Black and grey product node identification method and system based on multi-dimensional abnormal behaviors

Through multi-dimensional abnormal behavior analysis and Bayesian algorithm to identify black and gray nodes, the problem of black and gray node identification in the existing technology is solved, the accuracy of identification and network security level are improved, and the adaptability is strong.

CN120281502APending Publication Date: 2025-07-08XIAMEN MEIYA PICO INFORMATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510075206.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing technology lacks a systematic black and gray node identification method, making it difficult to directly identify black and gray nodes in the cyberspace, resulting in increased difficulty in attacks.

Method used

By obtaining multi-dimensional abnormal behavior feature data, an abnormal behavior feature engine and a black and gray production node feature knowledge base are constructed, and a Bayesian algorithm is used to judge the black and gray production nodes to which the abnormal behavior belongs, including a comprehensive analysis of data such as communication records, chat records, trajectory records, transaction records, etc.

Benefits of technology

It improves the accuracy and comprehensiveness of black and gray industry node identification, reduces the probability of misjudgment and misjudgment, enhances the flexibility and adaptability of the system, can respond to changes in black and gray industry in a timely manner, and provides continuous technical support for network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281502A_ABST
    Figure CN120281502A_ABST
Patent Text Reader

Abstract

The invention provides a multi-dimensional abnormal behavior-based black and grey product node identification method and system, and the method comprises the steps: obtaining target multi-dimensional abnormal behavior feature data which comprises a communication record, a chat record, a track record, a transaction record, an APP installation list, a file transmission record and traffic abnormal data; constructing an abnormal behavior feature engine based on a pre-configured abnormal behavior rule, and calculating a plurality of abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data by using the abnormal behavior feature engine; based on historical multi-dimensional abnormal behavior features corresponding to the historical black-grey production nodes, constructing a black-grey production node feature knowledge base, and based on the historical black-grey production nodes stored in the black-grey production node feature knowledge base, judging the black-grey production nodes to which a plurality of abnormal behaviors belong by using a Bayesian algorithm. Through comprehensive analysis of multi-dimensional abnormal behaviors, the accuracy and comprehensiveness of recognition are improved, and the probability of misjudgment and missed judgment of black and grey product nodes is effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data node analysis, and in particular to a method and system for identifying black and gray production nodes based on multi-dimensional abnormal behaviors. Background Art

[0002] The most important feature of the black and gray production entities in the cyberspace is the "chain-like" structure. In this structure, except for the main body of the black and gray production organizations, most of them are network black and gray productions playing different roles in various industrial chains. The black and gray productions of each industrial chain are intertwined with each other, thus forming a three-dimensional network structure. The black and gray production node is a component in the black and gray industrial chain, playing a link point, capable of providing a certain product, or providing a specific technical service, or independently completing a certain technical function. Since the black and gray production nodes often do not have direct contact with the victims and are difficult to be directly targeted, they are generally discovered by following up leads in the case expansion. Therefore, the identification and crackdown on black and gray production nodes have become the difficulties and hotspots in the new situation.

[0006] Currently, there are only methods or devices for identifying certain specific black and gray productions, such as black and gray production APKs, black and gray production devices, black and gray production fund transactions, etc., and there is no systematic method for solving the identification of black and gray production nodes. Summary of the Invention

[0007] In order to solve the technical problems raised in the background art, the present invention proposes a method and system for identifying black and gray production nodes based on multi-dimensional abnormal behaviors to solve the above technical problems.

[0008] According to one aspect of the present invention, a method for identifying black and gray production nodes based on multi-dimensional abnormal behaviors is proposed, including:

[0009] S1. Obtain target multi-dimensional abnormal behavior feature data, where the multi-dimensional abnormal behavior feature data includes forensic evidence data and traffic abnormal data, and the forensic evidence data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records;

[0010] S2. Construct an abnormal behavior feature engine based on pre-configured abnormal behavior feature rules, and use the abnormal behavior feature engine to calculate a number of abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data;

[0011] S3. Construct a black and gray production node feature knowledge base based on the historical multi-dimensional abnormal behavior features corresponding to the historical black and gray production nodes, and based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base, use the Bayesian algorithm to judge the black and gray production nodes to which the number of abnormal behaviors belong.

[0012] In some specific embodiments, the abnormal behavior rules in step S2 are defined according to the data types customarily input by users.

[0013] In some specific embodiments, the data types include trajectory data, communication data, IP login log, transaction data, APP installation list and chat data, and the abnormal behavior rules include time regularity anomalies, spatial location anomalies, IP change anomalies, transaction amount anomalies, transaction object anomalies, APP installation anomalies, transmission file size and frequency anomalies, file content anomalies and chat content anomalies of the corresponding data types.

[0014] In some specific embodiments, the IP change anomaly includes that the IP address is frequently changed in a short period of time, and the changed IP segments are completely different, or the real source is hidden by a proxy IP.

[0015] In some specific embodiments, abnormal transaction amounts include small but high-frequency abnormal transactions, or large transactions that are inconsistent with the historical transaction records of the account, or regular, periodic abnormal fluctuations in transaction amounts.

[0016] In some specific embodiments, abnormal APP installation includes installing applications of unknown origin, high risk rating, or inconsistent with the user's daily needs within a short period of time.

[0017] In some specific embodiments, the abnormal file transfer size and frequency include the existence of long-term continuous ultra-large file transfers, or irregular file transfer frequencies.

[0018] In some specific embodiments, the abnormal file content includes that the transmitted file contains sensitive information, or the format and encoding characteristics of the file are different from preset characteristics.

[0019] In some specific embodiments, step S3 includes:

[0020] S31. Calculate the historical black and gray production nodes C stored in the black and gray production node feature knowledge base i The prior probability P(C i );

[0021] S32, obtain m abnormal behaviors calculated by the abnormal behavior feature engine, and calculate them on the known black and gray production nodes C i In the case of , the joint probability of m abnormal behaviors is expressed as:

[0022] P(A1, A2, ..., A m |C i )=P(A1|C i )*P(A2|C i )*···*P(A m |C i )

[0023] Among them, P(A1, A2, A3, ... A m|C i ) represents the joint probability, P(A m |C i ) represents the probability that the m-th abnormal behavior occurs given the black and gray production node C i ;

[0024] S33. Calculate the total probability based on the prior probability and the joint probability, expressed as:

[0025]

[0026] where P(A1, A2, A3,... A m ) represents the total probability;

[0027] S34. Calculate the posterior probability of the black and gray production node C i based on the prior probability, the joint probability, and the total probability, expressed as:

[0028]

[0029] where P(C i |A1, A2, A3,... A m ) represents the posterior probability;

[0030] S35. Select the black and gray production node C i with the maximum posterior probability as the black and gray production node to which the m abnormal behaviors belong.

[0031] According to the second aspect of the present invention, a black and gray production node identification system based on multi-dimensional abnormal behaviors is proposed. The system includes:

[0032] An input module configured to obtain target multi-dimensional abnormal behavior feature data, where the multi-dimensional abnormal behavior feature data includes forensic data and traffic abnormal data, and the forensic data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records;

[0033] An identification module configured to construct an abnormal behavior feature engine based on pre-configured abnormal behavior feature rules and use the abnormal behavior feature engine to calculate a number of abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data;

[0034] A judgment module configured to construct a black and gray production node feature knowledge base based on historical multi-dimensional abnormal behavior features corresponding to historical black and gray production nodes, and use the Bayesian algorithm to judge the black and gray production nodes to which a number of abnormal behaviors belong based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base.

[0035] Through a method and system for identifying black and gray production nodes based on multi-dimensional abnormal behaviors in this application, black and gray production nodes can be effectively identified and combated, significantly improving the network security level and minimizing the harm caused by black and gray production to the greatest extent. Through the comprehensive analysis of multi-dimensional abnormal behaviors, the accuracy and comprehensiveness of identification are greatly improved, and the probabilities of misjudgment and missed judgment are effectively reduced. At the same time, the user-manageable definition of abnormal behaviors greatly increases the flexibility and adaptability of the system, enabling it to respond in a timely manner to the ever-changing means and patterns of black and gray production, providing strong and sustainable technical support for network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated into and constitute a part of this specification. The drawings illustrate the embodiments and, together with the description, are used to explain the principles of the present invention. Other embodiments and many of the expected advantages of the embodiments will be readily apparent as they become better understood by reference to the following detailed description. The other features, objects, and advantages of this application will become more apparent from the detailed description of the non-limiting embodiments made with reference to the following drawings:

[0037] Figure 1 is a flowchart of a method for identifying black and gray production nodes based on multi-dimensional abnormal behaviors according to an embodiment of this application;

[0038] Figure 2 is a flowchart of constructing an abnormal behavior feature engine according to an embodiment of this application;

[0039] Figure 3 is a schematic diagram of the historical multi-dimensional abnormal behavior features corresponding to historical black and gray production nodes according to an embodiment of this application;

[0040] Figure 4 is a framework diagram of a system for identifying black and gray production nodes based on multi-dimensional abnormal behaviors according to an embodiment of this application;

[0041] Figure 5 is a flowchart of the operation of a system for identifying black and gray production nodes based on multi-dimensional abnormal behaviors according to an embodiment of this application;

[0042] Figure 6 is a schematic diagram of the internal structure of a black and gray production node identification model according to an embodiment of this application;

[0043] Figure 7 is a schematic diagram of the structure of a computer system of an electronic device suitable for implementing the embodiments of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and are not intended to limit the invention. In addition, it should be noted that for the convenience of description, only the parts related to the invention are shown in the drawings.

[0045] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0046] A method for identifying black and gray production nodes based on multi-dimensional abnormal behaviors according to an embodiment of the present application Figure 1 is a flowchart of a method for identifying black and gray production nodes based on multi-dimensional abnormal behaviors according to an embodiment of the present application. Referring to Figure 1 this method includes:

[0047] S1. Obtain target multi-dimensional abnormal behavior feature data. The multi-dimensional abnormal behavior feature data includes forensic data and traffic abnormal data. The forensic data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records;

[0048] As an example, a large amount of forensic and traffic abnormal data related to black and gray production nodes is widely collected, covering users' behavior data, transaction data, network activity data, communication data, etc. These data sources are rich, including but not limited to various network platforms, e-commerce websites, social media, financial institutions, etc.

[0049] S2. Build an abnormal behavior feature engine based on pre-configured abnormal behavior feature rules, and use the abnormal behavior feature engine to calculate several abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data;

[0050] Specifically, Figure 2 is a flowchart of building an abnormal behavior feature engine according to an embodiment of the present application. Referring to Figure 2 the definition of abnormal behavior rules is defined for different dimensions according to different data types. For example, the data types include: trajectory data, communication data, IP login logs, transaction data, APP installation lists, chat data, etc. The configuration of abnormal behaviors can be divided into time pattern abnormalities, spatial location abnormalities, IP transformation abnormalities, transaction amount abnormalities, transaction object abnormalities, APP installation abnormalities, transmission file size and frequency abnormalities, file content abnormalities, chat content abnormalities, chat terminology abnormalities, etc.

[0051] Specifically, the IP transformation abnormality is manifested as that the IP address is frequently changed within a short time, and the difference between the changed IP segments is huge, or a large number of proxy IPs are used to hide the true source.

[0052] Abnormal transaction amounts include various situations, such as small but high-frequency abnormal transactions, or suddenly large transactions that are seriously inconsistent with the account's historical transaction records, or regular and periodic abnormal fluctuations in transaction amounts.

[0053] Abnormal transaction objects refer to those that are significantly different from the usual types of trading partners, or those that conduct frequent and large transactions with objects marked as high-risk.

[0054] Abnormal APP installations, for example, involve installing a large number of applications from unknown sources, with high risk ratings, or inconsistent with the user's daily needs within a short period.

[0055] Regarding abnormal transfer file sizes and frequencies, if there are long-term continuous transfers of extremely large files, or the frequencies of file transfers are extremely irregular, far exceeding normal business requirements.

[0056] Abnormal file contents include files that contain sensitive information, black and gray production content, or files whose characteristics such as format and encoding are significantly different from those of common normal files.

[0057] Abnormal chat contents may contain specific black and gray production keywords, codes, or expressions involving obvious fraud, inducement, etc.

[0058] Abnormal chat terms, for example, using highly patterned and formulaic language, which is significantly different from normal communication methods.

[0059] Users can flexibly manage the definitions of these abnormal behaviors, including adding new types of abnormal behaviors, deleting definitions that are no longer applicable, and modifying and improving existing definitions.

[0060] S3. Construct a black and gray production node feature knowledge base based on the historical multi-dimensional abnormal behavior characteristics corresponding to historical black and gray production nodes. Based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base, use the Bayesian algorithm to determine the black and gray production nodes to which several abnormal behaviors belong.

[0061] As an example, Figure 3 is a schematic diagram of the historical multi-dimensional abnormal behavior characteristics corresponding to a historical black and gray production node in an embodiment of the present application. Refer to Figure 3 , including:

[0062] 1. Having a large number of virtual identities such as QQ and WeChat

[0063] 2. Having a large number of devices such as mobile phones or computers

[0064] 3. Regularly transferring a large number of EXCEL files daily, with file sizes > 1MB, and file names mostly containing keywords such as materials, customers, resources, etc.

[0065] 4. There are numerous trading counterparts, and most of them only conduct one transaction.

[0066] 5. As the payee in the transaction records, the received amount is basically recorded in whole hundreds without any fractional amount.

[0067] 6. Install many special APPs: VPN, Telegram (TG), Potato, and virtual currency APPs

[0068] The chat content contains a large number of advertisements inferring personal information, and the content includes keywords such as: materials, customers, resources, no bargaining, etc.

[0069] Specifically, based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base, step S3 uses the Bayesian algorithm to determine the black and gray production nodes to which several abnormal behaviors belong, including: first, assume that there are n types of black and gray production nodes stored in the black and gray production node feature knowledge base, which are respectively marked as C1, C2, C3, …… C n , there are m abnormal behaviors in the input data, which are marked as A1, A2, A3, …… A m .

[0070] S31. Calculate the prior probability P(C i ) of the historical black and gray production node C i ) stored in the black and gray production node feature knowledge base;

[0071] S32. Obtain the m abnormal behaviors calculated by the abnormal behavior feature engine, and calculate the joint probability of the occurrence of m abnormal behaviors under the condition of knowing the black and gray production node C i , which is expressed as:

[0072] P(A1, A2, …, A m |C i ) = P(A1|C i ) * P(A2|C i ) * … * P(A m |C i )

[0073] Among them, P(A1, A2, A3, …… A m |C i ) represents the joint probability, and P(A m |C i ) represents the probability of the occurrence of the mth abnormal behavior under the condition of knowing the black and gray production node C i ;

[0074] S33. Calculate the total probability based on the prior probability and the joint probability, which is expressed as:

[0075]

[0076] Among them, P(A1, A2, A3, …… A m ) represents the total probability;

[0077] S34. Calculate the posterior probability of the black and gray production node C based on the prior probability, joint probability, and total probability, which is expressed as: i

[0078]

[0079] Among them, P(C i |A1, A2, A3, …… A m ) represents the posterior probability;

[0080] S35. Select the black and gray production node C with the largest posterior probability i as the black and gray production node to which the m abnormal behaviors belong.

[0081] As an example, assume that the calculation results are:

[0082] P(C1|A1, A2, A3, …… A m ) = 0.25

[0083] P(C2|A1, A2, A3, …… A m ) = 0.3

[0084] P(C3|A1, A2, A3, …… A m ) = 0.55

[0085] ……

[0086] P(C n |A1,A2,A3,……A m ) = 0.4

[0087] Since the value of P(C3|A1,A2,A3,……A m ) is the largest, it can be determined that the input data most likely belongs to the black and gray production node C3.

[0088] According to the second aspect of the present invention, Figure 4 is a framework diagram of a black and gray production node recognition system based on multi-dimensional abnormal behaviors according to an embodiment of the present application. Refer to Figure 4, the system includes: an input module 401 configured to obtain target multi-dimensional abnormal behavior feature data, where the multi-dimensional abnormal behavior feature data includes forensic data and traffic abnormal data, and the forensic data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records; an identification module 402 configured to build an abnormal behavior feature engine based on pre-configured abnormal behavior feature rules, and use the abnormal behavior feature engine to calculate several abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data; a judgment module 403 configured to build a black and gray production node feature knowledge base based on the historical multi-dimensional abnormal behavior features corresponding to historical black and gray production nodes, and use the Bayesian algorithm to judge the black and gray production nodes to which the several abnormal behaviors belong based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base.

[0089] As an example, Figure 5 is a flowchart of the operation of a black and gray production node identification system based on multi-dimensional abnormal behaviors according to an embodiment of the present application. Refer to Figure 5 , the forensic data and traffic data are input through the input module 401, and the black and gray production nodes are obtained through judgment by the black and gray production node identification model. Among them, Figure 6 is a schematic structural diagram inside a black and gray production node identification model according to an embodiment of the present application. Refer to Figure 6 , the black and gray production node identification model includes an identification module 402 and a judgment module 403.

[0090] Through the method and system for identifying black and gray production nodes based on multi-dimensional abnormal behaviors of the present application, black and gray production nodes can be effectively identified and combated, the network security level can be significantly improved, and the harm caused by black and gray production can be minimized to the greatest extent. Through the comprehensive analysis of multi-dimensional abnormal behaviors, the accuracy and comprehensiveness of identification are greatly improved, and the probability of misjudgment and missed judgment is effectively reduced. At the same time, the user-manageable definition of abnormal behaviors greatly increases the flexibility and adaptability of the system, can timely respond to the constantly changing means and patterns of black and gray production, and provides strong and sustainable technical support for network security protection.

[0091] Next, refer to Figure 7 , which shows a schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application. Figure 7 The electronic device shown is only an example and should not bring any limitations to the functions and usage scopes of the embodiments of the present application.

[0092] As Figure 7As shown, computer system 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage section 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the system 700 are also stored. The CPU 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0093] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, etc.; an output section 707 including, for example, a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, a modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as needed so that a computer program read from it can be installed into the storage section 708 as needed.

[0094] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable storage medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 709, and / or installed from a removable medium 711. When the computer program is executed by a central processing unit (CPU) 701, the above functions defined in the method of the present application are performed. It should be noted that the computer-readable storage medium of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable storage medium other than a computer-readable storage medium that can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0095] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0096] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0097] The modules described in the embodiments of this application can be implemented in software or in hardware.

[0098] As another aspect, the present application also provides a computer-readable storage medium. The computer-readable storage medium may be included in the electronic device described in the above embodiments; or it may exist separately without being assembled into the electronic device. The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to perform: obtaining target multi-dimensional abnormal behavior feature data, where the multi-dimensional abnormal behavior feature data includes forensic data and traffic abnormal data, and the forensic data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records; constructing an abnormal behavior feature engine based on pre-configured abnormal behavior rules, and using the abnormal behavior feature engine to calculate a number of abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data; constructing a black and gray production node feature knowledge base based on the historical multi-dimensional abnormal behavior features corresponding to historical black and gray production nodes, and using the Bayesian algorithm to determine the black and gray production nodes to which the number of abnormal behaviors belong based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base.

[0099] The above description is only the preferred embodiments of the present application and the description of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present application.

Claims

1. A method for identifying black and gray production nodes based on multi-dimensional abnormal behaviors, characterized in that, Including: S1. Obtain target multi-dimensional abnormal behavior feature data, where the multi-dimensional abnormal behavior feature data includes forensic data and traffic abnormal data, and the forensic data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records; S2. Construct an abnormal behavior feature engine based on pre-configured abnormal behavior feature rules, and use the abnormal behavior feature engine to calculate several abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data; S3. Construct a black and gray production node feature knowledge base based on the historical multi-dimensional abnormal behavior features corresponding to historical black and gray production nodes. Based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base, use the Bayesian algorithm to determine the black and gray production nodes to which the several abnormal behaviors belong.

2. The method according to claim 1, wherein The abnormal behavior rules in step S2 are defined according to the data types custom-input by the user.

3. The method according to claim 2, wherein The data types include trajectory data, communication data, IP login logs, transaction data, APP installation lists, and chat data. The abnormal behavior rules include time pattern abnormalities, spatial location abnormalities, IP transformation abnormalities, transaction amount abnormalities, transaction object abnormalities, APP installation abnormalities, transmission file size and frequency abnormalities, file content abnormalities, and chat content abnormalities corresponding to the data types.

4. The method according to claim 3, characterized in that The IP transformation abnormality includes that the IP address is frequently changed within a short period of time, and the differences in the changed IP segments are completely different, or the true source is hidden through a proxy IP.

5. The method according to claim 3, wherein The transaction amount abnormality includes the occurrence of small but frequent abnormal transactions, or the occurrence of large transactions that do not match the account's historical transaction records, or the transaction amount shows regular and periodic abnormal fluctuations.

6. The method according to claim 3, wherein The APP installation abnormality includes installing application programs with unknown sources, high risk ratings, or inconsistent with the user's daily needs within a short period of time.

7. The method according to claim 3, wherein The transmission file size and frequency abnormality includes the existence of long-term continuous large file transmissions, or the irregular frequency of file transmissions.

8. The method according to claim 3, wherein The file content abnormality includes that the transmitted file contains sensitive information, or the format and encoding characteristics of the file are different from the preset characteristics.

9. The method according to claim 1, wherein Step S3 includes: S31. Calculate the prior probability P(C i ) of the historical black and gray production node C stored in the black and gray production node feature knowledge base i ); S32. Obtain the m abnormal behaviors calculated by the abnormal behavior feature engine, and calculate the joint probability of the occurrence of the m abnormal behaviors when the black and gray production node C is known i is as follows: P(A1,A2,…,A m |C i ) = P(A1|C i ) * P(A2|C i ) * … * P(A m |C i ) Among them, P(A1,A2,A3,……A m |C i ) represents the joint probability, and P(A m |C i ) represents the probability of the m-th abnormal behavior occurring given the known black and gray production node C i . S33. Calculate the total probability based on the prior probability and the joint probability, expressed as: Among them, P(A1, A2, A3, …… A m ) represents the total probability; S34. Calculate the posterior probability of the black and gray production node C based on the prior probability, the joint probability, and the total probability, expressed as: i ​ Among them, P(C i |A1,A2,A3,……A m ) represents the posterior probability; S35. Select the black and gray production node C with the largest posterior probability. i As the black and gray production node to which the m abnormal behaviors belong.

10. A black and gray production node recognition system based on multi-dimensional abnormal behavior, characterized in that, The system includes: An input module configured to obtain target multi-dimensional abnormal behavior feature data, where the multi-dimensional abnormal behavior feature data includes forensic data and traffic abnormal data, and the forensic data includes communication records, chat records, trajectory records, transaction records, APP installation lists, and file transfer records; An identification module configured to construct an abnormal behavior feature engine based on pre-configured abnormal behavior feature rules, and use the abnormal behavior feature engine to calculate several abnormal behaviors existing in the target multi-dimensional abnormal behavior feature data; A judgment module configured to construct a black and gray production node feature knowledge base based on the historical multi-dimensional abnormal behavior features corresponding to historical black and gray production nodes. Based on the historical black and gray production nodes stored in the black and gray production node feature knowledge base, use the Bayesian algorithm to determine the black and gray production nodes to which the several abnormal behaviors belong.