Abnormal user behavior analysis method and device for research and development personnel

By generating and cleaning the behavior logs of R&D personnel, combining the risk assessment model and abnormal behavior detection engine, identifying the abnormal operation behavior of R&D personnel and providing real-time alarms, the problems of poor detection results and inability to promptly alerts in the existing technology are solved.

CN120104448APending Publication Date: 2025-06-06BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510184309.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The existing technology is difficult to accurately identify abnormal user behaviors of R&D personnel, resulting in poor detection results and inability to alert in time.

Method used

By generating target pending logs, cleaning the logs to obtain identification related behavior data, and using the risk assessment model and abnormal behavior detection engine, the current R&D personnel behavior alarm data and event handling alarm data are determined.

Benefits of technology

It realizes efficient and accurate identification of abnormal operation behaviors of R&D personnel, and provides real-time alarms, solving the problems of poor detection results and inability to promptly alert.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104448A_ABST
    Figure CN120104448A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal user behavior analysis method and device oriented to research and development personnel, and relates to the technical field of data security. The method comprises the steps of generating a target to-be-processed log based on research and development environment behavior data and office environment behavior data of research and development personnel; cleaning the target to-be-processed log to obtain identifier associated behavior data; and according to the identification association behavior data and a risk assessment model, determining current research and development personnel behavior alarm data, and based on an abnormal behavior detection engine, the identification association behavior data and the current research and development personnel behavior alarm data, determining current event disposal alarm data. According to the technical scheme provided by the embodiment of the invention, the abnormal operation behavior of the research and development personnel can be efficiently and accurately identified, and the abnormal operation behavior of the research and development personnel is alarmed in real time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to an abnormal user behavior analysis method and device for R&D personnel. Background Art

[0002] At present, various enterprises, especially those in the manufacturing industry, often have a lot of intellectual property rights, but they face the risk of external attacks, malicious theft of core data or related intellectual property rights by internal personnel. Code leakage, unauthorized access to sensitive data and other behaviors pose a serious threat to corporate information assets. However, traditional security management methods cannot accurately identify potential risks in user behavior, especially the complex operations of R&D personnel in development tools and systems are difficult to directly parse and analyze.

[0003] Many organizations and enterprises currently tend to use various means to protect the security of core data (such as product development codes). For example, through DLP (Data Leak Prevention) technology, whether enterprise personnel send sensitive data outward from the terminal desktop behavior and email sending and receiving aspects can be detected, and an alarm can be triggered. Another example is that through special Internet behavior management equipment, the Internet access behavior of personnel can be controlled, and access to sites such as network disks can be restricted.

[0004] However, in the application process of DLP technology, it is often necessary to maintain the sensitive data keyword definitions of different departments and detect the file transfer of chat tools or peripherals (such as USB flash drives). Generally, after a long period of time, due to the failure of maintenance of the sensitive dictionary table and the inability to automatically perceive some exceptions (such as the approval of the application for external file transmission on the office automation system, or normal behavior in daily work), the number of DLP alarms may increase sharply. In the application of DLP technology, there is a concern that false alarms will cause incorrect disposal and affect the user's office performance, and the actions of the hit strategy will not be blocked. This results in DLP technology being used only for auditing. Since the analysis dimension is too single, the number of alarms and the false alarm rate are too high, the technology will gradually lose its operation.

[0005] In terms of online behavior management, blacklists and whitelists are often used to control access to different Web access traffic protocols and different URLs (Universal Resource Locators). Many of the daily violations of corporate behavior are carried out through the Internet, so general organizations also hope to limit access to some illegal sites by controlling users' online access to reduce the occurrence of violations and leaks.

[0006] Traditional user behavior analysis technology does not distinguish between the detection methods of R&D personnel and ordinary employees. It still uses common detection methods to perform correlation analysis and detection logs, but the behavior of R&D personnel is different from that of ordinary employees. There are significant differences between the behavior of R&D personnel and ordinary employees in terms of work content, technical means, tool usage, operating habits, etc. This difference makes it difficult for conventional monitoring methods (such as DLP, Internet behavior management technology or traditional user behavior analysis technology) to adapt to the R&D environment, resulting in the inability to accurately identify potential risks or abnormal behaviors.

[0007] Therefore, an efficient and accurate user behavior analysis method is needed to deeply analyze the behavior logs of R&D personnel, identify abnormal behaviors and provide real-time alerts. Summary of the invention

[0008] The present invention provides a method and device for analyzing abnormal user behavior for R&D personnel, so as to solve the problems of poor detection effect of abnormal operation behavior of R&D personnel and failure to issue alarms for abnormal behavior in time.

[0009] According to one aspect of the present invention, a method for analyzing abnormal user behavior for R&D personnel is provided, comprising:

[0010] Generate target logs to be processed based on the R&D environment behavior data and office environment behavior data of R&D personnel;

[0011] Clean the target logs to be processed and obtain the identification-related behavior data;

[0012] According to the identification-related behavior data and the risk assessment model, the current R&D personnel behavior alarm data is determined, and based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data, the current event handling alarm data is determined.

[0013] According to another aspect of the present invention, there is provided an abnormal user behavior analysis device for R&D personnel, comprising:

[0014] A target log generation module for processing is used to generate a target log based on the R&D environment behavior data and office environment behavior data of the R&D personnel.

[0015] The log cleaning module is used to clean the target logs to be processed and obtain the identification-related behavior data;

[0016] The current event handling alarm data determination module is used to determine the current R&D personnel behavior alarm data based on the identification-related behavior data and the risk assessment model, and to determine the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data.

[0017] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0018] at least one processor; and

[0019] a memory communicatively connected to the at least one processor; wherein,

[0020] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the abnormal user behavior analysis method for R&D personnel described in any embodiment of the present invention.

[0021] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the abnormal user behavior analysis method for R&D personnel described in any embodiment of the present invention when executed.

[0022] The technical solution of the embodiment of the present invention generates a target log to be processed based on the R&D environment behavior data and office environment behavior data of the R&D personnel, thereby cleaning the target log to be processed, obtaining the identification-related behavior data, and then determining the current R&D personnel behavior alarm data according to the identification-related behavior data and the risk assessment model, and determining the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data. In this solution, the operation behavior logs of the R&D personnel are collected from the R&D environment and the office environment, and the collected log formats are unified through cleaning processing, which is convenient for effectively associating the operation behaviors of the same R&D personnel, and the R&D operation behaviors are scored based on the risk assessment model, and the behavior events are redefined through the abnormal behavior detection engine, so as to reliably identify the abnormal situations in the R&D process from the two dimensions of R&D operation behaviors and behavior events, solve the problems of poor detection effect of abnormal operation behaviors for R&D personnel and failure to timely warn against abnormal behaviors, and can efficiently and accurately identify the abnormal operation behaviors of R&D personnel, and warn the abnormal operation behaviors of R&D personnel in real time.

[0023] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0025] Figure 1 A flowchart of an abnormal user behavior analysis method for R&D personnel provided in the first embodiment of the present invention;

[0026] Figure 2 A flowchart of an abnormal user behavior analysis method for R&D personnel provided in Embodiment 2 of the present invention;

[0027] Figure 3 A logical schematic diagram of an abnormal user behavior analysis method for R&D personnel provided in the second embodiment of the present invention;

[0028] Figure 4 A logical schematic diagram of an associated scenario provided in the second embodiment of the present invention;

[0029] Figure 5 A schematic diagram of the structure of an abnormal user behavior analysis device for R&D personnel provided in Embodiment 3 of the present invention;

[0030] Figure 6 A schematic diagram of the structure of an electronic device that can be used to implement an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0031] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0032] It should be noted that the terms "current", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0033] Embodiment 1

[0034] Figure 1 The flowchart of a method for analyzing abnormal user behavior for R&D personnel provided in the first embodiment of the present invention is applicable to the situation of accurately and efficiently identifying abnormal operation behaviors of R&D personnel. The method can be executed by an abnormal user behavior analysis device for R&D personnel. The abnormal user behavior analysis device for R&D personnel can be implemented in the form of hardware and / or software. The abnormal user behavior analysis device for R&D personnel can be configured in an electronic device. The electronic device can be a computer or a server, etc. Figure 1 As shown, the method includes:

[0035] Step 110: Generate a target log to be processed based on the R&D environment behavior data and office environment behavior data of the R&D personnel.

[0036] Among them, the R&D environment behavior data may be data describing the user's operation behavior in the R&D environment. The office environment behavior data may be data describing the user's operation behavior in the office environment. The target log to be processed may be a log recording the operation behavior data of the R&D personnel.

[0037] In the embodiment of the present invention, relevant logs recording the operation behaviors of R&D personnel can be parsed from the R&D environment behavior data of R&D personnel and the office environment behavior data of R&D personnel as target logs to be processed.

[0038] For example, you can connect to various version management tools (such as GIT / SVN) through Syslog functions / database middleware (JDBC, ODBC) / application programming interfaces, etc., to obtain real-time logs such as code submission and branch operations, and use agents or software development kits to collect terminal logs (file access logs, outbound behavior logs, etc.), integrate R&D environment-related application systems such as GIT (distributed version control system), SVN (Subversion, version control system), bastion hosts, etc., and office environment-related systems such as mail systems and DLP systems. Sensitive data operation records, obtain the R&D environment behavior data and office environment behavior data of R&D personnel.

[0039] Step 120: clean the target log to be processed and obtain the identification-related behavior data.

[0040] The identification-related behavior data may be log data obtained by performing log cleaning on the target log to be processed.

[0041] In an embodiment of the present invention, the target log to be processed can be cleaned to remove invalid data in the target log to be processed, extract useful data for analyzing abnormal operation behavior of R&D personnel, and unify the data format to obtain identification-related behavior data.

[0042] Exemplarily, the target logs to be processed can be cleaned and the log format can be unified, that is, the target logs to be processed can be identified and unified using identity identifiers and file object identifiers, so as to identify the behavior logic of R&D personnel, associate the behavior of R&D personnel across platforms and regions, and obtain identification-associated behavior data.

[0043] Step 130: determine the current R&D personnel behavior alarm data based on the identification-related behavior data and the risk assessment model, and determine the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data.

[0044] Among them, the risk assessment model can be used as a model to calculate the risk score of abnormal operation behavior of R&D personnel. The current R&D personnel behavior alarm data can be an alarm information generated based on the risk value of the abnormal operation behavior of the R&D personnel. The abnormal behavior detection engine can be used to detect and identify different behaviors of different types of R&D personnel. The abnormal behavior detection engine is configured with predetermined analysis and judgment rules and secondary definition alarm types. The secondary definition alarm types may include but are not limited to routine events, noteworthy events, and events that need to be handled immediately. The current event handling alarm data can be a comprehensive alarm data determined based on the output results of the abnormal behavior detection engine and the current R&D personnel behavior alarm data, which is used to perform risk assessment from the two dimensions of abnormal operation behavior and behavioral events of R&D personnel.

[0045] In an embodiment of the present invention, based on a risk assessment model, the identification-associated behavior data can be analyzed to determine the risk score corresponding to the current R&D personnel's operational behavior, and based on the risk score corresponding to the current R&D personnel and the data related to the current R&D personnel's abnormal operational behavior, the current R&D personnel behavior alarm data can be generated, and then the identification-associated behavior data can be input into the abnormal behavior detection engine to determine the event risk level of the current R&D personnel's behavioral event through the abnormal behavior detection engine, thereby generating current event handling alarm data based on the current R&D personnel behavior alarm data and the event risk level of the current R&D personnel's behavioral event.

[0046] Optionally, behavioral events include, but are not limited to, R&D environment detection events, transit area events, and office environment detection events.

[0047] Exemplarily, R&D environment detection events include, but are not limited to, behavioral events of systems such as GIT, SVN, servers, and bastion hosts. The event sources of R&D environment detection events may include code management tools, log servers, and bastion host logs. R&D environment detection events from code management tools specifically include code submission (including time, number of files, whether it is a sensitive file), branch merge (recording the target and source of the merged branch), large-scale code deletion or modification (threshold triggering), high-frequency code operations (submission operations exceed the limit in a short period of time), permission changes (recording changes in user permissions to branches or warehouses), abnormal cloning or downloading (unregistered IP access to warehouses); R&D environment detection events from generation service logs may specifically include remote access login (recording login IP, user identity, operation time), file upload / download operations (recording file path, size, source), and permission escalation (escalation time, tools, results); R&D environment detection events from bastion host logs specifically include cross-system access (recording source and target system), high-frequency file operations (reading / deleting a large number of files in a short period of time), and sensitive instruction execution (such as inter-system data transmission tools scp or rsync for file transfer).

[0048] Exemplarily, the sources of transit area events include logs of FTP (File Transfer Protocol) systems, file ferry systems, and the like, and specifically include at least one of the following events: file upload (recording file name, size, and target address), file download (recording downloading user and target address), abnormal file size (exceeding a specified file threshold), abnormal upload frequency (multiple uploads of similar files in a short period of time), and changes in file encryption status (such as non-encrypted files being transmitted).

[0049] Exemplarily, office environment detection events may include behavioral events of security devices such as terminal security management systems, DLP, email systems, document encryption and decryption systems, and online behavior management systems. The behavioral events corresponding to the terminal security management system include at least one of inserting an external storage device (such as a USB), editing sensitive files locally (recording file paths, sensitive keywords), renaming files or hiding extensions, and sending files in batches (such as through instant messaging software). The behavioral events of DLP include at least one of sending sensitive data outbound (uploading files containing sensitive content through email / chat tools), copying to external devices (such as mobile hard drives), and printing sensitive files. The behavioral events of the email system may include abnormal attachments (sending files containing sensitive content or large attachments), and / or sending group emails in a short period of time. Document encryption and decryption events include decryption of sensitive files (operating users, decryption time), and / or unauthorized users attempting encryption and decryption. The behavioral events of online behavior management include visiting high-risk websites (such as unauthorized cloud storage or code sharing platforms), and / or uploading files to external platforms (such as Baidu Netdisk, etc.).

[0050] In a specific example, according to the monitoring requirements of the R&D environment, the transit area, and the office environment, the behavior events are standardized, and a standardized behavior event query table as shown in Table 1 can be obtained:

[0051] Table 1 Standard behavioral event query table

[0052]

[0053]

[0054] The technical solution of the embodiment of the present invention generates a target log to be processed based on the R&D environment behavior data and office environment behavior data of the R&D personnel, thereby cleaning the target log to be processed, obtaining the identification-related behavior data, and then determining the current R&D personnel behavior alarm data according to the identification-related behavior data and the risk assessment model, and determining the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data. In this solution, the operation behavior logs of the R&D personnel are collected from the R&D environment and the office environment, and the collected log formats are unified through cleaning processing, which is convenient for effectively associating the operation behaviors of the same R&D personnel, and the R&D operation behaviors are scored based on the risk assessment model, and the behavior events are redefined through the abnormal behavior detection engine, so as to reliably identify the abnormal situations in the R&D process from the two dimensions of R&D operation behaviors and behavior events, solve the problems of poor detection effect of abnormal operation behaviors for R&D personnel and failure to timely warn against abnormal behaviors, and can efficiently and accurately identify the abnormal operation behaviors of R&D personnel, and warn the abnormal operation behaviors of R&D personnel in real time.

[0055] Embodiment 2

[0056] Figure 2 This is a flowchart of an abnormal user behavior analysis method for R&D personnel provided in Example 2 of the present invention. This embodiment is specific based on the above embodiment and provides a specific optional implementation method for determining the current R&D personnel behavior alarm data based on the identification of associated behavior data and the risk assessment model. Figure 2 As shown, the method includes:

[0057] Step 210: Generate a target log to be processed based on the R&D environment behavior data and office environment behavior data of the R&D personnel.

[0058] Step 220: clean the target log to be processed to obtain identification-related behavior data.

[0059] In an optional embodiment of the present invention, cleaning the target log to be processed and obtaining identification-related behavior data may include: parsing the target log to be processed to obtain different account data under each user identity and user operation object data; performing unified user identity identification processing and file object identification processing on the target log to be processed according to the different account data and user operation object data under each user identity to obtain identification-related behavior data.

[0060] The user operation object data can be used to describe the operation object of the R&D personnel. The user identity unified processing can be the operation of uniformly identifying the log source. The file object identification unified processing can be the processing of uniformly identifying the same operation object of the R&D personnel.

[0061] In an embodiment of the present invention, the target log to be processed can be parsed to obtain different account data under the identity information of the relevant R&D personnel and user operation object data, and the identity information of the target log to be processed can be completed, and then the user identity identification of the target log to be processed can be uniformly processed to unify different accounts under the same user identity, and the file object identification of the target log to be processed can be uniformly processed to facilitate subsequent association, and then the log after the unified processing can be used as identification association behavior data.

[0062] Step 230: extract the current user behavior features in the identification-associated behavior data, and determine the current research and development stage corresponding to the identification-associated behavior data.

[0063] The current user behavior characteristics may be characteristics describing the current R&D personnel's R&D behavior. The current user behavior characteristics may include the current R&D personnel's operation frequency, sensitive data access, and cross-system behavior consistency. The current R&D stage may be the R&D stage of the current R&D personnel's R&D behavior in the project.

[0064] In an embodiment of the present invention, the R&D behavior characteristics of the current R&D personnel can be extracted from the identification-associated behavior data as the current user behavior characteristics, and the current R&D stage corresponding to the identification-associated behavior data can be determined based on the project management system (the management system of the project R&D stage).

[0065] Step 240: query the stage adjustment factor according to the current R&D stage, and determine the total risk score of the current R&D personnel according to the current user behavior characteristics, the user behavior characteristic dimension weights, the stage adjustment factor, and the risk assessment model.

[0066] The stage adjustment factor may be a different weight adjustment factor set for the user behavior feature in different development stages. The user behavior feature dimension weight may be a weight set for the user behavior feature.

[0067] In an embodiment of the present invention, a pre-set table storing stage adjustment factors of different R&D stages can be read to determine the stage adjustment factor matching the current R&D stage, and then the behavior risk score is calculated based on the current user behavior characteristics, thereby substituting the user behavior risk score, the user behavior characteristic dimension weight, and the stage adjustment factor into the pre-set risk assessment model to calculate the total risk score of the current R&D personnel.

[0068] In an optional embodiment of the present invention, the risk assessment model may include the following form: 总 =∑Stage k ·a k ·R k ; Among them, R 总 Indicates the total risk score of the current R&D personnel, Stage k represents the stage adjustment factor under the k-th user behavior feature dimension, a k represents the dimension weight under the k-th user behavior feature dimension, R k Represents the behavioral risk score under the k-th user behavior feature dimension.

[0069] Specifically, the risk assessment model can calculate the behavioral risk score of R&D personnel based on multi-dimensional behavioral characteristics and dynamic baselines, and can dynamically adjust the behavioral baseline in combination with the R&D stages (requirements analysis, design, development, testing, and release). The baseline behavior and exception rules of each stage are different, and the risk assessment model needs to dynamically adjust the baseline and weight: (1) Requirements analysis stage: low weights are assigned to code operation behaviors, and high weights are assigned to sensitive document processing and outbound behaviors. Development stage: increase tolerance for frequent code submission behaviors, and strengthen monitoring of sensitive data (such as core algorithms and configuration files). Testing stage: focus on monitoring the access and outbound delivery of test data, and increase tolerance for frequent script execution. Release stage: strengthen monitoring of packaging and outbound file operations, and reduce the sensitivity of regular file uploads and sharing.

[0070] The stage adjustment factors for different R&D stages can be found in Table 2:

[0071] Table 2 Stage adjustment factor query table

[0072]

[0073] Optional, based on Calculate the behavior risk score corresponding to the operation frequency in the user behavior feature dimension; where R 频 represents the operation frequency risk score, μ 频率 is the mean operation frequency of the user's historical data, σ 频率 Represents the standard deviation of the operation frequency of the user's historical data. 频 If it is greater than the threshold, it is marked as a high-risk operation.

[0074] Optional, based on Calculate the behavior risk score corresponding to the sensitive file operation in the user behavior feature dimension; where w i represents the weight of the i-th sensitive file operation, f i Indicates the number of operations on the i-th sensitive file.

[0075] Optional, can be based on R 一致性 =1-P calculates the behavioral risk score corresponding to the consistency of cross-system behavior in the user behavior feature dimension; where P represents the matching degree, that is, the degree of correlation between the behavior in multiple different systems (such as the matching degree between the submitted file name and the email attachment); the lower the P value, the more abnormal the behavior is and the higher the risk is.

[0076] Optional, based on Calculate the behavior risk score corresponding to high-sensitivity data transmission in the user behavior feature dimension. j represents the sensitivity weight; d jIndicates the number of sensitive data operations for the jth item. The weight of a regular matching keyword (such as "password", "encryption", etc.) can be 2, and the weight of identifying specific sensitive content in a code snippet (such as encryption algorithm, API key) can be 5.

[0077] Optional, based on Calculate the behavioral risk score of the behavioral baseline deviation in the user behavior feature dimension, x 当前 Represents the user's current behavior feature value, μ 基线 With σ 基线 They represent the mean and standard deviation of the user behavior and user historical behavior feature values ​​respectively.

[0078] Step 250: determine the current R&D personnel behavior alarm data based on the current R&D personnel total risk score, and determine the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data.

[0079] In an optional embodiment of the present invention, based on the abnormal behavior detection engine, the identification-associated behavior data and the current R&D personnel behavior alarm data, determining the current event handling alarm data may include: determining the current behavior event alarm level based on the identification-associated behavior data and the abnormal behavior detection engine; obtaining an event alarm secondary analysis mapping table; determining the current event handling alarm data based on the current behavior event alarm level, the current R&D personnel behavior alarm data and the event alarm secondary analysis mapping table.

[0080] The current behavior event alarm level may be an alarm level describing the current R&D behavior event of the R&D personnel. The event alarm secondary analysis mapping table may be a pre-set table for guiding the handling priority of R&D behavior events.

[0081] In an embodiment of the present invention, based on the abnormal behavior detection engine, the associated behavior data can be analyzed and identified to determine the event alarm level of the current R&D personnel behavior event, and then obtain a pre-configured event alarm secondary analysis mapping table, thereby mapping the current behavior event alarm level and the current R&D personnel behavior alarm data to the event alarm secondary analysis mapping table to determine the current event handling alarm data.

[0082] For example, the event alarm secondary analysis mapping table can be seen in Table 3:

[0083] Table 3 Event alarm secondary analysis mapping table

[0084]

[0085] Among them, low-risk personnel, medium-risk personnel and high-risk personnel are distinguished based on the scores output by the risk assessment model, and the score range corresponding to the specific risk level can be set by oneself.

[0086] In an optional embodiment of the present invention, determining the current behavior event alarm level based on the identification-associated behavior data and the abnormal behavior detection engine may include: inputting the identification-associated behavior data into the abnormal behavior detection engine, identifying abnormal behavior events on the identification-associated behavior data based on abnormal behavior event identification rules configured by the abnormal behavior detection engine, and generating the current behavior event alarm level when determining that an abnormal behavior event exists.

[0087] Among them, the abnormal behavior event identification rule may be a rule for identifying abnormal R&D behavior events of R&D personnel.

[0088] In an embodiment of the present invention, the identification-associated behavior data can be input into the abnormal behavior detection engine, and then based on the abnormal behavior event identification rules configured by the abnormal behavior detection engine, the identification-associated behavior data can be identified for abnormal behavior events, and when it is determined that the behavior event corresponding to the current R&D personnel's operating behavior is an abnormal behavior event, the current behavior event alarm level is generated.

[0089] Exemplarily, the abnormal behavior event identification rules include cross-environment abnormal access identification rules, multiple sensitive file outbound identification rules, and abnormal R&D operation and intermediate area behavior combined identification rules. The cross-environment abnormal access identification rule is used to identify the sensitive data crossing behavior from the R&D environment to the office environment, which is an abnormality. The multiple sensitive file outbound identification rule is used to identify the risk of sensitive file leakage, which can specifically trigger a high-risk alarm. The abnormal R&D operation combined with the intermediate area behavior identification rule is used to identify the combined behavior and display it as abnormal operation, which requires special attention. The cross-environment abnormal access identification rule is when there is a high frequency of code cloning operations in GIT / SVN, the associated files are uploaded to the intermediate area, and the files are downloaded from FTP to the office environment, it is determined that there is cross-environment abnormal access. The multiple sensitive file outbound identification rule is when in the office environment, multiple sensitive files are outbound through DLP in a short period of time, and the Internet behavior management system detects that the files are uploaded to the cloud storage, it is determined that there are multiple sensitive file outbound behaviors. The identification rule for the combination of abnormal R&D operations and intermediate area behaviors is as follows: when extraction or sensitive directory access is performed in the R&D environment, and a large number of files are uploaded to the intermediate transfer area within a short period of time, it is determined that abnormal R&D operations combined with intermediate area behaviors have occurred.

[0090] In an optional embodiment of the present invention, after determining the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data, it may also include: when an abnormal alarm is triggered based on the current event handling alarm data, calling the target interface and downloading the abnormal alarm related data.

[0091] The target interface may be an interface for automatically downloading files related to the current event handling alarm data. The abnormal alarm associated data may be R&D operation behavior data associated with the current event handling alarm data.

[0092] In an embodiment of the present invention, if it is determined based on the current event handling alarm data that there is a behavioral event that requires attention and / or immediate processing, an abnormal alarm is triggered, and the abnormal alarm-related data is automatically downloaded through the application program interface, i.e., the target interface, integrated in the third-party system, to facilitate subsequent evidence collection, research and analysis, provide the original chain of evidence for the alarm, and accelerate internal risk management.

[0093] In a specific example, Figure 3 As shown, the abnormal user behavior analysis method for R&D personnel may specifically include the following steps:

[0094] Step 1: Collect office environment behavior data (DLP, terminal management system, Internet behavior management system, document encryption and decryption system, and email system behavior data) and R&D environment behavior data (Git, SVN, server, bastion host, and other related logs).

[0095] Step 2: For the collected R&D-related logs, complete the identity information, responsibilities, access rights, and compile a list of identity information (in CSV or Excel format), then enter it into the platform's identity management function, associate different accounts under the same identity (existing in different logs), and generate a new identity field in different logs, that is, unified identity information, to complete the unification of user identification. For example, if the identity is Zhang San, in the Git system log, the relevant account field value is zhangsan, and in the DLP system, the email account is zhangsan@company.com. In order to facilitate the association, a unified identity is added to the collected logs for unified processing, which is convenient for subsequent association of behaviors of different dimensions.

[0096] Step 3. The cleaned R&D personnel behavior data and the current R&D stage obtained from the project management system are transmitted to the risk assessment model, and the cleaned R&D personnel behavior data, completed identity information, completed job descriptions, access permissions, and risk scores calculated by the risk assessment model are sent to the abnormal behavior detection engine.

[0097] Step 4: Abnormal behavior detection engine classifies the collected related behavior events, detects and warns of abnormal behaviors.

[0098] Among them, when conducting abnormal user behavior analysis for R&D personnel, from command operations in the R&D environment, to file downloading / copying to the office environment, and then to the external abnormal behavior detection associated scenario logic, see Figure 4 .

[0099] This solution can efficiently collect and integrate multi-source data (code management tool logs, terminal management logs, DLP logs, and other system logs). Through cross-system multi-dimensional data integration, it can achieve a comprehensive record of R&D behavior and make up for the limitations of traditional single data sources. Based on the characteristics of the R&D environment, a user behavior risk scoring model is designed to generate risk scores based on the following indicators. Combined with multiple log sources, it verifies the consistency and legality of the behavior (such as whether there are unauthorized outbound operations after the code is submitted). It can dynamically adjust weights and thresholds to adapt to different R&D environments and project stages, and support personalized risk assessment. The association mechanism is applicable to most R&D processes. Based on risk scores and predefined rules (such as sensitive data operations or unauthorized operations), abnormal behavior alerts are generated in real time, and alerts are automatically graded (low, medium, and high priority) according to risk scores to improve handling efficiency.

[0100] In summary, this solution specifically associates and analyzes the behavioral data of the R&D environment (GIT, SVN, server, bastion host), intermediate transfer area (FTP, file ferry system), and office environment (terminal management system, DLP, mail system, etc.) to achieve multi-environment monitoring and completely eliminate monitoring blind spots.

[0101] Accurate behavior modeling to reduce false positives: Behavior modeling for R&D scenarios divides the behavior of R&D personnel into R&D phase behavior (code submission, cloning, branch operation, etc.) and office phase behavior (file outbound, sensitive file encryption and decryption, etc.). By combining behavior context and specific association rules (such as cross-environment file transfer and abnormal access frequency), false positives can be effectively reduced and the accuracy of alarms can be improved.

[0102] Dynamic risk scoring model to provide quantitative security analysis: Introduce a dynamic risk scoring model to calculate risk scores based on multi-dimensional data such as user behavior patterns, event correlation strength, and behavioral risk history, and provide graded alarms based on the scores, providing clear risk levels (low, medium, and high) to facilitate security personnel to prioritize high-risk incidents and improve security management efficiency.

[0103] The technical solution of the embodiment of the present invention generates a target pending day based on the R&D environment behavior data and office environment behavior data of the R&D personnel, thereby cleaning the target pending log to obtain the identification-related behavior data, and then extracting the current user behavior characteristics in the identification-related behavior data, and determining the current R&D stage corresponding to the identification-related behavior data, and further querying the stage adjustment factor according to the current R&D stage, and determining the current R&D personnel's total risk score according to the current user behavior characteristics, the user behavior characteristic dimension weights, the stage adjustment factor, and the risk assessment model, and determining the current R&D personnel's behavior alarm data according to the current R&D personnel's total risk score, and determining the current R&D personnel's behavior alarm data, and based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel's behavior alarm data, determining the current event handling alarm data. In this solution, the operation behavior logs of R&D personnel are collected from the R&D environment and the office environment, and the collected log formats are unified through cleaning processing, which is convenient for effectively associating the operation behaviors of the same R&D personnel, and scoring the R&D operation behaviors based on the risk assessment model. The behavior events are redefined through the abnormal behavior detection engine, so as to reliably identify abnormal situations in the R&D process from the two dimensions of R&D operation behavior and behavior events, which solves the problems of poor detection of abnormal operation behaviors of R&D personnel and the inability to issue timely alarms for abnormal behaviors. It can efficiently and accurately identify the abnormal operation behaviors of R&D personnel and issue real-time alarms for abnormal operation behaviors of R&D personnel.

[0104] Embodiment 3

[0105] Figure 5 This is a schematic diagram of the structure of an abnormal user behavior analysis device for R&D personnel provided in Embodiment 3 of the present invention. Figure 5 As shown, the device comprises:

[0106] A target log to be processed generating module 310 is used to generate a target log to be processed based on the R&D environment behavior data and the office environment behavior data of the R&D personnel;

[0107] The log cleaning module 320 is used to clean the target log to be processed and obtain the identification-related behavior data;

[0108] The current event handling alarm data determination module 330 is used to determine the current R&D personnel behavior alarm data based on the identification-related behavior data and the risk assessment model, and to determine the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data.

[0109] The technical solution of the embodiment of the present invention generates a target log to be processed based on the R&D environment behavior data and office environment behavior data of the R&D personnel, thereby cleaning the target log to be processed, obtaining the identification-related behavior data, and then determining the current R&D personnel behavior alarm data according to the identification-related behavior data and the risk assessment model, and determining the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data and the current R&D personnel behavior alarm data. In this solution, the operation behavior logs of the R&D personnel are collected from the R&D environment and the office environment, and the collected log formats are unified through cleaning processing, which is convenient for effectively associating the operation behaviors of the same R&D personnel, and the R&D operation behaviors are scored based on the risk assessment model, and the behavior events are redefined through the abnormal behavior detection engine, so as to reliably identify the abnormal situations in the R&D process from the two dimensions of R&D operation behaviors and behavior events, solve the problems of poor detection effect of abnormal operation behaviors for R&D personnel and failure to timely warn against abnormal behaviors, and can efficiently and accurately identify the abnormal operation behaviors of R&D personnel, and warn the abnormal operation behaviors of R&D personnel in real time.

[0110] Optionally, the log cleaning module 320 is used to parse the target log to be processed to obtain different account data and user operation object data under each user identity; based on the different account data and the user operation object data under each user identity, the target log to be processed is uniformly processed with respect to user identity identification and file object identification to obtain the identification-associated behavior data.

[0111] Optionally, the current event handling alarm data determination module 330 includes a behavior alarm data determination unit and an event handling alarm data determination unit. The behavior alarm data determination unit is used to extract the current user behavior characteristics in the identification-associated behavior data, and determine the current R&D stage corresponding to the identification-associated behavior data; query the stage adjustment factor according to the current R&D stage, and determine the current total risk score of the R&D personnel according to the current user behavior characteristics, the user behavior characteristic dimension weights, the stage adjustment factor, and the risk assessment model.

[0112] Optional, risk assessment model, including the following forms: R 总 =∑Stage k ·a k ·R k ; Among them, R 总 Indicates the total risk score of the current R&D personnel, Stage k represents the stage adjustment factor under the k-th user behavior feature dimension, a k represents the dimension weight under the k-th user behavior feature dimension, R kRepresents the behavioral risk score under the k-th user behavior feature dimension.

[0113] Optionally, an event handling alarm data determination unit is used to determine the current behavior event alarm level based on the identification-associated behavior data and the abnormal behavior detection engine; obtain an event alarm secondary analysis mapping table; and determine the current event handling alarm data based on the current behavior event alarm level, the current R&D personnel behavior alarm data, and the event alarm secondary analysis mapping table.

[0114] Optionally, an event handling alarm data determination unit is used to input the identification-associated behavior data into the abnormal behavior detection engine, perform abnormal behavior event identification on the identification-associated behavior data based on abnormal behavior event identification rules configured by the abnormal behavior detection engine, and generate the current behavior event alarm level when it is determined that an abnormal behavior event exists.

[0115] Optionally, the abnormal user behavior analysis device for R&D personnel further includes a data download module, which is used to call a target interface and download abnormal alarm related data when an abnormal alarm is triggered based on the current event handling alarm data.

[0116] The abnormal user behavior analysis device for R&D personnel provided in the embodiment of the present invention can execute the abnormal user behavior analysis method for R&D personnel provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0117] Embodiment 4

[0118] Figure 6 A schematic diagram of an electronic device that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0119] like Figure 6As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0120] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0121] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The processor 11 executes the various methods and processes described above, such as an abnormal user behavior analysis method for R&D personnel.

[0122] In some embodiments, the abnormal user behavior analysis method for R&D personnel may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the abnormal user behavior analysis method for R&D personnel described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the abnormal user behavior analysis method for R&D personnel in any other appropriate manner (e.g., by means of firmware).

[0123] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0124] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0125] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0126] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0127] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0128] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of traditional physical hosts and VPS servers, which are difficult to manage and have weak business scalability.

[0129] The embodiment of the present application also discloses a computer program product, which includes a computer program, and when the computer program is executed by a processor, the abnormal user behavior analysis method for R&D personnel provided in any embodiment of the present application is implemented. The program product and the abnormal user behavior analysis method for R&D personnel disclosed in each embodiment of the present application belong to the same inventive concept, so it is not repeated here.

[0130] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0131] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for analyzing abnormal user behavior for R&D personnel, characterized in that: include: Generate target logs to be processed based on the R&D environment behavior data and office environment behavior data of R&D personnel; Cleaning the target log to be processed to obtain identification-related behavior data; According to the identification-associated behavior data and the risk assessment model, current R&D personnel behavior alarm data is determined, and based on the abnormal behavior detection engine, the identification-associated behavior data and the current R&D personnel behavior alarm data, current event handling alarm data is determined.

2. The method according to claim 1, characterized in that Clean the target log to be processed to obtain identification-related behavior data, including: Parse the target log to be processed to obtain different account data under each user identity and user operation object data; According to the different account data under each of the user identities and the user operation object data, the target log to be processed is subjected to unified processing of user identity identification and file object identification to obtain the identification-associated behavior data.

3. The method according to claim 1, characterized in that According to the identification-related behavior data and the risk assessment model, the current R&D personnel behavior warning data is determined, including: Extracting current user behavior features from the identification-associated behavior data, and determining a current research and development stage corresponding to the identification-associated behavior data; Querying a stage adjustment factor according to the current R&D stage, and determining a total risk score of the current R&D personnel according to the current user behavior characteristics, the user behavior characteristic dimension weights, the stage adjustment factor, and the risk assessment model; According to the total risk score of the current developer, the behavior warning data of the current developer is determined.

4. The method according to claim 3, characterized in that Risk assessment models include the following: R 总 =∑Stage k ·a k ·R k ; Among them, R 总 Indicates the total risk score of the current R&D personnel, Stage k represents the stage adjustment factor under the k-th user behavior feature dimension, a k represents the dimension weight under the k-th user behavior feature dimension, R k Represents the behavioral risk score under the k-th user behavior feature dimension.

5. The method according to claim 1, characterized in that Based on the abnormal behavior detection engine, the identification-related behavior data, and the current R&D personnel behavior alarm data, current event handling alarm data is determined, including: Determine the current behavior event alarm level according to the identification-associated behavior data and the abnormal behavior detection engine; Get the event alarm secondary analysis mapping table; The current event handling alarm data is determined according to the current behavior event alarm level, the current R&D personnel behavior alarm data and the event alarm secondary analysis mapping table.

6. The method according to claim 5, characterized in that Determining the current behavior event alarm level according to the identification-associated behavior data and the abnormal behavior detection engine includes: The identification-associated behavior data is input into the abnormal behavior detection engine, abnormal behavior events are identified on the identification-associated behavior data based on abnormal behavior event identification rules configured by the abnormal behavior detection engine, and when it is determined that an abnormal behavior event exists, the current behavior event alarm level is generated.

7. The method according to claim 2, characterized in that After determining the current event handling alarm data based on the abnormal behavior detection engine, the identification-related behavior data, and the current R&D personnel behavior alarm data, the method further includes: When an abnormal alarm is triggered based on the current event handling alarm data, the target interface is called to download abnormal alarm related data.

8. An abnormal user behavior analysis device for R&D personnel, characterized in that: include: A target log generation module for processing is used to generate a target log based on the R&D environment behavior data and office environment behavior data of the R&D personnel. A log cleaning module, used to clean the target log to be processed and obtain identification-related behavior data; The current event handling alarm data determination module is used to determine the current R&D personnel behavior alarm data based on the identification-associated behavior data and the risk assessment model, and to determine the current event handling alarm data based on the abnormal behavior detection engine, the identification-associated behavior data and the current R&D personnel behavior alarm data.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the abnormal user behavior analysis method for R&D personnel described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the abnormal user behavior analysis method for R&D personnel described in any one of claims 1 to 7 when executed.