Internal threat detection method, system and equipment based on behavior analysis and medium

By obtaining multimodal data and using graph neural networks and reinforcement learning to generate user behavior graphs, dynamically identifying abnormal behaviors, the problem of difficulty in adapting to dynamic threats in the existing technology is solved, and efficient and accurate internal threat detection and rapid response are achieved.

CN120408442AInactive Publication Date: 2025-08-01SHENZHEN TG NET BOTONE TECH
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510500708.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-08-01
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing internal threat detection technologies are difficult to adapt efficiently and accurately to dynamic and unknown internal threats, resulting in high false alarm rates and underreporting problems.

Method used

By obtaining multimodal data of the user's operating environment, using the time window mechanism for timing alignment, combining graph neural network and reinforcement learning methods, user behavior graphs and anomaly detection models are generated, abnormal behaviors are dynamically identified, and response strategies are generated based on trust scores.

Benefits of technology

It realizes efficient modeling of complex behavioral scenarios, dynamically identify potential threats, reduces security risks, and improves the accuracy and response speed of abnormal detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408442A_ABST
    Figure CN120408442A_ABST
Patent Text Reader

Abstract

The invention relates to an internal threat detection method, system and device based on behavior analysis and a medium, and the method comprises the steps: obtaining multi-modal data of a user operation environment, carrying out the time sequence alignment of the multi-modal data based on a time window mechanism, generating a multi-modal feature data set, and constructing a dynamic behavior model in combination with the context information of user behaviors. Performing secondary modeling on the dynamic behavior model by using a graph neural network to generate a user behavior graph; generating an adversarial network based on the user behavior graph so as to generate simulated threat behavior data, and dynamically generating a behavior anomaly detection model by using a reinforcement learning method in combination with the simulated threat behavior data and the user behavior graph; performing threat detection according to the user behavior anomaly detection model, identifying an abnormal behavior, and generating a threat detection result; and calculating a trust score according to the threat detection result, and generating a response priority strategy based on the trust score to execute a response operation on the abnormal behavior. The method has the effect of improving the internal threat detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network security, and in particular, to an internal threat detection method, system, device, and medium based on behavior analysis. Background Art

[0002] Currently, with the in-depth development of informatization and the advancement of enterprise digital transformation, internal threats have become an important issue in network security. Internal threat detection refers to the analysis of user behavior and operating environment to identify abnormal behaviors that may threaten enterprise information security. This detection is usually used to discover malicious users, misoperations, or information leakage behaviors, thereby protecting the core data and system security of enterprises.

[0003] Existing internal threat detection technologies usually adopt a rule-based approach, comparing user behavior with preset rules to determine whether the behavior is abnormal. However, the rule-based approach relies on a set of manually defined rules, which are difficult to cover all possible threat scenarios. Moreover, in the face of dynamic and complex user behaviors, these rules often cannot adapt to new threat patterns, easily leading to high false positive rates and missed detection problems.

[0004] The above existing technical solutions have the following defects: Most of the existing internal threat detection technologies are based on preset rules for determination, and it is difficult to efficiently and accurately adapt to dynamic and unknown internal threats. Therefore, there is room for improvement. Summary of the Invention

[0005] In order to improve the detection efficiency of internal threats, the present application provides an internal threat detection method, system, device, and medium based on behavior analysis.

[0006] The first invention object of the present application is achieved through the following technical solutions: An internal threat detection method based on behavior analysis, the internal threat detection method based on behavior analysis includes: Obtain multimodal data of the user operating environment, and perform temporal alignment on the multimodal data based on a time window mechanism to generate a unified multimodal feature dataset; Input the multimodal feature dataset into a context-aware modeling module, combine the context information of the user behavior, construct a dynamic behavior model, and use a graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph; Based on the user behavior graph, generate simulated threat behavior data through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and use a reinforcement learning method to dynamically generate a behavior anomaly detection model; Perform threat detection on the multi-modal feature data collected in real time according to the user behavior anomaly detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors; According to the threat detection results, calculate the trust scores of the user and the device, and generate a response priority policy based on the trust scores to perform response operations on abnormal behaviors.

[0007] By adopting the above technical solutions, by obtaining the multi-modal data of the user operation environment and performing temporal alignment on the multi-modal data based on the time window mechanism to generate a unified multi-modal feature data set, it is possible to comprehensively obtain the dynamic behavior characteristics of the user in the operation environment and perform time alignment, ensuring the consistency of multi-source data in the unified time dimension, thereby providing a complete and accurate data basis for subsequent behavior modeling and threat detection; by inputting the multi-modal feature data set into the context-aware modeling module, combining the context information of the user behavior, constructing a dynamic behavior model, and using a graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph, it is possible to capture the complex relationship between the user behavior characteristics and the context, and use global correlation analysis to identify potential abnormal behavior patterns, thereby effectively improving the modeling ability for complex behavior scenarios; by generating simulated threat behavior data through a generative adversarial network based on the user behavior graph, combining the simulated threat behavior data with the user behavior graph, and using a reinforcement learning method to dynamically generate a behavior anomaly detection model, it is possible to dynamically simulate and identify potential abnormal behavior patterns, and iteratively optimize the accuracy and adaptability of the detection model through reinforcement learning, thereby improving the detection ability and dynamic response ability for unknown threats; by performing threat detection on the multi-modal feature data collected in real time according to the user behavior anomaly detection model, identifying abnormal behaviors, and generating threat detection results based on the abnormal behaviors, it is possible to monitor the user behavior in real time and quickly identify abnormal behaviors, thereby responding in a timely manner at the early stage of the threat occurrence and effectively reducing the security risk.

[0008] In one example, the present application can be further configured as: inputting the multi-modal feature data set into the context-aware modeling module, combining the context information of the user behavior, constructing a dynamic behavior model, and using a graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph, specifically including: Extract the feature information of the user behavior from the multi-modal feature data set, and associate the feature information with the context information; Based on the context-aware mechanism, calculate the weights of the interaction between the feature information and the context information, and generate a behavior representation with time dynamic characteristics according to the calculation results, and further obtain the dynamic behavior model; Convert the dynamic behavior model into a node representation form, where the nodes represent behavior characteristics and the edges represent context interaction relationships; Using the multi - layer propagation mechanism of the graph neural network, aggregate the features of the nodes to generate the user behavior graph containing the global association of user behaviors.

[0009] By adopting the above - mentioned technical solution, by extracting the feature information of user behaviors from the multi - modal feature dataset and correlating the feature information with the context information, it is possible to comprehensively integrate the user behavior data and the context information of the operating environment, ensure a high degree of consistency between the behavior features and the environmental features, thereby improving the accuracy of behavior modeling; by based on the context - awareness mechanism, calculate the weights for the interaction between the feature information and the context information, and according to the calculation results, generate a behavior representation with time - dynamic characteristics, and then obtain a dynamic behavior model, which can dynamically capture the laws of behavior feature changes over time, mine the complex association relationships between operation behaviors and the context, thereby enhancing the description ability of the behavior model for dynamic behavior scenarios; by converting the dynamic behavior model into a node representation form, where the nodes represent behavior features and the edges represent context interaction relationships, it is possible to intuitively express the relationship between user behavior features and context interactions in a graph - structure manner, thereby improving the organization of behavior data and the flexibility of modeling; by using the multi - layer propagation mechanism of the graph neural network to aggregate the features of nodes and generate a user behavior graph containing the global association of user behaviors, it is possible to capture the high - order associations between local behaviors and global behaviors, thereby greatly improving the depth of behavior modeling and the accuracy of threat detection.

[0010] In one example, this application can be further configured as follows: based on the user behavior graph, generate simulated threat behavior data through a generative adversarial network, and combine the simulated threat behavior data with the user behavior graph, and use the reinforcement learning method to dynamically generate a behavior anomaly detection model, which specifically includes: Use the adversarial network generator to randomly perturb the user behavior graph to simulate abnormal behavior patterns and obtain user behavior simulation data; Use the adversarial network discriminator to screen the user behavior simulation data and retain the user behavior simulation data that meets the preset confidence requirement as the reinforcement learning data; Based on the user behavior graph and the reinforcement learning data, define a reward function, and then iteratively train the threat detection strategy through the reinforcement learning framework to generate the behavior anomaly detection model.

[0011] By adopting the above technical solution, by using the adversarial network generator to randomly perturb the user behavior graph, simulating abnormal behavior patterns, and obtaining user behavior simulation data, it is possible to generate abnormal behavior data with high credibility based on the global correlation information of user behavior, thereby providing diverse threat scenarios for subsequent model optimization; by using the adversarial network discriminator to screen the user behavior simulation data and retaining the user behavior simulation data that meets the preset confidence requirement as the reinforcement learning data, it is possible to effectively filter out low-quality or unrealistic threat scenario simulation data, ensuring the quality and credibility of the training data, and thus improving the efficiency and accuracy of model optimization; by defining a reward function based on the user behavior graph and the reinforcement learning data, and then iteratively training the threat detection strategy through the reinforcement learning framework to generate a behavior anomaly detection model, it is possible to dynamically optimize the threat detection model so that it can adapt to different abnormal behavior patterns, thereby significantly improving the accuracy and dynamic adaptability of anomaly detection.

[0012] In one example, the present application can be further configured as follows: Defining a reward function based on the user behavior graph and the reinforcement learning data specifically includes: Performing behavior embedding representation on the abnormal behavior pattern of the reinforcement learning data and the normal behavior pattern of the user behavior graph, and calculating the Euclidean distance of the behavior embedding representation, that is, the behavior deviation degree; Calculating the correct rate of identifying abnormal behaviors of the behavior anomaly detection model, and then determining the abnormal behavior detection accuracy of the reward function; Calculating the false alarm rate of normal behaviors of the behavior anomaly detection model, and then determining the false alarm rate of the reward function; Performing weighted summation combination on the behavior deviation degree, the abnormal behavior detection accuracy, and the false alarm rate to obtain the reward function.

[0013] By adopting the above technical solution, through the behavioral embedding representation of the abnormal behavior pattern of the reinforcement learning data and the normal behavior pattern of the user behavior graph, and calculating the Euclidean distance and behavioral deviation degree of the behavioral embedding representation, the behavioral deviation degree can quantify the deviation degree between the abnormal behavior and the normal behavior, thereby providing an accurate basis for evaluating the behavioral difference for the reward function; by calculating the correct recognition rate of the abnormal behavior of the behavioral anomaly detection model and then determining the abnormal behavior detection accuracy of the reward function, the accurate recognition ability of the model for abnormal behavior can be evaluated, thereby strengthening the detection performance of the model for high-risk abnormal behavior; by calculating the false detection rate of the normal behavior of the behavioral anomaly detection model and then determining the false alarm rate of the reward function, the discrimination ability of the model for normal behavior can be evaluated, reducing the occurrence of false alarms, and thereby improving the applicability and reliability of the model in the actual scenario; by performing weighted summation combination on the behavioral deviation degree, abnormal behavior detection accuracy and false alarm rate to obtain the reward function, the detection accuracy and false alarm rate of the model can be balanced, and at the same time, the recognition ability of the model for abnormal behavior can be optimized, thereby realizing a threat detection model with the optimal comprehensive performance.

[0014] In one example, the present application can be further configured as: the threat detection of the multi-modal feature data collected in real time according to the user behavior anomaly detection model, identifying abnormal behavior, and generating a threat detection result based on the abnormal behavior, specifically including: Embedding the multi-modal feature data collected in real time into the corresponding user behavior graph and inputting it into the user behavior anomaly detection model; According to the threat detection strategy preset in the threat detection model, judging whether the user behavior deviates from the normal mode, and assigning a threat level label to the abnormal behavior to obtain the threat detection result.

[0015] By adopting the above technical solution, by embedding the multi-modal feature data collected in real time into the corresponding user behavior graph and inputting it into the user behavior anomaly detection model, the current behavior characteristics of the user can be captured in real time and dynamically matched with the historical behavior graph, thereby improving the accuracy of real-time threat detection; by judging whether the user behavior deviates from the normal mode according to the threat detection strategy preset in the threat detection model, and assigning a threat level label to the abnormal behavior to obtain the threat detection result, a quantitative threat assessment result can be provided for the abnormal behavior according to the degree of behavior deviation, thereby providing a clear risk reference basis for the subsequent response strategy.

[0016] In one example, the present application can be further configured as: calculating the trust scores of the user and the device according to the threat detection result, and generating a response priority strategy based on the trust scores to execute the response operation for the abnormal behavior, specifically including: Define the calculation function of the trust score based on the consistency of the anomaly frequency and context information in the threat detection results, and dynamically adjust the weight ratio of the trust score, giving priority to reducing the trust score of users and devices with abnormal behaviors at a high threat level; According to the trust score, assign priorities to all abnormal behaviors in sequence, and set quick response rules for the abnormal behaviors whose priorities reach the preset danger level.

[0017] By adopting the above technical solutions, by defining the calculation function of the trust score based on the consistency of the anomaly frequency and context information in the threat detection results, and dynamically adjusting the weight ratio of the trust score, giving priority to reducing the trust score of users and devices with abnormal behaviors at a high threat level, it is possible to accurately evaluate the security status of users and devices, and give priority to marking high-risk objects, thereby providing a key decision-making basis for quick response; by assigning priorities to all abnormal behaviors in sequence according to the trust score, and setting quick response rules for the abnormal behaviors whose priorities reach the preset danger level, it is possible to ensure the priority handling of high-priority abnormal behaviors and quickly isolate potential threats, thereby significantly improving the response speed and handling effect of internal threats.

[0018] The second above-mentioned inventive object of this application is achieved through the following technical solutions: An internal threat detection system based on behavior analysis, the internal threat detection system based on behavior analysis includes: A data processing module, configured to obtain multimodal data of the user operation environment, and perform temporal alignment on the multimodal data based on a time window mechanism to generate a unified multimodal feature data set; A behavior modeling module, configured to input the multimodal feature data set into a context-aware modeling module, combine the context information of the user behavior, construct a dynamic behavior model, and perform secondary modeling on the dynamic behavior model by using a graph neural network to generate a user behavior graph; A threat detection model generation module, configured to generate simulated threat behavior data based on the user behavior graph through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and dynamically generate a behavior anomaly detection model by using a reinforcement learning method; An abnormal behavior detection module, configured to perform threat detection on the real-time collected multimodal feature data according to the user behavior abnormal detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors; A response decision module, configured to calculate the trust scores of users and devices according to the threat detection results, and generate a response priority policy based on the trust scores to execute response operations on abnormal behaviors.

[0019] By adopting the above technical solutions, by obtaining the multimodal data of the user operation environment and performing temporal alignment on the multimodal data based on the time window mechanism to generate a unified multimodal feature dataset, it is possible to comprehensively obtain the dynamic behavior characteristics of the user in the operation environment and perform time alignment, ensuring the consistency of multi-source data in the unified time dimension, thereby providing a complete and accurate data basis for subsequent behavior modeling and threat detection; by inputting the multimodal feature dataset into the context-aware modeling module, combining the context information of the user behavior, constructing a dynamic behavior model, and using the graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph, it is possible to capture the complex relationship between the user behavior characteristics and the context, and use global correlation analysis to identify potential abnormal behavior patterns, thereby effectively improving the modeling ability for complex behavior scenarios; by generating simulated threat behavior data based on the user behavior graph through the generative adversarial network, combining the simulated threat behavior data with the user behavior graph, and using the reinforcement learning method to dynamically generate a behavior anomaly detection model, it is possible to dynamically simulate and identify potential abnormal behavior patterns, and iteratively optimize the accuracy and adaptability of the detection model through reinforcement learning, thereby improving the detection ability and dynamic response ability for unknown threats; by performing threat detection on the real-time collected multimodal feature data according to the user behavior anomaly detection model, identifying abnormal behaviors, and generating threat detection results based on the abnormal behaviors, it is possible to monitor the user behavior in real time and quickly identify abnormal behaviors, thereby responding in a timely manner at the early stage of the threat occurrence and effectively reducing the security risk.

[0020] The above object three of the present application is achieved by the following technical solutions: A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above internal threat detection method based on behavior analysis are implemented.

[0021] The above object four of the present application is achieved by the following technical solutions: A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the above internal threat detection method based on behavior analysis are implemented.

[0022] In summary, the present application includes the following beneficial technical effects: 1. By obtaining the multi-modal data of the user's operating environment and performing temporal alignment on the multi-modal data based on the time window mechanism to generate a unified multi-modal feature dataset, it is possible to comprehensively obtain the dynamic behavior characteristics of the user in the operating environment and perform time alignment, ensuring the consistency of multi-source data in the unified time dimension, thereby providing a complete and accurate data basis for subsequent behavior modeling and threat detection; by inputting the multi-modal feature dataset into the context-aware modeling module, combining the context information of the user's behavior, constructing a dynamic behavior model, and using a graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph, it is possible to capture the complex relationship between the user's behavior characteristics and the context, and use global correlation analysis to identify potential abnormal behavior patterns, thereby effectively improving the modeling ability for complex behavior scenarios; by generating simulated threat behavior data based on the user behavior graph through a generative adversarial network, combining the simulated threat behavior data with the user behavior graph, and using a reinforcement learning method to dynamically generate a behavior anomaly detection model, it is possible to dynamically simulate and identify potential abnormal behavior patterns, and iteratively optimize the accuracy and adaptability of the detection model through reinforcement learning, thereby improving the detection ability and dynamic response ability for unknown threats; by performing threat detection on the real-time collected multi-modal feature data according to the user behavior anomaly detection model, identifying abnormal behaviors, and generating threat detection results based on the abnormal behaviors, it is possible to monitor the user's behavior in real time and quickly identify abnormal behaviors, thereby responding in a timely manner at the early stage of the threat occurrence and effectively reducing security risks. 2. By extracting the feature information of the user's behavior from the multi-modal feature dataset and associating the feature information with the context information, it is possible to comprehensively integrate the user's behavior data and the context information of the operating environment, ensuring a high degree of consistency between the behavior characteristics and the environmental characteristics, thereby improving the accuracy of behavior modeling; by calculating the weights of the interaction between the feature information and the context information based on the context-aware mechanism, and generating a behavior representation with time-dynamic characteristics according to the calculation results, and then obtaining a dynamic behavior model, it is possible to dynamically capture the law of the behavior characteristics changing with time, and explore the complex correlation between the operating behavior and the context, thereby enhancing the description ability of the behavior model for dynamic behavior scenarios; by converting the dynamic behavior model into a node representation form, where the nodes represent the behavior characteristics and the edges represent the context interaction relationships, it is possible to intuitively express the relationship between the user's behavior characteristics and the context interaction in the form of a graph structure, thereby improving the organization of behavior data and the flexibility of modeling; by using the multi-layer propagation mechanism of the graph neural network to aggregate the features of the nodes and generate a user behavior graph containing the global correlation of the user's behavior, it is possible to capture the high-order correlation between the local behavior and the global behavior, thereby greatly improving the depth of behavior modeling and the accuracy of threat detection. 3. By using the adversarial network generator to randomly perturb the user behavior graph and simulate abnormal behavior patterns, user behavior simulation data can be obtained, and high-confidence abnormal behavior data can be generated based on the global correlation information of user behavior, thereby providing diverse threat scenarios for subsequent model optimization; by using the adversarial network discriminator to screen the user behavior simulation data and retaining the user behavior simulation data that meets the preset confidence requirement as reinforcement learning data, low-quality or unrealistic threat scenario simulation data can be effectively filtered, ensuring the quality and credibility of the training data, and thus improving the efficiency and accuracy of model optimization; by defining a reward function based on the user behavior graph and the reinforcement learning data, and then iteratively training the threat detection strategy through the reinforcement learning framework to generate a behavior anomaly detection model, the threat detection model can be dynamically optimized to adapt to different abnormal behavior patterns, thereby significantly improving the accuracy and dynamic adaptability of anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a flowchart of a method for internal threat detection based on behavior analysis according to an embodiment of the present application; Figure 2 is a flowchart for implementing step S20 in the method for internal threat detection based on behavior analysis according to an embodiment of the present application; Figure 3 is a flowchart for implementing step S30 in the method for internal threat detection based on behavior analysis according to an embodiment of the present application; Figure 4 is a flowchart for implementing step S33 in the method for internal threat detection based on behavior analysis according to an embodiment of the present application; Figure 5 is a flowchart for implementing step S40 in the method for internal threat detection based on behavior analysis according to an embodiment of the present application; Figure 6 is a flowchart for implementing step S50 in the method for internal threat detection based on behavior analysis according to an embodiment of the present application; Figure 7 is a schematic block diagram of a principle of an internal threat detection system based on behavior analysis according to an embodiment of the present application; Figure 8 is a schematic diagram of a device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] The present application will be further described in detail below with reference to the accompanying drawings.

[0025] In one embodiment, as Figure 1 shown, the present application discloses a method for internal threat detection based on behavior analysis, which specifically includes the following steps: S10: Obtain the multimodal data of the user's operating environment, and perform temporal alignment on the multimodal data based on the time window mechanism to generate a unified multimodal feature dataset.

[0026] Specifically, the acquisition of multimodal data can be achieved by extracting raw data from the logs of the user's operating system, network traffic analysis module, device information collection module, and user input behavior analysis module. These raw data include, but are not limited to, operation records, network request behaviors, hardware characteristics of the device, and timestamps, etc. These data are divided into several time periods according to the set time window in chronological order, and synchronization and alignment processing are performed on multiple data sources within each time period. By standardizing each data type, the log information is converted into a classification coding form, the network traffic characteristics are converted into numerical vectors, the device characteristics are converted into attribute labels, and all the processed data are integrated into a unified format multimodal feature dataset.

[0027] S20: Input the multimodal feature dataset into the context-aware modeling module, combine the context information of the user's behavior, construct a dynamic behavior model, and use the graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph.

[0028] Specifically, by extracting features from the operation records and device characteristics in the multimodal feature dataset, associating the time when the operation occurs with the device environment where the operation is located, mapping the extracted feature information to a multi-dimensional vector space, analyzing the relationship between the operation and the context through the context-aware mechanism, and calculating the weights between the operation behavior and the context attributes; generating a behavior representation on the time series according to the weights, using the timestamp as the benchmark of the sequence, and dynamically adjusting the behavior representation at each time point, so as to generate a dynamic behavior model; converting the dynamic behavior model into a graph structure, where each operation behavior is used as a node in the graph, and each interaction of context information is used as an edge between nodes, and the edge weight in the graph structure is defined as the strength of the context interaction; using the graph neural network to perform multi-layer propagation on the graph structure, and aggregating the local features and global features of the nodes in the graph through the propagation mechanism, so as to generate a user behavior graph that can reflect the global association of the user's behavior.

[0029] S30: Based on the user behavior graph, generate simulated threat behavior data through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and use the reinforcement learning method to dynamically generate a behavior anomaly detection model.

[0030] Specifically, randomly perturb the generated user behavior graph. The perturbation includes randomly changing the eigenvalue of a node or adding or deleting edges in the graph to simulate abnormal behavior of users during operation and generate behavior data with potential threat patterns. Input the generated data into the discriminator of the generative adversarial network. The discriminator screens out high-quality threat behavior data that meets the preset criteria by scoring the quality of the simulated data. The screening criteria include whether the data conforms to the abnormal characteristics of the behavior pattern and the feasibility of the abnormal behavior in the actual scenario. Combine the screened high-quality threat behavior data with the original user behavior graph and input both into the reinforcement learning framework for training. By optimizing the reward function for abnormal behavior, the reinforcement learning framework gradually generates a behavior anomaly detection model that can accurately identify abnormal behavior.

[0031] S40: Perform threat detection on the real-time collected multi-modal feature data according to the user behavior anomaly detection model, identify abnormal behavior, and generate threat detection results based on the abnormal behavior.

[0032] Specifically, extract node features and calculate context relationships for the real-time collected multi-modal feature data in the same way as the user behavior graph, perform time series alignment on the real-time data through the same time window, and embed the processed real-time feature data into the node representation of the user behavior graph. Perform threat assessment on the embedded feature data through the user behavior anomaly detection model. The basis for the assessment is whether the node representation deviates from the distribution pattern of the normal behavior graph and whether the deviation degree exceeds the preset anomaly threshold. Assign a threat level label to each deviated behavior according to the detection result. The threat level label is divided according to the abnormal degree of the behavior and the possible influence range, and finally generate threat detection results including threat behavior types, levels, and context information.

[0033] S50: According to the threat detection results, calculate the trust scores of users and devices, and generate a response priority policy based on the trust scores to execute response operations for abnormal behavior.

[0034] Specifically, by extracting the threat level labels and context information in the threat detection results and combining with the historical behavior records of users and devices, calculate the trust scores of each user and device. The calculation basis of the trust scores includes the frequency of abnormal behavior occurrence, the cumulative value of the threat level, and the consistency between the operation environment and historical behavior. Dynamically adjust the trust scores to preferentially reduce the trust values of high-frequency abnormal behaviors or high-threat level behaviors. Assign response priorities to all threat behaviors according to the high and low trust scores. The basis for the priority division is the severity of the threat level and the low level of the trust score. Set fast response rules for threat behaviors that reach the preset danger level. The fast response rules include directly isolating relevant devices, reducing user permissions, or triggering security alarm notifications, so as to execute response operations for abnormal behavior.

[0035] In one embodiment, as Figure 2 shown, in step S20, the multimodal feature dataset is input into the context-aware modeling module, and combined with the context information of the user behavior, a dynamic behavior model is constructed, and the graph neural network is used to perform secondary modeling on the dynamic behavior model to generate a user behavior graph, specifically including: S21: Extract the feature information of the user behavior from the multimodal feature dataset, and associate the feature information with the context information.

[0036] Specifically, by parsing the operation record data in the multimodal feature data, the type, operation target, and operation time of the user operation are extracted, and the device type, operation environment attributes, and other context information where the operation occurs are extracted according to the device information. The operation behavior features and the context information are associated and matched. The matching methods include the correspondence of timestamps, the association of device attributes, and the similarity between the operation target and the context. The initial user behavior context feature pairs are generated through the matching results.

[0037] S22: Based on the context-aware mechanism, calculate the weights for the interaction between the feature information and the context information, and generate a behavior representation with time-dynamic characteristics according to the calculation results, and then obtain the dynamic behavior model.

[0038] Specifically, by constructing a context-aware matrix, the dependence relationship between the feature information and the context information is quantified. The weight of the dependence relationship is dynamically adjusted by calculating the similarity and importance between the user operation behavior and the context information. The similarity can be calculated by the cosine similarity function, and the importance is dynamically assigned according to the frequency of the operation behavior and the sensitivity of the context information; the calculated weight matrix is subjected to a dot product operation with the operation behavior features to highlight the parts of the behavior features that are highly relevant to the context information, and the time series modeling of the behavior features is combined with the time window mechanism. The dynamic change patterns on the time series are captured by the sliding window method, so as to generate a behavior representation with time-dynamic characteristics, and finally obtain the dynamic behavior model.

[0039] S23: Convert the dynamic behavior model into a node representation form, where the nodes represent the behavior features and the edges represent the context interaction relationships.

[0040] Specifically, by parsing the time series features in the dynamic behavior model, the behavior features at each time point are mapped to a node in the graph structure. The attributes of the node include the operation behavior type, device environment features, and context information at that time point. For the context information pairs with direct interaction relationships in the dynamic behavior model, edges in the graph are generated, and a weight value is assigned to each edge. The weight value is quantified according to the interaction frequency and strength of the context information. At the same time, by globally analyzing the operation behaviors adjacent in time in the dynamic behavior model, the time adjacency relationship is also defined as an edge in the graph, and a decay weight value based on the time window is assigned to these edges, thereby constructing a complete behavior graph structure containing nodes and edges.

[0041] S24: Utilize the multi-layer propagation mechanism of the graph neural network to perform feature aggregation on the nodes to generate a user behavior graph containing the global association of user behaviors.

[0042] Specifically, by inputting the behavior graph structure into the graph neural network, multi-layer propagation operations are performed on the nodes and edges in the graph. The propagation mechanism includes linearly weighted summing the feature vectors of each node with the feature vectors of its directly adjacent nodes to obtain local aggregation features, and at the same time, adjusting the propagation results in combination with the edge weights in the graph, so that the edges with high interaction strength between nodes have a greater impact on the aggregation results. The propagation operation is repeatedly executed in each layer of the graph neural network, aggregating the features of more neighboring nodes layer by layer. Finally, each node contains a feature representation of the global behavior pattern, forming a user behavior graph that can reflect the global relevance of user behaviors, and providing high-quality behavior modeling input for subsequent threat detection.

[0043] In one embodiment, as Figure 3 shown, in step S30, that is, based on the user behavior graph, simulated threat behavior data is generated through a generative adversarial network. Combining the simulated threat behavior data with the user behavior graph, a behavior anomaly detection model is dynamically generated using the reinforcement learning method, specifically including: S31: Use the adversarial network generator to randomly perturb the user behavior graph to simulate abnormal behavior patterns and obtain user behavior simulation data.

[0044] Specifically, by randomly perturbing the node features and edge structures in the user behavior graph, the perturbation methods include randomly changing the range of node feature values, randomly adding or deleting edges in the graph, and adjusting the edge weight values. The randomness of the perturbation can be achieved by setting a probability distribution function. For example, Gaussian distribution is used to generate random variables to offset the node feature values. At the same time, multiple abnormal behavior patterns can be simulated, such as abnormal login, frequent operations, and privilege escalation. The perturbation rules corresponding to these abnormal behavior patterns are added to the optimization process of the generator, so that the generator can generate data closer to the actual abnormal behavior scenarios, and finally output a set of user behavior simulation data with potential threat patterns.

[0045] S32: Use the adversarial network discriminator to screen the user behavior simulation data, and retain the user behavior simulation data that meets the preset confidence requirement as the reinforcement learning data.

[0046] Specifically, merge the user behavior simulation data generated by the generator with the normal behavior data in the user behavior graph to form a training data set, input it into the discriminator for classification processing. The discriminator extracts and analyzes the features of the data through a neural network, and calculates the confidence value of each data sample. The confidence value is the abnormal classification probability output by the discriminator, which reflects the degree of proximity between the simulation data and the abnormal behavior pattern. For the simulation data with a confidence higher than the preset threshold, it is regarded as high-quality abnormal data and retained as the training input of reinforcement learning, while the simulation data with a confidence lower than the threshold will be discarded or returned to the generator for further optimization, so as to ensure the authenticity and effectiveness of the reinforcement learning data.

[0047] S33: Based on the user behavior graph and the reinforcement learning data, define a reward function, and then iteratively train the threat detection strategy through the reinforcement learning framework to generate a behavior anomaly detection model.

[0048] Specifically, by combining the normal behavior pattern in the user behavior graph and the simulated abnormal behavior in the reinforcement learning data, define a reward function to guide the optimization of the reinforcement learning model. The reward function is designed according to the key indicators of anomaly detection, including behavior deviation, detection accuracy, and false alarm rate. Calculate the behavior deviation to evaluate the distance between the behavior simulation data and the normal behavior graph, which can be calculated by Euclidean distance or cosine similarity. The detection accuracy is evaluated according to the proportion of abnormal behaviors correctly classified, and the false alarm rate is used to evaluate the proportion of normal behaviors misclassified as abnormal behaviors. During the training process of reinforcement learning, dynamically adjust the threat detection strategy according to the feedback of the reward function, and gradually generate a behavior anomaly detection model that can accurately identify various abnormal behavior patterns through continuous iterative optimization. This model finally outputs to detect potential threats in real-time user behavior.

[0049] In one embodiment, as Figure 4 shown, in step S33, that is, based on the user behavior graph and the reinforcement learning data, define a reward function, specifically including: S331: Perform behavior embedding representation on the abnormal behavior pattern of the reinforcement learning data and the normal behavior pattern of the user behavior graph, and calculate the Euclidean distance of the behavior embedding representation, that is, the behavior deviation.

[0050] Specifically, the reinforcement learning data and the node features in the user behavior graph are subjected to embedding mapping, which is achieved through dimensionality reduction methods such as principal component analysis or deep embedding models, mapping the high-dimensional features to a unified low-dimensional vector space. The behavioral deviation degree is quantified by calculating the Euclidean distance between each simulated abnormal behavior and the corresponding normal behavior. The greater the distance, the higher the degree of deviation of the abnormal behavior from the normal behavior. The behavioral deviation degree is used to measure the quality of the reinforcement learning data and serves as an important input value for the reward function to optimize the training process.

[0051] S332: Calculate the correct recognition rate of abnormal behaviors for the behavior anomaly detection model, and then determine the anomaly detection accuracy of the reward function.

[0052] Specifically, by inputting the simulated abnormal behaviors in the reinforcement learning data into the behavior anomaly detection model, calculate the correct recognition rate of the model for the simulated abnormal behaviors. The correct recognition rate is obtained by counting the proportion of data samples that are actually abnormal behaviors in the model prediction results. This proportion reflects the detection ability of the model for abnormal behavior patterns. The higher the detection accuracy, the greater the weight of the corresponding part of the reward function. The improvement of the detection accuracy can directly optimize the training effect of the reinforcement learning model, thereby further enhancing the recognition ability of the behavior anomaly detection model.

[0053] S333: Calculate the false detection rate of normal behaviors for the behavior anomaly detection model, and then determine the false alarm rate of the reward function.

[0054] Specifically, by inputting the normal behaviors in the user behavior graph into the behavior anomaly detection model, calculate the false alarm rate of the model for the normal behaviors. The false alarm rate is the proportion of the model misclassifying normal behaviors as abnormal behaviors. This value reflects the error level in the detection process; the lower the false alarm rate, the stronger the classification ability of the model for normal behaviors, and the greater the corresponding weight in the reward function. In the reinforcement learning training process, by optimizing the goal of reducing the false alarm rate, improve the robustness and practical application effect of the model, while ensuring that the model reduces interference to normal behaviors while detecting abnormal behaviors.

[0055] S334: Perform weighted summation combination on the behavioral deviation degree, anomaly detection accuracy, and false alarm rate to obtain the reward function.

[0056] Specifically, by taking the behavior deviation degree, the abnormal behavior detection accuracy, and the false alarm rate as the three core indicators of the reward function, and using the weighted summation formula to combine these three indicators, the weight coefficients in the formula can be dynamically adjusted according to the requirements of the actual scenario. For example, in a scenario with high security requirements, the weight of the abnormal behavior detection accuracy can be increased, while the weight of the false alarm rate can be appropriately decreased; during the weighted summation process, the weight allocation ratio is dynamically adjusted according to the real-time training feedback, so that the reinforcement learning process can converge to the optimization goal faster, and finally a complete reward function is obtained, providing optimization guidance for the training of the subsequent reinforcement learning framework.

[0057] In one embodiment, as Figure 5 shown, in step S40, that is, according to the user behavior anomaly detection model, threat detection is performed on the real-time collected multi-modal feature data, abnormal behaviors are identified, and threat detection results are generated based on the abnormal behaviors, specifically including: S41: Embed the real-time collected multi-modal feature data into the corresponding user behavior graph and input it into the user behavior anomaly detection model.

[0058] Specifically, by parsing the real-time collected multi-modal feature data, matching it with the nodes in the user behavior graph according to its timestamp information, the matching rules include time proximity and behavior feature similarity, and taking the matching result as the embedding basis for the real-time data; for the real-time data that cannot be directly matched, find the node in the user behavior graph that is closest to it through similarity calculation, and generate a virtual edge, and embed the real-time data into the node features connected by the virtual edge; after the embedding is completed, use the new user behavior graph containing the real-time data as the input and pass it to the user behavior anomaly detection model for threat assessment.

[0059] S42: According to the preset threat detection strategy in the threat detection model, judge whether the user behavior deviates from the normal mode, and assign a threat level label to the abnormal behavior to obtain the threat detection result.

[0060] Specifically, by comparing the output of the user behavior anomaly detection model with the preset threat detection strategy, the detection strategy includes the distribution pattern threshold of normal behaviors, the deviation range of abnormal behaviors, and the threat level classification rules, for behaviors that deviate from the normal mode, calculate the threat score according to the degree of deviation, and the threat score is adjusted by combining the context information of the behavior and the historical behavior record; compare the adjusted threat score with the preset threat level threshold, and assign a threat level label to the abnormal behavior according to the range where the score is located, and finally generate a threat detection result including the type of abnormal behavior, the threat level, and the operation context information.

[0061] In one embodiment, as Figure 6As shown, in step S50, according to the threat detection results, the trust scores of users and devices are calculated, and a response priority policy is generated based on the trust scores to perform response operations on abnormal behaviors, specifically including: S51: Based on the abnormality frequency and context information consistency in the threat detection results, define a calculation function for the trust score, and dynamically adjust the weight ratio of the trust score, giving priority to reducing the trust scores of users and devices with abnormal behaviors of high threat levels.

[0062] Specifically, by parsing the threat level tags and context information of the occurrence of abnormal behaviors in the threat detection results, the frequency of abnormal behaviors is used as the basic factor for calculating the trust score. At the same time, the weight is adjusted in combination with the sensitivity of the environment in the context information and the consistency of the behavior with historical records. The weight of abnormal behaviors in sensitive environments is given priority to increase, and the weight of behaviors with lower consistency is given priority to decrease; the trust scores of users and devices are calculated by weighted summation, and the weight ratio of each factor in the score is dynamically adjusted, making the impact of abnormal behaviors of high threat levels on the score more significant, so as to achieve the priority identification of users and devices with low trust scores.

[0063] S52: According to the trust score, assign priorities to all abnormal behaviors in sequence, and set quick response rules for abnormal behaviors whose priorities reach the preset danger level.

[0064] Specifically, by sorting all abnormal behaviors in descending order according to the trust score, the abnormal behavior with the lowest score is preferentially included in the quick response queue. At the same time, the priority is further adjusted in combination with the threat level tags of the abnormal behaviors, and higher priorities are given to behaviors with higher threat levels; when the priority exceeds the preset danger level threshold, the quick response rules are triggered. The quick response rules include isolating the network connection of the relevant device, reducing the user permission to the lowest level, and sending an emergency alarm notification to the administrator, so as to make an effective response to the abnormal behavior in the shortest time.

[0065] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0066] In one embodiment, an internal threat detection system based on behavior analysis is provided. The internal threat detection system based on behavior analysis corresponds one-to-one with the internal threat detection method based on behavior analysis in the above embodiment. As Figure 7 shown, the internal threat detection system based on behavior analysis includes a data processing module, a behavior modeling module, a threat detection model generation module, an abnormal behavior detection module, and a response decision module. The detailed descriptions of each functional module are as follows: A data processing module, which is used to obtain multimodal data of the user operation environment, perform temporal alignment on the multimodal data based on the time window mechanism, and generate a unified multimodal feature dataset; A behavior modeling module, which is used to input the multimodal feature dataset into the context-aware modeling module, combine the context information of the user behavior, construct a dynamic behavior model, and perform secondary modeling on the dynamic behavior model by using a graph neural network to generate a user behavior graph; A threat detection model generation module, which is used to generate simulated threat behavior data based on the user behavior graph through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and dynamically generate a behavior anomaly detection model by using a reinforcement learning method; An abnormal behavior detection module, which is used to perform threat detection on the real-time collected multimodal feature data according to the user behavior anomaly detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors; A response decision module, which is used to calculate the trust scores of the user and the device according to the threat detection results, and generate a response priority policy based on the trust scores to execute response operations on the abnormal behaviors.

[0067] Optionally, the behavior modeling module specifically includes: A feature extraction sub-module, which is used to extract the feature information of the user behavior from the multimodal feature dataset and associate the feature information with the context information; An interaction modeling sub-module, which is used to calculate the weights of the interaction between the feature information and the context information based on the context-aware mechanism, and generate a behavior representation with time dynamics characteristics according to the calculation results, and then obtain a dynamic behavior model; A graph structure construction sub-module, which is used to convert the dynamic behavior model into a node representation form, where the nodes represent behavior features and the edges represent context interaction relationships; A graph neural network sub-module, which is used to aggregate the features of the nodes by using the multi-layer propagation mechanism of the graph neural network to generate a user behavior graph containing the global association of the user behavior.

[0068] Optionally, the threat detection model generation module specifically includes: A data generation sub-module, which is used to randomly perturb the user behavior graph by using an adversarial network generator to simulate abnormal behavior patterns and obtain user behavior simulation data; A data screening sub-module, which is used to screen the user behavior simulation data by using an adversarial network discriminator and retain the user behavior simulation data with the confidence level meeting the preset confidence level requirement as the reinforcement learning data; A training optimization sub-module, which is used to define a reward function based on the user behavior graph and the reinforcement learning data, and then iteratively train the threat detection strategy through a reinforcement learning framework to generate a behavior anomaly detection model.

[0069] Optionally, the training optimization sub-module specifically includes: A behavior deviation calculation unit, configured to perform behavior embedding representation on the abnormal behavior pattern of the reinforcement learning data and the normal behavior pattern of the user behavior graph, and calculate the Euclidean distance of the behavior embedding representation, that is, the behavior deviation; An abnormal detection accuracy calculation unit, configured to perform a correct rate identification calculation on the abnormal behavior of the behavior anomaly detection model, and further determine the abnormal detection accuracy of the reward function; A false alarm rate calculation unit, configured to perform a false detection rate calculation on the normal behavior of the behavior anomaly detection model, and further determine the false alarm rate of the reward function; A reward function combination unit, configured to perform weighted summation combination on the behavior deviation, abnormal detection accuracy and false alarm rate to obtain a reward function.

[0070] Optionally, the behavior anomaly detection module specifically includes: A data embedding sub-module, configured to embed the real-time collected multi-modal feature data into the corresponding user behavior graph and input it into the user behavior anomaly detection model; A threat judgment sub-module, configured to judge whether the user behavior deviates from the normal mode according to the preset threat detection strategy in the threat detection model, and assign a threat level label to the abnormal behavior to obtain a threat detection result.

[0071] Optionally, the response decision module specifically includes: A trust score calculation sub-module, configured to define a calculation function of the trust score based on the abnormality frequency in the threat detection result and the consistency of the context information, and dynamically adjust the weight ratio of the trust score, and preferentially reduce the trust scores of users and devices with abnormal behaviors of high threat levels; A priority assignment sub-module, configured to assign priorities to all abnormal behaviors in sequence according to the trust score, and set a quick response rule for abnormal behaviors whose priorities reach the preset danger level.

[0072] For the specific limitations of the internal threat detection system based on behavior analysis, reference can be made to the limitations of the internal threat detection method based on behavior analysis in the above text, which will not be elaborated here. Each module in the above internal threat detection system based on behavior analysis can be implemented in whole or in part by software, hardware and their combination. The above-mentioned modules can be embedded in the processor of the computer device in the form of hardware or be independent of it, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above-mentioned modules.

[0073] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8As shown in the figure. The computer device includes a processor, a memory, a network interface, and a database connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements an internal threat detection method based on behavior analysis.

[0074] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: Obtain multi-modal data of the user operation environment, and perform temporal alignment on the multi-modal data based on a time window mechanism to generate a unified multi-modal feature data set; Input the multi-modal feature data set into a context-aware modeling module, combine the context information of the user behavior, construct a dynamic behavior model, and perform secondary modeling on the dynamic behavior model using a graph neural network to generate a user behavior graph; Based on the user behavior graph, generate simulated threat behavior data through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and use a reinforcement learning method to dynamically generate a behavior anomaly detection model; Perform threat detection on the real-time collected multi-modal feature data according to the user behavior anomaly detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors; According to the threat detection results, calculate the trust scores of the user and the device, and generate a response priority policy based on the trust scores to execute response operations for abnormal behaviors.

[0075] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are implemented: Obtain multi-modal data of the user operation environment, and perform temporal alignment on the multi-modal data based on a time window mechanism to generate a unified multi-modal feature data set; Input the multi-modal feature data set into a context-aware modeling module, combine the context information of the user behavior, construct a dynamic behavior model, and perform secondary modeling on the dynamic behavior model using a graph neural network to generate a user behavior graph; Based on the user behavior graph, generate simulated threat behavior data through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and use a reinforcement learning method to dynamically generate a behavior anomaly detection model; Perform threat detection on the multi-modal feature data collected in real time according to the user behavior anomaly detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors; According to the threat detection results, calculate the trust scores of the user and the device, and generate a response priority policy based on the trust scores to execute response operations on the abnormal behaviors.

[0076] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0077] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above.

[0078] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. An internal threat detection method based on behavior analysis, characterized in that, The internal threat detection method based on behavior analysis includes: Obtain multi-modal data of the user operation environment, and perform temporal alignment on the multi-modal data based on the time window mechanism to generate a unified multi-modal feature dataset; Input the multi-modal feature dataset into the context-aware modeling module, combine the context information of the user behavior, construct a dynamic behavior model, and use a graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph; Based on the user behavior graph, generate simulated threat behavior data through a generative adversarial network, combine the simulated threat behavior data with the user behavior graph, and use a reinforcement learning method to dynamically generate a behavior anomaly detection model; Perform threat detection on the real-time collected multi-modal feature data according to the user behavior anomaly detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors; According to the threat detection results, calculate the trust scores of the user and the device, and generate a response priority policy based on the trust scores to execute response operations for abnormal behaviors.

2. The internal threat detection method based on behavior analysis according to claim 1, wherein The step of inputting the multi-modal feature dataset into the context-aware modeling module, combining the context information of the user behavior, constructing a dynamic behavior model, and using a graph neural network to perform secondary modeling on the dynamic behavior model to generate a user behavior graph specifically includes: Extract the feature information of the user behavior from the multi-modal feature dataset, and associate the feature information with the context information; Based on the context-aware mechanism, calculate the weights of the interaction between the feature information and the context information, and generate a behavior representation with time dynamic characteristics according to the calculation results, thereby obtaining the dynamic behavior model; Convert the dynamic behavior model into a node representation form, where the nodes represent behavior features and the edges represent context interaction relationships; Use the multi-layer propagation mechanism of the graph neural network to perform feature aggregation on the nodes to generate the user behavior graph including the global association of the user behavior.

3. The internal threat detection method based on behavior analysis according to claim 1, characterized in that The step of generating simulated threat behavior data through a generative adversarial network based on the user behavior graph, combining the simulated threat behavior data with the user behavior graph, and using a reinforcement learning method to dynamically generate a behavior anomaly detection model specifically includes: Use the adversarial network generator to randomly perturb the user behavior graph to simulate abnormal behavior patterns and obtain user behavior simulation data; Use the adversarial network discriminator to screen the user behavior simulation data, and retain the user behavior simulation data that meets the preset confidence requirement as the reinforcement learning data; Based on the user behavior graph and the reinforcement learning data, define a reward function, and then iteratively train the threat detection strategy through the reinforcement learning framework to generate the behavior anomaly detection model.

4. The internal threat detection method based on behavior analysis according to claim 3, wherein The step of defining a reward function based on the user behavior graph and the reinforcement learning data specifically includes: Perform behavior embedding representations on the abnormal behavior patterns of the reinforcement learning data and the normal behavior patterns of the user behavior graph, and calculate the Euclidean distance and behavior deviation degree of the behavior embedding representations; Calculate the correct recognition rate of abnormal behaviors for the behavior anomaly detection model, and then determine the abnormal behavior detection accuracy of the reward function; Calculate the false detection rate of normal behaviors for the behavior anomaly detection model, and then determine the false alarm rate of the reward function; Perform weighted summation combination on the behavior deviation degree, the abnormal behavior detection accuracy, and the false alarm rate to obtain the reward function.

5. The internal threat detection method based on behavior analysis according to claim 3, characterized in that, The threat detection of the multi-modal feature data collected in real time according to the user behavior anomaly detection model, identify abnormal behaviors, and generate threat detection results based on the abnormal behaviors, specifically including: Embed the multi-modal feature data collected in real time into the corresponding user behavior graph and input it into the user behavior anomaly detection model; According to the threat detection strategy preset in the threat detection model, judge whether the user behavior deviates from the normal mode, and assign a threat level label to the abnormal behavior to obtain the threat detection result.

6. The internal threat detection method based on behavior analysis according to claim 1, wherein The calculation of the trust scores of the user and the device according to the threat detection result, and generate a response priority policy based on the trust scores to execute the response operation for the abnormal behavior, specifically including: Based on the abnormality frequency and the consistency of the context information in the threat detection result, define the calculation function of the trust score, and dynamically adjust the weight ratio of the trust score, and preferentially reduce the trust scores of the users and devices with abnormal behaviors of high threat levels; According to the trust score, assign priorities to all abnormal behaviors in turn, and set fast response rules for the abnormal behaviors whose priorities reach the preset danger level.

7. An internal threat detection system based on behavior analysis, characterized in that, The internal threat detection system based on behavior analysis includes: A data processing module for obtaining multi-modal data of the user operation environment and performing time series alignment on the multi-modal data based on a time window mechanism to generate a unified multi-modal feature data set; A behavior modeling module for inputting the multi-modal feature data set into a context-aware modeling module, combining the context information of the user behavior, constructing a dynamic behavior model, and performing secondary modeling on the dynamic behavior model using a graph neural network to generate a user behavior graph; A threat detection model generation module for generating simulated threat behavior data based on the user behavior graph through a generative adversarial network, combining the simulated threat behavior data with the user behavior graph, and dynamically generating a behavior anomaly detection model using a reinforcement learning method; An abnormal behavior detection module for performing threat detection on the multi-modal feature data collected in real time according to the user behavior anomaly detection model, identifying abnormal behaviors, and generating threat detection results based on the abnormal behaviors; A response decision module for calculating the trust scores of the user and the device according to the threat detection result, and generating a response priority policy based on the trust scores to execute the response operation for the abnormal behavior.

8. The internal threat detection system based on behavior analysis according to claim 7, characterized in that, The behavior modeling module specifically includes: A feature extraction sub-module for extracting the feature information of the user behavior from the multi-modal feature data set and associating the feature information with the context information; An interaction modeling sub-module, which is used to calculate weights for the interaction between the feature information and the context information based on a context awareness mechanism, and generate a behavior representation with time-dynamic characteristics according to the calculation results, thereby obtaining the dynamic behavior model; A graph structure construction sub-module, which is used to convert the dynamic behavior model into a node representation form, where nodes represent behavior features and edges represent context interaction relationships; A graph neural network sub-module, which is used to aggregate features of the nodes by using the multi-layer propagation mechanism of the graph neural network to generate the user behavior graph including the global association of user behaviors.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the internal threat detection method based on behavior analysis according to any one of claims 1 to 6.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the internal threat detection method based on behavior analysis according to any one of claims 1 to 6.

Citation Information

Cited By

  • Dynamic data leakage protection method, system and device based on generative adversarial and storage medium

    CN121441650A

  • Adversarial-based dynamic data leakage protection method, system, device and storage medium

    CN121441650B

  • Multi-source heterogeneous public opinion risk assessment method and device based on dynamic weight

    CN121525042A

  • Method and device for multi-source heterogeneous public opinion risk assessment based on dynamic weight

    CN121525042B