Computer remote login identification equipment based on artificial intelligence
By introducing multimodal identity authentication and intelligent behavior analysis based on artificial intelligence into computer remote login recognition technology, the problem of single authentication means being vulnerable to attack in the existing technology is solved, intelligent identification and security response to user login is achieved, and the security of remote login is significantly improved.
Patent Information
- Application Number
- CN202510137724.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-06-20
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing computer remote login recognition technology relies on a single authentication method and is vulnerable to attacks. It lacks dynamic analysis and intelligent judgment of user behavior, and cannot evaluate the security of login requests in real time.
Using artificial intelligence-based computer remote login identification equipment, including user-side device module, authentication and verification module, behavior analysis and risk assessment module, database and storage module, and security monitoring and alarm module, we can realize intelligent identification and security response to user login through multi-modal identity authentication, dynamic adjustment of authentication policies, behavior analysis and risk assessment, encrypted storage and real-time security monitoring.
The security of remote login is significantly improved. Through multimodal authentication and intelligent behavior analysis, it can effectively prevent password theft and false fingerprint attacks, dynamically adjust authentication strategies, timely identify abnormal behaviors, and automatically trigger security responses, enhancing the system's anti-attack ability and user login security guarantees.
Smart Images

Figure CN120180409A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and in particular, to a computer remote login recognition device based on artificial intelligence. Background Art
[0002] With the continuous development of information technology, telecommuting and cloud computing have gradually become part of the work of modern enterprises and individuals, and remote login technology has thus received extensive attention. Existing computer remote login recognition technologies mainly rely on traditional authentication methods, such as the combination of username and password, or single biometric authentication (such as face recognition, fingerprint recognition, etc.).
[0003] Although traditional authentication methods can prevent malicious login behavior to a certain extent, due to relying on a single authentication means (such as password or single biometric method), they are still vulnerable to attacks. For example, passwords are easily cracked by brute force or stolen by phishing attacks, and fingerprint recognition technology may also be subject to fake fingerprint attacks. Especially in high-risk scenarios, a single authentication method cannot provide sufficient security protection, so it cannot effectively cope with modern complex network attacks. At the same time, the existing technology lacks dynamic analysis and intelligent judgment of user behavior, and cannot evaluate the security of login requests in real time. Usually, it can only rely on static security rules and manual intervention to handle abnormal situations, which increases the risk of security vulnerabilities. Summary of the Invention
[0004] To make up for the above deficiencies, the present invention provides a computer remote login recognition device based on artificial intelligence, aiming to improve the problem that traditional authentication methods are vulnerable to attacks due to relying on a single authentication means.
[0005] In a first aspect, the present invention provides the following technical solution. A computer remote login recognition device based on artificial intelligence includes:
[0006] A client device module, configured to collect biometric data and input behavior data of a user, and perform secure communication with a remote authentication server;
[0007] An authentication and verification module, configured to perform multi-modal identity authentication, dynamically adjust the authentication strategy, and detect abnormal behavior;
[0008] A behavior analysis and risk assessment module, configured to analyze the behavior pattern and login environment of a user, evaluate the risk level, and optimize the authentication method;
[0009] A database and storage module, configured to store user identity information, behavior characteristic data, authentication logs, and be responsible for data security and compliance;
[0010] The security monitoring and alarm module is used to monitor user login activities in real time, detect potential security threats, and trigger the security response mechanism.
[0011] Preferably, the client device module includes:
[0012] The terminal device access unit supports PCs and mobile device terminals and uses the encryption protocols SSL / TLS for data communication;
[0013] The biometric data collection unit collects multi-modal biometric features of users, including face, fingerprint, and voice data, and uses deep learning algorithms such as CNN or WaveNet for authentication;
[0014] The user input behavior monitoring unit is used to monitor the user's mouse trajectory and keyboard input method in real time and analyze the behavior pattern using machine learning models such as SVM or KNN.
[0015] Preferably, the authentication and verification module includes:
[0016] The multi-modal authentication unit supports multiple authentication methods and can dynamically switch according to authentication failure situations, including automatically enabling fingerprint or voice recognition when face recognition fails;
[0017] The dynamic authentication policy unit automatically adjusts the authentication policy based on the user's historical login behavior, device information, and IP address data, using risk assessment models such as LSTM or decision trees, and forcibly enables multi-factor authentication (MFA) in high-risk situations;
[0018] The abnormal behavior detection unit uses a behavior comparison algorithm to detect abnormal situations in the user's input habits and triggers a security alarm when an abnormality occurs.
[0019] Preferably, the behavior analysis and risk assessment module includes:
[0020] The user behavior analysis unit constructs a personalized behavior model based on the user's mouse track and keyboard input habits and performs behavior matching through K-means clustering and random forest algorithms;
[0021] The login environment analysis unit evaluates the security of the login request by detecting the IP address, device fingerprint, and network environment;
[0022] The risk assessment decision unit combines the user behavior data and environmental parameters, calculates the risk score, performs risk classification using neural networks or decision trees, and automatically determines the authentication level.
[0023] Preferably, the database and storage module includes:
[0024] User information storage unit, which stores user identity information and biometric data using AES-256 encryption, responsible for data security;
[0025] Behavior data storage unit, which records the user's historical login behaviors and device information, and uses distributed storage technology to provide efficient query capabilities;
[0026] Authentication log storage unit, which stores detailed logs of remote logins, supports access auditing, and complies with GDPR and ISO27001 security compliance requirements.
[0027] Preferably, the security monitoring and alarm module includes:
[0028] Monitoring engine unit, which uses a streaming data processing framework to monitor the user's login behavior data in real time;
[0029] Abnormal alarm system unit, which detects abnormal situations based on a rule engine and automatically triggers an alarm mechanism when risks are detected, including sending security notifications or locking accounts;
[0030] Security response module, which provides an automatic blocking function, can automatically deny access or require additional verification after detecting abnormal logins according to preset policies, and supports manual intervention.
[0031] Preferably, the abnormal behavior detection unit includes the following specific steps:
[0032] S1: Collect the user's behavior data through the user terminal device, including mouse trajectory, keyboard input, and device information, and extract the corresponding feature data;
[0033] The mouse trajectory data includes the mouse's moving speed, click position, click frequency, and drag path length;
[0034] The keyboard input data includes input speed, key press frequency, key press interval time, and input mode;
[0035] The device information includes device type, operating system, and device fingerprint;
[0036] S2: Establish the user's behavior pattern, compare the current behavior data with the historical behavior pattern, and calculate the behavior difference;
[0037] Generate the user's behavior benchmark pattern by calculating the mean and standard deviation of the user's historical behavior data;
[0038] Calculate the similarity between the current mouse trajectory and the historical behavior through the dynamic time warping algorithm. If the similarity is lower than the set threshold, the mouse behavior is considered abnormal;
[0039] Analyze the rhythm of keyboard input through a time-based comparison algorithm to evaluate the deviation between the current input behavior and the historical pattern;
[0040] S3: Use statistical methods, machine learning methods, or time series analysis methods to evaluate the behavior differences and detect whether there are abnormal behaviors;
[0041] Calculate the standard deviation between the user's current behavior and historical behavior using the Z-score method. If the Z-score value of the current behavior exceeds the preset range, it is determined as an abnormal behavior;
[0042] Analyze the differences between the current behavior data and the normal behavior model using support vector machines or random forest algorithms. If the model identifies it as abnormal, report it as an abnormal behavior;
[0043] Use long short-term memory networks to analyze time series data and detect whether there are significant time intervals or behavioral mutations;
[0044] S4: When an abnormal behavior is detected, take corresponding security response measures according to the degree of abnormality, including triggering an alarm, requiring secondary verification, or locking the account;
[0045] For mild abnormalities, including slightly inconsistent input speeds, trigger an alarm and request the user to perform an additional authentication;
[0046] For moderate abnormalities, including device changes or geographical location changes, require the user to perform secondary verification;
[0047] For severe abnormalities, including logins from new devices or logins that are severely inconsistent with historical behaviors, automatically lock the account and notify the administrator for manual intervention;
[0048] S5: Real-time feedback the abnormal detection results and update the user's behavior pattern according to the feedback data to improve the accuracy of subsequent abnormal detections;
[0049] Compare the user's feedback behavior with the detection results, and automatically adjust and optimize the user behavior model to adapt to the new normal behavior pattern and improve the detection accuracy.
[0050] In a second aspect, the present invention provides the following technical solution. A computer remote login recognition method based on artificial intelligence includes the following steps:
[0051] S1. The user device module collects the user's biometric data and input behavior data. The biometric data includes face images, fingerprint information, or voice data, and the input behavior data includes mouse trajectories, keyboard input patterns, and device information, and encrypts and transmits the data to the remote authentication server through the SSL / TLS protocol;
[0052] S2. The authentication and verification module performs multi-modal authentication on the user's identity, adjusts the authentication strategy based on the user's login history, device information, and geographical location, and uses machine learning algorithms to analyze the input behavior pattern to determine whether there are any anomalies.
[0053] S3. The behavior analysis and risk assessment module calculates the user's behavior deviation degree, uses the dynamic time warping method to compare the current behavior with the historical behavior pattern, calculates the comprehensive risk score in combination with time series analysis, and decides whether additional authentication measures are required.
[0054] S4. The database and storage module stores the user's identity information, behavior characteristic data, and authentication logs, uses AES-256 encryption to protect sensitive data, and supports efficient query and historical behavior comparison through a distributed database.
[0055] S5. The security monitoring and alarm module monitors the remote login process in real time, uses a rule engine to detect abnormal behaviors, and when a high-risk login is detected, automatically triggers a security response, including sending an alarm and requiring the user to perform secondary identity verification or locking the account.
[0056] In a third aspect, the present invention provides the following technical solution: a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned computer remote login recognition method based on artificial intelligence is implemented.
[0057] In a fourth aspect, the present invention provides the following technical solution: a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned computer remote login recognition method based on artificial intelligence is implemented.
[0058] The present invention has the following beneficial effects:
[0059] 1. In the present invention, the design based on multi-modal authentication greatly improves the security of remote login. By combining multiple authentication means such as face recognition, fingerprint recognition, and voice recognition, the system can effectively prevent security vulnerabilities such as password theft, fingerprint forgery, or facial image attacks. This multi-factor authentication method ensures that even if one authentication method is breached, other authentication means can still provide strong security protection.
[0060] 2. In the present invention, by analyzing the user's behavior patterns in real time, such as mouse trajectories, keyboard inputs, device usage, etc., the system can accurately identify normal and abnormal behaviors. Combining machine learning algorithms, the system automatically evaluates the risk level of each login and dynamically adjusts the authentication strategy according to the risk situation. The timely detection of abnormal behaviors enables the system to take immediate responses when the user's behavior deviates from the normal pattern, such as requesting secondary verification or blocking login requests, significantly enhancing security.
[0061] 3. In the present invention, based on factors such as the user's login history, device information, and geographical location, the system can intelligently adjust the authentication strength. For regular login requests, the system only performs authentication through basic biometrics; while in high-risk situations (such as the user logging in from an unfamiliar location, using a new device, etc.), the system automatically enables more stringent multi-factor authentication. This dynamic authentication strategy avoids unnecessary complex authentication processes and provides strong protection in high-risk situations.
[0062] 4. In the present invention, the automated security monitoring function of the system can monitor various data streams during the remote login process in real time to ensure the timely discovery of potential security threats. The system can automatically detect abnormal behaviors (such as multiple failed login attempts, logins from uncommon devices or locations, etc.) through behavior pattern recognition and rule engines. Once an anomaly is detected, the system automatically triggers a security response, such as sending an alert, locking the account, or requesting secondary authentication, to ensure that attacks or illegal logins can be detected and stopped in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 It is a system architecture diagram of a computer remote login recognition device based on artificial intelligence proposed by the present invention;
[0064] Figure 2 It is a user device module architecture diagram of a computer remote login recognition device based on artificial intelligence proposed by the present invention;
[0065] Figure 3 It is an authentication and verification module architecture diagram of a computer remote login recognition device based on artificial intelligence proposed by the present invention;
[0066] Figure 4 It is a behavior analysis and risk assessment module architecture diagram of a computer remote login recognition device based on artificial intelligence proposed by the present invention;
[0067] Figure 5 It is a database and storage module architecture diagram of a computer remote login recognition device based on artificial intelligence proposed by the present invention;
[0068] Figure 6The architecture diagram of the security monitoring and alarm module of a computer remote login recognition device based on artificial intelligence proposed by the present invention;
[0069] Figure 7 The flowchart of a computer remote login recognition method based on artificial intelligence proposed by the present invention. Specific implementation manners
[0070] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0071] Embodiment 1
[0072] Referring to Figures 1-6 , in the first embodiment of the present invention, the present invention provides a computer remote login recognition device based on artificial intelligence, including:
[0073] A client device module, configured to collect biometric data and input behavior data of a user, and perform secure communication with a remote authentication server;
[0074] An authentication and verification module, configured to perform multi-modal identity authentication, dynamically adjust the authentication strategy, and detect abnormal behaviors;
[0075] A behavior analysis and risk assessment module, configured to analyze the behavior pattern and login environment of a user, evaluate the risk level, and optimize the authentication method;
[0076] A database and storage module, configured to store user identity information, behavior characteristic data, authentication logs, and be responsible for data security and compliance;
[0077] A security monitoring and alarm module, configured to monitor user login activities in real time, detect potential security threats, and trigger a security response mechanism.
[0078] Specifically, the computer remote login recognition device based on artificial intelligence significantly improves the security of remote login through multi-modal authentication and intelligent behavior analysis. The system combines multiple identity verification methods such as face recognition, fingerprint recognition, and voice recognition to ensure that even if one authentication method is breached, other authentication measures can still provide strong protection. At the same time, by analyzing the user's behavior patterns in real time, such as mouse trajectories, keyboard inputs, and device information, the system can accurately identify abnormal behaviors and evaluate the risk of login requests in combination with machine learning algorithms. According to the risk level, the system automatically adjusts the authentication strategy and enables more stringent verification steps in high-risk situations to ensure that the system can dynamically adapt to different security requirements. In addition, the system's automated security monitoring and abnormal behavior detection functions ensure that any potential threats can be detected and responded to in real time during the user login process, greatly enhancing the overall security protection ability.
[0079] The user device module includes:
[0080] The terminal device access unit supports PCs and mobile device terminals and uses the encryption protocols SSL / TLS for data communication;
[0081] The biometric data collection unit collects the user's multi-modal biometric features, including face, fingerprint, and voice data, and uses deep learning algorithms CNN or WaveNet for identity verification;
[0082] The user input behavior monitoring unit is used to monitor the user's mouse trajectory and keyboard input method in real time and analyze the behavior pattern using machine learning models SVM or KNN.
[0083] Specifically, the user device module is the interaction interface between the user and the system, responsible for collecting login data from the user device and securely transmitting it to the remote authentication server. This module not only supports the access of multiple devices but also ensures the security of data transmission through encrypted communication.
[0084] Beneficial effects:
[0085] Supports multi-platform access: This module can support the access of multiple devices, including PCs, mobile devices, tablet devices, etc. No matter which device the user logs in on, seamless identity verification can be carried out, which provides great convenience for users.
[0086] High security: Through the SSL / TLS encryption protocol, it ensures that the user's identity information and behavior data are not stolen or tampered with during the transmission process, improving the overall security of the system.
[0087] Multi-modal Authentication Support: By collecting various biometric data (such as face images, fingerprint information, voice data, etc.), the system can provide a powerful identity authentication function. This enables users to complete identity verification efficiently even in adverse environmental conditions (such as low-light environments, device failures, etc.).
[0088] Detailed Implementation:
[0089] Biometric Data Collection: Face recognition uses an algorithm based on deep convolutional neural network (CNN) to capture the user's facial features and perform comparisons. The fingerprint recognition module uses a high-precision sensor to collect fingerprint images and extracts feature points through the Minutiae algorithm to ensure the ability to identify fake fingerprints. Voice recognition uses a model trained based on deep learning (such as WaveNet or DeepSpeech) to obtain the user's voice features and can effectively handle the influence of background noise.
[0090] Input Behavior Collection: Real-time collection of the user's input behaviors, including mouse clicks, drag paths, keyboard input speeds, etc. These behaviors are monitored in real time through front-end code (such as JavaScript), and the data is uploaded to the server in an encrypted manner for subsequent analysis.
[0091] The Authentication and Verification Module Includes:
[0092] A multi-modal authentication unit that supports multiple authentication methods and can dynamically switch according to authentication failure situations, including automatically enabling fingerprint or voice recognition when face recognition fails;
[0093] A dynamic authentication policy unit that automatically adjusts the authentication policy based on the user's historical login behaviors, device information, and IP address data, using risk assessment models such as LSTM or decision trees, and forcibly enables multi-factor authentication (MFA) in high-risk situations;
[0094] An abnormal behavior detection unit that uses a behavior comparison algorithm to detect abnormal situations in the user's input habits and triggers a security alarm when an abnormality occurs.
[0095] Specifically, the authentication and verification module is responsible for accurately verifying the user's identity through multi-modal identity authentication and behavioral analysis data. This module intelligently combines the user's historical behaviors and real-time input behaviors to decide whether additional authentication is required.
[0096] Beneficial Effects:
[0097] Enhanced Security: By combining multiple biometric authentication methods (face, fingerprint, voice, etc.), the system can effectively prevent identity theft and forgery, improving the system's anti-attack ability.
[0098] Dynamic authentication policy: The authentication policy is based on user behavior analysis and device recognition, and can dynamically adjust the authentication strength. When the system detects a high-risk login, it can automatically require the user to perform secondary verification, improving login security.
[0099] Real-time anomaly recognition: This module is based on a behavior analysis model, can identify abnormal behavior patterns in real time, and respond to prevent malicious attackers from bypassing security protection using weak authentication.
[0100] Detailed implementation:
[0101] Multi-modal authentication: When the user logs in, the system first attempts face recognition. If it fails, it switches to fingerprint recognition or voice recognition for secondary authentication. When the user uses an unregistered device or is in an unfamiliar environment, the system will require the user to enter a verification code as the final verification method.
[0102] Dynamic authentication policy: The authentication module dynamically adjusts the authentication process by evaluating the user's login historical data (such as device usage frequency, common login times and locations, etc.), combined with a risk scoring algorithm. For example, when there are significant changes in the time and location of the user's login, the system will automatically increase the authentication steps, requiring the input of a dynamic verification code or confirmation of the user's identity through SMS verification.
[0103] Abnormal behavior detection: This module is based on the user input data collected in real time, combined with historical behavior patterns, and uses machine learning algorithms (such as KNN, SVM) to detect whether there are abnormalities in the user's behavior. When an abnormal login behavior is found, the system will require the user to complete secondary authentication or directly reject the login request.
[0104] The behavior analysis and risk assessment module includes:
[0105] The user behavior analysis unit constructs a personalized behavior model based on the user's mouse movement and keyboard input habits, and performs behavior matching through K-means clustering and random forest algorithms;
[0106] The login environment analysis unit evaluates the security of the login request by detecting the IP address, device fingerprint, and network environment;
[0107] The risk assessment decision unit calculates the risk score by combining the user behavior data and environmental parameters, classifies the risk using a neural network or decision tree, and automatically determines the authentication level.
[0108] Specifically, the task of this module is to evaluate the risk level of the login request by analyzing the user's behavior patterns and environmental data, and accordingly adjust the authentication policy. Through learning historical behaviors and analyzing real-time data, the system can automatically adjust the login authentication process according to the risk situation.
[0109] Beneficial effects:
[0110] Intelligent behavior analysis: This module can continuously learn the user's behavior patterns and automatically identify the differences between normal and abnormal behaviors, thereby better evaluating the security of login requests. Compared with traditional static rule-based security checks, behavior analysis is more flexible and intelligent.
[0111] Real-time risk assessment: By analyzing the user's behavior characteristics (such as keyboard input rhythm, mouse click frequency, device information, etc.) and login environment (such as IP address, device fingerprint, etc.) in real time, the system can timely evaluate the risk of login behavior and ensure the security of the login process.
[0112] Adaptive learning: The system will continuously optimize the risk assessment model based on new behavior data and feedback information, so that the system can adapt to the user's behavior changes over time and reduce false positives and false negatives.
[0113] Detailed implementation:
[0114] User behavior modeling: By collecting the user's daily behavior data, such as login time, login frequency, used devices, etc., a behavior model is created for each user using a clustering algorithm (such as K-means). When the user logs in, the system will compare the current behavior with the historical data to evaluate the security of the login request.
[0115] Risk assessment: Calculate the risk score by combining multiple factors (such as device fingerprint, IP address, login geographical location, etc.). The system uses a deep neural network (such as LSTM) to analyze the behavior pattern and automatically adjusts the authentication policy according to the risk score. For example, if the risk score is high, the system will automatically increase the verification steps (such as multi-factor authentication).
[0116] The database and storage module includes:
[0117] User information storage unit, which stores the user's identity information and biometric data using AES-256 encryption to ensure data security;
[0118] Behavior data storage unit, which records the user's historical login behavior and device information and uses distributed storage technology to provide efficient query capabilities;
[0119] Authentication log storage unit, which stores the detailed logs of remote logins, supports access auditing, and complies with the GDPR and ISO27001 security compliance requirements.
[0120] Specifically, this module is used to store the user's identity information, behavior characteristic data, authentication logs, etc., and protects the user's privacy data through encryption. All data is stored encrypted to ensure security during storage.
[0121] Beneficial effects:
[0122] Data security guarantee: Protect the stored sensitive information through AES-256 encryption technology, ensuring that user data is in an encrypted state in the database. Even if the data is leaked, it cannot be directly accessed.
[0123] Efficient storage and retrieval: Through distributed database technologies (such as MongoDB, Elasticsearch), this module can support efficient data storage and fast query, and can handle the concurrent access requirements of a large amount of user data.
[0124] Compliance guarantee: The database design follows data protection regulations such as GDPR, ensuring that privacy protection requirements are met when storing and processing user data, and avoiding data leakage and abuse.
[0125] Detailed implementation:
[0126] Encrypted storage: Encrypt and store all sensitive information such as user identity information and behavior data through the AES-256 encryption algorithm. Even if the database is attacked, the data cannot be directly decrypted and read.
[0127] Distributed storage and retrieval: Use distributed database technologies such as MongoDB to store user data, supporting efficient query and indexing mechanisms. When administrators or the system need to quickly access historical behavior data, they can quickly retrieve and analyze it through Elasticsearch.
[0128] The security monitoring and alarm module includes:
[0129] The monitoring engine unit, which uses a streaming data processing framework to monitor user login behavior data in real time;
[0130] The abnormal alarm system unit, which detects abnormal situations based on a rule engine and automatically triggers an alarm mechanism when risks are detected, including sending security notifications or locking accounts;
[0131] The security response module, which provides an automatic blocking function, can automatically reject access or require additional verification after detecting abnormal logins according to preset policies, and supports manual intervention.
[0132] Specifically, this module monitors user login behavior in real time, detects and responds to potential security threats. Through an automated alarm mechanism, it can take immediate action when detecting high-risk logins, reducing manual intervention and improving the system's response speed.
[0133] Beneficial effects:
[0134] Real-time security monitoring: By monitoring users' login activities and behaviors in real time, the system can immediately detect potential security issues and reduce the response time for security incidents.
[0135] Automated response: This module can automatically execute response actions according to preset security rules, trigger alarms, and activate protection mechanisms, reducing the need for manual intervention.
[0136] Improve the emergency response speed: When the system detects a high-risk login, it can automatically trigger an emergency response process (such as account locking, two-factor authentication, etc.) to ensure that the remote login system can take prompt measures when security issues occur.
[0137] Detailed implementation:
[0138] Streaming data processing: Using streaming data processing technologies such as Apache Kafka, the system can monitor each user login activity in real time, capture abnormal behavior data, and process it immediately.
[0139] Alarm mechanism: Based on rule engines such as Drools, the monitoring module can automatically trigger the alarm mechanism. When the system detects login behaviors that do not meet expectations, it will notify the administrator via email, SMS, etc., and can automatically trigger security responses such as account freezing and two-factor authentication.
[0140] The abnormal behavior detection unit includes the following specific steps:
[0141] S1: Collect users' behavior data through the client device, including mouse trajectories, keyboard inputs, and device information, and extract corresponding feature data;
[0142] Mouse trajectory data includes the mouse's movement speed, click position, click frequency, and drag path length;
[0143] Keyboard input data includes input speed, key press frequency, key press interval time, and input mode;
[0144] Device information includes device type, operating system, and device fingerprint;
[0145] S2: Establish the user's behavior pattern, compare the current behavior data with the historical behavior pattern, and calculate the behavior difference;
[0146] Generate the user's behavior benchmark pattern by calculating the mean and standard deviation of the user's historical behavior data;
[0147] Calculate the similarity between the current mouse trajectory and the historical behavior through the dynamic time warping algorithm. If the similarity is lower than the set threshold, the mouse behavior is considered abnormal;
[0148] Analyze the rhythm of keyboard input through a time-based comparison algorithm to evaluate the deviation of the current input behavior from the historical pattern;
[0149] S3: Evaluate the behavior differences using statistical methods, machine learning methods, or time series analysis methods to detect whether there are abnormal behaviors;
[0150] Use the Z-score method to calculate the standard deviation between the user's current behavior and historical behavior. If the Z-score value of the current behavior exceeds the preset range, it is determined as an abnormal behavior;
[0151] Analyze the differences between the current behavior data and the normal behavior model using support vector machines or random forest algorithms. If the model identifies it as abnormal, report it as an abnormal behavior;
[0152] Use long short-term memory networks to analyze time series data to detect whether there are significant time intervals or behavioral mutations;
[0153] S4: When abnormal behaviors are detected, take corresponding security response measures according to the degree of abnormality, including triggering an alarm, requiring secondary verification, or locking the account;
[0154] For mild abnormalities, including slightly inconsistent input speeds, trigger an alarm and request the user to perform an additional authentication;
[0155] For moderate abnormalities, including device changes or location changes, require the user to perform secondary verification;
[0156] For severe abnormalities, including logins from new devices or logins that are severely inconsistent with historical behaviors, automatically lock the account and notify the administrator for manual intervention;
[0157] S5: Real-time feedback the abnormal detection results, and update the user's behavior pattern according to the feedback data to improve the accuracy of subsequent abnormal detections;
[0158] Compare the user's feedback behavior with the detection results, and automatically adjust and optimize the user behavior model to adapt to the new normal behavior pattern and improve the detection accuracy.
[0159] Specifically, 1. Data collection and feature extraction
[0160] The first step in abnormal behavior detection is to collect behavior data from the user's device, mainly including but not limited to the following aspects:
[0161] Mouse behavior:
[0162] Record the user's mouse movement trajectory, click frequency, click position, drag behavior, etc.
[0163] Feature extraction: Use the time window method to segment the mouse trajectory and extract statistical features of user behavior (such as average click speed, click preference area, drag path length, etc.).
[0164] Keyboard input behavior:
[0165] Record the keyboard input content of the user during the login process, including input speed, key press frequency, input time interval, etc.
[0166] Feature extraction: Use the dynamic time warping (DTW) algorithm to calculate the similarity of the user's keyboard input and extract the rhythm features of the user's input (such as input frequency, enter frequency, frequently used keys, etc.).
[0167] User device behavior:
[0168] Monitor the user's login device information, such as device fingerprint, operating system, browser type, etc.
[0169] Feature extraction: Analyze the changes in the user's device, such as whether the system settings of the device have changed, or whether a new browser or operating system version has been used.
[0170] 2. Behavior pattern establishment and comparison with historical data
[0171] To achieve anomaly detection, the system needs to first model the user's behavior pattern and compare it with historical data:
[0172] User behavior modeling:
[0173] Behavior learning: Adopt machine learning algorithms (such as K-means clustering or hidden Markov model HMM) to learn the user's historical behavior and generate a personalized behavior model for the user. The model can include statistical features such as the user's login duration, login frequency, access time period, etc.
[0174] Behavior feature vector: Convert behavior data such as mouse trajectory, keyboard input, and device information into multi-dimensional feature vectors to establish a feature space for the user's behavior pattern.
[0175] Historical data comparison:
[0176] When the user logs in, the system will compare the data of the current login behavior with the historical behavior pattern. If the difference between the current behavior and the historical behavior exceeds the set threshold, the system will consider this behavior may be abnormal.
[0177] 3. Anomaly behavior detection algorithm
[0178] Once the data collection and pattern establishment are completed, the system will use the following algorithm for anomaly behavior detection:
[0179] Anomaly Detection Based on Statistical Methods:
[0180] By calculating statistics such as the mean and variance of user behavior, and combining statistical detection methods (such as Z-score, Grubbs test) to evaluate the degree of anomaly of behavior. For example, when the occurrence frequency of certain behaviors is significantly different from the historical behavior statistics, it may indicate that this behavior is abnormal.
[0181] Anomaly Detection Based on Machine Learning:
[0182] Supervised Learning Method: Using labeled normal behavior data and abnormal behavior data to train a classification model (such as decision tree, random forest, support vector machine SVM) to identify abnormal behaviors.
[0183] Unsupervised Learning Method: Adopting K-means clustering or isolation forest algorithm to analyze whether the current behavior is significantly different from the existing group behavior pattern to determine whether it is an abnormal behavior. For example, when the user's device for logging in suddenly changes and there is no preset change pattern, the system will consider the login behavior as abnormal.
[0184] Anomaly Detection Based on Time Series:
[0185] Using time series analysis algorithms (such as dynamic time warping DTW, long short-term memory network LSTM) to analyze the time series data of user behavior and detect time change patterns that do not match the normal behavior pattern. For example, if the user's keyboard input speed changes abnormally or the login time does not match the historical login behavior, the system will consider this behavior as abnormal.
[0186] 4. Anomaly Behavior Judgment and Response
[0187] When detecting that the user's behavior is abnormal, the system will take different response measures according to the degree of anomaly:
[0188] Mild Abnormal Behavior:
[0189] When the abnormal behavior detected by the system is relatively mild (such as abnormal mouse trajectory or slight change in input pattern), the system will prompt the user to perform additional identity verification, such as requiring to enter a one-time dynamic verification code, perform face recognition or other secondary verifications.
[0190] Moderate Abnormal Behavior:
[0191] For moderately abnormal behaviors (such as device changes or geographical location anomalies), the system will automatically send an alarm to the administrator and require further verification, and may require the user to use different authentication methods (such as fingerprint or voice recognition) for verification.
[0192] Severe Abnormal Behavior:
[0193] When the system detects serious abnormal behaviors (such as login requests from unknown devices, login times that are completely different from historical behaviors, etc.), the system will trigger the automatic locking of the account and notify the administrator, and may temporarily freeze the account until the administrator confirms the user's identity.
[0194] 5. Abnormal Behavior Monitoring and Feedback Mechanism
[0195] To improve the intelligence and accuracy of the system, the abnormal behavior detection unit will continuously optimize the model and feedback mechanism:
[0196] Real-time Feedback Mechanism:
[0197] The detection result of each behavior will be fed back to the user in real time. If the abnormal behavior fails to pass the verification, the system will record the behavior and analyze its causes to improve the model.
[0198] Model Adaptive Update:
[0199] The system will continuously adjust the user behavior model according to the feedback data, update the user's behavior pattern through machine learning algorithms, and ensure that the system can accurately capture new types of abnormal behaviors. For example, if the user's behavior has changed significantly in the long term, the system will gradually adapt to these new behavior patterns.
[0200] Embodiment 2:
[0201] Refer to Figure 7 In the second embodiment of the present invention, the present invention provides a computer remote login recognition method based on artificial intelligence, including the following steps:
[0202] S1. The user terminal device module collects the user's biometric data and input behavior data. The biometric data includes face images, fingerprint information or voice data, and the input behavior data includes mouse trajectories, keyboard input patterns and device information, and encrypts and transmits the data to the remote authentication server through the SSL / TLS protocol;
[0203] S2. The authentication and verification module performs multi-modal authentication on the user's identity, adjusts the authentication strategy based on the user's login history, device information and geographical location, analyzes the input behavior pattern using machine learning algorithms, and determines whether there is an abnormality;
[0204] S3. The behavior analysis and risk assessment module calculates the user's behavior deviation degree, compares the current behavior with the historical behavior pattern using the dynamic time warping method, calculates the comprehensive risk score in combination with time series analysis, and decides whether additional authentication measures are required;
[0205] S4. The database and storage module store user identity information, behavior characteristic data, and authentication logs, use AES-256 encryption to protect sensitive data, and support efficient queries and historical behavior comparison through a distributed database;
[0206] S5. The security monitoring and alarm module monitors the remote login process in real time, uses a rule engine to detect abnormal behaviors, and automatically triggers security responses when high-risk logins are detected, including sending alerts and requiring users to perform secondary identity verification or locking accounts.
[0207] Specifically, the user device and data collection
[0208] Device access: When employees are at home or out, they use devices such as personal computers or smartphones to access the enterprise internal system. The device communicates with the enterprise server through the TCP / IP protocol.
[0209] Biometric data collection: After the system starts, the user first uses face recognition for identity verification. If the face recognition is successful, the system directly allows the user to log in; if it fails, the system will automatically switch to fingerprint recognition or voice recognition for the second authentication. At this time, the fingerprint recognition sensor collects the user's fingerprint, and the voice recognition collects the user's voice through the microphone for comparison.
[0210] Behavior data collection: During the user's login process, the system will simultaneously collect the user's behavior data in real time, including mouse trajectories, keyboard input patterns, click frequencies, etc. All this data will be encrypted and transmitted to the remote authentication server.
[0211] Authentication and verification
[0212] Multi-modal identity authentication: First, the system performs face recognition on the user, uses a deep convolutional neural network (CNN) to extract facial features and compares them with the stored data in the database. If the recognition is successful, the authentication is passed; if it fails, the system will automatically enable fingerprint or voice recognition for secondary authentication.
[0213] Dynamic authentication strategy: The system adjusts the dynamic authentication strategy by analyzing the user's historical login data (such as historical devices, login times, geographical locations, etc.). If the user has never logged in at a certain location or uses a new device, the system will increase the authentication intensity, such as requiring the input of a text message verification code or ensuring identity through other multi-factor authentication means.
[0214] Behavior analysis and risk assessment
[0215] User Behavior Modeling and Evaluation: The system automatically builds and updates the user behavior model every time the user logs in. By analyzing the user's mouse trajectory, keyboard input pattern, input time interval and other behavior data, the system can identify the user's personalized login characteristics. For example, which shortcut keys the user often uses when logging in, or whether the input speed and frequency are consistent with usual.
[0216] Risk Assessment and Decision-making: The system uses a Long Short-Term Memory network (LSTM) to analyze the behavior data during the user's login, and compares the current behavior with the historical data to evaluate the risk of the login request. If the system finds a large deviation between the user's current behavior and historical behavior, it generates a risk score and decides whether additional authentication is required. For example, when the user logs in from an uncommon geographical location, the system will automatically enhance the authentication policy and require multi-factor authentication (such as voice verification, SMS verification code, etc.).
[0217] Abnormal Behavior Detection
[0218] Real-time Abnormal Monitoring: During the user's login process, the system will monitor the user's behavior in real time. If there are obvious abnormalities when the user enters the password (for example, frequently clicking the wrong keys, or the keyboard input speed is too fast), the system will identify it as abnormal behavior.
[0219] Trigger Alarm Mechanism: If the system detects abnormal behavior, such as inconsistent mouse trajectory, inconsistent input habits with history, etc., the system will automatically generate an alarm and trigger a security response. The system will require the user to perform a second verification (such as a verification code sent via SMS or email) to confirm the identity.
[0220] Automatic Response and Protection: When the system discovers high-risk abnormal behavior (such as login from an unauthorized device, login from an unfamiliar IP address, etc.), it will immediately lock the account and notify the system administrator for manual intervention. If it is judged as a malicious attack, the system can temporarily freeze the account and require the administrator to conduct further investigation.
[0221] Database and Storage
[0222] Storage and Encryption: All users' biometric data, behavior data, and authentication logs will be encrypted and stored in a secure database. The database uses the AES-256 encryption standard to protect sensitive information, ensuring that even in the event of a data breach, attackers cannot directly access the user's private data.
[0223] Efficient Query and Backup: The system uses a distributed database (such as MongoDB) to store user behavior data and authentication logs, which can maintain the efficiency of data access and storage under high concurrency. The regular backup mechanism ensures that the system can be restored in case of data corruption or loss.
[0224] Security Monitoring and Alarm
[0225] Real-time Monitoring: The system continuously monitors the user's login activities and analyzes the security of login requests through a rule engine (such as Drools). Any detected abnormal or high-risk behavior will immediately trigger an alarm.
[0226] Alarm and Response: When a serious security issue is detected (e.g., multiple failed login attempts, abnormal logins from different geographical locations, etc.), the system will send a notification to the administrator, take automatic blocking actions, or request the administrator to perform manual verification.
[0227] Implementation Effect
[0228] Through this embodiment, the enterprise can effectively ensure the security of employees' logins in any remote environment. Multimodal authentication, behavior analysis, and abnormal behavior detection effectively improve the accuracy of authentication and can monitor and respond to potential security threats in real time. The system is highly intelligent, can automatically adapt to changes in users' login habits, dynamically adjust the authentication strategy, improve the user's login experience while ensuring security. In addition, the encryption measures for the database and storage module ensure the privacy and security of user data and comply with data privacy protection requirements such as GDPR.
[0229] Embodiment 3
[0230] In the third embodiment of the present invention, based on the same inventive concept, a computer-readable storage medium is proposed. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of the computer remote login recognition method based on artificial intelligence in the above embodiment.
[0231] Embodiment 4
[0232] In the fourth embodiment of the present invention, based on the same inventive concept, a computer device is proposed. The terminal includes: a processor and a memory; the processor and the memory communicate with each other; the memory is used to store instructions; the processor is used to execute the instructions in the memory and implement the computer remote login recognition method based on artificial intelligence in the above embodiment.
[0233] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one of the following techniques known in the art or a combination thereof can be used: discrete logic circuits having logic gate circuits for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0234] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A computer remote login recognition device based on artificial intelligence, characterized in that: include: The user terminal device module is used to collect the user's biometric data and input behavior data and communicate securely with the remote authentication server; Authentication and verification module, which is used to perform multi-modal identity authentication, dynamically adjust authentication strategies, and detect abnormal behavior; Behavior analysis and risk assessment module, which is used to analyze user behavior patterns and login environments, assess risk levels and optimize authentication methods; Database and storage module, used to store user identity information, behavioral characteristic data, authentication logs, and responsible for data security and compliance; The security monitoring and alarm module is used to monitor user login activities in real time, detect potential security threats, and trigger security response mechanisms.
2. The computer remote login recognition device based on artificial intelligence according to claim 1 is characterized in that: The user terminal equipment module comprises: Terminal device access unit, supports PC and mobile device terminals, and uses encryption protocol SSL / TLS for data communication; Biometric data collection unit, which collects multimodal biometric features of users, including face, fingerprint and voice data, and uses deep learning algorithms CNN or WaveNet for identity authentication; The user input behavior monitoring unit is used to monitor the user's mouse trajectory and keyboard input method in real time, and use machine learning models SVM or KNN to analyze behavior patterns.
3. The computer remote login recognition device based on artificial intelligence according to claim 1 is characterized in that: The authentication and verification module includes: Multimodal authentication unit, which supports multiple authentication methods and can dynamically switch based on authentication failures, including automatically enabling fingerprint or voice recognition when face recognition fails; Dynamic authentication policy unit, based on user historical login behavior, device information and IP address data, uses risk assessment model LSTM or decision tree to automatically adjust authentication policy and force multi-factor authentication MFA to be enabled in high-risk situations; The abnormal behavior detection unit uses a behavior comparison algorithm to detect abnormalities in user input habits and triggers a security alarm when an abnormality occurs.
4. The computer remote login recognition device based on artificial intelligence according to claim 1 is characterized in that: The behavior analysis and risk assessment module includes: The user behavior analysis unit builds a personalized behavior model based on the user's mouse track and keyboard input habits, and performs behavior matching through K-means clustering and random forest algorithms; Login environment analysis unit, which evaluates the security of login requests by detecting IP addresses, device fingerprints, and network environments; The risk assessment decision unit combines user behavior data and environmental parameters to calculate the risk score, uses a neural network or decision tree to classify the risk, and automatically determines the certification level.
5. According to the artificial intelligence-based computer remote login recognition device of claim 1, it is characterized in that: The database and storage module include: The user information storage unit uses AES-256 encryption to store user identity information and biometric data, responsible for data security; Behavior data storage unit, which records the user's historical login behavior and device information, and uses distributed storage technology to provide efficient query capabilities; Certified log storage unit that stores detailed logs of remote logins, supports access auditing, and meets GDPR and ISO27001 security compliance requirements.
6. The computer remote login recognition device based on artificial intelligence according to claim 1 is characterized in that: The security monitoring and alarm module includes: The monitoring engine unit uses a streaming data processing framework to monitor the user's login behavior data in real time; The abnormal alarm system unit detects abnormal situations based on the rule engine and automatically triggers the alarm mechanism when risks are detected, including sending security notifications or locking accounts; The security response module provides automatic blocking functions, which can automatically deny access or require additional verification after detecting abnormal logins based on preset policies, and supports manual intervention.
7. The computer remote login recognition device based on artificial intelligence according to claim 3 is characterized in that: The abnormal behavior detection unit includes the following specific steps: S1: Collect user behavior data through the user terminal device, including mouse trajectory, keyboard input and device information, and extract corresponding feature data; The mouse trajectory data includes the mouse movement speed, click position, click frequency and drag path length; The keyboard input data includes input speed, key frequency, key interval time and input mode; The device information includes device type, operating system and device fingerprint; S2: Establish the user's behavior pattern, compare the current behavior data with the historical behavior pattern, and calculate the behavior difference; Generate a user's behavioral benchmark pattern by calculating the mean and standard deviation of the user's historical behavior data; The dynamic time warping algorithm is used to calculate the similarity between the current mouse trajectory and the historical behavior. If the similarity is lower than the set threshold, the mouse behavior is considered abnormal. Analyze the rhythm of keyboard input through a time-based comparison algorithm to evaluate the deviation of current input behavior from historical patterns; S3: Use statistical methods, machine learning methods, or time series analysis methods to evaluate behavioral differences and detect whether there are abnormal behaviors; The Z-score method is used to calculate the standard deviation between the user's current behavior and historical behavior. If the Z-score value of the current behavior exceeds the preset range, it is considered abnormal behavior. Use support vector machine or random forest algorithm to analyze the difference between current behavior data and normal behavior model. If the model identifies it as abnormal, it will be reported as abnormal behavior. Use long short-term memory networks to analyze time series data to detect whether there are significant time intervals or behavioral mutations; S4: When abnormal behavior is detected, appropriate security response measures are taken according to the degree of abnormality, including triggering an alarm, requiring secondary verification, or locking the account; For minor anomalies, including slightly inconsistent input speed, an alert is triggered and the user is asked to perform an additional authentication; For moderate anomalies, including device changes or geographic location changes, users are required to perform secondary verification; For serious anomalies, including logins from new devices or logins that are seriously inconsistent with historical behavior, the account is automatically locked and the administrator is notified for manual intervention; S5: Provide real-time feedback on anomaly detection results and update user behavior patterns based on the feedback data to improve the accuracy of subsequent anomaly detection; Compare the user's feedback behavior with the detection results, automatically adjust and optimize the user behavior model to adapt to the new normal behavior pattern and improve detection accuracy.
8. A computer remote login recognition method based on artificial intelligence, characterized in that: The computer remote login recognition device based on artificial intelligence used in any one of claims 1 to 7 comprises the following steps: S1. The user terminal device module collects the user's biometric data and input behavior data, the biometric data includes face image, fingerprint information or voice data, and the input behavior data includes mouse track, keyboard input mode and device information, and encrypts and transmits the data to the remote authentication server through the SSL / TLS protocol; S2. The authentication and verification module performs multi-modal authentication on the user's identity, adjusts the authentication strategy based on the user's login history, device information, and geographic location, and uses machine learning algorithms to analyze input behavior patterns to determine whether there are any anomalies; S3. The behavior analysis and risk assessment module calculates the user's behavior deviation, uses the dynamic time warping method to compare the current behavior with the historical behavior pattern, combines time series analysis to calculate the comprehensive risk score, and determines whether additional authentication measures are needed; S4, the database and storage module store user identity information, behavior feature data and authentication logs, use AES-256 encryption to protect sensitive data, and support efficient query and historical behavior comparison through a distributed database; S5. The security monitoring and alarm module monitors the remote login process in real time and uses the rule engine to detect abnormal behavior. When a high-risk login is detected, a security response is automatically triggered, including sending an alarm and requiring the user to perform secondary identity authentication or lock the account.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the computer remote login recognition method based on artificial intelligence as described in claim 8 is implemented.
10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by the processor, the computer remote login recognition method based on artificial intelligence as claimed in claim 8 is implemented.
Citation Information
Cited By
Method and system for preventing mobile phone number card fraud
CN120640284A
Login authentication method and device and computer readable storage medium
CN120658520A
Security event early warning and response method based on operator-level network
CN120710781A
Intelligent verification code system and method based on multi-mode dynamic context awareness
CN120892883A
Electronic fence control method and system based on multi-mode identity authentication
CN121151079A