Management method and system for construction engineering cost data safety and medium
By analyzing the authentication behavior and operation behavior of the input account of the login system, calculating the degree of abnormality and autonomy, determining the possibility of identity theft attack, solving the problem that existing intrusion detection systems are difficult to identify identity theft attacks, and achieving effective security management of construction project cost data.
Patent Information
- Application Number
- CN202510480568.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-17
AI Technical Summary
Existing intrusion detection systems are difficult to effectively detect and prevent identity theft attacks, because these attacks do not generate obvious suspicious network traffic or system calls.
By analyzing the authentication behavior and operation behavior of the input account of the login system, generating an operation report, calculating the degree of authentication abnormality, the frequent operation of the operation behavior, and the degree of autonomy of the user's own operation, combining these factors to determine the possible degree of abnormal use, and notifying the technicians to handle the problem based on the set filter threshold.
Effectively identify and prevent identity theft attacks, promptly detect account abnormalities, reduce the loss of project cost data, and reduce the company's capital losses.
Smart Images

Figure CN120030534A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data analysis, and in particular to a management method, system and medium for the security of construction engineering cost data. Background Art
[0002] In the field of construction engineering, the confidentiality of construction costs is not only related to the core competitiveness of the enterprise, but also involves maintaining business secrets, maintaining good cooperative relationships, attracting potential investors, and enhancing the market value of the entire project. In addition, since the construction cost usually contains a large amount of sensitive information, such as cost budget, material procurement price, labor costs, etc., if this information is leaked, it may cause immeasurable economic losses to the enterprise; it may also affect the company's market positioning and negotiation strategy, and may even cause legal disputes. Therefore, in order to prevent the company's internal employee accounts from being stolen by criminals, resulting in illegal acquisition of construction cost data, the use of employee accounts must be strictly monitored and analyzed for abnormalities to ensure data security.
[0003] In existing methods, intrusion detection systems are usually used, which mainly rely on preset rule matching and behavior profiles to defend against potential network threats. However, identity theft attacks do not generate obvious suspicious network traffic or system calls in the computer system, making it difficult for intrusion detection systems to effectively detect and prevent such attacks. For example, identity theft attackers usually imitate the behavior of legitimate users, making the attack behavior look the same as normal operations in the system log, in order to evade the monitoring of rule-based detection systems. Summary of the invention
[0004] In order to solve the technical problem that the existing intrusion detection system does not generate suspicious network traffic and system calls on the computer for identity theft attacks, making it difficult to detect such attacks, the purpose of the present invention is to provide a management method for the security of construction project cost data, and the technical solution adopted is as follows: According to the input account of logging into the system, several types of operation information are obtained to generate an operation report, wherein the operation report includes authentication behavior and operation behavior; Analyze based on authentication behavior to obtain the degree of authentication abnormality; construct a rectangular coordinate system based on the operation behavior, obtain a curve graph according to the operation steps of the operation behavior, and analyze the similarity measurement value of the same operation behavior at any two logins; determine the first autonomous factor based on the time difference between each operation behavior and the corresponding simplest operation behavior; obtain the number of characteristic logins based on the similarity measurement value between the simplest operation and the operation behavior, obtain the second autonomous factor based on the number of characteristic logins, and obtain the degree of autonomy of the user's self-operation of the operation behavior at each login based on the first autonomous factor and the second autonomous factor; determine the possible degree of abnormal use in combination with the degree of authentication abnormality; Set a screening threshold. If the possibility of abnormal use is greater than the screening threshold, it is determined that abnormal use exists and the technical staff is notified to handle it.
[0005] Preferably, according to the input account number of the login system, several types of operation information are obtained to generate an operation report, including: According to the input account of logging into the system, the historical log data recorded by the server is extracted, and the login time, server, client, authentication type and protocol of any authentication behavior during login authentication are collected respectively, as well as the number of occurrences of any operation behavior of modifying, deleting and downloading database information in the historical log data during different logins, and an operation report is generated.
[0006] Preferably, the authentication behavior is analyzed to obtain the degree of authentication abnormality, including: Analyze the common situations corresponding to the authentication behavior at any login based on any authentication behavior; The common situations corresponding to the authentication behavior are used as the coordinate axis data to construct a coordinate system, and the coordinate axis data are clustered to obtain each cluster area. The distance between the cluster area corresponding to the common situation of the authentication behavior corresponding to any login and the center position of other cluster areas is obtained to calculate the degree of authentication abnormality.
[0007] Preferably, the common situations corresponding to the authentication behaviors at any login are analyzed, and the corresponding specific methods are: Determine a first ratio based on the maximum value of the number of times any authentication behavior appears in the historical log data during any login authentication and the number of times any authentication behavior appears in the historical log data in all login behaviors; Based on the number of times any authentication behavior appears in the historical log data during any login authentication and the cumulative number of times any authentication behavior appears in the historical log data in all login behaviors, a second ratio is determined; based on the first ratio and the second ratio, the common situation corresponding to any authentication behavior during any login authentication is determined.
[0008] Preferably, the specific method for calculating the degree of authentication anomaly is as follows: Based on the distance between the cluster area corresponding to the common situation of the authentication behavior corresponding to any login and the center position of each cluster area and the number of data points in the cluster area corresponding to the common situation of the authentication behavior corresponding to any login, the degree of authentication abnormality at any login is determined.
[0009] Preferably, obtaining the frequency of operation behavior is to calculate the frequency of operation of any operation behavior during any login, and the corresponding method is specifically: For the frequency of any operation behavior during any login, a first characteristic coefficient is determined based on the frequency of the number of times the operation behavior is performed during the login; Based on the average of the time intervals between two adjacent occurrences of this type of operation behavior during the login, a second characteristic coefficient is determined; and the frequency of operation of any type of operation behavior during any login is obtained according to the first characteristic coefficient and the second characteristic coefficient.
[0010] Preferably, obtaining the second autonomous factor includes: Taking any operation behavior at any login as the target operation behavior at the target login, obtaining the simplest operation steps of the target operation behavior, and the difference between the time taken for the first occurrence of the target operation behavior at the target login and the simplest operation steps; Determine a first autonomous factor based on a negative correlation coefficient of a difference between the time taken for a previous login adjacent to the target login and the target login; Based on the similarity measurement value between the target operation behavior that first appears in the target login and the target operation behavior that first appears in the previous login, determine the similarity feature factor of each two adjacent logins under the target operation behavior; the number of logins corresponding to all similar feature factors before the target login being less than a preset similarity threshold is taken as the first feature login number; Based on the similarity measurement value between the target operation behavior that appears for the first time at each login and the simplest operation steps, an operation similarity factor of the target operation behavior at each login is determined; the number of logins corresponding to when the difference between the operation similarity factors of the target operation behavior at each two adjacent logins before the target login is greater than a preset difference threshold is used as the second characteristic login number; Based on the ratio between the first characteristic login times and the second characteristic login times, a second autonomous factor is determined; and according to the first autonomous factor and the second autonomous factor, the degree of autonomy of the user's self-operation of the target operation behavior during the target login times is obtained.
[0011] Preferably, the possible degree of abnormal use is determined by: For any login behavior, obtain the cumulative sum of the differences in the frequency of operation between this login behavior and other login behaviors under the same operation behavior as the first coefficient; obtain the cumulative sum of the negative correlation coefficients of the degree of user autonomy of this login behavior under all operation behaviors as the second coefficient; and obtain the possible degree of abnormal use during this login based on the first coefficient, the second coefficient and the degree of authentication abnormality of the login behavior.
[0012] To solve the above problems, the present application also provides a management system for construction engineering cost data security, which is used to run a management method for construction engineering cost data security as described in any of the above items, and includes the following modules: A data collection module is used to obtain several types of operation information and generate an operation report according to the input account of logging into the system, wherein the operation report includes authentication behavior and operation behavior; The data analysis and processing module is used to: analyze based on the authentication behavior to obtain the degree of authentication abnormality; analyze the operation behavior to obtain the frequency of operation behavior and the degree of autonomy of the user's self-operation; and determine the possible degree of abnormal use in combination with the degree of authentication abnormality; The data screening and early warning module is used to: set a screening threshold. If the possibility of abnormal use is greater than the screening threshold, it is determined that there is abnormal use and the technical staff is notified to handle it.
[0013] To solve the above problems, the present application also provides a medium, wherein the medium stores program data, and when the program data is executed, a method for managing the security of construction project cost data as described in any of the above items is implemented.
[0014] The present invention has the following beneficial effects: 1. This application analyzes abnormal authentication and operation behaviors based on the input account number for logging into the system, and obtains the degree of authentication abnormality, the frequency of operation behavior, and the degree of autonomy of the user's own operation in turn, and combines the three to determine the possible degree of abnormal use, that is, to evaluate the abnormal situation in the authentication behavior, and then identify the abnormal operation behavior that occurs based on the operating habits of the account user; if the possible degree of abnormal use is greater than the screening threshold, it is determined that abnormal use exists, so that the account abnormality can be discovered in time when it occurs, and the technical staff can be notified in time to handle it, which can effectively reduce the large-scale loss of engineering cost data and reduce the company's financial losses.
[0015] 2. A management system and medium for the security of construction project cost data provided by the present invention have the same beneficial effects as a management method for the security of construction project cost data provided by the present invention, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1A flowchart of a method for managing construction project cost data security provided by an embodiment of the present invention; Figure 2 A curve diagram of the operation behavior of a method for managing the security of construction project cost data provided by one embodiment of the present invention; Figure 3 A curve diagram showing the comparison of any two operation behaviors of a method for managing construction project cost data security provided by an embodiment of the present invention Figure 1 ; Figure 4 A curve diagram showing the comparison of any two operation behaviors of a method for managing construction project cost data security provided by an embodiment of the present invention Figure 2 . DETAILED DESCRIPTION
[0018] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of the management method, system and medium for the security of construction project cost data proposed by the present invention, its specific implementation method, structure, characteristics and effects in combination with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.
[0019] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0020] The specific solutions of the method, system and medium for managing the security of construction project cost data provided by the present invention are described in detail below in conjunction with the accompanying drawings.
[0021] Traditional intrusion detection systems defend against potential network threats through pre-set rule matching and behavior profiles. However, identity theft attack behaviors do not generate obvious suspicious network traffic or system calls in computer systems, making it difficult to effectively detect and prevent such attacks. In an embodiment of the present invention, a management method for the security of construction project cost data is provided. According to the input account logged into the system, abnormal authentication behaviors and operation behaviors are analyzed to obtain the degree of authentication anomaly, the frequency of operation of the operation behavior, and the degree of autonomy of the user's self-operation in sequence. By combining these three, the possible degree of abnormal use is determined. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and the technical personnel are notified for processing to achieve the purpose of securely protecting the construction project cost data. To implement a management method for the security of construction project cost data, a management system and medium for the security of construction project cost data are provided. Substantially, the system and the medium are both software systems, which are composed of modules that implement corresponding functions. Now, the specific steps in this method will be introduced in detail.
[0022] Please refer to Figure 1 , which shows the flowchart of the steps of a management method for the security of construction project cost data provided by an embodiment of the present invention. The method includes: Step S1: According to the input account logged into the system, obtain several types of operation information to generate an operation report, where the operation report includes authentication behaviors and operation behaviors; Step S2: Analyze based on the authentication behaviors to obtain the degree of authentication anomaly; analyze the operation behaviors to obtain the frequency of operation of the operation behaviors and the degree of autonomy of the user's self-operation in sequence; combine the degree of authentication anomaly to determine the possible degree of abnormal use; Step S3: Set a screening threshold. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and the technical personnel are notified for processing.
[0023] For better illustration, in today's digital age, with the rapid development of information technology, the storage, processing, and transmission of construction project cost data increasingly rely on computer systems and network technologies. The importance of construction project cost confidentiality is mainly reflected in protecting business secrets, maintaining cooperative relationships, attracting investments, and enhancing project value. Therefore, ensuring that these data are not accessed, tampered with, or leaked without authorization is of crucial significance for protecting corporate interests, maintaining market order, and ensuring national economic security. Among them, construction project cost data refers to the total sum of all costs involved in completing the entire construction process in a construction project, that is, it includes the costs incurred in various links from the early-stage planning and design, material procurement, construction, to the later-stage maintenance and management of the project. It not only covers direct costs such as material costs, labor costs, and machinery usage costs, but also includes indirect costs such as management fees, financial expenses, and taxes.
[0024] As an optional implementation, in this embodiment, the login system refers to a server used by any enterprise to store construction project cost data.
[0025] Furthermore, in step S1, according to the input account number for logging into the system, several types of operation information are obtained to generate an operation report, including: According to the input account of logging into the system, the historical log data recorded by the server is extracted, and the login time, server, client, authentication type and protocol of any authentication behavior during login authentication are collected respectively, as well as the number of occurrences of any operation behavior of modifying, deleting and downloading database information in the historical log data during different logins, and an operation report is generated.
[0026] Specifically, in this embodiment, in order to obtain authentication behavior and operation behavior, the target IP (Internet Protocol) and operation code corresponding to the input account are collected, and an operation report is generated in chronological order from early to late according to the time when the information is obtained, wherein the target IP is a communication protocol used for a data packet switching network, which specifies the format and routing method of data packets transmitted in the network; the operation code refers to a unique code used to identify and distinguish different operation behaviors. Through the operation code, the system can accurately identify and record the user's operation behavior; and the operation report is as shown in Table 1, a schematic table of the operation report generated corresponding to the employee input account.
[0027] Table 1. Schematic diagram of the operation report generated by the employee's account input Understandably, there are significant differences in the behavior patterns of enterprise employees when they log into the system normally and attackers when they perform system login authentication. For example, when logging into the system, attackers will take more covert means and usually choose to perform identity authentication during a time period when normal user activities are less to reduce the risk of being discovered. In daily work and life, each user tends to use the authentication client they are familiar with to log in, while attackers, due to geographical restrictions or for specific attack purposes, often use clients that are significantly different from those that ordinary users are accustomed to using. In addition, the purpose of attackers entering the system through identity authentication is different from that of normal users. The main purpose of attackers is to move around the network and obtain more permissions, sensitive data, etc., while normal users mainly perform daily work or access necessary information resources. Therefore, attackers will also have significant differences in the choice of authentication types from normal users. Therefore, any authentication behavior needs to be analyzed in order to more effectively identify and prevent potential attack behaviors.
[0028] Furthermore, in step S2, the authentication behavior is analyzed to obtain the degree of authentication abnormality, including: It can be explained that each time an input account, that is, an employee account, logs in and out of the system, a test is performed on the possibility of the input account being attacked, that is, a security test is performed on the input account to assess the risk of potential attacks on the system; and the login time, server, client, authentication type and protocol during login authentication, the number of occurrences of any authentication behavior in the historical log data, and the proportion of any authentication behavior in the total data of the same type are obtained. The more the number of occurrences and the larger the proportion, the more frequently the authentication behavior occurs and is regarded as part of daily operations, indicating that the authentication behavior currently being analyzed is more normal.
[0029] Step S21: analyzing common situations corresponding to any authentication behavior during any login based on any authentication behavior; It is clarified that authentication behavior refers to representative characteristics, that is, the characteristics exhibited by any authentication behavior in the current login behavior. The common situation corresponding to the authentication behavior refers to the authentication mode used by the user when logging into the system. Any authentication behavior is analyzed to determine whether it deviates from the normal mode. If the usage of a certain authentication method is significantly different from the common situation, for example, an employee who rarely uses fingerprint recognition suddenly uses fingerprint recognition to log in frequently, it may be an abnormal signal and be determined as abnormal authentication behavior.
[0030] Further, in step S21, the common situations corresponding to the authentication behaviors at any login are analyzed, and the corresponding specific method is: based on the maximum number of times any authentication behavior appears in the historical log data at any login authentication and the number of times any authentication behavior in all login behaviors appears in the historical log data, a first ratio is determined; based on the cumulative sum of the number of times any authentication behavior appears in the historical log data at any login authentication and the number of times any authentication behavior in all login behaviors appears in the historical log data, a second ratio is determined; based on the first ratio and the second ratio, the common situations corresponding to any authentication behavior at any login authentication are determined.
[0031] Furthermore, in step S21, the common situations corresponding to the authentication behaviors at any login are analyzed, and the corresponding calculation formula is: in, Indicates First login Common situations corresponding to the authentication behaviors; Indicates First login The number of times the authentication behavior occurs in the historical log data; Indicates that among all login behaviors, The maximum number of times the authentication behavior appears in the historical log data; Indicates First login The number of occurrences of this authentication behavior in the historical log data and the number of occurrences of the first The ratio of the total number of times the authentication behavior appears in the historical log data is the second ratio.
[0032] To illustrate, the first ratio The larger the value, the The more normal the corresponding situation of the authentication behavior is, the more it conforms to the normal employee authentication behavior, and the smaller the possibility of abnormal authentication. Indicates First login The number of occurrences of this authentication behavior in the historical log data and the number of occurrences of the first The ratio of the total number of times the authentication behavior appears in the historical log data. The larger the value, the higher the The more times the corresponding situation of a certain authentication behavior occurs, the more normal the user's authentication behavior is.
[0033] It can be understood that when making an abnormal judgment based on the authentication behavior, if the common situations corresponding to the authentication behavior at any login are simply superimposed, it cannot well show the abnormal degree of the current authentication behavior; therefore, in this embodiment, the common situations corresponding to the login are usually obtained based on all authentication behaviors to evaluate any authentication behavior, and then these result values are placed in the coordinate system, that is, the common situations corresponding to the authentication behavior at login are used as coordinate axis data to construct the coordinate system; then the various result values in the coordinate system are clustered by the density clustering algorithm, and there is a significant difference between the behavior of the attacker and the behavior of normal employees. When the authentication behavior is abnormal, the data points in the corresponding cluster area will appear more outliers than the data points in other cluster areas, so as to effectively identify the abnormal behavior; wherein, the density clustering algorithm groups the data by identifying high-density areas in the data space, that is, if the distance between the data points in a cluster area is close enough, then these data points belong to the same cluster area.
[0034] Step S22: construct a coordinate system using the common situations corresponding to the authentication behavior as coordinate axis data, cluster the coordinate axis data to obtain each cluster area, obtain the distance between the cluster area corresponding to the common situation corresponding to the authentication behavior during any login and the center position of other cluster areas, and calculate the degree of authentication abnormality.
[0035] Specifically, a coordinate system is constructed using the common situations corresponding to the authentication behavior as coordinate axis data, that is, the horizontal axis represents any authentication behavior, and the vertical axis is the common situation corresponding to the authentication behavior. The performance data of the authentication behavior is quantified by plotting the data points in the coordinate system; then the Euclidean distance formula is used to calculate the distance between the cluster area corresponding to the common situation of the authentication behavior corresponding to any login and the center position of other cluster areas. If the number of data points in the cluster area corresponding to the common situation of the authentication behavior corresponding to the login analyzed at the time is smaller and the distance to the center position of other cluster areas is farther, it means that the data points in the current cluster area are more outliers, indicating that the authentication behavior is more abnormal; wherein, the Euclidean distance formula is a method for calculating the straight-line distance between two points in a multidimensional space, and then the distance between the two points is obtained by calculating the square root of the sum of the squares of the differences between the coordinate axis data; and the number of data points in each cluster area after clustering is obtained.
[0036] Further, in step S22, the degree of authentication abnormality is calculated, and the corresponding specific method is: based on the distance between the cluster area corresponding to the common situation of the authentication behavior corresponding to any login and the center position of each cluster area and the number of data points in the cluster area corresponding to the common situation of the authentication behavior corresponding to any login, the degree of authentication abnormality at any login is determined.
[0037] Furthermore, in step S22, the degree of authentication abnormality is calculated, and the corresponding calculation formula is: in, Indicates The degree of authentication anomaly during the first login; Indicates The number of data points in the cluster area corresponding to the common situation of the authentication behavior corresponding to the login; Indicates The cluster area corresponding to the common situation of the authentication behavior corresponding to the first login is the same as the The distance between the center positions of the cluster areas; Indicates The number of data points in a cluster area.
[0038] To explain, Indicates The number of data points in the cluster area corresponding to the common situation of the authentication behavior corresponding to the login. The smaller the value, the more special the authentication behavior currently analyzed is, indicating that the current login authentication behavior is significantly different from the behavior pattern of normal employees, and is more likely to be an abnormal login; The larger the value, the The more outliers the data points in the cluster area corresponding to the common situation of the authentication behavior during the first login, the more outliers the data points in the cluster area corresponding to the common situation of the authentication behavior during the first login. The greater the possibility of abnormal authentication behavior during the first login.
[0039] It can be explained that in step S2, the operation behavior is analyzed to obtain the frequency of the operation behavior and the degree of autonomy of the user's own operation in turn; among them, the frequency of the operation behavior refers to the frequency of any operation behavior when the user uses the system or application, which is used to measure the number of times the user repeats any operation behavior within a certain period of time; the degree of autonomy of the user's own operation refers to the degree to which the user can freely make choices and decisions according to his or her own wishes and needs during use.
[0040] Understandably, when an attacker conducts an identity theft attack, there are usually two attack scenarios, namely remote attack and internal attack. When an attacker attacks the system through remote means and exploits network vulnerabilities, the use of authentication behavior analysis can effectively judge and prevent. However, when the attacker directly accesses the host of the legitimate user and knows the exact login password and conducts an internal attack on the system, this method cannot be defended or identified. Different employees have their own operating procedures when working. When the identity is stolen, the attacker's behavior is significantly different from the normal operating habits of normal employees. Therefore, if the attacker is an internal attack, a comprehensive analysis based on the operating behavior is also required.
[0041] If during a certain login, an employee's operation behavior shows a significant difference in the number of occurrences and frequency of the same operation behavior at ordinary times, it indicates that the employee's operation behavior is abnormal. For example, in a normal workflow, employees' operations on the database are usually mainly storage and modification. Once identity theft occurs, the thief's behavior pattern will change significantly. He will download a large amount of data from the database frequently, which is very different from the employee's usual operation habits. In addition, when a normal employee downloads a large amount of data, special analysis marks are required to avoid misjudgment. Through this comparative analysis, abnormal behavior can be discovered in a timely manner, thereby effectively identifying and preventing identity theft in internal attacks.
[0042] Specifically, the operation behavior is any behavior of modifying, deleting and downloading database information during different logins. By crawling entity words and entity relationships in historical log data, the number of any operation behavior and the time of the operation are obtained; that is, the historical log data is preprocessed, including removing irrelevant information, correcting format errors and standardizing timestamps, and the historical log data is cleaned and formatted to identify and extract entity words related to the operation behavior, so as to obtain the number of any operation behavior and the time of the corresponding operation behavior.
[0043] At the same time, the process sequence of different operating behaviors is obtained, that is, the entire process of any operating behavior from the beginning to the end, including the duration of the simplest step process and the normal process of completing the operating behavior. Among them, the simplest step process refers to the most basic steps and time required for the user to complete the current operating behavior without any interference or abnormal circumstances; the normal process of completing the operating behavior refers to the entire time it takes for the user to complete the task according to the established process under a standard operating environment.
[0044] Further, in step S2, obtaining the frequency of operation behavior is to calculate the frequency of operation of any operation behavior at any login, and the corresponding method is specifically: for the frequency of operation of any operation behavior at any login, based on the frequency of the number of times this operation behavior is performed at this login, determine the first characteristic coefficient; based on the mean of the time intervals between each two adjacent occurrences of this operation behavior at this login, determine the second characteristic coefficient; according to the first characteristic coefficient and the second characteristic coefficient, obtain the frequency of operation of any operation behavior at any login.
[0045] Furthermore, in step S2, obtaining the frequency of operation behavior is to calculate the frequency of operation of any operation behavior during any login, and the corresponding calculation formula is: in, Indicates First login The frequency of operation of the operation behavior; Indicates First login The number of times the operation is performed; Indicates The maximum number of times this type of operation occurs in historical log data; Indicates First login The mean time interval between two adjacent occurrences of a certain operation behavior.
[0046] To illustrate, the first characteristic coefficient The larger the result value, the First login The more frequent the operation behavior is; is the second characteristic coefficient, , Indicates First login Operation Behavior The first appearance and The interval between occurrences, The smaller the value of First login The smaller the time interval between two occurrences of an operation behavior, the First login The more frequent the operation.
[0047] Understandably, when performing daily work tasks, due to changes in work tasks, the frequency of operations of normal employees in different operating behaviors may also change. Therefore, when conducting analysis, it is necessary to exclude the changes in the frequency of operations caused by normal task changes, that is, to make further judgments and analyses on the operating behaviors based on the different arrangements of process steps when different employees operate. In addition, after employees become familiar with system operations, their usage habits will gradually adjust the process steps to the most time-saving and convenient ones. Therefore, in order to distinguish the differences in process steps between normal employees' conscious self-adjustment of operating behaviors and account theft, it is necessary to distinguish the differences in any operating behavior during multiple consecutive account logins. That is, when the difference gradually increases after multiple consecutive logins, it means that the employee is modifying the process steps independently, and the possibility of account abnormality is relatively small, and relatively, the risk of account theft is relatively small. On the contrary, when the difference suddenly increases after multiple consecutive logins, it means that the current account is more likely to be abnormal, that is, the possibility of account theft is also greater.
[0048] Furthermore, in step S2, obtaining the degree of autonomy of the user's self-operation includes: A rectangular coordinate system is constructed based on the operation behavior, and a curve graph is obtained according to the operation steps of the operation behavior. The similarity measurement value of the same operation behavior at any two logins is analyzed to analyze the change difference of the operation steps.
[0049] Specifically, a rectangular coordinate system is constructed based on the operation behavior, and a curve graph is obtained according to the operation steps of the operation behavior, that is, each operation step in the operation behavior is numbered, and any operation behavior is used as the horizontal axis data, and the number of the operation step is used as the vertical axis data to construct a rectangular coordinate system, and a curve graph is drawn by connecting lines according to the operation steps of any operation behavior; when performing the same operation behavior, if there is a large difference between the curve graph of the user's current operation behavior and the curve graph of the current operation behavior drawn according to the user's historical log data, it indicates that the current operation behavior is abnormal, which means that the possibility of account theft is greater.
[0050] As an optional implementation, in this embodiment, Login and Log in to make analysis.
[0051] Please combine Figure 2 - Figure 4, which respectively show a curve diagram of an operation behavior of a method for managing construction engineering cost data security provided by this embodiment, and a curve diagram of a comparison of any two operation behaviors Figure 1 The curve diagram comparing any two operation behaviors Figure 2 ;in, Figure 2 The curve in the figure shows the A curve diagram drawn based on the operation steps of an operation behavior; Figure 3 and Figure 4 The indicated ones are Login and First login The curve diagram corresponding to the operation behavior is Login and First login When the step flow difference between the two operation behaviors is small, the corresponding drawing is Figure 3 ; If Login and First login When the step flow between the two operation behaviors is very different, the corresponding drawing is Figure 4 .
[0052] Next, we use the Dynamic Time Warping (DTW) method to Login and First login The similarity measurement value of the two operations is obtained by comparing the curve graph obtained by recording the operation behavior. DTW can process time series data of different lengths and align the two sequences through a special curved path for comparison; the similarity metric is a numerical indicator used to measure the similarity between the two; and the sigmoid function is used to align the two sequences. Perform negative correlation normalization operation and get , whose value range is (0,1), where the sigmoid function is used as an activation function to control the output range within the range of 0-1, which has a normalization effect. 0 means that the two are completely different, and 1 means that the two are exactly the same; when When the first of the two login behaviors is analyzed, The operation steps of the operation behaviors vary greatly; and the continuous The number of times the operation steps in the operation behavior changed significantly during login was .
[0053] Get the The first time you log in, The similarity measure between the operation behavior and the simplest operation step z , and The first time you log in, The similarity measure between the operation behavior and the simplest operation step z , the difference between the similarity measurement values corresponding to the same operation steps in consecutive logins , calculate the difference The number of ,when The larger it is, the more it proves that the process steps of the m-th consecutive operation are gradually optimized and are more likely to be changed by the user.
[0054] Specifically, this embodiment uses any operation behavior at any login as the target operation behavior at the target login, obtains the simplest operation steps of the target operation behavior, and the difference between the time taken for the first occurrence of the target operation behavior at the target login and the simplest operation steps. First login This operation behavior is used as the target operation behavior for the target login.
[0055] Further, obtaining the degree of autonomy of the user's self-operation includes: determining a first autonomy factor based on a negative correlation coefficient of the difference between the time spent at the previous login adjacent to the target login and the target login; determining a similarity feature factor between each two adjacent logins under the target operation behavior based on a similarity measure between the target operation behavior that first appears at the target login and the target operation behavior that first appears at the previous login; taking the number of logins corresponding to all similar feature factors before the target login being less than a preset similarity threshold as the first feature login number; determining the operation similarity factor of the target operation behavior at each login based on the similarity measure between the target operation behavior that first appears at each login and the simplest operation steps; taking the number of logins corresponding to the difference in the operation similarity factor of the target operation behavior at each two adjacent logins before the target login being greater than a preset difference threshold as the second feature login number; The first feature login times represent the login times with large differences in similarity metric values, and the second feature login times represent the login times with large differences in step changes. Therefore, the second autonomous factor is determined based on the ratio between the first feature login times and the second feature login times; the degree of autonomy of the user's self-operation of the target operation behavior at the target login time is obtained based on the first autonomous factor and the second autonomous factor. The similarity threshold is 0.3, and the difference threshold is 0.
[0056] Furthermore, the degree of autonomy of the user's self-operation is calculated, and the corresponding calculation formula is: in, Indicates First login The degree of autonomy of the user in performing the operation; Indicates The simplest operation steps for this operation; Indicates that before the kth login, The first characteristic login count of adjacent operation behaviors in the login operation step; Indicates the number of consecutive logins; Indicates continuous The second characteristic login number of the login operation; Indicates The first time you log in, the Operation behaviors and simplest operation steps The difference in time used, Indicates The first time you log in, the Operation behaviors and simplest operation steps The difference in time used, Indicates Login and The first time you log in, the Operational behavior and The difference in duration used; Represents a constant term, used to prevent the denominator from being zero.
[0057] Make a statement, before the kth login Get the first occurrence of the Operation behaviors and simplest operation steps The difference in similarity measure value is recorded as the similarity difference value, Before the kth login The number of logins corresponding to the similarity difference value greater than 0 in the login operation steps, that is, Indicates that before the kth login, The number of times the similarity measurement values of adjacent operation behaviors in the login operation steps are greatly different, and the larger the value, the more consecutive When you log in for the first time, The operation behavior is gradually optimized until the simplest operation steps are reached. At this point, the more likely it is that the current operation behavior is more likely to be changed by the user. Indicates continuous The number of times the login operation steps vary greatly. The smaller the time, the more Login and The first time you log in, the Operational behavior and During this period of time, the number of changes in the operation steps is small and the frequency is low, which means that the current account may not be stolen, and it is more likely that the user modifies the operation steps on his own.
[0058] is the first autonomous factor, when The smaller the value of is, the smaller the change between the operation steps is, and the less likely it is to be stolen. Login and The first time you log in, the Operational behavior and When the duration is exactly the same, that is, when the steps of the two operations are exactly the same, the denominator may be 0, so a constant term is added. Used to prevent the denominator from being 0; Indicates First login The smaller the value, the greater the possibility that the employee account is abnormal, that is, the greater the possibility that the account is stolen.
[0059] Understandably, Indicates First login The frequency of the operation behavior, that is, the R value represents the change in the frequency of the operation instructions. During different logins, the frequency of normal instructions issued by normal employees is interspersed with the frequency of other instructions used by attackers, which may affect the frequency of normal instructions and cause interference. Therefore, in the analysis process, in order to eliminate this interference, it is necessary to compare the number of occurrences of the operation behavior and the changes in the operation steps of the operation behavior in the current analysis login compared with other logins, that is, Indicates First login The E value of any operation behavior is compared with the degree of user autonomy in the operation behavior. When the E value is smaller and the difference with the E value of other login operations is larger, it means that the possibility of abnormality in the current analyzed login is greater, which means that the current system is more likely to be stolen by attackers. It can be explained that when the aforementioned normal employees download large quantities of data, the E value of this operation behavior is analyzed normally and specially marked to prevent system misjudgment.
[0060] Furthermore, in step S2, the possible degree of abnormal use is determined, and the corresponding specific method is: For any login behavior, obtain the cumulative sum of the differences in the frequency of operation between this login behavior and other login behaviors under the same operation behavior as the first coefficient; obtain the cumulative sum of the negative correlation coefficients of the degree of user autonomy of this login behavior under all operation behaviors as the second coefficient; and obtain the possible degree of abnormal use during this login based on the first coefficient, the second coefficient and the degree of authentication abnormality of the login behavior.
[0061] Furthermore, in step S2, the possible degree of abnormal use is determined, and the corresponding calculation formula is: in, Indicates The likelihood of abnormal usage during the first login; represents the first coefficient, , Indicates First login The frequency of operation of the operation behavior; Indicates First login The frequency of operation of the operation behavior; Indicates the number of logins; Indicates the number of operation behaviors; Indicates First login The degree of autonomy of the user in performing the operation; Indicates The degree of authentication anomaly during the first login, is the second coefficient.
[0062] To explain, The larger the value is, the more abnormal the operation behavior of the current analysis is.
[0063] It can be explained that in step S3, a screening threshold is set, and if the possibility of abnormal use is greater than the screening threshold, it is determined that abnormal use exists, and the technical staff is notified to handle it.
[0064] As an optional implementation, in this embodiment, the screening threshold is 0.8.
[0065] Specifically, Indicates The possibility of abnormal use during the first login is normalized using the sigmoid function to obtain ,like , it indicates that there is abnormal use in the current login, that is, there is a problem of account theft in the current login. At this time, the system sends an intrusion alarm signal to the technician's computer or mobile phone to notify the technician to handle it.
[0066] Make an explanation. When the technical staff handles the case, they confirm the abnormal authentication and operation behaviors, that is, compress and package the login time, server, client, authentication type, protocol, and all operation information of the stolen login authentication to transmit to the processing equipment, intercept the intruding account in time and avoid further losses.
[0067] Preferably, after the abnormal usage is processed, a series of preventive strategies can be adopted to strengthen security protection measures, including but not limited to: establishing a strict data access control mechanism to ensure that only authorized personnel can access sensitive information; applying advanced encryption technology to encrypt data, so that even if the data is intercepted during transmission, unauthorized third parties cannot interpret it; regularly updating and strengthening password policies to ensure the complexity and difficulty of guessing passwords; implementing multi-factor authentication to increase account security; and real-time monitoring of login behavior to facilitate timely detection of abnormal patterns to greatly reduce the risk of input account theft; and regular data backup and recovery drills can also be performed to prevent data loss due to system failures or human errors.
[0068] It can be understood that the present application analyzes abnormal authentication and operation behaviors according to the input account number of the login system, and obtains the degree of authentication abnormality, the frequency of operation behavior and the degree of autonomy of the user's own operation in turn, and combines the three to determine the possible degree of abnormal use, that is, to evaluate the abnormal situation in the authentication behavior, and then identify the abnormal operation behavior according to the operating habits of the account user; if the possible degree of abnormal use is greater than the screening threshold, it is determined that abnormal use exists, so that the account abnormality can be discovered in time when it occurs, and the technical personnel can be notified in time to deal with it, which can effectively reduce the large-scale loss of engineering cost data and reduce the financial loss of the enterprise.
[0069] A management system for construction engineering cost data security provided by one embodiment of the present invention is used to run a management method for construction engineering cost data security provided by one of the aforementioned embodiments, and includes the following modules: A data collection module is used to obtain several types of operation information and generate an operation report according to the input account of logging into the system, wherein the operation report includes authentication behavior and operation behavior; The data analysis and processing module is used to: analyze based on the authentication behavior to obtain the degree of authentication abnormality; analyze the operation behavior to obtain the frequency of operation behavior and the degree of autonomy of the user's self-operation; and determine the possible degree of abnormal use in combination with the degree of authentication abnormality; The data screening and early warning module is used to: set a screening threshold. If the possibility of abnormal use is greater than the screening threshold, it is determined that there is abnormal use and the technical staff is notified to handle it.
[0070] It is explained that the data acquisition module, as a front-end module, is used to accurately capture the authentication behavior and operation behavior at each login to ensure the comprehensiveness and accuracy of the operation information; the data analysis and processing module is responsible for cleaning, integrating and deeply analyzing the generated operation report to convert the relevant data in the operation report, and obtain the frequency of operation behavior, the degree of user autonomy and the degree of authentication abnormality in turn; the data screening and early warning module is used to screen out signs of abnormal use. Once the data screening and early warning module detects that the possible degree of abnormal use exceeds the preset screening threshold, it will immediately trigger the early warning mechanism and notify the technical staff to intervene and deal with it, effectively preventing the occurrence of security incidents such as data leakage or tampering; that is, through the collaborative work of the three modules, the security of construction project cost data is jointly guaranteed.
[0071] It can be understood that when a module of a management system for the security of construction project cost data is in operation, it is necessary to utilize a management method for the security of construction project cost data provided by the aforementioned embodiment. Therefore, whether the data acquisition module, the data analysis and processing module, and the data screening and early warning module are integrated or different hardware is configured to produce functions similar to the effects achieved by the present invention, they all fall within the scope of protection of the present invention.
[0072] An embodiment of the present invention further proposes a medium, which stores program data. When the program data is executed, a management method for the security of construction project cost data as described in the aforementioned embodiment is implemented; the medium has the same beneficial effects as the aforementioned management method for the security of construction project cost data, which will not be repeated here.
[0073] It should be noted that the sequence of the above embodiments of the present invention is only for description and does not represent the advantages and disadvantages of the embodiments. The processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0074] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
Claims
1. A method for managing the security of construction project cost data, characterized in that: The method comprises: According to the input account of logging into the system, several types of operation information are obtained to generate an operation report, wherein the operation report includes authentication behavior and operation behavior; Analyze based on authentication behavior to obtain the degree of authentication abnormality; construct a rectangular coordinate system based on the operation behavior, obtain a curve graph according to the operation steps of the operation behavior, and analyze the similarity measurement value of the same operation behavior at any two logins; determine the first autonomous factor based on the time difference between each operation behavior and the corresponding simplest operation behavior; obtain the number of characteristic logins based on the similarity measurement value between the simplest operation and the operation behavior, obtain the second autonomous factor based on the number of characteristic logins, and obtain the degree of autonomy of the user's self-operation of the operation behavior at each login based on the first autonomous factor and the second autonomous factor; determine the possible degree of abnormal use in combination with the degree of authentication abnormality; Set a screening threshold. If the possibility of abnormal use is greater than the screening threshold, it is determined that abnormal use exists and the technical staff is notified to handle it.
2. A method for managing construction engineering cost data security as claimed in claim 1, characterized in that: According to the account number input for logging into the system, several types of operation information are obtained to generate operation reports, including: According to the input account of logging into the system, the historical log data recorded by the server is extracted, and the login time, server, client, authentication type and protocol of any authentication behavior during login authentication are collected respectively, as well as the number of occurrences of any operation behavior of modifying, deleting and downloading database information in the historical log data during different logins, and an operation report is generated.
3. A method for managing construction engineering cost data security as claimed in claim 2, characterized in that: Based on the analysis of authentication behavior, the degree of authentication anomaly is obtained, including: Analyze the common situations corresponding to the authentication behavior at any login based on any authentication behavior; The common situations corresponding to the authentication behavior are used as the coordinate axis data to construct a coordinate system, and the coordinate axis data are clustered to obtain each cluster area. The distance between the cluster area corresponding to the common situation of the authentication behavior corresponding to any login and the center position of other cluster areas is obtained to calculate the degree of authentication abnormality.
4. A method for managing construction engineering cost data security as claimed in claim 3, characterized in that: Analyze the common situations corresponding to the authentication behavior at any login. The corresponding specific methods are: Determine a first ratio based on the maximum value of the number of times any authentication behavior appears in the historical log data during any login authentication and the number of times any authentication behavior appears in the historical log data in all login behaviors; Based on the number of times any authentication behavior appears in the historical log data during any login authentication and the cumulative number of times any authentication behavior appears in the historical log data in all login behaviors, a second ratio is determined; based on the first ratio and the second ratio, the common situation corresponding to any authentication behavior during any login authentication is determined.
5. A method for managing construction engineering cost data security as claimed in claim 3, characterized in that: Calculate the degree of authentication anomaly. The corresponding specific method is: Based on the distance between the cluster area corresponding to the common situation of the authentication behavior corresponding to any login and the center position of each cluster area and the number of data points in the cluster area corresponding to the common situation of the authentication behavior corresponding to any login, the degree of authentication abnormality at any login is determined.
6. A method for managing construction engineering cost data security as claimed in claim 3, characterized in that: Obtaining the frequency of operation behavior is to calculate the frequency of any operation behavior during any login. The corresponding method is as follows: For the frequency of any operation behavior during any login, a first characteristic coefficient is determined based on the frequency of the number of times the operation behavior is performed during the login; Based on the average of the time intervals between two adjacent occurrences of this type of operation behavior during the login, a second characteristic coefficient is determined; and the frequency of operation of any type of operation behavior during any login is obtained according to the first characteristic coefficient and the second characteristic coefficient.
7. A method for managing construction engineering cost data security as claimed in claim 6, characterized in that: Obtain the second autonomous factor, including: Any operation behavior at any login is used as the target operation behavior at the target login; based on the similarity measurement value between the target operation behavior that appears for the first time at the target login and the target operation behavior that appears for the first time at the previous login, the similarity feature factor of each two adjacent logins under the target operation behavior is determined; the number of logins corresponding to all similar feature factors before the target login being less than a preset similarity threshold is used as the first feature login number; Based on the similarity measurement value between the target operation behavior that appears for the first time at each login and the simplest operation steps, an operation similarity factor of the target operation behavior at each login is determined; the number of logins corresponding to when the difference between the operation similarity factors of the target operation behavior at each two adjacent logins before the target login is greater than a preset difference threshold is used as the second characteristic login number; A second autonomous factor is determined based on a ratio between the first feature login count and the second feature login count.
8. A method for managing construction engineering cost data security as claimed in claim 7, characterized in that: Determine the possible degree of abnormal use. The corresponding specific methods are: For any login behavior, obtain the cumulative sum of the differences in the frequency of operation between this login behavior and other login behaviors under the same operation behavior as the first coefficient; obtain the cumulative sum of the negative correlation coefficients of the degree of user autonomy of this login behavior under all operation behaviors as the second coefficient; and obtain the possible degree of abnormal use during this login based on the first coefficient, the second coefficient and the degree of authentication abnormality of the login behavior.
9. A management system for construction engineering cost data security, characterized in that: A method for managing construction engineering cost data security according to any one of claims 1 to 8 is used to run the method, comprising the following modules: A data collection module is used to obtain several types of operation information and generate an operation report according to the input account of logging into the system, wherein the operation report includes authentication behavior and operation behavior; The data analysis and processing module is used to: analyze the authentication behavior and obtain the degree of authentication anomaly; Analyze the operation behavior, and obtain the frequency of the operation behavior and the degree of autonomy of the user's own operation in turn; Determine the possible degree of abnormal use in combination with the degree of authentication abnormality; The data screening and early warning module is used to: set a screening threshold. If the possibility of abnormal use is greater than the screening threshold, it is determined that there is abnormal use and the technical staff is notified to handle it.
10. A medium, characterized in that The medium stores program data, and when the program data is executed, a method for managing the security of construction project cost data as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Behavior data identification method and device and storage medium
CN111310139A
An FP-growth algorithm-based abnormal behavior detection method and a model applying the method
CN112800101A
Method and device for identifying potential threat service account of intranet
CN113326507A
Method and device for predicting identity of account operator
CN114154058A
Safety protection method based on user abnormal behavior detection
CN117081759A