Computer terminal user and software exception identification method
By capturing and standardizing the static and dynamic behavior characteristics of computer terminals, combined with supervised learning models, the insufficient identification of unknown threats in the prior art is solved, and more efficient anomaly detection and lower false alarm rates are achieved.
Patent Information
- Application Number
- CN202311830287.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-25
AI Technical Summary
Existing computer terminal security detection relies too much on static rules and prior knowledge, making it difficult to identify unknown threats, especially unknown viruses and dynamic threats.
By capturing the terminal's static and dynamic user and software behavior feature vectors, integrating and standardizing, establishing a supervised learning model, and using historical data to train the feature exception recognition model, and using support vector machine algorithm for exception recognition.
Improve detection capabilities for unknown threats, reduce false positive rates, adapt to dynamic and unknown security threats, and reduce dependence on static rules.
Smart Images

Figure CN120372608A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer science. Background Art
[0002] In the field of computer terminal security, the existing technologies mainly rely on rule engines and feature-matching-based methods. The limitations of these methods are mainly reflected in the following aspects: 1. Limited static rules: Static rules are a predefined set of rules used to detect specific security threats or abnormal behaviors. However, due to the formulation of static rules being limited by prior knowledge, it is difficult to cover all possible security threat scenarios. The emergence of new threats requires manual rule updates, and this process may lag behind the changes in threats. Dependence on prior knowledge: 2. Rule engines and feature-matching methods usually need to rely on prior knowledge, that is, information about normal and abnormal behaviors predefined in the system. This dependence causes the system to be difficult to adapt to unknown threats because new threats are often not in the prior knowledge base. 3. Inability to adapt to dynamic and unknown threats: Static rules and feature-matching-based methods perform poorly in the face of dynamic and unknown threats. Since these methods usually lack the ability to understand context and learn, the detection effect for new threats is limited.
[0003] One manifestation of the above limitations is anti-virus software based on feature matching. Traditional anti-virus software usually uses a virus signature database for feature matching and can only detect known viruses, while it is unable to accurately identify unknown viruses. In this way, the computer is easily threatened by virus variants and unknown viruses during operation. Summary of the Invention
[0004] The present invention aims to solve the problem that the existing computer terminal security detection overly relies on static rules and prior knowledge and is unable to accurately identify unknown threats. Now, a method for identifying computer terminal user and software anomalies is provided.
[0005] The method for identifying computer terminal user and software anomalies according to the present invention includes:
[0006] Step 1, capturing static and dynamic user and software behavior feature vectors of the terminal;
[0007] Step 2, integrating and normalizing the captured feature vectors;
[0008] Step 3, establishing a supervised learning model and training the supervised learning model using historical user and software behavior feature vectors and corresponding fault data to obtain a feature anomaly recognition model;
[0009] Step 4, using the anomaly recognition model to identify the integrated and normalized feature vectors to determine whether there are anomalies in the computer terminal user and software.
[0010] Further, in the present invention, in step one, the static and dynamic user and software behavior feature vectors of the terminal include:
[0011] The static user and software behavior feature vectors of the terminal include: file system and registry information on the terminal, information on running programs and services, and user configuration information;
[0012] The file system and registry information includes: information on the creation, modification, and deletion of files and the registry;
[0013] The information on running programs and services includes: version numbers, startup times, and network connection information of running programs;
[0014] The user configuration information includes: browser bookmarks, desktop layout, and application setting information;
[0015] The dynamic user and software behavior feature vectors include: system call information, communication and networking information between applications and users, keyboard and mouse operation information, and memory occupancy information of applications and users.
[0016] Further, in the present invention, after step four, it further includes storing the input feature vectors and recognition results, establishing a database, and regularly training the feature anomaly recognition model with the input feature vectors and recognition results in the database.
[0017] The method of the present invention can more efficiently detect abnormal behaviors of the terminal and improve security through the knowledge base established by machine learning. It adapts to dynamic and unknown security threats and avoids over-reliance on static rule engines. The training of the machine learning model makes the classification of normal and abnormal behaviors more accurate and reduces the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0020] DETAILED DESCRIPTION OF THE EMBODIMENT 1: Refer to Figure 1Specifically describing this embodiment, the computer terminal user and software anomaly recognition method described in this embodiment includes:
[0021] Step 1: Capture static and dynamic user and software behavior feature vectors of the terminal;
[0022] Step 2: Integrate and standardize the captured feature vectors;
[0023] Step 3: Establish a supervised learning model, and use historical user and software behavior feature vectors and corresponding fault data to train the supervised learning model to obtain a feature anomaly recognition model;
[0024] Step 4: Use the anomaly recognition model to identify the integrated and standardized feature vectors to determine whether there are anomalies in the computer terminal user and software.
[0025] In the present invention, after integrating and standardizing the features, representative anomaly features can be selected according to vector correlation or time series, which can be abnormal login or operation time, abnormal access, etc. For example, for various captured features, correlation analysis is performed to select features strongly correlated with abnormal behaviors. So as to use machine learning algorithms later to evaluate the relevance between features and anomalies, thereby excluding features that do not contribute significantly to the model. If the user and software behaviors have the nature of time series, then time-related features can be extracted, such as the frequency and change trend of behaviors.
[0026] Further, in the present invention, in Step 1, the static and dynamic user and software behavior feature vectors of the terminal include:
[0027] The static user and software behavior feature vectors of the terminal include: file system and registry information on the terminal, information on running programs and services, and user configuration information;
[0028] The file system and registry information includes: information on the creation, modification, and deletion of files and registries;
[0029] The information on running programs and services includes: version numbers, startup times, and network connection information of running programs;
[0030] The user configuration information includes: browser bookmarks, desktop layout, and application setting information;
[0031] The dynamic user and software behavior feature vectors include: system call information, communication and networking information between applications and users, keyboard and mouse operation information, and memory occupancy information of applications and users.
[0032] Further, in the present invention, after step four, it further includes storing the input feature vector and the recognition result, establishing a database, and regularly training the feature anomaly recognition model with the input feature vector and the recognition result in the database.
[0033] The method of the present invention first captures a large number of static and dynamic user and software behavior feature vectors of the terminal;
[0034] The capture of static user and software behavior feature vectors includes:
[0035] File and registry analysis: By scanning and analyzing the file system and registry on the terminal, record operations such as the creation, modification, and deletion of files and the registry, as well as information related to software and user behavior.
[0036] Collection of program and service information: Obtain information about the programs and services running on the terminal, including version numbers, startup times, network connections, etc., for constructing static feature vectors.
[0037] Analysis of user configuration files: Analyze user configuration files, including but not limited to browser bookmarks, desktop layouts, application settings, etc., to obtain information about user preferences and behavior.
[0038] The capture of dynamic user and software behavior feature vectors includes:
[0039] System call monitoring: By monitoring system calls on the terminal, record program access to system resources, file operations, network communications, etc., to obtain dynamic behavior information.
[0040] Network traffic analysis: Analyze the network traffic on the terminal, capture the communication patterns between applications and users, and the establishment and closing processes of network connections.
[0041] Keyboard recording and mouse tracking: Record the user's keyboard input and mouse operations to obtain the user's interaction behavior with the software, such as the commands entered and the buttons clicked.
[0042] Memory analysis: Monitor the memory usage on the terminal, capture the runtime information of the program, including variable values, function calls, etc., to identify potential abnormal behaviors.
[0043] Integrating static and dynamic information:
[0044] Data integration and standardization: Integrate and standardize the captured static and dynamic information to construct a consistent feature vector representation.
[0045] Feature selection and extraction: Through feature selection algorithms and feature extraction methods, select the most representative and discriminative features to construct the final user and software behavior feature vectors.
[0046] Then, machine learning is used to train and model the end-users and software behaviors;
[0047] Clean the historical data, process the potentially existing abnormal or inconsistent data to ensure data quality. Then label and mark the data, classifying normal and abnormal behaviors.
[0048] The present invention will adopt the Support Vector Machine (SVM) algorithm in the supervised learning model for training. SVM performs excellently in high-dimensional spaces and is suitable for datasets with a large number of features. Divide the dataset into a training set and a test set, and use the labeled data to conduct supervised learning training on the model. Combining the strong generalization ability of SVM when dealing with unseen data, identify abnormal behaviors. Then adjust the hyperparameters of the model through methods such as cross-validation to improve the model performance. Finally, evaluate and optimize the performance of the model based on accuracy, precision, and recall.
[0049] Conduct classification detection to establish a knowledge base of normal and abnormal behaviors of users and software in the usage scenarios;
[0050] Classify the samples in the test set and analyze the classification effect of the model on normal and abnormal behaviors. Store the results of model training and testing as a knowledge base, including information such as the weights of features and classification rules. In actual applications, continuously monitor the performance of the model to ensure its adaptability to new data. As the system runs, continuously update the knowledge base according to the actual performance to keep it adaptable to new data.
[0051] Utilize the knowledge base to efficiently detect abnormal behaviors of the terminal:
[0052] Match the features to be detected captured from the terminal with the features in the knowledge base, and use the rules and models defined in the knowledge base for anomaly detection. Generate a detailed report for the detected abnormal behaviors, including time, behavior features, detection results, etc.
[0053] In terms of static data capture, the present invention can perform scanning and collection through the file system and group policy monitoring tools; use system commands or relevant APIs to obtain information about running programs and services; extract user configuration file information by reading the configuration files in the user directory or using relevant APIs.
[0054] In terms of dynamic data capture: Use system call monitoring tools to capture information such as program access to system resources, file operations, and network communications; use network traffic monitoring tools to analyze the network traffic on the terminal and capture the communication patterns between applications and users; record the user's keyboard input and mouse operations through a keyboard and mouse event listener program; use memory analysis tools to monitor the memory usage on the terminal and capture the runtime information of programs.
[0055] Store the results of model training and testing as a knowledge base, including information such as the weights of features, classification rules, etc., and a structured database such as MySQL can be used.
[0056] Although the present invention has been described herein with reference to specific embodiments, it should be understood that these embodiments are merely examples of the principles and applications of the present invention. Therefore, it should be understood that many modifications can be made to the exemplary embodiments, and other arrangements can be designed, as long as they do not depart from the spirit and scope of the present invention as defined by the appended claims. It should be understood that the different dependent claims and the features described herein can be combined in a manner different from that described in the original claims. It should also be understood that the features described in connection with a single embodiment can be used in other described embodiments.
Claims
1. A method for identifying computer terminal users and software anomalies, characterized in that, Including: Step 1: Capture the static and dynamic user and software behavior feature vectors of the terminal; Step 2: Integrate and standardize the captured feature vectors; Step 3: Establish a supervised learning model, and use the historical user and software behavior feature vectors and the corresponding fault data to train the supervised learning model to obtain a feature anomaly recognition model; Step 4: Use the anomaly recognition model to identify the integrated and standardized feature vectors to determine whether there are anomalies in the computer terminal users and software.
2. The computer terminal user and software anomaly recognition method according to claim 1, wherein In Step 1, the static and dynamic user and software behavior feature vectors of the terminal include: The static user and software behavior feature vectors of the terminal include: file system and registry information on the terminal, information on running programs and services, and user configuration information; The file system and registry information includes: information on the creation, modification, and deletion of files and registries; The information on running programs and services includes: version numbers, startup times, and network connection information of running programs; The user configuration information includes: browser bookmarks, desktop layouts, and application setting information; The dynamic user and software behavior feature vectors include: system call information, communication and networking information between applications and users, keyboard and mouse operation information, and memory occupancy information of applications and users.
3. The computer terminal user and software anomaly recognition method according to claim 1, characterized in that, After Step 4, it further includes the steps of storing the input feature vectors and recognition results, establishing a database, and periodically training the feature anomaly recognition model with the input feature vectors and recognition results in the database.