Event detection method, device and equipment, medium and program product
Through a feature extraction model based on traceability diagram sequence, combined with Transformer and GRU neural network, the problem of difficulty in identifying APT attacks in the existing technology is solved, efficient abnormal detection of system events is achieved, and system security is improved.
Patent Information
- Application Number
- CN202410009577.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-07-04
AI Technical Summary
Existing anomaly detection methods are difficult to effectively identify and defend against advanced persistent cybersecurity attacks (APT attacks), especially when the system behavior is complex, the detection efficiency is not high and timely enough.
By building a feature extraction model based on traceability diagram sequence, combining the Transformer encoder-decoder and GRU neural network with self-attention mechanism, long and short-term features are extracted, and an end-to-end anomaly detection model is established using the Anomaly Score mechanism to perform anomaly detection of events.
It realizes convenient and fast abnormality detection of system events, improving system security, especially in detecting long-term APT attacks.
Smart Images

Figure CN120263432A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technologies, and in particular, to an event detection method, apparatus, device, medium, and program product. Background Art
[0002] With the development of Internet technologies, Internet security has become a key concern for people. In the field of network security, various system anomaly detection technologies are used to detect network security attacks and resolve these attacks to maintain system security. For some current attack events, such as APT attacks (Advanced Persistent Threat), due to their long duration and high concealment, it is difficult for traditional security devices and defense methods to effectively identify and defend against them. In recent years, the anomaly detection field has gradually paid more attention to attack events such as APT. By analyzing system call logs, the system behavior can be described more accurately, and then these system behaviors are analyzed to confirm abnormal events.
[0003] However, in actual scenarios, the system behavior is very complex, and the efficiency of current multiple anomaly behavior detection methods is not high, and there are problems such as untimely anomaly detection. Summary of the Invention
[0004] An embodiment of the present application provides an event detection method, which can conveniently and quickly perform anomaly detection on events in a system, thereby improving the efficiency of anomaly detection on events in the system, and further improving the security of the system.
[0005] On the one hand, an embodiment of the present application provides an event detection method, which includes:
[0006] Obtain a traceability graph sequence of a target event in the system;
[0007] Perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event;
[0008] Extract a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence;
[0009] Extract a second feature vector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism;
[0010] Perform anomaly detection on the target event according to the first feature vector and the second feature vector.
[0011] On the one hand, an embodiment of the present application provides an event detection device, which includes:
[0012] An acquisition unit, configured to acquire a traceability graph sequence of a target event in the system;
[0013] A processing unit, configured to perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event;
[0014] The processing unit is further configured to extract a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence;
[0015] The processing unit is further configured to extract a second feature vector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence based on a gating mechanism;
[0016] The processing unit is further configured to perform anomaly detection on the target event according to the first feature vector and the second feature vector.
[0017] On the one hand, an embodiment of the present application provides a computer device, including:
[0018] A storage device, configured to store a computer program;
[0019] A processor, configured to execute the computer program stored in the storage device to implement the above event detection method.
[0020] On the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program, and the computer program is loaded and executed by a processor to perform the above event detection method.
[0021] On the one hand, an embodiment of the present application provides a computer program product, which includes a computer program or computer instructions, and when the computer program or computer instructions are executed by a processor, the above event detection method is implemented.
[0022] In an embodiment of the present application, a traceability graph sequence of a target event in a system is obtained; feature extraction processing is performed on the traceability graph sequence to obtain a feature vector sequence of the target event; a first feature vector is extracted from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence; a second feature vector is extracted from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism; and anomaly detection is performed on the target event according to the first feature vector and the second feature vector. In the embodiment of the present application, different feature vectors between different positions can be extracted by using different feature encoding rules, and anomaly detection is performed on the target event based on the extracted feature vectors between different positions, so that anomaly detection of events in the system can be conveniently and quickly performed, thereby improving the anomaly detection efficiency of events in the system and further enhancing the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0024] Figure 1 A flowchart of an event detection provided by an embodiment of the present application;
[0025] Figure 2 A schematic diagram of a traceability graph provided by an embodiment of the present application;
[0026] Figure 3 A schematic diagram of the structure of an anomaly detection model provided by an embodiment of the present application;
[0027] Figure 4 An architecture diagram of an event detection system provided by an embodiment of the present application;
[0028] Figure 5 A flowchart of an event detection method provided by an embodiment of the present application;
[0029] Figure 6 A flowchart of another event detection method provided by an embodiment of the present application;
[0030] Figure 7 A schematic diagram of the structure of an event detection device provided by an embodiment of the present application;
[0031] Figure 8A schematic structural diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0032] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0033] The embodiment of the present application provides an event detection solution. This event detection solution involves AI (Artificial Intelligence). The so-called AI is to use a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results in terms of theory, method, technology, and application system. In other words, artificial intelligence is a comprehensive technology in computer science. It attempts to understand the essence of intelligence and produce a new intelligent machine that can react in a way similar to human intelligence. Artificial intelligence also studies the design principles and implementation methods of various intelligent machines, enabling the machines to have the functions of perception, reasoning, and decision-making. Artificial intelligence technology is an interdisciplinary subject involving a wide range of fields, including both hardware-level technologies and software-level technologies. The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, pre-trained model technology, operation / interaction systems, mechatronics, etc. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning. In addition, the embodiment of the present application also involves Machine Learning (ML). ML is an interdisciplinary subject involving multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how a computer simulates or realizes human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve its own performance. Machine learning is the core of artificial intelligence and the fundamental way to make a computer intelligent. Its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning.
[0034] The general principle of the event detection solution provided by the embodiments of this application is as follows: Considering that attack events (such as APT attacks (Advanced Persistent Threat, advanced persistent cybersecurity attacks)) have characteristics such as high pertinence, strong concealment, and long duration, in the embodiments of this application, a traceability graph sequence is first used to record the system behavior when the system processes events such as data requests and instructions initiated by an external party. Through the traceability graph sequence, the system state changes during the processing of this event can be described more accurately. Then, dimensionality reduction processing is performed on the feature vectors in the traceability graph sequence to remove some unnecessary information, obtaining a feature vector sequence. Further, since real attack events contain both long-term features and short-term features, in the embodiments of this application, a neural network structure of a Transformer encoder-decoder based on the self-attention mechanism and a GRU (Gated Recurrent Unit) are used to construct a feature extraction model. This feature extraction model extracts the feature reconstruction vector of the event by fusing long-term and short-term features, which can fully consider the long-term and short-term features of attack events, and uses the Anomaly Score mechanism to establish an end-to-end anomaly detection model to achieve anomaly detection of events in the system.
[0035] Please refer to Figure 1 , which is a schematic flowchart of an event detection provided by the embodiments of this application. In Figure 1 , this event detection process includes the following three stages: The first stage: Traceability graph feature sequence extraction; The second stage: Long and short sequence feature fusion; The third stage: Anomaly detection of events.
[0036] (1) The first stage: Traceability graph feature sequence extraction
[0037] Obtain the traceability graph sequence of the target event in the system, and perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence. This traceability graph sequence includes the node objects that appear during the process of the system processing the target event and the processing relationships between the node objects. It should be understood that in the traceability graph, all system-level entities are regarded as node objects, and the operations between entities are regarded as edges. The traceability graph sequence is directed graph structure data. This method is expected to improve the recognition and prevention effectiveness of attack events (such as APT attacks) and provide more comprehensive security protection. It should be understood that through the traceability graph, the system behavior generated when the system processes the target event can be recorded. The target event here can include: a request, an instruction, etc., and the embodiments of this application do not make any limitations in this regard. Schematically, as Figure 2 shown, which is a schematic diagram of a traceability graph provided by the embodiments of this application. In Figure 2 , the node objects can be divided into two types. One type of node object is the subject of the operation, such asFigure 2 It mainly includes processes, threads, services (Nginx), etc. Nginx is a high-performance HTTP (Hypertext Transfer Protocol) and reverse proxy web server. Another type of node object is the object that is passively received, such as Figure 2 It includes files, registries, sockets, etc. Sockets can be, for example, network ports, network addresses (such as Figure 2 155.162.39.48 in Figure 2 ). Schematically, when the system processes a target event, which processes or threads will be involved in the system to perform read and write operations on a certain file. At this time, the node objects can include processes and files, and the processing relationship between node objects includes the process performing a write operation on the file. Schematically, if the target event is an attack event, then
[0038] It should be understood that when the system processes a target event at different time periods, the traceability graph sequences for each time period are different. For example, in Figure 1 the traceability graph sequences of the target event are different in four different time periods, that is, as time goes by, more system behaviors generated by the system when processing the target event are recorded in the traceability graph sequence. In Figure 1 abnormal system behaviors occurred when the system processed the target event in the third and fourth time periods, that is, as shown in Figure 1 11 in
[0039] (2) The second stage: fusion of long and short feature sequences
[0040] In the embodiments of the present application, considering the long-term and concealed nature of attack events, a feature extraction model can be trained. The feature extraction model can include a neural network structure of a Transformer encoder-decoder with a self-attention mechanism and a GRU. The neural network structure of the Transformer encoder-decoder based on the self-attention mechanism is combined with the GRU for cross-training. During the cross-training process, the neural network structure of the Transformer encoder-decoder with the self-attention mechanism and the GRU are trained by minimizing the feature reconstruction error. Finally, the trained feature extraction model can extract features from the feature vector sequence of the target event. Among them, the neural network structure of the Transformer encoder-decoder based on the self-attention mechanism can be used to extract features according to the long-distance dependence relationship between different positions in the feature vector sequence. The finally extracted feature vector can be called the long-term feature. The GRU is used to extract features according to the dependence relationship between different positions in the feature vector sequence through a gating mechanism. The finally extracted feature vector can be called the short-term feature.
[0041] After the feature extraction model is trained, during the testing or application process, only the encoder part of the trained feature extraction model is used to extract the feature vector of the event, that is, only the encoder in the Transformer and the encoder in the GRU are used to extract the feature vector of the event. Taking the target event in the system as an example, the encoder in the Transformer and the encoder in the GRU can be used to extract the features of the feature vector sequence of the target event respectively, and the first feature vector and the second feature vector are obtained respectively. The first feature vector is the long-term feature of the target event, and the second feature vector is the short-term feature of the target event. After obtaining the first feature vector and the second feature vector, the first feature vector and the second feature vector can be subjected to feature reconstruction processing to obtain a feature reconstruction vector.
[0042] By using the Transformer+GRU model to model the system state change, the long-term and short-term impacts on the system when the system processes a certain event are extracted, so that the features of the attack behavior of the attack event are more easily distinguishable from normal behaviors.
[0043] (3) The anomaly detection model performs anomaly detection on the event
[0044] Please refer to Figure 3, which is a schematic structural diagram of an anomaly detection model provided by an embodiment of the present application. First, multiple normal sample events and unknown sample events are input, and the feature reconstruction vectors of the multiple normal sample events are clustered using the Anomaly Score algorithm to obtain cluster centers. Then, the isolation score of the unknown sample events is calculated through the isolation forest, and the similarity score between the feature reconstruction vectors of the unknown sample events and the nearest cluster center (the nearest cluster center refers to the cluster center corresponding to the maximum similarity between the feature reconstruction vector and each cluster center) is determined. The detection score of the unknown sample events is calculated according to a certain weight to screen out the pseudo-labels of the target events, and the pseudo-labels include one of the following: potentially normal and reliable abnormal samples. The implementation steps include: 1. Obtain multiple sample events, where the multiple sample events include known normal sample events, unknown sample events, etc.; cluster the known normal sample events to obtain K cluster centers. As Figure 3 In this case, clustering the known normal sample events can obtain 3 cluster centers. Calculate the similarity score of the unknown sample events according to the distances from the unknown sample events to each cluster center. 2. Introduce the concept of isolation forest, which is used to calculate the isolation score of the unknown sample events. Specifically, use the isolation forest algorithm to determine the isolation score of the unknown sample events. 3. Calculate the detection score of the unknown sample events by weighted combination of the similarity score and the isolation score. According to the detection score of the unknown sample events, a pseudo-label can be set for the unknown sample events. Schematically, as Figure 3 In this case, the detection scores of some sample events in the unknown sample events are 0.6 and 0.5 respectively. According to the detection score and the preset threshold, it can be determined that these sample events are added with reliable abnormal labels; the normal scores of some other sample events are 0.99, 0.9, 0.89, and 0.88 respectively. According to the detection score and the preset threshold, it can be determined that these sample events are added with potentially normal labels. 4. Introduce a classification model and perform classification operations in combination with the detection score and pseudo-label of the sample events. Schematically, the classification model can include but is not limited to: LGBMClassifier (Light Gradient Boosting Machine Classifier, an ensemble learning classification model based on decision trees).
[0045] It should be understood that after training the anomaly detection model with multiple sample events and unknown sample events, during subsequent testing or application, the similarity between the target event and the K clustering centers can be directly determined, and the similarity corresponding to the nearest clustering center is used as the similarity score of the target event. Then, the isolation score of the target event is obtained. Based on the similarity score and the estimated score, the detection score of the target event can be determined. Thus, the detection score, the feature reconstruction vector of the target event, and the pseudo label can be input into the classification model to perform a classification operation on the target event, and the anomaly detection result of the target event can be obtained.
[0046] Through the above solution, by establishing a traceability graph sequence, the system state changes during event processing can be captured, and by constructing a traceability graph sequence, a basis for anomaly detection can be provided. In addition, in the embodiments of the present application, by extracting long-term and short-term features from the feature vector sequence corresponding to the traceability graph sequence, when analyzing longer data, context association information with a longer interval can be captured, resulting in better event detection effects in the system. Further, the long-term features and short-term features are reconstructed to obtain a feature reconstruction vector, and based on the feature reconstruction vector and the K clustering centers, anomaly detection of events in the system is performed, which can effectively detect anomalies in events in the system, improve the security of the system, and is more suitable for effectively detecting long-term APT attacks in the industrial field.
[0047] In addition to the above solution, in some other embodiments, the anomaly detection of events can also be achieved by using a sequence feature extraction method. Specifically, first, the traceability graph sequence describing the system operation state is converted into a feature vector sequence, and then a GRU (Gate Recurrent Unit) model is used to extract the features of the system state change. In addition, an encoder-decoder model combined with a local attention mechanism is used to train the GRU model, and finally, a clustering method (such as the K-means algorithm (Kmeans)) is used to model the normal behavior of the system.
[0048] Next, the event detection system provided by the embodiments of the present application will be described in detail.
[0049] Please refer to Figure 4 , which is an architecture diagram of an event detection system provided by the embodiments of the present application. The event detection system includes a computer device 101 and a server 102. It should be understood that the embodiments of the present application do not make any limitations on the number and form of the terminal device and the server. Among them:
[0050] The computer device 101 can be used to obtain the call logs of the system from the server 102, generate a sequence of traceability graphs for the target event based on the call logs, convert the sequence of traceability graphs into a sequence of feature vectors, then extract a first feature vector from the sequence of feature vectors according to a first feature encoding rule and extract a second feature vector from the sequence of feature vectors according to a second feature encoding rule. Schematically, the first feature encoding rule can include the encoder in the above-mentioned transformer, and the second feature encoding rule includes the encoder in the above-mentioned GRU. Further, based on the first feature vector and the second feature vector, anomaly detection can be performed on the target event in the system to determine whether the target event is an abnormal event or an attack event. The server 102 can be deployed with various systems, such as various business systems, data storage systems, etc. The server 102 can store the call logs of the system.
[0051] The computer device can be a terminal device or a server. The terminal device can include, but is not limited to: smart phones, tablet computers, smart wearable devices, smart voice interaction devices, smart home appliances, personal computers, vehicle-mounted terminals, smart cameras, virtual reality devices (such as AR (Augmented Reality) devices), and so on. This application does not limit this. The server can include, but is not limited to: an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms, and so on. The so-called cloud computing refers to the delivery and usage model of IT infrastructure, which means obtaining the required resources in a on-demand and easily expandable manner through the network; generalized cloud computing refers to the delivery and usage model of services, which means obtaining the required services in a on-demand and easily expandable manner through the network. Such services can be related to IT and software, the Internet, or other services. Cloud computing is the product of the development and integration of traditional computer and network technologies such as Grid Computing, Distributed Computing, Parallel Computing, Utility Computing, Network Storage Technologies, Virtualization, and Load Balance. The so-called cloud storage is a new concept extended and developed from the cloud computing concept. A distributed cloud storage system (hereinafter referred to as the storage system) refers to a storage system that combines a large number of different types of storage devices (storage devices are also called storage nodes) in the network through cluster applications, grid technologies, and distributed storage file systems, and collaborates through application software or application interfaces to jointly provide data storage and business access functions to the outside world.
[0052] Next, the event detection method provided by the embodiments of this application will be elaborated.
[0053] Please refer to Figure 5 , which is a schematic flowchart of an event detection method provided by the embodiments of this application. This event detection method can be executed by a computer device. This event detection method can include the following steps: S501-S505:
[0054] S501. Obtain the traceability graph sequence of the target event in the system.
[0055] The system here may include but is not limited to: various business systems, data storage systems, etc. The target events may include but are not limited to: instructions, requests, etc. The traceability graph sequence includes: the node objects that appear during the system's processing of the target event and the processing relationships between the node objects. The traceability graph sequence can more accurately describe the system behavior state of the system when processing the target event.
[0056] In one implementation, when the system receives a target event, it can process the target event. The computer device can analyze the system call logs and generate a traceability graph sequence for the target event according to the analysis results. The traceability graph sequence can be as Figure 2 shown.
[0057] S502. Perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event.
[0058] In one implementation, feature extraction processing can be performed on the node objects of the traceability graph sequence and the processing relationships between the node objects to obtain an initial feature vector sequence of the target event. As Figure 1 shown, first, histogram statistics can be performed on the processing relationships between the node objects of the traceability graph sequence to obtain a histogram, which represents the system behavior generated when the system processes the target event. If new edges are generated, the counting result of the histogram is updated in real time. Then, the histogram is processed to obtain an initial feature vector sequence of the target event. Further, the initial feature vector sequence of the target event includes the system behavior in different time periods when processing the target event. In the embodiments of the present application, the initial feature vector sequence can be dimensionally reduced to obtain a feature vector sequence of the target event. Through dimensionality reduction processing, the core information for anomaly detection of the target event can be extracted, and some unnecessary information in the initial feature vector sequence can be removed. Schematically, the unnecessary information may include the time information in the initial feature vector sequence. For example, if a certain system behavior occurs at a certain time, then the time is unnecessary information, while the system behavior is the core information. Through dimensionality reduction processing, the unnecessary time information can be removed.
[0059] S503. Extract a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence. Through the first feature encoding rule, the context correlation relationship with a longer interval can be better captured, which is beneficial to subsequent anomaly detection of the target event.
[0060] Among them, the first feature encoding rule may include a first feature encoding module. Schematically, the first feature encoding module may be an encoder in a transformer. In one implementation, each feature vector in the feature vector sequence and the position information of each feature vector in the feature vector sequence are obtained, and each feature vector and the corresponding position information are input into the first feature encoding module to obtain the first feature vector output by the first feature encoding block.
[0061] S504. A second feature vector is extracted from the feature vector sequence based on the second feature encoding rule. The second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism. The difference between the first feature encoding rule and the second feature encoding rule is that: the first feature encoding rule takes into account that the information at the current position has a strong correlation with its context information. Therefore, the first feature encoding rule focuses on the extraction of long-distance context features in the feature vector sequence. The second feature encoding rule can also perform long-distance feature extraction on the feature vector sequence, but the length of the positions on which the second feature encoding rule depends when extracting the feature vector is shorter than the length of the positions on which the first feature rule depends when extracting the feature vector. Therefore, the first feature vector extracted by the first feature encoding rule can be called a long-term feature vector, and the second feature vector extracted by the second feature encoding rule can be called a short-term feature vector.
[0062] Among them, the second feature encoding rule may include a second feature encoding module, and the gating mechanism may include an update gate and a reset gate. The update gate and the reset gate can control the information flow in the feature vector sequence. The update gate and the reset gate can determine which position feature information in the feature vector sequence needs to be retained, which feature information should be forgotten, and which feature information needs to be replaced by new input information. In one implementation, each feature vector and the corresponding position information can be input into the first feature encoding module, and the feature vector sequence is processed through the reset gate and the update gate in the first feature encoding module to obtain a first type of feature vector and a second type of feature vector. The first type of feature vector contains the feature information to be retained in the feature vector sequence, and the second type of feature vector contains the feature information to be forgotten in the feature vector sequence; the second feature vector is determined according to the first feature vector and the second type of feature vector. In one implementation, the update gate is used to control the degree to which the feature information of the previous position is retained to the current position. The larger the value of the update gate, the more feature information of the previous position is retained. The reset gate is used to control the degree of forgetting the feature information of the previous position. The smaller the value of the reset gate, the more is forgotten; through the update gate and the reset gate, the dependence relationship between different positions in the feature vector sequence can be better used for feature extraction. Schematically, the second feature encoding module includes an encoder in a GRU.
[0063] S505. Perform anomaly detection on the target event according to the first eigenvector and the second eigenvector.
[0064] In some implementation manners, performing anomaly detection on the target event according to the first eigenvector and the second eigenvector may specifically include: performing feature reconstruction processing on the first eigenvector and the second eigenvector to obtain a feature reconstruction vector, and according to the feature reconstruction vector, invoking an anomaly detection model to perform anomaly detection on the target event.
[0065] In the embodiments of the present application, obtain a traceability graph sequence of a target event in the system; perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event; extract a first eigenvector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence; extract a second eigenvector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism; perform anomaly detection on the target event according to the first eigenvector and the second eigenvector. In the embodiments of the present application, different eigenvectors between different positions can be extracted by using different feature encoding rules, and anomaly detection is performed on the target event based on the extracted eigenvectors between different positions, so that anomaly detection of events in the system can be conveniently and quickly performed, thereby improving the anomaly detection efficiency of events in the system and further improving the security of the system.
[0066] Please refer to Figure 6 , which is a schematic flowchart of an event detection method provided by an embodiment of the present application. This event detection method can be executed by the above computer device 101. The event detection method provided by the embodiments of the present application may include the following steps S601-S605:
[0067] S601. Obtain a traceability graph sequence of a target event in the system.
[0068] S602. Perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event.
[0069] Among them, the specific implementation manners of steps S601-S602 can refer to the descriptions in the corresponding parts above, and will not be elaborated here.
[0070] S603. Extract a first eigenvector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence.
[0071] Among them, the first feature encoding rule includes a first feature encoding module. The first feature encoding module includes 6 layers, and each layer contains two sub-layers. The first sub-layer is a multi-head self-attention mechanism, which is used to calculate the self-attention of the input. The second sub-layer is a fully connected network. By obtaining each feature vector in the feature vector sequence and the position information of each feature vector in the feature vector sequence, and inputting each feature vector in the feature vector sequence and the position information of each feature vector in the feature vector sequence into each layer in the first feature encoding module for feature extraction, the first feature vector output by the first feature encoding module is obtained.
[0072] S604. Extract a second feature vector from the feature vector sequence based on the second feature encoding rule. The second feature encoding module is used to indicate feature extraction according to the dependency relationship between different positions in the feature vector sequence based on the gating mechanism. The second feature encoding rule includes a second feature encoding module.
[0073] It should be understood that the first feature encoding module and the second feature encoding module are respectively used to extract long-term and short-term feature vectors. Specifically, the first feature vector extracted based on the first feature encoding module can be a long-term feature vector, and the second feature vector extracted based on the second feature encoding module can be called a short-term feature vector. In the embodiments of the present application, cross-training can be used to obtain the first feature encoding module and the second feature encoding module. Specifically, a sample event set is obtained, and the sample event set includes M sample events. In one implementation, the initial first sample feature vectors of each sample event can be extracted from the feature vector sequences of each sample event by using the initial first feature encoding module, and the initial second sample feature vectors of each sample event can be extracted from the feature vector sequences of each sample event by using the initial second feature encoding module; feature reconstruction processing is respectively performed on the initial first sample feature vectors and the initial second sample feature vectors of each sample event to respectively obtain the initial sample feature reconstruction vectors of each sample event; according to the initial sample feature reconstruction vectors of each sample event and the feature vector sequences of each sample event, cross-training is performed on the initial first feature encoding module and the initial second feature encoding module to obtain the first feature encoding module and the second feature encoding module.
[0074] Among them, cross-training the initial first feature encoding module and the initial second feature encoding module according to the initial sample feature reconstruction vectors of each sample event and the feature vector sequences of each sample event to obtain the first feature encoding module and the second feature encoding module includes: ① Using the first feature decoding module corresponding to the initial first feature encoding module to decode the initial sample feature reconstruction vectors of each sample event to obtain the first decoded feature vectors of each sample event. Among them, when the first feature encoding module includes the encoder of the transformer, the first feature decoding module corresponding to the first feature encoding module includes the decoder of the transformer. The first feature decoding module includes 6 layers, and each layer includes three sub-layers. The first sub-layer is the masked multi-head attention mechanism, and the first sub-layer is used to calculate the self-attention of the input. The second sub-layer is a fully connected layer similar to the first feature encoding module, and the third sub-layer can calculate the attention of the input of the first feature encoding module. In the embodiment of the present application, the initial sample feature vectors of each sample event are input into the first feature decoding module, and after 6 layers of processing in the first feature decoding module, the first decoded feature vectors of each sample event are obtained. ② Using the second feature decoding module corresponding to the initial second feature encoding module to decode the initial sample feature reconstruction vectors of each sample event to obtain the second decoded feature vectors of each sample event. Schematically, the initial second feature encoding module includes the encoder in the GRU, and correspondingly, the initial second feature encoding module may include the decoder in the GRU. ③ Based on the first decoded feature vectors, the second decoded feature vectors of each sample event and the feature vector sequences of each sample event, determine the reconstruction feature error of each sample event. ④ Adjust the parameters in the initial first feature encoding module and the parameters in the initial second feature encoding module in the direction of minimizing the reconstruction feature error to obtain the first feature encoding module and the second feature encoding module.
[0075] S605. Perform feature reconstruction processing on the first feature vector and the second feature vector to obtain a feature reconstruction vector.
[0076] In some implementation manners, the feature reconstruction processing includes feature fusion, and the first feature vector and the second feature vector can be fused to obtain a feature reconstruction vector. By fusing the first feature vector and the second feature vector, the long-term and short-term feature vectors corresponding to the target event can be better utilized to perform anomaly detection on the target event.
[0077] S606. Perform anomaly detection on the target event according to the feature reconstruction vector and the K clustering centers, where the K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to multiple sample events.
[0078] In one implementation, the feature reconstruction vectors corresponding to multiple sample events can be clustered according to a clustering algorithm to obtain K clustering centers, where K is a positive integer. The K clustering centers are normal events selected from the multiple sample events. A so-called normal event refers to an event that does not pose a security risk to the system. For example, a request with access permission is a normal event. Correspondingly, an abnormal event can refer to an event that poses a certain security risk to the system or the information in the system. For example, a request without access permission is an abnormal event, and an APT attack event is also an abnormal event. Among them, the clustering algorithm can include, but is not limited to: Kmeans (a clustering algorithm), etc., and the embodiments of the present application do not make any limitations in this regard. In another implementation, the K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events using an anomaly detection model. At this time, M sample events in the sample event set include the sample labels corresponding to the N sample events. Here, the sample labels are used to identify the corresponding sample events as normal events. That is, in the embodiments of the present application, the sample event set can include N sample events known to be normal events and M - N unknown sample events. M is an integer greater than 1, and M is greater than or equal to N. Specifically, the first sample feature vectors of each sample event are extracted from the feature vector sequence of each sample event based on the first feature encoding rule, and the second sample feature vectors of each sample event are extracted from the feature vector sequence of each sample event based on the second feature encoding rule; the first sample feature vectors and the second sample feature vectors of each sample event are respectively subjected to feature reconstruction processing to obtain the sample feature reconstruction vectors of each sample event. The sample feature reconstruction vectors of the N sample events are clustered to obtain multiple initial clustering centers, and K clustering centers are obtained according to the multiple initial clustering centers; based on the multiple initial clustering centers and the feature reconstruction vectors of the M - N sample events, the anomaly detection model is trained, and the trained anomaly detection model can be used to detect anomalies in the events in the system. Among them, the anomaly detection model can be as Figure 3 shown.
[0079] In some implementations, step S606 may specifically include steps s41 - s42:
[0080] s41. Determine the detection score of the target event according to the feature reconstruction vector and the K clustering centers.
[0081] In one implementation, the specific implementation of step S41 may include: determining the similarity between the feature reconstruction vector and each cluster center. Specifically, the distance from the feature reconstruction vector to each cluster center can be determined, and the distance from the feature reconstruction vector to each cluster center is used as the similarity between the feature reconstruction vector and each cluster center. Then, the maximum similarity is selected from the similarities between the feature reconstruction vector and each cluster center as the detection score of the target event. Schematically, K = 2, and the two cluster centers are cluster center 1 and cluster center 2 respectively. The distance between cluster center 1 and the feature reconstruction vector is used as the similarity between the feature reconstruction vector and cluster center 1, and the distance between cluster center 2 and the feature reconstruction vector is used as the similarity between the feature reconstruction vector and cluster center 2. If the similarity between the feature reconstruction vector and cluster center 2 is greater than the similarity between the feature reconstruction vector and cluster center 1, then the similarity between the feature reconstruction vector and cluster center 2 can be determined as the detection score of the target event. It should be understood that the larger the detection score, the closer the target event is to a normal event; the smaller the detection score, the closer the target event is to an abnormal event.
[0082] In another implementation, the specific implementation of step S41 may include: determining the similarity between the feature reconstruction vector and each cluster center, selecting the maximum similarity from the similarities between the feature reconstruction vector and each cluster center as the similarity score of the target event, using the isolation forest algorithm to determine the isolation score of the target event, and then determining the detection score of the target event according to the similarity score and the isolation score. Among them, the similarity score and the isolation score can be weighted and summed according to a certain weight ratio to obtain the detection score of the target event. Schematically, assume that the weight ratios of the similarity score and the isolation score are 60% and 40% respectively; the similarity score is 0.6, and the isolation score is 0.4. The detection score of the target event is: 0.6 * 60% + 0.4 * 40% = 0.52. Of course, the similarity score and the isolation score can also be directly averaged to obtain the detection score of the target event. Schematically, in the above example, the detection score of the target event is (0.6 + 0.4) / 2 = 0.5.
[0083] S42. Based on the detection score of the target event and a preset threshold, perform anomaly detection on the target event.
[0084] In the embodiments of the present application, a preset threshold is introduced, and this preset threshold can be set according to requirements. The specific implementation process of step S42 includes: determining whether the detection score is greater than the preset anomaly threshold. If the detection score is greater than the preset threshold, it can be determined that the target event is a normal event; if the detection score is less than or equal to the preset threshold, it can be determined that the target event is an abnormal event. In another implementation manner, based on the detection score of the target event and the preset threshold, pseudo-labels are added to the target event. The pseudo-labels can include two types: the first label and the second label. The first label is used to indicate that the target event is potentially normal. The so-called potentially normal means that it may be a normal event. The second label is used to indicate that the target event is reliably abnormal. The so-called reliably abnormal means that it is very likely to be an abnormal event. If the detection score is greater than the preset threshold, the first label is added to the target event; if the detection score is less than or equal to the preset threshold, the second label is added to the target event. Then, based on the feature reconstruction vector, the detection score, and the pseudo-labels, anomaly detection is performed on the target event to obtain the anomaly detection result of the target event. In the embodiments of the present application, a classification model can be introduced. The feature reconstruction vector, the detection score, and the pseudo-labels are input into the trained classification model, and the classification result output by the trained classification model is used as the anomaly detection result of the target event. This anomaly detection result includes abnormal events or normal events.
[0085] In the embodiments of the present application, a traceability graph sequence of a target event in the system is obtained; feature extraction processing is performed on the traceability graph sequence to obtain a feature vector sequence of the target event; a first feature vector is extracted from the feature vector sequence based on a first feature encoding rule, and the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence; a second feature vector is extracted from the feature vector sequence based on a second feature encoding rule, and the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism; feature reconstruction processing is performed on the first feature vector and the second feature vector to obtain a feature reconstruction vector; anomaly detection is performed on the target event according to the feature reconstruction vector and K clustering centers, and the K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events. It can be seen that in the embodiments of the present application, considering that attack events include not only long-term behaviors but also short-term behaviors, the embodiments of the present application can perform feature reconstruction on the extracted first feature vector and second feature vector, which is beneficial to anomaly detection of the target event. In addition, the embodiments of the present application provide K clustering centers, and anomaly detection is performed on the target event according to the K clustering centers and the feature reconstruction vector, which can conveniently and quickly perform anomaly detection on the events in the system, improve the efficiency and accuracy of event detection in the system, and further improve the security of the system.
[0086] In some implementations, the object detection method provided by the embodiments of the present application can be implemented on five publicly available datasets. In order to effectively evaluate the experimental results, a standard confusion matrix for binary classification tasks is adopted. The confusion matrix is shown in the following table:
[0087]
[0088] In the confusion matrix, TP represents the number of samples that predict the positive class as the positive class (the positive class refers to normal events), TN represents the number of samples that predict the negative class as the negative class (the negative class refers to abnormal events), FP represents the number of samples that predict the negative class as the positive class, and FN represents the number of samples that predict the positive class as the negative class. According to the confusion matrix, three evaluation indicators can be obtained, including accuracy, precision, and recall:
[0089] Accuracy = (TP + TN) / (TP + FN + FP + TN)
[0090] Precision = TP / (TP + FP)
[0091] Recall = TP / (TP + FN)
[0092] Through the above three evaluation indicators, the event detection method provided by the embodiments of the present application can achieve better detection effects on abnormal events, such as attack events with characteristics of long duration and high concealment, compared with some other anomaly detection methods. It can more effectively detect abnormal events in the system and improve the security of the system.
[0093] Next, the event detection device provided by the embodiments of the present application will be described in detail.
[0094] Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of an event detection device provided by the embodiments of the present application. The event detection device can be a computer program (including program code) in a computer device. For example, the event detection device can be an application software in a computer device. The event detection device can be used to execute Figure 5 and Figure 6 some or all of the steps in the method embodiments shown. Please refer to Figure 7 . The event detection device includes the following units:
[0095] An acquisition unit 701, configured to acquire a traceability graph sequence of a target event in the system;
[0096] A processing unit 702, configured to perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event;
[0097] The processing unit 702 is further configured to extract a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence;
[0098] The processing unit 702 is further configured to extract a second feature vector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism;
[0099] The processing unit 702 is further configured to perform anomaly detection on the target event according to the first feature vector and the second feature vector.
[0100] Among them, the processing unit 702 is specifically configured to:
[0101] Perform feature reconstruction processing on the first feature vector and the second feature vector to obtain a feature reconstruction vector;
[0102] Perform anomaly detection on the target event according to the feature reconstruction vector and K cluster centers, where the K cluster centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events, and each sample event corresponding to the K cluster centers is a selected normal event; N is an integer greater than 1, and K is a positive integer.
[0103] Among them, the processing unit 702 is specifically configured to:
[0104] Determine the detection score of the target event according to the feature reconstruction vector and K cluster centers;
[0105] Perform anomaly detection on the target event based on the detection score of the target event and a preset threshold.
[0106] Among them, the processing unit 702 is specifically configured to:
[0107] Add a pseudo label to the target event based on the detection score of the target event and a preset threshold; where, if the detection score is greater than the preset threshold, the pseudo label includes a first label, and if the detection score is less than or equal to the preset threshold, the pseudo label includes a second label;
[0108] Perform anomaly detection on the target event based on the feature reconstruction vector, the detection score, and the pseudo label to obtain the anomaly detection result of the target event.
[0109] Among them, the processing unit 702 is specifically configured to:
[0110] Determine the similarity between the feature reconstruction vector and each cluster center;
[0111] Select the maximum similarity from the similarities between the feature reconstruction vector and each clustering center as the similarity score of the target event;
[0112] Use the isolation forest algorithm to determine the isolation score of the target event;
[0113] Determine the detection score of the target event according to the similarity score and the isolation score.
[0114] Among them, the traceability graph sequence includes: node objects that appear during the system's processing of the target event and the processing relationships between the node objects; the processing unit 702 is specifically used for:
[0115] Perform feature extraction processing on the node objects of the traceability graph sequence and the processing relationships between the node objects to obtain the initial feature vector sequence of the target event;
[0116] Perform dimensionality reduction processing on the initial feature vector sequence to obtain the feature vector sequence of the target event.
[0117] Among them, the K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events using the anomaly detection model; the processing unit 702 is further used for:
[0118] Obtain a sample event set, the sample event set includes M sample events, among which, the sample event set includes the sample labels corresponding to N sample events, M is an integer greater than 1, and M is greater than or equal to N;
[0119] Extract the first sample feature vectors of each sample event from the feature vector sequence of each sample event based on the first feature encoding rule, and extract the second sample feature vectors of each sample event from the feature vector sequence of each sample event based on the second feature encoding rule;
[0120] Perform feature reconstruction processing on the first sample feature vector and the second sample feature vector of each sample event respectively to obtain the sample feature reconstruction vectors of each sample event;
[0121] Perform clustering processing on the sample feature reconstruction vectors of N sample events to obtain multiple initial clustering centers, and obtain K clustering centers according to the multiple initial clustering centers;
[0122] Based on the multiple initial clustering centers and the feature reconstruction vectors of M - N sample events, train the anomaly detection model.
[0123] Among them, the first feature encoding rule includes a first feature encoding module, the second feature encoding rule includes a second feature encoding module, and the processing unit 702 is further used for:
[0124] The initial first sample feature vectors of each sample event are extracted by using an initial first feature encoding module, and the initial second sample feature vectors of each sample event are extracted by using an initial second feature encoding module;
[0125] Feature reconstruction processing is respectively performed on the initial first sample feature vectors and the initial second sample feature vectors of each sample event to respectively obtain the initial sample feature reconstruction vectors of each sample event;
[0126] According to the initial sample feature reconstruction vectors of each sample event and the feature vector sequences of each sample event, cross-training is performed on the initial first feature encoding module and the initial second feature encoding module to obtain a first feature encoding module and a second feature encoding module.
[0127] Among them, the processing unit 702 is specifically used for:
[0128] The first decoding feature vectors of each sample event are obtained by performing decoding processing on the initial sample feature reconstruction vectors of each sample event by using a first feature decoding module corresponding to the initial first feature encoding module;
[0129] The second decoding feature vectors of each sample event are obtained by performing decoding processing on the initial sample feature reconstruction vectors of each sample event by using a second feature decoding module corresponding to the initial second feature encoding module;
[0130] Based on the first decoding feature vectors, the second decoding feature vectors of each sample event and the feature vector sequences of each sample event, the reconstruction feature errors of each sample event are determined;
[0131] In the direction of minimizing the reconstruction feature error, the parameters in the initial first feature encoding module and the parameters in the initial second feature encoding module are adjusted to obtain a first feature encoding module and a second feature encoding module.
[0132] Based on the same inventive concept, the principles and beneficial effects of the problems solved by the event detection device provided in the embodiments of the present application can be referred to the principles and beneficial effects described in the above method embodiments. For the sake of brevity, they will not be repeated here.
[0133] Next, the computer device provided in the embodiments of the present application will be described in detail.
[0134] Furthermore, the embodiments of the present application also provide a structural schematic diagram of a computer device. The structural schematic diagram of the computer device can be referred to Figure 8; The computer device may include: a processor 801, an input device 802, an output device 803, and a memory 804. The above-mentioned processor 801, input device 802, output device 803, and memory 804 are connected through a bus. The memory 804 is used to store a computer program, and the computer program includes program instructions. The processor 801 is used to execute the program instructions stored in the memory 804.
[0135] In one embodiment, the processor 801 is configured to obtain a traceability graph sequence of a target event in the system by running the program instructions in the memory 804; perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event; extract a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence; extract a second feature vector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism; and perform anomaly detection on the target event according to the first feature vector and the second feature vector.
[0136] In a possible embodiment, when the processor 801 performs anomaly detection on the target event according to the first feature vector and the second feature vector, it may be configured to perform feature reconstruction processing on the first feature vector and the second feature vector to obtain a feature reconstruction vector; perform anomaly detection on the target event according to the feature reconstruction vector and K cluster centers, where the K cluster centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events, and each sample event corresponding to the K cluster centers is a selected normal event; N is an integer greater than 1, and K is a positive integer.
[0137] In a possible embodiment, when the processor 801 performs anomaly detection on the target event according to the feature reconstruction vector and K cluster centers, it may be configured to determine a detection score of the target event according to the feature reconstruction vector and K cluster centers; and perform anomaly detection on the target event based on the detection score of the target event and a preset threshold.
[0138] In a possible embodiment, when the processor 801 determines the detection score of the target event according to the feature reconstruction vector and K cluster centers, it may be configured to add a pseudo label to the target event based on the detection score of the target event and a preset threshold; where, if the detection score is greater than the preset threshold, the pseudo label includes a first label, and if the detection score is less than or equal to the preset threshold, the pseudo label includes a second label; and perform anomaly detection on the target event based on the feature reconstruction vector, the detection score, and the pseudo label to obtain an anomaly detection result of the target event.
[0139] In a possible embodiment, when determining the detection score of a target event based on the feature reconstruction vector and K clustering centers, the processor 801 can be used to determine the similarity between the feature reconstruction vector and each clustering center; select the maximum similarity from the similarities between the feature reconstruction vector and each clustering center as the similarity score of the target event; use the isolation forest algorithm to determine the isolation score of the target event; and determine the detection score of the target event according to the similarity score and the isolation score.
[0140] In a possible embodiment, the traceability graph sequence includes: node objects that appear during the system's processing of the target event and the processing relationships between the node objects; when the processor 801 performs feature extraction processing on the traceability graph sequence to obtain the feature vector sequence of the target event, it can be used to perform feature extraction processing on the node objects of the traceability graph sequence and the processing relationships between the node objects to obtain the initial feature vector sequence of the target event; and perform dimensionality reduction processing on the initial feature vector sequence to obtain the feature vector sequence of the target event.
[0141] In a possible embodiment, the K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events using an anomaly detection model; the processor 801 can also be used to obtain a sample event set, where the sample event set includes M sample events, and among them, the M sample events include the sample labels corresponding to the N sample events, M is an integer greater than 1, and M is greater than or equal to N; extract the first sample feature vectors of each sample event from the feature vector sequence of each sample event based on the first feature encoding rule, and extract the second sample feature vectors of each sample event from the feature vector sequence of each sample event based on the second feature encoding rule; perform feature reconstruction processing on the first sample feature vectors and the second sample feature vectors of each sample event respectively to obtain the sample feature reconstruction vectors of each sample event; perform clustering processing on the sample feature reconstruction vectors of the N sample events to obtain multiple initial clustering centers, and obtain the K clustering centers according to the multiple initial clustering centers; and train the anomaly detection model based on the multiple initial clustering centers and the feature reconstruction vectors of the M - N sample events.
[0142] In a possible embodiment, the first feature encoding rule includes a first feature encoding module, and the second feature encoding rule includes a second feature encoding module. The processor 801 is further configured to extract the initial first sample feature vectors of each sample event from the feature vector sequence of each sample event by using the initial first feature encoding module, and extract the initial second sample feature vectors of each sample event from the feature vector sequence of each sample event by using the initial second feature encoding module; perform feature reconstruction processing on the initial first sample feature vectors and the initial second sample feature vectors of each sample event respectively to obtain the initial sample feature reconstruction vectors of each sample event; perform cross-training on the initial first feature encoding module and the initial second feature encoding module according to the initial sample feature reconstruction vectors of each sample event and the feature vector sequence of each sample event to obtain the first feature encoding module and the second feature encoding module.
[0143] In a possible embodiment, when the processor 801 performs cross-training on the initial first feature encoding module and the initial second feature encoding module according to the initial sample feature reconstruction vectors of each sample event and the feature vector sequence of each sample event to obtain the first feature encoding module and the second feature encoding module, it is configured to decode the initial sample feature reconstruction vectors of each sample event by using the first feature decoding module corresponding to the initial first feature encoding module to obtain the first decoded feature vectors of each sample event; decode the initial sample feature reconstruction vectors of each sample event by using the second feature decoding module corresponding to the initial second feature encoding module to obtain the second decoded feature vectors of each sample event; determine the reconstruction feature error of each sample event based on the first decoded feature vectors, the second decoded feature vectors of each sample event and the feature vector sequence of each sample event; adjust the parameters in the initial first feature encoding module and the parameters in the initial second feature encoding module in the direction of minimizing the reconstruction feature error to obtain the first feature encoding module and the second feature encoding module.
[0144] Based on the same inventive concept, the principles and beneficial effects of the problems solved by the computer device provided in the embodiments of the present application can be referred to the principles and beneficial effects described in the above method embodiments. For the sake of brevity, they will not be repeated here.
[0145] In the embodiments of the present application, the term "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more units. In addition, each unit can be a part of an overall unit including the function of the unit.
[0146] In addition, it should be noted here that: The embodiments of the present application also provide a computer-readable storage medium, and a computer program is stored in the computer-readable storage medium. The computer program includes program instructions. When the processor executes the above program instructions, it can execute the methods in the corresponding embodiments described above Figure 5 and Figure 6 and thus will not be elaborated here. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in the present application, please refer to the description of the method embodiments of the present application. As an example, the program instructions can be deployed on a computer device, or executed on multiple computer devices located at one place, or alternatively, executed on multiple computer devices distributed at multiple places and interconnected through a communication network.
[0147] According to one aspect of the present application, a computer program product is provided. The computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium. The processor of the computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device can execute the methods in the corresponding embodiments described above Figure 5 and Figure 6 and thus will not be elaborated here.
[0148] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0149] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of the rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. An event detection method, characterized in that, Including: Obtaining a traceability graph sequence of a target event in the system; Performing feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event; Extracting a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependency relationship between different positions in the feature vector sequence; Extracting a second feature vector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependency relationship between different positions in the feature vector sequence by means of a gating mechanism; Performing anomaly detection on the target event according to the first feature vector and the second feature vector.
2. The method according to claim 1, characterized in that, The performing anomaly detection on the target event according to the first feature vector and the second feature vector includes: Performing feature reconstruction processing on the first feature vector and the second feature vector to obtain a feature reconstruction vector; Performing anomaly detection on the target event according to the feature reconstruction vector and K clustering centers, where the K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events, and each sample event corresponding to the K clustering centers is a selected normal event; N is an integer greater than 1, and K is a positive integer.
3. The method according to claim 2, wherein The performing anomaly detection on the target event according to the feature reconstruction vector and K clustering centers includes: Determining a detection score of the target event according to the feature reconstruction vector and K clustering centers; Performing anomaly detection on the target event based on the detection score of the target event and a preset threshold.
4. The method according to claim 3, wherein The determining a detection score of the target event according to the feature reconstruction vector and K clustering centers includes: Adding a pseudo label to the target event based on the detection score of the target event and a preset threshold; wherein, if the detection score is greater than the preset threshold, the pseudo label includes a first label, and if the detection score is less than or equal to the preset threshold, the pseudo label includes a second label; Performing anomaly detection on the target event based on the feature reconstruction vector, the detection score, and the pseudo label to obtain an anomaly detection result of the target event.
5. The method according to claim 3, characterized in that, The determining a detection score of the target event according to the feature reconstruction vector and K clustering centers includes: Determining the similarity between the feature reconstruction vector and each clustering center; Selecting the maximum similarity from the similarities between the feature reconstruction vector and each clustering center as the similarity score of the target event; Using an isolation forest algorithm to determine the isolation score of the target event; Determining the detection score of the target event according to the similarity score and the isolation score.
6. The method according to claim 1, characterized in that, The traceability graph sequence includes: node objects that appear during the process of the system processing the target event and the processing relationships between the node objects; the performing feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event includes: Performing feature extraction processing on the node objects of the traceability graph sequence and the processing relationships between the node objects to obtain an initial feature vector sequence of the target event; Perform dimensionality reduction on the initial feature vector sequence to obtain the feature vector sequence of the target event.
7. The method according to claim 2, wherein The K clustering centers are obtained by clustering the feature reconstruction vectors corresponding to N sample events using an anomaly detection model; the method further includes: Obtain a sample event set, where the sample event set includes M sample events, and among the M sample events, there are sample labels corresponding to N sample events. M is an integer greater than 1, and M is greater than or equal to N; Based on the first feature encoding rule, extract the first sample feature vectors of the respective sample events from the feature vector sequences of the respective sample events, and based on the second feature encoding rule, extract the second sample feature vectors of the respective sample events from the feature vector sequences of the respective sample events; Perform feature reconstruction processing on the first sample feature vectors and the second sample feature vectors of the respective sample events respectively to obtain the sample feature reconstruction vectors of the respective sample events; Perform clustering processing on the sample feature reconstruction vectors of the N sample events to obtain a plurality of initial clustering centers, and obtain the K clustering centers according to the plurality of initial clustering centers; Based on the plurality of initial clustering centers and the feature reconstruction vectors of the M - N sample events, train the anomaly detection model.
8. The method according to claim 7, wherein The first feature encoding rule includes a first feature encoding module, the second feature encoding rule includes a second feature encoding module, and the method further includes: Use an initial first feature encoding module to extract the initial first sample feature vectors of the respective sample events from the feature vector sequences of the respective sample events, and use an initial second feature encoding module to extract the initial second sample feature vectors of the respective sample events from the feature vector sequences of the respective sample events; Perform feature reconstruction processing on the initial first sample feature vectors and the initial second sample feature vectors of the respective sample events respectively to obtain the initial sample feature reconstruction vectors of the respective sample events; According to the initial sample feature reconstruction vectors of the respective sample events and the feature vector sequences of the respective sample events, perform cross-training on the initial first feature encoding module and the initial second feature encoding module to obtain the first feature encoding module and the second feature encoding module.
9. The method according to claim 8, wherein The performing cross-training on the initial first feature encoding module and the initial second feature encoding module according to the initial sample feature reconstruction vectors of the respective sample events and the feature vector sequences of the respective sample events to obtain the first feature encoding module and the second feature encoding module includes: Use a first feature decoding module corresponding to the initial first feature encoding module to perform decoding processing on the initial sample feature reconstruction vectors of the respective sample events to obtain the first decoded feature vectors of the respective sample events; Use a second feature decoding module corresponding to the initial second feature encoding module to perform decoding processing on the initial sample feature reconstruction vectors of the respective sample events to obtain the second decoded feature vectors of the respective sample events; Determine the reconstruction feature error of each sample event based on the first decoding feature vector, the second decoding feature vector of each sample event, and the feature vector sequence of each sample event; Adjust the parameters in the initial first feature encoding module and the parameters in the initial second feature encoding module in the direction of minimizing the reconstruction feature error to obtain the first feature encoding module and the second feature encoding module.
10. An event detection device, characterized in that, Comprising: An acquisition unit, configured to acquire a traceability graph sequence of a target event in the system; A processing unit, configured to perform feature extraction processing on the traceability graph sequence to obtain a feature vector sequence of the target event; The processing unit is further configured to extract a first feature vector from the feature vector sequence based on a first feature encoding rule, where the first feature encoding rule is used to indicate feature extraction according to the long-distance dependence relationship between different positions in the feature vector sequence; The processing unit is further configured to extract a second feature vector from the feature vector sequence based on a second feature encoding rule, where the second feature encoding rule is used to indicate feature extraction according to the dependence relationship between different positions in the feature vector sequence by means of a gating mechanism; The processing unit is further configured to perform anomaly detection on the target event according to the first feature vector and the second feature vector.
11. A computer device, characterized in that, Comprising: A storage device, configured to store a computer program; A processor, configured to execute the computer program stored in the storage device to implement the event detection method according to any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The computer storage medium stores a computer program, and when the computer program is executed by a processor, it executes the event detection method according to any one of claims 1-9.
13. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the event detection method according to any one of claims 1-9.