Abnormal path analysis method and device, equipment, storage medium and product

By identifying sensitive data types and generating sensitive path mapping, combining the improved algorithm to determine abnormal nodes and analyze abnormal paths, the problem of lack of sensitive data flow analysis in the existing technology is solved, and higher data flow security and automated analysis capabilities are achieved.

CN120128394APending Publication Date: 2025-06-10CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510320746.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The prior art lacks circulation analysis for sensitive data in data circulation path analysis, resulting in low data circulation security.

Method used

By identifying sensitive data types and sensitivity levels, sensitive path mappings are generated and transmission risk values ​​are calculated based on sensitive data types, number of transmissions, and transmission time. The improved node-to-vector algorithm, jump model algorithm and deep anomaly detection model based on attribute network are used to determine the abnormal node and analyze the abnormal path.

Benefits of technology

Effectively capture the complex relationship between the transmission sensitive data between nodes and edges in the graph structure, improve the security of data flow, can automatically learn features and rules, without manual intervention, and have good interpretability and visualization capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128394A_ABST
    Figure CN120128394A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal path analysis method and device, equipment, a storage medium and a product, and relates to the technical field of data security, and the method comprises the steps: generating a sensitive path plot according to a sensitive data type and a sensitivity level, calculating a transmission risk value of each edge in the plot, and obtaining a transmission risk value of each edge in the plot; and according to the improved node-to-vector algorithm, the jump model algorithm and the improved depth anomaly detection model based on the attribute network, determining abnormal nodes in the sensitive path surveying and mapping graph, and analyzing the abnormal nodes to obtain an abnormal path. Therefore, the complex relation of transmission sensitive data between the nodes and the edges in the graphic structure can be effectively captured, node risk characteristics and path risk characteristics of data circulation can be more accurately understood, and the method can adapt to data circulation structures of different scales and types. According to the method, manual intervention is not needed, various aspects of data flow can be analyzed more comprehensively, abnormal paths and potential security threats can be found better, and the security of data flow is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular, to an abnormal path analysis method, device, equipment, storage medium and product. Background Art

[0002] With the deepening of digital transformation, the network applications within enterprises have become increasingly complex, the network distribution has become more extensive, the number of terminal devices has become increasingly large, and the number of business application systems has become more and more. All of the above have led to an increasing number of endpoints through which enterprise data flows, and the risk of data leakage has been increasing. How to track the data flow process, discover and predict data leakage behavior during the data flow has become an important issue faced in the current enterprise data security governance construction.

[0003] Data flow path analysis tools and technologies have become increasingly mature and diversified. From traditional network traffic analysis tools to advanced behavior analysis systems, and threat detection solutions based on artificial intelligence and machine learning, security vendors have continuously launched new products and services to meet the ever-changing network security needs. Secondly, with the continuous evolution of network attack technologies, the importance of data flow path analysis in network security defense has become increasingly prominent. By deeply analyzing the path and behavior of data flows, potential threats and abnormal activities can be quickly identified, and the detection and response speed of network security events can be improved. However, although the existing common traffic analysis methods can solve the problem of discovering abnormal traffic, they lack the analysis of the flow of sensitive data, resulting in the technical problem of low security of data flow. Summary of the Invention

[0004] The main purpose of this application is to provide an abnormal path analysis method, device, equipment, storage medium and product, aiming to solve the technical problem that the existing flow methods lack the analysis of the flow of sensitive data, resulting in low security of data flow.

[0005] To achieve the above object, this application proposes an abnormal path analysis method, and the method includes:

[0006] Identify the collected raw data to obtain sensitive data types and sensitivity levels;

[0007] Generate a sensitive path mapping diagram according to the sensitive data types and the sensitivity levels, where the nodes in the sensitive path mapping diagram represent the associated components corresponding to the sensitive data, and the edges in the sensitive path mapping diagram represent the sensitive data types, transmission times and transmission times for transmission between nodes;

[0008] Determine the transmission risk value according to the sensitive data type, the transmission times and the transmission time, and add the transmission risk value as an attribute to the edge;

[0009] Determine the abnormal nodes in the sensitive path mapping diagram according to the improved node2vec algorithm, the skip model algorithm, and the improved deep anomaly detection model based on the attribute network;

[0010] Analyze the abnormal nodes in the sensitive path mapping diagram to obtain the abnormal paths in the sensitive path mapping diagram.

[0011] In one embodiment, the step of determining the transmission risk value according to the sensitive data type, the number of transmissions, and the transmission time includes:

[0012] Determine the sensitive data type weight of the sensitive data type according to the sensitivity level;

[0013] Determine the transmission times weight of the sensitive data type according to the number of transmissions;

[0014] Determine the transmission time weight of the sensitive data type according to the transmission time;

[0015] Determine the transmission risk value according to the sensitive data type weight, the transmission times weight, the transmission time weight, the time decay function, and the time interval from the last sensitive data transmission to the current time.

[0016] In one embodiment, in the improved node2vec algorithm, the transmission risk value and the node transmission important core sensitive data risk value are used as parameters for random walk probability control, and in the improved deep anomaly detection model based on the attribute network, the process of generating nodes by the attribute network encoder is replaced with the improved node2vec algorithm;

[0017] The step of determining the abnormal nodes in the sensitive path mapping diagram according to the improved node2vec algorithm, the skip model algorithm, and the improved deep anomaly detection model based on the attribute network includes:

[0018] Perform random walk in the sensitive path mapping diagram according to the improved node2vec algorithm to generate multiple random walk paths;

[0019] Input the multiple random walk paths into the skip model algorithm for node representation learning, and output the vector representation of each random walk path;

[0020] Determine the abnormal nodes in the sensitive path mapping diagram through the improved deep anomaly detection model based on the attribute network according to the vector representation of each random walk path.

[0021] In one embodiment, the step of performing random walk in the sensitive path mapping diagram according to the improved node2vec algorithm to generate multiple random walk paths includes:

[0022] Based on the improved node2vec algorithm, determine the proportion of the transmission risk value between the target node and the next-hop node in the sensitive path mapping graph, where the transmission risk value is between the target node and the next-hop node, and between the next-hop node and the neighbor node corresponding to the next-hop node.

[0023] Normalize the number of times important core sensitive data has been transmitted between the target node and the next-hop node and the number of times the important core sensitive data has been transmitted between the next-hop node and the neighbor node to obtain the node transmission risk value of important core sensitive data.

[0024] Determine the probability expression controlled by random walk according to the distance between the target node and the next-hop node and the random walk parameter.

[0025] Determine the probability value of jumping from the target node to the next-hop node according to the proportion of the transmission risk value, the node transmission risk value of important core sensitive data, and the probability expression, and generate multiple random walk paths according to the probability value.

[0026] In one embodiment, the step of inputting the multiple random walk paths into the skip model algorithm for node representation learning and outputting the vector representation of each random walk path includes:

[0027] Input the multiple random walk paths into the skip model algorithm, and the skip model algorithm represents the multiple random walk paths through one-hot encoding to obtain an encoding matrix.

[0028] Map the encoding matrix to a low-dimensional space with a preset dimension according to the index mapping.

[0029] Use the initialization matrix corresponding to the low-dimensional space with a preset dimension as the weight matrix. Take each node in the encoding matrix as the central node in turn, and update the vector representation of the central node in the weight matrix by maximizing the probability of the central node to obtain the vector representation of each random walk path.

[0030] In one embodiment, the step of determining the abnormal nodes in the sensitive path mapping graph according to the vector representation of each random walk path by the improved deep anomaly detection model based on the attribute network includes:

[0031] Reconstruct the adjacency matrix according to the vector representation of each random walk path by the structure reconstruction decoder in the improved deep anomaly detection model based on the attribute network.

[0032] The reconstructed node vectors are determined by the attribute reconstruction decoder;

[0033] According to the adjacency matrix, the reconstructed node vectors, the error weight parameters corresponding to the reconstructed node vectors, and the vector representation, the reconstruction error is determined;

[0034] According to the reconstruction error, the abnormal nodes in the sensitive path mapping graph are determined.

[0035] In addition, to achieve the above object, the present application also proposes an abnormal path analysis device, which includes:

[0036] A sensitive data recognition module, configured to recognize the collected original data to obtain the sensitive data type and the sensitivity level;

[0037] A sensitive path graph generation module, configured to generate a sensitive path mapping graph according to the sensitive data type and the sensitivity level, where the nodes in the sensitive path mapping graph represent the associated components corresponding to the sensitive data, and the edges in the sensitive path mapping graph represent the sensitive data type, the transmission times, and the transmission time for transmission between nodes;

[0038] A transmission risk value determination module, configured to determine a transmission risk value according to the sensitive data type, the transmission times, and the transmission time, and add the transmission risk value as an attribute to the edge;

[0039] An abnormal node determination module, configured to determine the abnormal nodes in the sensitive path mapping graph according to the improved node-to-vector algorithm, the skip model algorithm, and the improved deep anomaly detection model based on the attribute network;

[0040] An abnormal path analysis module, configured to analyze the abnormal nodes in the sensitive path mapping graph to obtain the abnormal paths in the sensitive path mapping graph.

[0041] In addition, to achieve the above object, the present application also proposes an abnormal path analysis device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the computer program is configured to implement the steps of the abnormal path analysis method as described above.

[0042] In addition, to achieve the above object, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the abnormal path analysis method as described above are implemented.

[0043] In addition, to achieve the above object, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the abnormal path analysis method described above.

[0044] The present application provides an abnormal path analysis method. By generating a sensitive path mapping diagram according to the sensitive data type and sensitivity level, calculating the transmission risk value of each edge in the diagram according to the sensitive data type, transmission times, and transmission time, determining the abnormal nodes in the sensitive path mapping diagram according to the improved node2vec algorithm, jump model algorithm, and improved deep anomaly detection model based on attribute network, and analyzing the abnormal nodes in the sensitive path mapping diagram, the abnormal path in the sensitive path mapping diagram is obtained. Thus, it can effectively capture the complex relationship of transmitting sensitive data between nodes and edges in the graph structure, more accurately understand the node risk characteristics and path risk characteristics of data flow, has high flexibility and scalability, and can adapt to data flow structures of different scales and types. It can automatically learn features and rules without manual intervention, can more comprehensively analyze all aspects of data flow, thereby better discovering abnormal paths and potential security threats, has good interpretability and visualization capabilities, can intuitively display abnormal paths and related sensitive data flow conditions, and improve the security of data flow. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0046] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0047] Figure 1 It is a schematic flowchart provided for Embodiment 1 of the abnormal path analysis method of the present application;

[0048] Figure 2 It is an example diagram of the sensitive path mapping diagram in the abnormal path analysis method of the present application;

[0049] Figure 3 It is a schematic flowchart provided for Embodiment 2 of the abnormal path analysis method of the present application;

[0050] Figure 4 It is a schematic module structure diagram of the abnormal path analysis device in the embodiment of the present application;

[0051] Figure 5This is a schematic diagram of the device structure of the hardware operating environment involved in the abnormal path analysis method in the embodiments of the present application.

[0052] The implementation, functional features, and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners

[0053] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0054] To better understand the technical solutions of the present application, the following will be described in detail with reference to the accompanying drawings of the specification and specific implementation manners.

[0055] The main solution of the embodiments of the present application is: identifying the collected raw data to obtain sensitive data types and sensitivity levels; generating a sensitive path mapping diagram according to the sensitive data types and the sensitivity levels, where the nodes in the sensitive path mapping diagram represent the associated components corresponding to the sensitive data, and the edges in the sensitive path mapping diagram represent the sensitive data types, transmission times, and transmission times for transmission between the nodes; determining a transmission risk value according to the sensitive data type, the transmission times, and the transmission time, and adding the transmission risk value as an attribute to the edge; determining abnormal nodes in the sensitive path mapping diagram according to the improved node2vec algorithm, the skip-gram model algorithm, and the improved deep anomaly detection model based on an attribute network; analyzing the abnormal nodes in the sensitive path mapping diagram to obtain abnormal paths in the sensitive path mapping diagram.

[0056] Since the existing technologies for analyzing the data flow transfer path are becoming increasingly mature and diverse. From traditional network traffic analysis tools to advanced behavior analysis systems, and threat detection solutions based on artificial intelligence and machine learning, security vendors are constantly launching new products and services to meet the ever-changing network security requirements. Secondly, with the continuous evolution of network attack technologies, the importance of data flow transfer path analysis in network security defense has become increasingly prominent. By deeply analyzing the path and behavior of the data flow, potential threats and abnormal activities can be quickly identified, and the detection and response speed of network security events can be improved. However, the existing commonly used traffic analysis methods, although they can solve the problem of detecting abnormal traffic, lack the analysis of the transfer of sensitive data, resulting in the technical problem of low security of data transfer.

[0057] The present application provides a solution. By generating a sensitive path mapping diagram according to the sensitive data type and sensitivity level, calculating the transmission risk value of each edge in the diagram based on the sensitive data type, transmission times, and transmission time, determining the abnormal nodes in the sensitive path mapping diagram according to the improved node-to-vector algorithm, skip model algorithm, and improved deep anomaly detection model based on attribute network, and analyzing the abnormal nodes in the sensitive path mapping diagram to obtain the abnormal paths in the sensitive path mapping diagram. Thus, it can effectively capture the complex relationship of transmitting sensitive data between nodes and edges in the graph structure, more accurately understand the node risk characteristics and path risk characteristics of data flow, has high flexibility and scalability, and can adapt to data flow structures of different scales and types. It can automatically learn features and rules without manual intervention, can more comprehensively analyze all aspects of data flow, thus better discovering abnormal paths and potential security threats, has good interpretability and visualization capabilities, can intuitively display abnormal paths and related sensitive data flow conditions, and improve the security of data flow.

[0058] It should be noted that the execution subject of the method in this embodiment can be a computing service device with functions such as abnormal path analysis, network communication, and program operation, such as a tablet computer, a personal computer, a mobile phone, etc.; it can also be an abnormal path analysis device with the same or similar functions. This embodiment and the following embodiments will be described by taking the abnormal path analysis device as an example.

[0059] Based on this, the embodiment of the present application provides an abnormal path analysis method, referring to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the abnormal path analysis method of the present application.

[0060] In this embodiment, the abnormal path analysis method includes steps S10 to S50:

[0061] Step S10, identify the collected raw data to obtain the sensitive data type and sensitivity level.

[0062] It can be understood that various types of logs generated during the data flow process can be collected, including operations of application systems involving sensitive data, operations of system resources containing sensitive data, traffic data, and operations of terminal operation logs containing sensitive data. It is necessary to perform various conversions, cleaning, and data processing on the received data to unify the data format. Regular expressions, keyword matching, and the fastText method of classification algorithms can be used to identify sensitive data in the collected data and identify sensitive data types, such as data types such as ID cards, telephone numbers, bank card numbers, and Internet Protocol Address (IP address).

[0063] It should be understood that the identified sensitive data can also be classified and graded. According to the sensitivity and importance of the data, the data is divided into different levels or categories. The specific method is as follows: According to the provided industry classification and grading specifications, the identified sensitive data is associated, and the sensitive data is divided into 4 categories. Among them, types such as business order class and violation record data are of low sensitivity level, types such as device information, device identification, and bill-related are of relatively high sensitivity level, types such as natural person identity identification, network identity identification, user basic information, contact information, service content data, and location data are of high sensitivity level, and types such as entity identity proof and user private information are of extremely high sensitivity level.

[0064] Step S20: Generate a sensitive path mapping graph according to the sensitive data type and the sensitivity level. The nodes in the sensitive path mapping graph represent the associated components corresponding to the sensitive data, and the edges in the sensitive path mapping graph represent the sensitive data type, the number of transmissions, and the transmission time for the transmission between the nodes.

[0065] It can be understood that based on the sorted data, it is necessary to determine the scope of sensitive data for which path mapping is to be performed, including data type, source, associated devices, etc. The sensitive data types of concern can be screened according to the classification and grading of sensitive data, the files containing sensitive data can be screened out, and the MD5 values of these files are associated with the Message Digest Algorithm 5 (MD5) values in the file message digest in the file transfer log to form a sensitive file transfer path. Log information with sensitive data transmission is screened out from the Application Programming Interface (API) data, application system operation logs, and system resource operation logs. The above two types of paths (sensitive file transfer path and log information with sensitive data transmission) form a graphical structure. The nodes represent devices, APIs, etc. related to sensitive data. The source device, target device, used account information, etc. are classified from the sorted data and can be divided into associated components according to the actual situation. The associated components can include account nodes, device nodes (including terminals (Personal Computer, PC), databases, applications, etc.), API nodes, etc.; the edges represent that sensitive data is transmitted between the nodes, and record the sensitive data type, the number of transmissions, and the transmission time. The constructed sensitive path mapping graph can be referred to Figure 2 as shown.

[0066] Step S30: Determine the transmission risk value according to the sensitive data type, the number of transmissions, and the transmission time, and add the transmission risk value as an attribute to the edge.

[0067] It can be understood that the calculation process of the sensitive data transmission risk value is described here. This method calculates the sensitive data transmission risk value based on the sensitive data type, the number of transmissions, and the time of sensitive data transmission, and uses it as an attribute of the edge to measure the risks of different transmission paths. Its advantage is that it comprehensively depicts the risks of sensitive paths from multiple perspectives, and different weights are assigned to different perspectives, making the calculation more focused and more in line with the actual situation. The time factor is considered. On the one hand, the size of the transfer risk value changes with time. On the other hand, for paths where sensitive data has not been transmitted for a long time, the risk value will decrease.

[0068] In a feasible implementation manner, step S30 may include steps S301 to S304:

[0069] Step S301, determine the sensitive data type weight of the sensitive data type according to the sensitivity level.

[0070] It can be understood that the sensitive data type weight of the sensitive data type can be determined according to the sensitivity level. For different types of sensitive data, different weight values can be assigned to them. For example, the weight of the extremely sensitive level type can be set to 4, the weight of the sensitive level type can be set to 3, the weight of the relatively sensitive level type can be set to 2, and the weight of the low sensitive level type can be set to 1.

[0071] Step S302, determine the transmission times weight of the sensitive data type according to the number of transmissions.

[0072] It should be understood that the transmission times weight of the sensitive data type can be determined according to the number of transmissions. For the number of transmissions of sensitive data, weighted processing can be considered. The more the number of transmissions, the higher the possibility of sensitive data exposure. Therefore, the number of transmissions can be used as a factor of the risk value.

[0073] Step S303, determine the transmission time weight of the sensitive data type according to the transmission time.

[0074] It should be understood that the transmission time weight of the sensitive data type can be determined according to the transmission time. For the transmission time of sensitive data, weighted processing can be considered. Transmitting sensitive data during certain time periods or time points may increase the risk. For example, transmitting sensitive data during non-working hours or when the system has a low load may be more easily exploited by attackers. Therefore, different weights are set for working hours and non-working hours respectively. The weight for working hours is 0.2 or 0.3, and the weight for non-working hours is 0.8 or 0.7.

[0075] Step S304, determine the transmission risk value according to the sensitive data type weight, the transmission times weight, the transmission time weight, the time decay function, and the time interval from the most recent sensitive data transmission to the current time.

[0076] It is understandable that the transmission risk value can be calculated by the following formula:

[0077] F = (p 1 W 1 T 1 + p 2 W 2 T 2 + p 3 W 3 T 3 +... + p n W n T n ) * e -λt

[0078] = e -λt ∑P i W i T i (i = 1, 2, 3, 4,..., n)

[0079] In the formula, F represents the transmission risk value of sensitive data transmitted along a certain path, W i is the weight of the sensitive data type, T i represents the weight of the transmission time, P i represents the transmission frequency weight of the i-th path at T i , and e -λt is the time decay function, and t is the time interval from the time of the most recent transmission of sensitive data to the present (for example, it can be the number of months or years).

[0080] It is understandable that by integrating the classified sensitive data, the transmission risk value is further calculated. The calculation of this risk value can effectively and accurately evaluate the path risk during the transmission of sensitive data. If sensitive data with a high sensitivity level has been transmitted recently and the transmission is more frequent, and there are more transmissions during non-working hours, the transmission risk value will be relatively high. This calculation method can better quantify the paths with a higher transmission risk value of sensitive data in the traffic data.

[0081] In this embodiment, by calculating the transmission risk value of sensitive data based on the sensitive data type, transmission frequency, and the time of sensitive data transmission, and using it as the attribute of the edge to measure the risks of different transmission paths. Its advantage is that it comprehensively depicts the risks of sensitive paths from multiple perspectives, and different weights are assigned to different perspectives, making the calculation more focused and more in line with the actual situation. The time factor is taken into account. On the one hand, the size of the transfer risk value changes with time. On the other hand, for paths where sensitive data has not been transmitted for a long time, the risk value will decrease.

[0082] Step S40: Determine the abnormal nodes in the sensitive path mapping graph according to the improved node2vec algorithm, skip-gram model algorithm, and the improved deep anomaly detection model based on the attributed network.

[0083] It can be understood that, based on the processing of the obtained data and the calculation of the risk value, the improved node2vec algorithm is then used to improve and optimize the generation of node vectors. Random walks are performed on the graph structure composed of items to generate a large number of item sequences, and then these item sequences are used as training samples and input into the word2vec algorithm for training to obtain the vector representation of the items. According to the obtained multiple node sequences, each sequence represents a random walk path, that is, the output result of the random walk sequence in the previous step. The skip-gram model of the skip-gram model algorithm is used to learn the node representation. Finally, anomaly detection will be carried out next. According to the improved deep anomaly detection (DOMINANT) model based on the training of sensitive data transfer sample data, the abnormal nodes in the sensitive path mapping graph are then detected based on this model.

[0084] Step S50: Analyze the abnormal nodes in the sensitive path mapping graph to obtain the abnormal paths in the sensitive path mapping graph.

[0085] It can be understood that according to the above steps, the abnormal nodes are obtained and can be displayed using a graph. Further analysis can obtain the abnormal paths. By taking the top-K (K can be defined by oneself) of the reverse reconstruction error, it is judged whether the path is abnormal and the number of abnormalities is reduced. The abnormal display can rely on the graph database to intuitively and clearly display the abnormal nodes and their related transmission paths. Through the above steps, the sensitive data transmission data generated in the traffic data and log data is fully mined for abnormal transmission paths from two aspects: the sensitive data transmission risk value and the nodes transmitting important core sensitive data, and the interference caused by some common and non-key sensitive data such as IP addresses, Chinese addresses, unified social credit codes, etc. is effectively avoided, so as to discover the abnormal transmission paths and abnormal nodes in the circulation.

[0086] This embodiment provides an abnormal path analysis method. By generating a sensitive path mapping diagram according to the sensitive data type and sensitivity level, calculating the transmission risk value of each edge in the diagram according to the sensitive data type, transmission times, and transmission time, determining the abnormal nodes in the sensitive path mapping diagram according to the improved node2vec algorithm, jump model algorithm, and improved deep anomaly detection model based on the attribute network, and analyzing the abnormal nodes in the sensitive path mapping diagram, the abnormal path in the sensitive path mapping diagram is obtained. Thus, it can effectively capture the complex relationship of transmitting sensitive data between nodes and edges in the graph structure, more accurately understand the node risk characteristics and path risk characteristics of data flow, has high flexibility and scalability, and can adapt to data flow structures of different scales and types. It can automatically learn features and rules without manual intervention, can more comprehensively analyze all aspects of data flow, thus better discovering abnormal paths and potential security threats, has good interpretability and visualization capabilities, can intuitively display abnormal paths and related sensitive data flow conditions, and improve the security of data flow.

[0087] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 3 , in the improved node2vec algorithm, the transmission risk value and the node transmission important core sensitive data risk value are used as parameters to control the random walk probability, and in the improved deep anomaly detection model based on the attribute network, the process of generating nodes by the attribute network encoder is replaced with the improved node2vec algorithm; step S40, the abnormal path analysis method further includes steps S401 to S403:

[0088] Step S401, perform random walks in the sensitive path mapping diagram according to the improved node2vec algorithm to generate multiple random walk paths.

[0089] It can be understood that in this embodiment, the generation of node vectors is improved and optimized through the improved Node2vec algorithm. By introducing the parameter transmission risk value and the risk value of the node transmitting important core sensitive data to be jumped to, the random walk probability is controlled, and random walks are performed in the sensitive path mapping diagram to generate multiple random walk paths, so that the result of graph embedding better adapts to different sensitive data flow scenarios.

[0090] In a feasible implementation manner, step S401 may include steps S4011 to S4014:

[0091] Step S4011: Determine the proportion of the transmission risk value between the target node and the next-hop node in the sensitive path mapping graph according to the transmission risk value between the target node and the next-hop node and the transmission risk value between the next-hop node and the neighbor node corresponding to the next-hop node through the improved node-to-vector algorithm.

[0092] It can be understood that if we want to calculate the probability value of the target node v in the sensitive path mapping graph jumping to the next node x, we can first calculate the proportion of the transmission risk value w corresponding to the edge vx between node v and node x. νx , and the formula is as follows:

[0093]

[0094] Among them, F vx represents the sensitive data transmission risk value of edge vx, and F xy represents the sensitive data transmission risk value of edge xy, where y is the neighbor node adjacent to x.

[0095] Step S4012: Normalize the number of times important core sensitive data has been transmitted between the target node and the next-hop node and the number of times important core sensitive data has been transmitted between the next-hop node and the neighbor node to obtain the risk value of the node transmitting important core sensitive data.

[0096] It should be understood that the risk value p of the node transmitting important core sensitive data can be calculated through the following formula x :

[0097]

[0098] Among them, k xv is the number of times important core data has been transmitted through edge vx, and k xy is the number of edges that have transmitted important core data with node x, and normalization processing is added. This value mainly measures the risk value of node x transmitting important core data. Since important core data is a more concerned sensitive data type in data flow, this embodiment fully considers the impact brought by this type of sensitive data during calculation.

[0099] Step S4013: Determine the probability expression controlled by random walk probability according to the distance between the target node and the next-hop node and the random walk parameter.

[0100] It should be understood that the probability expression controlled by random walk probability can be calculated through the following formula:

[0101]

[0102] Among them, αpq (v, x) is the probability expression that controls whether the node migration tends to depth - first search (DFS) or breadth - first search (BFS), and d vx refers to the distance from node v to node x, and the parameters p and q jointly control the tendency of random walk.

[0103] Step S4014, determine the probability value of jumping from the target node to the next - hop node according to the proportion of the transmission risk value, the risk value of the node transmitting important core sensitive data, and the probability expression, and generate multiple random - walk paths according to the probability value.

[0104] It can be understood that the probability value of jumping from node v to the next node x is calculated by the following formula:

[0105] π νx = α pq (v, x)·w νx ·p x .

[0106] It can be understood that after calculating the probability value, the probability value determines the walk path and affects the sequence generation. During the random walk process, the probability of each node jumping to the next node is calculated by a specific formula. This probability value determines the choice of the walk path, that is, which neighbor node the current node is more likely to jump to. Since each node's jump is based on the probability value, different jump probabilities will generate different multiple random - walk paths.

[0107] In this embodiment, by introducing a risk value, the characteristics of sensitive data transmission of a node can be better reflected when representing the node. And since the risk value evaluates the path well, the propagation relationship of sensitive risks between upstream and downstream nodes is better described when generating the vector of the node. The improved method proposed in this solution not only considers the features of the edges, but also adds the node risk features during the process of sensitive data flow. This approach increases the original generalization ability of the algorithm. On the one hand, for the data flow scenario proposed in this solution, there is still a broad application space. For example, abnormal features in the behavior of nodes can be considered, such as baseline deviation, abnormal operations, the overall deviation of the behavior sequence, etc. from multiple dimensions, or vulnerability risks in the network attack scenario. Different calculation methods can be modified according to the focus of different scenarios, greatly improving the adaptability of the algorithm. On the other hand, according to the business scenario, the node feature method can be replaced with that of different corresponding business scenarios, making this algorithm not only applicable to the field of data security, but also having a broad application prospect in other fields. The advantages of doing so are significantly superior to adding the similarity of the two basic attributes of nodes, which are reflected in that the media for sensitive data transmission is diverse, that is, the attributes of the transmission media themselves vary greatly; and the proportion of first-order paths for directly abnormally transmitting sensitive data is very small, and many abnormal paths are hidden in the huge path network. Therefore, the abnormal risk value of the peer node is added in this solution. As the path deepens, even risk nodes far from this node still have an impact on it, which is reflected in the generated vector results. The above two aspects of improvements are considered from the aspects of nodes and edges to achieve the role of comprehensively depicting node information.

[0108] Step S402: Input the multiple random walk paths into a skip-gram model algorithm for node representation learning, and output the vector representation of each random walk path.

[0109] It can be understood that according to the obtained multiple node sequences, each sequence represents a random walk path, that is, the random walk sequence result output in the previous step. The skip-gram model of the skip-gram model algorithm is used to learn the node representation. The skip-gram model is a classic algorithm for learning word vectors. It learns word vectors by predicting the context words around a given center word. In this way, each path is represented in the form of a vector.

[0110] In a feasible embodiment, step S402 may include steps S4021 to S4023:

[0111] Step S4021: Input the multiple random walk paths into the skip-gram model algorithm. The skip-gram model algorithm represents the multiple random walk paths through one-hot encoding to obtain an encoding matrix.

[0112] It can be understood that one-hot encoding can be used to represent the random walk sequence. Each node forms a V×1 vector, and for the entire set of nodes, it is a V×V encoding matrix.

[0113] Step S4022, map the encoding matrix into a low-dimensional space of a preset dimension according to the index mapping.

[0114] It should be understood that each node can be mapped into a d-dimensional space according to the index mapping. "d" generally refers to the number of dimensions of the space. This vector space is low-dimensional and is usually much smaller than the dimension of the original data space. "d" can be determined according to the requirements of the actual application and the selected graph embedding algorithm. In this way, all nodes can be mapped onto matrix W (the shape of matrix W is V×d), and each node corresponds one-to-one with a certain column in the matrix.

[0115] Step S4023, use the initialization matrix corresponding to the low-dimensional space of the preset dimension as the weight matrix. Successively take each node in the encoding matrix as the central node, and update the vector representation of the central node in the weight matrix by maximizing the probability of the central node, so as to obtain the vector representation of each random walk path.

[0116] It should be understood that model training is carried out here. Initialize a matrix in the d-dimensional space as the weight matrix, and the shape of this matrix is V×d. Successively take each node in the encoding matrix as the central node, and update the vector representation of the central node in the weight matrix by maximizing the probability of the central node. Repeat the execution until all nodes are trained, so as to obtain the vector representation of each random walk path.

[0117] In this embodiment, according to the obtained multiple random walk paths, the skip-gram model algorithm is used to learn the node representation. The Skip-gram model is a classic algorithm for learning word vectors. It learns word vectors by predicting the context words around a given central word. Thus, each path is represented in the form of a vector.

[0118] Step S403, determine the abnormal nodes in the sensitive path mapping graph according to the vector representation of each random walk path through the improved deep anomaly detection model based on the attribute network.

[0119] It can be understood that anomaly detection will be performed here, and an improved DOMINANT model is trained based on the sample data of sensitive data flow for processing. It is an autoencoder network with graph convolutional layers, and its reconstruction error will be the node anomaly score. The process of generating nodes by the attribute network encoder is replaced by the improved Node2Vec algorithm described above. On the one hand, this makes it better to extract the features of the network for the representation of nodes, and secondly, it can improve the generalization ability of the entire model. By adjusting the model parameters, the model can adapt to more data flow application scenarios. The improved DOMINANT model can be used to determine the abnormal nodes in the sensitive path mapping diagram according to the vector representation of each random walk path.

[0120] In a feasible implementation manner, step S403 may include steps S4031 to S4034:

[0121] Step S4031, reconstruct the adjacency matrix according to the vector representation of each random walk path through the structure reconstruction decoder in the improved deep anomaly detection model based on the attribute network.

[0122] It can be understood that the structure reconstruction decoder in the model uses the vector representation learned by the improved Node2vec above to reconstruct the original graph edges (i.e., the adjacency matrix). It calculates the dot product of node embeddings from each possible node pair and creates a probability score representing the existence of an edge on each node pair. When reconstructing, the method for determining whether there is a link between node i and node j in the original graph is as follows:

[0123]

[0124] where z i is the vector of node i, and z j is the vector of node j. To determine the similarity of the two vectors in space, that is, perform an inner product operation on the two vectors. If they are in the same direction, the value is the largest. Then use the sigmoid function to control the dimension within [0,1]. The value obtained in this way can also be directly used as a probability. Applied to the matrix, it is:

[0125] Step S4032, determine the reconstructed node vectors through the attribute reconstruction decoder.

[0126] It can be understood that the attribute reconstruction decoder in the model uses another graph convolutional layer to predict the original node vectors and finally outputs the reconstructed node vectors.

[0127] Step S4033, determine the reconstruction error according to the adjacency matrix, the reconstructed node vectors, the error weight parameters corresponding to the reconstructed node vectors, and the vector representation.

[0128] It is understandable that the reconstruction error can be calculated by the following formula:

[0129]

[0130] where A represents the adjacency matrix, represents the matrix after being calculated by the sigmoid function in step S4031, X represents the vector representation of node2vec, represents the reconstructed node vector. α represents the error weight parameter of the reconstructed node vector.

[0131] Step S4034, determine the abnormal nodes in the sensitive path mapping diagram according to the reconstruction error.

[0132] It is understandable that an adjacency matrix A is generated according to the sensitive path mapping diagram. If there is a relationship between nodes v i , v i , then A i,j = 0. Substitute the node vector calculated in the previous step into the above neural network model DOMINANT model, reconstruct the nodes, and calculate the reconstruction error of the nodes. This process mainly improves the auto-encoding process of the DOMINANT model, uses the improved Node2Vec combined with skip-gram to generate the node vector. This method optimizes the representation of the nodes and makes full use of the relevant effective features in the business scenario. Calculate the reconstruction error. Data instances with larger reconstruction errors are more likely to be identified as abnormal because their patterns significantly deviate from most of the data and cannot be fully expressed through accurate data reconstruction.

[0133] In this embodiment, the auto-encoding process of the DOMINANT model is improved, and the improved Node2Vec combined with skip-gram is used to generate the node vector. This method optimizes the representation of the nodes and makes full use of the relevant effective features in the business scenario. Calculate the reconstruction error. Data instances with larger reconstruction errors are more likely to be identified as abnormal because their patterns significantly deviate from most of the data and cannot be fully expressed through accurate data reconstruction.

[0134] In this embodiment, the improved Node2vec algorithm is used to perform random walks on the graph structure composed of items, generating a large number of item sequences. Then these item sequences are used as training samples to be input into word2vec for training to obtain the vector representation of the items. Then, based on the improved deep anomaly detection model based on the attribute network, the features of the network can be better extracted, and again, the generalization ability of the entire model can be improved. By adjusting the model parameters, the model can be adapted to more data transfer application scenarios.

[0135] It should be noted that the above examples are only for understanding this application and do not limit the abnormal path analysis method of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.

[0136] This application also provides an abnormal path analysis device. Please refer to Figure 4 , the abnormal path analysis device includes:

[0137] A sensitive data recognition module 10, configured to recognize the collected original data to obtain the sensitive data type and the sensitivity level;

[0138] A sensitive path map generation module 20, configured to generate a sensitive path mapping diagram according to the sensitive data type and the sensitivity level. The nodes in the sensitive path mapping diagram represent the associated components corresponding to the sensitive data, and the edges in the sensitive path mapping diagram represent the sensitive data type, the number of transmissions, and the transmission time for transmission between the nodes;

[0139] A transmission risk value determination module 30, configured to determine a transmission risk value according to the sensitive data type, the number of transmissions, and the transmission time, and add the transmission risk value as an attribute to the edge;

[0140] An abnormal node determination module 40, configured to determine the abnormal nodes in the sensitive path mapping diagram according to the improved node2vec algorithm, the skip-gram model algorithm, and the improved deep anomaly detection model based on the attribute network;

[0141] An abnormal path analysis module 50, configured to analyze the abnormal nodes in the sensitive path mapping diagram to obtain the abnormal paths in the sensitive path mapping diagram.

[0142] The abnormal path analysis device provided by this application adopts the abnormal path analysis method in the above embodiment and can solve technical problems. Compared with the prior art, the beneficial effects of the abnormal path analysis device provided by this application are the same as those of the abnormal path analysis method provided by the above embodiment, and other technical features in the abnormal path analysis device are the same as those disclosed in the method of the above embodiment, which will not be elaborated here.

[0143] This application provides an abnormal path analysis device. The abnormal path analysis device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the abnormal path analysis method in the first embodiment above.

[0144] Next, refer to Figure 5, which shows a schematic structural diagram of an abnormal path analysis device suitable for implementing the embodiments of the present application. The abnormal path analysis device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description: tablet computers), PMPs (Portable Media Player), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The shown abnormal path analysis device is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0145] As Figure 5 shown, the abnormal path analysis device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the abnormal path analysis device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the abnormal path analysis device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an abnormal path analysis device with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be alternatively implemented or had.

[0146] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.

[0147] The abnormal path analysis device provided by the present application adopts the abnormal path analysis method in the above embodiments and can solve the technical problems of abnormal path analysis. Compared with the prior art, the beneficial effects of the abnormal path analysis device provided by the present application are the same as those of the abnormal path analysis method provided by the above embodiments, and other technical features in the abnormal path analysis device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated herein.

[0148] It should be understood that each part disclosed in the present application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0149] As described above, only the specific embodiments of the present application are provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0150] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the abnormal path analysis method in the above embodiments.

[0151] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0152] The above computer-readable storage medium can be included in the abnormal path analysis device; or it can exist separately and not be assembled into the abnormal path analysis device.

[0153] The computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0154] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0155] The modules involved in the embodiments described in the present application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.

[0156] The readable storage medium provided in the present application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned abnormal path analysis method, which can solve technical problems. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in the present application are the same as those of the abnormal path analysis method provided in the above embodiments, and will not be elaborated here.

[0157] The present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the abnormal path analysis method as described above.

[0158] The computer program product provided in the present application can solve technical problems. Compared with the prior art, the beneficial effects of the computer program product provided in the present application are the same as those of the abnormal path analysis method provided in the above embodiments, and will not be elaborated here.

[0159] The above are only some embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.

Claims

1. An abnormal path analysis method, characterized in that: The method includes: Identify the collected raw data to obtain sensitive data types and sensitivity levels; Generate a sensitive path mapping map according to the sensitive data type and the sensitivity level, wherein the nodes in the sensitive path mapping map represent associated components corresponding to the sensitive data, and the edges in the sensitive path mapping map represent the sensitive data type, transmission times, and transmission time transmitted between nodes; Determine a transmission risk value according to the sensitive data type, the number of transmissions and the transmission time, and add the transmission risk value as an attribute to the edge; Determine abnormal nodes in the sensitive path mapping map according to the improved node-to-vector algorithm, the jump model algorithm and the improved attribute network-based deep anomaly detection model; The abnormal nodes in the sensitive path mapping map are analyzed to obtain abnormal paths in the sensitive path mapping map.

2. The method according to claim 1, characterized in that The step of determining the transmission risk value according to the sensitive data type, the number of transmissions and the transmission time comprises: Determining a sensitive data type weight of the sensitive data type according to the sensitivity level; Determine a transmission frequency weight of the sensitive data type according to the transmission frequency; Determine a transmission time weight of the sensitive data type according to the transmission time; The transmission risk value is determined according to the sensitive data type weight, the transmission number weight, the transmission time weight, the time decay function, and the time interval from the last sensitive data transmission to the present.

3. The method according to claim 1, characterized in that In the improved node-to-vector algorithm, the transmission risk value and the node transmission important core sensitive data risk value are used as parameters to control the random walk probability, and in the improved attribute network-based deep anomaly detection model, the process of generating nodes by the attribute network encoder is replaced by the improved node-to-vector algorithm; The step of determining abnormal nodes in the sensitive path mapping map according to the improved node-to-vector algorithm, the jump model algorithm and the improved attribute network-based deep anomaly detection model includes: Performing random walks in the sensitive path mapping map according to an improved node-to-vector algorithm to generate multiple random walk paths; Inputting the plurality of random walk paths into a jumping model algorithm to perform node representation learning, and outputting a vector representation of each of the random walk paths; The abnormal nodes in the sensitive path mapping map are determined according to the vector representation of each of the random walk paths through the improved attribute network-based deep anomaly detection model.

4. The method according to claim 3, characterized in that The step of performing random walks in the sensitive path mapping map according to the improved node-to-vector algorithm to generate multiple random walk paths includes: Determine the transmission risk value ratio between the target node and the next hop node according to the transmission risk value between the target node and the next hop node in the sensitive path mapping map and the transmission risk value between the next hop node and the neighbor node corresponding to the next hop node by using an improved node-to-vector algorithm; Normalizing the number of times the important core sensitive data has been transmitted between the target node and the next hop node and the number of times the important core sensitive data has been transmitted between the next hop node and the neighboring node to obtain a risk value of the node transmitting the important core sensitive data; Determine a probability expression for random walk probability control according to the distance between the target node and the next hop node and a random walk parameter; The probability value of jumping from the target node to the next hop node is determined according to the transmission risk value ratio, the risk value of the node transmitting important core sensitive data and the probability expression, and multiple random walk paths are generated according to the probability value.

5. The method according to claim 3, characterized in that The step of inputting the plurality of random walk paths into a jumping model algorithm for node representation learning and outputting a vector representation of each of the random walk paths comprises: Inputting the multiple random walk paths into a jumping model algorithm, wherein the jumping model algorithm represents the multiple random walk paths by one-hot encoding to obtain a coding matrix; Mapping the encoding matrix to a low-dimensional space of a preset dimension according to index mapping; The initialization matrix corresponding to the low-dimensional space of a preset dimension is used as a weight matrix, and each node in the encoding matrix is ​​taken as a central node in turn. The vector representation of the central node is updated in the weight matrix by maximizing the probability of the central node, so as to obtain the vector representation of each random walk path.

6. The method according to claim 3, characterized in that The step of determining abnormal nodes in the sensitive path mapping map according to the vector representation of each random walk path through the improved attribute network-based deep anomaly detection model includes: Reconstructing an adjacency matrix according to the vector representation of each random walk path through an improved structure reconstruction decoder in a deep anomaly detection model based on an attribute network; Determine the reconstructed node vector through the attribute reconstruction decoder; Determining a reconstruction error according to the adjacency matrix, the reconstructed node vector, an error weight parameter corresponding to the reconstructed node vector, and the vector representation; An abnormal node in the sensitive path mapping map is determined according to the reconstruction error.

7. An abnormal path analysis device, characterized in that: The abnormal path analysis device comprises: A sensitive data identification module is used to identify the collected raw data and obtain the sensitive data type and sensitivity level; A sensitive path map generation module, configured to generate a sensitive path mapping map according to the sensitive data type and the sensitivity level, wherein the nodes in the sensitive path mapping map represent associated components corresponding to the sensitive data, and the edges in the sensitive path mapping map represent the sensitive data type, transmission times and transmission time transmitted between nodes; a transmission risk value determination module, configured to determine a transmission risk value according to the sensitive data type, the number of transmissions and the transmission time, and add the transmission risk value as an attribute to the edge; An abnormal node determination module is used to determine abnormal nodes in the sensitive path mapping map according to an improved node-to-vector algorithm, a jump model algorithm and an improved attribute network-based deep anomaly detection model; The abnormal path analysis module is used to analyze the abnormal nodes in the sensitive path mapping map to obtain abnormal paths in the sensitive path mapping map.

8. An abnormal path analysis device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the abnormal path analysis method according to any one of claims 1 to 6.

9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the abnormal path analysis method according to any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the abnormal path analysis method according to any one of claims 1 to 6 are implemented.