A method for network attack security detection
By collecting and analyzing users' micro-behavioral data, extracting and detecting entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm, multi-dimensional anomaly detection and threat level assessment of network attacks are achieved. This overcomes the limitations of traditional detection methods and improves the detection capabilities and response efficiency of network security.
Patent Information
- Application Number
- CN202510486940.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2045-04-17
AI Technical Summary
Existing network attack detection methods struggle to identify abnormal operational behaviors of internal personnel and new network attack methods, especially changes at the micro level, and are difficult to quickly and accurately identify security threats in complex network environments.
By collecting users' micro-behavioral data, including mouse movement trajectory, click interval time, and keyboard input rhythm, we extract the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm to perform single-dimensional and multi-dimensional anomaly detection, calculate a comprehensive anomaly score, and conduct threat level assessment and response.
It improves the accuracy and reliability of network attack detection, reduces false negatives and missed positives, enables timely detection of abnormal behavior, and allows for targeted responses based on threat levels, thus ensuring network security.
Smart Images

Figure CN120238361B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security detection technology, and specifically to a method for network attack security detection. Background Technology
[0002] In today's highly digitalized era, cybersecurity issues are becoming increasingly serious, with various cyberattack methods emerging one after another, posing a significant threat to the security of computer systems and networks. Traditional cyberattack detection methods mainly focus on analyzing macro-level data such as network traffic and port connections. However, as attackers' techniques continue to evolve, many attack behaviors are difficult to detect effectively at the macro level, which has gradually exposed many limitations of traditional detection methods.
[0003] On the one hand, macro-level detection struggles to accurately identify abnormal user behavior. For example, employees might unknowingly perform unusual computer operations due to malware infection or social engineering attacks. These operations may not be apparent from a macro perspective, such as network traffic, but could severely damage sensitive data and critical systems. On the other hand, new cyberattack methods, such as exploiting vulnerabilities in specific applications, often evade traditional macro-level detection mechanisms by simulating normal user behavior. These attacks may alter user behavior patterns at the micro-level, such as abnormal mouse movements, click intervals, and keyboard input rhythms, but existing detection methods based on macro-level data cannot capture these subtle changes.
[0004] Furthermore, with the widespread application of new technologies such as cloud computing and big data, the network environment has become more complex, and the amount of data is growing exponentially. This further increases the burden on traditional network attack detection methods, making it difficult for them to quickly and accurately identify real security threats from massive amounts of data. Therefore, there is an urgent need for a network attack security detection method that can delve into the micro-behavioral level of users to compensate for the shortcomings of traditional detection methods, improve the ability and level of network security protection, and promptly and effectively detect and respond to various potential network attack behaviors. Summary of the Invention
[0005] The purpose of this invention is to provide a network attack security detection method that solves the technical problems mentioned in the background art.
[0006] The objective of this invention can be achieved through the following technical solutions:
[0007] A network attack security detection method includes the following steps:
[0008] Step 1: Micro-behavioral data collection:
[0009] Collect micro-behavioral data of users during computer operation; this includes: mouse movement trajectory, click interval time, and keyboard input rhythm.
[0010] Step 2: Extraction of micro-behavioral features:
[0011] Feature extraction processing is performed on the collected raw microscopic behavior data to obtain microscopic behavior feature indicators;
[0012] Micro-behavioral characteristic indicators include mouse movement trajectory entropy change characteristics, click interval time entropy change characteristics, and keyboard input rhythm entropy change characteristics;
[0013] Step 3: Abnormal Behavior Detection
[0014] By comparing and analyzing the extracted micro-behavioral features, it is determined whether user behavior is abnormal. The comparative analysis methods include: single-dimensional anomaly detection and multi-dimensional joint detection. Single-dimensional anomaly detection refers to independently detecting the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm, and triggering a single-dimensional alarm based on the results. Multi-dimensional joint detection is as follows: it comprehensively considers the current entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm to calculate a comprehensive anomaly score. When the comprehensive anomaly score exceeds a preset detection threshold, it indicates that the user behavior is abnormal in multiple dimensions simultaneously, triggering a global alarm.
[0015] Step 4: Threat Level Assessment
[0016] Based on the results of abnormal behavior detection, a threat level assessment is conducted, and corresponding preset response strategies are adopted.
[0017] As a further aspect of the present invention: the mouse movement trajectory refers to recording the coordinate sequence of the mouse on the screen; the click interval time refers to recording the time difference between two consecutive clicks, specifically: each time the mouse clicks, the computer system generates a corresponding timestamp, and the click interval time can be obtained by obtaining the timestamps of two adjacent clicks and calculating the difference; the keyboard input rhythm refers to recording the time interval sequence between keyboard keys; specifically: when the user presses keys on the keyboard, the computer system records the time of each key being pressed and released, and the keyboard input rhythm data can be obtained by calculating the time difference between adjacent key operations.
[0018] As a further aspect of the present invention, the feature extraction processing method for the entropy change features of the mouse movement trajectory is as follows:
[0019] Step K1.1, Trajectory Velocity:
[0020] pass: Calculate the moving speed V between adjacent coordinate pointsj,j+1 ;
[0021] In the formula, (x j ,y j Let j be the sequence of mouse coordinates on the screen, where j = 1, 2, ..., n;
[0022] Among them, the movement speed between adjacent coordinate points is used to measure the speed change of the mouse during the movement process;
[0023] (x j ,y j ) and (x j+1 ,y j+1 ) represents two adjacent mouse coordinates, TC j,j+1 It is the time interval between these two coordinate points;
[0024] Simultaneously, the movement speed V between all adjacent coordinate points j,j+1 Forming a sequence of moving speeds;
[0025] Step K1.2, Velocity Fluctuation Entropy:
[0026] Firstly, through:
[0027] Calculate each movement speed V j,j+1 The probability P(V) in the movement speed sequence g=[j,j+1] This refers to the proportion of each speed value to the total number of movement speeds in the sequence.
[0028] In the formula, VZ represents the sum of all movement speeds in the movement speed sequence, and n represents the number of mouse coordinate points;
[0029] Next, according to the formula for calculating entropy:
[0030]
[0031] Calculate the velocity fluctuation entropy EV;
[0032] Among them, the greater the speed fluctuation entropy, the higher the dispersion of the mouse movement speed, that is, the more irregular the speed change;
[0033] Among them, the speed fluctuation entropy EV is the entropy change feature of the mouse movement trajectory.
[0034] As a further aspect of the present invention, the feature extraction processing method for the entropy change feature of the click interval time is as follows:
[0035] StepK2.1, Click Interval Stability:
[0036] pass:
[0037] Calculate the standard deviation (WT) of the click interval;
[0038] In the formula, TC i,i+1 =T i+1 -T i T i TC refers to the timestamp of the i-th mouse click operation. i,i+1 Let be the click interval between the i-th and (i+1)-th mouse click operations, i = 1, 2, ..., v, where v represents the number of mouse click operations, and TCP is the average click interval.
[0039] The standard deviation is used to measure whether the click interval time of multiple mouse click operations is stable. The smaller the standard deviation, the more stable the click interval time.
[0040] Step K2.2, Click-spaced mutation detection:
[0041] First, via: TCC f,f+1 =TC f+1=[i+1,i+2] -TC f=[i,i+1] ;
[0042] Calculate the difference (TCC) between adjacent clicks. f,f+1 ;
[0043] The difference between adjacent click intervals is then TCC f,f+1 Compare with a pre-set difference threshold CCY:
[0044] When TCC f,f+1 If the value is greater than CCY, it indicates that there has been a sudden change in the click interval between two consecutive mouse click operations;
[0045] Next, the difference in TCC between all adjacent click intervals. f,f+1 In the middle, obtain TCC f,f+1 The number of times > CCY is recorded, and it is marked as CM;
[0046] Then through:
[0047] Calculate the mutation ratio (TBB) of all adjacent click intervals;
[0048] Among them, the mutation ratio is used to measure whether the change in the click interval time is abnormal. The higher the mutation ratio, the more abnormal the change in the click interval time.
[0049] Among them, the abrupt change ratio TBB of all adjacent click intervals is the click interval time entropy change feature.
[0050] As a further aspect of the present invention, the feature extraction processing method for the entropy change features of keyboard input rhythm is as follows:
[0051] Step K3.1, Consistent Key Pressing Rhythm:
[0052] pass:
[0053] Calculate the coefficient of variation (BY) of the time intervals between keyboard key presses;
[0054] In the formula, SJ q Let q be the time interval sequence between keyboard keys, where q = 1, 2, ..., k, and k represents the number of times the keyboard key corresponds to the time interval; SJP and SJB represent the mean and standard deviation of the time interval sequence between keyboard keys, respectively.
[0055] The coefficient of variation is used to measure the consistency of the key press interval time. The smaller the coefficient of variation, the more consistent the key press rhythm.
[0056] Step K3.2, Abnormal Key Press Detection:
[0057] To detect whether there are abnormally long or short intervals between key presses.
[0058] Get the pre-set threshold A for judging two abnormal buttons min and A max ;
[0059] Among them, the abnormal key judgment threshold is used to detect whether there are abnormal long intervals or short intervals of key presses.
[0060] The time interval between keyboard keys, SJ q Each is compared with the abnormal key press judgment threshold A. min and A max Comparison:
[0061] If SJ q <A min Or SJ q >A max If so, the key is considered an abnormal key;
[0062] Then, count the number of abnormal keys among all keyboard keys and mark them as AJ;
[0063] Then passed:
[0064] Then through:
[0065] Calculate the abnormal key press ratio YAB;
[0066] Among them, the abnormal key ratio is used to measure whether the keyboard input rhythm is abnormal. The higher the abnormal key ratio, the more abnormal the keyboard input rhythm is.
[0067] Among them, the coefficient of variation BY of the time interval between keyboard keys is the entropy change feature of keyboard input rhythm.
[0068] As a further aspect of the present invention: the single-dimensional anomaly detection method specifically includes:
[0069] For the entropy change feature of mouse movement trajectory, if the speed fluctuation entropy EV > EVZ, it is determined that the mouse movement trajectory is abnormal and a single-dimensional alarm is triggered.
[0070] Among them, EVZ is a detection threshold preset based on the entropy change characteristics of the mouse movement trajectory;
[0071] For the click interval entropy change feature, if the abrupt change ratio of the click interval TBB > TBZ, it is determined that the click interval time is abnormal and a single-dimensional alarm is triggered.
[0072] Wherein, TBZ is a detection threshold pre-set based on the entropy change characteristics of the click interval time;
[0073] For the entropy change feature of keyboard input rhythm, if the coefficient of variation BY > BYZ of the time interval between keyboard keys, it is determined that the keyboard input rhythm is abnormal and a single-dimensional alarm is triggered.
[0074] BYZ is a detection threshold pre-set based on the entropy change characteristics of keyboard input rhythm.
[0075] As a further aspect of the present invention, the calculation method for the comprehensive anomaly score is as follows:
[0076] The system acquires micro-behavioral data of multiple historical windows during normal computer operation, and calculates the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm of multiple historical windows based on the micro-behavioral feature extraction steps.
[0077] Subsequently, the maximum and minimum values of the features were obtained from the entropy change features of the historical mouse movement trajectory, the entropy change features of the click interval time, and the entropy change features of the keyboard input rhythm in multiple historical windows, respectively.
[0078] Then, by combining the maximum and minimum values of the entropy change features from multiple historical windows, the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm are normalized.
[0079] The normalization formula is:
[0080] In the formula, GY0 represents the current entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm, and GY0 = {TBB, BY, YAB}. GY1 represents the normalized entropy change features of the current mouse movement trajectory, click interval time, and keyboard input rhythm, and is denoted as GY1 = {TBB1, BY1, YAB1}. max and GY min The variable refers to the maximum and minimum values of the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm across multiple history windows.
[0081] Then, the following is used: ZHP = β1 × TBB1 + β2 × BY1 + β3 × YAB1;
[0082] The Comprehensive Anomaly Score (ZHP) was calculated.
[0083] As a further aspect of the present invention, the threat level assessment method is as follows:
[0084] When only a single-dimensional alarm occurs and no global alarm occurs, and the difference between the comprehensive anomaly scores and the detection thresholds is greater than the corresponding preset score difference threshold, it is judged as low risk.
[0085] When a single-dimensional anomaly occurs, and the overall anomaly score does not exceed the detection threshold, and the difference between the overall anomaly scores and the detection threshold is less than or equal to the corresponding preset score difference threshold, it is judged as medium risk.
[0086] When multiple single-dimensional anomalies occur and a global alarm is triggered simultaneously, the risk level is determined to be high.
[0087] The beneficial effects of this invention are:
[0088] Multi-dimensional behavioral data collection and analysis: By collecting micro-behavioral data such as mouse movement trajectory, click interval time, and keyboard input rhythm, and performing feature extraction and anomaly detection from multiple dimensions, it can capture user behavior characteristics more comprehensively and meticulously. Compared with single-dimensional detection methods, it greatly improves the accuracy and reliability of detection and reduces the possibility of missed and false alarms.
[0089] Mouse movement trajectory entropy change characteristics: By calculating the trajectory speed and speed fluctuation entropy, the variation pattern and dispersion of mouse movement speed can be accurately reflected, thereby effectively identifying abnormal mouse movement trajectories. For example, a larger speed fluctuation entropy indicates more irregular changes in mouse movement speed, which may suggest abnormal operation.
[0090] Click interval entropy change characteristics: By utilizing click interval stability and click interval mutation detection, the stability of the click interval is measured by the standard deviation, and the mutation ratio is used to determine whether the click interval changes are abnormal. This allows for precise identification of abnormal click interval situations. A smaller standard deviation indicates a more stable click interval, while a higher mutation ratio indicates a more abnormal change, which helps in the timely detection of abnormal click behavior.
[0091] Keyboard input rhythm entropy variation characteristics: By analyzing key rhythm consistency (measured by coefficient of variation) and detecting abnormal keys, it is possible to effectively assess whether the keyboard input rhythm is abnormal. The smaller the coefficient of variation, the more consistent the key rhythm; the higher the proportion of abnormal keys, the more abnormal the keyboard input rhythm, providing a powerful means to detect abnormal keyboard input-related behaviors.
[0092] Single-dimensional anomaly detection: Independent detection is performed on the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm. When the feature value of a certain dimension exceeds the corresponding preset threshold, a single-dimensional alarm is triggered. This method is simple and direct, and can quickly detect abnormal behavior in a single dimension, providing a basis for timely measures.
[0093] Multi-dimensional joint detection: This method comprehensively considers micro-behavioral features across three dimensions to calculate a comprehensive anomaly score. By analyzing micro-behavioral data from multiple historical windows, the maximum and minimum values of the features are obtained, normalized, and then used to calculate the comprehensive anomaly score. A global alarm is triggered when the score exceeds a preset detection threshold. This approach can comprehensively assess situations where user behavior exhibits anomalies across multiple dimensions simultaneously, improving the detection capability for complex anomalies.
[0094] A reasonable threat level assessment and response strategy: Threat levels are assessed based on the results of abnormal behavior detection, categorized as low-risk, medium-risk, and high-risk. Low-risk corresponds to only a single-dimensional alarm and a difference between the overall anomaly score and the detection threshold exceeding a preset score difference threshold; medium-risk corresponds to a single-dimensional anomaly and a difference between the overall anomaly score and the detection threshold less than or equal to a preset score difference threshold; high-risk corresponds to multiple single-dimensional anomalies and a global alarm. Adopting corresponding preset response strategies for different threat levels allows for more targeted responses to varying degrees of security threats, improving the practicality and effectiveness of network attack security detection, and ensuring the secure and stable operation of computer systems and networks. Attached Figure Description
[0095] The invention will now be further described with reference to the accompanying drawings.
[0096] Figure 1 This is a flowchart illustrating a network attack security detection method according to the present invention.
[0097] Figure 2This is a schematic diagram of microscopic behavioral data collection for a network attack security detection method according to the present invention.
[0098] Figure 3 This is a schematic diagram illustrating the extraction of microscopic behavioral features in a network attack security detection method according to the present invention. Detailed Implementation
[0099] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0100] Example 1
[0101] Please see Figure 1 , Figure 2 , Figure 3 As shown, this invention is a network attack security detection method, comprising the following steps:
[0102] Step 1: Micro-behavioral data collection:
[0103] Collect micro-behavioral data of users during computer operation;
[0104] Micro-behavioral data includes:
[0105] Mouse movement trajectory: Recording the sequence of mouse coordinates on the screen using the coordinate acquisition mechanism of the computer system;
[0106] Click interval time: The time difference between two consecutive clicks is recorded using the computer system's time recording function;
[0107] Specifically, each time a mouse click is performed, the computer system generates a corresponding timestamp. By obtaining the timestamps of two consecutive clicks and calculating the difference, the click interval can be obtained.
[0108] Keyboard input rhythm: Using the computer system's time recording function to record the time interval sequence between keyboard keys;
[0109] Specifically, when a user presses a key on the keyboard, the computer system records the time it takes for each key to be pressed and released. By calculating the time difference between adjacent key presses, the system can obtain keyboard input rhythm data.
[0110] Step 2: Extraction of micro-behavioral features:
[0111] The collected raw micro-behavioral data is processed to extract micro-behavioral feature indicators that can characterize user behavior patterns.
[0112] The feature extraction process is as follows:
[0113] Step K1, Entropy Change Characteristics of Mouse Movement Trajectory:
[0114] pass: Calculate the moving speed V between adjacent coordinate points j,j+1 ;
[0115] In the formula, (x j ,y j Let j be the sequence of mouse coordinates on the screen, where j = 1, 2, ..., n;
[0116] Among them, the movement speed between adjacent coordinate points is used to measure the speed change of the mouse during the movement process;
[0117] (x j ,y j ) and (x j+1 ,y j+1 ) represents two adjacent mouse coordinates, TC j,j+1 It is the time interval between these two coordinate points;
[0118] Simultaneously, the movement speed V between all adjacent coordinate points j,j+1 Forming a sequence of moving speeds;
[0119] pass:
[0120] Calculate each movement speed V j,j+1 The probability P(V) in the movement speed sequence g=[j,j+1] This refers to the proportion of each speed value to the total number of movement speeds in the sequence.
[0121] In the formula, VZ represents the sum of all movement speeds in the movement speed sequence, and n represents the number of mouse coordinate points;
[0122] Next, according to the formula for calculating entropy:
[0123]
[0124] Calculate the velocity fluctuation entropy EV;
[0125] In this embodiment, the greater the speed fluctuation entropy, the higher the dispersion of the mouse movement speed, that is, the more irregular the speed change;
[0126] Among them, the velocity fluctuation entropy EV is the entropy change feature of the mouse movement trajectory:
[0127] Step K2, Click Interval Time Entropy Change Feature:
[0128] First, via: TCCf,f+1 =TC f+1=[i+1,i+2] -TC f=[i,i+1] ;
[0129] Calculate the difference (TCC) between adjacent clicks. f,f+1 ;
[0130] The difference between adjacent click intervals is then TCC f,f+1 Compare with a pre-set difference threshold CCY:
[0131] When TCC f,f+1 If the value is greater than CCY, it indicates that there has been a sudden change in the click interval between two consecutive mouse click operations;
[0132] Next, the difference in TCC between all adjacent click intervals. f,f+1 In the middle, obtain TCC f,f+1 The number of times > CCY is recorded, and it is marked as CM;
[0133] Then through:
[0134] Calculate the mutation ratio (TBB) of all adjacent click intervals;
[0135] In this embodiment, the mutation ratio is used to measure whether the change in the click interval time is abnormal. The higher the mutation ratio, the more abnormal the change in the click interval time.
[0136] Among them, the abrupt change ratio TBB of all adjacent click intervals is the click interval time entropy change feature;
[0137] Step K3, Keyboard Input Rhythm Entropy Change Characteristics:
[0138] pass:
[0139] Calculate the coefficient of variation (BY) of the time intervals between keyboard key presses;
[0140] In the formula, SJ q Let q be the time interval sequence between keyboard keys, where q = 1, 2, ..., k, and k represents the number of times the keyboard key corresponds to the time interval; SJP and SJB represent the mean and standard deviation of the time interval sequence between keyboard keys, respectively.
[0141] In this embodiment, the coefficient of variation is used to measure the consistency of the key press interval time. The smaller the coefficient of variation, the more consistent the key press rhythm.
[0142] Among them, the coefficient of variation BY of the time interval between keyboard keys is the entropy change feature of keyboard input rhythm.
[0143] Step 3: Abnormal Behavior Detection
[0144] By comparing and analyzing the extracted micro-behavioral features, it can be determined whether user behavior is abnormal.
[0145] The comparative analysis also includes single-dimensional anomaly detection, the specific method of which is as follows:
[0146] The entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm are detected independently.
[0147] Specifically:
[0148] For the entropy change feature of mouse movement trajectory, if the speed fluctuation entropy EV > EVZ, it is determined that the mouse movement trajectory is abnormal and a single-dimensional alarm is triggered.
[0149] Among them, EVZ is a detection threshold preset based on the entropy change characteristics of the mouse movement trajectory;
[0150] For the click interval entropy change feature, if the abrupt change ratio of the click interval TBB > TBZ, it is determined that the click interval time is abnormal and a single-dimensional alarm is triggered.
[0151] Wherein, TBZ is a detection threshold pre-set based on the entropy change characteristics of the click interval time;
[0152] For the entropy change feature of keyboard input rhythm, if the coefficient of variation BY > BYZ of the time interval between keyboard keys, it is determined that the keyboard input rhythm is abnormal and a single-dimensional alarm is triggered.
[0153] Among them, BYZ is a detection threshold pre-set based on the entropy change characteristics of keyboard input rhythm;
[0154] This embodiment achieves single-dimensional detection of user behavior anomalies by collecting and analyzing user micro-behavioral data (such as mouse movement trajectory, click interval time, and keyboard input rhythm) and extracting entropy change features (such as speed fluctuation entropy, click interval mutation ratio, and keyboard input rhythm variation coefficient). This method can quantify the dispersion and abnormal changes in behavioral patterns; for example, it can identify irregular mouse movement through speed fluctuation entropy or detect abnormal fluctuations in click intervals through mutation ratio. The single-dimensional independent detection mechanism can quickly locate specific behavioral anomalies (such as sudden changes in mouse or keyboard operation), triggering targeted alarms. It is suitable for preliminary risk screening, has high computational efficiency, and low system resource consumption.
[0155] Example 2
[0156] As a second embodiment of the present invention, in specific implementation, the technical solution of this embodiment differs from that of embodiment one only in that: in this embodiment, the click interval time entropy change feature further includes: click interval stability, which is calculated as follows:
[0157] pass:
[0158] Calculate the standard deviation (WT) of the click interval;
[0159] In the formula, TC i,i+1 =T i+1 -T i T i TC refers to the timestamp of the i-th mouse click operation. i,i+1 Let be the click interval between the i-th and (i+1)-th mouse click operations, i = 1, 2, ..., v, where v represents the number of mouse click operations, and TCP is the average click interval.
[0160] In this embodiment, the standard deviation is used to measure whether the click interval time of multiple mouse click operations is stable. The smaller the standard deviation, the more stable the click interval time.
[0161] This embodiment, building upon Embodiment 1, adds the detection of click interval stability (measured by standard deviation), further enhancing the comprehensiveness of click interval time anomaly analysis. Standard deviation reflects the temporal consistency of multiple click operations, compensating for the limitation of mutation ratio focusing only on the number of mutations. For example, a stable low standard deviation may indicate automated script operation, while a high standard deviation may suggest instability in human operation. This improvement enables the click interval time entropy change feature to possess both mutation detection and stability assessment capabilities, improving the accuracy of identifying regular abnormal behaviors (such as script attacks or human fatigue).
[0162] Example 3
[0163] As a third embodiment of the present invention, in specific implementation, compared with embodiments one and two, the technical solution of this embodiment is to combine the solutions of embodiments one and two. The difference between the technical solution of this embodiment and embodiments one and two is only that in this embodiment, the keyboard input rhythm entropy change feature also includes abnormal key detection, the specific method of which is as follows:
[0164] To detect the presence of abnormally long or short key presses, two pre-defined abnormal key press judgment thresholds A are obtained. min and A max ;
[0165] Among them, the abnormal key judgment threshold is used to detect whether there are abnormal long intervals or short intervals of key presses.
[0166] The time interval between keyboard keys, SJ q Each is compared with the abnormal key press judgment threshold A. min and A max Comparison:
[0167] If SJ q <A min Or SJ q >A max If so, the key is considered an abnormal key;
[0168] Then, count the number of abnormal keys among all keyboard keys and mark them as AJ;
[0169] Then passed:
[0170] Then through:
[0171] Calculate the abnormal key press ratio YAB;
[0172] In this embodiment, the abnormal key ratio is used to measure whether the keyboard input rhythm is abnormal. The higher the abnormal key ratio, the more abnormal the keyboard input rhythm.
[0173] This embodiment combines the solutions from the previous two examples and adds an abnormal key press detection function based on keyboard input rhythm (such as long / short interval key press statistics). By setting thresholds (Amin and Amax), abnormal key press intervals are directly identified, and the proportion of abnormal key presses is calculated, which can effectively capture extreme abnormal behaviors in keyboard input (such as rapid input during brute-force attacks or delayed operations controlled by Trojans). This feature, combined with the coefficient of variation, forms a dual detection mechanism that assesses both the overall rhythm consistency (coefficient of variation) and locates local anomalies (abnormal key press proportion), significantly enhancing the defense capability against keyboard input attacks (such as password guessing).
[0174] Example 4
[0175] As a fourth embodiment of the present invention, in specific implementation, compared with embodiments one, two, and three, the difference between this embodiment and embodiments one, two, and three is only that in this embodiment, the comparative analysis also includes multi-dimensional joint detection, the specific method of which is as follows:
[0176] A comprehensive anomaly score is calculated by comprehensively considering the current entropy change characteristics of mouse movement trajectory, the entropy change characteristics of click interval time, and the entropy change characteristics of keyboard input rhythm.
[0177] When the overall anomaly score is greater than the preset detection threshold, it indicates that the user's behavior is abnormal in multiple dimensions at the same time, triggering a global alarm.
[0178] The comprehensive anomaly score is calculated as follows:
[0179] The system acquires micro-behavioral data of multiple historical windows during normal computer operation, and calculates the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm of multiple historical windows based on the micro-behavioral feature extraction steps.
[0180] Subsequently, the maximum and minimum values of the features were obtained from the entropy change features of the historical mouse movement trajectory, the entropy change features of the click interval time, and the entropy change features of the keyboard input rhythm in multiple historical windows, respectively.
[0181] Then, by combining the maximum and minimum values of the entropy change features from multiple historical windows, the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm are normalized.
[0182] The normalization formula is:
[0183] In the formula, GY0 represents the current entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm, and GY0 = {TBB, BY, YAB}. GY1 represents the normalized entropy change features of the current mouse movement trajectory, click interval time, and keyboard input rhythm, and is denoted as GY1 = {TBB1, BY1, YAB1}. max and GY min The variable refers to the maximum and minimum values of the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm across multiple history windows.
[0184] Then, the following is used: ZHP = β1 × TBB1 + β2 × BY1 + β3 × YAB1;
[0185] Calculate the Comprehensive Anomaly Score (ZHP);
[0186] This embodiment also includes the step of: threat level assessment;
[0187] Based on the results of abnormal behavior detection, a threat level assessment is conducted, and corresponding preset response strategies are adopted.
[0188] When only a single-dimensional alarm occurs and no global alarm occurs, and the difference between the comprehensive anomaly scores and the detection thresholds is greater than the corresponding preset score difference threshold, it is judged as low risk.
[0189] For example, if only the speed fluctuation entropy in the entropy change feature of the mouse movement trajectory exceeds the threshold, but the overall anomaly score is still lower than the detection threshold, it is considered a low-risk situation, which may be an accidental abnormal operation by the user.
[0190] For low-risk situations, the corresponding preset response strategy is: the system only logs the data and does not block user operations; by logging the data, abnormal user operations can be retained for subsequent analysis and auditing, without affecting the user's normal use.
[0191] When a single-dimensional anomaly occurs, and the overall anomaly score does not exceed the detection threshold, and the difference between the overall anomaly scores and the detection threshold is less than or equal to the corresponding preset score difference threshold, it is judged as medium risk.
[0192] For example, if the proportion of click interval mutations in the click interval time entropy change feature exceeds the threshold, and the comprehensive anomaly score is already close to the detection threshold, it indicates that there is a certain possibility of abnormal user behavior, which needs to be further confirmed.
[0193] When the risk level is determined to be medium, the corresponding preset response strategy is to require the user to perform secondary authentication, such as SMS verification code. By adding an authentication step, the user's identity is further confirmed, preventing unauthorized users from using abnormal behavior to launch attacks. This ensures system security to a certain extent without excessively affecting the user experience.
[0194] When multiple single-dimensional anomalies occur and a global alarm is triggered simultaneously, the risk level is determined to be high.
[0195] If multiple dimensions of the mouse movement trajectory entropy change feature, click interval time entropy change feature, and keyboard input rhythm entropy change feature show anomalies simultaneously, and the overall anomaly score exceeds the detection threshold, then a network attack is highly suspected.
[0196] For high-risk situations, the corresponding preset response strategy is: the system immediately blocks the session and notifies the administrator; once high-risk behavior is detected, in order to prevent the attack from spreading further and to protect system and data security, the user's connection with the system is immediately cut off, and the administrator is notified in a timely manner to handle the situation so that the administrator can take further security measures, such as investigating the source of the attack and fixing system vulnerabilities.
[0197] This embodiment introduces a multi-dimensional joint detection and threat level assessment mechanism. By normalizing various entropy change features and calculating a comprehensive anomaly score, it solves the false positive problem that may exist in single-dimensional detection. For example, abnormal mouse movement alone may be accidental behavior, but if it is accompanied by abnormal click intervals and keyboard rhythm, it is more likely to be an attack. Risk levels (low / medium / high risk) are dynamically classified based on score differences and alarm combinations, and differentiated response strategies (such as logging, two-factor authentication, or session blocking) are matched, achieving a balance between security and user experience. This solution is particularly suitable for high-security scenarios, enabling layered responses to potential threats and reducing the interference of false positives on normal users.
[0198] Example 5
[0199] As a fifth embodiment of the present invention, in specific implementation, compared with embodiments one, two, three and four, the technical solution of this embodiment is to combine the solutions of embodiments one, two, three and four.
[0200] This embodiment integrates all the optimizations from the previous four examples to form a complete micro-behavior detection system. By fusing single-dimensional detection (Examples 1-3) and multi-dimensional joint analysis (Example 4), it retains sensitivity to specific behavioral anomalies while reducing the false alarm rate through comprehensive scoring. The threat level assessment module further transforms technical indicators into actionable security policies, such as logging only low-risk attacks while immediately blocking high-risk attacks. This combined approach is comprehensive, flexible, and practical, suitable for complex and ever-changing network attack scenarios, and can adapt to different security needs ranging from occasional anomalies to advanced persistent threats (APTs).
[0201] It should be stated that all micro-behavioral data collected in this application was collected with the user's consent and authorization, and the use of micro-behavioral data is legal and compliant, and the use and processing of micro-behavioral data comply with the relevant laws, regulations and standards of the relevant regions.
[0202] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.
[0203] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A network attack security detection method, characterized in that, Includes the following steps: Micro-behavioral data collection: Collecting micro-behavioral data of users during computer operation, including: mouse movement trajectory, click interval time, and keyboard input rhythm. Keyboard input rhythm refers to recording the time interval sequence between keyboard key presses. Micro-behavioral feature extraction: Feature extraction processing is performed on the collected raw micro-behavioral data to obtain micro-behavioral feature indicators; micro-behavioral feature indicators include mouse movement trajectory entropy change features, click interval time entropy change features, and keyboard input rhythm entropy change features; Abnormal behavior detection: By comparing and analyzing the extracted micro-behavioral features, it determines whether user behavior is abnormal; Threat Level Assessment: Based on the results of abnormal behavior detection, a threat level assessment is conducted; The feature extraction process for the entropy change feature of mouse movement trajectory is as follows: pass: Calculate the moving speed V between adjacent coordinate points. j,j+1 ; In the formula, (x j ,y j Let j be the sequence of mouse coordinates on the screen, where j = 1, 2, ..., n; (x j ,y j ) and (x j+1 ,y j+1 ) represents two adjacent mouse coordinates, TC j,j+1 It is the time interval between these two coordinate points; Simultaneously, the movement speed V between all adjacent coordinate points j,j+1 Forming a sequence of moving speeds; Firstly, through: ; Calculate each movement speed V j,j+1 The probability P(V) in the movement speed sequence g=[j,j+1] This refers to the proportion of each speed value to the total number of movement speeds in the sequence. In the formula, VZ represents the sum of all movement speeds in the movement speed sequence, and n represents the number of mouse coordinate points; Next, according to the formula for calculating entropy: ; Calculate the velocity fluctuation entropy EV; Among them, the speed fluctuation entropy EV is the entropy change feature of the mouse movement trajectory.
2. The network attack security detection method according to claim 1, characterized in that, Mouse movement trajectory refers to the sequence of coordinates of the mouse on the screen; click interval refers to the time difference between two consecutive clicks. Specifically, each mouse click generates a corresponding timestamp. By obtaining the timestamps of two adjacent clicks and calculating the difference, the click interval can be obtained. When a user presses keys on the keyboard, the computer system records the time of each key press and release. By calculating the time difference between adjacent key presses, keyboard input rhythm data can be obtained.
3. The network attack security detection method according to claim 1, characterized in that, The feature extraction processing method for the entropy change feature of the click interval time is as follows: Firstly, through: ; Calculate the difference (TCC) between adjacent clicks. f,f+1 ; The difference between adjacent click intervals is then TCC f,f+1 Compare with a pre-set difference threshold CCY: When TCC f,f+1 If the value is greater than CCY, it indicates that there has been a sudden change in the click interval between two consecutive mouse click operations; Next, the difference in TCC between all adjacent click intervals. f,f+1 In the middle, obtain TCC f,f+1 The number of times > CCY is recorded, and it is marked as CM; Then through: ; Calculate the mutation ratio (TBB) of all adjacent click intervals; Among them, the abrupt change ratio TBB of all adjacent click intervals is the click interval time entropy change feature, T i TC refers to the timestamp of the i-th mouse click operation. i,i+1 Let be the click interval between the i-th and (i+1)-th mouse click operations, i = 1, 2, ..., v, where v represents the number of mouse click operations, and TCP is the average click interval.
4. The network attack security detection method according to claim 3, characterized in that, The feature extraction processing method for the entropy change feature of keyboard input rhythm is as follows: pass: ; Calculate the coefficient of variation (BY) of the time intervals between keyboard key presses; In the formula, SJ q Let q be the time interval sequence between keyboard keys, where q = 1, 2, ..., k, and k represents the number of times the keyboard key corresponds to the time interval; SJP and SJB represent the mean and standard deviation of the time interval sequence between keyboard keys, respectively. Among them, the coefficient of variation BY of the time interval between keyboard keys is the entropy change feature of keyboard input rhythm.
5. The network attack security detection method according to claim 4, characterized in that, The comparative analysis methods in abnormal behavior detection include: single-dimensional anomaly detection and multi-dimensional joint detection. Single-dimensional anomaly detection refers to independently detecting the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm, and triggering a single-dimensional alarm based on the results. Multi-dimensional joint detection involves comprehensively considering the current entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm to calculate a comprehensive anomaly score. When the comprehensive anomaly score is greater than a preset detection threshold, it indicates that the user behavior is abnormal in multiple dimensions simultaneously, triggering a global alarm.
6. The network attack security detection method according to claim 5, characterized in that, The single-dimensional anomaly detection method is as follows: For the entropy change feature of mouse movement trajectory, if the speed fluctuation entropy EV > EVZ, it is determined that the mouse movement trajectory is abnormal and a single-dimensional alarm is triggered. Among them, EVZ is a detection threshold preset based on the entropy change characteristics of the mouse movement trajectory; For the click interval entropy change feature, if the abrupt change ratio of the click interval TBB > TBZ, it is determined that the click interval time is abnormal and a single-dimensional alarm is triggered. Wherein, TBZ is a detection threshold pre-set based on the entropy change characteristics of the click interval time; For the entropy change feature of keyboard input rhythm, if the coefficient of variation BY > BYZ of the time interval between keyboard keys, it is determined that the keyboard input rhythm is abnormal and a single-dimensional alarm is triggered. BYZ is a detection threshold pre-set based on the entropy change characteristics of keyboard input rhythm.
7. A network attack security detection method according to claim 6, characterized in that, The comprehensive anomaly score is calculated as follows: The system acquires micro-behavioral data of multiple historical windows during normal computer operation, and calculates the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm of multiple historical windows based on the micro-behavioral feature extraction steps. Subsequently, the maximum and minimum values of the features were obtained from the entropy change features of the historical mouse movement trajectory, the entropy change features of the click interval time, and the entropy change features of the keyboard input rhythm in multiple historical windows, respectively. Then, by combining the maximum and minimum values of the entropy change features from multiple historical windows, the entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm are normalized. Then passed: ; Calculate the Comprehensive Anomaly Score (ZHP); In the formula, TBB1, BY1, and YAB1 are the entropy change features of the current mouse movement trajectory, the click interval time, and the keyboard input rhythm after normalization, respectively.
8. The network attack security detection method according to claim 7, characterized in that, The normalization formula is: ; In the formula, GY0 represents the current entropy change features of mouse movement trajectory, click interval time, and keyboard input rhythm, and GY0 = {TBB, BY, YAB}. GY1 represents the normalized entropy change features of the current mouse movement trajectory, click interval time, and keyboard input rhythm, and is denoted as GY1 = {TBB1, BY1, YAB1}. max and GY min This refers to the maximum and minimum values of the entropy change features of mouse movement trajectories, click interval time, and keyboard input rhythm across multiple historical windows.
9. A network attack security detection method according to claim 7, characterized in that, Threat level assessment is conducted as follows: When only a single-dimensional alarm occurs and no global alarm occurs, and the difference between the comprehensive anomaly scores and the detection thresholds is greater than the corresponding preset score difference threshold, it is judged as low risk. When a single-dimensional anomaly occurs, and the overall anomaly score does not exceed the detection threshold, and the difference between the overall anomaly scores and the detection threshold is less than or equal to the corresponding preset score difference threshold, it is judged as medium risk. When multiple single-dimensional anomalies occur and a global alarm is triggered simultaneously, the risk level is determined to be high.
Citation Information
Patent Citations
Proposition person detection and verification method and system for online examination
CN119004429A
Keyboard and mouse intelligent control system based on Internet of Things
CN119271520A