Network security detection system and method based on machine learning
By building multimodal user portraits and device fingerprint proofreading blocks, combined with timing prediction models, the problem of insufficient monitoring of abnormal behaviors during the session cycle in static credential verification is solved, and accurate risk assessment and dynamic prevention and control of network security is achieved.
Patent Information
- Application Number
- CN202510379326.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-03-28
AI Technical Summary
In the existing network security protection system, the static credential verification mechanism lacks real-time monitoring of abnormal use of accounts during the session cycle, resulting in illegal users being able to perform malicious operations for a long time, threatening data security, and causing privacy leakage and damage to brand reputation.
By obtaining user login and browsing behavior characteristics, a multi-modal feature fusion model is built to generate user portraits, combining device fingerprint proofreading blocks and behavior baseline analysis, user risks are evaluated in real time, and potentially associated risk users are tracked dynamically through timing prediction models to achieve accurate identification and early warning.
It significantly improves the accuracy and response efficiency of network security detection, can timely identify abnormal behaviors, expand the monitoring scope, optimize resource allocation, and achieve accurate prediction and prevention of risk spread.
Smart Images

Figure CN120263454A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically to a network security detection system and method based on machine learning. Background Art
[0002] The network instantaneously connects to global information resources, significantly improving the efficiency and breadth of knowledge acquisition, breaking the time and space limitations of traditional information dissemination, constructing an efficient and convenient communication and collaboration system, promoting the normalization of remote work and cross-border communication, and reshaping fields such as education, economy, and culture. Online education makes high-quality resources inclusive, e-commerce activates global trade, and social media accelerates the sharing of cultural creativity. At the same time, the network provides a digital platform for government affairs disclosure and public services, significantly enhancing the efficiency of social governance. Its core value lies in continuously empowering the interconnection and innovative development of human civilization, becoming an important engine driving social progress.
[0003] In the existing network security protection system, the login verification mechanism relying on static credentials on the website server has significant defects. It overly focuses on identity verification during the login stage and lacks the ability to monitor abnormal account usage behaviors in real time during the session period, such as illegal sharing, session hijacking, malicious code injection, etc. Due to the lack of analysis of dynamic features such as user collection device fingerprints and behavior trajectories on the server side, and the lag of traditional rule matching algorithms, illegal users can lurk for a long time after logging in to perform malicious operations, directly threatening data security and triggering secondary risks such as privacy leakage and damage to brand reputation. Summary of the Invention
[0004] The purpose of the present invention is to provide a network security detection system and method based on machine learning to solve the problems raised in the prior art.
[0005] To achieve the above purpose, the present invention provides the following technical solution: A network security detection method based on machine learning, the network security detection method includes the following steps:
[0006] Step S1, obtain the login behavior characteristics when the user logs in as the first behavior characteristics, obtain the browsing behavior characteristics of the user on the web page as the second behavior characteristics, and construct a user profile according to the first behavior characteristics and the second behavior characteristics;
[0007] Step S1-1, obtain the login behavior characteristics when the user logs in through event listening, the login behavior characteristics include input speed, error rate, time interval, and mouse trajectory; and the browsing behavior characteristics of the user on the web page, the browsing behavior characteristics include residence duration, path jump, and web page content;
[0008] Step S1-2: Align and jointly embed the first-line features and the second-line features in terms of space and time through a multi-modal feature fusion model to generate a composite feature vector containing the user behavior pattern and operation habit; and construct a uniquely mapped user portrait in the implicit semantic space according to the feature vector.
[0009] Real-time obtain multi-dimensional feature data of the user's login behavior and web browsing behavior through event listening technology, and combine with the multi-modal feature fusion model to achieve space-time alignment and joint embedding of the two types of behavior data, generate a composite feature vector containing the user's operation habit and behavior pattern, and finally construct a uniquely mapped accurate user portrait in the implicit semantic space. This method effectively integrates the behavior data in the user identity authentication stage and the network access stage, improves the three-dimensionality and recognition of the user portrait through multi-dimensional feature cross-verification, provides a more comprehensive behavior baseline basis for subsequent risk assessment, and significantly enhances the ability of the network security detection system to identify abnormal behavior patterns.
[0010] Step S2: Collect the user's IP address and device information to construct a device fingerprint verification block, construct a portrait baseline based on the user's historical user portrait, monitor and analyze the user's real-time behavior characteristics through the portrait baseline, and conduct risk assessment on the user according to the monitoring and analysis results in combination with the device fingerprint verification block. The risk assessment results include risky users and normal users.
[0011] Step S2-1: Obtain the user's IP address through the web server log, obtain the user's device information through the user agent string, construct a device fingerprint verification block according to the user's IP address and device information, and compare the matching degree between the currently logged-in device fingerprint and the historical trusted device fingerprint library through the device fingerprint verification block to determine whether there is a risk for the logged-in user; the lower the matching degree of the currently logged-in device fingerprint, the higher the judged risk of the logged-in user.
[0012] Step S2-2: Analyze and extract the first-line features of the historical user portrait, and calculate the average value of the first-line features to construct a portrait baseline.
[0013] Step S2-3: Verify the user's logged-in IP address and device information with the device fingerprint verification block. During the verification process, when the user's logged-in IP address does not match any of the historical trusted IP addresses recorded in the device fingerprint verification block, or when the device information does not match the corresponding information in the device fingerprint verification block, mark the user as a marked user.
[0014] Step S2-4: Select the first row in the historical user portrait with the largest deviation of the first behavior feature from the average value as the portrait baseline threshold; when the first behavior feature of the marked user at login exceeds the portrait baseline threshold, the user is determined to be a risky user; when the first behavior feature of the marked user at login does not exceed the portrait baseline threshold, the risk mark of the marked user is removed.
[0015] Through multi-dimensional information collection and analysis technology, accurate user risk assessment is achieved. By means of web server logs and user agent strings, the user's IP address and device information are obtained respectively, and a device fingerprint verification block is constructed. By comparing the matching degree with the historical trusted device fingerprint library, the login risk is initially judged, providing a basis at the hardware level for risk assessment. At the same time, the first behavior features in the historical user portrait are analyzed and extracted, and the average value is calculated to construct a portrait baseline. Then, the group of first behavior features with the largest deviation from the average value is used as the portrait baseline threshold. During actual risk assessment, the IP address and device information of the user at login are verified with the device fingerprint verification block, and users with mismatches are marked as risky. Then, combined with the comparison result of the first behavior feature of the marked user at login and the portrait baseline threshold, it is finally determined whether the user is a risky user or a normal user. The method of integrating device information and behavior features can comprehensively and meticulously identify potential user risks from multiple perspectives, effectively improving the accuracy and reliability of network security detection, and providing a solid data foundation for network security protection.
[0016] Step S3: Monitor risky users in real time, and find potential associated risky users by combining the device fingerprint verification block of risky users with browsing behavior features, and construct a set of potential associated risky users;
[0017] Step S3-1: Monitor the logs generated by risky users on the web page, and find users with browsing behavior features the same as the second behavior features of risky users based on the monitored logs, and obtain their IP addresses and device information; when the device information of the found user is the same as that of the risky user, or the IP addresses belong to the same Class B subnet, the found user is determined to be a risky user;
[0018] Step S3-2: Find the potential risky users associated with each risky user, store them with the username of the associated potential risky user as the index and the user portrait as the value, and construct a set of potential associated risky users.
[0019] Through the real-time monitoring of risk users and the correlation analysis of multi-dimensional information, the precise mining and set construction of potentially associated risk users are realized. By monitoring the web logs of risk users, their browsing behavior characteristics are captured. Using this as a clue, other users with the same browsing behavior are found, and at the same time, the IP addresses and device information of these users are obtained. With the help of device information matching and IP address subnet attribution judgment, potentially associated risk users are further screened from the aspects of behavior and network environment. Storing with the user names of potentially associated risk users as indexes and user portraits as values, a complete set of potentially associated risk users is constructed. It can not only timely discover other potential threats closely associated with known risk users, but also provide comprehensive and systematic target objects for subsequent risk early warning and handling through centralized management, effectively expanding the monitoring scope of network security protection and enhancing the response speed and prevention and control ability for potential risks.
[0020] Step S4: Conduct a population fluctuation analysis on the set of potentially associated risk users. Record the number of users with normal risk assessment results in the set of potentially associated risk users over time to form a risk elimination value; and use a time series prediction model to predict the number of the risk elimination value and the number of the set of potentially associated risk users respectively;
[0021] Step S4-1: Traverse the data in the set of potentially associated risk users, analyze and extract the new IP addresses, device information, and user portraits of risk users for population fluctuation analysis, and obtain the shortest time interval between two logins of users as the time threshold for fluctuation analysis. The population fluctuation analysis process is as follows:
[0022] When the login time interval of a risk user exceeds the time threshold for fluctuation analysis, the IP address, device information, and user portrait obtained again are called to step S2 for risk assessment. When the risk assessment result is a normal user, the risk elimination value is incremented by one;
[0023] When the login time interval of a risk user does not exceed the time threshold for fluctuation analysis, the IP address, device information, and user portrait obtained again are synchronized and updated to the set of potentially associated risk users, and the risk elimination value remains unchanged;
[0024] Step S4-2: Predict the number of the risk elimination value through a time series prediction model to obtain the risk user reduction value;
[0025] Step S4-3: Predict the set of potentially associated risk users through a time series prediction model to obtain the risk user prediction value;
[0026] Step S4-4: Subtract the risk user reduction value from the risk user prediction value to obtain the actual number of risk users;
[0027] The time series prediction model is calculated using the following formula:
[0028]
[0029] In the formula, Pt represents the predicted value at time t; a represents the constant term; n represents the order of the autoregressive part; Yi represents the autoregressive coefficient; m represents the order of the moving average part; Rj represents the moving average coefficient; Ft-j represents the error term at time t-j;
[0030] Traverse the data in the set of potentially associated risk users. During the traversal process, data verification work will be carried out, with a focus on new IP addresses, device information, and user portraits. For these key pieces of information, the frequencies of occurrence and continuity will be recorded. When new IP addresses, device information, and user portraits appear continuously or frequently, a judgment will be made. The user portrait will be further analyzed and adjusted, and the new IP addresses and device information will be incorporated into the device fingerprint database; it is determined that the user has changed from a risk user to a normal user. When a risk user successfully changes to a normal user, the risk elimination value will be decremented by one. Through continuous traversal, verification, and judgment, the risk elimination value will dynamically reflect the elimination situation of risk users. The entire process is a data-driven and tightly logic-judgment-combined process, thus realizing the effective monitoring and management of the status of risk users.
[0031] By using the risk elimination value and applying the time series prediction model, the dynamic tracking and accurate prediction of the scale of potentially associated risk users are realized. By accumulating the number of users who turn into normal users over time in the set of potentially associated risk users, combined with the time series prediction model, the risk elimination volume and the increment of potentially associated users are respectively predicted. Finally, the actual number of risk users is calculated through the difference between the predicted value and the reduction value. This method effectively integrates the historical data of risk elimination and the prediction of future trends, can reflect the dynamic evolution of the risk user group in real time, provides a quantitative basis for risk early warning, and at the same time optimizes the allocation strategy of network security resources through accurate number prediction, significantly improving the system's ability to predict risk diffusion and response efficiency.
[0032] Step S5: Analyze and calculate the maximum growth rate of risk users based on the set of potentially associated risk users, calculate the future growth rate through the predicted number of associated risk users, and issue an early warning based on the maximum growth rate and the future growth rate;
[0033] In step S5, the future growth rate is calculated based on the predicted number of risk users and the current number of risk users. The calculation formula for the future growth rate is:
[0034] G = (z - Z) / Z;
[0035] Wherein, G represents the future growth rate; z represents the predicted number of risky users; Z represents the current number of risky users;
[0036] Select the prediction time period used in step S4 as the growth rate calculation period, calculate the growth rate of the set of potentially associated risky users using the growth rate calculation period, and select the maximum growth rate as the warning threshold. When the future growth rate exceeds the warning threshold, a warning signal is issued;
[0037] Calculate the future growth rate based on the predicted number of risky users and the current number of risky users. For the calculation of the future growth rate, obtain the increment of risky users by subtracting the current number of risky users from the predicted number of risky users, and then divide the increment of risky users by the current number of risky users to obtain the future growth rate; select the prediction time period used in step S4 as the growth rate calculation period, calculate the growth rate of the set of potentially associated risky users using the growth rate calculation period, and select the maximum growth rate as the warning threshold. When the future growth rate exceeds the warning threshold, a warning signal is issued.
[0038] Through dynamic analysis of the growth pattern of the set of potentially associated risky users and the prediction model, a quantitative warning of the change in the scale of risky users is realized. Calculate the historical maximum growth rate of the set of potentially associated risky users as the warning threshold, and calculate the real-time growth rate based on the difference between the future number of risky users and the current number obtained from the time series prediction model. When the real-time growth rate exceeds the preset threshold, the warning mechanism is triggered, thus constructing a dynamic risk assessment system. This method effectively combines historical behavior patterns with future trend prediction, realizes visual monitoring of the risk diffusion situation through the growth rate, provides a quantifiable decision-making basis for network security protection, and significantly improves the system's ability to predict risk outbreaks and emergency response efficiency.
[0039] Furthermore, a network security detection system based on machine learning, the network security detection system includes a user profile construction module, a risk assessment module, an associated risk mining module, a risk number prediction module, and a risk warning module;
[0040] The user profile construction module is used to generate a composite feature vector by fusing login behavior and browsing behavior characteristics to construct a user profile; the risk assessment module is used to fuse device fingerprint verification and behavior baseline analysis to identify risky users in real time; the associated risk mining module is used to find potentially associated user groups based on the behavior characteristics of risky users and device information; the risk number prediction module is used to determine the actual number of risky users by combining the risk elimination prediction value and the potential growth prediction value; the risk warning module is used to set a threshold based on the growth rate of risky users and issue a warning signal;
[0041] The output end of the user profile construction module is electrically connected to the input end of the risk assessment module; the output end of the risk assessment module is electrically connected to the input end of the associated risk mining module; the output end of the associated risk mining module is electrically connected to the input end of the risk number prediction module; the output end of the risk number prediction module is electrically connected to the input end of the risk warning module;
[0042] The user profile construction module includes a behavior feature acquisition unit and a profile generation unit; the behavior feature acquisition unit is used to collect input speed, error rate, and data trajectory, as well as features such as web page browsing stay duration and path jump; the profile generation unit is used to align behavior features in space and time through a multimodal fusion model and generate an implicit semantic profile;
[0043] The risk assessment module includes a device fingerprint construction unit and a profile baseline assessment unit; the device fingerprint construction unit is used to obtain the IP address and device information and compare them with the historical trusted library to evaluate the login risk; the profile baseline assessment unit is used to construct a baseline based on the mean value of historical behavior features and detect the real-time behavior deviation degree;
[0044] The associated risk mining module includes an associated user search unit and a risk set construction unit; the associated user search unit is used to monitor the risk user log to match associated users with the same browsing behavior, device information, and IP address; the risk set construction unit is used to store the associated risk user profiles indexed by user name and construct a dynamic risk set;
[0045] The risk number prediction module includes a reduction value prediction unit and a prediction value calculation unit; the reduction value prediction unit is used to predict the number of risk users who turn into normal users in the risk elimination value; the prediction value calculation unit is used to calculate the actual risk number based on the predicted value of potential associated users and the risk reduction value;
[0046] The risk warning module includes a growth rate calculation unit and a warning trigger unit; the growth rate calculation unit is used to calculate the future growth rate of risk users according to the difference between the prediction and the current number; the warning trigger unit is used to compare with the maximum growth rate threshold and send a warning signal.
[0047] Compared with the prior art, the beneficial effects of the present invention are:
[0048] 1. The present invention uses event listening technology to collect multi-dimensional features of user login and browsing behaviors in real time, and constructs a uniquely mapped user profile in combination with a multimodal feature fusion model. This method breaks through the limitations of traditional static credential verification, integrates dynamic behavior data in the identity authentication and network access stages, and significantly enhances the ability to identify abnormal operations. Through the joint analysis of behavior features such as input speed and stay duration, legal users and malicious attackers can be effectively distinguished, providing a comprehensive and reliable data basis for subsequent risk assessment.
[0049] 2. The present invention compares the fingerprint verification block constructed by the IP address and device information with the historical trusted library, and combines the analysis of the behavioral feature baseline threshold to realize the risk assessment in both the hardware and behavioral dimensions. When the device information or IP address is abnormal, the system automatically triggers a risk mark and quantifies the risk through the deviation degree of the behavioral feature. This multi-factor verification mechanism effectively improves the accuracy of risk identification.
[0050] 3. The present invention realizes the accurate prediction and dynamic regulation of the scale of potentially associated risk users through the risk elimination value and the application timing prediction model. The system accumulates in real time the number of users who turn into normal users over time in the risk user set, and combines the timing model including the autoregressive term and the moving average term to predict both the risk elimination amount and the user increment, significantly improving the prediction accuracy of the evolution of the risk user scale. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a schematic flow chart of a network security detection method based on machine learning according to the present invention;
[0052] Figure 2 It is a schematic structural diagram of a network security detection system based on machine learning according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0054] Embodiment 1: As Figure 1 shown, the present invention provides a technical solution, a network security detection method based on machine learning, and the network security detection method includes the following steps:
[0055] Step S1: Obtain the login behavior feature when the user logs in as the first behavior feature, obtain the browsing behavior feature of the user on the web page as the second behavior feature, and construct a user portrait according to the first behavior feature and the second behavior feature;
[0056] Step S1-1: Obtain the login behavior feature when the user logs in through event listening, and the login behavior feature includes input speed, error rate, time interval, and mouse trajectory; and the browsing behavior feature of the user on the web page, and the browsing behavior feature includes residence duration, path jump, and web page content;
[0057] Step S1-2: Align and jointly embed the first behavioral feature and the second behavioral feature in terms of time and space through a multi-modal feature fusion model to generate a composite feature vector containing the user's behavior pattern and operation habit; and construct a uniquely mapped user portrait in the implicit semantic space according to the feature vector.
[0058] In specific implementation, the system captures dynamic behavior data such as input speed, error rate, time interval, and mouse trajectory during the user login phase through event listening technology, and simultaneously synchronously collects scenario features such as dwell time, path jump, and web page content during the browsing phase. The multi-modal feature fusion model uses a spatio-temporal alignment algorithm to calibrate the two types of data in the time dimension, eliminating the influence of the time difference between login and browsing behaviors, and then performs joint feature embedding through a deep neural network (such as a hybrid architecture of LSTM and CNN): First, perform time series modeling on the time series data of the login behavior (such as the input speed sequence) to extract operation rhythm features; secondly, perform spatial feature encoding on the spatial data of the browsing behavior (such as the page dwell heat map); finally, interact and fuse the time and space features through a cross-modal attention mechanism to generate a high-dimensional composite feature vector containing the user's operation habit, interest preference, and behavior pattern. After the vector is dimension-reduced and mapped to the implicit semantic space, a unique user portrait is formed. Its essence is to construct a dynamic digital twin of the user identity in the feature space through cross-verification of multi-dimensional behavior data, thereby breaking through the limitations of traditional single-modal authentication.
[0059] Step S2: Collect the user's IP address and device information to construct a device fingerprint verification block, construct a portrait baseline based on the user's historical user portrait, monitor and analyze the user's real-time behavior characteristics through the portrait baseline, and perform risk assessment on the user according to the monitoring and analysis results combined with the device fingerprint verification block. The risk assessment results include risky users and normal users;
[0060] Step S2-1: Obtain the user's IP address through the web server log, obtain the user's device information through the user agent string, construct a device fingerprint verification block according to the user's IP address and device information, and compare the matching degree between the current login device fingerprint and the historical trusted device fingerprint library through the device fingerprint verification block to determine whether there is a risk for the logged-in user; the lower the matching degree of the current login device fingerprint, the higher the judged risk of the logged-in user;
[0061] Step S2-2: Analyze and extract the first behavioral feature of the historical user portrait, and calculate the average value of the first behavioral feature to construct a portrait baseline.
[0062] Step S2-3: Compare the IP address and device information of the logged-in user with the device fingerprint verification block. During the verification process, when the IP address of the logged-in user does not match any of the historical trusted IP addresses recorded in the device fingerprint verification block, or when the device information does not match the corresponding information in the device fingerprint verification block, mark this user as a risky user, denoted as a marked user.
[0063] Step S2-4: Select the first row in the historical user portrait with the largest deviation from the average value of the first behavioral feature as the portrait baseline threshold. When the first behavioral feature of the marked user during login exceeds the portrait baseline threshold, it is determined as a risky user; when the first behavioral feature of the marked user during login does not exceed the portrait baseline threshold, remove the risk mark of the marked user.
[0064] In specific implementation, the system parses the IP address of the logged-in user through the server log and extracts information such as device type, operating system, and browser fingerprint using the user agent string, and combines them to generate the device fingerprint verification block. When the IP address or device information of the logged-in user does not match the verification block, the system automatically marks it as a risky user and collects its login behavioral characteristics in real time. If the characteristic value exceeds the baseline threshold range, it is determined as a risky user; if it is still within the normal fluctuation range, the risk mark is removed. This mechanism realizes the accurate identification of illegal device logins and abnormal behaviors through the dual verification of hardware fingerprints and behavioral characteristics, combined with the dynamic threshold algorithm.
[0065] Step S3: Monitor the risky users in real time, and find out the potential associated risky users by combining the device fingerprint verification block of the risky users with their browsing behavioral characteristics, and construct a set of potential associated risky users.
[0066] Step S3-1: Monitor the logs generated by the risky users on the web page, find the users with the same browsing behavioral characteristics as the second behavioral characteristics of the risky users based on the monitored logs, and obtain their IP addresses and device information; when the device information of the found users is the same as that of the risky users, or the IP addresses belong to the same Class B subnet, determine the found users as risky users.
[0067] Step S3-2: Find out the potential associated risky users of each risky user, store them with the username of the associated potential risky user as the index and the user portrait as the value, and construct a set of potential associated risky users.
[0068] In specific implementation, the system continuously captures the browsing behavior data of risk users through the real-time log monitoring module, including eigenvectors such as page stay duration, jump path, and content interaction mode. Based on these features, the system uses the cosine similarity algorithm to perform a nearest neighbor search in the global user behavior database to screen out a set of candidate users with highly similar browsing behavior patterns. At the same time, the system automatically extracts the device fingerprints (such as operating system, browser version, etc.) and IP address information of the candidate users, and verifies whether their device information is exactly the same as that of the risk users or whether the IP address belongs to the same Class B subnet through two-way hash comparison. If either condition is met, the user is marked as a potentially associated risk user. Finally, the system uses the username as the main index to structurally store the portrait feature values of the associated users, forming a dynamically updated set of potentially associated risk users. This mechanism realizes a three-dimensional prevention and control from single-point risk to group threat through behavior pattern clustering and network environment relevance analysis, effectively expanding the coverage of risk monitoring.
[0069] Step S4: Conduct a population fluctuation analysis on the set of potentially associated risk users. Store and record the number of users with a normal risk assessment result in the set of potentially associated risk users over time to form a risk elimination value; and use a time series prediction model to predict the number of the risk elimination value and the number of the set of potentially associated risk users respectively.
[0070] Step S4-1: Traverse the data in the set of potentially associated risk users, analyze and extract the new IP address, device information, and user portrait of the risk users for population fluctuation analysis, and obtain the shortest time interval between two logins of the users as the time threshold for fluctuation analysis. The population fluctuation analysis process is as follows:
[0071] When the login time interval of the risk user exceeds the time threshold for fluctuation analysis, the IP address, device information, and user portrait obtained again are called to step S2 for risk assessment. When the risk assessment result is a normal user, the risk elimination value is incremented by one.
[0072] When the login time interval of the risk user does not exceed the time threshold for fluctuation analysis, the IP address, device information, and user portrait obtained again are synchronized and updated to the set of potentially associated risk users, and the risk elimination value remains unchanged.
[0073] Step S4-2: Use a time series prediction model to predict the number of the risk elimination value to obtain a risk user reduction value.
[0074] Step S4-3: Use a time series prediction model to predict the set of potentially associated risk users to obtain a risk user prediction value.
[0075] Step S4-4: Subtract the risk user reduction value from the risk user prediction value to obtain the actual number of risk users.
[0076] In specific implementation, the system statistically calculates the number of users who turn into normal users through behavior feature review over time in the set of potentially associated risk users in real time based on the risk elimination value, and uses this data as the input sample for model training. The time series prediction model adopts an autoregressive moving average architecture, combines the time series data of historical risk elimination amounts and the scale of potentially associated users, and respectively establishes a risk user reduction prediction model and a potential user increment prediction model. Among them, by learning the fluctuation law of risk users turning into normal users in the historical period, seasonal and periodic characteristics are captured; the increment prediction model is based on the evolution trend of user behavior patterns and combines the periodic characteristics of network attack activities for dynamic extrapolation. The system calculates the difference between the two values output by the prediction model to obtain the net growth number of potentially risky users in the future period. This mechanism provides data support for the dynamic adjustment of security policies by quantitatively analyzing the dynamic growth and decline of the risk user group, and realizes the accurate prediction of the risk diffusion situation.
[0077] Step S5: Analyze and calculate the maximum growth rate of risk users based on the set of potentially associated risk users, calculate the future growth rate based on the predicted number of users in the associated risk user set, and issue a warning based on the maximum growth rate and the future growth rate;
[0078] Calculate the future growth rate based on the predicted number of risk users and the current number of risk users. For the calculation of the future growth rate, first obtain the risk user increment by subtracting the current number of risk users from the predicted number of risk users, and then divide the risk user increment by the current number of risk users to obtain the future growth rate; select the prediction time period used in step S4 as the growth rate calculation period, calculate the growth rate for the set of potentially associated risk users using the growth rate calculation period, and select the maximum growth rate as the warning threshold. When the future growth rate exceeds the warning threshold, a warning signal is issued.
[0079] In specific implementation, the system traverses the historical data of the set of potentially associated risk users and calculates the peak value of the user number growth per unit time as the maximum growth rate benchmark. Based on the predicted value of risk users in the future period output by the time series prediction model and the current actual number, calculate the future growth rate (i.e., (predicted value - current value) / current value). The system compares this growth rate with the historical maximum growth rate in real time. If it exceeds the preset threshold, the warning mechanism is triggered, effectively improving the ability to predict the risk outbreak.
[0080] Embodiment 2, as Figure 2 shown, the present invention provides a network security detection system based on machine learning. The network security detection system includes a user profile construction module, a risk assessment module, an associated risk mining module, a risk number prediction module, and a risk warning module;
[0081] The user profile construction module is used to fuse login behavior and browsing behavior characteristics to generate a composite feature vector for constructing a user profile; the risk assessment module is used to fuse device fingerprint verification and behavior baseline analysis to identify risk users in real time; the associated risk mining module is used to find potential associated user groups based on risk user behavior characteristics and device information; the risk number prediction module is used to determine the actual number of risk users by combining the risk elimination prediction value and the potential growth prediction value; the risk warning module is used to set a threshold based on the risk user growth rate and send out a warning signal.
[0082] The output end of the user profile construction module is electrically connected to the input end of the risk assessment module; the output end of the risk assessment module is electrically connected to the input end of the associated risk mining module; the output end of the associated risk mining module is electrically connected to the input end of the risk number prediction module; the output end of the risk number prediction module is electrically connected to the input end of the risk warning module.
[0083] The user profile construction module includes a behavior feature acquisition unit and a profile generation unit; the behavior feature acquisition unit is used to collect input speed, error rate, and data trajectory, as well as the characteristics of web page browsing stay duration and path jump; the profile generation unit is used to align behavior features in space-time through a multimodal fusion model and generate an implicit semantic profile.
[0084] The risk assessment module includes a device fingerprint construction unit and a profile baseline assessment unit; the device fingerprint construction unit is used to obtain the IP address and device information and compare them with the historical trusted library to evaluate the login risk; the profile baseline assessment unit is used to construct a baseline based on the mean value of historical behavior features and detect the real-time behavior deviation degree.
[0085] The associated risk mining module includes an associated user search unit and a risk set construction unit; the associated user search unit is used to monitor the risk user log to match associated users with the same browsing behavior, device information, and IP address; the risk set construction unit is used to store the associated risk user profile indexed by the user name and construct a dynamic risk set.
[0086] The risk number prediction module includes a reduction value prediction unit and a prediction value calculation unit; the reduction value prediction unit is used to predict the number of risk users who turn into normal users in the risk elimination value; the prediction value calculation unit is used to calculate the actual number of risk users based on the potential associated user prediction value and the risk reduction value.
[0087] The risk warning module includes a growth rate calculation unit and a warning trigger unit; the growth rate calculation unit is used to calculate the future growth rate of risk users according to the difference between the prediction and the current number; the warning trigger unit is used to send out a warning signal by comparing the maximum growth rate threshold.
[0088] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be construed as limiting the claims concerned.
Claims
1. A network security detection method based on machine learning, characterized in that: The network security detection method includes the following steps: Step S1: Obtain the login behavior characteristics of the user during login as the first behavior characteristics, obtain the browsing behavior characteristics of the user on the web page as the second behavior characteristics, and construct a user profile based on the first behavior characteristics and the second behavior characteristics; Step S2: Collect the user's IP address and device information to construct a device fingerprint verification block, construct a profile baseline based on the user's historical user profile, monitor and analyze the real-time behavior characteristics of the user through the profile baseline, and conduct a risk assessment on the user according to the monitoring and analysis results combined with the device fingerprint verification block. The risk assessment results include risk users and normal users; Step S3: Monitor the risk users in real time, and find out potential associated risk users by combining the device fingerprint verification block of the risk users with the browsing behavior characteristics, and construct a set of potential associated risk users; Step S4: Conduct a population fluctuation analysis on the set of potential associated risk users, store and record the number of users whose risk assessment results are normal users in the set of potential associated risk users over time to form a risk elimination value; and predict the number of people in the risk elimination value and the number of people in the set of potential associated risk users respectively through a time series prediction model; Step S5: Calculate the maximum growth rate of the risk users according to the analysis of the set of potential associated risk users, calculate the future growth rate according to the predicted number of the set of associated risk users, and issue a warning according to the maximum growth rate and the future growth rate.
2. The network security detection method based on machine learning according to claim 1, wherein: The specific steps of step S1 are as follows: Step S1-1: Obtain the login behavior characteristics of the user during login through event listening. The login behavior characteristics include input speed, error rate, time interval, and mouse trajectory; And the browsing behavior characteristics of the user on the web page. The browsing behavior characteristics include residence duration, path jump, and web page content; Step S1-2: Align and jointly embed the first behavior characteristics and the second behavior characteristics in space and time through a multi-modal feature fusion model to generate a composite feature vector containing the user's behavior pattern and operation habit; and construct a uniquely mapped user profile in the implicit semantic space according to the feature vector.
3. The network security detection method based on machine learning according to claim 2, characterized in that: The specific steps of step S2 are as follows: Step S2-1: Obtain the user's IP address through the web server log, obtain the user's device information through the user agent string, construct a device fingerprint verification block according to the user's IP address and device information, and judge whether the logged-in user has a risk by comparing the matching degree of the current logged-in device fingerprint with the historical trusted device fingerprint library through the device fingerprint verification block; Step S2-2: Analyze and extract the first behavior characteristics of the historical user profile, and calculate the average value of the first behavior characteristics to construct a profile baseline.
4. A network security detection method based on machine learning according to claim 3, characterized in that: In step S2, it also includes: Step S2-3: Verify the user's logged-in IP address and device information with the device fingerprint verification block. During the verification process, when the logged-in user's IP address does not match any of the historical trusted IP addresses recorded in the device fingerprint verification block, or the device information does not match the corresponding information in the device fingerprint verification block, mark the user as a marked user; Step S2-4: Select the first row in the historical user profile with the largest deviation of features from the average as the portrait baseline threshold. When the first behavior features of the marked user at login exceed the portrait baseline threshold, the user is determined to be a risk user. When the first behavior features of the marked user at login do not exceed the portrait baseline threshold, the risk mark of the marked user is removed.
5. The network security detection method based on machine learning according to claim 4, characterized in that: The specific steps of step S3 are as follows: Step S3-1: Monitor the logs generated by risk users on the web page, and based on the monitored logs, find users with browsing behavior features identical to the second behavior features of the risk users, and obtain their IP addresses and device information. When the device information of the found user is the same as that of the risk user, or the IP addresses belong to the same Class B subnet, the found user is determined to be a risk user. Step S3-2: Find the potential risk users associated with each risk user, store them with the user names of the associated potential risk users as indexes and the user profiles as values, and construct a set of potential associated risk users.
6. The network security detection method based on machine learning according to claim 5, characterized in that: The specific steps of step S4 are as follows: Step S4-1: Traverse the data in the set of potentially associated risk users, analyze and extract the new IP addresses, device information, and user profiles of the risk users for population fluctuation analysis, and obtain the shortest time interval between two logins of the user as the fluctuation analysis time threshold. The population fluctuation analysis process is as follows: When the login time interval of the risk user exceeds the fluctuation analysis time threshold, the IP address, device information, and user profile obtained again are used to call step S2 for risk assessment. When the risk assessment result is a normal user, the risk elimination value is incremented by one. When the login time interval of the risk user does not exceed the fluctuation analysis time threshold, the IP address, device information, and user profile obtained again are synchronized and updated to the set of potentially associated risk users, and the risk elimination value remains unchanged. Step S4-2: Predict the number of people with the risk elimination value through a time series prediction model to obtain the risk user reduction value. Step S4-3: Predict the set of potentially associated risk users through a time series prediction model to obtain the risk user prediction value. Step S4-4: Subtract the risk user reduction value from the risk user prediction value to obtain the actual number of risk users.
7. A network security detection method based on machine learning according to claim 6, characterized in that: In step S5, the future growth rate is calculated based on the predicted number of risk users and the current number of risk users. The calculation formula for the future growth rate is: G = (z - Z) / Z; In the formula, G represents the future growth rate; z represents the predicted number of risk users; Z represents the current number of risk users. Select the prediction time period used in step S4 as the growth rate calculation period, calculate the growth rate for the set of potentially associated risk users using the growth rate calculation period, and select the maximum growth rate as the warning threshold. When the future growth rate exceeds the warning threshold, a warning signal is issued.
8. A network security detection system based on machine learning, which is applied to a network security detection method based on machine learning according to any one of claims 1-7, characterized in that: The network security detection system includes a user profile construction module, a risk assessment module, an associated risk mining module, a risk user number prediction module, and a risk warning module. The user profile construction module is used to generate a composite feature vector by fusing login behavior and browsing behavior features to construct a user profile. The risk assessment module is used to fuse device fingerprint verification and behavior baseline analysis to identify risk users in real time; The associated risk mining module is used to find potential associated user groups based on the behavior characteristics and device information of risk users; the risk number prediction module is used to determine the actual number of risk users by combining the risk elimination prediction value and the potential growth prediction value; The risk warning module is used to set a threshold based on the growth rate of risk users and issue a warning signal; The output end of the user portrait construction module is electrically connected to the input end of the risk assessment module; the output end of the risk assessment module is electrically connected to the input end of the associated risk mining module; the output end of the associated risk mining module is electrically connected to the input end of the risk number prediction module; the output end of the risk number prediction module is electrically connected to the input end of the risk warning module.
9. The network security detection system based on machine learning according to claim 8, wherein: The user portrait construction module includes a behavior feature acquisition unit and a portrait generation unit; the behavior feature acquisition unit is used to collect input speed, error rate, and data trajectory, as well as features such as web page browsing stay duration and path jump; the portrait generation unit is used to align the behavior features in space and time through a multi-modal fusion model and generate an implicit semantic portrait; The risk assessment module includes a device fingerprint construction unit and a portrait baseline evaluation unit; the device fingerprint construction unit is used to obtain the IP address and device information and compare them with the historical trusted library to evaluate the login risk; the portrait baseline evaluation unit is used to construct a baseline based on the mean value of historical behavior features and detect the real-time behavior deviation degree; The associated risk mining module includes an associated user search unit and a risk set construction unit; the associated user search unit is used to monitor the risk user logs to match associated users with the same browsing behavior, device information, and IP address; the risk set construction unit is used to store the associated risk user portraits indexed by user name and construct a dynamic risk set.
10. The network security detection system based on machine learning according to claim 8, wherein: The risk number prediction module includes a reduction value prediction unit and a prediction value calculation unit; the reduction value prediction unit is used to predict the number of risk users who turn into normal users in the risk elimination value; The prediction value calculation unit is used to calculate the actual number of risk users based on the potential associated user prediction value and the risk reduction value; The risk warning module includes a growth rate calculation unit and a warning trigger unit; The growth rate calculation unit is used to calculate the future growth rate of risk users according to the difference between the prediction and the current number; the warning trigger unit is used to issue a warning signal by comparing the maximum growth rate threshold.
Citation Information
Patent Citations
Equipment data supervision system and method based on temperature change
CN117032415A
Real-time attack detection method and system based on label transfer and event baseline learning
CN118827248A
System and methods for cybersecurity analysis using UEBA and network topology data and trigger - based network remediation
US20230412620A1
Operation and maintenance processing method, and terminal device
WO2023159994A1
Cited By
Target object portrait generation method and device, computer equipment and storage medium
CN116451074A
Image generation method, device, computer device, and storage medium for target object
CN116451074B
Network risk behavior identification method, electronic equipment, storage medium and program
CN121125169A
Insurance data processing method and device based on machine learning and storage medium
CN121304353A