Abnormal behavior analysis method, system, equipment and medium
By constructing an abnormal behavior analysis model, analyzing the domain name log behavior characteristics of users with abnormal traffic, the problem of low analysis accuracy in the existing technology is solved, and high accuracy analysis of users who use P2P CDN service violations is achieved.
Patent Information
- Application Number
- CN202510348416.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-10
AI Technical Summary
It is difficult to accurately determine whether users deploy P2P CDN services in violation of regulations, and the analysis accuracy is low.
By building an abnormal behavior analysis model, the domain name log of users with abnormal traffic is obtained and behavioral characteristics are analyzed, including resource acquisition behavior characteristics, domain name access behavior characteristics, resource service behavior characteristics and cross-access behavior characteristics, and these characteristics are input to the model for analysis.
It improves the accuracy of abnormal user analysis for illegal use of P2P CDN services, and can deeply mine user DNS access data from the perspective of DNS domain name resolution to adapt to the analysis accuracy after the content of PCDN services is updated.
Smart Images

Figure CN120128403A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network detection technologies, and in particular, to an abnormal behavior analysis method, system, device, and medium. Background Art
[0002] In recent years, with the rapid growth of network traffic, content delivery networks (CDNs) have played a key role in improving user experience and reducing network congestion. To further improve content delivery efficiency and reduce costs, peer-to-peer CDN (PCDN) technology has been widely used. However, there are some abnormal users who illegally use PCDN services, affecting the normal operations of communication operators.
[0003] Currently, existing technologies mainly analyze by comparing the bandwidth traffic performance of users with the traffic performance during PCDN services to determine whether a user is an abnormal user who illegally deploys PCDN services. In actual applications, since users may also have high uplink bandwidth traffic behaviors when using private cloud services, watching live broadcasts, etc., this method cannot accurately determine whether a user illegally deploys PCDN services, resulting in low analysis accuracy.
[0004] In summary, the technical problems in the related technologies need to be improved. Summary of the Invention
[0005] The purpose of the present invention is to solve at least to some extent one of the technical problems in the related technologies.
[0006] The main purpose of the embodiments of this application is to propose an abnormal behavior analysis method, system, device, and medium. Among them, this method can effectively improve the analysis accuracy of abnormal users who illegally use PCDN services.
[0007] To achieve the above purpose, on the one hand, an embodiment of this application proposes an abnormal behavior analysis method, including:
[0008] Construct an abnormal behavior analysis model and obtain the domain name logs of a number of traffic abnormal users;
[0009] Perform behavior feature parsing on all the domain name logs to obtain the behavior feature set of each traffic abnormal user. The behavior feature set includes resource acquisition behavior features, domain name access behavior features, resource service behavior features, and cross-access behavior features;
[0010] Input all the behavior feature sets into the abnormal behavior analysis model for behavior analysis to obtain the abnormal behavior analysis results of each traffic abnormal user.
[0011] In some embodiments, the constructing of the abnormal behavior analysis model includes:
[0012] Obtain the historical operation data of the personal distribution network device;
[0013] Extract data features from the historical operation data to obtain a device feature set, where the device feature set includes traffic features, domain name access frequency features, domain name naming rule features, and domain name usage features;
[0014] Construct the abnormal behavior analysis model according to the device feature set.
[0015] In some embodiments, the method further includes:
[0016] Obtain an uplink threshold, a ratio threshold, and the uplink traffic and downlink traffic of network users;
[0017] Calculate the ratio of the uplink traffic and the downlink traffic to obtain a traffic ratio;
[0018] Compare the uplink threshold and the uplink traffic to obtain a first comparison result, and compare the ratio threshold and the traffic ratio to obtain a second comparison result;
[0019] If the first comparison result is that the uplink threshold is less than the uplink traffic, and the second comparison result is that the ratio threshold is less than the traffic ratio, then determine the network user as the traffic abnormal user.
[0020] In some embodiments, parsing the behavior features of all the domain name logs to obtain the behavior feature set of each traffic abnormal user, including:
[0021] Obtain a domain name analysis time window;
[0022] According to the domain name analysis time window, perform time window statistical analysis on the domain name logs to obtain the domain name access behavior features of the traffic abnormal user;
[0023] In some embodiments, parsing the behavior features of all the domain name logs to obtain the behavior feature set of each traffic abnormal user, including:
[0024] Obtain a domain name resource library and a domain name blacklist, and several target domain names in the domain name logs;
[0025] According to the domain name resource library, extract resource source information for all the target domain names to obtain the resource acquisition behavior features;
[0026] According to the domain name blacklist, perform domain name blacklist verification on all the target domain names to obtain the domain name verification information of each target domain name;
[0027] Based on all the domain name verification information, the resource service behavior characteristics are obtained.
[0028] In some embodiments, parsing the behavior characteristics of all the domain name logs to obtain the behavior characteristic set of each traffic abnormal user, including:
[0029] Obtain the first domain name and the second domain name of each domain name log, where the first domain name is the local domain name of the corresponding traffic abnormal user in the domain name log, and the second domain name is the target domain name of the corresponding traffic abnormal user in the domain name log;
[0030] According to each first domain name, perform domain name matching on all the second domain names to obtain the domain name matching information of each first domain name, and the domain name matching information records several second domain names that match successfully with the first domain name;
[0031] Based on all the domain name matching information, obtain the cross-access behavior characteristics of each traffic abnormal user.
[0032] In some embodiments, input the behavior characteristic set into the abnormal behavior analysis model for behavior analysis to obtain the abnormal behavior analysis results of the traffic abnormal user, including:
[0033] Input the behavior characteristic set into the abnormal behavior analysis model to obtain the resource acquisition characteristic value, domain name access characteristic value, resource service characteristic value, and cross-access characteristic value output by the abnormal behavior analysis model;
[0034] Based on the resource acquisition characteristic value, the domain name access characteristic value, the resource service characteristic value, and the cross-access characteristic value, obtain the abnormal behavior analysis results of the traffic abnormal user.
[0035] To achieve the above object, on the other hand, an embodiment of the present application proposes an abnormal behavior analysis system, including:
[0036] The first processing unit is used to construct an abnormal behavior analysis model and obtain the domain name logs of several traffic abnormal users;
[0037] The second processing unit is used to parse the behavior characteristics of all the domain name logs to obtain the behavior characteristic set of each traffic abnormal user, and the behavior characteristic set includes resource acquisition behavior characteristics, domain name access behavior characteristics, resource service behavior characteristics, and cross-access behavior characteristics;
[0038] The third processing unit is used to input all the behavior characteristic sets into the abnormal behavior analysis model for behavior analysis to obtain the abnormal behavior analysis results of each traffic abnormal user.
[0039] In some embodiments, the third processing unit includes a model processing subunit and a behavior analysis subunit;
[0040] The model processing subunit is configured to input the behavior feature set into the abnormal behavior analysis model to obtain a resource acquisition feature value, a domain name access feature value, a resource service feature value, and a cross-access feature value output by the abnormal behavior analysis model;
[0041] The behavior analysis subunit is configured to obtain an abnormal behavior analysis result of the traffic abnormal user according to the resource acquisition feature value, the domain name access feature value, the resource service feature value, and the cross-access feature value.
[0042] To achieve the above object, on the other hand, an embodiment of the present application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the foregoing method is implemented.
[0043] To achieve the above object, on the other hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the foregoing method is implemented.
[0044] The embodiments of the present application at least include the following beneficial effects:
[0045] The present application provides an abnormal behavior analysis method, system, device, and medium. Among them, the method constructs an abnormal behavior analysis model and obtains domain name logs of several traffic abnormal users; performs behavior feature parsing on all the domain name logs to obtain a behavior feature set of each traffic abnormal user, and the behavior feature set includes a resource acquisition behavior feature, a domain name access behavior feature, a resource service behavior feature, and a cross-access behavior feature; inputs all the behavior feature sets into the abnormal behavior analysis model for behavior analysis to obtain an abnormal behavior analysis result of each traffic abnormal user. By performing behavior feature parsing on the domain name logs and performing behavior analysis on all the parsed behavior feature sets, the method can analyze abnormal users who violate the use of the PCDN service from the perspective of DNS domain name resolution, effectively improving the analysis accuracy of abnormal users who violate the use of the PCDN service. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 is a flowchart of an abnormal behavior analysis method provided by an embodiment of the present application;
[0047] Figure 2 is a flowchart of constructing an abnormal behavior analysis model provided by an embodiment of the present application;
[0048] Figure 3 It is a schematic flowchart of a process for abnormal traffic users provided by an embodiment of the present application;
[0049] Figure 4 It is a detailed flowchart of the first step S120 provided by an embodiment of the present application;
[0050] Figure 5 It is a detailed flowchart of the second step S120 provided by an embodiment of the present application;
[0051] Figure 6 It is a detailed flowchart of the third step S120 provided by an embodiment of the present application;
[0052] Figure 7 It is a detailed flowchart of a step S130 provided by an embodiment of the present application;
[0053] Figure 8 It is a schematic framework diagram of an abnormal behavior analysis system provided by an embodiment of the present application;
[0054] Figure 9 It is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0056] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. When the following description involves the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present application. They are only examples of devices / equipment and methods that are consistent with some aspects of the embodiments of the present application detailed in the appended claims.
[0057] It can be understood that the terms "first", "second", etc. used in the present application can be used herein to describe various concepts, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information. Depending on the context, the words "if", "when" as used herein can be interpreted as "when...", "while...", or "in response to determining".
[0058] The terms "at least one", "multiple", "each", "any", etc. used in this application, at least one includes one, two or more, multiple includes two or more, each refers to each of the corresponding multiple, and any refers to any one of the multiple.
[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0060] The following is an explanation of the terms involved in the embodiments of the present application:
[0061] CDN (Content Delivery Network) is a content distribution network that uses traffic load and intelligent scheduling technology to publish site content to massive acceleration nodes around the world, allowing network users to obtain the required content nearby, speeding up user access and reducing the load on business servers.
[0062] PCDN (P2P CDN) is a content distribution network based on P2P technology. This technology is an underlying expansion of traditional CDN technology, allowing each user participating in the CDN lower layer to act as a "mini node" for content distribution, so that network users can further reduce the path to the CDN or even the source site when requesting network resources, thereby obtaining faster resource acquisition speed.
[0063] At present, the existing technology mainly compares and analyzes the user's bandwidth traffic performance with the traffic performance of the PCDN service to analyze whether the user is an abnormal user who deploys the PCDN service in violation of the regulations. However, in actual applications, since users also have high uplink bandwidth traffic when using private cloud services, watching live broadcasts, etc., this method cannot accurately determine whether the user has deployed the PCDN service in violation of the regulations, and the analysis accuracy is low.
[0064] In addition, there are some existing technologies that analyze abnormal users from the perspective of DNS domain name resolution. However, they mainly analyze by presetting a PCDN domain name library or a PCDN feature library, and determining whether the user to be identified accesses the PCDN domain names identified in the PCDN domain name library, or whether the features of the user to be identified belong to the features of the PCDN feature library. This method lacks multi-dimensional cross-analysis and in-depth mining of users' DNS access data, and its analysis accuracy for abnormal users is not high. Moreover, since PCDN service providers will continuously and periodically update the algorithms and other service contents of the PCDN services they provide, after the PCDN service providers update their service contents, the analysis accuracy of the existing method of presetting a PCDN domain name library or a PCDN feature library is often not high or even invalid, and the adaptability of abnormal behavior analysis is limited.
[0065] In view of this, the present application provides an abnormal behavior analysis method, system, device and medium. Among them, this method parses the behavior characteristics of domain name logs and performs behavior analysis on all parsed behavior feature sets, and it can analyze abnormal users who violate the use of PCDN services from the perspective of DNS domain name resolution, effectively improving the analysis accuracy of abnormal users who violate the use of PCDN services.
[0066] In addition, specifically by performing time window statistical analysis on domain name logs, this method can obtain the business activity content of users from the time dimension, and by extracting resource source information from domain name logs, it can deeply mine the business activity content accessed by users from the resource content dimension, so as to deeply mine users' DNS access data from multiple dimensions, which is beneficial to improving the analysis accuracy of abnormal users.
[0067] Furthermore, this method performs domain name matching on all second domain names according to each first domain name. Compared with the existing method of determining whether the user to be identified accesses the PCDN domain names identified in the CDN domain name library, or whether the features of the user to be identified belong to the features of the PCDN feature library, this method can fully associate and analyze the behavior of PCDN users as domain name resolution addresses and serving other source users, and can fully consider the behavior characteristics of mutual access between PCDN users. It not only improves the analysis accuracy of abnormal users (network users who violate the use of PCDN services) with a new technical idea, but also can ensure the accuracy of analyzing abnormal users after the PCDN service content is updated, and the adaptability of abnormal behavior analysis is relatively high.
[0068] An abnormal behavior analysis method, system, device and medium provided by an embodiment of the present application can be applied to a network service application scenario. In the network service application scenario, a network service provider can analyze the domain name logs of users through the method provided by the embodiment of the present application to determine whether there is an abnormal behavior analysis result of violating the PCDN service. This method can effectively improve the analysis accuracy of the abnormal behavior of violating the PCDN service and improve the adaptability of abnormal behavior analysis.
[0069] The method provided by the embodiment of the present application can be applied to a terminal, a server, or software running on a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, etc., but is not limited thereto; the server side can be configured as an independent physical server, or can be configured as a server cluster or a distributed system composed of multiple physical servers, or can be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network; the software can be an application implementing this method, etc., but is not limited to the above forms.
[0070] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0071] Refer to Figure 1 , Figure 1 is an optional flowchart of an abnormal behavior analysis method provided by an embodiment of the present application, Figure 1 The method in
[0072] S110. Build an abnormal behavior analysis model and obtain the domain name logs of several users with abnormal traffic;
[0073] In the embodiments of the present application, the abnormal behavior analysis model is used to analyze whether a user with abnormal traffic has violated the PCDN service. Specifically, the abnormal behavior analysis model can be a linear model or a neural network model. Among them, the neural network model can be any one of a fully connected neural network (FCNN), an autoencoder (Auto Encoder), a long short-term memory network (LSTM), a recurrent neural network (RNN), etc. The examples in the present application are only for illustration and do not limit the specific type of the abnormal behavior analysis model.
[0074] It can be understood that a user with abnormal traffic can be a network user with abnormal traffic usage among all network users of a communication service operator or a network service operator. Among them, abnormal traffic usage is used to characterize the situation where the traffic usage of a network user is similar to the traffic performance of the PCDN service.
[0075] It should be noted that the domain name log is a detailed log file for recording the access behavior of a corresponding network user to a specific domain name. The domain name log includes log information such as the source IP address of the corresponding network user, the accessed domain name, and the IP address of the accessed domain name after domain name resolution.
[0076] Refer to Figure 2 , in some embodiments, constructing the abnormal behavior analysis model includes:
[0077] A1. Obtain the historical operation data of the personal distribution network device;
[0078] A2. Extract data features from the historical operation data to obtain a device feature set, where the device feature set includes traffic features, domain name access frequency features, domain name naming rule features, and domain name usage features;
[0079] A3. Construct the abnormal behavior analysis model according to the device feature set.
[0080] In the embodiments of the present application, the personal distribution network device can be a network device used by a network user in the PCDN network, and the historical operation data can be the operation data of the personal distribution network device in the historical time period of the PCDN network. The historical operation data can usually be obtained through the domain name log recorded in the corresponding personal distribution network device, or through traffic mirroring technology to mirror the network data packets of the personal distribution network device.
[0081] It can be understood that step A2 can be to extract features from various data of historical operation data, and construct a device feature set based on the extracted traffic features, domain name access frequency features, domain name naming rule features, and domain name usage features. Specifically, for the historical operation data of a certain content delivery network (CDN) device, its traffic features can be the traffic information determined by mirroring network data packets in a certain historical event segment of the historical operation data; the domain name access frequency feature can be the access frequency of each accessed domain name in the historical operation data; since CDN providers have similar domain names when providing CDN services, the naming rule feature can be the naming features of multiple accessed domain names of each CDN provider in the historical operation data; the domain name usage feature can be the usage of each accessed domain name in the CDN service in the historical operation data, such as at least one of the resource acquisition access domain name for content delivery and resource pulling, the interface access domain name for node management and control signaling interaction, and the NAT network type detection access domain name for network environment diagnosis and connection optimization.
[0082] It should be noted that if the abnormal behavior analysis model is a linear model, first, the abnormal behavior labels of the historical operation data can be obtained, and then the traffic features, domain name access frequency features, domain name naming rule features, and domain name usage features in the historical operation data are used as input variables and input into the linear model. Then, based on the predicted values and abnormal behavior labels output by the linear model, the linear model is updated by backpropagation using the least squares method or the gradient descent method, so as to obtain the finally constructed abnormal behavior analysis model.
[0083] Alternatively, if the abnormal behavior analysis model is a neural network model, the accuracy of the abnormal behavior analysis model for abnormal behavior analysis can be measured by the consistency between the analysis results it outputs and the abnormal behavior labels. The closer the analysis results are to the abnormal behavior labels, the more accurate the analysis results of the abnormal behavior analysis model are, and the better the reliability is; on the contrary, the less close the analysis results are to the abnormal behavior labels, the less accurate the analysis results of the abnormal behavior analysis model are, and the worse the reliability is. Therefore, in the embodiments of the present application, a target loss value can be determined according to the analysis results and the abnormal behavior labels. The present application does not limit the loss function used to determine the target loss value. For example, 0-1 loss function, square loss function, absolute loss function, logarithmic loss function, cross-entropy loss function, etc. can all be used as the loss function of the abnormal behavior analysis model.
[0084] It is worth mentioning that the target loss value can be used to train the abnormal behavior analysis model. Specifically, the relevant parameters of the abnormal behavior analysis model can be updated through the backpropagation algorithm to improve their performance. In the embodiments of the present application, the training method can be carried out in a cyclic iterative manner, that is, the parameters of the abnormal behavior analysis model can be updated round by round. Exemplarily, for example, multiple historical operation data can be obtained, and then these historical operation data are divided into different training data groups. First, the target loss value corresponding to a training data group is calculated using the data of the training data group, and the parameters of the abnormal behavior analysis model are updated once. Then, based on the updated abnormal behavior analysis model, the target loss value corresponding to another training data group is calculated using the data of another training data group, and the parameters of the abnormal behavior analysis model are updated again. By such cyclic iteration, a trained abnormal behavior analysis model is obtained. Here, the condition for determining the end of training can be set according to actual needs. For example, in some embodiments, the target number of training iterations can be set, and the number of iteration rounds is recorded during the training process. Each time the parameters of the model are updated, the number of iteration rounds can be incremented by 1. If the number of iteration rounds reaches the target number of rounds after the current update of the model parameters, it can be considered that the training is completed, and a trained abnormal behavior analysis model is obtained; if the number of iteration rounds does not reach the target number of rounds after the current update of the model parameters, iterative training can continue. In some embodiments, a test data set can also be obtained, and the prediction accuracy of the abnormal behavior analysis model is detected through the test data set. Each time the parameters of the model are updated, the test data set is used for detection once. If the analysis accuracy obtained by testing reaches the pre-set index requirements after the current update of the model parameters, it can be considered that the training is completed, and a trained abnormal behavior analysis model is obtained; if the analysis accuracy obtained by testing does not reach the pre-set index requirements after the current update of the model parameters, iterative training can continue.
[0085] Referring to Figure 3 , in some embodiments, the method further includes:
[0086] B1. Obtain an uplink threshold, a ratio threshold, and the uplink traffic and downlink traffic of a network user;
[0087] B2. Calculate the ratio of the uplink traffic and the downlink traffic to obtain a traffic ratio;
[0088] B3. Compare the uplink threshold and the uplink traffic to obtain a first comparison result, and compare the ratio threshold and the traffic ratio to obtain a second comparison result;
[0089] B4. If the first comparison result is that the uplink threshold is less than the uplink traffic and the second comparison result is that the ratio threshold is less than the traffic ratio, determine the network user as the traffic abnormal user.
[0090] In the embodiment of the present application, the uplink threshold is used to indicate the maximum threshold of the uplink traffic of a network user, and the ratio threshold is used to indicate the maximum threshold of the uplink traffic and the downlink traffic of a network user. Specifically, for a certain network user, step B2 may be to obtain the ratio of its uplink traffic to the downlink traffic, denoted as the traffic ratio; step B3 may be to compare the magnitude relationship between the uplink threshold and the uplink traffic, and to compare the magnitude relationship between the ratio threshold and the traffic ratio.
[0091] Specifically, if the first comparison result is that the uplink threshold is less than the uplink traffic, and the second comparison result is that the ratio threshold is less than the traffic ratio, it indicates that the network user has a behavior of transmitting a large amount of data externally, which conforms to the traffic performance of a PCDN user. At this time, the network user can be determined as a traffic user. Or, if the first comparison result is that the uplink threshold is greater than or equal to the uplink traffic, or the second comparison result is that the ratio threshold is greater than or equal to the traffic ratio, it indicates that the network user does not currently have a behavior of transmitting a large amount of data externally. At this time, the process can return to the awareness step B1.
[0092] S120. Perform behavior feature parsing on all the domain name logs to obtain a behavior feature set for each traffic abnormal user, where the behavior feature set includes a resource acquisition behavior feature, a domain name access behavior feature, a resource service behavior feature, and a cross-access behavior feature;
[0093] In the embodiment of the present application, behavior feature parsing can be performed on all domain name logs respectively from the dimensions of resource acquisition, domain name access, resource service, and cross-access, so as to obtain a behavior feature set for each traffic abnormal user. Among them, the resource acquisition behavior feature is used to indicate the resource demand of the corresponding traffic abnormal user, which can specifically be the number of requests for the website CDN domain name by the traffic abnormal user and the number of organizations; the domain name access behavior feature is used to indicate the behavior of the traffic abnormal user accessing the PCDN service domain name externally, which can specifically be at least one of the number of requests for the PCDN domain name, the number of PCDN domain names requested, etc.
[0094] It can be understood that the resource service behavior feature is used to indicate whether the first abnormal user has a behavior of providing resource services to the second abnormal user. Among them, the first abnormal user is any traffic abnormal user marked as a suspected PCDN user among all traffic abnormal users, and the second abnormal user is any traffic abnormal user other than the first abnormal user among all traffic abnormal users.
[0095] It should be noted that the cross - access behavior feature is used to indicate whether there is an access behavior in at least one direction between the third abnormal user and the fourth abnormal user. For example, the access behavior of the third abnormal user to the fourth abnormal user, or the access behavior of the fourth abnormal user to the third abnormal user. Among them, the third abnormal user is any one of all traffic abnormal users, and the fourth abnormal user is any one of all traffic abnormal users except the third abnormal user.
[0096] Referring to Figure 4 , in some embodiments, the step S120 of parsing the behavior features of all the domain name logs to obtain the behavior feature set of each traffic abnormal user includes:
[0097] C1. Obtain the domain name analysis time window;
[0098] C2. According to the domain name analysis time window, perform time window statistical analysis on the domain name logs to obtain the domain name access behavior features of the traffic abnormal users;
[0099] In the embodiments of the present application, the time length of the actual domain name analysis window can be any one of 3 minutes, 5 minutes, 10 minutes, etc. Specifically, step D2 can be based on the domain name analysis time window. Perform coverage extraction on the domain name logs to obtain several log time windows. Each log time window records at least one of data information such as the domain names accessed by the traffic user in this time window, the manufacturers providing the PCDN service, the number of requests for the PCDN domain name, and the quantity of requests for the PCDN domain name. Then, by statistically analyzing each item of data information in each log time window, the domain name access behavior features of the traffic abnormal users are determined.
[0100] Referring to Figure 5 , the step S120 of parsing the behavior features of all the domain name logs to obtain the behavior feature set of each traffic abnormal user includes:
[0101] D1. Obtain the domain name resource library, the domain name blacklist, and several target domain names in the domain name logs;
[0102] D2. According to the domain name resource library, extract the resource source information of all the target domain names to obtain the resource acquisition behavior features;
[0103] D3. According to the domain name blacklist, perform domain name blacklist verification on all the target domain names to obtain the domain name verification information of each target domain name;
[0104] D4. According to all the domain name verification information, obtain the resource service behavior features.
[0105] In the embodiments of the present application, the domain name resource library is used to record each domain name and the CDN provider or website organization corresponding to each domain name; while the domain name blacklist is used to record the local domain names of traffic anomaly users who were previously marked as suspected PCDN users. Specifically, for the resource acquisition behavior characteristics, first, several target domain names of the domain name log can be obtained; then, according to the domain name resource library, each target domain name is respectively matched and mapped to determine the CDN provider or website organization of each target domain name, and the resource acquisition behavior characteristics of the traffic anomaly user are determined by counting the access times of the CDN provider or website organization of each target domain name.
[0106] It can be understood that for the resource service behavior characteristics, first, several target domain names of the domain name log can be obtained; then, according to the domain name blacklist, each target domain name is respectively matched and verified to obtain several domain name verification information, and each domain name verification information is used to represent whether there is a local threshold corresponding to the target domain name; after obtaining all the domain name verification information, the resource service behavior characteristics of the traffic anomaly user can be determined by an integration method. The resource service behavior characteristics of the remaining traffic anomaly users can be obtained by simple analogy in the same way, and the present application will not elaborate here.
[0107] Referring to Figure 6 , in some embodiments, step S120, parsing the behavior characteristics of all the domain name logs to obtain the behavior characteristic set of each traffic anomaly user, includes:
[0108] E1. Obtaining the first domain name and the second domain name of each domain name log, where the first domain name is the local domain name of the corresponding traffic anomaly user in the domain name log, and the second domain name is the target domain name of the corresponding traffic anomaly user in the domain name log;
[0109] E2. Performing domain name matching on all the second domain names according to each first domain name to obtain the domain name matching information of each first domain name, and the domain name matching information records several second domain names that match successfully with the first domain name;
[0110] E3. Obtaining the cross - access behavior characteristics of each traffic anomaly user according to all the domain name matching information.
[0111] In the embodiments of the present application, step E1 may be to obtain the first domain name and the second domain name of each domain name log. Since there are various types of accessed domain names, such as resource acquisition access domain names, interface access domain names, etc., the specific number of the first domain name and the second domain name may be one or more, and the present application does not limit this here.
[0112] It can be understood that for a certain first domain name, step E2 can be to perform domain name matching between the first domain name and each second domain name in all domain name logs respectively. There are already various specific domain name matching methods. For example, the first domain name and the second domain name can be regarded as text words, and text matching methods such as string-based matching, statistic-based feature matching, or word vector-based matching can be used to determine whether the first domain name successfully matches each second domain name, so as to obtain the domain name matching information of the first domain name. The domain name matching information of the remaining first domain names can be obtained by simple analogy, and will not be elaborated here in this application.
[0113] It should be noted that for a certain domain name matching information, if there is at least one second domain name in the domain name matching information, it means that there is an interconnection behavior between the traffic abnormal user corresponding to the domain name matching information and other traffic abnormal users. The PCDN service provided by this traffic abnormal user to other traffic abnormal users is also the access behavior of the aforementioned third abnormal user in one direction with the fourth abnormal user.
[0114] It is worth mentioning that after obtaining all the domain name matching information, all the domain name matching information can be integrated, redundant information can be updated, so as to obtain the cross-access behavior characteristics of each traffic abnormal user.
[0115] S130. Input all the behavior feature sets into the abnormal behavior analysis model for behavior analysis to obtain the abnormal behavior analysis results of each traffic abnormal user.
[0116] In the embodiments of this application, the behavior feature set of each traffic abnormal user can be input into the abnormal behavior analysis model. Through the abnormal behavior analysis model, based on each behavior feature set, it is predicted and analyzed whether each traffic abnormal user has the abnormal behavior of illegally using the PCDN service, so as to obtain the abnormal behavior analysis results.
[0117] Refer to Figure 7 , in some embodiments, step S130. Input the behavior feature set into the abnormal behavior analysis model for behavior analysis to obtain the abnormal behavior analysis results of the traffic abnormal user, including:
[0118] F1. Input the behavior feature set into the abnormal behavior analysis model to obtain the resource acquisition feature value, domain name access feature value, resource service feature value, and cross-access feature value output by the abnormal behavior analysis model;
[0119] F2. Obtain the abnormal behavior analysis results of the traffic abnormal user according to the resource acquisition feature value, the domain name access feature value, the resource service feature value, and the cross-access feature value.
[0120] In an embodiment of the present application, for a user with abnormal traffic, the resource acquisition behavior characteristics, domain name access behavior characteristics, resource service behavior characteristics, and cross-access behavior characteristics in the behavior feature set can be input into an abnormal behavior analysis model. The abnormal behavior analysis model can be a linear model or a neural network model. Based on the weights recorded by the abnormal behavior analysis model, the corresponding resource acquisition feature value, domain name access feature value, resource service feature value, and cross-access feature value can be obtained. Then, the resource acquisition feature value, domain name access feature value, resource service feature value, and cross-access feature value are calculated by summation, and based on a preset abnormal behavior scoring table and the final feature values, the abnormal behavior analysis result of the user with abnormal traffic is determined.
[0121] Please refer to Figure 8 , the embodiment of the present application further provides an abnormal behavior analysis system, including:
[0122] A first processing unit 810, configured to construct an abnormal behavior analysis model and obtain domain name logs of several users with abnormal traffic;
[0123] A second processing unit 820, configured to perform behavior feature parsing on all the domain name logs to obtain a behavior feature set of each user with abnormal traffic. The behavior feature set includes resource acquisition behavior characteristics, domain name access behavior characteristics, resource service behavior characteristics, and cross-access behavior characteristics;
[0124] A third processing unit 830, configured to input all the behavior feature sets into the abnormal behavior analysis model for behavior analysis to obtain an abnormal behavior analysis result of each user with abnormal traffic.
[0125] In some embodiments, the third processing unit includes a model processing subunit and a behavior analysis subunit;
[0126] The model processing subunit 831 is configured to input the behavior feature set into the abnormal behavior analysis model to obtain a resource acquisition feature value, a domain name access feature value, a resource service feature value, and a cross-access feature value output by the abnormal behavior analysis model;
[0127] The behavior analysis subunit 832 is configured to obtain an abnormal behavior analysis result of the user with abnormal traffic according to the resource acquisition feature value, the domain name access feature value, the resource service feature value, and the cross-access feature value.
[0128] It can be understood that the content in the above method embodiments is applicable to the system embodiments of the present application. The functions specifically implemented by the system embodiments of the present application are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0129] An embodiment of the present application further provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above-mentioned method is implemented. The electronic device may be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.
[0130] It can be understood that the content in the above method embodiments is applicable to the device embodiments of the present application. The functions specifically implemented by the device embodiments of the present application are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0131] Please refer to Figure 9 , Figure 9 which schematically shows the hardware structure of an electronic device according to an embodiment. The electronic device includes:
[0132] A processor 901, which can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;
[0133] A memory 902, which can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 902 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 902 and are called by the processor 901 to execute the method of the embodiments of the present application;
[0134] An input / output interface 903, which is used to implement information input and output;
[0135] A communication interface 904, which is used to implement communication interaction between the device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.);
[0136] A bus 905, which transmits information between various components of the device (such as the processor 901, the memory 902, the input / output interface 903, and the communication interface 904);
[0137] Among them, the processor 901, the memory 902, the input / output interface 903, and the communication interface 904 are communicatively connected to each other inside the device through the bus 905.
[0138] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned method is implemented.
[0139] It can be understood that the content in the above method embodiments is applicable to the present storage medium embodiments. The functions specifically implemented by the present storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0140] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory can optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0141] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0142] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or combine certain steps, or different steps.
[0143] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0144] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0145] In the description of this application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0146] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expression refers to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0147] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0148] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0149] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0150] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The aforementioned storage medium includes: various media that can store programs such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0151] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings, which does not limit the scope of the rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.
Claims
1. A method for analyzing abnormal behavior, characterized in that: include: Build an abnormal behavior analysis model and obtain domain name logs of several users with abnormal traffic; Performing behavioral feature analysis on all the domain name logs to obtain a behavioral feature set of each user with abnormal traffic, wherein the behavioral feature set includes resource acquisition behavior features, domain name access behavior features, resource service behavior features, and cross-access behavior features; All of the behavior feature sets are input into the abnormal behavior analysis model to perform behavior analysis, and an abnormal behavior analysis result of each user with abnormal traffic is obtained.
2. The method according to claim 1, characterized in that The construction of the abnormal behavior analysis model includes: Obtain historical operating data of personal distribution network equipment; Extracting data features from the historical operation data to obtain a device feature set, wherein the device feature set includes traffic features, domain name access frequency features, domain name naming rule features, and domain name usage features; The abnormal behavior analysis model is constructed based on the device feature set.
3. The method according to claim 1, characterized in that The method further comprises: Obtain the upstream threshold, ratio threshold, and the upstream and downstream traffic of network users; Calculating a ratio of the uplink flow and the downlink flow to obtain a flow ratio; Comparing the uplink threshold and the uplink traffic to obtain a first comparison result, and comparing the ratio threshold and the traffic ratio to obtain a second comparison result; If the first comparison result is that the uplink threshold is less than the uplink traffic, and the second comparison result is that the ratio threshold is less than the traffic ratio, the network user is determined as the abnormal traffic user.
4. The method according to claim 1, characterized in that: The behavior feature analysis of all the domain name logs is performed to obtain a behavior feature set of each user with abnormal traffic, including: Get the domain name analysis time window; According to the domain name analysis time window, a time window statistical analysis is performed on the domain name log to obtain the domain name access behavior characteristics of the user with abnormal traffic.
5. The method according to claim 1, characterized in that The behavior feature analysis of all the domain name logs is performed to obtain a behavior feature set of each user with abnormal traffic, including: Obtain a domain name resource library and a domain name blacklist, as well as several target domain names in the domain name log; Extracting resource source information of all the target domain names according to the domain name resource library to obtain the resource acquisition behavior characteristics; According to the domain name blacklist, a domain name blacklist check is performed on all the target domain names to obtain domain name verification information of each target domain name; The resource service behavior characteristics are obtained according to all the domain name verification information.
6. The method according to any one of claims 1 to 5, characterized in that: The behavior feature analysis of all the domain name logs is performed to obtain a behavior feature set of each user with abnormal traffic, including: Obtain a first domain name and a second domain name of each domain name log, wherein the first domain name is a local domain name of the corresponding user with abnormal traffic in the domain name log, and the second domain name is a target domain name of the corresponding user with abnormal traffic in the domain name log; According to each of the first domain names, domain name matching is performed on all the second domain names to obtain domain name matching information of each of the first domain names, wherein the domain name matching information records a number of second domain names that successfully match the first domain name; According to all the domain name matching information, the cross-access behavior characteristics of each user with abnormal traffic are obtained.
7. The method according to any one of claims 1 to 5, characterized in that: The behavior feature set is input into the abnormal behavior analysis model to perform behavior analysis, and the abnormal behavior analysis result of the abnormal traffic user is obtained, including: Inputting the behavior feature set into the abnormal behavior analysis model to obtain resource acquisition feature values, domain name access feature values, resource service feature values, and cross-access feature values output by the abnormal behavior analysis model; The abnormal behavior analysis result of the user with abnormal traffic is obtained according to the resource acquisition characteristic value, the domain name access characteristic value, the resource service characteristic value and the cross access characteristic value.
8. An abnormal behavior analysis system, characterized in that: include: The first processing unit is used to build an abnormal behavior analysis model and obtain domain name logs of several users with abnormal traffic; A second processing unit is used to perform behavioral feature analysis on all the domain name logs to obtain a behavioral feature set of each user with abnormal traffic, wherein the behavioral feature set includes resource acquisition behavior features, domain name access behavior features, resource service behavior features, and cross-access behavior features; The third processing unit is used to input all the behavior feature sets into the abnormal behavior analysis model to perform behavior analysis, and obtain the abnormal behavior analysis result of each user with abnormal traffic.
9. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
PCDN traffic anomaly detection method based on AI drive
CN122293419A
An AI-driven PCDN traffic anomaly detection method
CN122293419B