Management Method, System and Medium for the Security of Construction Project Cost Data

By analyzing the authentication behavior and operation behavior of the login system, combining the degree of abnormality and autonomy, identifying and handling identity theft attacks, the problem of difficult to detect identity theft in the existing technology is solved, and the security management of construction project cost data is realized.

CN120030534BActive Publication Date: 2025-07-08BEIJING GO TO TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510480568.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-08
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

Existing intrusion detection systems are difficult to effectively detect and prevent identity theft attacks, because these attacks will not generate obvious suspicious network traffic or system calls in the computer system, making it difficult to ensure the security of engineering cost data.

Method used

By analyzing the input account of the login system, generating operation reports, combining authentication behavior and operation behavior, calculating the degree of authentication abnormality, the frequency of operation behavior and the degree of user autonomy, setting filtering thresholds, and timely discovering and handling abnormal use.

Benefits of technology

Effectively identify and deal with abnormal usage behaviors, reduce the leakage of engineering cost data, reduce corporate capital losses, and ensure data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030534B_ABST
    Figure CN120030534B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data analysis, and specifically relates to a management method, system and medium for the security of construction project cost data. The method includes: obtaining several types of operation information based on the input account for logging in to the system to generate an operation report; analyzing based on the authentication behavior to obtain the degree of authentication anomaly; analyzing the operation behavior, and sequentially obtaining the frequency of frequent operation of the operation behavior and the degree of autonomy of the user's self-operation; combining the degree of authentication anomaly to determine the possible degree of abnormal use; if the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and the technical personnel are notified for processing; sequentially obtaining the degree of authentication anomaly, the frequency of frequent operation of the operation behavior and the degree of autonomy of the user's self-operation, and combining the three to determine the possible degree of abnormal use, so that when an account anomaly occurs, it can be discovered in time, the technical personnel are notified for processing, effectively reducing the large loss of project cost data and reducing the financial loss of the enterprise.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data analysis, and particularly to a management method, system and medium for the security of construction project cost data. Background Art

[0002] In the field of construction projects, the confidentiality of project costs is not only related to the core competitiveness of enterprises, but also involves maintaining trade secrets, maintaining good cooperative relationships, attracting potential investors, and enhancing the market value of the entire project. Moreover, since construction project costs usually contain a large amount of sensitive information, such as cost budgets, material procurement prices, labor costs, etc., if this information is leaked, it may cause incalculable economic losses to the enterprise; it may also affect the market positioning and negotiation strategies of the enterprise, and even may lead to legal disputes. Therefore, in order to prevent the accounts of company internal employees from being stolen by criminals, resulting in the illegal acquisition of project cost data, it is necessary to strictly monitor and analyze abnormal usage of employee accounts to ensure data security.

[0003] In the existing methods, an intrusion detection system is usually adopted, which mainly relies on preset rule matching and behavior profiles to defend against potential network threats. However, identity theft attack behaviors do not generate obvious suspicious network traffic or system calls in the computer system, making it difficult for the intrusion detection system to effectively detect and prevent such attacks; for example, identity theft attackers usually imitate the behaviors of legitimate users, making the attack behaviors appear the same as normal operations in the system logs to evade the monitoring of rule-based detection systems. Summary of the Invention

[0004] In order to solve the technical problem that the existing intrusion detection system does not generate suspicious network traffic and system calls on the computer for identity theft attack behaviors, making it difficult to detect such attack behaviors, the purpose of the present invention is to provide a management method for the security of construction project cost data, and the specific technical solution adopted is as follows:

[0005] Obtain several types of operation information according to the input account for logging in to the system to generate an operation report, and the operation report includes authentication behaviors and operation behaviors;

[0006] Analyze based on authentication behaviors to obtain the degree of authentication anomaly; construct a rectangular coordinate system based on operation behaviors, obtain a curve graph according to the operation steps of the operation behaviors, and analyze the similarity metric value of the same operation behavior during any two logins; determine the first autonomous factor based on the duration difference between each operation behavior and the corresponding simplest operation behavior; obtain the characteristic login times based on the similarity metric value between the simplest operation and the operation behaviors, obtain the second autonomous factor based on the characteristic login times, and obtain the autonomous degree of the user's self-operation of the operation behaviors during each login according to the first autonomous factor and the second autonomous factor; combine the degree of authentication anomaly to determine the possible degree of abnormal use;

[0007] Set a screening threshold. If the possible degree of abnormal use is greater than the screening threshold, determine that there is abnormal use and notify the technical staff for handling.

[0008] Preferably, according to the input account for logging in to the system, obtain several types of operation information to generate an operation report, including:

[0009] According to the input account for logging in to the system, extract the historical log data recorded by the server, respectively collect the occurrence times of any one authentication behavior such as the login time, server, client, authentication type, and protocol during login authentication, and any one operation behavior such as modifying, deleting, and downloading database information during different logins in the historical log data, and generate an operation report.

[0010] Preferably, analyze based on authentication behaviors to obtain the degree of authentication anomaly, including:

[0011] Analyze the common situations of the corresponding situations of any one authentication behavior during any one login;

[0012] Use the common situations of the corresponding situations of the authentication behaviors as coordinate axis data to construct a coordinate system, perform clustering on the coordinate axis data to obtain each cluster region, obtain the distance between the cluster region corresponding to the common situations of the corresponding situations of the authentication behaviors during any one login and the center positions of other cluster regions, and calculate the degree of authentication anomaly.

[0013] Preferably, the specific method for analyzing the common situations of the corresponding situations of any one authentication behavior during any one login is:

[0014] Based on the occurrence times of any one authentication behavior in the historical log data during any one login authentication and the maximum value of the occurrence times of any one authentication behavior in the historical log data of all login behaviors, determine the first ratio;

[0015] Determine a second ratio based on the number of occurrences of any authentication behavior in the historical log data during any one login authentication and the cumulative sum of the number of occurrences of any authentication behavior in the historical log data during all login behaviors; determine the common situation corresponding to any authentication behavior during any one login authentication based on the first ratio and the second ratio.

[0016] Preferably, calculate the degree of authentication anomaly, and the corresponding specific method is:

[0017] Determine the degree of authentication anomaly during any one login based on the distance between the class cluster area corresponding to the common situation of the authentication behavior during any one login and the central position of each class cluster area and the number of data points in the class cluster area corresponding to the common situation of the authentication behavior during any one login.

[0018] Preferably, obtain the frequent operation degree of the operation behavior by calculating the frequent operation degree of any operation behavior during any one login, and the corresponding method is specifically:

[0019] For the frequent operation degree of any operation behavior during any one login, determine a first characteristic coefficient based on the frequency of the number of times of performing this operation behavior during this login;

[0020] Determine a second characteristic coefficient based on the mean value between the time intervals of every two adjacent occurrences of this operation behavior during this login; obtain the frequent operation degree of any operation behavior during any one login according to the first characteristic coefficient and the second characteristic coefficient.

[0021] Preferably, obtain a second autonomous factor, including:

[0022] Take any operation behavior during any one login as the target operation behavior during the target login, obtain the simplest operation steps of the target operation behavior, and the difference value between the time used for the first occurrence of the target operation behavior during the target login and the simplest operation steps;

[0023] Determine a first autonomous factor based on the negative correlation coefficient of the difference between the time used corresponding to the previous login adjacent to the target login and the target login;

[0024] Determine the similarity feature factor of every two adjacent logins under the target operation behavior based on the similarity metric value between the first occurrence of the target operation behavior during the target login and the first occurrence of the target operation behavior during the previous adjacent login; take the number of logins corresponding to all similarity feature factors less than the preset similarity threshold before the target login as the first characteristic login times;

[0025] Determine the operation similarity factor of the target operation behavior at each login based on the similarity metric value between the target operation behavior that first appears at each login and the simplest operation steps; when the difference between the operation similarity factors of the target operation behavior at every two adjacent logins before the target login is greater than a preset difference threshold, use the corresponding login times as the second characteristic login times.

[0026] Determine the second autonomy factor based on the ratio between the first characteristic login times and the second characteristic login times; obtain the degree of autonomy of the user's self-operation of the target operation behavior at the target login according to the first autonomy factor and the second autonomy factor.

[0027] Preferably, determine the possible degree of abnormal use, and the specific method is as follows:

[0028] For any login behavior, obtain the cumulative sum of the differences in the frequent operation degrees of this login behavior and each other login behavior under the same type of operation behavior as the first coefficient; obtain the cumulative sum of the negative correlation coefficients of the degree of autonomy of the user's self-operation of this login behavior under all types of operation behaviors as the second coefficient; obtain the possible degree of abnormal use at this login according to the first coefficient, the second coefficient, and the authentication abnormal degree of this login behavior.

[0029] To solve the above problems, the present application also provides a management system for the security of construction project cost data, which is used to run a management method for the security of construction project cost data as described in any one of the foregoing, and includes the following modules:

[0030] A data collection module, which is used to: obtain several types of operation information according to the input account for logging in to the system and generate an operation report, and the operation report includes authentication behaviors and operation behaviors;

[0031] A data analysis and processing module, which is used to: analyze based on the authentication behavior to obtain the authentication abnormal degree; analyze the operation behavior, and sequentially obtain the frequent operation degree and the degree of autonomy of the user's self-operation of the operation behavior; combine the authentication abnormal degree to determine the possible degree of abnormal use;

[0032] A data screening and warning module, which is used to: set a screening threshold, and if the possible degree of abnormal use is greater than the screening threshold, determine that there is abnormal use and notify the technical personnel for processing.

[0033] To solve the above problems, the present application also provides a medium, and the medium stores program data, and when the program data is executed, it implements a management method for the security of construction project cost data as described in any one of the foregoing.

[0034] The present invention has the following beneficial effects:

[0035] 1. Based on the input account of the login system, this application analyzes abnormal authentication behaviors and operation behaviors, successively obtains the degree of abnormal authentication, the frequency of frequent operation behaviors, and the degree of autonomy of the user's self-operation, combines the three to determine the possible degree of abnormal use, that is, evaluates the abnormal situations in the authentication behaviors, and then identifies the abnormal operation behaviors that occur according to the operation habits of the account user. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, so that when the abnormal situation of the account appears, it can be discovered in time and the technical personnel can be notified for processing, which can effectively reduce the large loss of project cost data and reduce the financial losses of the enterprise.

[0036] 2. A management system and medium for the security of building project cost data provided by the present invention have the same beneficial effects as a management method for the security of building project cost data provided by the present invention, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0038] Figure 1 It is a flowchart of the steps of a management method for the security of building project cost data provided by an embodiment of the present invention;

[0039] Figure 2 It is a curve graph of the operation behaviors of a management method for the security of building project cost data provided by an embodiment of the present invention;

[0040] Figure 3 It is a curve schematic diagram of the comparison of any two operation behaviors of a management method for the security of building project cost data provided by an embodiment of the present invention Figure 1 ;

[0041] Figure 4 It is a curve schematic diagram of the comparison of any two operation behaviors of a management method for the security of building project cost data provided by an embodiment of the present invention Figure 2 。 DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation manners, structures, features and effects of the management method, system and medium for the safety of construction project cost data proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs.

[0044] The following specifically describes the specific solutions of the management method, system and medium for the safety of construction project cost data provided by the present invention in conjunction with the accompanying drawings.

[0045] Traditional intrusion detection systems defend against potential network threats through preset rule matching and behavior profiles. However, identity theft attack behaviors do not generate obvious suspicious network traffic or system calls in computer systems, making it difficult to effectively detect and prevent such attacks. In one embodiment of the present invention, a management method for the safety of construction project cost data is provided. According to the input account logged into the system, abnormal authentication behaviors and operation behaviors are analyzed to obtain the degree of authentication abnormality, the frequency of operation of the operation behavior, and the degree of autonomy of the user's self-operation in sequence. By combining these three, the possible degree of abnormal use is determined. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and technicians are notified in a timely manner for handling, achieving the purpose of securely protecting construction project cost data. To implement a management method for the safety of construction project cost data, a management system and medium for the safety of construction project cost data are provided. The system and medium are essentially a software system, which is composed of modules that implement corresponding functions. The specific steps in this method are now introduced in detail.

[0046] Please refer to Figure 1 , which shows the flowchart of the steps of a management method for the safety of construction project cost data provided by one embodiment of the present invention. The method includes:

[0047] Step S1: According to the input account logged into the system, obtain several types of operation information to generate an operation report, and the operation report includes authentication behaviors and operation behaviors;

[0048] Step S2: Analyze based on the authentication behaviors to obtain the degree of authentication abnormality; analyze the operation behaviors, and sequentially obtain the frequency of operation of the operation behaviors and the degree of autonomy of the user's self-operation; combine the degree of authentication abnormality to determine the possible degree of abnormal use;

[0049] Step S3: Set a screening threshold. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and the technical staff is notified for handling.

[0050] For better illustration, in today's digital age, with the rapid development of information technology, the storage, processing, and transmission of construction project cost data increasingly rely on computer systems and network technologies. The importance of construction project cost confidentiality is mainly reflected in protecting business secrets, maintaining cooperative relationships, attracting investments, and enhancing project value. Therefore, ensuring that these data are not accessed, tampered with, or leaked without authorization is of crucial significance for protecting corporate interests, maintaining market order, and ensuring national economic security. Among them, construction project cost data refers to the total sum of all costs involved in completing the entire construction process in a construction project, that is, it includes the costs incurred in various links from project pre-planning and design, material procurement, construction, to post-maintenance management. It not only covers direct costs such as material costs, labor costs, and machinery usage costs, but also includes indirect costs such as management fees, financial expenses, and taxes.

[0051] As an optional implementation method, in this embodiment, logging in to the system refers to the server used by any enterprise to store construction project cost data.

[0052] Furthermore, in step S1, according to the input account logged in to the system, several types of operation information are obtained to generate an operation report, including:

[0053] According to the input account logged in to the system, the historical log data recorded by the server is extracted, and the occurrence times of any one authentication behavior such as login time, server, client, authentication type, and protocol during login authentication, and any one operation behavior such as modifying, deleting, and downloading database information during different logins are collected in the historical log data, and an operation report is generated.

[0054] Specifically, in this embodiment, to obtain the authentication behavior and operation behavior, the target IP (Internet Protocol) and operation code corresponding to the input account are collected, and an operation report is generated in chronological order from earliest to latest according to the time obtained from the acquired information. Among them, the target IP is a communication protocol used in a packet-switching network, which stipulates the format and routing method of data packets transmitted in the network; the operation code refers to the unique code used to identify and distinguish different operation behaviors. Through the operation code, the system can accurately identify and record the operation behaviors of users; and the operation report is as shown in Table 1, the schematic table of the operation report generated corresponding to the employee's input account.

[0055] Table 1. Schematic Table of the Operation Report Generated Corresponding to the Employee's Input Account

[0056]

[0057] Understandably, there are significant differences in the behavior patterns between normal enterprise employees logging in to the system and attackers during system login authentication. For example, when logging in to the system, attackers will adopt more concealed means. They usually choose to conduct identity authentication during periods when normal user activities are less frequent to reduce the risk of being discovered. In daily work and life, each user tends to use a familiar authentication client for login. However, due to geographical location restrictions or specific attack purposes, the clients used by attackers are often significantly different from those commonly used by ordinary users. Additionally, the purposes of attackers and normal users for entering the system through identity authentication are different. The main purpose of attackers is to move in the network and obtain more permissions, sensitive data, etc., while normal users mainly aim to carry out daily work or access necessary information resources. Therefore, there are also significant differences between attackers and normal users in the selection of authentication types. Thus, it is necessary to analyze any authentication behavior to more effectively identify and prevent potential attack behaviors.

[0058] Furthermore, in step S2, based on the analysis of authentication behavior, the degree of authentication anomaly is obtained, including:

[0059] It can be noted that for each login and logout of the system by an input account, i.e., an employee account, it is necessary to detect the possibility of the input account being attacked once, that is, to conduct a security detection on the input account to evaluate the risk of the system being potentially attacked. And obtain the number of occurrences of any authentication behavior such as login time, server, client, authentication type, and protocol in the historical log data during login authentication, as well as the proportion of any authentication behavior in the total data of its same type. The more frequent the occurrences and the larger the proportion, the more frequently the authentication behavior appears, which is regarded as part of daily operations, indicating that the currently analyzed authentication behavior is more normal.

[0060] Step S21: Analyze the common situations corresponding to the authentication behavior for any login based on any authentication behavior;

[0061] It should be noted that the authentication behavior refers to the representative characteristics, that is, the characteristics shown by any authentication behavior in the current login behavior. The common situations corresponding to the authentication behavior refer to the authentication mode used by the user when logging in to the system. By analyzing any authentication behavior, it is determined whether it deviates from the normal mode. If the usage situation of a certain authentication method is significantly different from the common situation, for example, an employee who rarely uses fingerprint recognition suddenly frequently uses fingerprint recognition to log in, it may be an abnormal signal and is determined as an abnormal authentication behavior.

[0062] Further, in step S21, to analyze the common situation of the authentication behavior corresponding to any login, the specific method is as follows: Based on the number of occurrences of any authentication behavior in the historical log data during any login authentication and the maximum value of the number of occurrences of any authentication behavior in the historical log data during all login behaviors, determine the first ratio; Based on the number of occurrences of any authentication behavior in the historical log data during any login authentication and the cumulative sum of the number of occurrences of any authentication behavior in the historical log data during all login behaviors, determine the second ratio; Based on the first ratio and the second ratio, determine the common situation of the authentication behavior corresponding to any login authentication.

[0063] Furthermore, in step S21, to analyze the common situation of the authentication behavior corresponding to any login, the calculation formula is as follows:

[0064]

[0065] Wherein, represents the common situation of the authentication behavior corresponding to the th login and the th authentication behavior; represents the number of occurrences of the th authentication behavior in the historical log data during the th login; represents the maximum value of the number of occurrences of the th authentication behavior in the historical log data during all login behaviors; represents the ratio of the number of occurrences of the th authentication behavior in the historical log data during the th login to the total number of occurrences of the th authentication behavior in the historical log data during all login behaviors, that is, the second ratio.

[0066] It should be noted that the larger the value of the first ratio , the more normal the authentication behavior corresponding to the th authentication behavior, indicating that it is more in line with the authentication behavior of normal employees and the possibility of abnormal authentication is smaller; wherein, represents the ratio of the number of occurrences of the th authentication behavior in the historical log data during the th login to the total number of occurrences of the th authentication behavior in the historical log data during all login behaviors. The larger this value is, the more times the authentication behavior corresponding to the th authentication behavior occurs, indicating that the user's authentication behavior is more normal.

[0067] Understandably, when making an abnormal judgment based on authentication behaviors, simply adding up the common situations corresponding to the authentication behaviors during any login cannot well reflect the abnormal degree of the current authentication behavior. Therefore, in this embodiment, generally, the common situations corresponding to the situations during login are obtained based on all authentication behaviors to evaluate any authentication behavior, and then these result values are placed in a coordinate system, that is, the common situations corresponding to the situations during login are used as coordinate axis data to construct a coordinate system. Then, clustering operations are performed on each result value in the coordinate system through a density clustering algorithm. Since the behaviors of attackers are significantly different from those of normal employees, when the authentication behavior is abnormal, the data points in the corresponding cluster region will appear more outlier compared to the data points in other cluster regions, so as to effectively identify abnormal behaviors. Among them, the density clustering algorithm groups data by identifying high-density regions in the data space, that is, if the distance between data points within a cluster region is close enough to each other, then these data points belong to the same cluster region.

[0068] Step S22: Use the common situations corresponding to the authentication behaviors as coordinate axis data to construct a coordinate system, perform clustering on the coordinate axis data to obtain each cluster region, and obtain the distance between the center positions of the cluster region corresponding to the common situation of the authentication behavior during any login and the other cluster regions, and calculate the authentication abnormal degree.

[0069] Specifically, use the common situations corresponding to the authentication behaviors as coordinate axis data to construct a coordinate system, that is, the horizontal axis represents any authentication behavior, and the vertical axis is the common situation corresponding to the authentication behavior. The performance data of the authentication behavior is quantified through the data points plotted in the coordinate system. Then, use the Euclidean distance formula to calculate the distance between the center positions of the cluster region corresponding to the common situation of the authentication behavior during any login and the other cluster regions. If the number of data points in the cluster region corresponding to the common situation of the authentication behavior during the current analysis of login is less, and the distance from the center position of the other cluster regions is farther, it indicates that the data points in the current cluster region are more outlier, indicating that the authentication behavior is more abnormal. Among them, the Euclidean distance formula is a method for calculating the straight-line distance between two points in a multi-dimensional space, and the distance between two points is obtained by calculating the square root of the sum of the squares of the differences between the coordinate axis data. And obtain the number of data points in each cluster region after clustering.

[0070] Furthermore, in step S22, the specific method for calculating the authentication abnormal degree is: based on the distance between the center position of the cluster region corresponding to the common situation of the authentication behavior during any login and the center position of each cluster region and the number of data points in the cluster region corresponding to the common situation of the authentication behavior during any login, determine the authentication abnormal degree of the said any login.

[0071] Furthermore, in step S22, the authentication anomaly degree is calculated, and the corresponding calculation formula is:

[0072]

[0073] where represents the authentication anomaly degree at the -th login; represents the number of data points in the cluster area corresponding to the common situation of the authentication behavior at the -th login; represents the distance between the cluster area corresponding to the common situation of the authentication behavior at the -th login and the center position of the -th cluster area; represents the number of data points in the -th cluster area.

[0074] It should be noted that represents the number of data points in the cluster area corresponding to the common situation of the authentication behavior at the -th login. The smaller this value is, the more special the currently analyzed authentication behavior is, indicating that there is a significant difference between the current login authentication behavior and the behavior pattern of normal employees, and it is more likely to be an abnormal login. The larger the value of , the more outlier the data points in the cluster area corresponding to the common situation of the authentication behavior at the -th login are, that is, the greater the possibility that the authentication behavior at the

[0075] It should be noted that in step S2, the operation behavior is analyzed, and the frequent operation degree and the autonomous degree of the user's self-operation of the operation behavior are obtained in sequence. Among them, the frequent operation degree of the operation behavior refers to the frequency of any operation behavior when the user uses the system or application, which is used to measure the number of times the user repeats any operation behavior within a certain period of time; the autonomous degree of the user's self-operation refers to the degree to which the user can freely make choices and decisions according to his own will and needs during the use process.

[0076] Understandably, when an attacker conducts an identity theft attack, there are usually two attack scenarios, namely remote attack and internal attack. When the attacker uses remote means to exploit network vulnerabilities to attack the system, authentication behavior analysis can be used to effectively judge and prevent such attacks. However, when the attacker directly accesses the legitimate user's host and knows the accurate login password to conduct an internal attack on the system, this method cannot defend against or identify such attacks. Moreover, different employees have their own habits in work operations, and in the case of identity theft, the attacker's behavior is significantly different from the normal operation habits of employees. Therefore, when the attacker conducts an internal attack, it is necessary to comprehensively analyze the operation behavior.

[0077] If, during a certain login, there are significant changes in the number of occurrences, frequency, etc. of an employee's operation behavior compared to the same operation behavior in normal times, it indicates that the employee's operation behavior is abnormal. For example, in the normal work process, an employee's operations on the database usually mainly involve storage and modification. Once identity theft occurs, the behavior pattern of the thief will change significantly. The thief will perform a large number of and frequent operations such as downloading data in the database, which is very different from the normal operation habits of employees. In addition, when a normal employee conducts a large-scale data download, special analysis marks need to be made to avoid misjudgment. Through this comparative analysis, abnormal behaviors can be discovered in a timely manner, and thus identity theft in internal attacks can be effectively identified and prevented.

[0078] Specifically, the operation behavior is any one of the behaviors of modifying, deleting, and downloading database information during different logins. By capturing entity words and entity relationships in the historical log data, the number of occurrences of any one operation behavior and the time of the operation can be obtained. That is, the historical log data is preprocessed, including removing irrelevant information, correcting format errors, and standardizing timestamps. By cleaning and formatting the historical log data, entity words related to the operation behavior are identified and extracted to obtain the number of occurrences of any one operation behavior and the time corresponding to the operation behavior.

[0079] At the same time, the process sequence of different operation behaviors is obtained, that is, the entire process from the start to the end of any one operation behavior, including the duration of the simplest step process and the process of normally completing the operation behavior, etc. The simplest step process refers to the most basic steps and time required for the user to complete the current operation behavior without any interference and abnormality. The process of normally completing the operation behavior refers to the entire duration for the user to complete the task according to the established process in the standard operation environment.

[0080] Further, in step S2, obtaining the frequent operation degree of the operation behavior is to calculate the frequent operation degree of any operation behavior during any login. The corresponding method is specifically as follows: For the frequent operation degree of any operation behavior during any login, based on the frequency of the number of times of this operation behavior during this login, determine the first characteristic coefficient; based on the average value of the time intervals between every two adjacent occurrences of this operation behavior during this login, determine the second characteristic coefficient; obtain the frequent operation degree of any operation behavior during any login according to the first characteristic coefficient and the second characteristic coefficient.

[0081] Furthermore, in step S2, obtaining the frequent operation degree of the operation behavior is to calculate the frequent operation degree of any operation behavior during any login. The corresponding calculation formula is:

[0082]

[0083] where, represents the frequent operation degree of the th operation behavior during the th login; represents the number of times of the th operation behavior during the th login; represents the average value of the time intervals between every two adjacent occurrences of the

[0084] operation behavior in the historical log data. It should be noted that the larger the result value of the first characteristic coefficient , the more frequent the th operation behavior during the is the second characteristic coefficient , represents the time interval between the th occurrence and the th occurrence of the operation behavior during the th login. The smaller the value of , the smaller the time interval between two occurrences of the operation behavior during the

[0085] Understandably, when performing daily work tasks, due to changes in work tasks, the frequency of normal employees' frequent operations in different operation behaviors may also change. Therefore, when conducting analysis, it is necessary to exclude the changes in the frequency of frequent operations caused by normal task changes, that is, starting from the different arrangements of process steps in the operations of different employees, further judgment and analysis should be made on the operation behaviors. In addition, after employees are familiar with the system operation, their usage habits will gradually adjust the process steps to the most time-saving and convenient ones. Therefore, in order to distinguish the differences between the conscious self-adjustment of operation behaviors by normal employees and the differences in process steps in account theft, it is necessary to distinguish the change situation of the differences in any operation behavior during consecutive multiple account logins. That is, when the difference gradually increases after consecutive multiple logins, it indicates that the employee independently modifies the process steps, and at this time, the possibility of the account being abnormal is relatively small, and relatively, the risk of the account being stolen is small. On the contrary, when the difference changes suddenly and increases after consecutive multiple logins, it indicates that the possibility of the current account being abnormal is relatively large, that is, the possibility of being stolen is also greater.

[0086] Further, in step S2, obtaining the degree of autonomy of the user's self-operation includes:

[0087] Construct a rectangular coordinate system based on the operation behavior, obtain a curve graph according to the operation steps of the operation behavior, and analyze the similarity metric value of the same operation behavior during any two logins to analyze the change difference of the operation steps.

[0088] Specifically, construct a rectangular coordinate system based on the operation behavior, and obtain a curve graph according to the operation steps of the operation behavior, that is, number each operation step in the operation behavior, use any operation behavior as the abscissa data, and the label number of the operation step as the ordinate data to construct a rectangular coordinate system, and draw a curve graph by connecting the operation steps of any operation behavior; when performing the same operation behavior, if the curve graph of the user's current operation behavior is quite different from the curve graph of the current operation behavior drawn according to the user's historical log data, it indicates that the current operation behavior is abnormal, indicating that the possibility of the account being stolen is greater.

[0089] As an optional implementation manner, in this embodiment, take the th login and the th login for analysis.

[0090] Please refer to Figure 2 - Figure 4 , which respectively show the curve graph of the operation behavior of a management method for the safety of construction project cost data provided in this embodiment, the curve schematic diagram of the comparison of any two operation behaviors Figure 1 and the curve schematic diagram of the comparison of any two operation behaviors Figure 2 ; among them, Figure 2 the curve graph in represents the one that appears for the first time according to the A curve graph drawn based on the operation steps of an operation behavior; Figure 3 and Figure 4 respectively shown in the th login and the th login are the curve graphs corresponding to the th and th logins for the th operation behavior. If the difference in the step flow between the Figure 3 th and th logins for the th operation behavior is small, it is correspondingly drawn as ; if the difference in the step flow between the Figure 4 .

[0091] Next, use the Dynamic Time Warping (DTW) method to compare the curve graphs obtained from the records of the th and th logins for the th operation behavior to obtain the similarity metric value of the two operations. Among them, DTW can handle time series data of different lengths and align these two sequences through a special warping path for comparison; and the similarity metric value is a numerical index used to measure the similarity between the two; and use the sigmoid function to perform negative correlation normalization on to obtain , whose value range is (0, 1). Among them, the sigmoid function, as an activation function, is used to control the output range within 0 - 1 and has a normalization effect. 0 indicates that the two are completely different, and 1 indicates that the two are completely the same; when , it proves that when analyzing the th operation behavior in the two login behaviors being analyzed, the difference in the operation steps is large; and it is recorded that the number of times the difference in the operation steps in the operation behavior is large during consecutive logins is .

[0092] Obtain the similarity metric value between the first occurrence of the th operation behavior at the th login and the simplest operation step z, and the similarity metric value between the first occurrence of the th operation behavior at the th login and the simplest operation step z, and the difference between the similarity metric values corresponding to the same operation step during adjacent logins , calculate and obtain the difference of the number of times , when is larger, it proves that the process steps of the m-th operation in sequence are gradually optimized and are more likely to be changed by the user independently.

[0093] Specifically, in this embodiment, any operation behavior during any login is used as the target operation behavior during the target login, and the simplest operation steps of the target operation behavior are obtained, as well as the difference value between the time used for the first occurrence of the target operation behavior during the target login and the simplest operation steps. More specifically, in this embodiment, the -th login and the -th operation behavior are used as the target operation behavior during the target login.

[0094] Further, obtain the degree of autonomy of the user's self-operation, including: determining the first autonomy factor based on the difference negative correlation coefficient of the difference values of the time used corresponding to the previous login adjacent to the target login and the target login; determining the similar feature factor of each adjacent two logins under the target operation behavior based on the similarity metric value between the first occurrence of the target operation behavior during the target login and the first occurrence of the target operation behavior during the previous adjacent login; taking the number of logins corresponding to all similar feature factors less than the preset similarity threshold before the target login as the first feature login number; determining the operation similarity factor of the target operation behavior during each login based on the similarity metric value between the first occurrence of the target operation behavior during each login and the simplest operation steps; taking the number of logins corresponding to the difference between the operation similarity factors of the target operation behavior during each adjacent two logins before the target login being greater than the preset difference threshold as the second feature login number;

[0095] Among them, the first feature login number represents the number of logins with a large difference in the similarity metric value, and the second feature login number represents the number of logins with a large difference in the step change. Therefore, determine the second autonomy factor based on the ratio between the first feature login number and the second feature login number; obtain the degree of autonomy of the user's self-operation of the target operation behavior during the target login according to the first autonomy factor and the second autonomy factor. Among them, the value of the similarity threshold is 0.3, and the value of the difference threshold is 0.

[0096] Even further, calculate the degree of autonomy of the user's self-operation, and the corresponding calculation formula is:

[0097]

[0098] Among them, represents the degree of autonomy of the user's self-operation of the -th operation behavior during the -th login; Indicates the simplest operation steps of the th operation behavior; Indicates that before the k-th login, for consecutive times of login operation steps, the first characteristic login times of adjacent operation behaviors; Indicates the consecutive login times; Indicates consecutive times of login operation, the second characteristic login times; Indicates the th time of login, the first time the th operation behavior appears, and the time difference from the simplest operation steps is, Indicates the th time of login, the first time the th operation behavior appears, and the time difference from the simplest operation steps is, Indicates the th login and the th login, the first time the th operation behavior appears, and the time difference used; Indicates a constant term used to prevent the denominator from being 0.

[0099] It is explained that for consecutive times of login operation steps before the k-th login, when obtaining the similarity metric value difference of the first appearance of the th operation behavior and the simplest operation steps for every two adjacent logins, it is recorded as the similarity difference value. For consecutive times of login operation steps before the k-th login, the login times corresponding to the similarity difference value greater than 0, that is, indicates the number of times with a large difference in the similarity metric value of adjacent operation behaviors in consecutive times of login operation steps before the k-th login. The larger its value, the more it indicates that during consecutive times of login, the th operation behavior is gradually optimized until the simplest operation steps. At this time, it is more likely to indicate that the occurrence of the current operation behavior is more likely to be changed by the user independently; Indicates the number of times with a large difference in the consecutive times of login operation steps. When is smaller, it indicates that the th login and the th login, the first time the th operation behavior appears, and the th operation behavior and the During the time period used, the number of changes in the operation steps appears less frequently, indicating that the current account is likely not stolen, and it is more likely that the user independently modifies the operation steps.

[0100] As the first independent factor, when the value is smaller, it indicates that the change between operation steps is smaller, and the likelihood of being stolen is also smaller at this time; in addition, if the th login and the th login first appear the th operation behavior and the time period used are exactly the same, that is, when the operation steps of the current two operation behaviors are exactly the same, the situation of the denominator being 0 may occur, so a constant term is added to prevent the denominator from being 0; represents the degree of independence of the th login for the th operation behavior by the user himself. The smaller this value, the greater the possibility that the employee account is abnormal, that is, the greater the possibility that the account is stolen.

[0101] Understandably, represents the degree of frequent operation of the th login for the th operation behavior, that is, the R value represents the change in the operation instruction frequency. During different logins, the normal instruction frequencies sent by normal employees are interspersed with the frequencies of the remaining instructions used by attackers, which may affect the normal instruction frequencies and cause interference; therefore, in the analysis process, to exclude this interference, it is necessary to compare the number of occurrences of operation behaviors and the changes in operation steps shown by operation behaviors in the current analyzed login compared with other logins, that is, represents the degree of independence of the th login for the th operation behavior by the user himself. Compare the E values of any operation behavior. When the E value is smaller and the gap with the E values of operation behaviors during other logins is larger, it indicates that the possibility of abnormality in the current analyzed login is greater, indicating that the current system is more likely to be stolen by attackers; it can be explained that in the case of the above-mentioned normal employees downloading a large amount of data, the E value of this operation behavior is normally analyzed and a special mark is made to prevent misjudgment of the system.

[0102] Furthermore, in step S2, to determine the possible degree of abnormal use, the corresponding specific method is:

[0103] For any login behavior, obtain the cumulative sum of the differences in the frequent operation degrees of this login behavior and each other login behavior under the same type of operation behavior as the first coefficient; obtain the cumulative sum of the negative correlation coefficients of the autonomy degrees of the user's self-operations of this login behavior under all types of operation behaviors as the second coefficient; obtain the possible degree of abnormal use at the time of this login according to the first coefficient, the second coefficient, and the authentication abnormality degree of this login behavior.

[0104] Further, in step S2, to determine the possible degree of abnormal use, the corresponding calculation formula is:

[0105]

[0106] Wherein, represents the possible degree of abnormal use at the -th login; represents the first coefficient, , represents the frequent operation degree of the -th type of operation behavior at the -th login; represents the frequent operation degree of the -th type of operation behavior at the -th login; represents the number of logins; represents the number of types of operation behaviors; represents the autonomy degree of the user's self-operation of the -th type of operation behavior at the -th login; represents the authentication abnormality degree at the -th login, is the second coefficient.

[0107] It should be noted that the larger the value of, the more abnormal the operation behavior of the current analysis indicates.

[0108] It can be explained that in step S3, a screening threshold is set. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and the technical staff is notified for processing.

[0109] As an optional implementation manner, in this embodiment, the screening threshold is 0.8.

[0110] Specifically, represents the possible degree of abnormal use at the -th login, and is normalized using the sigmoid function to obtain . If When it indicates that there is abnormal use in the current login, that is, it means that there is an account theft problem in the current login. At this time, the system sends an intrusion alarm signal to the technician's computer or mobile phone to notify the technician to handle it.

[0111] It is explained that when the technician handles it, the authentication behavior and operation behavior of the abnormal use are confirmed. That is, after theft, the login time, server, client, authentication type, protocol at the login authentication of the stolen login time, and all operation information are compressed and packaged to be transmitted to the processing device to intercept the invaded account in time and avoid further losses.

[0112] Preferably, after handling the abnormal use situation, to strengthen the security protection measures, a series of prevention strategies can also be adopted, including but not limited to: establishing a strict data access control mechanism to ensure that only authorized personnel can access sensitive information; applying advanced encryption technology to encrypt data so that even if the data is intercepted during transmission, unauthorized third parties cannot interpret it; regularly updating and strengthening the password policy to ensure the complexity and unpredictability of passwords; implementing multi-factor authentication to increase account security; and real-time monitoring of login behaviors to facilitate timely discovery of abnormal patterns to greatly reduce the risk of the input account being stolen; data backup and recovery drills can also be carried out regularly to prevent data loss caused by system failures or human errors.

[0113] It can be understood that this application analyzes the abnormal authentication behavior and operation behavior based on the input account of the login system, and successively obtains the degree of authentication abnormality, the degree of frequent operation of the operation behavior, and the degree of autonomy of the user's own operation. Combining the three, the possible degree of abnormal use is determined, that is, the abnormal situation in the authentication behavior is evaluated, and then the abnormal operation behavior that appears is identified according to the operation habits of the account user; if the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, so that the abnormal situation of the account can be discovered in time and the technician can be notified to handle it in time, which can effectively reduce the large loss of project cost data and reduce the financial loss of the enterprise.

[0114] A management system for the security of construction project cost data provided by an embodiment of the present invention is used to run a management method for the security of construction project cost data provided in the foregoing embodiment, and includes the following modules:

[0115] A data collection module, configured to: obtain several types of operation information according to the input account of the login system to generate an operation report, and the operation report includes authentication behavior and operation behavior;

[0116] The data analysis and processing module is used for: analyzing based on authentication behaviors to obtain the degree of authentication anomaly; analyzing operation behaviors to sequentially obtain the degree of frequent operation and the degree of autonomy of user self-operation of the operation behaviors; and determining the possible degree of abnormal use in combination with the degree of authentication anomaly.

[0117] The data screening and warning module is used for: setting a screening threshold, and if the possible degree of abnormal use is greater than the screening threshold, determining that there is abnormal use and notifying the technical personnel for processing.

[0118] It should be noted that the data collection module, as the front-end module, is used to accurately capture the authentication behaviors and operation behaviors during each login to ensure the comprehensiveness and accuracy of operation information; the data analysis and processing module is responsible for cleaning, integrating, and deeply analyzing the generated operation reports to convert the relevant data in the operation reports, and sequentially obtaining the frequency of operation behaviors, the degree of user self-operation, and the degree of authentication anomaly; the data screening and warning module is used to screen out signs of abnormal use. Once the data screening and warning module detects that the possible degree of abnormal use exceeds the preset screening threshold, it will immediately trigger the warning mechanism and notify the technical personnel to intervene and handle, effectively preventing the occurrence of security incidents such as data leakage or tampering; that is, through the collaborative work of the three modules, the security of construction project cost data is jointly guaranteed.

[0119] It can be understood that when a module of a management system for the security of construction project cost data is operating, it needs to utilize a management method for the security of construction project cost data provided by the foregoing embodiment. Therefore, whether the data collection module, the data analysis and processing module, and the data screening and warning module are integrated or configured with different hardware to generate functions similar to the effects achieved by the present invention, they all fall within the protection scope of the present invention.

[0120] An embodiment of the present invention also proposes a medium. The medium stores program data, and when the program data is executed, it implements a management method for the security of construction project cost data as described in the foregoing embodiment; this medium has the same beneficial effects as the foregoing provided management method for the security of construction project cost data, and will not be elaborated here.

[0121] It should be noted that: the above sequence of embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be beneficial.

[0122] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments.

Claims

1. A management method for the security of construction project cost data, characterized in that, The method includes: Obtaining several types of operation information based on the input account for logging in to the system to generate an operation report, where the operation report includes authentication behaviors and operation behaviors; Analyzing based on the authentication behaviors to obtain the degree of authentication anomaly; sequentially obtaining the degree of frequent operation of the operation behaviors and the degree of autonomy of the user's self-operation, and determining the possible degree of abnormal use in combination with the degree of authentication anomaly; Setting a screening threshold. If the possible degree of abnormal use is greater than the screening threshold, it is determined that there is abnormal use, and the technical personnel are notified for handling; Among them, obtaining the degree of frequent operation of the operation behaviors is to calculate the degree of frequent operation of any one operation behavior during any one login; The method for obtaining the degree of autonomy is as follows: Taking any one operation behavior during any one login as the target operation behavior during the target login, obtaining the simplest operation steps of the target operation behavior, and the difference value between the time duration used for the first appearance of the target operation behavior during the target login and the simplest operation steps; Determining the first autonomy factor based on the difference negative correlation coefficient of the difference values of the time durations corresponding to the previous login adjacent to the target login and the target login; Determining the similarity feature factor of each adjacent two logins under the target operation behavior based on the similarity metric value between the first appearance of the target operation behavior during the target login and the first appearance of the target operation behavior during the previous adjacent login; taking the number of logins corresponding to all similarity feature factors less than the preset similarity threshold before the target login as the first feature login number; Determining the operation similarity factor of the target operation behavior during each login based on the similarity metric value between the first appearance of the target operation behavior during each login and the simplest operation steps; taking the number of logins corresponding to the difference between the operation similarity factors of the target operation behavior during each adjacent two logins before the target login being greater than the preset difference threshold as the second feature login number; Determining the second autonomy factor based on the ratio between the first feature login number and the second feature login number; obtaining the degree of autonomy of the user's self-operation of the target operation behavior during the target login according to the first autonomy factor and the second autonomy factor.

2. The management method for the safety of construction project cost data according to claim 1, characterized in that, Obtaining several types of operation information based on the input account for logging in to the system, including: Extracting the historical log data recorded by the server based on the input account for logging in to the system, respectively collecting the occurrence times of any one authentication behavior such as the login time, server, client, authentication type, and protocol during login authentication, and any one operation behavior such as modifying, deleting, and downloading database information during different logins in the historical log data, and generating an operation report.

3. A management method for the security of construction project cost data as described in claim 2, characterized in that, Analyzing based on the authentication behaviors to obtain the degree of authentication anomaly, including: Analyzing the common situations corresponding to the authentication behaviors during any one login based on any one authentication behavior; Taking the common situations corresponding to the authentication behaviors as coordinate axis data to construct a coordinate system, clustering the coordinate axis data to obtain each cluster region, obtaining the distance between the cluster region corresponding to the common situation of the authentication behavior during any one login and the central positions of other cluster regions, and calculating the degree of authentication anomaly.

4. A management method for the security of construction project cost data as claimed in claim 3, characterized in that, Analyze the common situations corresponding to the authentication behavior during any login. The specific method is as follows: Based on the number of occurrences of any authentication behavior in the historical log data during any login authentication and the maximum value of the number of occurrences of any authentication behavior in the historical log data among all login behaviors, determine the first ratio; Based on the number of occurrences of any authentication behavior in the historical log data during any login authentication and the cumulative sum of the number of occurrences of any authentication behavior in the historical log data among all login behaviors, determine the second ratio; Based on the first ratio and the second ratio, determine the common situation corresponding to any authentication behavior during any login authentication.

5. A management method for the security of construction project cost data according to claim 3, characterized in that, Calculate the degree of authentication anomaly. The specific method is as follows: Based on the distance between the common situation corresponding class cluster area of the authentication behavior during any login and the central position of each class cluster area and the number of data points in the class cluster area corresponding to the common situation of the authentication behavior during any login, determine the degree of authentication anomaly during any login.

6. The management method for the security of construction project cost data according to claim 3, characterized in that, The method for obtaining the frequent operation degree of the operation behavior is to calculate the frequent operation degree of any operation behavior during any login. The specific method is as follows: For the frequent operation degree of any operation behavior during any login, based on the frequency of the number of times of this operation behavior during this login, determine the first characteristic coefficient; Based on the average value between the time intervals of the occurrences of this operation behavior during this login, determine the second characteristic coefficient; Obtain the frequent operation degree of any operation behavior during any login according to the first characteristic coefficient and the second characteristic coefficient.

7. The management method for the security of construction project cost data according to claim 3, characterized in that, Determine the possible degree of abnormal use. The specific method is as follows: For any login behavior, obtain the cumulative sum of the differences in the frequent operation degrees of this login behavior and each other login behavior under the same type of operation behavior as the first coefficient; Obtain the cumulative sum of the negative correlation coefficients of the degree of autonomy of the user's self-operation of this login behavior under all types of operation behaviors as the second coefficient; Obtain the possible degree of abnormal use during this login according to the first coefficient, the second coefficient, and the degree of authentication anomaly of this login behavior.

8. A management system for the security of construction project cost data, characterized in that, A management method for the security of construction project cost data as described in any one of claims 1-7, when run, includes the following modules: A data collection module, used for: According to the input account for logging in to the system, obtain several types of operation information to generate an operation report, and the operation report includes authentication behavior and operation behavior; A data analysis and processing module, used for: Analyze based on the authentication behavior to obtain the degree of authentication anomaly; Analyze the operation behavior, and sequentially obtain the frequent operation degree of the operation behavior and the degree of autonomy of the user's self-operation; Combine the degree of authentication anomaly to determine the possible degree of abnormal use; A data screening and warning module, used for: Set a screening threshold. If the possible degree of abnormal use is greater than the screening threshold, determine that there is abnormal use and notify the technical personnel for processing.

9. A medium, characterized in that, The medium stores program data, and when the program data is executed, it implements a management method for the security of construction project cost data as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Behavior data identification method and device and storage medium

    CN111310139A

  • Method and device for identifying potential threat service account of intranet

    CN113326507A