Scenarized audit analysis method and system based on Fagger behavior model
Through the Foger behavior model, the operation and maintenance behavior is broken down into scene goals, operations and triggers, and the classification results of abnormal scene behavior are generated, which solves the problem of insufficient evidence links in the existing technology, and realizes efficient abnormal behavior identification and audit management.
Patent Information
- Application Number
- CN202510551746.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-22
AI Technical Summary
The existing operation and maintenance log audit analysis model cannot effectively form a link of evidence, resulting in the lack of persuasiveness of audit results and inefficient audits, making it impossible to effectively identify consecutive events of abnormal behavior.
The Foger behavior model is adopted to decompose operation and maintenance behavior into three dimensions: scene objectives, behavioral operations and behavior triggers. Through multi-level composite calculation, the scope, technology, effective and comprehensive behavioral capabilities are generated, and the classification results of normal and abnormal scene behaviors are generated by combining behavioral triggers and scene targets, and the five major attributes recognized by the audit are output.
By building a continuous chain of evidence of abnormal behavior, the relevance and persuasiveness of audit evidence are improved, the efficiency of audit management is improved, and abnormal scenario behavior can be accurately identified.
Smart Images

Figure CN120355302A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of electronic information technology, and in particular to a scenario-based audit analysis method and system based on the Fogg behavior model. Background Art
[0002] The operation and maintenance log audit mainly collects and audits the operation logs of IT operation and maintenance personnel. The current mainstream audit analysis model is the behavior event analysis model (5W1H), which analyzes specific events of operation and maintenance personnel during the operation and maintenance process based on audit indicators. By tracking and recording the operation and maintenance behavior events of operation and maintenance personnel, abnormal events can be quickly audited.
[0003] The commonly used analysis methods of the behavioral event analysis model (5W1H) mainly include keywords and data statistics:
[0004] 1. Keyword analysis is mainly the process of matching and comparing operation logs based on the set audit rules to find abnormalities and violations, such as rules for abnormal time periods for operation and maintenance personnel, rules for abnormal operation permissions for operation and maintenance personnel, etc.
[0005] 2. Data statistical analysis is mainly based on statistical rules to count the number of groupings of each attribute dimension in the audit subject, audit object, and audit action. The statistical results are analyzed and compared with the set thresholds to discover abnormal violations, such as the number of logins by operation and maintenance personnel exceeding the threshold statistics, the number of operations by operation and maintenance personnel exceeding the threshold statistics, etc.
[0006] With the application of technologies such as big data, AI, and semantic analysis, the relevant technologies are combined with the event analysis model (5W1H), which has improved the speed of analysis and the accuracy of abnormal behavior. However, the results are often a single abnormal behavior event, which cannot effectively form a chain of evidence and thus lacks audit recognition.
[0007] Existing technologies either combine event analysis models (5W1H) with single-factor or multi-factor rule matching and simple statistics, or combine event analysis models (5W1H) with big data, AI and other technologies. The abnormal results (evidence) of the audit are isolated, resulting in the audit results being ineffective and persuasive. Auditors need to spend a lot of time to dig out, restore and verify the entire process of the event, which reduces the efficiency of the audit. And usually, the following conditions must be met for the audit to be recognized:
[0008] 1) Occurrence: All behavioral scenarios, behavioral operations, and scenario goals (the result set of a series of behavioral operations) have occurred and are related to the audited object.
[0009] 2) Completeness: All behavioral scenarios, behavioral operations, and scenario goals that should be recorded have been recorded.
[0010] 3) Accuracy: Consistent with all scenario goals related to behavioral scenarios or behavioral operations and recorded.
[0011] 4) Effectiveness: All behavioral operations and scenario goals occur within the effective time of the behavioral scenario and are recorded.
[0012] 5) Classification: All behavioral scenarios, behavioral operations, and scenario goals that should be recorded are accurately recorded in the corresponding accounts. Summary of the Invention
[0013] In view of the deficiencies of the prior art, the present invention discloses a scenario-based audit analysis method and system based on the Fogg behavior model to solve the problems raised in the above background technology.
[0014] To achieve the above object, the present invention provides the following technical solutions: A scenario-based audit analysis method based on the Fogg behavior model, including the following steps:
[0015] S1. Establish a Fogg behavior theory model for IT operation and maintenance personnel, and decompose the operation and maintenance behavior into three dimensions: scenario goal, i.e., motivation m, behavioral operation, i.e., behavioral ability a, and behavioral trigger, i.e., trigger t. The behavioral theory model is expressed as B = m * a * t;
[0016] Scenario goal: Represents the set of a series of behavioral results of IT operation and maintenance personnel during operation and maintenance;
[0017] Behavioral operation: Represents the ability points required for IT operation and maintenance personnel to achieve the goal;
[0018] Behavioral trigger: Represents the flag event that triggers the scenario goal;
[0019] S2. Decompose the behavioral ability into five basic factors: role ability, permission ability, operation ability, time ability, and channel ability, and sequentially generate range ability, technical ability, effective ability, and comprehensive behavioral ability through multi-level composite calculation;
[0020] S3. Combine the composite calculation results of behavioral triggers, scenario goals, and behavioral abilities to generate classification results of normal scenario behaviors and abnormal scenario behaviors;
[0021] S4. Output audit determination results including five major attributes: occurrence, integrity, accuracy, effectiveness, and classification according to the level of abnormal scenario behaviors to enhance the persuasiveness of audit determination and audit management efficiency.
[0022] Preferably, the multi-level composite calculation in step S2 includes:
[0023] Scope ability = Role ability * Permission ability, where Role ability refers to the role of IT operation and maintenance personnel, and Role ability includes job classifications such as development, testing, operation and maintenance, guarantee, inspection, data extraction, and rehearsal. Permission ability refers to the access permissions set by the administrator for operation and maintenance targets, and Permission ability includes development permissions, testing permissions, online permissions, inspection permissions, guarantee permissions, data extraction permissions, and rehearsal permissions;
[0024] Technical ability = Scope ability * Operation ability, where Operation ability refers to the operations of IT operation and maintenance personnel on target resources. Operation ability is a set of operation instructions for target resources. The matching degree between the operation instruction set and the resource access scope determines the technical ability score. Technical ability is obtained by the composite calculation of Operation ability and Scope ability, which means that IT operation and maintenance personnel have executed equivalent operation sets within the corresponding scope;
[0025] Effective ability = Technical ability * Time ability, where Time ability refers to whether IT operation and maintenance personnel operate within the effective time. Time ability includes working time and non - working time. Working time is further divided into working periods such as fault time, online time, inspection time, testing time, data extraction time, guarantee time, and rehearsal time. Operating during non - working periods triggers the abnormal determination of Time ability;
[0026] Behavior ability = Effective ability * Channel ability, where Channel ability refers to whether IT personnel execute Effective ability through the set channels. Channel ability verifies whether the access path conforms to the preset rules of 4A channels, VPN + 4A channels, and inter - network access + 4A channels. Access through a detoured channel triggers abnormal determination. Behavior ability is obtained by the composite calculation of Effective ability and Channel ability.
[0027] Preferably, in the multi - level composite calculation:
[0028] 1) Interactive verification level binding:
[0029] The interactive analysis of Role ability and Permission ability only acts on the calculation stage of Scope ability;
[0030] The interactive analysis of Scope ability and Operation ability only acts on the calculation stage of Technical ability;
[0031] The interactive analysis of Technical ability and Time ability only acts on the calculation stage of Effective ability;
[0032] The interactive analysis of Effective ability and Channel ability only acts on the calculation stage of Behavior ability;
[0033] 2) Calculation rule conflict resolution:
[0034] When the interactive analysis shows a significant association between factors, the product calculation rule output result is maintained;
[0035] When the interaction analysis shows no significant association, the main effect value of a single factor is used to replace the product calculation result;
[0036] 3) Forced application of verification results:
[0037] In the calculation of range capabilities, the conclusion of the interaction analysis between role capabilities and permission capabilities is used as the judgment condition for whether to trigger permission review;
[0038] In the calculation of technical capabilities, the conclusion of the interaction analysis between range capabilities and operation capabilities is used as the basis for correcting the matching degree of the operation instruction set.
[0039] Preferably, in step S3:
[0040] The judgment condition for normal scenario behavior is: within the effective trigger interval, the behavior operation ability matches the scenario target motivation;
[0041] The judgment conditions for abnormal scenario behavior include at least one of the following:
[0042] (a) Triggering behavior operations and scenario targets in the invalid trigger interval;
[0043] (b) Triggering behavior operations or scenario targets inconsistent with the event in the effective trigger interval.
[0044] Preferably, in step S3, the classification results of normal scenario behavior and abnormal scenario behavior are obtained by calculating and quantifying the scores through the following formula:
[0045] Fogg behavior scenario analysis score for IT operation and maintenance personnel = Motivation score * Ability score * Trigger score, and the normal / abnormal levels are divided according to the score threshold, where:
[0046] Normal scenario behavior is divided into three categories: high, medium, and low according to the behavior ability score;
[0047] Abnormal scenario behavior is divided into five categories: extremely large, major, high, medium, and low according to the abnormal level score;
[0048] Among them,
[0049] Extremely large abnormal behavior: Abnormal deviations occur in range capabilities, technical capabilities, and effective capabilities;
[0050] Major abnormal behavior: Two basic ability factors are abnormal and deviate from the preset threshold;
[0051] High, medium, and low abnormal behaviors: The levels are divided according to the number of abnormal ability factors or the degree of deviation.
[0052] Preferably, the audit determination results in step S4 include:
[0053] The specific levels of abnormal scenario behaviors include extremely large, major, high, medium, and low abnormal behaviors according to the hazard levels.
[0054] The types of abnormal ability factors include role ability, permission ability, operation ability, time ability, and channel ability.
[0055] The present invention also provides a scenario-based audit analysis system based on the Fogg Behavior Model, including: a processor and a memory, and the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the scenario-based audit analysis method based on the Fogg Behavior Model is implemented.
[0056] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention first introduces the Fogg Behavior Model into the field of IT operation and maintenance audit, and establishes a scenario-based abnormal behavior analysis model through the behavioral psychology framework of three dimensions: motivation, ability, and trigger factors; adopts the audit determination of the scenario goals (motivation), behavior operations (ability), and behavior scenarios (trigger points) of IT operation and maintenance personnel. Through the Fogg Behavior Model, starting from the behavior scenario and scenario goals, it explains normal operation and maintenance behavior operations and abnormal behavior operations, and constructs relevant abnormal behavior operations into a series of continuous events, forming an effective abnormal behavior evidence chain, achieving a breakthrough from single-point event detection to continuous behavior chain analysis, effectively improving the relevance and persuasive power of audit evidence, and at the same time improving the efficiency of audit management. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification, and are used to explain the present invention together with the embodiments of the present invention, and do not constitute a limitation to the present invention.
[0058] In the drawings:
[0059] Figure 1 is a flowchart of a scenario-based audit analysis method based on the Fogg Behavior Model of the present invention;
[0060] Figure 2 is a schematic structural diagram of the Fogg Behavior Model of the present invention;
[0061] Figure 3 is a schematic diagram of the application steps of the Fogg behavior scenario audit analysis of IT operation and maintenance personnel of the present invention;
[0062] Figure 4 is a schematic diagram of the corresponding relationship between roles and operation sets of the scope ability of the present invention under different settings;
[0063] Figure 5 is a schematic diagram of the comparison of the number of abnormal IPs of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0064] The preferred embodiments of the present invention will be described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present invention, and are not intended to limit the present invention.
[0065] Embodiment: As Figure 1 shown, a scenario-based audit analysis method based on the Fogg behavior model includes the following steps:
[0066] S1. Establish a Fogg behavior theory model for IT operation and maintenance personnel, and divide the operation and maintenance behaviors into three dimensions: scenario goals (i.e., motivation m), behavior operations (i.e., behavior ability a), and behavior triggers t. The behavior theory model is expressed as B = m * a * t;
[0067] S2. Split the behavior ability into five basic factors: role ability, permission ability, operation ability, time ability, and channel ability, and generate range ability, technical ability, effective ability, and comprehensive behavior ability through multi-level composite calculation in sequence;
[0068] S3. Combine the composite calculation results of behavior triggers, scenario goals, and behavior ability to generate classification results of normal scenario behaviors and abnormal scenario behaviors;
[0069] S4. Output the audit determination results including five major attributes: occurrence, integrity, accuracy, effectiveness, and classification according to the level of abnormal scenario behaviors.
[0070] Specifically, it includes three major steps: establishing the Fogg behavior theory model for IT operation and maintenance personnel, analyzing the application of the theory model, and code implementation:
[0071] I. Establishing the Fogg behavior theory model for IT operation and maintenance personnel
[0072] The establishment of the Fogg behavior theory model for IT operation and maintenance is first based on the study of the psychology of IT operation and maintenance personnel using the Fogg behavior model. The Fogg behavior model is as Figure 2 shown. Based on the Fogg behavior model, the IT operation and maintenance model is from scenario goals (motivation m), behavior operations (ability a), and behavior scenarios (triggers t), specifically as follows:
[0073] 1. Scenario goals (motivation m) are mainly a set of behavioral results of IT operation and maintenance personnel during the operation and maintenance process, such as the set of online behavior results, inspection results, troubleshooting results, data extraction results, etc. Through the scenario goals, it is to understand the background, purpose, what to do, and how to do of the behaviors of IT operation and maintenance personnel.
[0074] 2. Behavior operations (ability a) are mainly a series of support ability points for IT operation and maintenance personnel to obtain goals, such as time ability, role ability, permission ability, technical ability, channel ability, etc. Quantify and evaluate the ability points, and the purpose of the evaluation is to understand the corresponding abilities of the behavioral personnel.
[0075] 3. The behavior trigger (trigger t) mainly triggers the flag events of the scenario target, and through the events, understands the motivation of the triggered behavior, behavior operations, etc.
[0076] According to the above, the Fogg behavior (B) of IT operation and maintenance personnel = scenario target (motivation m) * behavior operation (ability a) * behavior trigger (trigger t). During the audit process, the behavior operation (ability a) and scenario target (motivation m) that occur in the effective trigger interval are the effective recognition of the normal behavior scenario, otherwise it is an abnormal behavior scenario. For example, triggering the behavior operation (ability a) and scenario target (motivation m) in the invalid trigger area, or triggering a behavior operation (ability a) or scenario target (motivation m) inconsistent with the trigger event in the effective trigger area, etc.
[0077] II. Analysis steps for the application of the theoretical model
[0078] After the Fogg behavior theory model for IT operation and maintenance personnel is established, the application analysis steps are as Figure 3 shown. First, split the behavior ability into basic factors such as role ability, permission ability, operation ability, time ability, channel ability, etc., and sequentially obtain the scope ability, technical ability, and effective ability, and finally comprehensively obtain the behavior ability. Then, calculate the composite of the behavior trigger, scenario target, and behavior ability to obtain the normal scenario behavior and abnormal scenario behavior of IT operation and maintenance personnel. The specific application steps are annotated as follows:
[0079] 1) Scope ability = role ability * permission ability, where role ability refers to the role of IT operation and maintenance personnel, generally divided into development, testing, operation and maintenance, guarantee, inspection, data extraction, rehearsal, etc.; permission ability refers to the access permissions set by the administrator for operation and maintenance targets, generally divided into development permission, testing permission, online permission, inspection permission, guarantee permission, data extraction permission, rehearsal permission; after the composite calculation of role ability and permission ability, the scope ability is generally the access permissions that the corresponding role has for target resources;
[0080] 2) Technical ability = scope ability * operation ability, where operation ability refers to the operations of IT operation and maintenance personnel on target resources, here it refers to the operation set; the composite calculation of operation ability and scope ability obtains the technical ability, which means that IT operation and maintenance personnel have executed the corresponding operation set within the corresponding scope;
[0081] 3) Effective ability = technical ability * time ability, where time ability refers to whether IT operation and maintenance personnel operate during effective time, generally divided into working time and non-working time, and working time is further divided into fault time, online time, inspection time, testing time, data extraction time, guarantee time, rehearsal time, etc.; the composite calculation of technical ability and time ability obtains the effective ability, which generally means that IT operation and maintenance personnel operate during effective time;
[0082] 4) Behavior ability = Effective ability * Channel ability, where the channel ability refers to whether IT personnel execute the effective ability through the set channels. The set channels are set as 4A channels, VPN + 4A channels, inter-network access + 4A channels, detour channels, etc. The behavior ability is obtained by the composite calculation of the effective ability and the channel ability. The behavior ability is a comprehensive quantitative scoring result of a behavior set, and the results are divided into normal behaviors and abnormal behaviors. Normal behaviors are divided into three levels of high, medium, and low behavior abilities, which reflect the behavior efficiency of IT operation and maintenance personnel. Abnormal behaviors are divided into five major types of abnormal behavior hazard accidents of extremely large, major, high, medium, and low levels according to the level, which are the key analysis content of IT operation and maintenance audit. For example, in the extremely large abnormal behavior accident, the scope ability, technical ability, and effective ability all show abnormal deviations.
[0083] 5) The analysis result of the Fogg behavior scenario of IT operation and maintenance personnel = Behavior trigger point * Scenario motivation * Behavior ability, where the normal scenario behavior and abnormal scenario behavior are obtained by the composite calculation and scoring quantification of the behavior trigger point, scenario motivation, and behavior ability. Normal scenario behaviors are divided into three levels of high, medium, and low behavior abilities, which reflect the action efficiency of IT operation and maintenance personnel in daily scenario behaviors. Abnormal scenario behaviors are divided into five major types of abnormal scenario behavior accidents of extremely large, major, high, medium, and low levels according to the level.
[0084] The above application steps mainly use the factorial analysis of variance with interaction to verify whether there is an interaction between factors on the result.
[0085] III. Code implementation
[0086] Taking "Scope ability = Role ability * Permission ability" as an example for the factorial analysis of variance with interaction, the calculation of the scope ability uses two-way analysis of variance to verify the influence of the interaction between the role ability and the permission ability on the scope ability. The specific steps are as follows:
[0087] Assume that the role ability is set as factor A and the permission ability is set as factor B; factor A has r level classifications A1, A2,... A r ; factor B has s level classifications B1, B2,... B S ;
[0088] Since there is a certain interaction between factor A and B, to examine the interaction between the two and the resulting scope ability level, assume that the scope ability level is verified t times under each level classification combination (A i , B j ), and the verification value of the kth time is denoted as X ijk . Then the two-way analysis of variance model for this interaction is expressed as:
[0089]
[0090] Among them, α iis the effect of the i-th level of factor A, β j is the effect of the j-th level of factor B, δ ij is A i and B j is the interaction effect of A and B. μ represents the theoretical average level of the range ability under all possible level combinations, and its calculation formula is: μ = (1 / rs)∑ r i=1 ∑ s j=1 μ ij ; where μ ij is A i and B j is the interaction effect of A and B.
[0091] The present invention also provides a scenario-based audit analysis system based on the Fogg Behavior Model, including: a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, the described scenario-based audit analysis method based on the Fogg Behavior Model is implemented.
[0092] The code is specifically implemented as follows:
[0093] Step 1. Input data:
[0094]
[0095] Step 2. Data processing:
[0096]
[0097] Step 3. Data analysis:
[0098]
[0099] Step 4. Result analysis:
[0100] A single role ability factor has no effect on the range ability;
[0101] A single permission ability factor has no effect on the range ability;
[0102] The interaction factor of role ability and permission ability affects the range ability.
[0103] Step 5. Range ability combination arrangement:
[0104] Then the normal range ability is related to the role ability and permission ability respectively according to the ranges recorded in the log. The smaller the role and permission ranges, the more accurate the range ability, and the larger the role and permission ranges, the more extensive the range ability. For example, Figure 4 shows the corresponding relationship between the range ability and the role and operation set under different settings;
[0105] The normal range ability refers to the role ability corresponding to the corresponding permission ability, and the abnormal range ability refers to the role ability not corresponding to the corresponding permission ability. Therefore, according to permutation and combination, the normal range and abnormal range interval sets of the range ability are obtained.
[0106] Calculate the technical ability = range ability * operation ability, effective ability = technical ability * time ability, behavior ability = effective ability * channel ability, and the Fogg behavior scenario analysis result of IT operation and maintenance personnel = behavior trigger point * scenario motivation * behavior ability in sequence according to the above steps. The purpose of the calculation and inspection is to check whether each factor affects the Fogg behavior scenario analysis result of IT operation and maintenance personnel. If there is an impact, analyze the corresponding normal result set and abnormal result set, and finally obtain the results of normal scenario behavior and abnormal scenario behavior. The normal scenario behavior is the set of triggered events & behaviors & results; the abnormal scenario behavior is the set of abnormal trigger events || abnormal behaviors || abnormal results, which conforms to the five major attributes of occurrence, completeness, accuracy, effectiveness, and classification in the audit determination.
[0107] Application effect:
[0108] In the scenario analysis of abnormal authentication and login of IT operation and maintenance personnel, the Fogg behavior model analyzes the illegal operation behavior of multiple people sharing the same account. For example Figure 5 As shown, in this result, the behavior of the same account having 1 - 3 different source IP logins within one hour is marked as normal scenario behavior, and the behavior of having 6 or more different source IPs is marked as abnormal scenario behavior. Compared with the rule of the behavior event analysis model that 2 or more source IPs log in to the same account within a specific time, the audit analysis strategy of the Fogg behavior model realizes more accurate risk positioning in the actual production environment of the enterprise. Through the audit alarm work order and confirmation by IT operation and maintenance personnel, there is indeed the behavior of borrowing work numbers.
[0109] Finally, it should be noted that the above are only preferred examples of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A scenario-based audit analysis method based on the Fogg Behavior Model, characterized in that, It includes the following steps: S1. Establish a Fogg Behavior Theory model for IT operation and maintenance personnel, and divide operation and maintenance behaviors into three dimensions: scenario goals (i.e., motivation m), behavior operations (i.e., behavior ability a), and behavior triggers t. The behavior theory model is expressed as B = m * a * t; S2. Decompose behavior ability into five basic factors: role ability, permission ability, operation ability, time ability, and channel ability, and generate scope ability, technical ability, effective ability, and comprehensive behavior ability through multi-level composite calculations in sequence; S3. Combine the composite calculation results of behavior triggers, scenario goals, and behavior ability to generate classification results of normal scenario behaviors and abnormal scenario behaviors; S4. Output audit determination results including five major attributes: occurrence, integrity, accuracy, effectiveness, and classification according to the level of abnormal scenario behaviors.
2. The scenario-based audit analysis method based on the Fogg Behavior Model according to claim 1, characterized in that: The multi-level composite calculation in step S2 includes: Scope ability = role ability * permission ability, where role ability includes job classifications such as development, testing, operation and maintenance, guarantee, inspection, data extraction, and rehearsal, and permission ability includes development permission, testing permission, online permission, inspection permission, guarantee permission, data extraction permission, and rehearsal permission; Technical ability = scope ability * operation ability, where operation ability is a set of operation instructions for target resources, and the matching degree between the operation instruction set and the resource access scope determines the technical ability score; Effective ability = technical ability * time ability, where time ability includes working hours and non-working hours. Working hours are further divided into working periods such as fault time, online time, inspection time, testing time, data extraction time, guarantee time, and rehearsal time. Abnormal determination of time ability is triggered for operations during non-working periods; Behavior ability = effective ability * channel ability, and channel ability verifies whether the access path conforms to the preset rules of 4A channels, VPN + 4A channels, and inter-network access + 4A channels. Abnormal determination is triggered for access through detour channels.
3. The scenario-based audit analysis method based on the Fogg Behavior Model according to claim 2, wherein: In the above multi-level composite calculation: 1) Interactive verification level binding: The interactive analysis of role ability and permission ability only acts on the scope ability calculation stage; The interactive analysis of scope ability and operation ability only acts on the technical ability calculation stage; The interactive analysis of technical ability and time ability only acts on the effective ability calculation stage; The interactive analysis of effective ability and channel ability only acts on the behavior ability calculation stage; 2) Calculation rule conflict resolution: When the interactive analysis shows a significant association between factors, maintain the output result of the product calculation rule; When the interactive analysis shows no significant association, use the main effect value of a single factor to replace the product calculation result; 3) Forced application of verification results: In the scope ability calculation, the conclusion of the interactive analysis of role ability and permission ability is used as the determination condition for whether to trigger permission review; In the technical ability calculation, the conclusion of the interactive analysis of scope ability and operation ability is used as the basis for correcting the matching degree of the operation instruction set.
4. The scenario-based audit analysis method based on the Fogg Behavior Model according to claim 1, characterized in that: In step S3: The determination condition for normal scenario behaviors is that within the effective trigger interval, the behavior operation ability matches the scenario goal motivation; The determination conditions for abnormal scenario behaviors include at least one of the following: (a) Triggering behavior operations and scenario goals in an invalid trigger interval; (b) Triggering behavior operations or scenario goals inconsistent with the event in the effective trigger interval.
5. The scenario-based audit analysis method based on the Fogg behavior model according to claim 1, characterized in that: In step S3, the classification results of normal scenario behaviors and abnormal scenario behaviors are quantified by calculating scores through the following formula to obtain normal scenario behaviors and abnormal scenario behaviors: The Fogg behavior scenario analysis score of IT operation and maintenance personnel = Motivation score * Ability score * Trigger score, and the normal / abnormal levels are divided according to the score threshold, where: Normal scenario behaviors are divided into three categories: high, medium, and low according to the behavior ability score; Abnormal scenario behaviors are divided into five categories: extremely large, major, high, medium, and low according to the abnormal level score.
6. The scenario-based audit analysis method based on the Fogg Behavior Model according to claim 1, characterized in that: The audit determination results in step S4 include: The specific level of abnormal scenario behaviors, including extremely large, major, high, medium, and low abnormal behaviors according to the harm level; The types of abnormal ability factors, including role ability, permission ability, operation ability, time ability, and channel ability.
7. A scenario-based audit analysis system based on the Fogg Behavior Model, comprising: A processor and a memory, the memory stores computer program instructions, and when the computer program instructions are executed by the processor, a scenario-based audit analysis method based on the Fogg behavior model according to any one of claims 1-6 is implemented.
Citation Information
Cited By
IT operation and maintenance behavior anomaly detection method and device and electronic equipment
CN116861414A