Abnormal behavior risk early warning system, method and equipment based on autonomous learning

Through the autonomous learning abnormal behavior risk warning system, independent subsets are divided based on user business attributes and scale, and the behavior baseline is dynamically updated, solving the problem of abnormal behavior detection at user terminals and achieving efficient and accurate risk warning.

CN120342789AActive Publication Date: 2025-07-18CHINA TOWER CO LTD

Patent Information

Application Number
CN202510819616.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-18
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

The prior art is difficult to detect abnormal behavior of user terminals through unified standards, and the lack of hierarchical classification of user terminals, resulting in cumbersome management and detection process and lack of representativeness in standard settings.

Method used

Through an autonomous learning abnormal behavior risk warning system, user terminal behavior is recorded, independent subsets are divided and permissions are set, similar users are classified into the same category using cosine similarity, dynamically update behavior baselines, and comprehensive behavior detection is carried out.

Benefits of technology

It improves the data magnitude of machine learning, reduces the consumption of computing power resources, realizes accurate detection and efficient risk warning of user behavior, and improves the accuracy and practicality of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342789A_ABST
    Figure CN120342789A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and provides an abnormal behavior risk early warning system, method and device based on autonomous learning and a storage medium, and the system comprises a log recording module which is used for recording behaviors and behavior information of a user terminal to generate a log file; the data storage module is used for storing log files; the user classification module is used for acquiring text information of different types of users, calculating business similarity, creating independent subsets, setting permissions and determining behavior baselines of the independent subsets; the log analysis module is used for analyzing the log file corresponding to each independent subset to obtain a data form, and associating the data form with a corresponding behavior baseline; the abnormal behavior judgment module is used for obtaining an association result and comparing to determine an abnormal behavior; and the early warning processing module is used for acquiring abnormal behaviors and performing early warning processing. According to the invention, through user classification, multi-scene behavior detection and behavior baseline setting, accurate monitoring and efficient abnormity early warning of user behaviors are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and particularly relates to an abnormal behavior risk early warning system, method, device and storage medium based on autonomous learning. Background Art

[0002] With the rapid development of technology, especially the progress in fields such as big data processing, cloud computing, data mining and machine learning, the detection and early warning of abnormal behaviors have become a research hotspot. Especially in the real world, the timely early warning and effective response to abnormal behaviors such as violence and lawbreaking are of great significance for maintaining social security and stability.

[0003] In the digital age, the security and compliance of resource access have become the focus of attention for organizations such as enterprises and government agencies. The abnormal behavior risk early warning system can identify and early warn risks such as unauthorized access, malicious downloads, and data leaks, thereby ensuring the legitimate use of resources and the stable operation of the system.

[0004] Traditional network security defense methods mainly rely on tools such as firewalls, anti-virus software and intrusion detection systems. These tools usually detect threats based on known attack signatures or rules, but lack sufficient detection means for legitimate user behaviors, and the diversification of malicious behaviors increases the privacy problem of data leaks.

[0005] The difficulties in abnormal behavior detection are as follows: The abnormal behaviors are diverse, and it is difficult to thoroughly check abnormal behaviors through manually set behavior patterns for detection. It is difficult to set the standards for abnormal behavior detection. Each user terminal has its own usage habits, and it is impossible to formulate a unified standard to track and detect user behaviors. The data volume of a single user is limited, and it is difficult to determine the behavior patterns and characteristics of the corresponding user through the machine learning of a single user. There is a lack of classification of user terminals, and it is difficult to perform machine learning on the classified user data sets together, making the management and detection process cumbersome and the standard setting lack representativeness. Summary of the Invention

[0006] In view of the problems mentioned in the above background art, the present invention provides an abnormal behavior risk early warning system, method, device and storage medium based on autonomous learning.

[0007] An abnormal behavior risk early warning system based on autonomous learning of the present invention, the system includes: A log recording module, configured to record the behaviors and behavior information of user terminals in real time and generate log files; A data storage module, configured to store the log files; A user classification module, which is used to obtain text information of different types of users, calculate business similarity, create independent subsets based on the business similarity and set permissions; determine the behavior baselines of each of the independent subsets according to the log file; A log parsing module, which is used to parse the log files corresponding to each of the independent subsets to obtain data forms, and associate each of the independent subsets with the corresponding behavior baselines; An abnormal behavior judgment module, which is used to obtain the association results, compare and judge to determine abnormal behaviors; An early warning processing module, which is used to obtain the abnormal behaviors and perform early warning processing.

[0008] Furthermore, the user classification module specifically includes: An acquisition unit, which is used to acquire text information of different types of users; the text information includes the function scope, administrative level and number of employees of government users, the industry business scope, asset scale and personnel scale of enterprise users, and the occupations and skill attributes of individual users; A conversion unit, which is used to process and convert the text information to obtain numerical vectors; A calculation unit, which is used to divide the numerical vectors of different users based on scale feature words and attribute feature words to obtain feature vectors of different users, and calculate business similarity; A creation unit, which is used to create independent subsets according to a preset threshold and the business similarity, and set access permissions, API interface call ranges and normal operation behaviors for each of the independent subsets; A determination unit, which is used to determine the behavior baselines of each of the independent subsets according to the log file and perform dynamic updates.

[0009] Furthermore, the log parsing module specifically includes: A parsing unit, which is used to parse the log files generated by user behaviors in each of the independent subsets to obtain data forms of key-value pair information; An association unit, which is used to associate each of the independent subsets with the corresponding behavior baselines.

[0010] The present invention also provides a method for early warning of abnormal behavior risks based on autonomous learning, and the method includes: Record the behaviors and behavior information of the user terminal in real time to generate a log file; Obtain text information of different types of users and calculate business similarity, create independent subsets based on the business similarity and set permissions; determine the behavior baselines of each of the independent subsets according to the log file; Parse the log files corresponding to each of the independent subsets to obtain data forms, and associate each of the independent subsets with the corresponding behavior baselines; Obtain the association results, compare and judge them, and determine abnormal behaviors; Obtain the abnormal behaviors and perform early warning processing.

[0011] Further, the log files are stored in a data storage module.

[0012] Further, the behaviors include login behaviors, access behaviors, and operation behaviors; the behavior information includes the login status, IP address, operation behavior, number of operations, operation time, traffic volume, and behavior object of the behavior subject.

[0013] Further, obtaining the text information of different types of users and calculating the business similarity, creating independent subsets based on the business similarity and setting permissions; according to the log files, determining the behavior baselines of each of the independent subsets, specifically including: Obtain the text information of different types of users; the text information includes the function scope, administrative level, and number of employees of government users, the industry business scope, asset scale, and number of personnel of enterprise users, and the occupation and skill attributes of individual users; Process and transform the text information to obtain numerical vectors; Based on the scale feature words and attribute feature words, divide the numerical vectors of different users to obtain the feature vectors corresponding to different users, and calculate the business similarity; According to the preset threshold and the business similarity, create independent subsets, and set the access permissions, API interface call ranges, and normal operation behaviors of each of the independent subsets; According to the log files, determine the behavior baselines of each of the independent subsets and perform dynamic updates.

[0014] Further, the parsing of the log files corresponding to each of the independent subsets to obtain data forms, and the association of each of the independent subsets with the corresponding behavior baselines specifically includes: Parse the log files generated by user behaviors in each of the independent subsets to obtain data forms of key-value pair information; Associate each of the independent subsets with the corresponding behavior baselines.

[0015] The present invention also provides a device, including a processor, and the processor is coupled with a memory; the processor is used to read and execute the computer program stored in the memory to implement the foregoing method for warning of abnormal behavior risks based on autonomous learning.

[0016] The present invention also provides a computer-readable storage medium storing a program or instructions. When the program or instructions are run on a computer, the computer is caused to execute the foregoing method for early warning of abnormal behavior risks based on autonomous learning.

[0017] Compared with the prior art, the present invention has the following advantages: The present invention provides a system, method, device and storage medium for early warning of abnormal behavior risks based on autonomous learning. A feature vector representing a user is obtained based on user service attributes and service scale, and cosine similarity is used to divide highly similar users into the same independent subset, improving the data magnitude of machine learning. At the same time, there is no need to set a behavior baseline for a single user, reducing the consumption of computing resources. By setting various scenarios for login behavior, access behavior and operation behavior, comprehensive detection of user behavior is achieved. At the same time, the addition of a custom mode enables users to set a matching behavior baseline according to their respective usage scenarios and work characteristics, making the detection of abnormal behavior more accurately meet the actual needs of users, and improving the accuracy and practicality of risk early warning. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a schematic structural diagram of a system for early warning of abnormal behavior risks based on autonomous learning according to the present invention; Figure 2 It is a schematic flow diagram of a method for early warning of abnormal behavior risks based on autonomous learning according to the present invention; Figure 3 It is a schematic structural diagram of an electronic device according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0021] In the description, claims and drawings of the present invention, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a series of steps or methods included do not have to be limited to those clearly listed, but may include other steps or units not clearly listed or inherent to these processes or methods.

[0022] In an embodiment of the present invention, an abnormal behavior risk warning system based on autonomous learning is provided, as Figure 1 shown, the system includes: A log recording module for real-time recording of the behaviors and behavior information of user terminals to generate log files; the behaviors include login behaviors, access behaviors, and operation behaviors; the behavior information includes the login status, IP address, operation behavior, number of operations, operation time, traffic size, and behavior object of the behavior subject.

[0023] In this embodiment, the log recording module performs real-time recording of the login behaviors, access behaviors, and operation behaviors of each user terminal. Among them, the access behavior may include page access, database access, etc.; the operation behavior may include database operations, file transfers such as uploads and downloads, and API interface call behaviors. Among them, API (Application Programming Interface) is a set of defined rules and protocols that allow different software application programs to communicate and interact with each other.

[0024] In this embodiment, the information recorded for each behavior includes the login status, IP address, operation behavior, number of operations, operation time, traffic size, and behavior object of the behavior subject. Among them, the behavior subject is a user with a unique UID; the behavior object includes the content requested for query and retrieval, the content of data operations, and the API interfaces called. Among them, UID (User Identifier) is the "user identifier" or "user ID", which is a number or string used to uniquely identify each user in the system.

[0025] A data storage module for storing the log files.

[0026] A user classification module for obtaining the text information of different users and calculating the business similarity, creating independent subsets based on the business similarity and setting permissions; and determining the behavior baselines of each of the independent subsets according to the log files.

[0027] In this embodiment, the user classification module specifically includes: An acquisition unit, configured to acquire text information of different types of users; the text information includes the functional scope, administrative level, and number of employees of government users, the industry business scope, asset scale, and personnel scale of enterprise users, and the occupations and skill attributes of individual users.

[0028] A conversion unit, configured to process and convert the text information to obtain a numerical vector.

[0029] In this embodiment, the conversion unit processes and converts the text information to obtain a numerical vector, specifically: For the text information, a word segmentation tool is used to perform word segmentation on the text information, and the TF-TDF model is used to convert the word-segmented text entries to obtain a numerical vector. The word segmentation tool can be SnowNLP.

[0030] A calculation unit, configured to divide the numerical vectors of different users based on scale feature words and attribute feature words to obtain feature vectors corresponding to different users, and calculate the business similarity.

[0031] In this embodiment, the calculation unit divides the numerical vectors of different users based on scale feature words and attribute feature words to obtain feature vectors corresponding to different users, and calculates the business similarity, specifically: Based on a certain enterprise user of the same type of users, all numerical vectors related to this enterprise user are distinguished according to business attribute entries and business scale entries. For the business attribute entries, the industry field, business scope, and main products are selected as attribute feature words; for the business scale entries, the number of customers, annual turnover, and number of employees are selected as scale feature words. Among them, corresponding attribute feature words and scale feature words are also defined for government users and individual users respectively.

[0032] The numerical vectors corresponding to the scale feature words and attribute feature words are respectively weighted and summed according to a set ratio to obtain a feature vector representing the characteristics of this enterprise user. Among them, government users or individual users can also obtain their feature vectors in the above manner. It should be noted that the above set ratio can be adjusted according to different types of users.

[0033] In this embodiment, taking enterprise users as an example: in the business scale entries, according to "the number of customers, annual turnover, and number of employees", the weight ratio for evaluating the influence degree of the enterprise user scale is set, which can be set to 3:5:2. For the "industry field, business scope, and main products" in the corresponding business attribute entries, the representative weight ratio of the business attributes can be "2:4:4".

[0034] In the process of weighted summation, the ratio between the business scale entry and the business attribute entry can be 1:1 or other more appropriate ratio allocations, so that the global allocation ratio of the above characteristic words is 1.5:2.5:1:1:2:2.

[0035] Among users of the same type, calculate the cosine similarity between the feature vectors of any two users.

[0036] A creation unit is used to create independent subsets according to a preset threshold and the business similarity, and set the access rights, API interface call ranges, and normal operation behaviors of each of the independent subsets.

[0037] In this embodiment, the creation unit creates independent subsets according to a preset threshold and the business similarity, and sets the access rights, API interface call ranges, and normal operation behaviors of each of the independent subsets. Specifically: When the cosine similarity is greater than the preset threshold, it is considered that the businesses of the two users are highly similar, and an independent subset is created, and the two users are placed in the same subset, so that the businesses of the users in each independent subset are highly similar. It should be noted that subsequent users need to be compared with the cosine similarity of the feature vectors of all users in the subset. When the cosine similarity of the feature vectors of subsequent users is greater than the preset threshold, the user is added to the subset.

[0038] Each of the multiple independent subsets of users of each type is numbered, and the user classification module sets the access rights, API interface call ranges, and normal operation behaviors for independent subsets with different numbers. Among them, the setting principles include: according to the different types of users, different permissions in the same query form are given to them, and government users > enterprise users > individual users. The API interface call range is publicly corresponded according to the business attributes of the users, and the API interfaces between different independent subsets are different. The normal operation behavior is determined according to the access rights and API interface call ranges.

[0039] A determination unit is used to determine the behavior baselines of each of the independent subsets according to the log file and perform dynamic updates.

[0040] In this embodiment, the determination unit determines the behavior baselines of each of the independent subsets according to the log file and performs dynamic updates. Specifically: Learn the historical behaviors of the users in each independent subset to obtain the behavior baselines such as the normal login frequencies and time periods, operation objects and behaviors, and corresponding traffic data conditions of users with similar business attributes, and dynamically update the behavior baselines of the above factors in the independent subset within a certain time period.

[0041] In this embodiment, the behavior baseline is a concentrated representation of the user-related behavior operation data with similar service attributes within a certain set time, and the behavior baseline reflects the data representativeness of the behavior operations corresponding to this type of user.

[0042] For example, the time period can be set to one week or one month, depending on the amount of user behavior occurrence data. Within this time period, if the normal concentrated operation time of a certain type of user occurs from 9:00 am to 12:00 pm, then the time baseline for the occurrence of this behavior can be determined in the corresponding independent subset; when one week or one month has passed, learn about the occurrence time of this operation for this month and find that the concentrated time period of the operation has changed, such as becoming from 2:00 pm to 5:00 pm, then the time baseline for the occurrence of the behavior should be dynamically updated to avoid misjudgment of abnormal behaviors that may still occur subsequently.

[0043] In this embodiment, users with similar service attributes are placed in the same independent subset because if the service attributes are similar, the information data content they involve must be similar, and their access behaviors and operation behaviors are highly similar. There are only differences in the corresponding behavior frequencies and the sizes of the operation data, but these differences are not obvious. According to the above process of dividing users in the independent subset, their business scales are also similar.

[0044] The behavior baseline is a statistic of the corresponding login behaviors, access behaviors, and operation behaviors of users with similar service attributes and business scales within the independent subset. The relevant behaviors of all users are calculated according to the time granularities of daily, weekly, and monthly to obtain data such as the average behavior frequency, average duration, concentrated time period of behavior occurrence, and data traffic threshold under different time granularities. The data constitutes the behavior baseline of the behavior.

[0045] In this embodiment, from each independent subset, a fixed login frequency baseline is set, all independent subsets are traversed, and users in each independent subset with a login frequency lower than the login frequency baseline are extracted into another independent subset for centralized management. Users with a login frequency lower than the login frequency baseline are defined as dormant users.

[0046] In this embodiment, the present invention obtains the feature vectors representing users based on user service attributes and business scales, and uses cosine similarity to divide highly similar users into the same independent subset, which improves the data volume level of machine learning. At the same time, there is no need to set a behavior baseline for a single user, reducing the consumption of computing power resources.

[0047] The log parsing module is used to parse the log files corresponding to each of the independent subsets to obtain data forms, and associate each of the independent subsets with the corresponding behavior baseline.

[0048] In this embodiment, the log parsing module specifically includes: A parsing unit for parsing the log files generated by user behaviors in each of the independent subsets to obtain a data form of key-value pair information.

[0049] An association unit for associating each of the independent subsets with a corresponding behavior baseline. Among them, by automatically associating the data form with the behavior baseline, data comparison can be realized at different time granularities.

[0050] An abnormal behavior judgment module for obtaining the association result, comparing and judging to determine abnormal behaviors.

[0051] In this embodiment, the data form parsed by the log parsing module is obtained, the corresponding data form is matched and compared with the behavior baseline, and the comparison result is evaluated and judged to finally determine abnormal behaviors. Specifically: Based on the users within a certain independent subset, the login behavior, access behavior, and operation behavior are compared and evaluated at different time granularities respectively.

[0052] In the login behavior, when the deviation rate of the login frequency at any time granularity is greater than the set value, the login frequency is determined to be abnormal. Among them, the number of logins at the current time granularity is compared with the corresponding behavior baseline, and |number of logins - average login frequency| / average login frequency is used to obtain the deviation rate of the login frequency at this time granularity.

[0053] When the abnormal number of login times at any time granularity exceeds the set value, the login time is determined to be abnormal. Among them, the concentrated period when the login behavior occurs is the normal login period. For example: the normal login period is from 8:00 am to 8:00 pm. When a login behavior occurs at 10:00 pm or 4:00 am, it is determined that the login is at an abnormal time, and the abnormal number of login times at the corresponding time granularity is counted.

[0054] When the login behavior is successfully logged in on multiple different terminals within a specified time range, it is determined to be an abnormal login sharing. For example, if a user logs in from two different locations 1000 kilometers apart within 30 minutes, that is, the IP address of the login behavior appears in different geographical locations within the specified time range, and the spatial distance of the geographical locations exceeds the set distance, it is determined to be an abnormal login address.

[0055] In the access behavior and operation behavior, any behavior beyond the authority is determined to be an abnormal over-authority behavior. For behaviors within the authority, when there are short-term high-frequency deletion and modification operations on the same data form, it is determined to be an abnormal data operation. When the number of file data transmissions or the file transmission size exceeds the behavior baseline, it is determined to be an abnormal data migration.

[0056] In this embodiment, the abnormal behavior judgment module further includes a custom unit: The user can construct a dedicated baseline for the location range of the activity geographical center point. When the IP address logged in by the user exceeds this location range baseline, it is determined that the custom login address is abnormal.

[0057] When the content engaged in by an individual user is associated with or has an employment relationship with an enterprise user / government user, a baseline for associated behavior is set between the enterprise user / government user and the individual user. When the behavior of an individual user exceeds the behavior range of the enterprise user / government user or the behavior of a certain individual user is different from that of other individual users in the enterprise user / government user, it is determined that the behavior deviation is abnormal.

[0058] In this embodiment, the login behaviors of all dormant users are determined as active behavior anomalies. Dormant users include normal users with an activity frequency lower than the set value, users who have stopped using but have not been cancelled, and users who have not been used for a long time.

[0059] In this embodiment, by setting various scenarios for login behaviors, access behaviors, and operation behaviors, a full - range detection of user behaviors is achieved. At the same time, the addition of the custom mode allows users to set matching behavior baselines according to their respective usage scenarios and work characteristics, making the abnormal behavior detection more in line with user needs.

[0060] An early warning processing module, which is used to obtain the abnormal behavior and perform early warning processing.

[0061] In this embodiment, the early warning processing module obtains the abnormal behavior and performs early warning processing, specifically as follows: When the abnormal login frequency and abnormal data migration show the same trend of change, it is analyzed and determined that it is related to the change in business density, that is, the business density increases, resulting in an increase in login frequency, data migration, and working hours. It is included in the questionnaire item and sent to the user; otherwise, a corresponding alarm is directly sent to the user's emergency contact information. The user can choose to ignore the alarm or change the login information; the user needs to manually ignore the ignored alarm, otherwise the user's operations are restricted.

[0062] When there are abnormal login sharing and abnormal login addresses, a corresponding alarm is directly sent to the user's emergency contact information. The user can choose to ignore the alarm or change the login information.

[0063] For abnormal over - privilege behaviors, a counter is started to count the number of occurrences within each time granularity. When it exceeds the set value under any time granularity, the user is locked and the user's permissions are automatically downgraded.

[0064] For abnormal data operations, the data form is immediately locked, and a corresponding alarm is directly sent to the user's emergency contact information. The user can choose to ignore the alarm or change the login information.

[0065] For the abnormal behavior of custom units, directly send corresponding alarms to the user's emergency contact information. In addition to ignoring the alarm or changing the login information, the user can also modify the custom content.

[0066] For the abnormal behavior of dormant users, perform identity verification. When a dormant user is associated with an enterprise user / government user, the superior user needs to synchronously confirm the identity.

[0067] An embodiment of the present invention also provides a method for early warning of abnormal behavior risk based on autonomous learning, as Figure 2 shown, the method includes: S1. Record the behaviors and behavior information of the user terminal in real time, and generate a log file.

[0068] In this embodiment, the log file is stored in the data storage module.

[0069] In this embodiment, the behaviors include login behaviors, access behaviors, and operation behaviors. Among them, access behaviors can include page access, database access, etc.; operation behaviors can include database operations, file transfers such as uploads and downloads, and API interface call behaviors.

[0070] In this embodiment, the behavior information includes the login status, IP address, operation behavior, number of operations, operation time, traffic size, and behavior object of the behavior subject. Among them, the behavior subject is a user with a unique UID; the behavior object includes the content requested for query and retrieval, the content of data operations, and the API interfaces called.

[0071] S2. Obtain the text information of different types of users and calculate the business similarity. Create independent subsets based on the business similarity and set permissions; determine the behavior baselines of each independent subset according to the log file.

[0072] In this embodiment, in step S2, obtaining the text information of different types of users and calculating the business similarity, creating independent subsets based on the business similarity and setting permissions; determining the behavior baselines of each independent subset according to the log file includes the following steps: Obtain the text information of different types of users; the text information includes the functional scope, administrative level, and number of employees of government users, the industry business scope, asset scale, and number of employees of enterprise users, and the occupations and skill attributes of individual users.

[0073] Use a word segmentation tool to perform word segmentation on the text information, and use the TF-TDF model to transform the word text after word segmentation to obtain a numerical vector. The word segmentation tool can be SnowNLP.

[0074] Based on the scale feature words and attribute feature words, divide the numerical vectors of different users; respectively perform weighted summation on the numerical vectors corresponding to the scale feature words and attribute feature words according to the set ratio to obtain a feature vector representing the user's characteristics, and calculate the business similarity between any two user feature vectors. Among them, the set ratio can be adjusted according to different types of users.

[0075] Create independent subsets according to the preset threshold and the business similarity, and set the access rights, API interface call ranges, and normal operation behaviors of each of the independent subsets.

[0076] In this embodiment, when the cosine similarity is greater than the preset threshold, it is considered that the businesses of the two users are highly similar, and an independent subset is created, and the two users are placed in the same subset. Among them, the subsequent users need to compare the cosine similarity of their feature vectors with those of all users in the subset. When the cosine similarity of the subsequent user's feature vector is greater than the preset threshold, the user is added to the subset.

[0077] Number the multiple independent subsets of each type of user respectively, and the user classification module sets the access rights, API interface call ranges, and normal operation behaviors for the independent subsets with different numbers. Among them, the setting principles include: according to the different types of users, different permissions in the same query form are given to them, and government users > enterprise users > individual users. The API interface call range is publicly corresponding according to the business attributes of the users, and the API interfaces between different independent subsets are different. The normal operation behavior is determined according to the access rights and API interface call range.

[0078] Determine the behavior baselines of each of the independent subsets according to the log file and perform dynamic updates.

[0079] In this embodiment, learn the historical behaviors of the users in each independent subset to obtain the behavior baselines such as the normal login frequency and time period, operation objects and behaviors, and corresponding traffic data conditions of users with similar business attributes, and dynamically update the behavior baselines of the above factors in the independent subset within a certain time period.

[0080] S3. Parse the log files corresponding to each of the independent subsets to obtain data forms, and associate each of the independent subsets with the corresponding behavior baselines.

[0081] In this embodiment, in step S3, parsing the log files corresponding to each of the independent subsets to obtain data forms, and associating each of the independent subsets with the corresponding behavior baselines includes the following steps: Parse the log files generated by the user behaviors in each of the independent subsets to obtain data forms of key-value pair information; Associate each of the said independent subsets with the corresponding behavior baseline.

[0082] S4. Parse the log files corresponding to each of the said independent subsets to obtain data forms, and associate each of the said independent subsets with the corresponding behavior baseline.

[0083] In this embodiment, for the users within a certain independent subset, compare and evaluate the login behavior, access behavior, and operation behavior at different time granularities respectively, specifically including: In the login behavior, when the deviation rate of the login frequency at any time granularity is greater than the set value, it is determined that the login frequency is abnormal. Among them, compare the number of logins at the current time granularity with the corresponding behavior baseline, and let |number of logins - average login frequency| / average login frequency to obtain the deviation rate of the login frequency at this time granularity.

[0084] When the number of abnormal login times at any time granularity exceeds the set value, it is determined that the login time is abnormal. Among them, the concentrated period when the login behavior occurs is the normal login period.

[0085] When the login behavior is successfully logged in on different terminals multiple times within the specified time range, it is determined that the login sharing is abnormal.

[0086] In the access behavior and operation behavior, any behavior that exceeds the authority is determined to be an over-authority behavior exception. For behaviors within the authority, when there are short-term and high-frequency deletion and modification operations on the same data form, it is determined that the data operation is abnormal. When the number of file data transmissions or the file transmission size exceeds the behavior baseline, it is determined that the data migration is abnormal.

[0087] In this embodiment, the user can construct a baseline for the location range of the exclusive activity geographical center point. When the IP address where the user logs in exceeds this location range baseline, it is determined that the custom login address is abnormal.

[0088] When the content engaged in by an individual user is related to or there is an employment relationship with an enterprise user / government user, set an associated behavior baseline between the enterprise user / government user and the individual user. When the behavior of an individual user exceeds the behavior range of the enterprise user / government user or the behavior of a certain individual user is different from the behavior of other individual users among the enterprise user / government users, it is determined that the behavior deviation is abnormal.

[0089] In this embodiment, the login behavior of all dormant users is determined to be an active behavior exception. Dormant users include normal users with an activity frequency lower than the set value, users who have stopped using but have not been canceled, and users who have not been used for a long time.

[0090] S5. Obtain the said abnormal behavior and perform early warning processing.

[0091] In this embodiment, obtaining the abnormal behavior and performing early warning processing specifically includes: When the abnormal login frequency and abnormal data migration show the same trend of change, it is analyzed and determined that it is related to the change in business density, that is, the business density increases, resulting in an increase in the login frequency, data migration, and working hours, which are included in the questionnaire item and sent to the user; otherwise, a corresponding alarm is directly sent to the user's emergency contact, and the user can choose to ignore the alarm or change the login information; the user needs to manually ignore the alarm, otherwise the user's operation is restricted.

[0092] When there are abnormal login sharing and abnormal login addresses, a corresponding alarm is directly sent to the user's emergency contact, and the user can choose to ignore the alarm or change the login information.

[0093] For abnormal over - privilege behavior, a counter is started to count the number of occurrences within each time granularity. When the set value under any time granularity is exceeded, the user is locked and the user's permissions are automatically downgraded.

[0094] For abnormal data operations, the data form is immediately locked, and a corresponding alarm is directly sent to the user's emergency contact. The user can choose to ignore the alarm or change the login information.

[0095] For the abnormal behavior of the custom unit, a corresponding alarm is directly sent to the user's emergency contact. In addition to choosing to ignore the alarm or change the login information, the user can also modify the custom content.

[0096] For the abnormal behavior of dormant users, identity verification is performed. When the dormant user is associated with an enterprise user / government user, the superior user needs to synchronously confirm the identity.

[0097] As Figure 3 shown, an embodiment of the present invention also provides a device, including: a processor 301, the processor 301 is coupled to a memory 302, and the processor 301 is configured to read and execute a computer program stored in the memory 302 to implement a method for early warning of abnormal behavior risks based on autonomous learning as described in the above - mentioned method embodiment.

[0098] An embodiment of the present invention also provides a computer - readable storage medium. The computer - readable storage medium stores a program or instruction. When the above - mentioned program or instruction runs on a computer, the computer is enabled to execute a method for early warning of abnormal behavior risks based on autonomous learning as described in the above - mentioned method embodiment.

[0099] Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An abnormal behavior risk early warning system based on autonomous learning, characterized in that, The system includes: A log recording module, which is used to record the behaviors and behavior information of the user terminal in real time and generate a log file; A data storage module, which is used to store the log file; A user classification module, which is used to obtain the text information of different types of users and calculate the business similarity, create independent subsets based on the business similarity and set permissions; according to the log file, determine the behavior baselines of each of the independent subsets; A log parsing module, which is used to parse the log files corresponding to each of the independent subsets to obtain data forms, and associate each of the independent subsets with the corresponding behavior baselines; An abnormal behavior judgment module, which is used to obtain the association result, compare and judge, and determine abnormal behaviors; An early warning processing module, which is used to obtain the abnormal behaviors and perform early warning processing.

2. The system according to claim 1, characterized in that, The user classification module specifically includes: An acquisition unit, which is used to obtain the text information of different types of users; the text information includes the functional scope, administrative level and number of employees of government users, the industry business scope, asset scale and number of personnel of enterprise users, and the occupations and skill attributes of individual users; A conversion unit, which is used to process and convert the text information to obtain a numerical vector; A calculation unit, which is used to divide the numerical vectors of different users based on scale feature words and attribute feature words to obtain the feature vectors of different users, and calculate the business similarity; A creation unit, which is used to create independent subsets according to a preset threshold and the business similarity, and set the access permissions, API interface call ranges and normal operation behaviors of each of the independent subsets; A determination unit, which is used to determine the behavior baselines of each of the independent subsets according to the log file and perform dynamic updates.

3. The system according to claim 1, wherein The log parsing module specifically includes: A parsing unit, which is used to parse the log files generated by user behaviors in each of the independent subsets to obtain data forms of key-value pair information; An association unit, which is used to associate each of the independent subsets with the corresponding behavior baselines.

4. An abnormal behavior risk early warning method based on autonomous learning, characterized in that, The method includes: Recording the behaviors and behavior information of the user terminal in real time and generating a log file; Obtaining the text information of different types of users and calculating the business similarity, creating independent subsets based on the business similarity and setting permissions; according to the log file, determining the behavior baselines of each of the independent subsets; Parsing the log files corresponding to each of the independent subsets to obtain data forms, and associating each of the independent subsets with the corresponding behavior baselines; Obtaining the association result, comparing and judging, and determining abnormal behaviors; Obtaining the abnormal behaviors and performing early warning processing.

5. The method according to claim 4, characterized in that, The log file is stored in the data storage module.

6. The method according to claim 4, characterized in that, The behaviors include login behaviors, access behaviors and operation behaviors; the behavior information includes the login status, IP address, operation behavior, number of operations, operation time, traffic size and behavior object of the behavior subject.

7. The method according to claim 4, wherein Obtaining the text information of different types of users and calculating the business similarity, creating independent subsets based on the business similarity and setting permissions; According to the log file, determining the behavior baselines of each of the independent subsets specifically includes: Obtain the text information of different types of users; the text information includes the functional scope, administrative level, and number of employees of government users, the industry business scope, asset scale, and personnel scale of enterprise users, and the occupations and skill attributes of individual users; Process and transform the text information to obtain a numerical vector; Based on the scale feature words and attribute feature words, divide the numerical vectors of different users to obtain the feature vectors corresponding to different users, and calculate the business similarity; Create independent subsets according to the preset threshold and the business similarity, and set the access rights, API interface call ranges, and normal operation behaviors of each independent subset; Determine the behavior baselines of each independent subset according to the log file and perform dynamic updates.

8. The method according to claim 4, wherein Parsing the log files corresponding to each independent subset to obtain data forms, and associating each independent subset with the corresponding behavior baseline, specifically including: Parsing the log files generated by user behaviors in each independent subset to obtain data forms of key-value pair information; Associate each independent subset with the corresponding behavior baseline.

9. An electronic device, characterized in that It includes a processor, and the processor is coupled to a memory; The processor is used to read and execute the computer program stored in the memory to implement an abnormal behavior risk warning method based on autonomous learning as described in any one of claims 4-8.

10. A computer storage medium, characterized in that It stores a program or instruction, and when the program or instruction runs on a computer, the computer is made to execute an abnormal behavior risk warning method based on autonomous learning as described in any one of claims 4-8.

Citation Information

Patent Citations

  • Internal threat early warning method based on user portrait

    CN113408579A

  • User abnormal operation behavior identification method and device

    CN115577348A

  • User abnormal behavior detection method, system and device and readable storage medium

    CN117499103A

  • Intelligent analysis early warning system based on log data mining

    CN118445333A

  • Method for analyzing abnormal behavior of user based on log and flow data

    CN119484003A

Cited By

  • Large packet anomaly detection method and device based on dynamic baseline, medium and product

    CN121309161A