Behavior data analysis method and device
Through an automated analysis method based on normal behavior model, combined with multi-dimensional data and usage parameters for matching and judgment, the problem of low intelligence of user behavior monitoring and analysis methods in the existing technology is solved, and the effect of improving the intelligence of user behavior analysis is achieved.
Patent Information
- Application Number
- CN202510146429.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-30
AI Technical Summary
In the prior art, the intelligence of user behavior monitoring and analysis methods is not high, and it is difficult to meet the demand for the amount of user behavior data that has increased exponentially with the increase in the complexity of Internet applications.
An automated analysis method based on the normal behavior model is adopted, and multi-dimensional data such as user identity identification, access time, operation type, access path, request parameters, response status code and other usage parameters are used to match and judge to determine whether the user behavior is normal or abnormal behavior.
It improves the intelligence of user behavior analysis, can accurately distinguish between normal and abnormal behavior, reduce false alarms, improve analysis efficiency, promptly detect potential security threats, and ensure the safe operation of internal systems of the enterprise.
Smart Images

Figure CN120067587A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of data processing, and more particularly, to a method and device for analyzing behavior data. Background Art
[0002] With the development of the digital age, the technology for monitoring and analyzing user behavior has evolved from simple log recording to complex multi-dimensional data analysis. Early user behavior monitoring and analysis mainly relied on server logs and basic statistical analysis to track users' basic access paths and operation behaviors. However, with the increasing complexity of Internet applications, the amount of user behavior data has grown exponentially, and the traditional monitoring and analysis methods are not highly intelligent and gradually difficult to meet the requirements. Summary of the Invention
[0003] Embodiments of the present invention provide a method and device for analyzing behavior data, which at least solve the problem that the traditional monitoring and analysis methods are not highly intelligent and gradually difficult to meet the requirements.
[0004] According to an embodiment of the present invention, a method for analyzing behavior data is provided, including: obtaining log data of user behavior, where the log data includes: user identity identifier, access time, operation type, access path, request parameters, response status code; analyzing the log data based on a normal behavior model to determine whether the user behavior corresponds to normal behavior or abnormal behavior; where the normal behavior model stores usage parameters of multiple users, and the usage parameters include: behavior permissions, permission periods, permission address information; in the case where the log data matches the usage parameters, determining that the user behavior corresponds to normal behavior; in the case where the log data does not match the usage parameters, determining that the user behavior corresponds to abnormal behavior.
[0005] According to another embodiment of the present invention, a system for analyzing behavior data is further provided, including: an obtaining module, configured to obtain log data of user behavior, where the log data includes: user identity identifier, access time, operation type, access path, request parameters, response status code; an intelligent analysis module, configured to analyze the log data based on a normal behavior model to determine whether the user behavior corresponds to normal behavior or abnormal behavior; where the normal behavior model stores usage parameters of multiple users, and the usage parameters include: behavior permissions, permission periods, permission address information; where, in the case where the log data matches the usage parameters, determining that the user behavior corresponds to normal behavior; in the case where the log data does not match the usage parameters, determining that the user behavior corresponds to abnormal behavior.
[0006] According to another embodiment of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein when the computer program is run by a processor, the steps in any one of the above method embodiments are executed.
[0007] According to another embodiment of the present invention, there is also provided an electronic device including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0008] According to another embodiment of the present invention, there is also provided a computer program product including computer instructions, and when the computer instructions are executed by a processor, the steps in any one of the above method embodiments are implemented.
[0009] Through the embodiments of the present invention, due to the feature of automatically analyzing log data based on a normal behavior model and making a matching judgment by combining multi-dimensional data such as user identity identification, access time, operation type, access path, request parameters, response status codes (actual operation parameters of the user) and usage parameters such as behavior permissions, permission periods, and permission address information (parameters that the system theoretically allows the user to operate), the problem that the monitoring and analysis methods in the related art have low intelligence and gradually become difficult to meet the requirements is solved. Furthermore, the effect of improving the intelligence level of user behavior analysis is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0011] Figure 1 is a schematic structural diagram of a computer terminal for an execution behavior data analysis method according to an embodiment of the present invention;
[0012] Figure 2 is a flowchart of a behavior data analysis method according to an embodiment of the present invention;
[0013] Figure 3 is a flowchart of a method for determining and updating usage parameters based on preset values according to an embodiment of the present invention;
[0014] Figure 4 is a flowchart of a method for determining and updating usage parameters based on a machine learning model according to an embodiment of the present invention;
[0015] Figure 5 is a flowchart of a method for updating usage parameters based on a machine learning model according to an embodiment of the present invention;
[0016] Figure 6 It is a flowchart of a method for determining vertical privilege escalation vulnerabilities based on real operation results and virtual operation results according to an embodiment of the present invention;
[0017] Figure 7 It is a flowchart of a method for determining horizontal privilege escalation vulnerabilities based on the log data of a first user and the log data of a second user according to an embodiment of the present invention;
[0018] Figure 8 It is a schematic structural diagram of a behavior data analysis system according to an embodiment of the present invention. Detailed implementation manners
[0019] In the following, the present invention will be described in detail with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0020] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence.
[0021] The method embodiments provided by the embodiments of the present invention can be executed on a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 It is a schematic structural diagram of a computer terminal for executing the behavior data analysis method according to an embodiment of the present invention. As Figure 1 shown, the computer terminal may include one or more ( Figure 1 only one is shown in Figure 1 a processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Optionally, the above-mentioned computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that, Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above-mentioned computer terminal. For example, the computer terminal may further include more or fewer components than those shown in
[0022] The memory 104 can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the behavior data analysis method in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0023] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computer terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC for Network Interface Controller), which can be connected to other network devices through a gateway and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0024] In this embodiment, a behavior data analysis method is provided. Figure 2 is a flowchart of the behavior data analysis method according to the embodiments of the present invention, as Figure 2 shown, and this process includes the following steps:
[0025] Step S201, obtain the log data of user behavior, and the log data includes: user identity identifier, access time, operation type, access path, request parameter, response status code;
[0026] In an exemplary implementation manner, for the collection of log data: for example, in an enterprise internal system, through the log recording function of the server side (such as the access log of the Web server, the log module of the application server, etc.), the user login and operation behaviors are recorded in real time. The log data includes user identity identifiers (such as employee numbers, user names), access times (accurate to seconds), operation types (such as login, accessing a specific page, submitting a form, etc.), access paths (such as / login, / dashboard), request parameters (such as user names, passwords, query parameters, etc.), and response status codes (such as 200 indicates success, 401 indicates unauthorized).
[0027] For log transmission and storage: For example, the collected log data is transmitted to a centralized log storage system (such as Elasticsearch, Hadoop) through a log transmission tool (such as Fluentd, Logstash) for subsequent analysis.
[0028] By adopting the above technical solutions, it is possible to record the entire process of user login and operations in detail, providing a rich data basis for subsequent analysis. Moreover, the log data is collected in real time to ensure that abnormal behaviors can be detected in a timely manner.
[0029] Step S202: Analyze the log data based on the normal behavior model to determine whether the user behavior corresponds to a normal behavior or an abnormal behavior; wherein, the normal behavior model stores the usage parameters of multiple users, and the usage parameters include: behavior permissions, permission periods, and permission address information.
[0030] In an exemplary implementation, for example, according to the business rules and historical data of the enterprise internal system, a normal behavior model is constructed. This model stores the usage parameters of users, including behavior permissions (such as the permission to access a specific page), permission periods (such as the validity period of an employee's permissions), and permission address information (such as the range of IP addresses allowed to log in). For example, employee A has the permission to access the / dashboard page, the permission period is December 31, 2025, and access is only allowed from the company's internal IP addresses.
[0031] Match and analyze the collected log data with the usage parameters in the normal behavior model. For example, check whether the user is within the permission period, whether accessing from the allowed IP addresses, and whether the operation type conforms to its permission scope, etc.
[0032] For example, machine learning algorithms (such as decision trees, random forests) can be used to train the historical log data, learn the normal behavior patterns of users, and incorporate them into the normal behavior model.
[0033] By adopting the above technical solutions, through machine learning algorithms, it is possible to automatically identify complex abnormal behavior patterns and improve the intelligence level of analysis. Moreover, the normal behavior model can be continuously updated according to new data to adapt to changes in user behavior.
[0034] Step S203: When the log data matches the usage parameters, determine that the user behavior corresponds to a normal behavior.
[0035] In an exemplary embodiment, if the information such as the user identity identifier, access time, operation type, access path, request parameters, and response status code in the log data exactly match the usage parameters in the normal behavior model, it is determined that the user behavior is a normal behavior. For example, if Employee A accesses the / dashboard page from an internal company IP address within the permission period, and the operation type and request parameters are within the scope of their permissions, it is determined as a normal behavior.
[0036] Record the normal behavior in the log system and mark it as "normal behavior" for subsequent auditing and analysis.
[0037] By adopting the above technical solution, through multi-dimensional matching judgment, normal behavior and abnormal behavior can be accurately distinguished, reducing false alarms. Moreover, the automated matching process improves the analysis efficiency and can quickly process a large amount of log data.
[0038] Step S204, in the case where the log data does not match the usage parameters, determine that the user behavior corresponds to an abnormal behavior.
[0039] In an exemplary embodiment, if some fields in the log data do not match the usage parameters in the normal behavior model, it is determined that the user behavior is an abnormal behavior. For example, if Employee A attempts to access the / dashboard page from an external IP address or attempts to access an unauthorized page (such as / admin), it is determined as an abnormal behavior.
[0040] For example, the method may further include: in the case where the log data does not match the usage parameters, generate an alarm for abnormal behavior and record the detailed information of the abnormal behavior, including the user identity, operation time, type of abnormality, etc., for subsequent security analysis and investigation.
[0041] For the detected abnormal behavior, its possible causes can be further analyzed, such as whether it is a misoperation or a malicious attack.
[0042] By adopting the above technical solution, potential security threats such as illegal login and unauthorized access can be discovered in a timely manner, protecting the security of the enterprise internal system. Moreover, the detailed abnormal behavior records provide a basis for subsequent security auditing and investigation.
[0043] Through the above steps S201 to S204, since the automated analysis of log data is carried out based on the normal behavior model, and the multi-dimensional data such as user identity identification, access time, operation type, access path, request parameters, response status code (actual operation parameters of the user) and usage parameters such as behavior permissions, permission periods, and permission address information (parameters that the system theoretically allows the user to operate) are used for matching and judgment, the problem that the monitoring and analysis methods in the related technologies have low intelligence and gradually become difficult to meet the requirements is solved. Furthermore, the effect of improving the intelligence of user behavior analysis is achieved.
[0044] The above process is explained and illustrated with examples as follows:
[0045] For example, an enterprise uses the above behavior data analysis method to monitor the behavior of employees logging in to the internal system. The specific scenario is as follows:
[0046] Step S201: The system collects the log data of employees' logins and operations in real time through the log recording function on the server side. For example, when employee A attempts to log in to the system, the log records their user identity identification (user name A123), access time (January 25, 2025, 10:00), operation type (login), access path ( / login), request parameters (user name A123, password ******), and response status code (200 indicates success).
[0047] Step S202: The system analyzes the collected log data using the normal behavior model. The usage parameters of employee A are stored in the normal behavior model. For example, employee A has the permission to access the / dashboard page, the permission period is December 31, 2025, and access is only allowed from the company's internal IP address (such as 192.168.1.0 / 24).
[0048] Step S203: If employee A logs in to the system from the company's internal IP address (such as 192.168.1.10) within the permission period, accesses the / dashboard page, and the operation type and request parameters are within the scope of their permissions, the system determines that this behavior is a normal behavior and records it as "normal behavior".
[0049] Step S204: If employee A attempts to log in to the system from an external IP address (such as 10.0.0.1) or attempts to access an unauthorized page (such as / admin), the system will determine that this behavior is an abnormal behavior, generate an alarm, and record the detailed information of the abnormal behavior, such as user identity A123, operation time January 25, 2025, 10:05, abnormal type illegal IP access, etc., for security personnel to further investigate.
[0050] Through the above steps, the present invention can effectively improve the intelligence level of user behavior analysis, timely detect potential security threats, and ensure the secure operation of the enterprise internal system.
[0051] In one implementation manner, Figure 3 is a flowchart of a method for determining and updating usage parameters based on preset values according to an embodiment of the present invention. As Figure 3 shown, the method further includes:
[0052] Step S301, determining usage parameters based on preset values;
[0053] In an exemplary implementation manner, for example, the implementation manner of this step can be:
[0054] Defining preset values:
[0055] Manual input: The system administrator manually inputs or configures the usage parameters of users through the management interface. These parameters include behavior permissions (such as allowed access pages, operation types, etc.), permission periods (such as the validity period of permissions), permission address information (such as the range of IP addresses allowed to log in), etc.
[0056] Storing preset values: Storing these manually input preset values in the system configuration file or database. For example, the permission information can be stored in a relational database (such as MySQL) or a key-value store (such as Redis) for quick query and use.
[0057] Initializing the normal behavior model:
[0058] Loading preset values: When the system starts, load these preset values from the configuration file or database and initialize them into the normal behavior model. For example, the system reads the permission table in the database and loads the permission information of each user into memory for subsequent real-time analysis.
[0059] Model construction: Construct a normal behavior model based on these preset values, and the model contains detailed usage parameters of each user. For example, the model can be a data structure containing user IDs, permission lists, permission periods, and allowed IP address ranges.
[0060] By adopting the above technical solutions, through manual setting of preset values, the system administrator can flexibly configure the usage parameters of users according to the specific needs of the enterprise. Moreover, the preset values are set by professionals, which can ensure the accuracy and compliance of the usage parameters.
[0061] Step S302, in response to a write operation, updating the preset values based on a preset time period.
[0062] In an exemplary implementation manner, for example, the implementation manner of this step can be:
[0063] Detect write operations:
[0064] Monitor changes to configuration files or databases: The system uses file monitoring tools (such as inotify) or database triggers (such as MySQL's TRIGGER) to detect changes to preset values in configuration files or databases in real time. For example, when a system administrator updates the permission information of a certain user, the trigger will capture this write operation.
[0065] Record write operations: Record the detected write operations, including information such as the time of modification and the content of modification.
[0066] Update preset values based on a preset time period:
[0067] Set the update period: The system administrator can configure a preset time period (such as 2 am every day) as the update period. The system will check for new write operations within each update period. Alternatively, the system administrator modifies the behavior permissions for a certain user after receiving a notice of the change in the user's authority.
[0068] Automatic update: Within the preset time period, the system will automatically reload the latest preset values from the configuration file or database and update the normal behavior model. For example, the system will check for new permission update operations at 2 am every day. If there are any, it will load the new permission information into the normal behavior model.
[0069] Set the notification mechanism: After the update is completed, the system can send a notification to the administrator to confirm that the update operation has been completed.
[0070] By adopting the above technical solutions, by regularly updating the preset values, it is ensured that the usage parameters in the system can timely reflect the latest business rules and security policies. Moreover, the automated update mechanism reduces manual intervention and improves the system maintenance efficiency.
[0071] In one implementation, Figure 4 is a flowchart of a method for determining and updating usage parameters based on a machine learning model according to an embodiment of the present invention, as Figure 4 shown, the method further includes:
[0072] Step S401, determine usage parameters based on a machine learning model;
[0073] In an exemplary implementation, for example, use machine learning algorithms (such as random forest, decision tree, support vector machine, etc.) to train historical user behavior data.
[0074] Construct a user profile, including the user's role, permission level, common operation paths, etc., as part of the model.
[0075] Through model training, learn the normal behavior patterns of users, so as to determine the usage parameters of users, such as behavior permissions, permission periods, permission address information, etc.
[0076] Step S402, update the usage parameters based on the machine learning model to obtain new usage data.
[0077] In an exemplary embodiment, for example, the machine learning model can be updated according to the analysis results of real-time data. For example, use the incremental learning algorithm to enable the model to adapt to changes in user behavior.
[0078] Based on the update results of the model, automatically adjust the usage parameters of users. For example, if the model detects changes in the user behavior pattern, automatically update their permission information.
[0079] Through the above steps S401 to S402, the embodiments of the present invention can automatically set and update usage parameters using the machine learning model, improve the intelligence and accuracy of user behavior analysis, timely discover potential security threats, and ensure the secure operation of the enterprise internal system.
[0080] In one embodiment, Figure 5 is a flowchart of a method for updating usage parameters based on a machine learning model according to an embodiment of the present invention, as Figure 5 shown, updating the usage parameters based on the machine learning model includes:
[0081] Step S501, construct a user portrait based on machine learning algorithms, and the user portrait includes: the role of the user, the permission level, and the common operation path;
[0082] In an exemplary embodiment, for example, collect user behavior data from the enterprise internal system, including user identity identification, access time, operation type, access path, request parameters, response status codes, etc. Use data cleaning tools (such as pandas) to process missing values and outliers, and perform data format conversion and normalization. Extract features related to user behavior, such as the role of the user, the permission level, and the common operation path. For example, features can be constructed by counting the frequency of user access to specific pages and the distribution of operation times.
[0083] Use a feature selection algorithm (such as SelectKBest in scikit-learn) to select the most valuable features for user behavior analysis. Use a clustering algorithm (such as KMeans or DBSCAN) to divide users into different groups, and each group has similar behavior patterns. According to the clustering results, create a detailed user portrait for each user group, including the role of the user, the permission level, and the common operation path.
[0084] By adopting the above technical solution, through multi-dimensional data collection and feature extraction, the behavioral characteristics of users can be comprehensively reflected. Moreover, the user portrait based on cluster analysis can accurately distinguish the behavioral patterns of different user groups, providing an accurate reference for subsequent behavioral analysis.
[0085] Step S502: Train a machine learning model based on historical data to learn the normal behaviors of users so as to obtain usage parameters; wherein, the normal behaviors are the behaviors of users under the usage parameters.
[0086] In an exemplary embodiment, the historical data is labeled as normal behavior or abnormal behavior. For example, according to known business rules and security policies, the behaviors of users within the scope of permissions are marked as normal behaviors, and the behaviors beyond the scope of permissions are marked as abnormal behaviors. The data is divided into a training set and a test set. Usually, 80% of the data is used as the training set, and 20% of the data is used as the test set.
[0087] Select a suitable machine learning algorithm, such as decision tree, random forest, support vector machine, etc. Use the training set to train the model and adjust the model parameters to optimize the performance. Use the test set to evaluate the performance of the model to ensure that the model can accurately identify normal behaviors and abnormal behaviors. Metrics such as accuracy, recall rate, and F1 score can be used for evaluation.
[0088] Extract rules and patterns from the trained model to determine the usage parameters of users, such as behavioral permissions, permission periods, permission address information, etc. Deploy the trained model to the production environment for real-time analysis of user behaviors.
[0089] By adopting the above technical solution, the model can continuously learn and update according to historical data and adapt to changes in user behaviors. Moreover, through model evaluation and optimization, it is ensured that the model can accurately identify normal behaviors and abnormal behaviors.
[0090] Step S503: Update the machine learning model based on real-time data to update the usage parameters so as to obtain new usage data.
[0091] In an exemplary embodiment, continuously collect the real-time behavioral data of users and perform preprocessing. Update the features in the user portrait according to the real-time data. For example, if a user starts to frequently access new pages, update their common operation path.
[0092] Use an incremental learning algorithm (such as an online learning algorithm) to update the machine learning model so that the model can adapt to changes in user behaviors. Automatically adjust the usage parameters of users according to the model update results. For example, if the model detects a change in the user's behavioral pattern, automatically update their permission information.
[0093] For example, a feedback mechanism can also be set up: regularly evaluate the performance of the model, and use methods such as cross-validation and ROC curves to ensure the accuracy and reliability of the model. Feed the updated usage parameters back into the system and send a notification to the administrator to confirm that the update operation has been completed.
[0094] By adopting the above technical solutions, the model can be dynamically updated according to real-time data, adapt to changes in user behavior, and ensure the timeliness and accuracy of usage parameters. Moreover, through the automated update mechanism, manual intervention is reduced and the maintenance efficiency of the system is improved.
[0095] Through the above steps S501 to S503, the embodiments of the present invention can automatically construct and update user portraits and usage parameters using machine learning models, improve the intelligence and accuracy of user behavior analysis, timely discover potential security threats, and ensure the secure operation of enterprise internal systems.
[0096] In one implementation Figure 6 is a flowchart of a method for determining vertical privilege escalation vulnerabilities based on real operation results and virtual operation results according to an embodiment of the present invention. As Figure 6 shown, in the case where it is determined that the user behavior corresponds to an abnormal behavior, the method further includes:
[0097] Step S601, obtaining the real operation result of the abnormal behavior;
[0098] In an exemplary implementation, after detecting abnormal user behavior, the system records the specific operation result of the behavior. For example, record the return information (such as HTTP status code 403 Forbidden) when the user attempts to access an unauthorized page. The system can also record detailed information such as the time when the abnormal behavior occurred, the user identity identifier, and the access path for subsequent analysis.
[0099] By adopting the above technical solutions, obtaining the real operation result provides an accurate data basis for subsequent analysis, which helps to comprehensively understand the nature of the abnormal behavior. Detailed recording of the context information of the abnormal behavior facilitates subsequent security audits and investigations.
[0100] Step S602, replacing the current user identity identifier of the user corresponding to the abnormal behavior with a virtual user identity identifier;
[0101] In an exemplary implementation, for example, create a virtual user identity identifier, and this virtual user has behavior permissions higher than the current user identity. Replace the user identity identifier in the abnormal behavior record with the virtual user identity identifier, while retaining the original user identity information for subsequent comparison.
[0102] By adopting the above technical solution, by using a virtual user identity, direct modification of the real user's permissions is avoided, ensuring the normal operation of the system. Moreover, it facilitates subsequent simulation operations and can clearly distinguish between real user behaviors and simulated behaviors.
[0103] Step S603: Use the virtual user identity to simulate operations with behavior permissions higher than the current user identity to obtain a virtual operation result.
[0104] In an exemplary embodiment, for example, according to the permissions of the virtual user identity, simulate and execute the same operations as the abnormal behavior. Record the results of the simulation operations, including return information, operation paths, operation times, etc.
[0105] By adopting the above technical solution, through simulation operations, a virtual operation result is obtained, providing a basis for subsequent comparison with the real operation result. Without affecting the real user's permissions, test the system's response to high-privilege operations.
[0106] Step S604: Compare the virtual operation result with the real operation result.
[0107] In an exemplary embodiment, for example, compare the virtual operation result and the real operation result item by item, including return information, operation paths, operation times, etc. Calculate the differences between the two, such as whether the return information is consistent, whether the operation paths are the same, etc.
[0108] By adopting the above technical solution, through the comparison result, it can be accurately determined whether there is a vertical privilege escalation vulnerability in the system. Based on the comparison between the real operation result and the simulated operation result, the reliability of the detection result is improved.
[0109] Step S605: When the distance between the virtual operation result and the real operation result is less than a preset threshold, determine that the system executing the user behavior has a vertical privilege escalation vulnerability.
[0110] In an exemplary embodiment, for example, preset a threshold for determining whether the difference between the virtual operation result and the real operation result is within an acceptable range. If the difference between the two is less than the preset threshold, the system determines that there is a vertical privilege escalation vulnerability and triggers an alarm.
[0111] By adopting the above technical solution, a vertical privilege escalation vulnerability can be discovered in a timely manner and measures can be taken for repair in a timely manner. Moreover, it can effectively prevent security risks caused by vertical privilege escalation vulnerabilities and protect the system security.
[0112] Through the above steps S601 to S605, the embodiments of the present invention can effectively detect whether there is a vertical privilege escalation vulnerability in the system, timely discover potential security threats, and ensure the secure operation of the enterprise internal system.
[0113] In one embodiment, Figure 7 is a flowchart of a method for determining a horizontal privilege escalation vulnerability based on the log data of a first user and the log data of a second user according to an embodiment of the present invention. As Figure 7 shown, in the case where it is determined that the user behavior corresponds to an abnormal behavior, it further includes:
[0114] Step S701, determining the user with the abnormal behavior as the first user;
[0115] In an exemplary embodiment, when the system analyzes the log data through a normal behavior model, if it is found that a certain log data does not match the usage parameters, it is determined that the behavior is an abnormal behavior. The system records the detailed information of the abnormal behavior, including the user identity identifier (such as the username, user ID), operation time, access path, request parameters, response status code, etc.
[0116] The user who triggers the abnormal behavior is marked as the "first user", and their user identity identifier and the specific information of the abnormal behavior are recorded. For example, when employee A attempts to access an unauthorized page / admin, after the system detects that this behavior is abnormal, employee A is marked as the first user.
[0117] By adopting the above technical solution, by marking the user with the abnormal behavior, the responsible entity can be clarified, which is convenient for subsequent security analysis and investigation. Moreover, it provides a basis for comparing the behavior of the first user with the behavior of other users in the future.
[0118] Step S702, comparing the log data of the first user with the log data of the second user;
[0119] In an exemplary embodiment, for example, a user with different behavior permissions is selected from the system as the "second user". For example, a user with higher permissions or a different role is selected. Ensure that the behavior permissions of the first user and the second user are different so as to effectively detect horizontal privilege escalation vulnerabilities.
[0120] Extract the log data of the first user and the second user within the same time period, including the access path, operation type, request parameters, response status code, etc. Compare the behavior patterns of the two users to check whether there are similar operation paths and request parameters. For example, check whether the first user attempts to access a page that the second user has the right to access but the first user does not have the right to access.
[0121] Use a similarity analysis algorithm (such as cosine similarity, Jaccard similarity) to calculate the similarity of the behaviors of the two users. For example, calculate the similarity of the access paths of the two users, or check whether the request parameters are highly similar.
[0122] By adopting the above technical solution, by comparing the behaviors of two users with different permissions, it is possible to accurately detect whether there is a horizontal privilege escalation vulnerability. Analyzing based on actual log data improves the reliability and accuracy of the detection results.
[0123] Step S703: In the case where the log data of the first user is similar to the log data of the second user and the behavior permissions of the first user and the second user are different, it is determined that the system executing the user behavior has a horizontal vulnerability.
[0124] In an exemplary embodiment, for example, according to the result of the similarity analysis, it is judged whether the log data of the first user is highly similar to the log data of the second user. For example, if the similarity of the access paths of the two users exceeds a preset threshold (such as 80%), the behaviors are considered highly similar.
[0125] Confirm whether the behavior permissions of the first user and the second user are different. For example, the first user may only have the permission to access / dashboard, while the second user has the permission to access / admin. If the first user attempts to access the page that the second user has the right to access and the behavior patterns are highly similar, it is determined as a horizontal privilege escalation vulnerability.
[0126] If the above conditions are met, the system determines that there is a horizontal privilege escalation vulnerability and generates an alarm. Record the detailed information of the vulnerability, including the user identities involved, operation paths, request parameters, etc., for security personnel to further investigate and handle.
[0127] By adopting the above technical solution, it is possible to discover horizontal privilege escalation vulnerabilities in a timely manner and take measures to repair them in a timely manner. Secondly, it can effectively prevent security risks caused by horizontal privilege escalation vulnerabilities and protect the system security. Moreover, the detailed vulnerability records provide a basis for subsequent security audits and investigations.
[0128] The above steps S701 to S703 are explained and illustrated as follows with examples:
[0129] For example, an enterprise uses the above method to detect horizontal privilege escalation vulnerabilities, and the specific scenario is as follows:
[0130] Step S701: The system detects that employee A (the first user) attempts to access the unauthorized page / admin, and records the detailed information of the abnormal behavior, including the user identity identifier A123, the operation time 10:05 on January 25, 2025, the access path / admin, etc.
[0131] Step S702: Select employee B (the second user) as the comparison object. Employee B has the permission to access / admin. The system extracts the log data of employee A and employee B within the same time period and finds that the access paths and request parameters of employee A are highly similar to those of employee B.
[0132] Step S703: The system confirms that the behavioral permissions of employee A and employee B are different, and the behavioral pattern of employee A is highly similar to that of employee B. Therefore, the system determines that there is a horizontal privilege escalation vulnerability, generates an alarm, and records the detailed information of the vulnerability, such as user identity A123, operation time 10:05 on January 25, 2025, and abnormal type horizontal privilege escalation vulnerability, etc.
[0133] Through the above steps S701 to S703, the present invention can effectively detect whether there is a horizontal privilege escalation vulnerability in the system, timely discover potential security threats, and ensure the secure operation of the enterprise internal system.
[0134] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software adding the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions to enable a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.
[0135] According to another embodiment of the present invention, a behavior data analysis system is further provided. Figure 8 It is a schematic structural diagram of the behavior data analysis system according to the embodiment of the present invention, as Figure 8 shown. The system includes:
[0136] An acquisition module 81, configured to acquire log data of user behavior. The log data includes: user identity identifier, access time, operation type, operation result, access path, request parameter, and response status code.
[0137] An intelligent analysis module 82, configured to analyze the log data based on a normal behavior model to determine whether the user behavior corresponds to a normal behavior or an abnormal behavior. Among them, the normal behavior model stores usage parameters of multiple users, and the usage parameters include: behavior permissions, permission expiration dates, and permission address information.
[0138] Among them, when the log data matches the usage parameters, it is determined that the user behavior corresponds to a normal behavior.
[0139] In the case where the log data does not match the usage parameters, it is determined that the user behavior corresponds to an abnormal behavior.
[0140] By adopting the above technical solution, since the acquisition module 81 and the intelligent analysis module 82 are combined, the acquisition module 81 can comprehensively acquire the log data of user behavior, including multi-dimensional data such as user identity identification, access time, operation type, operation result, access path, request parameters, response status code, etc., while the intelligent analysis module 82 analyzes the log data based on the normal behavior model storing usage parameters such as behavior permissions, permission periods, permission address information, etc., and determines whether the user behavior is a normal behavior or an abnormal behavior through matching judgment. Therefore, the problem that the monitoring and analysis methods of the related technology have low intelligence and gradually cannot meet the requirements is solved. Furthermore, the effect of improving the intelligence level of user behavior analysis is achieved.
[0141] In one implementation, the system is also used to: determine usage parameters based on preset values;
[0142] In response to a write operation, update the preset value based on a preset time period.
[0143] In one implementation, the system is also used to: determine usage parameters based on a machine learning model;
[0144] Update the usage parameters based on the machine learning model to obtain new usage data.
[0145] In one implementation, the system is also used to: construct a user portrait based on a machine learning algorithm, and the user portrait includes: the user's role, permission level, and common operation paths;
[0146] Train a machine learning model based on historical data to learn the normal behavior of the user to obtain usage parameters; where the normal behavior is the behavior of the user under the usage parameters;
[0147] Update the machine learning model based on real-time data to update the usage parameters to obtain new usage data.
[0148] In one implementation, in the case where it is determined that the user behavior corresponds to an abnormal behavior, the system is also used to: obtain the real operation result of the abnormal behavior;
[0149] Replace the current user identity identification of the user corresponding to the abnormal behavior with a virtual user identity identification;
[0150] Use the virtual user identity identification to simulate the operation of a behavior permission higher than the current user identity identification to obtain a virtual operation result;
[0151] Compare the virtual operation result with the real operation result;
[0152] In the case where the distance between the virtual operation result and the real operation result is less than a preset threshold, it is determined that the system for executing user behavior has a vertical privilege escalation vulnerability.
[0153] In one implementation, in the case where it is determined that the user behavior corresponds to an abnormal behavior, the system is further configured to: determine that the user of the abnormal behavior is the first user;
[0154] Compare the log data of the first user with the log data of the second user;
[0155] In the case where the log data of the first user is similar to the log data of the second user and the behavior permissions of the first user and the second user are different, it is determined that the system for executing user behavior has a horizontal vulnerability.
[0156] It should be noted that the above-mentioned various modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to this: the above-mentioned modules are all located in the same processor; or, the above-mentioned various modules are separately located in different processors in any combination form.
[0157] An embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored. Wherein, when the computer program is run by a processor, it executes the steps in any one of the above method embodiments.
[0158] In one implementation, in this embodiment, the above storage medium may include but is not limited to: USB flash drive, read-only memory (abbreviated as ROM), random access memory (abbreviated as RAM), mobile hard disk, magnetic disk or optical disc, etc., various media that can store computer programs.
[0159] An embodiment of the present invention also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0160] An embodiment of the present invention also provides a computer program product, including computer instructions, and when the computer instructions are executed by a processor, the steps of the methods described in various embodiments of the present invention are implemented.
[0161] In one implementation, specific examples in this embodiment may refer to the examples described in the above embodiments and optional embodiments, and details are not described herein again.
[0162] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a sequence different from here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.
[0163] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A behavior data analysis method, characterized in that: include: Obtaining log data of user behavior, the log data including: user identity, access time, operation type, access path, request parameters, and response status code; Analyze the log data based on a normal behavior model to determine whether the user behavior corresponds to normal behavior or abnormal behavior; wherein the normal behavior model stores usage parameters of multiple users, and the usage parameters include: behavior authority, authority period, and authority address information; In a case where the log data matches the usage parameter, determining that the user behavior corresponds to normal behavior; In a case where the log data does not match the usage parameter, it is determined that the user behavior corresponds to an abnormal behavior.
2. The method according to claim 1, characterized in that Also includes: Determining the usage parameter based on a preset value; In response to a write operation, the preset value is updated based on a preset time period.
3. The method according to claim 1, characterized in that Also includes: Determining the usage parameters based on a machine learning model; The usage parameters are updated based on the machine learning model to obtain new usage data.
4. The method according to claim 3, characterized in that Updating the usage parameter based on the machine learning model includes: Build a user profile based on a machine learning algorithm, the user profile includes: the user's role, permission level, and common operation paths; The machine learning model is trained based on historical data to learn the normal behavior of the user to obtain the usage parameters; wherein the normal behavior is the behavior of the user under the usage parameters; The machine learning model is updated based on real-time data to update the usage parameters to obtain new usage data.
5. The method according to claim 1, characterized in that In the case where it is determined that the user behavior corresponds to abnormal behavior, the method further includes: Obtaining the actual operation result of the abnormal behavior; Replacing the current user identity of the user corresponding to the abnormal behavior with the virtual user identity; Using the virtual user identity to simulate an operation with a higher behavioral authority than the current user identity to obtain a virtual operation result; Comparing the virtual operation result with the real operation result; When the distance between the virtual operation result and the real operation result is less than a preset threshold, it is determined that the system executing the user behavior has a vertical authority overflow vulnerability.
6. The method according to claim 1, characterized in that In the case where it is determined that the user behavior corresponds to abnormal behavior, the method further includes: Determining that the user with the abnormal behavior is the first user; comparing the log data of the first user with the log data of the second user; When the log data of the first user is similar to the log data of the second user, and the behavior authority of the first user is different from the behavior authority of the second user, it is determined that a horizontal vulnerability exists in the system that executes the user behavior.
7. A behavioral data analysis system, characterized in that: include: An acquisition module is used to acquire log data of user behavior, wherein the log data includes: user identity, access time, operation type, access path, request parameters, and response status code; An intelligent analysis module, for analyzing the log data based on a normal behavior model to determine whether the user behavior corresponds to normal behavior or abnormal behavior; wherein the normal behavior model stores usage parameters of multiple users, and the usage parameters include: behavior authority, authority period, and authority address information; Wherein, when the log data matches the usage parameter, determining that the user behavior corresponds to normal behavior; In a case where the log data does not match the usage parameter, it is determined that the user behavior corresponds to an abnormal behavior.
8. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program executes the steps of the method described in any one of claims 1 to 6 when executed by a processor.
9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the steps of the method according to any one of claims 1 to 6.
10. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Cited By
Intelligent guiding method, device and system based on user behaviors, and electronic equipment
CN121070478A