A method, device, and medium for security control of a microcomputer host system

By analyzing the log data collected by the microcomputer host system, combining technologies such as FP-Tree and VAE, abnormal access mode is identified, and access status sequence is determined using HMM and Viterbi algorithms, the problem of traditional security protection methods not being able to identify complex abnormal access modes is solved, and higher detection accuracy and response capabilities are achieved.

CN119939635BActive Publication Date: 2025-06-13SHENZHEN MEIGAO ELECTRONICS EQUIP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510416919.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-13
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Traditional security protection methods based on static rules cannot effectively identify complex abnormal access patterns, and it is difficult to conduct intelligent abnormal detection based on user access behavior characteristics, resulting in the lack of an effective response mechanism when the system faces the threat of zero-day attacks and hidden penetration.

Method used

By collecting user log data, converting it into transaction data to calculate the frequency of occurrence, filtering the frequent item sets and performing recursive expansion calculations through the FP-Tree algorithm to calculate the confidence of different resource combinations. At the same time, the access feature vector is constructed, the probability density of the access feature vector is extracted using the VAE encoder, the covariance matrix is ​​calculated, and the deviation value is calculated using the Mahayana distance algorithm. The hidden Markov model HMM is used to define hidden states, distinguish between normal access and abnormal access, calculate the conditional probability of maximizing the observation sequence through the Viterbi algorithm, determine the optimal state sequence, and perform two-factor authentication.

Benefits of technology

It improves detection accuracy, can automatically distinguish stable access modes and abnormal access modes, avoid local misjudgment, ensures that the final access status judgment is more accurate, and enhances the system's response ability in the face of zero-day attacks and hidden penetration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939635B_ABST
    Figure CN119939635B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device and medium for security control of a microcomputer host system, which relates to the technical field of security control. The method includes accessing the microcomputer host system to collect user log data, converting user access behaviors into transaction data to calculate the occurrence frequency, screening frequent itemsets, calculating the support degree of the conditional pattern base through the conditional pattern base, recursively expanding and calculating the superimposed support degree according to the FP-Tree algorithm, and calculating the confidence degree of different resource combinations to screen high-confidence access sequences. The method of the present invention ensures that only access patterns with strong correlation are retained in the FP-Tree structure by recursively calculating the support degree of the conditional pattern base, and calculates the probability density of the access pattern based on the standard normal distribution to ensure that low-probability access patterns obtain higher anomaly scores, thereby improving the detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security control, and particularly to a security control method, device, and medium for a microcomputer host system. Background Art

[0002] With the popularization of Internet technology and the increasing demand for remote access, the microcomputer host system faces increasingly severe security threats, including problems such as unauthorized access, malware attacks, data theft, identity theft, and abnormal operation behaviors emerging in an endless stream, seriously threatening the normal operation of the system and data security. Existing security control technologies mainly rely on traditional access control lists (ACLs), static rule configurations, signature-based intrusion detection systems (IDSs), etc. to manage user access permissions;

[0003] However, traditional static rule-based security protection methods cannot effectively identify complex abnormal access patterns. Secondly, it is difficult for existing technologies to perform intelligent anomaly detection based on the access behavior characteristics of users, resulting in a lack of effective response mechanisms when the system faces threats such as zero-day attacks and stealth penetrations. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a security control method for a microcomputer host system to solve the problems that traditional static rule-based security protection methods cannot effectively identify complex abnormal access patterns, and secondly, it is difficult for existing technologies to perform intelligent anomaly detection based on the access behavior characteristics of users, resulting in a lack of effective response mechanisms when the system faces threats such as zero-day attacks and stealth penetrations.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a security control method for a microcomputer host system, which includes:

[0008] Access the microcomputer host system to collect user log data, convert the user access behavior into transaction data to calculate the occurrence frequency, screen the frequent item sets, calculate the support degree of the conditional pattern base through the conditional pattern base, perform recursive expansion calculation of the superimposed support degree according to the FP-Tree algorithm, and calculate the confidence of different resource combinations to screen high-confidence access sequences;

[0009] Construct an access feature vector according to the access time, use a VAE encoder to extract the probability density of the access feature vector, and calculate the deviation value of the access feature vector using the Mahalanobis distance MD algorithm by calculating the covariance matrix;

[0010] Screen the probability density and deviation values respectively, define hidden states using the Hidden Markov Model (HMM), distinguish normal access from abnormal access, calculate the transition probabilities of access states, use the Viterbi algorithm to calculate the conditional probability that maximizes the observed sequence, and determine the optimal state sequence;

[0011] Based on the abnormality determination of the state sequence, perform two-factor authentication and record the abnormal access behavior data.

[0012] As a preferred solution of the microcomputer host system security control method described in the present invention, wherein: perform recursive expansion calculation, calculate the confidence levels of different resource combinations to screen high-confidence access sequences, including constructing a transaction data table for the log data file, converting user access behaviors into transaction data, and each transaction corresponding to the user's access records at different time periods;

[0013] Set the resources accessed by the user to form a resource set X, and count the transaction data containing the resource set X and calculate the occurrence frequency in all transactions;

[0014] Based on historical data, determine the minimum support threshold, and only retain the resource set X with an occurrence frequency greater than the minimum support threshold as the frequent item set;

[0015] Sort the resources in the frequent item set in descending order of occurrence frequency, select the accessed resource, count the transaction data containing this resource and determine all the resource paths before this resource as the conditional pattern base (CPB), and recursively calculate the support of the conditional pattern base;

[0016] Based on historical data, determine the support threshold of the minimum conditional pattern base, and retain the support data greater than or equal to this threshold;

[0017] Perform recursive expansion according to the FP-Tree algorithm, continuously increase the number of frequent items, combine the frequent items of the current expansion calculation quantity, and calculate the superimposed support;

[0018] Repeat the process of recursive expansion and calculation of the new superimposed support until there is no new recursive expansion and the superimposed support is greater than the minimum support threshold, to obtain different combinations of different resources accessed by the user in the same time window that meet the minimum support threshold. Each combination represents a set of resources accessed by the user in the same time window in sequence, and the occurrence frequencies of these combinations meet the requirements of the support threshold;

[0019] For these resource combinations, calculate the confidence levels of the resource combinations in two consecutive orders according to the sequence;

[0020] Screening is performed based on the historical confidence threshold, and resource combinations that are greater than or equal to the historical confidence threshold are used as high-confidence access sequences.

[0021] As a preferred solution of the microcomputer host system security control method of the present invention, wherein: the access feature vector is constructed according to the access time, and the deviation value of the access feature vector is calculated, including calculating the mean and variance of the access window T according to the high confidence access sequence and the corresponding access time;

[0022] The access feature vector constructed based on the resource combination order, mean and variance of the high-confidence access sequence ;

[0023] Extract access feature vector using VAE encoder The implicit features of the data are used to calculate the probability density under the standard normal distribution based on the implicit features, and the negative logarithmic probability NLL conversion is used to access the feature vector The probability density of

[0024] Extracting access feature vector based on VAE encoder The implicit feature output of The implicit mean and standard deviation of , and calculate the corresponding covariance matrix;

[0025] Use Mahalanobis distance MD algorithm to calculate access feature vector The deviation value of the hidden feature.

[0026] As a preferred solution of the microcomputer host system security control method of the present invention, wherein: the screening probability density and deviation value define the hidden state, use the Viterbi algorithm to calculate the conditional probability of maximizing the observation sequence, and determine the optimal state sequence, including, within the time window, respectively recording the probability density and deviation value of the corresponding access feature vector of the access combination;

[0027] The sum of the mean and standard deviation of the historical offset values ​​is used as the deviation threshold. If the deviation value is less than or equal to the deviation threshold, the access feature vector is determined. The corresponding access resource combination deviates less;

[0028] Based on the sum of the mean and standard deviation of the historical probability density as the density threshold, if the probability density is greater than or equal to the density threshold, the access feature vector is judged The corresponding access resource combination has a high probability of belonging to the normal distribution;

[0029] Apply the hidden Markov model HMM and define the hidden state , the user access resource combinations with a relatively high probability belonging to the normal distribution and a small deviation are used as the normal access state of the user in the hidden state, while the remaining user access states are defined as the abnormal access state in the hidden state;

[0030] Perform abnormal trend analysis. Through learning from historical data, the large deviation values and low probability densities are combined to form observed variables;

[0031] Calculate the transition probability of the access behavior from the normal access state to the abnormal access state;

[0032] Statistical hidden state The occurrence probability of the observed variables in the following is calculated, and the Viterbi algorithm is used to calculate the conditional probability that maximizes the observed sequence to determine the optimal state sequence.

[0033] As a preferred solution of the microcomputer host system security control method described in the present invention, wherein: the two-factor authentication is performed according to the abnormal determination of the state sequence, which means that based on the optimal state sequence, if the state sequence is an abnormal access state, it is determined as a suspicious user and two-factor authentication is performed.

[0034] As a preferred solution of the microcomputer host system security control method described in the present invention, wherein: the access to the microcomputer host system to collect user log data includes accessing the log data file of the microcomputer host system and reading the user identification ID, access timestamp, access resource identification, access type, access success flag, access IP address, and access device information;

[0035] Calculate the user access frequency for outlier detection. Based on the sum of the mean of the historical access frequency and three times the standard deviation as the frequency threshold, if the user access frequency is greater than or equal to the frequency threshold, it is determined as abnormal data and excluded.

[0036] As a preferred solution of the microcomputer host system security control method described in the present invention, wherein: the recording of abnormal access behavior data refers to recording all abnormal access behaviors in the abnormal access state, generating an access record, including access time, visitor identity, and requested resource information.

[0037] In a second aspect, the present invention provides a system for a microcomputer host system security control method, including,

[0038] A log data processing module that collects user access log data from the microcomputer host system;

[0039] A frequent item set mining module that uses the FP-Growth algorithm to perform frequent item set mining on transaction data and calculates the support degree through the conditional pattern base CPB;

[0040] The access feature vector module constructs an access feature vector based on the timestamp and resource combination of the user's access, uses VAE to extract the implicit features of the access behavior, and calculates the probability density of the access feature vector.

[0041] The abnormal trend analysis module calculates the deviation value of the vector using the Mahalanobis distance algorithm, performs time series analysis on the high-confidence access sequence and the Mahalanobis distance using the Hidden Markov Model (HMM), models the hidden state, and calculates the most likely state sequence using the Viterbi algorithm.

[0042] The access control decision module makes real-time access control decisions based on the access state sequence output by the HMM and records abnormal access behavior data.

[0043] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the microcomputer host system security control method described in the first aspect of the present invention is implemented.

[0044] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the microcomputer host system security control method described in the first aspect of the present invention is implemented.

[0045] The beneficial effects of the present invention are as follows: By recursively calculating the support of the conditional pattern base, it is ensured that only the access patterns with strong correlation are retained in the FP-Tree structure. The probability density of the access pattern is calculated based on the standard normal distribution, ensuring that the access patterns with low probability obtain higher abnormal scores, thereby improving the detection accuracy. The Hidden Markov Model (HMM) is applied to regard the user access resource combinations with a higher probability belonging to the normal distribution and smaller deviation as normal access states, enabling the system to automatically distinguish stable access patterns and abnormal access patterns. The Viterbi algorithm calculates the conditional probability of maximizing the observation sequence to determine the optimal state sequence, making the identification of abnormal access patterns more accurate. Through the optimal path search, it is possible to avoid the abnormal access detection errors caused by local misjudgment, making the final access state judgment more accurate. Description of the Drawings

[0046] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0047] Figure 1It is a schematic flowchart of the security control method for the microcomputer host system in Embodiment 1.

[0048] Figure 2 It is a schematic structural diagram of the security control system for the microcomputer host system in Embodiment 1. Specific implementation manners

[0049] To make the above objects, features, and advantages of the present invention more obvious and understandable, the specific implementation manners of the present invention will be described in detail below with reference to the accompanying drawings of the specification.

[0050] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar promotions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0051] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" that appears in different places in this specification does not all refer to the same embodiment, nor is it a separate or selectively mutually exclusive embodiment with other embodiments.

[0052] Embodiment 1, referring to From Figure 1 to Figure 2 , which is the first embodiment of the present invention. This embodiment provides a security control method for a microcomputer host system, including the following steps:

[0053] S1. Access the microcomputer host system to collect user log data, convert the user access behavior into transaction data to calculate the occurrence frequency, screen the frequent item sets, calculate the support degree of the conditional pattern basis through the conditional pattern basis, perform recursive expansion calculation on the superposition support degree according to the FP-Tree algorithm, and calculate the confidence degree of different resource combinations to screen the high-confidence access sequences;

[0054] Preferably, accessing the microcomputer host system to collect user log data includes accessing the log data file of the microcomputer host system and reading the user identification ID, access timestamp, access resource identification, access type, access success flag, access IP address, and access device information;

[0055] Calculate the user access frequency for outlier detection. Based on the sum of the mean of the historical access frequency and three times the standard deviation as the frequency threshold, if the user access frequency is greater than or equal to the frequency threshold, it is determined as abnormal data and excluded.

[0056] The multi-dimensional data collection method can provide richer feature information, making the subsequent access behavior analysis more accurate. It can also combine multiple data sources to cross-verify abnormal behaviors, improve the reliability of detection, calculate the user access frequency and perform outlier detection, enabling the system to identify users with abnormal high-frequency accesses, and avoid potential abuse, crawling, or attacks by certain malicious users or automated attack programs through ultra-high-frequency access behaviors. Set the frequency threshold and filter abnormal access data to make the data on which the access behavior analysis is based cleaner, and avoid affecting the modeling and learning effects of normal user behaviors due to extreme values or outliers.

[0057] Furthermore, perform recursive expansion calculation to calculate the confidence levels of different resource combinations and screen high-confidence access sequences, including constructing a transaction data table for the log data file, converting user access behaviors into transaction data, where each transaction corresponds to the access records of a user in different time periods, expressed as:

[0058] ;

[0059] where represents the time window, represents the i-th user, represents the resources accessed by the user within the m-th time window, and T represents the transaction data;

[0060] Set the different resource data accessed by the user to form a resource set X, count the transaction data containing the resource set X and calculate the occurrence frequency in all transactions, expressed as:

[0061] ;

[0062] where represents the occurrence frequency of the resource set X, represents the transaction data containing the number of the resource set X, represents the total number of transactions;

[0063] Based on historical data, determine the minimum support threshold, and only retain the resource set X with an occurrence frequency greater than the minimum support threshold as the frequent item set;

[0064] Sort the resources in the frequent item set from high to low according to their occurrence frequencies, select the access resources, count the transaction data containing this resource , determine all the resource paths before this resource as the conditional pattern base CPB, and recursively calculate the support of the conditional pattern base, expressed as:

[0065] ;

[0066] ;

[0067] Among them represents the conditional pattern base containing all the previous resource paths of the resource, represents the support of the conditional pattern base of the resource ;

[0068] Determine the support threshold of the minimum conditional pattern base based on historical data, and retain the support data greater than or equal to this threshold;

[0069] According to the FP-Tree algorithm, perform recursive expansion, continuously increase the number of frequent items, combine the current expanded frequent items for calculation, and calculate the superimposed support, which can be expressed as:

[0070] ;

[0071] Among them represents the superimposed support of the resource and the conditional pattern base, represents the conditional pattern base of all the previous resource paths of the resource ;

[0072] Repeat the process of recursive expansion and calculation of the new superimposed support until there are no new recursive expansions and the superimposed support is greater than the minimum support threshold, obtaining different combinations of different resources that users access in sequence within the same time window and meet the minimum support threshold. Each combination represents a set of resources that users access in sequence within the same time window, and the occurrence frequencies of these combinations meet the requirements of the support threshold;

[0073] For these resource combinations, calculate the confidence of the resource combinations in two consecutive orders (that is, a set of resources that the user first accesses within the same time window and then immediately accesses another set of resources), which is expressed as:

[0074] ;

[0075] Among them represents the confidence of the combinations and that meet the requirements of the support threshold, represents the occurrence frequency of the combinations and that meet the requirements of the support threshold, represents the occurrence frequency of the combination that meets the requirements of the support threshold;

[0076] Based on the historical confidence threshold for screening, use the resource combinations greater than or equal to the historical confidence threshold as high-confidence access sequences.

[0077] By constructing a transaction data table, the user access behavior is converted into transaction data, enabling the system to analyze the user's access habits using frequent pattern mining methods, calculate the occurrence frequency of the resource set X, ensure that only those resource combinations that are statistically significant for the user access pattern are analyzed, and ignore low-frequency access behaviors. Based on the occurrence frequency ranking of resources in the frequent item set, a conditional pattern base CPB is constructed. Through the FP-Tree, the computational complexity of access pattern mining is lower than that of the traditional Apriori method. The calculation of the conditional pattern base enables the frequent pattern expansion to be carried out in the local search space, reducing redundant calculations;

[0078] By recursively calculating the support of the conditional pattern base, ensuring that only the access patterns with strong correlation are retained in the FP-Tree structure, improving the accuracy of data mining, further reducing irrelevant data, and improving the efficiency of pattern mining, ensuring that the finally extracted access patterns represent the long-term trend of user behavior rather than some short-term and accidental access behaviors;

[0079] Through the recursive expansion of the FP-Tree, not only simple access patterns can be discovered, but also more complex multi-step access paths can be extracted, making the analysis results more comprehensive. Through strict support filtering, the finally extracted patterns can accurately describe the user's access habits rather than accidental events. Confidence calculation can quantify the correlation between different access patterns and identify whether the sequence of user access behaviors is regular, ensuring that the finally extracted patterns have long-term stability rather than behaviors that are only valid in a short period of time.

[0080] S2. Construct an access feature vector according to the access time, use a VAE encoder to extract the probability density of the access feature vector, and calculate the deviation value of the access feature vector using the Mahalanobis distance MD algorithm by calculating the covariance matrix;

[0081] Preferably, construct an access feature vector according to the access time and calculate the deviation value of the access feature vector, including calculating the mean (representing the time when this access pattern usually occurs) and variance (representing the volatility of the occurrence time of this access pattern) of the access window T according to the high-confidence access sequence and the corresponding access time;

[0082] The access feature vector constructed according to the resource combination order of the high-confidence access sequence (which can be embedded using One-Hot Encoding) and the mean and variance can be expressed as:

[0083] ;

[0084] where represents the access feature vector of the resource combination of the i-th access sequence, The resource combination of the i-th access behavior that meets the support threshold requirement The subsequent resource combination of the i-th access behavior that meets the support threshold requirement Represents the average access time of the access window T Represents the variance of the access time of the access window T;

[0085] Use the VAE encoder to extract the access feature vector The latent feature, and calculate the probability density under the standard normal distribution based on the latent feature, and use the negative log probability NLL to transform the access feature vector The probability density, expressed as:

[0086] ;

[0087] Where Represents The probability density, Represents The probability density of the latent feature under the standard normal distribution;

[0088] Based on the VAE encoder, extract the latent feature output of the access feature vector To obtain The latent mean and standard deviation, and calculate the corresponding covariance matrix, expressed as:

[0089] ;

[0090] Where ∑ represents the covariance matrix, N represents the total number of access feature vectors, Represents the Corresponding latent mean of the resource combination of the i-th access sequence, Represents the Corresponding latent mean of the resource combination of all access sequences, Represents the Transpose calculation of the corresponding latent standard deviation of the resource combination of the i-th access sequence, J represents the transpose calculation;

[0091] Use the Mahalanobis distance MD algorithm to calculate the deviation value of the access feature vector The latent feature, expressed as:

[0092] ;

[0093] Where Represents the deviation value of the access feature vector , Represents the access feature vector The latent feature.

[0094] By calculating the mean and variance of the access window, the time distribution characteristics of high-confidence access sequences can be quantified, ensuring the time stability analysis of access patterns. By constructing an access feature vector, the feature vector can simultaneously reflect the structural information and time characteristics of the accessed resources, thus providing richer information than analyzing the access resource combination alone. By using a VAE encoder to extract the hidden features of the access feature vector, the access pattern can be mapped to a low-dimensional latent space, improving the data representation ability. Based on the standard normal distribution, the probability density of the access pattern is calculated, which can measure the commonness of different access patterns. Using the negative log probability (NLL) to transform the probability density makes the scoring of abnormal access patterns more stable, ensuring that low-probability access patterns get higher anomaly scores, thereby improving the detection accuracy. By calculating the covariance matrix, not only the changes in individual access patterns are considered, but also the global correlation between different access sequences can be captured, improving the detection ability for abnormal access. Using the Mahalanobis distance to calculate the deviation value of the hidden features of the access feature vector enables the system to measure the distance between a certain access pattern and the historical normal pattern, avoiding misjudgments that may occur when only using the Euclidean distance.

[0095] S3. Respectively screen the probability density and the deviation value, apply the Hidden Markov Model (HMM) to define the hidden states, distinguish normal access and abnormal access, calculate the transition probability of the access states, use the Viterbi algorithm to calculate the conditional probability that maximizes the observed sequence, and determine the optimal state sequence.

[0096] Preferably, screen the probability density and the deviation value to define the hidden states, use the Viterbi algorithm to calculate the conditional probability that maximizes the observed sequence, and determine the optimal state sequence, including recording the probability density and the deviation value of the corresponding access feature vector of the access combination respectively within the time window.

[0097] Based on the sum of the mean and standard deviation of the historical deviation values as the deviation threshold, if the deviation value is less than or equal to the deviation threshold, it is determined that the access resource combination corresponding to the access feature vector has a small deviation.

[0098] Based on the sum of the mean and standard deviation of the historical probability density as the density threshold, if the probability density is greater than or equal to the density threshold, it is determined that the access resource combination corresponding to the access feature vector has a high probability of belonging to the normal distribution.

[0099] Apply the Hidden Markov Model (HMM) and define the hidden states , and regard the user access resource combinations with a high probability of belonging to the normal distribution and a small deviation as the normal access states of the hidden states for users. At the same time, define the remaining user access states as the abnormal access states of the hidden states.

[0100] Perform abnormal trend analysis. Through learning from historical data, combine the deviation values with large deviations and the probability densities with low probabilities to form an observation variable, expressed as:

[0101] ;

[0102] where represents the observation variable, represents the probability density with a low probability, represents the access feature vector with a large deviation deviation value;

[0103] Calculate the transition probability of the access behavior from the normal access state to the abnormal access state, expressed as:

[0104] ;

[0105] where represents the access state transition probability between time t and t - 1, represents the probability that if the previous access behavior is in the normal access state, the next access is still in the normal access state, represents the probability that if the previous access behavior is in the normal access state, the next access is in the abnormal access state, represents the probability that if the previous access behavior is in the abnormal access state, the next access is in the normal access state, represents the probability that if the previous access behavior is in the abnormal access state, the next access is still in the abnormal access state;

[0106] Statistically analyze the occurrence probability of the observation variable under the hidden state

[0107] ;

[0108] where represents the optimal state sequence, represents the maximum probability of the hidden state under the condition of the given observation variable (i.e., the access behavior within the time window from 1 to t).

[0109] By recording the probability density and deviation value of the access feature vector corresponding to the access combination in the time window, the system can analyze the changing trend of access behavior in a time series manner, rather than detecting a single access event in isolation. The hidden Markov model HMM is applied to treat the user access resource combination with a high probability of belonging to the normal distribution and a small deviation as the normal access state, so that the system can automatically distinguish between stable access patterns and abnormal access patterns. This method can effectively combine time series data, so that the detection of access patterns is not only based on static features, but also takes into account the evolution trend over time, thereby improving the overall detection capability. In addition, HMM allows the system to analyze the conversion law of access behavior through the time dimension, so that abnormal access detection is no longer based solely on current access behavior, but on the overall evolution trend of historical access patterns.

[0110] Abnormal trend analysis enables the system to discover abnormal access patterns based on long-term monitoring, rather than relying solely on short-term access behavior judgments. The transition probability of access behavior from normal access state to abnormal access state is calculated, so that the system can learn the changing trend of access behavior, rather than just detecting a single abnormal event. The transition probability can more accurately analyze the evolution of user behavior, allowing the system to more accurately predict future access patterns, improve access security while reducing false alarm rates. By calculating the Gaussian distribution probability density, the probability distribution of access behavior under different states can be accurately estimated. The Viterbi algorithm is used to calculate the conditional probability of the maximum observation sequence to determine the optimal state sequence, making the identification of abnormal access patterns more accurate. Through the optimal path search, abnormal access detection errors caused by local misjudgments can be avoided, making the final access state judgment more accurate. The calculation method of the Viterbi algorithm combines the historical access behavior within the entire time window, making the abnormal detection results more in line with the evolution of the access pattern, thereby improving the overall access security and detection accuracy.

[0111] S4, based on the abnormal determination of the state sequence, two-factor identity authentication is performed and abnormal access behavior data is recorded;

[0112] Preferably, the two-factor identity authentication is performed based on the abnormal determination of the state sequence, which means that based on the optimal state sequence, if the state sequence is an abnormal access state, it is determined to be a suspicious user and two-factor identity authentication is performed to ensure that the operation is performed by a legitimate user.

[0113] By judging whether access behavior is abnormal based on the optimal state sequence, the system can analyze user access patterns within a longer time window to avoid misjudgment caused by access fluctuations in a short period of time. Through additional identity authentication, the system can effectively prevent attackers from accessing with only stolen account credentials, reduce the risk of account hijacking, and improve the security level of identity authentication.

[0114] Further, recording abnormal access behavior data means recording all abnormal access behaviors in the abnormal access state to generate an access record, including the access time, the identity of the visitor, and the resource information requested.

[0115] By recording all abnormal access behaviors in the abnormal access state, the system can conduct a detailed security analysis afterwards, ensuring that the security team can trace back abnormal events, find out the sources of potential security threats, generate an access record, including the access time, the identity of the visitor, and the resource information requested, enabling the system to track the details of each abnormal access and ensuring that the security team can accurately judge the severity of abnormal behaviors.

[0116] This embodiment also provides a system for the security control method of a microcomputer host system, including:

[0117] A log data processing module that collects the access log data of users from the microcomputer host system;

[0118] A frequent itemset mining module that uses the FP-Growth algorithm to mine frequent itemsets from transaction data and calculates the support degree through the conditional pattern base CPB;

[0119] An access feature vector module that constructs an access feature vector according to the timestamp and resource combination of user accesses, uses VAE to extract the implicit features of access behaviors, and calculates the probability density of the access feature vector;

[0120] An abnormal trend analysis module that calculates the deviation value of the vector using the Mahalanobis distance algorithm, uses the Hidden Markov Model HMM to perform time series analysis on the high-confidence access sequences and the Mahalanobis distance, models the hidden states, and uses the Viterbi algorithm to calculate the most likely state sequence;

[0121] An access control decision module that makes real-time access control decisions according to the access state sequence output by the HMM and records the abnormal access behavior data.

[0122] This embodiment also provides a computer device applicable to the security control method of a microcomputer host system, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the security control method of the microcomputer host system as proposed in the above embodiment.

[0123] The computer device may be a terminal, which includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be achieved through WIFI, carrier networks, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0124] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method for realizing the security control of a microcomputer host system as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM for short), Electrically Erasable Programmable Read-Only Memory (EEPROM for short), Erasable Programmable Read Only Memory (EPROM for short), Programmable Red-Only Memory (PROM for short), Read-Only Memory (ROM for short), magnetic memory, flash memory, magnetic disks, or optical discs.

[0125] In summary, the present invention calculates the support of the conditional pattern basis through recursion to ensure that only the access patterns with strong correlation are retained in the FP-Tree structure, calculates the probability density of the access patterns based on the standard normal distribution to ensure that the access patterns with low probability obtain higher anomaly scores, thereby improving the detection accuracy. The hidden Markov model HMM is applied to regard the user access resource combinations with relatively high probability belonging to the normal distribution and small deviation as the normal access states, enabling the system to automatically distinguish stable access patterns from abnormal access patterns. The Viterbi algorithm calculates the conditional probability of maximizing the observation sequence to determine the optimal state sequence, making the recognition of abnormal access patterns more accurate. Through the optimal path search, the abnormal access detection errors caused by local misjudgment can be avoided, making the final judgment of the access state more accurate.

[0126] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A microcomputer host system security control method, characterized in that: include: Access the microcomputer host system to collect user log data, convert user access behavior into transaction data to calculate the frequency of occurrence, filter frequent item sets, calculate the support of the conditional pattern base through the conditional pattern base, recursively expand and calculate the superposition support according to the FP-Tree algorithm, calculate the confidence of different resource combinations, and filter high-confidence access sequences; The recursive expansion calculation is performed to calculate the confidence of different resource combinations to select high-confidence access sequences, including constructing a transaction data table for the log data file, converting the user access behavior into transaction data, and each transaction corresponds to the user's access record in different time periods; Assume that users access different resource data to form resource set X, and count the transaction data T containing resource set X X And calculate the frequency of occurrence in all transactions; Determine the minimum support threshold based on historical data, and only retain the resource set X whose occurrence frequency is greater than the minimum support threshold as a frequent itemset; Sort the resources in the frequent item set from high to low according to their frequency of occurrence, and select the transaction data T containing the resource to be accessed. X , determine all resource paths before the resource as the conditional pattern base CPB, and recursively calculate the support of the conditional pattern base; Determine the support threshold of the minimum conditional pattern base based on historical data, and retain support data greater than or equal to the threshold; According to the FP-Tree algorithm, recursive expansion is performed to continuously increase the number of frequent items, and the frequent items of the current expanded calculation number are combined to calculate the superposition support; Repeat the process of recursive expansion and calculating new superposition support until there is no new recursive expansion and the superposition support is greater than the minimum support threshold, and obtain different combinations of different resources that users visit in sequence in the same time window that meet the minimum support threshold. Each combination represents a group of resources that users visit in sequence in the same time window, and the frequency of occurrence of these combinations meets the support threshold requirement. For these resource combinations, the confidence of the resource combinations in two orders is calculated according to the order; Screening is performed based on the historical confidence threshold, and resource combinations greater than or equal to the historical confidence threshold are used as high-confidence access sequences; Construct access feature vectors based on access time, use VAE encoder to extract the probability density of access feature vectors, and calculate the deviation value of access feature vectors using Mahalanobis distance MD algorithm by calculating the covariance matrix; The probability density and deviation value are screened separately, the hidden Markov model HMM is applied to define the hidden state, normal access and abnormal access are distinguished, the transition probability of the access state is calculated, the Viterbi algorithm is used to calculate the conditional probability of maximizing the observation sequence, and the optimal state sequence is determined; Based on the abnormal judgment of the state sequence, two-factor identity authentication is performed and abnormal access behavior data is recorded.

2. The microcomputer host system security control method as claimed in claim 1, characterized in that: The step of constructing an access feature vector according to the access time and calculating a deviation value of the access feature vector includes calculating a mean and a variance of the access window T according to a high confidence access sequence and a corresponding access time; The access feature vector V is constructed based on the resource combination order, mean and variance of the high-confidence access sequence. i ; Use the VAE encoder to extract the access feature vector V i The implicit features of the vector V are obtained by calculating the probability density of the standard normal distribution based on the implicit features, and the negative logarithmic probability NLL conversion is used to access the feature vector V. i The probability density of Extract access feature vector V based on VAE encoder i The implicit feature output of V i The implicit mean and standard deviation of , and calculate the corresponding covariance matrix; Use the Mahalanobis distance MD algorithm to calculate the access feature vector V i The deviation value of the hidden feature.

3. The microcomputer host system security control method as claimed in claim 2, characterized in that: The screening probability density and deviation value define the hidden state, use the Viterbi algorithm to calculate the conditional probability of maximizing the observation sequence, and determine the optimal state sequence, including, within the time window, recording the probability density and deviation value of the corresponding access feature vector of the access combination respectively; The sum of the mean and standard deviation of the historical offset values ​​is used as the deviation threshold. If the deviation value is less than or equal to the deviation threshold, the access feature vector V is determined. i The corresponding access resource combination deviates less; Based on the sum of the mean and standard deviation of the historical probability density as the density threshold, if the probability density is greater than or equal to the density threshold, the access feature vector V is determined. i The corresponding access resource combination has a high probability of belonging to the normal distribution; Apply the hidden Markov model HMM and define the hidden state S t , the user access resource combinations with higher probability and smaller deviation belonging to normal distribution are defined as the normal access states of users in hidden states, and the remaining user access states are defined as abnormal access states of hidden states; Conduct abnormal trend analysis and, through historical data learning, combine large deviation values ​​and low probability density into observed variables; Calculate the transition probability of access behavior from normal access state to abnormal access state; Statistics hidden state S t The probability of occurrence of the observed variables is calculated using the Viterbi algorithm to maximize the conditional probability of the observed sequence to determine the optimal state sequence.

4. The microcomputer host system security control method as claimed in claim 1, characterized in that: The two-factor identity authentication is performed based on the abnormal determination of the state sequence, which means that if the state sequence is an abnormal access state based on the optimal state sequence, the user is judged as a suspicious user and two-factor identity authentication is performed.

5. The microcomputer host system security control method as claimed in claim 1, characterized in that: The access to the microcomputer host system to collect user log data includes accessing the log data file of the microcomputer host system, reading the user identification ID, access timestamp, access resource identification, access type, access success identification, access IP address and access device information; The user access frequency is calculated for outlier detection, and the sum of the mean and three times the standard deviation of the historical access frequency is used as the frequency threshold. If the user access frequency is greater than or equal to the frequency threshold, it is judged as abnormal data and removed.

6. The microcomputer host system security control method as claimed in claim 1, characterized in that: The recording of abnormal access behavior data refers to recording all abnormal access behaviors under abnormal access status and generating access records, including access time, visitor identity and requested resource information.

7. A system for a microcomputer host system security control method, based on the microcomputer host system security control method according to any one of claims 1 to 6, characterized in that: include, A log data processing module collects user access log data from the microcomputer host system; Frequent item set mining module uses FP-Growth algorithm to mine frequent item sets on transaction data and calculates support through conditional pattern base CPB; The access feature vector module constructs an access feature vector based on the timestamp and resource combination of the user's access, uses VAE to extract the implicit features of the access behavior, and calculates the probability density of the access feature vector; The abnormal trend analysis module uses the Mahalanobis distance algorithm to calculate the deviation value of the vector, uses the hidden Markov model HMM to perform time series analysis on the high-confidence access sequence and the Mahalanobis distance, and uses the Viterbi algorithm to calculate the most likely state sequence by modeling the hidden state; The access control decision module makes real-time access control decisions based on the access state sequence output by the HMM and records abnormal access behavior data.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the microcomputer host system security control method described in any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the microcomputer host system security control method described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Uncertain data frequent item set publishing method based on differential privacy

    CN112464277A

  • Mini-computer operation state information interaction control method and system

    CN118885085A