Behavior extraction and analysis device based on host operation log
Through the clustered slicing processing and intent analysis model based on the host operation log, the deep correlation analysis problem of host operation behavior is solved, and the accurate identification of complex attacks and advanced persistent threats is achieved, and the security and stability of the system are improved.
Patent Information
- Application Number
- CN202510290443.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-07-25
AI Technical Summary
The existing technology lacks in-depth correlation analysis and mining models, and cannot conduct forward-back correlation analysis and behavioral intention analysis of host operation behavior, resulting in untimely and inadequate security audit analysis, affecting system security and stability.
It provides a behavior extraction and analysis device based on the host operation log, including a clustered slice processing module and an intention analysis model. By processing and fusion of the clustered data, it identifies the user behavior pattern and performs abnormal intention alarms.
It can reveal the attack patterns and abnormal behaviors of host operations, accurately identify complex attacks and advanced persistent threats, and improve the security and stability of the system.
Smart Images

Figure CN120372605A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a host behavior extraction and analysis device, and more particularly to a behavior extraction and analysis device based on host operation logs. Background Art
[0002] In recent years, the network security situation has been severe and complex. Especially when accessing important business hosts of government services and performing business operations, it is urgent to establish user history and group behavior security baselines for new attack behaviors, abnormal operation behaviors, etc. By combining multi-source log time series and context analysis, abnormal access behaviors or attack behaviors can be discovered, and potential unknown risks can be mined and identified. Through the analysis of host operation logs, internal and external abnormal behaviors can be accurately and efficiently identified, which is beneficial to the early warning and control of risk events and ensures the continuous and stable operation of the business system. The behaviors of host operation logs include: analyzing the behaviors of on-site operations through logs, and performing statistics and analysis on relevant data to discover the patterns of user behaviors under the condition of obtaining basic data.
[0003] In the existing behavior analysis of host operation logs, due to the lack of in-depth correlation analysis and mining analysis models, it is impossible to perform forward and backward correlation analysis and behavior intention analysis on the behaviors of host operations, resulting in the inability to timely identify and discover the compliance and security risks of host operation behaviors. Therefore, there are problems such as untimely security audit analysis and insufficient depth of audit analysis, which affect the security and stability of the system and pose security risks during the operation of important business hosts. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a behavior extraction and analysis device based on host operation logs, which can analyze the relationships and trends between data, thereby revealing possible attack patterns or abnormal behaviors of host operations, and helping to more accurately identify complex attacks and advanced persistent threats.
[0005] The technical solution adopted by the present invention to solve the above technical problem is to provide a behavior extraction and analysis device based on host operation logs, including a clustering and slicing processing module for processing the input clustered data, extracting single-operation behavior descriptions of each cluster, processing the clusters based on the single-operation behavior descriptions, and fusing the clusters with behavior coherence to obtain cluster slices; an intention analysis model for analyzing the cluster slices based on the single-operation behavior descriptions, analyzing the user's behavior pattern from the overall behavior, and further obtaining the user's intention; and an intention analysis result processing module for identifying the intention analysis result output by the intention analysis model and giving an alarm if the intention analysis result is abnormal.
[0006] Further, the acquisition of the clustered data is as follows: Analyze the log data to obtain the behavior time of user behavior, form a cluster of user behaviors with continuous behavior time into a single cluster, and further obtain the clustered data.
[0007] Further, the extraction process of the single operation behavior description of each cluster i is as follows: Input cluster i into a pre-trained intention analysis model, identify the behavior intention of cluster i, and extract the keyword of the intention to form a single operation behavior description composed of keywords.
[0008] Further, the clustered slice processing module further includes determining the central cluster of each clustered slice according to the situation of the behavior intention, and further obtaining an initial clustered slice with only the central cluster.
[0009] Further, the determination process of the central cluster is as follows: (i) By identifying the single operation behavior description of each cluster, determine whether each single operation behavior description is a description of an abnormal intention; (ii) Determine the clusters corresponding to the single operation behavior descriptions of each abnormal intention as the central clusters; (iii) Form a positive cluster set of the clusters corresponding to the single operation behavior descriptions of all normal intentions; (iv) In the positive cluster set, calculate the similarity between the intention of each cluster and the intentions of other clusters; (v) Calculate the weight of each cluster; (vi) Select the cluster with the smallest weight as the central cluster.
[0010] Further, the clustered sharding is formed by fusing the central clusters of the initial clustered slices according to the coherence between the clusters, specifically including: calculating the feature similarity between the operation features of the clusters of each non-central cluster and the operation features of other clusters, and further obtaining the coherence between them according to the similarity; if the cluster with the greatest coherence with the clusters of any non-central cluster is the central cluster, then fuse the cluster with the cluster with the greatest coherence.
[0011] Further, if the cluster with the greatest coherence with the clusters of any non-central cluster is a non-central cluster, obtain the coherence between it and each central cluster, update the coherence between each central cluster, if the maximum value of the updated coherence is the central cluster, then fuse the cluster with the cluster with the greatest coherence, otherwise, the cluster is a new central cluster, and further form a new clustered slice.
[0012] Further, after the intention analysis model performs intention analysis on a single cluster, the analysis result is returned to the clustered slice processing module, so that the clustered slice processing module obtains the single operation behavior description of each cluster according to the single cluster intention analysis result; at the same time, the analysis result is input into the intention analysis result processing module for analysis to determine whether it is a description of an abnormal intention, and this analysis result will be returned to the clustered slice processing module.
[0013] Further, the intention analysis model is a BERT model.
[0014] Further, the alarm of the intention analysis result processing module includes a user identifier, an operation set involved in the clustered slice corresponding to the abnormal intention, and the corresponding intention.
[0015] The present invention has the following beneficial effects compared with the prior art: The behavior extraction and analysis device based on host operation logs provided by the present invention not only analyzes the log data itself, but also analyzes the relationships and trends between the data, so as to reveal possible attack patterns or abnormal behaviors in host operations. It not only focuses on single security events, but also understands the security trends of the entire business environment through correlation analysis, correlates isolated events, and establishes baselines for user historical business behaviors and group user access and operation behaviors through algorithms, predicts and discovers users' abnormally high-risk behaviors, and forms a complete attack scenario, which helps to more accurately identify complex attacks and advanced persistent threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a schematic diagram of the architecture of the behavior extraction and analysis device based on host operation logs of the present invention; Figure 2 is a schematic diagram of the implementation process of the clustering and slicing module of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0017] The present invention will be further described below with reference to the drawings and embodiments.
[0018] Figure 1 is a schematic diagram of the architecture of the behavior extraction and analysis device based on host operation logs of the present invention.
[0019] Please refer to Figure 1 , the behavior extraction and analysis device based on host operation logs provided by the present invention can analyze the clustered data through a clustering and slicing processing module, an intention analysis model, and an intention analysis result processing module to obtain an intention analysis result.
[0020] The detailed implementation processes of each part will be described below: 1. Clustered data The clustered data is the input data of the present invention, and this data can be obtained by existing methods.
[0021] For example, by analyzing the log data to obtain the behavior time of user behavior, a cluster of user behaviors with continuity in the behavior time is formed into a cluster, and then the clustered data is obtained.
[0022] In specific implementation, the clustered data can be stored in a database first, and when implementing the method of the present invention, the clustered data can be read from this database.
[0023] The clustered data will be input into the intention analysis model simultaneously to obtain the behavior intention of each cluster, and into the cluster slicing processing module to fuse the clusters to obtain cluster slices.
[0024] 2. Cluster slicing processing module The cluster slicing processing module is mainly used to process the input clustered data. This processing process includes extracting the single-operation behavior descriptions of each cluster, fusing the clusters based on the single-operation behavior descriptions, and fusing the clusters with behavior coherence to obtain cluster slices.
[0025] The implementation process of the cluster slicing processing module is as Figure 2 shown; it includes the following processing steps: Step S1: Extract the single-operation behavior descriptions of each cluster.
[0026] The single-operation behavior description is a description of the user intention represented by the behavior of this cluster.
[0027] For any cluster i, the extraction process of its single-operation behavior description is as follows: Input cluster i into the pre-trained intention analysis model, identify the behavior intention of cluster i, and extract keywords such as the subject, predicate, and object of the intention to form a single-operation behavior description composed of keywords.
[0028] For example, the single-operation behavior description is that user A performed operation D on object C at time B, and the operation was successful.
[0029] Step S2: Form initial cluster slices according to the single-operation behavior descriptions.
[0030] Each cluster slice represents an overall behavior intention. For each abnormal intention, a cluster slice will be formed, and multiple cluster slices will also be formed among the normal intentions. Step S2 will determine the central cluster of each cluster slice according to the situation of the behavior intention, and then obtain the initial cluster slice with only the central cluster.
[0031] The method for determining the central cluster is as follows: (i) By identifying the single-operation behavior descriptions of each cluster, determine whether each single-operation behavior description is a description of an abnormal intention.
[0032] The judgment result here is obtained through the intention analysis result processing module. That is, after the intention analysis model performs intention analysis on a single cluster, on the one hand, the analysis result is returned to the cluster slicing processing module so that the cluster slicing processing module can obtain the single-operation behavior description of each cluster according to the single-cluster intention analysis result. On the other hand, the analysis result will be input into the intention analysis result processing module for analysis to determine whether it is a description of an abnormal intention, and this analysis result will be returned to the cluster slicing processing module.
[0033] (ii)Determine each cluster corresponding to the single operation behavior description of each abnormal intention as the central cluster.
[0034] (iii)Form a set of positive clusters with all the clusters corresponding to the single operation behavior descriptions of normal intentions.
[0035] (iv)In the set of positive clusters, calculate the similarity between the intention of each cluster and the intentions of other clusters.
[0036] (v)Calculate the weight of each cluster.
[0037] (vi)The cluster with the smallest weight is used as the central cluster.
[0038] Step S3: Cluster and fuse the central clusters of the initial cluster slices according to the coherence between the clusters to form the final cluster slices.
[0039] (i)Calculate the feature similarity between the operation characteristics of each non - central cluster and those of other clusters, and then obtain the coherence between them according to the similarity.
[0040] (ii)If the cluster with the maximum coherence with any non - central cluster is the central cluster, then fuse this cluster with the cluster with the maximum coherence.
[0041] If the cluster with the maximum coherence with any non - central cluster x is not a central cluster, then obtain the coherence between it and each central cluster, update the coherence between it and each central cluster to. If the maximum value of the updated coherence is a central cluster, then fuse the cluster with the cluster with the maximum coherence; otherwise, the cluster becomes a new central cluster, and then a new cluster slice is formed.
[0042] After executing step S3, all the clusters can be fused according to the coherence to obtain multiple cluster slices.
[0043] A cluster slice is composed of multiple clusters with coherence, which can reflect a user's behavior pattern.
[0044] 3. Intention analysis model The cluster slices obtained by the cluster slice processing module are input into the intention analysis model. At the same time, the single operation behavior descriptions of each cluster in the cluster slices are also input into the intention analysis model to provide auxiliary parameters for the intention analysis of the intention analysis model.
[0045] The intention analysis model is a trained large - scale model. This model can analyze the cluster slices based on the single operation behavior descriptions, understand the user's behavior pattern from the overall behavior, and then accurately obtain the user's intention.
[0046] The large model can be any existing big data model. For example, it can be implemented using the BERT model (Bidirectional Encoder Representations from Transformers). The large model extracts features for each operation behavior in each cluster, analyzes the intent reflected by the extracted features, and outputs the intent.
[0047] Since multiple behaviors in the cluster slices can reflect the unique intent of the user, the intent analysis model conducts intent analysis based on the cluster slices, which can overall reflect the true intent of the user and obtain accurate intent analysis results.
[0048] In addition, the intent analysis model also conducts intent analysis on the clustered data, and the clustered intent analysis results will be transmitted to the cluster slice processing module for subsequent cluster fusion.
[0049] 4. Intent Analysis Result Processing Module The intent analysis result processing module identifies the intent analysis results output by the intent analysis model. If the intent analysis results (including the abnormal analysis results of clusters and the abnormal analysis results of cluster slices) are abnormal, an alarm will be issued, including the user identification, the operation set involved in the cluster slice corresponding to the abnormal intent, and the corresponding intent.
[0050] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications and improvements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be defined by the claims.
Claims
1. An apparatus for behavior extraction and analysis based on host operation logs, characterized in that Including: A clustering slice processing module, which is used to process the input clustering data, extract the single operation behavior descriptions of each cluster, process the clusters based on the single operation behavior descriptions, and fuse the clusters with behavioral coherence to obtain cluster slices; An intention analysis model, which analyzes the cluster slices based on the single operation behavior descriptions, analyzes the user's behavior pattern from the overall behavior, and then obtains the user's intention; An intention analysis result processing module, which identifies the intention analysis result output by the intention analysis model, and issues an alarm if the intention analysis result is abnormal.
2. The behavior extraction and analysis device based on the host operation log according to claim 1, characterized in that, The acquisition of the clustering data is as follows: analyze the log data to obtain the behavior time of the user behavior, form a cluster of user behaviors with continuity in the behavior time as a cluster, and then obtain the clustering data.
3. The behavior extraction and analysis device based on the host operation log according to claim 1, characterized in that, The extraction process of the single operation behavior description of each cluster i is as follows: input cluster i into a pre-trained intention analysis model, identify the behavior intention of cluster i, and extract the keyword of the intention to form a single operation behavior description composed of keywords.
4. The behavior extraction and analysis device based on the host operation log according to claim 1, characterized in that The clustering slice processing module further includes determining the central cluster of each clustering slice according to the situation of the behavior intention, and then obtaining an initial clustering slice with only the central cluster.
5. The behavior extraction and analysis device based on the host operation log according to claim 4, wherein The determination process of the central cluster is as follows: (i) By identifying the single operation behavior descriptions of each cluster, determine whether each single operation behavior description is a description of an abnormal intention; (ii) Determine the clusters corresponding to the single operation behavior descriptions of each abnormal intention as the central clusters; (iii) Form a positive cluster set of the clusters corresponding to the single operation behavior descriptions of all normal intentions; (iv) In the positive cluster set, calculate the similarity between the intention of each cluster and the intentions of other clusters; (v) Calculate the weight of each cluster; (vi) Select the cluster with the smallest weight as the central cluster.
6. The behavior extraction and analysis device based on the host operation log according to claim 4, characterized in that, The cluster slices are formed by fusing the central clusters of the initial clustering slices according to the coherence between the clusters, specifically including: Calculate the feature similarity between the operation features of the cluster of each non-central cluster and the operation features of other clusters, and then obtain the coherence between the two according to the similarity; If the cluster with the greatest coherence with the cluster of any non-central cluster is the central cluster, then fuse the cluster with the cluster with the greatest coherence.
7. The behavior extraction and analysis device based on the host operation log according to claim 6, characterized in that, If the cluster with the greatest coherence with the cluster of any non-central cluster is a non-central cluster, obtain the coherence between it and each central cluster, update the coherence between it and each central cluster. If the maximum value of the updated coherence is the central cluster, then fuse the cluster with the cluster with the greatest coherence, otherwise, the cluster is a new central cluster, and then form a new clustering slice.
8. The behavior extraction and analysis device based on the host operation log according to claim 1, wherein After the intention analysis model analyzes the single cluster for intention, it returns the analysis result to the clustering slice processing module, so that the clustering slice processing module can obtain the single operation behavior description of each cluster according to the single cluster intention analysis result; at the same time, the analysis result is input into the intention analysis result processing module for analysis to determine whether it is a description of an abnormal intention, and this analysis result will be returned to the clustering slice processing module.
9. The behavior extraction and analysis device based on the host operation log according to claim 1, wherein, The intention analysis model is a BERT model.
10. The behavior extraction and analysis device based on the host operation log according to claim 1, characterized in that, The alarm of the intention analysis result processing module includes the user identifier, the operation set involved in the cluster slice corresponding to the abnormal intention, and the corresponding intention.