abnormal access state is calculated, so that the system can learn the changing trend of access behavior, rather than just detecting a single abnormal event. The transition probability can more accurately analyze the evolution of user behavior, allowing the system to more accurately predict future access patterns, improve access security while reducing false alarm rates. By calculating the Gaussian distribution probability density, the probability distribution of access behavior under different states can be accurately estimated. The Viterbi algorithm is used to calculate the conditional probability of the maximum observation sequence to determine the optimal state sequence, making the identification of abnormal access patterns more accurate. Through the optimal path search, abnormal access detection errors caused by local misjudgments can be avoided, making the final access state judgment more accurate. The calculation method of the Viterbi algorithm combines the historical access behavior within the entire time window, making the abnormal detection results more in line with the evolution of the access pattern, thereby improving the overall access security and detection accuracy.

[0030] S4, based on the abnormal determination of the state sequence, two-factor identity authentication is performed and abnormal access behavior data is recorded; Preferably, the two-factor identity authentication is performed based on the abnormal determination of the state sequence, which means that based on the optimal state sequence, if the state sequence is an abnormal access state, it is determined to be a suspicious user and two-factor identity authentication is performed to ensure that the operation is performed by a legitimate user.

[0031] By judging whether access behavior is abnormal based on the optimal state sequence, the system can analyze user access patterns within a longer time window to avoid misjudgment caused by access fluctuations in a short period of time. Through additional identity authentication, the system can effectively prevent attackers from accessing with only stolen account credentials, reduce the risk of account hijacking, and improve the security level of identity authentication.

[0032] Furthermore, recording abnormal access behavior data refers to recording all abnormal access behaviors under abnormal access status and generating access records, including access time, visitor identity, and requested resource information.

[0033] By recording all abnormal access behaviors under abnormal access status, the system can perform detailed security analysis afterwards, ensuring that the security team can trace back abnormal events, identify potential sources of security threats, and generate access records, including access time, visitor identity, and requested resource information, so that the system can track the details of each abnormal access and ensure that the security team can accurately judge the severity of abnormal behavior.

[0034] This embodiment also provides a system of a microcomputer host system security control method, comprising: A log data processing module collects user access log data from the microcomputer host system; Frequent item set mining module uses FP-Growth algorithm to mine frequent item sets on transaction data and calculates support through conditional pattern base CPB; The access feature vector module constructs an access feature vector based on the timestamp and resource combination of the user's access, uses VAE to extract the implicit features of the access behavior, and calculates the probability density of the access feature vector; The abnormal trend analysis module uses the Mahalanobis distance algorithm to calculate the deviation value of the vector, uses the hidden Markov model HMM to perform time series analysis on the high-confidence access sequence and the Mahalanobis distance, and uses the Viterbi algorithm to calculate the most likely state sequence by modeling the hidden state; The access control decision module makes real-time access control decisions based on the access state sequence output by the HMM and records abnormal access behavior data.

[0035] This embodiment also provides a computer device, which is suitable for the case of a microcomputer host system security control method, including: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute computer executable instructions to implement the microcomputer host system security control method proposed in the above embodiment.

[0036] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covered on the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.

[0037] The present embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the method for realizing the security control of a microcomputer host system as proposed in the above embodiment is implemented; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable red-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, disk or optical disk.

[0038] In summary, the present invention recursively calculates the support of the conditional pattern base to ensure that only access patterns with strong correlation are retained in the FP-Tree structure, calculates the probability density of the access pattern based on the standard normal distribution, ensures that low-probability access patterns obtain higher anomaly scores, thereby improving detection accuracy, and applies the hidden Markov model HMM to take the user access resource combination with a higher probability and a smaller deviation belonging to the normal distribution as the normal access state, so that the system can automatically distinguish between stable access patterns and abnormal access patterns. The Viterbi algorithm calculates the conditional probability of the maximized observation sequence to determine the optimal state sequence, so that the identification of abnormal access patterns is more accurate, and through the optimal path search, it can avoid abnormal access detection errors caused by local misjudgment, making the final access state judgment more accurate.

[0039] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A microcomputer host system security control method, characterized in that: include: Access the microcomputer host system to collect user log data, convert user access behavior into transaction data to calculate the frequency of occurrence, filter frequent item sets, calculate the support of the conditional pattern base through the conditional pattern base, recursively expand and calculate the superposition support according to the FP-Tree algorithm, calculate the confidence of different resource combinations, and filter high-confidence access sequences; Construct access feature vectors based on access time, use VAE encoder to extract the probability density of access feature vectors, and calculate the deviation value of access feature vectors using Mahalanobis distance MD algorithm by calculating the covariance matrix; The probability density and deviation value are screened separately, the hidden Markov model HMM is applied to define the hidden state, normal access and abnormal access are distinguished, the transition probability of the access state is calculated, the Viterbi algorithm is used to calculate the conditional probability of maximizing the observation sequence, and the optimal state sequence is determined; Based on the abnormal judgment of the state sequence, two-factor identity authentication is performed and abnormal access behavior data is recorded.

2. The microcomputer host system security control method as claimed in claim 1, characterized in that: The recursive expansion calculation is performed to calculate the confidence of different resource combinations to select high-confidence access sequences, including constructing a transaction data table for the log data file, converting the user access behavior into transaction data, and each transaction corresponds to the user's access record in different time periods; Set the user to access different resource data to form resource set X, and count the transaction data including resource set X And calculate the frequency of occurrence in all transactions; Determine the minimum support threshold based on historical data, and only retain the resource set X whose occurrence frequency is greater than the minimum support threshold as a frequent itemset; Sort the resources in the frequent item set from high to low in frequency, and select the access resource statistics to include the transaction data of the resource , determine all resource paths before the resource as the conditional pattern base CPB, and recursively calculate the support of the conditional pattern base; Determine the support threshold of the minimum conditional pattern base based on historical data, and retain support data greater than or equal to the threshold; According to the FP-Tree algorithm, recursive expansion is performed to continuously increase the number of frequent items, and the frequent items of the current expanded calculation number are combined to calculate the superposition support; Repeat the process of recursive expansion and calculating new superposition support until there is no new recursive expansion and the superposition support is greater than the minimum support threshold, and obtain different combinations of different resources that users visit in sequence in the same time window that meet the minimum support threshold. Each combination represents a group of resources that users visit in sequence in the same time window, and the frequency of occurrence of these combinations meets the support threshold requirement. For these resource combinations, the confidence of the resource combinations in two orders is calculated according to the order; Screening is performed based on the historical confidence threshold, and resource combinations that are greater than or equal to the historical confidence threshold are used as high-confidence access sequences.

3. The microcomputer host system security control method as claimed in claim 2, characterized in that: The step of constructing an access feature vector according to the access time and calculating a deviation value of the access feature vector includes calculating a mean and a variance of the access window T according to a high confidence access sequence and a corresponding access time; The access feature vector constructed based on the resource combination order, mean and variance of the high-confidence access sequence ; Extract access feature vector using VAE encoder The implicit features of the data are used to calculate the probability density under the standard normal distribution based on the implicit features, and the negative logarithmic probability NLL conversion is used to access the feature vector The probability density of Extracting access feature vector based on VAE encoder The implicit feature output of The implicit mean and standard deviation of , and calculate the corresponding covariance matrix; Use Mahalanobis distance MD algorithm to calculate access feature vector The deviation value of the hidden feature.

4. The microcomputer host system security control method as claimed in claim 3, characterized in that: The screening probability density and deviation value define the hidden state, use the Viterbi algorithm to calculate the conditional probability of maximizing the observation sequence, and determine the optimal state sequence, including, within the time window, recording the probability density and deviation value of the corresponding access feature vector of the access combination respectively; The sum of the mean and standard deviation of the historical offset values ​​is used as the deviation threshold. If the deviation value is less than or equal to the deviation threshold, the access feature vector is determined. The corresponding access resource combination deviates less; Based on the sum of the mean and standard deviation of the historical probability density as the density threshold, if the probability density is greater than or equal to the density threshold, the access feature vector is judged The corresponding access resource combination has a high probability of belonging to the normal distribution; Apply the hidden Markov model HMM and define the hidden state , the user access resource combinations with higher probability and smaller deviation belonging to normal distribution are defined as the normal access states of users in hidden states, and the remaining user access states are defined as abnormal access states of hidden states; Conduct abnormal trend analysis and, through historical data learning, combine large deviation values ​​and low probability density into observed variables; Calculate the transition probability of access behavior from normal access state to abnormal access state; Statistics hidden state The probability of occurrence of the observed variables is calculated using the Viterbi algorithm to maximize the conditional probability of the observed sequence to determine the optimal state sequence.

5. The microcomputer host system security control method as claimed in claim 1, characterized in that: The two-factor identity authentication is performed based on the abnormal determination of the state sequence, which means that if the state sequence is an abnormal access state based on the optimal state sequence, the user is judged as a suspicious user and two-factor identity authentication is performed.

6. The microcomputer host system security control method as claimed in claim 1, characterized in that: The access to the microcomputer host system to collect user log data includes accessing the log data file of the microcomputer host system, reading the user identification ID, access timestamp, access resource identification, access type, access success identification, access IP address and access device information; The user access frequency is calculated for outlier detection, and the sum of the mean and three times the standard deviation of the historical access frequency is used as the frequency threshold. If the user access frequency is greater than or equal to the frequency threshold, it is judged as abnormal data and removed.

7. The microcomputer host system security control method as claimed in claim 1, characterized in that: The recording of abnormal access behavior data refers to recording all abnormal access behaviors under abnormal access status and generating access records, including access time, visitor identity and requested resource information.

8. A system for a microcomputer host system security control method, based on the microcomputer host system security control method according to any one of claims 1 to 7, characterized in that: include, A log data processing module collects user access log data from the microcomputer host system; Frequent item set mining module uses FP-Growth algorithm to mine frequent item sets on transaction data and calculates support through conditional pattern base CPB; The access feature vector module constructs an access feature vector based on the timestamp and resource combination of the user's access, uses VAE to extract the implicit features of the access behavior, and calculates the probability density of the access feature vector; The abnormal trend analysis module uses the Mahalanobis distance algorithm to calculate the deviation value of the vector, uses the hidden Markov model HMM to perform time series analysis on the high-confidence access sequence and the Mahalanobis distance, and uses the Viterbi algorithm to calculate the most likely state sequence by modeling the hidden state; The access control decision module makes real-time access control decisions based on the access state sequence output by the HMM and records abnormal access behavior data.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the microcomputer host system security control method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the microcomputer host system security control method described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Uncertain data frequent item set publishing method based on differential privacy

    CN112464277A

  • Mini-computer operation state information interaction control method and system

    CN118885085A

  • Microcomputer system performance test and evaluation method, device, equipment and medium

    CN119576673A

  • Enhancing API access controls with markov chains and hidden markov models

    US20230376811A1