Abnormal login detection method and device based on time ring coordinate system

Through the abnormal login detection method based on the time ring coordinate system, the normal login rules are automatically learned, and the false alarms and missed reports caused by manual configuration rules are solved, and efficient and low-overhead abnormal login detection is achieved.

CN120342787AActive Publication Date: 2025-07-18BEIJING CHAITIN TECH CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510817159.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

In the prior art, abnormal login detection relies on manual configuration rules, making it difficult to accurately configure the time field, resulting in false alarms and missed alarms, and cannot adapt to changes in server login situations.

Method used

The method based on the time ring coordinate system is adopted, by collecting historical login events, building the time ring coordinate system, dividing the adjacent point clusters, calculating the weight of the adjacent point clusters, automatically learning the normal login rules, and judging abnormal login.

Benefits of technology

There is no need for manual configuration rules, it automatically adapts to changes in login rules, reduces false alarms and missed reports, has low performance overhead, strong interpretability, and can visually present the normality of login events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342787A_ABST
    Figure CN120342787A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal login detection method and device based on a time ring coordinate system, and relates to the technical field of network security. The method comprises the steps of collecting historical login events of a target host, and extracting login time of each historical login event to form a historical login time sequence; marking the historical login time sequence as a plurality of coordinate points on a time annular coordinate system; dividing the coordinate points on the circumference into a plurality of adjacent point clusters, and calculating the weight of each adjacent point cluster according to the weight of each coordinate point in the adjacent point clusters; and judging whether the current login event is abnormal login or not by comparing the weight of the adjacent point cluster where the coordinate point of the current login event on the time annular coordinate system is located with a preset weight threshold value. According to the method, the abnormal login can be automatically found by learning the time rule of the login event through an algorithm without depending on a manually configured detection rule.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to an abnormal login detection method and device based on a time circular coordinate system. Background Art

[0002] Login events generated by normal users' logins are normal logins, and login events generated by attackers logging in to the invaded host through remote desktop (RDP) or SSH and other means are abnormal logins. Abnormal logins are prevalent in real-world intrusion activities.

[0003] Traditional abnormal login detection mainly relies on detection rules configured manually. The abnormal login detection function of security products provides a user interface for configuring detection rules. Administrators who deploy and use the security products configure detection rules that suit their own situations based on their understanding of their own network environments. Detection rules generally can configure fields such as login account names, login source IP addresses, and login times. The login time field is usually further refined into week, hour, minute, etc. Some security products' abnormal login detection functions support configuring normal login rules, that is, login events that meet the conditions are normal logins, and login events that do not meet the conditions are abnormal logins; they also support configuring abnormal login rules, that is, login events that meet the conditions are abnormal logins, and login events that do not meet the conditions are normal logins. It may also support configuring multiple different types of rules to comprehensively determine whether a login event is an abnormal login.

[0004] When configuring rules, the configuration of login account names and login source IP addresses is relatively simple. These information is easy to obtain and does not change frequently. The configuration of login time is relatively difficult. Security product administrators often have difficulty accurately filling in which time period's logins are normal logins or which time period's logins are abnormal logins. This is because the technical solutions for detecting abnormal logins relying on manually configured rules have the following several inherent defects: (1) Due to limited energy, the detection rules configured manually are often applied to a large number of servers in batches. However, in fact, even in the same network environment, the login situations of different servers are not exactly the same. For example: The security product administrator may configure the logins from 18:00 after work every day to 08:30 before work the next day as abnormal logins, but a certain department of the company may often work overtime, and there are still a large number of login events on the department's servers at 23:00 at night, resulting in a large number of false alarms.

[0005] (2) After manually completing the rule configuration, it is often not modified anymore. However, in reality, the login situation of the same server changes over time. For example, when a certain server is just launched, the operation and maintenance personnel will log in to the server relatively frequently, and a large number of normal logins will occur during working hours from Monday to Friday. The security product administrator may configure the normal login time range as from Monday to Friday working hours according to this situation, and logins outside the normal login time are considered abnormal logins. As the service runs stably, the server is no longer logged in frequently, and it is only logged in during the inspection on Wednesday morning every week. However, the security product administrator often cannot adjust the configuration in time. At this time, the originally configured normal login time range is too broad, and it is easy to miss abnormal login events.

[0006] Therefore, the prior art urgently needs to solve the problem that it is difficult for humans to accurately configure the time field in the abnormal login detection rule. Summary of the Invention

[0007] In view of the above defects or deficiencies in the prior art, the present invention provides an abnormal login detection method and device based on a time circular coordinate system to solve the technical problems mentioned in the background art.

[0008] In one aspect of the present invention, there is provided an abnormal login detection method based on a time circular coordinate system, including: Collect historical login events of the target host, and extract the login time of each historical login event to form a historical login time sequence; Mark the historical login time sequence as several coordinate points on the time circular coordinate system. The coordinate points on the time circular coordinate system are distributed on the circumference in sequence. The length of the circumference represents the time period for measuring user login activities. The scale value of the coordinate points on the circumference represents the user login time, and the arrangement order of the coordinate points on the circumference represents the direction of time passage; Divide the coordinate points on the circumference into several adjacent point clusters, and calculate the weight of each adjacent point cluster according to the weight of each coordinate point in the adjacent point cluster; wherein, each adjacent point cluster includes directly adjacent coordinate points and indirectly adjacent coordinate points; the directly adjacent coordinate points represent two adjacent coordinate points whose distance from each other is less than the distance threshold; the indirectly adjacent coordinate points represent a pair of points that are not in a directly adjacent relationship, but are formed by the direct adjacent relationship between the two coordinate points and at least one intermediate point; Judge whether the current login event is an abnormal login by comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold.

[0009] In another aspect of the present invention, there is also provided an abnormal login detection device based on a time circular coordinate system, including: A data acquisition module, configured to acquire historical login events of a target host, and extract the login time of each historical login event to form a historical login time series; A marking module, configured to mark the historical login time series as several coordinate points on a time circular coordinate system, where the coordinate points on the time circular coordinate system are distributed in sequence on the circumference, the length of the circumference represents the time period for measuring user login activities, the scale value of the coordinate points on the circumference represents the user login time, and the arrangement order of the coordinate points on the circumference represents the direction of time passing; A weight calculation module, configured to divide the coordinate points on the circumference into several adjacent point clusters, and calculate the weight of each adjacent point cluster according to the weights of each coordinate point in the adjacent point cluster; wherein, each adjacent point cluster includes directly adjacent coordinate points and indirectly adjacent coordinate points; the directly adjacent coordinate points represent two adjacent coordinate points whose distance from each other is less than a distance threshold; the indirectly adjacent coordinate points represent a pair of points formed by two coordinate points that do not belong to a directly adjacent relationship, but through the direct adjacent relationship of the two coordinate points and at least one intermediate point; A detection module, configured to determine whether the current login event is an abnormal login by comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold.

[0010] An abnormal login detection method and device based on a time circular coordinate system provided by the present invention can automatically learn the time pattern of normal logins and automatically detect abnormal logins without manually configuring any rules; it does not involve any complex machine learning algorithms, has a small amount of calculation and low performance overhead; the result is highly interpretable, and it can visually present why a login event is a normal login or an abnormal login through the time circular coordinate system; a historical login event expiration mechanism is designed, which can gradually adapt to the changes in the login pattern of the same host and the same login service over time. Description of the Drawings

[0011] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives and advantages of the present application will become more obvious: Figure 1 is a flowchart of an abnormal login detection method based on a time circular coordinate system provided by an embodiment of the present application; Figure 2 is a schematic diagram of a time circular coordinate system provided by an embodiment of the present application; Figure 3 is a schematic diagram of an adjacent point cluster provided by an embodiment of the present application; Figure 4 is a curve showing the change of the weight of a login event with the occurrence time of the login event provided by an embodiment of the present application; Figures 5 - 9 It is a schematic diagram of the time circular coordinate system provided by another embodiment of the present application in the entire abnormal login detection process; Figure 10 It is a schematic structural diagram of an abnormal login detection device based on the time circular coordinate system provided by another embodiment of the present application. Detailed implementation manners

[0012] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0013] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "said", and "the" used in the embodiments of the present invention are also intended to include the plural forms unless the context clearly indicates otherwise.

[0014] It should be understood that although the terms first, second, third, etc. may be used to describe the acquisition modules in the embodiments of the present invention, these acquisition modules should not be limited to these terms. These terms are only used to distinguish the acquisition modules from each other.

[0015] Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".

[0016] It should be noted that the orientation words such as "upper", "lower", "left", and "right" described in the embodiments of the present invention are described from the angles shown in the drawings and should not be construed as limiting the embodiments of the present invention. In addition, in the context, it should also be understood that when it is mentioned that an element is formed "on" or "under" another element, it can not only be directly formed "on" or "under" another element, but also be indirectly formed "on" or "under" another element through an intermediate element.

[0017] An embodiment of the present application provides an abnormal login detection method based on a time circular coordinate system, which is applicable but not limited to solving technical problems in the following scenarios: there are many login events of the same account on the same host from the same source IP address. These login events only differ in login time, and other fields are the same. Technical personnel need to automatically discover abnormal logins in these login events by learning the time rules of login events through algorithms without relying on manually configured detection rules.

[0018] See Figure 1 , the abnormal login detection method based on the time circular coordinate system in this embodiment includes the following steps: Step S101, collect historical login events of the target host, and extract the login time of each historical login event to form a historical login time sequence.

[0019] Specifically, we deploy an agent on the computer where abnormal login needs to be detected. This agent has the functions of parsing existing login logs to obtain historical login events and monitoring new login logs to obtain the latest login events in real time. The agent can collect login logs of failed logins and can also collect login logs of successful logins. However, this embodiment only focuses on login logs of successful logins. Login logs of failed logins are usually concerned by brute-force cracking detection algorithms. Since this embodiment only focuses on the login time field in login events, theoretically any login event with a login time field can be used as the input of this embodiment. However, from the design intention of this embodiment, when the algorithm runs in the Windows system, the agent should at least support parsing Remote Desktop (RDP) login logs, and when the algorithm runs in the Linux system, the agent should at least support parsing SSH login logs. After deploying the agent, group the obtained historical login events and the latest login events obtained by subsequent real-time monitoring according to fields such as login source IP address and login account name. For each group of login events, except for the login time field, the other fields are the same. This group of login events can extract the login time, which is represented as a login time sequence t1, t2, t3,..., tn. Each item in the sequence is the login time of a login event, and the unit can be accurate to seconds. For each generated login event, a new item will be added to the login time sequence of the corresponding group (grouped according to fields such as login source IP address and login account name).

[0020] Step S102, mark the historical login time sequence as several coordinate points on the time circular coordinate system. The coordinate points on the time circular coordinate system are distributed on the circumference in sequence. The length of the circumference represents the time period for measuring user login activities. The scale value of the coordinate point on the circumference represents the user login time, and the arrangement order of the coordinate points on the circumference represents the direction of time passing.

[0021] Since network maintenance personnel generally work on a weekly cycle, the time circular coordinate system in this embodiment is described by taking the week circular coordinate system as an example. However, the adaptation period of the circular coordinate system can also be years, months, days, etc., which can be adjusted according to the specific working scenario. The subsequent algorithm will learn the time pattern of normal logins with the help of this time circular coordinate system.

[0022] Exemplarily, draw a circle on a plane, divide the circumference into seven equal parts, and sequentially label each arc segment as Monday, Tuesday, Wednesday, Thursday, Friday, Saturday, and Sunday. Then divide each arc segment of the seven-equal-part circumference into 86,400 equal parts (i.e., 60x60x24, the number of seconds in a day), and each small equal-part arc segment represents a time duration of 1 second. In this way, a week circular coordinate system accurate to the second is formed.

[0023] Any login time in the historical login time series can be marked on the week circular coordinate system. For example: Mark the login time "Monday 20:45:12" on the week circular coordinate system, and the effect is as Figure 2 shown (due to the drawing accuracy problem, Figure 2 only the week equal-points, that is, 00:00:00 of each day, are marked on the scale in Figure 2 . For easy understanding,

[0024] From Figure 2 it can also be seen that in the week circular coordinate system, there are two arcs that can connect any two points. In this embodiment, the length of the shorter arc among these two arcs is defined as the distance between these two points, and the distance between two points represents a time length. The length of the entire circumference represents the time period for measuring user login activities. In the week circular coordinate system, the circumference length is 1 week.

[0025] From Figure 2 it can also be found that compared with other coordinate systems expressing time, the week circular coordinate system designed in this embodiment can better reflect the time in the real world: (1) The distance between the times (coordinate points) in the week circular coordinate system is consistent with real-world experience. For example: The time distance from 00:00:00 on Sunday to 00:00:00 on Monday is equal to the time distance from 00:00:0 on Monday to 00:00:00 on Tuesday. If 1, 2,..., 7 represent Monday, Tuesday,..., Sunday respectively on a traditional number line, then the distance between Sunday and Monday on the number line will be very far, which is inconsistent with real-world experience.

[0026] (2) In the week circular coordinate system, the continuity between times is consistent with real-world experience. For example, the distance between 23:59:59 on Sunday and 00:00:00 on Monday is a small arc segment of equal division, that is, 1 second, and the two coordinate points are adjacent. If in a plane rectangular coordinate system, the X-axis represents the week, where 1, 2, ..., 7 represent Monday, Tuesday, ..., Sunday respectively, and the Y-axis represents the time of a day, with a value range from 0 to 86400 - 1 (i.e., the time scale unit is seconds), then the distance between 23:59:59 on Sunday and 00:00:00 on Monday will be very far, which is inconsistent with real-world experience.

[0027] From Figure 2 It can also be seen that the coordinate points on the week circular coordinate system are distributed on the circumference in chronological order. Therefore, the arrangement order of the coordinate points on the circumference represents the direction of time flow.

[0028] Step S103: Divide the coordinate points on the circumference into several adjacent point clusters, and calculate the weight of each adjacent point cluster according to the weight of each coordinate point within the adjacent point cluster; where each adjacent point cluster includes directly adjacent coordinate points and indirectly adjacent coordinate points; the directly adjacent coordinate points represent two adjacent coordinate points whose distance between each other is less than the distance threshold; the indirectly adjacent coordinate points represent a pair of points where the two coordinate points are not in a directly adjacent relationship, but are formed by the direct adjacent relationship between the two coordinate points and at least one intermediate point.

[0029] This embodiment introduces the concept of adjacent point clusters. We set the farthest adjacent distance threshold to t, then the following relationships hold in the week circular coordinate system: (1) If the distance between A and B is less than or equal to t, then A and B are considered directly adjacent; (2) If A and B are directly adjacent, B and C are directly adjacent, and A and C are not directly adjacent, then A and C are considered indirectly adjacent; (3) If A and B are indirectly adjacent, B and C are indirectly adjacent, and A and C are not directly adjacent, then A and C are considered indirectly adjacent; (4) If there are N points, and any two points among these N points are directly adjacent or indirectly adjacent, then these N points form an adjacent point cluster.

[0030] (5) If the distance between A and other points is greater than t, then A itself forms an adjacent point cluster that contains only one point.

[0031] Figure 3 are some schematic diagrams of adjacent point clusters in the week circular coordinate system. The coordinate points represented by triangles and the punctuation points represented by circles respectively form two adjacent point clusters.

[0032] In addition, it is easy to see from the adjacent point clusters that the points in the week circular coordinate system always form several adjacent point clusters, and a certain point in the week circular coordinate system must belong to and only belong to a certain adjacent point cluster.

[0033] Furthermore, the more recent the login event in time, the greater the help for determining whether the current login event is a normal login or an abnormal login. To give an extreme and intuitive example, a login event that occurred a very long time ago, such as a certain login event more than 1 year ago, has almost no meaning for determining the current login event. Therefore, this embodiment introduces a login event weight, and defines a basic weight for each login event , and the initial value can be 1. The basic weight may change under certain conditions. For example, if manual verification confirms that a certain login event is a normal login event, the basic weight will be increased.

[0034] Next, this embodiment will introduce how to determine the weight of each coordinate point within the adjacent point cluster .

[0035] This embodiment defines a constant k representing a period of time, with a default value of 4 weeks. According to the practical experience of some real-world scenarios, it is found that within 2 times of k, that is, within 8 weeks, the login events have strong reference value for the current normal login. Within this time range, the weight should remain unchanged. Between 2 times of k and 4 times of k, that is, between 8 weeks ago and 16 weeks, the login events have a certain reference value for the current normal login pattern, but the farther back in time, the smaller the reference value. Beyond 4 times of k, that is, the login events 16 weeks ago, are already too far back and have no reference value for the current normal login pattern. If such a long-term login event is still referred to, it will instead lead to the omission of some abnormal login events. This embodiment needs to design a function formula, or rather, find a function curve, that can express the variation law of the weight with time.

[0036] Specifically, this embodiment sets the login time of a login event to be , the current time to be , is the default initial weight, with an initial default value of 1, is the current time when the login event (i.e., the th coordinate point in the coordinate system) has a weight. For the sake of convenient description, we let: represents how long ago the login event occurred. Obviously, has a value range of [0, +∞).

[0037] Next, let: represent the decrease in the weight of the login event over time (i.e., as increases). Obviously, should have a value range of [0, 1]. When is 1, it means there is no decrease in weight. When is 0, it means the weight has decreased to 0. The goal of this embodiment is to find a function such that when , varies with in accordance with the requirements of this embodiment.

[0038] has a value range of [0, 1]. It is easy to think that the function should be a fractional function where the numerator is never greater than the denominator. When is 0, the numerator and denominator are the same, and is 1.

[0039] The simplest fractional function is: The default value of is 4 weeks. However, for the convenience of discussion, in this embodiment, when plotting the function graph, can be set to 1 to observe the degree of weight decrease when is several times k. When is 1, although it meets the condition that has a value range of [0, 1] (when is greater than 0), there are two problems: First, is never 0, that is: when is very large, only approaches 0 but is not 0; Second, the function curve drops too fast at the beginning. However, in this embodiment, when is relatively small, the value of

[0040] Regarding the first problem, since , if we want to be 0 after is greater than a specific value, we have to make be 0 after is greater than a specific value. Since making greater than a specific value causes It is very difficult to keep it equal to 0. In this embodiment, we take the second best option and stipulate that if is less than 0, then is equal to 0, which can be expressed as: Therefore, as long as you ensure When it is greater than 0 and less than a specific value, The value of is in [0, 1]; When it is equal to a certain value, is equal to 0; When it is greater than a certain value, Less than 0.

[0041] It is a fractional function, the denominator cannot be 0. is equal to 0, we can only make the numerator equal to 0. for: In the above formula, the numerator is a constant, so we only need to adjust the numerator to , we can achieve equal hour, is 0, when Greater than hour, Less than 0. It becomes: Since this embodiment expects More than 4 times The weight drops to 0 only when After this adjustment, when When it is 0, It is 4, not satisfied The condition is 1. Therefore, the synchronous adjustment denominator is .

[0042] so It becomes: The value range of the above function meets the requirements of this embodiment, but the shape of the function curve still does not meet the requirements, because the above function drops too fast at the beginning, and further adjustment is needed. The above function drops too fast at the beginning because: When it increases, the numerator decreases and the denominator increases. The value of drops rapidly. This embodiment should try to make When starting to increase from 0, the numerator does not decrease quickly at first, and the denominator does not increase quickly at first.

[0043] Therefore, in this embodiment, for the current perform an algebraic transformation by dividing both the numerator and denominator by : For the above formula, in this embodiment, it is necessary to ensure that when is relatively small, the function decreases slowly, and when is relatively large, the function decreases rapidly. Therefore, this embodiment mainly considers when the value range is [0, , the shape of the function curve, within this value range, the value range of is [0, 1]. In addition, it is easy to think of the curve of a quadratic function. When is relatively small (close to 0), the growth is slow. As further increases, the growth rate of the curve becomes faster and faster. Therefore, consider adding a quadratic power to both in the numerator and denominator of , so that becomes: The decrease rate of the above function curve has significantly slowed down, but it is still not slow enough for the ultimate goal of this embodiment. As is well known, the fourth power of 0.1 is smaller than the second power of 0.1. Therefore, the larger the power, the slower the growth starts from 0. Therefore, try changing the quadratic power to the fourth power again, The decrease rate of the above function curve has significantly slowed down, but there is an obvious decrease when is approximately equal to 1. This embodiment hopes to have an obvious decrease when is approximately equal to 2. Therefore, try changing the fourth power to the eighth power again, The curve of the above function very much meets the requirements of this embodiment, and there is an obvious decrease only when is approximately equal to 2. Then perform an algebraic transformation on the above by multiplying both the numerator and denominator by , and the following function is obtained: = = Since it can be known from the above reasoning that: We substitute into the above formula and get: Since it can be known from the above reasoning that: Thus, it is obtained that: Since it can be known from the above reasoning that: Thus, it is obtained that: Performing algebraic transformation on the above formula, the final weight calculation formula is obtained: Among them, represents the basic weight of the th coordinate point (login event ); represents the shortest learning time constant, which is used to represent weeks of time; represents the current time; represents the th coordinate point (login event ) corresponding login time; Furthermore, we need to meet certain preconditions before starting to detect abnormal logins, so as to obtain more accurate judgment results. This is because the process of calculating the weight of the adjacent point cluster is actually the process of the algorithm learning the login rules of historical login events. If the learning time of the login rules is too short, for example: three login events occurred between 9 am and 12 pm on Wednesday in a random week, these three events may be normal logins by chance. Since the oldest login event is only one week, the above accidental events are easily misrecognized as the rules of normal logins, which will lead to deviations in the judgment of abnormal logins, that is: misrecognizing abnormal logins in the above time period as normal logins. Therefore, in this embodiment, it is more preferable to set a shortest learning time constant , that is, in the coordinate point weight formula. After learning for the shortest learning duration, the detection of abnormal logins will start.

[0044] When the basic weight is 1 and is 1, the curve graph of the weight of the coordinate point changing with (that is, how long ago the login event occurred) is as shown in Figure 4 . It can be seen from Figure 4 that when is relatively small (less than 2 At this time, the weight of the coordinate point is almost equal to , indicating that the closer login events have higher weights. As further increases (greater than 2 and less than 4 at this time), the weight of the coordinate point gradually decreases, indicating that the farther login events have lower weights. When further increases (greater than 4 at this time), the weight of the coordinate point drops to 0, indicating that very distant login events are no longer considered.

[0045] Furthermore, by summing the weights of each coordinate point within the adjacent point cluster, the weight of the adjacent point cluster can be obtained.

[0046] Furthermore, the preferred value of the shortest learning time constant in this embodiment is 4, that is, 4 weeks. It can also be seen from the weight calculation formula that when is 4: (1) Twice of 4 weeks, that is, 56 days, the weights of login events within approximately 2 months basically remain unchanged; (2) Four times of 4 weeks, that is, 112 days, the weights of login events within approximately 4 months gradually decrease; (3) Four times of 4 weeks, that is, 112 days, the weights of login events before approximately 4 months drop to 0 and are no longer considered.

[0047] Furthermore, the distance threshold for determining whether the coordinate points are directly adjacent is preferably 30 minutes, that is, two login events within a distance of 30 minutes are considered directly adjacent, and the adjacent point cluster obtained in this way can bring more accurate abnormal login recognition results.

[0048] Step S104, by comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold, determine whether the current login event is an abnormal login.

[0049] Specifically, if the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system is greater than the preset weight threshold, it indicates that there are a large number of login events during this adjacent time period, which is very likely the normal login behavior and login pattern of network maintenance engineers. At this time, it is determined that the current login event is a normal login; if the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system is less than or equal to the preset weight threshold, it indicates that there are fewer login events during this adjacent time period, that is, the staff rarely log in to the host during this adjacent time period. Then the current login event is more likely to be an abnormal login.

[0050] More preferably, in this embodiment, the weight threshold w of the adjacent node cluster is set to 4. The greater the weight of an adjacent node cluster, the more recent login events there are, and the more likely it is a normal login; conversely, the smaller the weight of an adjacent node cluster, the fewer recent login events there are, and the more likely it is an abnormal login. Setting the weight threshold to 4 in this embodiment can obtain a more accurate recognition result of abnormal logins.

[0051] Further, before determining whether the current login event is an abnormal login, it further includes: if the current time is greater than the interval time from the earliest login time corresponding to the coordinate point on the time circular coordinate system by a certain number of weeks, enter the detection mode to determine whether the current login event is an abnormal login; otherwise, enter the learning mode and do not make a judgment on whether the current login event is an abnormal login.

[0052] Even further, based on the historical login events, after a new login event occurs, mark the new login time corresponding to the new login event as a new coordinate point on the time circular coordinate system; if the current is the learning mode, then determine whether the interval time between the current time and the earliest login time corresponding to the coordinate point on the time circular coordinate system is greater than a certain number of weeks. If so, it means that enough time has been spent learning and the detection mode can be entered; otherwise, continue with the learning mode; after entering the detection mode, traverse the login times corresponding to each coordinate point in the time circular coordinate system, and then combine the current time to update the weight of each coordinate point according to the coordinate point weight formula . If the weight of a certain coordinate point is 0, then delete the coordinate point from the time circular coordinate system; calculate the weight of the adjacent node cluster where the new coordinate point is located. If the weight of this adjacent node cluster is greater than the preset weight threshold, then determine that the new login event is a normal login; otherwise, it is an abnormal login.

[0053] Even further, if the algorithm identifies an abnormal login, an abnormal event alarm is generated. After that, this algorithm receives the manual verification result. After receiving the manual verification result of an abnormal login event, the following process is carried out: If the manual verification result is "false alarm", then retain the coordinate point (i.e., the login time) corresponding to this login event in the week circular coordinate system and adjust the basic weight of the coordinate point ; if the manual verification result is "confirmed as an abnormal login event", then directly delete the coordinate point corresponding to this abnormal event from the week circular coordinate system.

[0054] See Figure 5 the following for introducing the entire recognition process of abnormal logins through a specific embodiment: Suppose the proxy required by this algorithm is deployed on a Windows server. After the proxy is deployed, the historical login logs are read and parsed, and 10 login events are obtained. In the real world, the source IP addresses and account names of login events on a single host usually do not be exactly the same. It is necessary to group them by source IP address and account name first. For simplicity in this embodiment, it is assumed that the source IP addresses and account names of these login events are all the same, and it is assumed that the oldest login event occurred 3 weeks ago.

[0055] The algorithm constants take the following values: Shortest learning time constant : 4 weeks. That is, at least learn the login time pattern for 4 weeks before starting to detect abnormal logins.

[0056] Coordinate point distance threshold t: 30 minutes. When calculating the adjacent point cluster, two login events within 30 minutes are considered directly adjacent.

[0057] Adjacent point cluster weight threshold w: 4. The weight of the adjacent point cluster where the new login event is located needs to be greater than or equal to 4 to be considered a normal login.

[0058] The specific process is as follows: After parsing the existing historical login events, these historical login events need to be marked on a one-week circular coordinate system. When marking, calculate the weight of each login event (i.e., the coordinate point weight). Assuming that the weights are all greater than 0, so no login events will be deleted, and all 10 login events will be marked on the one-week circular coordinate system, as Figure 5 shown.

[0059] Since the oldest event occurred 3 weeks ago, which is less than 4 weeks (the shortest learning time constant ). To avoid generating too many false alarms, detection is not started for the time being, and the current state is the learning mode. The learning mode will be maintained for the next week. Assuming that 2 more login events are generated during this week, they will also be marked on the one-week circular coordinate system, and the result is as Figure 6 shown (the solid triangle symbols in the figure represent the newly added login events).

[0060] After learning for 4 weeks, any newly generated login events will trigger a change in the mode, that is: switching from the learning mode to the detection mode. In the detection mode, it will be detected whether the new login event is an abnormal login. Suppose a new login event is generated and marked on the one-week circular coordinate system, represented by a solid triangle symbol. Traverse all points in the one-week circular coordinate system, calculate the weight of each point, and find that they are all greater than 0, so no points are deleted. Calculate the adjacent point cluster where the new login event is located, represented by a dotted box. The result is as Figure 7 shown.

[0061] Calculate the weight of the adjacent node cluster where the new login event is located. Assume the result is 4.5 (there are 5 points in the adjacent node cluster, but as time goes by, the weights of some points have decreased and are less than 1). Since it is greater than the weight threshold of 3, this login event is a normal login, not an abnormal login.

[0062] Suppose there is a new login event, which is marked in the week circular coordinate system and represented by a solid triangle symbol. Traverse all the points in the week circular coordinate system, calculate the weight of each point, and find a login event on Friday. Since the event is too old, its weight has dropped to 0, so it is deleted and represented by a dashed triangle. Calculate the adjacent node cluster where the new login event is located, which is represented by a dashed box. The result is as Figure 8 shown.

[0063] Calculate the weight of the adjacent node cluster where the new login event is located. Assume the result is 2, which is less than the weight threshold of 3. So this login event is an abnormal login. An abnormal login warning will be generated. After manual verification, it is confirmed that the above login event is indeed an abnormal login, and this login event is deleted from the week circular coordinate system. After deleting the expired login events and abnormal login events, the week circular coordinate system is as Figure 9 shown.

[0064] See Figure 10 , another embodiment of the present invention also provides an abnormal login detection device 200 based on a time circular coordinate system, including a data acquisition module 201, a marking module 202, a weight calculation module 203, and a detection module 204. This device 200 can execute the abnormal login detection method based on the time circular coordinate system in the method embodiment.

[0065] Specifically, the abnormal login detection device 200 based on the time circular coordinate system includes: A data acquisition module 201, configured to collect historical login events of a target host and extract the login time of each historical login event to form a historical login time series; A marking module 202, configured to mark the historical login time series as several coordinate points on the time circular coordinate system. The coordinate points on the time circular coordinate system are distributed on the circumference in sequence. The circumference length represents the time period for measuring user login activities. The scale value of the coordinate points on the circumference represents the user login time, and the arrangement order of the coordinate points on the circumference represents the direction of time passage; The weight calculation module 203 is configured to divide the coordinate points on the circumference into several adjacent point clusters, and calculate the weight of each adjacent point cluster according to the weights of each coordinate point within the adjacent point cluster; wherein, each adjacent point cluster includes directly adjacent coordinate points and indirectly adjacent coordinate points; the directly adjacent coordinate points represent two adjacent coordinate points whose distance from each other is less than the distance threshold; the indirectly adjacent coordinate points represent a pair of points formed by two coordinate points that do not belong to the directly adjacent relationship, but through the direct adjacent relationship between the two coordinate points and at least one intermediate point. The detection module 204 is configured to determine whether the current login event is an abnormal login by comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold.

[0066] It should be noted that the technical solution of the abnormal login detection device 200 based on the time circular coordinate system provided in this embodiment can be used to execute the technical solutions of the method embodiments. The implementation principle and technical effects are similar to those of the method, and will not be elaborated here.

[0067] The above description is only a preferred embodiment of the present invention. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solution formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present invention.

Claims

1. An abnormal login detection method based on a time circular coordinate system, characterized in that, Including the following steps: Collect historical login events of the target host, and extract the login time of each historical login event to form a historical login time series; Mark the historical login time series as several coordinate points on a time circular coordinate system. The coordinate points on the time circular coordinate system are distributed on the circumference in sequence. The length of the circumference represents the time period for measuring user login activities. The scale value of the coordinate points on the circumference represents the user login time, and the arrangement order of the coordinate points on the circumference represents the direction of time passage; Divide the coordinate points on the circumference into several adjacent point clusters, and calculate the weight of each adjacent point cluster according to the weights of each coordinate point in the adjacent point cluster. Wherein, each adjacent point cluster includes directly adjacent coordinate points and indirectly adjacent coordinate points; The directly adjacent coordinate points represent two adjacent coordinate points whose distance from each other is less than the distance threshold; The indirectly adjacent coordinate points represent a pair of points formed by two coordinate points that do not belong to the directly adjacent relationship, but through the directly adjacent relationship between the two coordinate points and at least one intermediate point; By comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold, determine whether the current login event is an abnormal login.

2. The abnormal login detection method based on a time circular coordinate system according to claim 1, wherein The step of calculating the weight of each adjacent point cluster according to the weights of each coordinate point in the adjacent point cluster includes: Calculate the weights of each coordinate point within the adjacent point cluster according to the following formula :[[]]END]] Among them, represents the basic weight of the th coordinate point; represents the shortest learning time constant; represents the current time; represents the login time corresponding to the th coordinate point; Sum the weights of each coordinate point within the adjacent point cluster to obtain the weight of the adjacent point cluster.

3. The anomaly login detection method based on a time circular coordinate system according to claim 2, wherein The step of determining whether the current login event is an abnormal login by comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold includes: If the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system is greater than the preset weight threshold, determine that the current login event is a normal login, otherwise it is an abnormal login.

4. The anomaly login detection method based on a time circular coordinate system according to claim 3, wherein, Before determining whether the current login event is an abnormal login, it also includes: If the current time has an interval time greater than the time corresponding to times the circumference length from the earliest login time corresponding to the coordinate point on the time circular coordinate system, then enter the detection mode to determine whether the current login event is an abnormal login; otherwise, enter the learning mode and do not make a judgment on whether the current login event is an abnormal login.

5. The anomaly login detection method based on a time circular coordinate system according to claim 4, characterized in that It also includes: When a new login event occurs, mark the new login time corresponding to the new login event as a new coordinate point on the time circular coordinate system; If the current is the learning mode, then judge the current time whether the interval time from the earliest login time corresponding to the coordinate point on the time circular coordinate system is greater than the time corresponding to times the circumference length. If so, enter the detection mode; otherwise, continue the learning mode; After entering the detection mode, traverse the login times corresponding to each coordinate point in the time circular coordinate system, and then combine with the current time , update the weight of each coordinate point , if the weight of a certain coordinate point is 0, then delete this coordinate point from the time circular coordinate system; Calculate the weight of the adjacent point cluster where the new coordinate point is located. If the weight of the adjacent point cluster is greater than the preset weight threshold, determine that the new login event is a normal login, otherwise it is an abnormal login.

6. An abnormal login detection device based on a time circular coordinate system, characterized in that, Including: A data collection module, configured to collect historical login events of the target host, and extract the login time of each historical login event to form a historical login time series; A marking module, configured to mark the historical login time series as several coordinate points on a time circular coordinate system. The coordinate points on the time circular coordinate system are distributed on the circumference in sequence. The length of the circumference represents the time period for measuring user login activities. The scale value of the coordinate points on the circumference represents the user login time, and the arrangement order of the coordinate points on the circumference represents the direction of time passage; The weight calculation module is configured to divide the coordinate points on the circumference into several adjacent point clusters, and calculate the weight of each adjacent point cluster according to the weights of each coordinate point within the adjacent point cluster; wherein, each adjacent point cluster includes directly adjacent coordinate points and indirectly adjacent coordinate points; the directly adjacent coordinate points represent two adjacent coordinate points whose distance from each other is less than the distance threshold; the indirectly adjacent coordinate points represent a pair of points formed by two coordinate points that are not in a directly adjacent relationship, but through the direct adjacent relationship between the two coordinate points and at least one intermediate point. The detection module is configured to determine whether the current login event is an abnormal login by comparing the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system with a preset weight threshold.

7. An abnormal login detection device based on a time circular coordinate system according to claim 6, characterized in that, The weight calculation module is further configured to: Calculate the weight of each coordinate point within the adjacent point cluster according to the following formula :[[]]END]] Among them, represents the basic weight of the th coordinate point; represents the shortest learning time constant; represents the current time; represents the th login time corresponding to the coordinate point; Sum the weights of each coordinate point within the adjacent point cluster to obtain the weight of the adjacent point cluster.

8. An abnormal login detection device based on a time circular coordinate system according to claim 7, characterized in that The detection module is further configured to: If the weight of the adjacent point cluster where the coordinate point of the current login event is located on the time circular coordinate system is greater than the preset weight threshold, it is determined that the current login event is a normal login; otherwise, it is an abnormal login.

9. The anomaly login detection device based on a time circular coordinate system according to claim 8, wherein, It further includes: A mode switching module, configured to enter a detection mode to determine whether the current login event is an abnormal login if the interval time between the current time and the earliest login time corresponding to the coordinate point on the time circular coordinate system is greater than the time corresponding to times the circumference length; Otherwise, enter the learning mode and do not make a judgment on whether the current login event is an abnormal login.

10. The abnormal login detection device based on the time circular coordinate system according to claim 9, characterized in that: The marking module is further configured to: when a new login event occurs, mark the new login time corresponding to the new login event as a new coordinate point on the time circular coordinate system; The mode switching module is further configured to: if the current mode is the learning mode, then determine the current time Whether the interval time from the earliest login time corresponding to the coordinate point on the time circular coordinate system is greater than The time corresponding to times the circumference length, if so, enter the detection mode, otherwise continue with the learning mode; The weight calculation module is further configured to: after entering the detection mode, traverse the login time corresponding to each coordinate point in the time circular coordinate system, and then combine the current time , and update the weight of each coordinate point . If the weight of a certain coordinate point is 0, then delete the coordinate point from the time circular coordinate system; calculate the weight of the adjacent point cluster where the new coordinate point is located; The detection module is further configured to: if the weight of the adjacent point cluster is greater than the preset weight threshold, it is determined that the new login event is a normal login; otherwise, it is an abnormal login.

Citation Information

Patent Citations

  • Method and device for detecting user behavior

    CN107770129A

  • Data detection method and device, electronic equipment and medium

    CN113312239A

  • Abnormal analysis method and device for user login behavior and electronic equipment

    CN119557861A

  • Abnormal login detection method and device, equipment and storage medium

    CN120050110A

  • Machine learning for anomaly detection based on logon events

    US20230275915A1