Abnormal behavior analysis method and device

Through an abnormal behavior analysis method, the encryption and offline processing of log data, combined with the data transmission of message queues, the problem of identifying and preventing information leakage risks is solved, and efficient, safe and flexible information security analysis is achieved.

CN120223380APending Publication Date: 2025-06-27BEIJING BAIGEFEICHI TECH LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510338075.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

It is difficult for the existing technology to effectively identify and prevent information leakage caused by employees due to excessive authority in the field of information security, and the data leakage prevention system has problems such as difficulty in promoting, deep technical accumulation, affecting equipment performance and handling false alarms.

Method used

A method of abnormal behavior analysis is proposed. By obtaining log data, processing data according to preset encryption and offline processing rules, the second data is generated, and abnormal behavior analysis is performed based on the data. The method includes obtaining log data, encryption processing, offline processing and abnormal behavior analysis, using message queues for data transmission, and realizing decoupling between modules.

Benefits of technology

It realizes accurate and efficient analysis of employee abnormal behavior, ensures data security, reduces costs, improves the scalability and operability of the system, strengthens privacy protection, and improves the flexibility of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223380A_ABST
    Figure CN120223380A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal behavior analysis method and device. The method comprises the steps of obtaining log data; processing the log data according to a preset data encryption rule to obtain first data; processing the first data according to a preset data offline processing rule to obtain second data; and in response to an abnormal behavior analysis request, subscribing and analyzing target data based on the second data to determine an abnormal behavior analysis result. And the efficiency and accuracy of abnormal behavior analysis are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular, to an abnormal behavior analysis method and device. Background Art

[0002] This section aims to provide background or context for the embodiments of the present application described in the claims. The descriptions herein are not considered prior art merely because they are included in this section.

[0003] In the information age, enterprise information security has become a key challenge in operation. Although the popularization of cloud computing, big data, and Internet technologies has improved the convenience of internal network systems, it has also increased the risk of information leakage. Employees may intentionally or unintentionally leak sensitive information due to greater permissions, which causes economic losses to the enterprise and damages its reputation and customer trust.

[0004] To address this issue, the industry widely adopts a data loss prevention (DLP) system, installing a client on employees' devices to monitor and detect sensitive data transmission. However, this method has problems such as great difficulty in promotion, relying on deep technical accumulation, affecting device performance, and handling false alarms.

[0005] Another relatively simple method is to identify abnormal behaviors by analyzing logs, such as monitoring the interface access frequency. However, this method also faces challenges such as employee information exposure, inability to directly perform logical processing (such as IP location requires calling internal services), and lack of intuitiveness for operation personnel.

[0006] Based on this, this application urgently needs to propose an abnormal behavior analysis method and device that can solve the above technical problems. Summary of the Invention

[0007] Multiple aspects of this application provide an abnormal behavior analysis method and device for accurately and efficiently analyzing the abnormal behaviors of enterprise users.

[0008] In one aspect of this application, an abnormal behavior analysis method is provided, and the method includes:

[0009] Obtain log data;

[0010] Process the log data according to a preset data encryption rule to obtain first data;

[0011] Process the first data according to a preset data offline processing rule to obtain second data;

[0012] In response to an abnormal behavior analysis request, subscribe to and analyze target data based on the second data to determine the abnormal behavior analysis result.

[0013] Further, the obtaining of the log data includes: in response to a data acquisition request, obtaining behavior data and the interaction mode of the behavior data; and taking the behavior data with the interaction mode being internal interaction as the log data.

[0014] Further, processing the first data according to a preset data offline processing rule to obtain second data includes: converting the first data into offline data according to a preset format conversion rule; aggregating the first data according to a preset data aggregation rule to determine aggregated data; filtering the first data according to a preset data filtering rule to determine filtered data; perfecting the first data according to a preset field perfection rule to determine perfected data; and obtaining the second data based on at least one of the offline data, the aggregated data, the filtered data, and the perfected data.

[0015] Further, converting the first data into offline data according to a preset format conversion rule includes: converting the first data into the json format in a segmented form; or, aggregating the first data according to a preset data aggregation rule to determine aggregated data includes: obtaining the same first data within a preset time period and aggregating the same first data to determine aggregated data.

[0016] Further, filtering the first data according to a preset data filtering rule to determine filtered data includes: based on the first data, obtaining the request source and the access object; based on the request source, retaining the first data with the request source being a private Internet protocol address; and based on the access object, retaining the first data with the access object being a front-end resource file and / or the network resource identifier being in the white list as the filtered data.

[0017] Further, when processing the first data according to a preset data offline processing rule to obtain second data, the method further includes: processing the first data according to a preset offline processing rule to obtain second data; generating data features based on the second data, and publishing the second data and its data features to a second queue; where the data features include at least one of wireless network access users, system user names, file names, file sizes, and access times.

[0018] On the other hand, the present application provides an abnormal behavior analysis device, which includes:

[0019] An obtaining unit for obtaining log data;

[0020] A first processing unit for processing the log data according to a preset data encryption rule to obtain first data;

[0021] A second processing unit for processing the first data according to a preset data offline processing rule to obtain second data;

[0022] A response analysis unit, configured to subscribe to and analyze target data based on the second data in response to an abnormal behavior analysis request to determine an abnormal behavior analysis result.

[0023] In another aspect of the present application, there is provided an electronic device, including: at least one processor; and

[0024] A memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the abnormal behavior analysis method as described above.

[0025] In yet another aspect of the present application, there is provided a computer-readable medium, on which computer program instructions are stored, and the computer program instructions can be executed by a processor to implement the abnormal behavior analysis method as described above.

[0026] In yet another aspect of the present application, there is provided a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, it implements the abnormal behavior analysis method as described above.

[0027] An abnormal behavior analysis method and device proposed by the present application. The abnormal behavior analysis method includes obtaining log data; processing the log data according to a preset data encryption rule to obtain first data; processing the first data according to a preset data offline processing rule to obtain second data; in response to an abnormal behavior analysis request, subscribing to and analyzing target data based on the second data to determine an abnormal behavior analysis result. The abnormal behavior analysis method proposed by the present application ensures the security, low cost, high scalability and operability of employee data. It adopts a three-stage processing method of a log system, real-time processing and offline processing, and uses a message queue for data transmission to achieve decoupling between modules. This design not only ensures the timeliness of data processing and the operability of the system, but also strengthens privacy protection and improves the flexibility of the system. Through the abnormal behavior analysis method proposed by the present application, enterprises can more effectively prevent and control the risk of internal information leakage and comprehensively ensure information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.

[0029] Other features, objects, and advantages of the present application will become more apparent from the following detailed description of non - limiting embodiments read in conjunction with the accompanying drawings:

[0030] Figure 1 Schematic flowchart of an abnormal behavior analysis method provided for an embodiment of the present application;

[0031] Figure 2 Schematic structural diagram of an abnormal behavior analysis architecture provided for an embodiment of the present application;

[0032] Figure 3 Schematic structural diagram of an abnormal behavior analysis device provided for another embodiment of the present application;

[0033] Figure 4 Schematic structural diagram of an electronic device suitable for implementing the solution in the embodiments of the present application;

[0034] Identical or similar reference numerals in the drawings represent identical or similar components. Detailed implementation manners

[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0036] In a typical configuration of the present application, devices of a terminal and a service network both include one or more processors (CPUs), an input / output interface, a network interface, and a memory.

[0037] The memory may include non - permanent memory in a computer - readable medium, random access memory (RAM), and / or forms of non - volatile memory such as read - only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer - readable medium.

[0038] A computer-readable medium includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer program instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0039] An embodiment of the present application provides an abnormal behavior analysis method, which includes:

[0040] Step S1, obtain log data;

[0041] Step S2, process the log data according to a preset data encryption rule to obtain first data;

[0042] Step S3, process the first data according to a preset data offline processing rule to obtain second data;

[0043] Step S4, in response to an abnormal behavior analysis request, subscribe to and analyze target data based on the second data to determine the abnormal behavior analysis result.

[0044] In an actual scenario, the execution subject of this method can be a user device, or a device formed by integrating a user device and a network device through a network, or it can also be an application program running on the above device. The user device includes, but is not limited to, various terminal devices such as computers, mobile phones, tablets, smart watches, and bracelets. The network device includes, but is not limited to, network hosts, single network servers, multiple network server sets, or computer collections based on cloud computing, etc., which can be used to implement some processing functions when setting an alarm. Here, the cloud is composed of a large number of hosts or network servers based on cloud computing (CloudComputing). Among them, cloud computing is a type of distributed computing, consisting of a virtual computer formed by a group of loosely coupled computer sets.

[0045] Embodiment 1

[0046] Figure 1 Shows the processing flow of an abnormal behavior analysis method provided by an embodiment of the present application. The abnormal behavior analysis method is based on an abnormal behavior analysis architecture as shown in Figure 2 The method at least includes the following processing steps:

[0047] Step S1, obtain log data;

[0048] Step S2, process the log data according to a preset data encryption rule to obtain first data;

[0049] Step S3, process the first data according to a preset data offline processing rule to obtain second data;

[0050] Step S4, in response to an abnormal behavior analysis request, subscribe to and analyze target data based on the second data to determine an abnormal behavior analysis result.

[0051] The account sharing warning architecture includes a log unit, a first message queue, a real-time processing unit, a second message queue, an offline task unit, and a display unit (report module and observation module) connected in sequence; specifically, after the log unit obtains log data in real time, it publishes the intranet data to the first message queue. The real-time processing unit subscribes to the intranet data of the first message queue, performs logical processing, and then sends it to the second message queue. The offline task unit, in response to an account sharing warning request, obtains the data of the second message queue from the second message queue according to a preset rule and sends it to the display unit for display so that the operation and maintenance personnel can observe.

[0052] In one embodiment, the obtaining of the log data includes: in response to a data obtaining request, obtaining behavior data and the interaction mode of the behavior data; the behavior data with the interaction mode of internal interaction is the log data.

[0053] Specifically, the interaction modes of the behavior data include internal interaction and external interaction. At the log data generation stage, the behavior data is shunted to optimize the data flow from the gateway log to the big data platform, ensuring the efficient transmission and storage of the behavior data.

[0054] In one embodiment, processing the first data according to a preset data offline processing rule to obtain second data includes: converting the first data into offline data according to a preset format conversion rule; aggregating the first data according to a preset data aggregation rule to determine aggregated data; filtering the first data according to a preset data filtering rule to determine filtered data; perfecting the first data according to a preset field perfection rule to determine perfected data; obtaining second data based on at least one of the offline data, the aggregated data, the filtered data, and the perfected data. This application simplifies the data processing process based on simple data offline processing rules, improving the adaptability and flexibility of the system.

[0055] Specifically, by converting the first data into a unified offline data format, the consistency and compatibility of the data are ensured, facilitating subsequent processing and analysis; based on preset data aggregation rules, the scattered first data is integrated into aggregated data, which helps to discover patterns and trends in the data and provides a more comprehensive information view; using preset data filtering rules to remove irrelevant or redundant data, improving data quality and processing efficiency, and reducing unnecessary consumption of storage and computing resources; according to the preset field improvement rules, supplementing and perfecting the missing or incomplete fields in the first data to enhance the integrity and accuracy of the data. The second data is generated based on at least one of the above-mentioned offline data, aggregated data, filtered data, and improved data. This process not only improves the quality and usability of the data but also provides more accurate and effective decision-making support for enterprises. In addition, this method can significantly reduce the cost of data processing, improve the scalability and flexibility of the system, and thus better meet the diverse needs of enterprises.

[0056] In one implementation, converting the first data into offline data according to preset format conversion rules includes: converting the first data into json format in a split format; or, aggregating the first data according to preset data aggregation rules to determine aggregated data, including: obtaining the same first data within a preset time period and aggregating the same first data to determine aggregated data.

[0057] Preferably, the preset time period is 24 hours; it should be understood that the size of the preset time period in this application is not limited, and those skilled in the art can make reasonable selections and settings according to the actual application scenario and actual needs.

[0058] In one implementation, filtering the first data according to preset data filtering rules to determine filtered data includes: based on the first data, obtaining the request source and access object; based on the request source, retaining the first data with the request source being a private Internet protocol address; based on the access object, retaining the first data with the access object being a front-end resource file and / or the network resource identifier being on the whitelist as the filtered data.

[0059] Specifically, by filtering the first data according to a preset data filtering rule to determine the filtered data, this method performs precise screening based on the request source and the access object, only retaining the first data from private Internet Protocol (IP) addresses, and preferentially retaining the data with the access object being a front-end resource file. At the same time, in combination with the network resource identifier, the first data marked as a whitelist is retained. This method not only ensures that only data from internal trusted sources is retained, effectively preventing external illegal access and potential security threats, but also focuses on protecting key front-end resource files, reducing the risk of malicious access or tampering. In addition, the multi-level filtering mechanism removes irrelevant, redundant or potentially risky data, making the finally generated filtered data more concise and efficient, improving the data processing efficiency, reducing the consumption of storage and computing resources, and providing more reliable and efficient decision-making support for enterprises.

[0060] In one of the embodiments, when processing the first data according to a preset data offline processing rule to obtain the second data, the method further includes: processing the first data according to the preset offline processing rule to obtain the second data; generating data features based on the second data, and publishing the second data and its data features to a second queue; wherein, the data features include at least one of a wireless network access user, a system user name, a file name, a file size, and the number of access times.

[0061] Specifically, by processing the first data according to a preset data offline processing rule to generate the second data, this method first performs standardization processing on the first data to generate structured second data, and then generates data features including at least one of a wireless network access user, a system user name, a file name, a file size, and the number of access times based on the second data, and publishes the second data and its data features to the second queue. This method improves the quality and usability of the data, makes the data more descriptive and interpretable, and helps for deeper analysis and insight. At the same time, by managing the data and features orderly and transmitting them efficiently to the second queue, the seamless connection and scheduling of the data processing process are realized, and the overall efficiency of the system is improved. In addition, the detailed recording and management of data features enhance the security and compliance of the system, and help to detect and respond to potential security threats in a timely manner. In summary, this method provides a more reliable, secure and flexible data processing solution for enterprises, supporting more precise decision-making and risk control.

[0062] In one of the embodiments, when processing the log data according to a preset data encryption rule to obtain the first data, the method further includes: obtaining the user identifier of the user based on the log data and encrypting the user identifier; publishing the first data with the encrypted user identifier to a first queue.

[0063] The above-mentioned first data is obtained by processing the log data according to the preset data encryption rules: First, by encrypting the user identification, the privacy and security of user data are ensured, preventing sensitive information from being leaked or tampered with during transmission and storage. Second, the encrypted user identification is published to the first queue, realizing the orderly management and efficient transmission of data, facilitating the connection and scheduling of subsequent processing flows, and improving the overall efficiency and reliability of the system. In addition, this method also provides secure basic data support for data analysis and auditing, helping to more accurately track user behavior and optimize system performance, thereby providing a more secure and efficient operating environment for enterprises. In summary, this method not only enhances data security and privacy protection, but also improves data processing efficiency and system manageability.

[0064] In one of the embodiments, in response to an abnormal behavior analysis request, based on the second data, subscribe to and analyze the target data to determine the abnormal behavior analysis result, including: in response to the abnormal behavior analysis request, based on the second data, subscribe to the abnormal behavior data and the access party of the abnormal behavior data; analyze the abnormal behavior data to determine the abnormal behavior level; send the abnormal behavior data and its abnormal behavior level to the preview table, and review the data access party based on the abnormal behavior level; wherein, the abnormal behavior data includes at least one of the user - end access identifier, the sensitive data access frequency, the interface data access frequency, and the data download frequency.

[0065] Specifically, the preview table includes, but is not limited to, bar charts, line charts, and pie charts. In this application, by sending the abnormal behavior data and its abnormal behavior level to the preview table, the difficult - to - understand abnormal behavior data is generated into an easy - to - understand preview table, and the complex analysis results are presented in a graphical and chart - based form, facilitating the observation by operation and maintenance personnel.

[0066] In one of the embodiments, the abnormal behaviors include, but are not limited to, account sharing, high - frequency access, file downloading, and other abnormal behaviors.

[0067] The abnormal behavior analysis method proposed in this embodiment combines the abnormal behavior analysis architecture and big data technology, uses big data technology to obtain log data for efficient processing and analysis to accurately identify abnormal behaviors; and based on the abnormal behavior analysis architecture, real - time monitors the log data of employees to timely discover and respond to potential abnormal behaviors.

[0068] It should be understood that the log data and other related data involved in this application are all information and data that have been authorized by users or fully authorized by all parties, and the collection, use, and processing of the related data strictly comply with the relevant laws, regulations, and standards of the relevant countries and regions.

[0069] Embodiment Two

[0070] Figure 3 shows an abnormal behavior analysis device provided by an embodiment of the present application. The device at least includes:

[0071] an acquisition unit for acquiring log data;

[0072] a first processing unit for processing the log data according to a preset data encryption rule to obtain first data;

[0073] a second processing unit for processing the first data according to a preset data offline processing rule to obtain second data;

[0074] a response analysis unit for subscribing to and analyzing target data based on the second data in response to an abnormal behavior analysis request to determine an abnormal behavior analysis result.

[0075] Embodiment III

[0076] Based on the same inventive concept, an embodiment of the present application also provides an electronic device. The method corresponding to the electronic device may be the method for abnormal behavior analysis in the foregoing embodiments, and the principle of solving problems is similar to that of the method. The electronic device provided by the embodiment of the present application includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the methods and / or technical solutions of multiple foregoing embodiments of the present application.

[0077] The electronic device may be a user device, or a device formed by integrating the user device and a network device through a network, or may also be an application program running on the above device. The user device includes, but is not limited to, various terminal devices such as a computer, a mobile phone, a tablet computer, a smart watch, a smart bracelet, etc. The network device includes, but is not limited to, a network host, a single network server, a set of multiple network servers, or a computer set based on cloud computing, etc., and can be used to implement some processing functions when setting an alarm clock. Here, the cloud is composed of a large number of hosts or network servers based on cloud computing (Cloud Computing), where cloud computing is a type of distributed computing and consists of a virtual computer formed by a group of loosely coupled computer sets.

[0078] Figure 4The structure of an electronic device suitable for implementing the methods and / or technical solutions in the embodiments of the present application is shown. The device 500 includes a central processing unit (CPU, Central Processing Unit) 501, which can perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM, Read Only Memory) 502 or the programs loaded from the storage section 508 into the random access memory (RAM, Random Access Memory) 503. In the RAM 503, various programs and data required for system operation are also stored. The CPU 501, ROM 502, and RAM 503 are connected to each other via a bus 504. The input / output (I / O, Input / Output) interface 505 is also connected to the bus 504.

[0079] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, a touch screen, a microphone, an infrared sensor, etc.; an output section 507 including such as a cathode ray tube (CRT, Cathode Ray Tube), a liquid crystal display (LCD, Liquid Crystal Display), an LED display, an OLED display, etc. and a speaker; a storage section 508 including one or more computer-readable media such as a hard disk, an optical disc, a magnetic disk, a semiconductor memory, etc.; and a communication section 509 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet.

[0080] In particular, the methods and / or embodiments in the embodiments of the present application can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. When the computer program is executed by the central processing unit (CPU) 501, the above functions defined in the methods of the present application are executed.

[0081] Embodiment 4

[0082] Another embodiment of the present application further provides a computer-readable storage medium, on which computer program instructions are stored, and the computer program instructions can be executed by a processor to implement the methods and / or technical solutions of any one or more of the foregoing embodiments of the present application.

[0083] Specifically, one or more combinations of any computer-readable media may be employed in this embodiment. The computer-readable media may be either computer-readable signal media or computer-readable storage media. The computer-readable storage media may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage media include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In this document, the computer-readable storage media may be any tangible medium that contains or stores a program which can be used by or in connection with an instruction execution system, apparatus, or device.

[0084] The computer-readable signal media may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. Such a propagated data signal may take many forms, including - but not limited to - an electromagnetic signal, an optical signal, or any suitable combination of the foregoing. The computer-readable signal media may also be any computer-readable media other than the computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.

[0085] The program code contained on the computer-readable media may be transmitted using any appropriate media, including - but not limited to - wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0086] The computer program code for performing the operations of this application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0087] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of devices, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0088] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0089] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or page components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed among each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can be in electrical, mechanical, or other forms.

[0090] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0091] In addition, the functional units in various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of a combination of hardware and software functional units.

[0092] The integrated unit implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units are stored in a storage medium and include several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.

[0093] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.

[0094] In addition, obviously, the word "including" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the apparatus claims can also be implemented by one unit or device through software or hardware. The terms first, second, etc. are used to denote names and do not denote any particular order.

Claims

1. A method for analyzing abnormal behavior, characterized in that: The method comprises: Get log data; Processing the log data according to a preset data encryption rule to obtain first data; Processing the first data according to a preset data offline processing rule to obtain second data; In response to the abnormal behavior analysis request, the target data is subscribed and analyzed based on the second data to determine an abnormal behavior analysis result.

2. The abnormal behavior analysis method according to claim 1, characterized in that: The obtaining of log data includes: In response to the data acquisition request, acquiring the behavior data and acquiring the interaction mode of the behavior data; The behavior data obtained when the interaction mode is internal interaction is log data.

3. The abnormal behavior analysis method according to claim 2, characterized in that: Processing the first data according to a preset data offline processing rule to obtain second data includes: Converting the first data into offline data according to a preset format conversion rule; aggregating the first data to determine aggregated data according to a preset data aggregation rule; According to a preset data filtering rule, filtering the first data to determine filtered data; According to a preset field improvement rule, the first data is improved to determine improved data; The second data is obtained based on at least one of the offline data, the aggregated data, the filtered data, and the improved data.

4. The abnormal behavior analysis method according to claim 3, characterized in that: According to a preset format conversion rule, converting the first data into offline data includes: converting the first data in a segmented format into a json format; Or, according to a preset data aggregation rule, aggregating the first data to determine the aggregated data includes: acquiring the same first data within a preset time period, and aggregating the same first data to determine the aggregated data.

5. The abnormal behavior analysis method according to claim 3 or 4, characterized in that: According to a preset data filtering rule, filtering the first data to determine filtered data includes: Based on the first data, obtaining a request source and an access object; Based on the request source, retain first data where the request source is a private Internet Protocol address; Based on the access object, the access object is retained as a front-end resource file, and / or the first data of the network resource identifier as a whitelist is filtered data.

6. The abnormal behavior analysis method according to claim 1, characterized in that: When the first data is processed according to a preset data offline processing rule to obtain the second data, the method further includes: Processing the first data according to a preset offline processing rule to obtain second data; generating data features based on the second data, and publishing the second data and the data features thereof to a second queue; The data feature includes at least one of a wireless network access user, a system user name, a file name, a file volume, and a number of access times.

7. The abnormal behavior analysis method according to claim 1, characterized in that: When the log data is processed according to a preset data encryption rule to obtain the first data, the method further includes: Based on the log data, obtaining a user ID of the user and encrypting the user ID; The first data encrypted by the user identification is published to the first queue.

8. The abnormal behavior analysis method according to claim 1, characterized in that: In response to the abnormal behavior analysis request, subscribing to and analyzing the target data based on the second data to determine an abnormal behavior analysis result, including: In response to an abnormal behavior analysis request, subscribing to abnormal behavior data and abnormal behavior data access parties based on the second data; Analyzing the abnormal behavior data to determine an abnormal behavior level; Sending the abnormal behavior data and its abnormal behavior level to a preview table, and reviewing the data access party based on the abnormal behavior level; The abnormal behavior data includes at least one of the following: user terminal access identification, sensitive data access frequency, interface data access frequency, and data download frequency.

9. An abnormal behavior analysis device, characterized in that: The device comprises: An acquisition unit, used for acquiring log data; A first processing unit, configured to process the log data according to a preset data encryption rule to obtain first data; A second processing unit, configured to process the first data according to a preset data offline processing rule to obtain second data; A response analysis unit is used to respond to the abnormal behavior analysis request and determine an abnormal behavior analysis result based on the second data subscription and analysis of the target data.

10. An electronic device, comprising: at least one processor; as well as A memory communicatively connected to the at least one processor; characterized in that The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 9.

11. A computer readable medium having computer program instructions stored thereon, characterized in that: The computer program instructions are executable by a processor to implement the method according to any one of claims 1 to 9.

12. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.