Computer abnormal behavior detection method based on artificial intelligence

By verifying the diversity of user login passwords, reserved password databases and search keywords, the misjudgment problem of abnormal behavior detection in traditional methods is solved, and more efficient user behavior identification and security protection is achieved.

CN120337189APending Publication Date: 2025-07-18ZHEJIANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510481051.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Traditional computer abnormal behavior detection methods only judge the errors of the user entering password multiple times, resulting in inaccurate judgment results and high misjudgment rates, which cannot effectively distinguish between the user's own forgetting password and external attacks.

Method used

By obtaining the sameness between the three login passwords of the target user, the matching degree with the reserved password library, and the correlation between the search keywords, and combining the user's historical access route and keyword matching, diversity information verification is carried out to judge the user's behavior type.

Benefits of technology

It improves the accuracy and organization of abnormal behavior detection, can more accurately distinguish users' own errors from external attacks, reduce misjudgments, and ensure information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337189A_ABST
    Figure CN120337189A_ABST
Patent Text Reader

Abstract

The invention discloses a computer abnormal behavior detection method based on artificial intelligence, and relates to the technical field of computer abnormal behavior detection. And when the same login password does not exist in the three-time login password and the reserved password library and the association matching degree between the keyword to which the search text information of the target user in other files or search pages belongs and the content information of the file which is not frequently accessed is smaller than a preset association degree threshold value, outputting abnormal behavior early warning information. And if the password similarity is greater than or equal to the same judgment value, the three-time login password and the reserved password are stored in at least one same login password, and the association matching degree is smaller than an association degree threshold value, performing abnormal behavior verification according to the content search keyword. According to the computer abnormal behavior detection method based on artificial intelligence, the accuracy of computer abnormal behavior detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of computer abnormal behavior detection, and particularly to a computer abnormal behavior detection method based on artificial intelligence. Background Art

[0002] In today's digital age, the security of user information is of crucial importance. A large amount of sensitive data is stored in various computer systems and network platforms. As the first entry interface for accessing this data, once abnormal behavior occurs during user login, it is very likely that the user's account information has been stolen or suffered a malicious attack. By detecting user login abnormal behavior promptly and accurately, potential security threats such as brute-force password cracking and credential stuffing attacks can be quickly discovered, and corresponding measures can be taken to prevent illegal access, effectively protecting users' privacy information, including personal identity data, financial information, social profiles, etc., and avoiding a series of serious consequences such as property losses and damaged personal reputations caused by information leakage.

[0003] In traditional technologies, the detection of user login abnormal behavior often only judges the abnormality of the user based on the single form of multiple incorrect password inputs by the user, without further verifying whether it is the user who has forgotten the password or most likely an abnormal behavior of an external invasive user, resulting in inaccurate judgment results of abnormal behavior, that is, false positives, reducing the low efficiency of computer abnormal behavior detection work and the lack of timeliness of early warnings. Summary of the Invention

[0004] To overcome the deficiencies of the above-mentioned prior art, this application provides a computer abnormal behavior detection method based on artificial intelligence.

[0005] A computer abnormal behavior detection method based on artificial intelligence provided by this application includes the following steps:

[0006] Step S1: Obtain the three login passwords of the target user for incorrect inputs when logging in to infrequently accessed files and the reserved password library for viewing all files of the main user. If the password similarity between the three login passwords is less than a preset similarity judgment value, and there is no identical login password between the three login passwords and the reserved password library, and the association matching degree between the keywords of the search text information of the target user on other files or search pages and the content information of the infrequently accessed files is less than a preset association degree threshold, an abnormal behavior warning message is output;

[0007] Step S2: If the password similarity is less than the similarity judgment value, and there is at least one identical login password between the three login passwords and the reserved password library, and the association matching degree is greater than or equal to the association degree threshold, a judgment result of the main user's incorrect behavior is output;

[0008] Step S3. If the password similarity is greater than or equal to the similarity judgment value, and there is or is not at least one identical login password between the three login passwords and the reserved password library and the associated matching degree is less than the association threshold, then verify the abnormal behavior according to the content access route or the search keyword, and output the judgment result of the main user's wrong behavior or the warning information of the abnormal behavior.

[0009] Preferably, obtain the three login passwords of the target user for incorrect login inputs to infrequently accessed files, and compare the three login passwords to obtain the password similarity.

[0010] Obtain the reserved password library for all file views of the main user, and preset the similarity judgment value. If the password similarity is less than the similarity judgment value and there is no identical login password between the three login passwords and the reserved password library, then output the first situation to be judged.

[0011] Preferably, according to the first situation to be judged, extract the characteristic keywords from the keyword of the search text information of the target user on other files or the search page, and match the associated matching degree between the characteristic keywords and the content information of the infrequently accessed files.

[0012] Preset the association threshold. If the associated matching degree is less than the association threshold, then judge that the target user is an abnormal user, and give an early warning of abnormal behavior, and output the warning information of abnormal behavior.

[0013] Preferably, if the password similarity is less than the similarity judgment value and there is at least one identical login password between the three login passwords and the reserved password library, then output the second situation to be judged. According to the second situation to be judged, if the associated matching degree is greater than or equal to the association threshold, then judge that the target user is the main user, and output the judgment result of the main user's wrong behavior.

[0014] If the password similarity is greater than or equal to the similarity judgment value and the associated matching degree is greater than or equal to the association threshold, then judge that the target user is the main user, and output the judgment result of the main user's wrong behavior.

[0015] Preferably, according to the second situation to be judged, if the associated matching degree is less than the association threshold, then it is impossible to judge whether the target user is the main user, and output the first verification information.

[0016] If the password similarity is greater than or equal to the similarity judgment value and there is at least one identical login password between the three login passwords and the reserved password library, then output the third situation to be judged. According to the third situation to be judged, if the associated matching degree is less than the association threshold, then it is impossible to judge whether the target user is the main user, and output the first verification information.

[0017] Preferably, according to the first verification information, the preprocessed access file to which at least one of the three login passwords and the reserved password library belongs, extract the reference access file that the main user often accessed in the most recent historical period from the preprocessed access file, and extract the three most frequently accessed keyword information from the reference access file to obtain the reference keywords;

[0018] Obtain the three keywords to be judged provided by the target user. If there are at least two identical keywords between the three keywords to be judged and the reference keywords, it is determined that the target user is the main user, and the judgment result of the main user's wrong behavior is output. If there are at least two different keywords between the three keywords to be judged and the reference keywords, it is determined that the target user is an abnormal user, and an abnormal behavior warning is given, and the abnormal behavior warning information is output.

[0019] Preferably, according to the first situation to be judged, if the correlation matching degree is greater than or equal to the correlation threshold, it is impossible to judge whether the target user is the main user, and the second verification information is output;

[0020] If the password similarity is greater than or equal to the similarity judgment value, and there is no identical login password in the three login passwords and the reserved password library, the fourth situation to be judged is output. According to the fourth situation to be judged, if the correlation matching degree is less than the correlation threshold, it is impossible to judge whether the target user is the main user, and the second verification information is output.

[0021] Preferably, according to the second verification information, obtain the reference content access route to which all the files that the main user often accessed in the most recent historical period belong, and obtain the access route to be judged provided by the target user, and perform similarity matching on the reference content access route and the access route to be judged to obtain the route matching degree;

[0022] Preset a route matching threshold. If the route matching degree is greater than or equal to the route matching threshold, it is determined that the target user is the main user, and the judgment result of the main user's wrong behavior is output. If the route matching degree is less than the route matching threshold, it is determined that the target user is an abnormal user, and an abnormal behavior warning is given, and the abnormal behavior warning information is output.

[0023] Compared with the prior art, the present invention has the following characteristics and beneficial effects:

[0024] By comparing the similarity between the three login passwords of the target user's incorrect input, whether there is the same login password for accessing other files among the three login passwords, it is highly likely that the target user is the primary user and may confuse the login passwords for other accessed files and files that are not frequently accessed at this time. Also, it is checked whether the target user searches for relevant information before logging in to infrequently accessed files and performs a similarity match with the keyword information in the infrequently accessed files. Based on the matching results of the above three aspects of information, it is finally determined whether the target user's behavior is an abnormal behavior of an external intruder or an error of the primary user. In addition, if there is a situation where a direct judgment cannot be made, information comparison is performed between the access route of the frequently accessed files of the primary user provided by the target user in the recent historical period and the actual access route of the frequently accessed files of the primary user in the recent historical period, or information comparison is performed between the keyword information of the content viewed in the frequently accessed files of the primary user provided by the target user in the recent historical period and the actual keyword information of the content viewed in the frequently accessed files of the primary user in the recent historical period, so as to finally determine whether the target user's behavior is an abnormal behavior of an external intruder or an error of the primary user. By performing the above-mentioned detection of abnormal behaviors in various situations, the rationality of the user login abnormal behavior detection process is enhanced, and the verification process of discriminatory information is fully carried out to further improve the accuracy of the final abnormal behavior detection result. Description of the Drawings

[0025] Figure 1 It is a block diagram of the steps of a computer abnormal behavior detection method based on artificial intelligence mainly embodied in this embodiment. Detailed Embodiment

[0026] The present invention will be further described in detail below in conjunction with the following embodiments.

[0027] Refer to Figure 1 , a computer abnormal behavior detection method based on artificial intelligence, the method includes the following steps:

[0028] Step S1, obtain the three login passwords of the target user's incorrect login to infrequently accessed files and the reserved password library for all file views of the primary user. If the password similarity between the three login passwords is less than the preset similarity judgment value, and there is no identical login password between the three login passwords and the reserved password library, and the association matching degree between the keyword information of the search text information of the target user in other files or search pages and the content information of the infrequently accessed files is less than the preset association degree threshold, an abnormal behavior warning message is output.

[0029] Step S2, if the password similarity is less than the similarity judgment value, and there is at least one identical login password between the three login passwords and the reserved password library and the association matching degree is greater than or equal to the association degree threshold, a judgment result of the primary user's error behavior is output.

[0030] Step S3, if the password similarity is greater than or equal to the similarity judgment value, and there is at least one identical login password in the three login passwords and the reserved password library, or there is no such identical login password, and the associated matching degree is less than the association threshold, then verify the abnormal behavior according to the content access route or the search keyword, and output the judgment result of the main user's wrong behavior or the warning information of the abnormal behavior.

[0031] Specifically, by comparing the similarity between the three login passwords wrongly entered by the target user, and whether there is an identical login password for other accessed files among the three login passwords. Since it is very likely that the target user is the main user and confuses the login passwords of other accessed files and the files not frequently accessed at this time. Also, check whether the target user searches for relevant information before logging in to the files not frequently accessed, and perform a similarity match with the keyword information in the files not frequently accessed. Based on the matching results of the above three aspects of information, finally determine whether the target user's behavior is an abnormal behavior of an external intruder or a wrong behavior of the main user. In addition, if there is a situation where it is impossible to directly judge, then compare the access route of the files frequently accessed by the main user provided by the target user in the most recent historical period with the actual access route of the files frequently accessed by the main user in the most recent historical period, or compare the keyword information of the content viewed in the files frequently accessed by the main user provided by the target user in the most recent historical period with the actual keyword information of the content viewed in the files frequently accessed by the main user in the most recent historical period, so as to finally determine whether the target user's behavior is an abnormal behavior of an external intruder or a wrong behavior of the main user. By performing the abnormal behavior judgment in the above diverse situations, the rationality of the user login abnormal behavior detection process is enhanced, and the verification process of the discriminative information is fully carried out to further improve the accuracy of the final abnormal behavior detection result.

[0032] Specifically, step S1 includes the following sub-steps:

[0033] Obtain the three login passwords wrongly entered by the target user for logging in to the files not frequently accessed, and compare the similarity of the three login passwords to obtain the password similarity.

[0034] Obtain the reserved password library for all file views of the main user, preset the similarity judgment value. If the password similarity is less than the similarity judgment value, and there is no identical login password in the three login passwords and the reserved password library, then output the first situation to be judged.

[0035] Specifically, for example, the three - time login passwords (such as 123456, 123564, 123645), the password similarity (the first three - digit passwords are the same, which is 50%, that is, the password similarity, where "the same" here means the order and the numbers are both the same), the reserved password library (if the infrequently accessed file for this login is b, then all these files refer to the other infrequently accessed files and frequently accessed files that have set login passwords except b. If there are a1, a2, a3, and their respective login passwords are 132465, 555333, 231456 (here, three are selected for illustration), this is the reserved password library), and the first case to be judged (if the preset similarity judgment value is 60%, and the password similarity of the above - mentioned situation is 50% which is less than 60%, and there is no identical login password between the three - time login passwords and the reserved password library, then this situation is the first case to be judged).

[0036] Specifically, step S1 further includes the following sub - steps:

[0037] According to the first case to be judged, extract the characteristic keywords from the keywords belonging to the search text information of the target user in other files or on the search page, and match the correlation between the characteristic keywords and the content information of the infrequently accessed files to obtain the correlation matching degree.

[0038] Preset a correlation threshold. If the correlation matching degree is less than the correlation threshold, then judge that the target user is an abnormal user, and issue an early warning for abnormal behavior, and output the abnormal behavior early - warning information.

[0039] Specifically, for example, the characteristic keywords (refer to the target user's viewing of the content of other files or querying the content of other web page information before logging in to b, and extract the keywords from the queried content to obtain the characteristic keywords, such as t1, t2, t3, t4, t5 respectively. Since this process is very likely that the target user is the main user and selectively accesses the b file through relevant information queries), the correlation matching degree (if the keywords contained in the content information of b are t1, T2, T3, T4, T5, and only t1 is the same, then the correlation matching degree is 20%), and the abnormal behavior early - warning information (if the preset correlation threshold is 80%, it means that the target user is not the main user, that is, very likely an external intrusion user. Then judge the abnormal behavior of the external intrusion user and issue an abnormal behavior early - warning information to give an early - warning notice to the backend and take security maintenance measures in a timely manner).

[0040] Specifically, step S2 includes the following sub - steps:

[0041] If the password similarity is less than the similarity judgment value, and there is at least one identical login password between the three - time login passwords and the reserved password library, then output the second case to be judged. According to the second case to be judged, if the correlation matching degree is greater than or equal to the correlation threshold, then judge that the target user is the main user and output the judgment result of the main user's wrong behavior.

[0042] If the password similarity is greater than or equal to the similarity judgment value, and the associated matching degree is greater than or equal to the associated degree threshold, then it is determined that the target user is the primary user, and the judgment result of the primary user's incorrect behavior is output.

[0043] Specifically, for the second case to be judged (if the password similarity is 50%, the reserved password library contains 123564, 132465, 555333, and there is at least one identical login password between the three login passwords and the reserved password library: 123564), the judgment result of the primary user's incorrect behavior (the associated matching degree is 80%), then it can be determined that the target user is the primary user, that is, in this process, it is very likely that the target user is the primary user, and it is a process of selectively accessing file b through querying relevant information and is a real-time operation process. Then, it is determined that the above password input error operation process is the primary user's own forgotten password login error behavior. If the password similarity is 66.6%, then whether there is an identical login password between the three login passwords and the reserved password library at this time is not the main judgment condition. If the main judgment of the associated matching degree is 80%, then it can be directly determined that the target user is the primary user, and it is determined that the above password input error operation process is the primary user's own forgotten password login error behavior).

[0044] Specifically, step S3 includes the following sub-steps:

[0045] According to the second case to be judged, if the associated matching degree is less than the associated degree threshold, then it is impossible to determine whether the target user is the primary user, and verification information one is output.

[0046] If the password similarity is greater than or equal to the similarity judgment value, and there is at least one identical login password between the three login passwords and the reserved password library, then the third case to be judged is output. According to the third case to be judged, if the associated matching degree is less than the associated degree threshold, then it is impossible to determine whether the target user is the primary user, and verification information one is output.

[0047] Specifically, according to the second case to be judged, if the associated matching degree is less than the associated degree threshold, then it may be that the target user is the primary user: his own forgotten password behavior, or it may be an intrusion behavior of an external intrusion user. Therefore, further judgment is still required. The fifth case to be judged (if the password similarity is 66.6%, the reserved password library contains 123564, 132465, 555333, and there is at least one identical login password between the three login passwords and the reserved password library: 123564, this situation is the third case to be judged). According to the third case to be judged, if the associated matching degree is less than the associated degree threshold, then it may be that the target user is the primary user: his own forgotten password behavior, or it may be an intrusion behavior of an external intrusion user. Therefore, further judgment is still required.

[0048] Specifically, step S3 also includes the following sub-steps:

[0049] According to the preprocessed access file to which the verification information one, the three login passwords, and at least one of the reserved password libraries belong and share the same login password, extract the reference access file that the main user often accessed in the recent historical period from the preprocessed access file, and extract the three most frequently accessed keyword information from the reference access file to obtain the reference keywords.

[0050] Obtain the three keywords to be judged provided by the target user. If there are at least two identical keywords between the three keywords to be judged and the reference keywords, determine that the target user is the main user and output the judgment result of the main user's incorrect behavior. If there are at least two different keywords between the three keywords to be judged and the reference keywords, determine that the target user is an abnormal user, issue an early warning for abnormal behavior, and output the early warning information for abnormal behavior.

[0051] Specifically, for example, in the preprocessed access file (such as the a1 file to which 123564 belongs, if the a1 file also contains a11, a12, and a13 files, and if a11 is the file that the main user often accessed in the recent historical period, it is the reference access file), the reference keywords (if they are g1, g2, g3), the three keywords to be judged (that is, provide an information filling form to the target user for the target user to conduct secondary information verification. If the target user provides G1, g2, g3, and g2 and g3 are the same, determine that the target user is the main user, and the above password input error operation process is the incorrect behavior of the main user forgetting the password to log in), and the early warning information for abnormal behavior (if the target user provides G1, G2, g3, it can be explained that the target user is not the main user, that is, most likely an external intrusion user. Then judge the abnormal behavior of the external intrusion user and issue an early warning information for abnormal behavior to give an early warning notice to the backend and take security maintenance measures in a timely manner).

[0052] Specifically, step S3 further includes the following sub-steps:

[0053] According to the to-be-judged situation one, if the correlation matching degree is greater than or equal to the correlation threshold, it is impossible to determine whether the target user is the main user, and output the verification information two.

[0054] If the password similarity is greater than or equal to the similarity judgment value, and there is no identical login password between the three login passwords and the reserved password library, then output the to-be-judged situation four. According to the to-be-judged situation four, if the correlation matching degree is less than the correlation threshold, it is impossible to determine whether the target user is the main user, and output the verification information two.

[0055] Specifically, according to the first situation to be judged, if the associated matching degree is greater than or equal to the associated degree threshold, it may be that the target user is the main user: the behavior of forgetting the password by himself, or it may be the intrusion behavior of an external invasive user. Therefore, further judgment is still needed. For the fourth situation to be judged (if the password similarity is 66.6%, the reserved password library contains 132465, 555333, and 231456, and none of the three login passwords match the reserved password library, this situation is the fourth situation to be judged). According to the fourth situation to be judged, if the associated matching degree is less than the associated degree threshold, it may be that the target user is the main user: the behavior of forgetting the password by himself, or it may be the intrusion behavior of an external invasive user. Therefore, further judgment is still needed.

[0056] Specifically, step S3 further includes the following sub-steps:

[0057] According to the second verification information, obtain the reference content access route to which all the frequently accessed files of the main user belong in the most recent historical period, and obtain the access route to be judged provided by the target user. Match the reference content access route and the access route to be judged to obtain the route matching degree.

[0058] Preset a route matching threshold. If the route matching degree is greater than or equal to the route matching threshold, judge that the target user is the main user and output the judgment result of the main user's wrong behavior. If the route matching degree is less than the route matching threshold, judge that the target user is an abnormal user, issue an early warning for abnormal behavior, and output the early warning information for abnormal behavior.

[0059] Specifically, such as the reference content access route (if all the frequently accessed files of the main user in the most recent historical period are w1 (the browsing route of the sub-file is: w11 - w14 - w12), w2 (the browsing route of the sub-file is: w21 - w22 - w23), w3 (the browsing route of the sub-file is: w32 - w31 - w33), the browsing route of the sub-file is mainly determined by the main user's query of the content in the file, and the browsing route of the sub-file is mainly related to the content connection association degree between the files), the access route to be judged (if the browsing route of the sub-file provided by the target user is w25 - w22 - w26, that is, the access route to be judged), the route matching degree (which is 0), the preset route matching threshold (if it is 60%), then the above judgment result is that the route matching degree is less than the route matching threshold, judge the abnormal behavior of the external invasive user, and issue an early warning information for abnormal behavior to give an early warning notice to the backend and take security maintenance measures in time. For the access route to be judged (if the browsing route of the sub-file provided by the target user is w25 - w22 - w26, w11 - w14 - w12, w21 - w22 - w23, that is, the access route to be judged), then the above judgment result is that the route matching degree is greater than the route matching threshold, judge that the target user is the main user, and the above process of incorrect password input is the wrong behavior of the main user forgetting the password to log in.

[0060] The above are all preferred embodiments of the present application, and the protection scope of the present application is not limited thereby. Therefore, all equivalent changes made according to the structure, shape, and principle of the present application shall be covered within the protection scope of the present application.

Claims

1. A computer abnormal behavior detection method based on artificial intelligence, characterized in that, Including the following steps: Step S1: Obtain the three login passwords entered incorrectly by the target user for infrequently accessed files and the reserved password library for all file views of the main user. If the password similarity degree between the three login passwords is less than the preset similarity judgment value, and there is no identical login password among the three login passwords and the reserved password library, and the association matching degree between the keyword of the search text information of the target user in other files or search pages and the content information of the infrequently accessed files is less than the preset association degree threshold, an abnormal behavior warning message is output; Step S2: If the password similarity degree is less than the similarity judgment value, and there is at least one identical login password among the three login passwords and the reserved password library, and the association matching degree is greater than or equal to the association degree threshold, the judgment result of the main user's incorrect behavior is output; Step S3: If the password similarity degree is greater than or equal to the similarity judgment value, and there is or is not at least one identical login password among the three login passwords and the reserved password library, and the association matching degree is less than the association degree threshold, then verify the abnormal behavior according to the content access route or search keyword, and output the judgment result of the main user's incorrect behavior or the abnormal behavior warning message.

2. The method for detecting computer abnormal behavior based on artificial intelligence according to claim 1, wherein Step S1 includes: Obtain the three login passwords entered incorrectly by the target user for infrequently accessed files, and compare the similarity degree of the three login passwords to obtain the password similarity degree; Obtain the reserved password library for all file views of the main user, preset the similarity judgment value. If the password similarity degree is less than the similarity judgment value, and there is no identical login password among the three login passwords and the reserved password library, then output the first situation to be judged.

3. The method for detecting abnormal computer behavior based on artificial intelligence according to claim 2, characterized in that, Step S1 also includes: According to the first situation to be judged, extract the characteristic keywords from the keyword of the search text information of the target user in other files or search pages, and match the association degree between the characteristic keywords and the content information of the infrequently accessed files to obtain the association matching degree; Preset the association degree threshold. If the association matching degree is less than the association degree threshold, it is determined that the target user is an abnormal user, and an abnormal behavior warning is issued, and an abnormal behavior warning message is output.

4. The method for detecting abnormal computer behavior based on artificial intelligence according to claim 3, characterized in that, Step S2 includes: If the password similarity degree is less than the similarity judgment value, and there is at least one identical login password among the three login passwords and the reserved password library, then output the second situation to be judged. According to the second situation to be judged, if the association matching degree is greater than or equal to the association degree threshold, it is determined that the target user is the main user, and the judgment result of the main user's incorrect behavior is output; If the password similarity degree is greater than or equal to the similarity judgment value, and the association matching degree is greater than or equal to the association degree threshold, it is determined that the target user is the main user, and the judgment result of the main user's incorrect behavior is output.

5. The method for detecting computer abnormal behavior based on artificial intelligence according to claim 4, wherein Step S3 includes: According to the second situation to be judged, if the association matching degree is less than the association degree threshold, it is impossible to determine whether the target user is the main user, and verification information one is output; If the password similarity degree is greater than or equal to the similarity judgment value, and there is at least one identical login password among the three login passwords and the reserved password library, then output the third situation to be judged. According to the third situation to be judged, if the association matching degree is less than the association degree threshold, it is impossible to determine whether the target user is the main user, and verification information one is output.

6. The method for detecting computer abnormal behavior based on artificial intelligence according to claim 5, wherein Step S3 also includes: According to the preprocessed access file to which at least one of the same login passwords belongs among the verification information one, the three login passwords, and the reserved password library, extract the reference access file that the primary user often accessed in the recent historical period from the preprocessed access file, and extract the three most frequently accessed keyword information from the reference access file to obtain the reference keywords; Obtain the three keywords to be judged provided by the target user. If there are at least two identical keywords among the three keywords to be judged and the reference keywords, determine that the target user is the primary user and output the judgment result of the primary user's incorrect behavior. If there are at least two different keywords among the three keywords to be judged and the reference keywords, determine that the target user is an abnormal user, issue an early warning for abnormal behavior, and output the early warning information for abnormal behavior.

7. An artificial intelligence-based computer abnormal behavior detection method according to claim 6, characterized in that, Step S3 further includes: According to the first situation to be judged, if the correlation matching degree is greater than or equal to the correlation threshold, it is impossible to determine whether the target user is the primary user, and verification information two is output; If the password similarity is greater than or equal to the similarity judgment value, and there is no identical login password in the three login passwords and the reserved password library, then output the fourth situation to be judged. According to the fourth situation to be judged, if the correlation matching degree is less than the correlation threshold, it is impossible to determine whether the target user is the primary user, and verification information two is output.

8. An artificial intelligence-based computer abnormal behavior detection method according to claim 7, characterized in that, Step S3 further includes: According to the verification information two, obtain the reference content access route to which all the frequently accessed files of the primary user belong in the recent historical period, and obtain the access route to be judged provided by the target user. Perform similarity matching on the reference content access route and the access route to be judged to obtain the route matching degree; Preset a route matching threshold. If the route matching degree is greater than or equal to the route matching threshold, determine that the target user is the primary user and output the judgment result of the primary user's incorrect behavior. If the route matching degree is less than the route matching threshold, determine that the target user is an abnormal user, issue an early warning for abnormal behavior, and output the early warning information for abnormal behavior.