Abnormal behavior detection method and system for e-government system

By constructing a behavior pointer turntable and path, and combining preset models to perform abnormal behavior detection, the problem of low abnormal detection efficiency in the e-government system is solved, and efficient and accurate abnormal behavior recognition and correction are achieved to ensure system security.

CN120492456AActive Publication Date: 2025-08-15WUHAN ZHONGLIAN HENGXING TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510579454.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-08-15
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The abnormal detection efficiency of operating behavior in the e-government system is low, making it difficult to accurately identify normal operating behaviors and abnormal operating behaviors, resulting in the impact of system security and stability.

Method used

By obtaining the data associated with the system functional module and the module and historical behavior data, building the behavior pointer turntable and the pointer behavior path, performing abnormal behavior checksum correction, combining real-time operation behavior to make abnormal judgments, and using preset behavior correction models for identification and correction.

Benefits of technology

It improves the efficiency and accuracy of abnormal behavior detection in the e-government system, can promptly detect and correct abnormal operations, prevent data leakage and system failure, and ensure the safe and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120492456A_ABST
    Figure CN120492456A_ABST
Patent Text Reader

Abstract

The invention relates to an abnormal behavior detection method and system for an e-government affair system, and relates to the technical field of abnormal detection, and the method comprises the steps: obtaining system function modules, module association data and function behavior data, carrying out the arrangement of the system function modules and the module association data, obtaining a behavior pointer turntable and a pointer behavior path, performing abnormal behavior verification on the functional behavior data, determining whether the functional behavior data is abnormal behavior data or not, and if yes, inputting the functional behavior data into a preset behavior correction model for abnormal correction identification to obtain corrected behavior data, and binding the corrected behavior data and the functional behavior data with the pointer behavior path according to a preset corresponding relation to obtain behavior path data, collecting a real-time operation behavior of an operator, and performing abnormality judgment on the real-time operation behavior according to the behavior pointer turntable and the behavior path data to obtain an abnormality judgment result. According to the invention, the abnormal behavior detection and identification efficiency of the e-government system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of anomaly detection, and in particular to a method and system for detecting abnormal behavior in an e-government system. Background Art

[0002] With the rapid development of information technology, e-government systems are playing an increasingly important role in daily government operations, public service provision, and government administration. E-government systems integrate numerous interconnected and collaborative functional modules to enable the digital processing and efficient flow of government business. However, e-government systems face numerous security challenges and compliance issues during operation. Detecting and addressing anomalies in operational behavior is crucial for ensuring secure and stable system operation and the compliance of government business operations.

[0003] E-government systems typically include multiple functional modules, such as administrative approval, document circulation, information release, and data statistics. These modules are complexly interconnected. This diversity and interconnectedness makes the operator's behavioral path within the system complex and variable. For example, when processing an administrative approval application, an operator must sequentially access multiple functional modules and perform operations according to a specific process sequence. Due to the differences in business scenarios and processes, the operator's behavioral path is difficult to describe with simple, fixed rules. This makes it difficult to accurately identify normal and abnormal operational behaviors, thereby reducing the efficiency of abnormal behavior detection and identification in e-government systems. Summary of the Invention

[0004] In order to solve at least one of the above technical problems, the present application provides a method and system for detecting abnormal behavior in an e-government system.

[0005] In the first aspect, the present application provides a method for detecting abnormal behavior in an e-government system, which adopts the following technical solutions: A method for detecting abnormal behavior in an e-government system, comprising: Obtaining system function modules and module association data of the e-government system and function behavior data of the e-government system in a historical period; Arrange the system function modules and module-related data to obtain a behavior pointer turntable and a pointer behavior path; Performing abnormal behavior verification on the functional behavior data to determine whether the functional behavior data is abnormal behavior data; if so, inputting the functional behavior data into a preset behavior correction model to perform abnormal correction identification to obtain corrected behavior data corresponding to the functional behavior data; Binding the correction behavior data, the functional behavior data and the pointer behavior path according to a preset correspondence to obtain behavior path data; When an operator is detected logging into the e-government system, the operator's real-time operation behavior is collected; An abnormality determination is performed on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result.

[0006] By employing the above technical solution, we obtain data on the system's functional modules and module associations, as well as functional behavior data from historical time periods, for the e-government system. This data forms the basis for constructing the behavior indicator wheel and pointer behavior path, reflecting the architecture and connections between modules within the system. Historical functional behavior data, however, contains records of past system operations and serves as the basis for subsequent analysis. Acquiring this fundamental data provides comprehensive data support for in-depth analysis of system operational behavior. By organizing the acquired system functional modules and module association data, we generate the behavior indicator wheel and pointer behavior path. The behavior indicator wheel intuitively displays the relationships between system functional modules, providing a clear overview of the system architecture. The pointer behavior path records the interaction sequence and behavior patterns of each module under normal operational processes. These two findings, achieved through the organization and analysis of fundamental data, present the system's complex module relationships and operational processes in a structured manner. This structuring facilitates the rapid and accurate identification of operational behaviors within the system and their conformance to normal processes. It also provides a clear reference standard for subsequent anomaly verification of functional behavior data, effectively improving the efficiency and accuracy of anomaly detection. Performing anomaly verification on functional behavior data can screen out problematic data. For abnormal behavior data, it is input into a pre-set behavior correction model for anomaly correction identification, generating corrected behavior data. The pre-set behavior correction model, trained on a large amount of normal behavior data, accurately identifies abnormal behavior and provides correction recommendations. This process ensures timely detection and correction of abnormal behavior, making functional behavior data more accurate and reliable. Corrected behavior data and functional behavior data are bound to the pointer behavior path according to pre-set correspondences to generate behavior path data. The pre-set correspondences clearly define the associations between different behavior data and pointer behavior paths. This binding operation tightly integrates the behavior data with the operational processes of system modules. Behavior path data not only includes specific operational behaviors but also clarifies their position and sequence within the system's operational processes. This integration approach enables a more comprehensive and in-depth analysis of system operational behavior, clearly demonstrating the contextual relationship of each operational behavior within the overall system operation. When an operator is detected logging into the e-government system, their real-time operational behavior is collected. Real-time operational behavior truly reflects the current state of the system's operation and is directly related to the system's security and stability. Abnormality is determined for real-time operational behavior based on the previously generated behavior pointer wheel and behavior path data. The behavior pointer dial and behavior path data provide accurate reference standards for abnormality judgment. By comparing real-time operation behavior with these standards, it is possible to quickly determine whether the behavior conforms to the normal operation process and module association relationship of the system.This anomaly determination method based on historical data and system architecture can promptly detect improper operations or potential security threats by operators, prevent data leakage, system failures and other problems caused by abnormal operations, and improve the efficiency of abnormal behavior detection and identification in e-government systems.

[0007] In a preferred example, the present application may be further configured as follows: the system function modules and module-related data are sorted to obtain a behavior pointer turntable and a pointer behavior path, including: Performing application frequency weight determination on the system function module to obtain a first weight value; Performing a weighted determination of the number of abnormalities on the system function module to obtain a second weight value; Performing abnormal consequence weight determination on the system function module to obtain a third weight value; Determining the number of reference branches between each of the system function modules and other system function modules according to the module association data, and multiplying the number of reference branches by the sum of the first weight value, the second weight value, and the third weight value to obtain a comprehensive weight value corresponding to each system function module; Sorting the system function modules according to the comprehensive weight values, and placing the system function modules into an initial pointer turntable according to the sorted module sequence to obtain a behavior pointer turntable; A module association determination is performed on each system function module on the behavior pointer dial according to the module association data, and on the premise of determining that there is an association between the system function modules, a path is constructed between the associated system function modules to obtain a pointer behavior path.

[0008] In a preferred example, the present application may be further configured as follows: placing the system function modules into the initial pointer turntable according to the sorted module sequence to obtain the behavior pointer turntable, including: Determine a first functional module according to the module sequence, and place the first functional module in the center wheel corresponding to the initial pointer wheel, wherein the first functional module is the system functional module ranked first in the module sequence; Determining a second functional module set associated with the first functional module in the module sequence and a first module ranking corresponding to each system functional module in the second functional module set; Determine whether the ranking of the first module meets the preset ranking standard corresponding to the initial pointer wheel; if so, place the system function module in the second function module set into the first function wheel corresponding to the initial pointer wheel; if not, retain the system function module and transfer the retained system function module to the next wheel for determination; Determine an N+1th functional module set associated with the Nth functional module in the module sequence and an Nth module ranking corresponding to each functional module in the N+1th functional module set, where N is greater than or equal to 2; Determine whether the ranking of the Nth module and the ranking of the reserved modules corresponding to the system function modules retained before the Nth function module meet the preset ranking standard; if so, place the system function modules in the N+1th function module set and the system function modules retained before the Nth function module into the Nth function wheel corresponding to the initial pointer wheel; if not, retain the system function modules and transfer the retained system function modules to the next wheel for determination, until all the system function modules in the module sequence are placed into the initial pointer wheel to obtain the behavior pointer wheel.

[0009] In a preferred example, the present application may be further configured as follows: performing abnormality determination on the real-time operation behavior based on the behavior pointer dial and the behavior path data to obtain an abnormality determination result includes: Classifying the real-time operation behavior to determine the real-time behavior category of the operator; Matching the real-time behavior category with a preset category segmentation standard to obtain the real-time operational behavior segmentation specification; Performing node segmentation on the real-time operation behavior based on the behavior segmentation specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes; Sorting the multiple behavior operation nodes in sequence according to time nodes to obtain an operation node sequence; Perform abnormal behavior sequence detection on the operation node sequence according to the behavior pointer dial to obtain a node determination result; Perform abnormal behavior data detection on the behavior demonstration data according to the behavior path data to obtain a data determination result; The node determination result and the data determination result are correspondingly bound and integrated to obtain an abnormality determination result.

[0010] In a preferred example, the present application may be further configured as follows: performing abnormal behavior sequence detection on the operation node sequence according to the behavior pointer dial to obtain a node determination result includes: Determining the positions of the pointer turntables corresponding to the plurality of behavior operation nodes according to the system function modules corresponding to the plurality of behavior operation nodes and the system function modules corresponding to the behavior pointer turntable; Based on the position of the pointer dial, the multiple behavior operation nodes are placed into the behavior pointer dial to perform a behavior node abnormality determination simulation to determine whether there is a behavior node abnormality in the operation node sequence. If so, the abnormal module position and the correction module position corresponding to the behavior node abnormality are determined according to the behavior pointer dial, and the abnormal module position and the correction module position are used as the node determination result.

[0011] In a preferred example, the present application may be further configured as follows: performing abnormal behavior data detection on the behavior demonstration data according to the behavior path data to obtain a data determination result includes: Determining a path data sample corresponding to the behavior demonstration data according to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data; constructing a first data type curve based on the behavior demonstration data, and constructing a second data type curve based on the path data sample; Splitting the second data type curve based on whether the path data sample is abnormal or not to obtain a third data type curve without abnormal data and a fourth data type curve with abnormal data; performing curve overlap comparison on the first data type curve, the third data type curve, and the fourth data type curve according to data types, respectively, to obtain a first overlap ratio corresponding to the third data type curve and a second overlap ratio corresponding to the fourth data type curve; The first overlap rate and the second overlap rate are input into a preset overlap rate standard for judgment. If the first overlap rate and the second overlap rate both meet the preset overlap rate standard, the second overlap rate is pre-diagnosed for behavioral abnormality to obtain a data judgment result. If not, the data abnormality factors corresponding to the first overlap rate and the second overlap rate are determined according to the preset overlap rate standard, and a data judgment result is generated based on the data abnormality factors.

[0012] In a preferred example, the present application may be further configured as follows: performing behavioral abnormality pre-diagnosis on the second coincidence rate to obtain a data determination result includes: Determine a time overlap rate between the first data type curve and the fourth data type curve within a preset unit time according to the second overlap rate, and construct a overlap rate curve corresponding to the time overlap rate; Determine, based on the coincidence rate curve, a curve extension vector extending from different unit time points to the next unit time point and a coincidence rate feature corresponding to each unit time point; Determining an extension vector feature based on the curve extension vector, and binding the extension vector feature with the coincidence rate feature to obtain a point feature set; Arranging the point feature set in a matrix according to time sequence to obtain a point feature matrix; Deducing the point feature matrix from the point feature set according to a unit time period to obtain a predicted point matrix in a future period; Determining a future point feature set according to the predicted point matrix, and determining a future coincidence rate in a future period based on the future point feature set; The future overlap rate is determined based on the preset overlap rate standard to obtain a data determination result.

[0013] In a second aspect, the present application provides an abnormal behavior detection system for an e-government system, which adopts the following technical solutions: An abnormal behavior detection system for an e-government system, comprising: A data acquisition module is used to acquire system function modules and module association data of the e-government system and functional behavior data of the e-government system in a historical period; A data sorting module is used to sort the system function modules and module-related data to obtain a behavior pointer turntable and a pointer behavior path; a behavior verification module, configured to perform abnormal behavior verification on the functional behavior data to determine whether the functional behavior data is abnormal behavior data; if so, input the functional behavior data into a preset behavior correction model to perform abnormal correction identification, and obtain corrected behavior data corresponding to the functional behavior data; a data binding module, configured to bind the correction behavior data, the functional behavior data and the pointer behavior path according to a preset corresponding relationship to obtain behavior path data; The behavior collection module is used to collect the operator's real-time operation behavior after detecting that the operator has logged into the e-government system; The abnormality determination module is used to perform abnormality determination on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result.

[0014] In a possible implementation, when the data sorting module sorts the system function modules and module-related data to obtain the behavior pointer turntable and the pointer behavior path, it is specifically configured to: Performing application frequency weight determination on the system function module to obtain a first weight value; Performing a weighted determination of the number of abnormalities on the system function module to obtain a second weight value; Performing abnormal consequence weight determination on the system function module to obtain a third weight value; Determining the number of reference branches between each of the system function modules and other system function modules according to the module association data, and multiplying the number of reference branches by the sum of the first weight value, the second weight value, and the third weight value to obtain a comprehensive weight value corresponding to each system function module; Sorting the system function modules according to the comprehensive weight values, and placing the system function modules into an initial pointer turntable according to the sorted module sequence to obtain a behavior pointer turntable; A module association determination is performed on each system function module on the behavior pointer dial according to the module association data, and on the premise of determining that there is an association between the system function modules, a path is constructed between the associated system function modules to obtain a pointer behavior path.

[0015] In another possible implementation, when the data sorting module places the system function modules into the initial pointer turntable according to the sorted module sequence to obtain the behavior pointer turntable, it is specifically configured to: Determine a first functional module according to the module sequence, and place the first functional module in the center wheel corresponding to the initial pointer wheel, wherein the first functional module is the system functional module ranked first in the module sequence; Determining a second functional module set associated with the first functional module in the module sequence and a first module ranking corresponding to each system functional module in the second functional module set; Determine whether the ranking of the first module meets the preset ranking standard corresponding to the initial pointer wheel; if so, place the system function module in the second function module set into the first function wheel corresponding to the initial pointer wheel; if not, retain the system function module and transfer the retained system function module to the next wheel for determination; Determine an N+1th functional module set associated with the Nth functional module in the module sequence and an Nth module ranking corresponding to each functional module in the N+1th functional module set, where N is greater than or equal to 2; Determine whether the ranking of the Nth module and the ranking of the reserved modules corresponding to the system function modules retained before the Nth function module meet the preset ranking standard; if so, place the system function modules in the N+1th function module set and the system function modules retained before the Nth function module into the Nth function wheel corresponding to the initial pointer wheel; if not, retain the system function modules and transfer the retained system function modules to the next wheel for determination, until all the system function modules in the module sequence are placed into the initial pointer wheel to obtain the behavior pointer wheel.

[0016] In another possible implementation, when the abnormality determination module performs abnormality determination on the real-time operation behavior according to the behavior pointer dial and the behavior path data and obtains the abnormality determination result, it is specifically configured to: Classifying the real-time operation behavior to determine the real-time behavior category of the operator; Matching the real-time behavior category with a preset category segmentation standard to obtain the real-time operational behavior segmentation specification; Performing node segmentation on the real-time operation behavior based on the behavior segmentation specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes; Sorting the multiple behavior operation nodes in sequence according to time nodes to obtain an operation node sequence; Perform abnormal behavior sequence detection on the operation node sequence according to the behavior pointer dial to obtain a node determination result; Perform abnormal behavior data detection on the behavior demonstration data according to the behavior path data to obtain a data determination result; The node determination result and the data determination result are correspondingly bound and integrated to obtain an abnormality determination result.

[0017] In another possible implementation, when the abnormal behavior sequence detection is performed on the operation node sequence according to the behavior pointer dial to obtain a node determination result, the abnormality determination module is specifically configured to: Determining the positions of the pointer turntables corresponding to the plurality of behavior operation nodes according to the system function modules corresponding to the plurality of behavior operation nodes and the system function modules corresponding to the behavior pointer turntable; Based on the position of the pointer dial, the multiple behavior operation nodes are placed into the behavior pointer dial to perform a behavior node abnormality determination simulation to determine whether there is a behavior node abnormality in the operation node sequence. If so, the abnormal module position and the correction module position corresponding to the behavior node abnormality are determined according to the behavior pointer dial, and the abnormal module position and the correction module position are used as the node determination result.

[0018] In another possible implementation, when the abnormality determination module performs abnormal behavior data detection on the behavior demonstration data according to the behavior path data and obtains a data determination result, it is specifically configured to: Determining a path data sample corresponding to the behavior demonstration data according to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data; constructing a first data type curve based on the behavior demonstration data, and constructing a second data type curve based on the path data sample; Splitting the second data type curve based on whether the path data sample is abnormal or not to obtain a third data type curve without abnormal data and a fourth data type curve with abnormal data; performing curve overlap comparison on the first data type curve, the third data type curve, and the fourth data type curve according to data types, respectively, to obtain a first overlap ratio corresponding to the third data type curve and a second overlap ratio corresponding to the fourth data type curve; The first overlap rate and the second overlap rate are input into a preset overlap rate standard for judgment. If the first overlap rate and the second overlap rate both meet the preset overlap rate standard, the second overlap rate is pre-diagnosed for behavioral abnormality to obtain a data judgment result. If not, the data abnormality factors corresponding to the first overlap rate and the second overlap rate are determined according to the preset overlap rate standard, and a data judgment result is generated based on the data abnormality factors.

[0019] In another possible implementation, when the abnormality determination module performs behavioral abnormality pre-diagnosis on the second overlap rate and obtains a data determination result, it is specifically configured to: Determine a time overlap rate between the first data type curve and the fourth data type curve within a preset unit time according to the second overlap rate, and construct a overlap rate curve corresponding to the time overlap rate; Determine, based on the coincidence rate curve, a curve extension vector extending from different unit time points to the next unit time point and a coincidence rate feature corresponding to each unit time point; Determining an extension vector feature based on the curve extension vector, and binding the extension vector feature with the coincidence rate feature to obtain a point feature set; Arranging the point feature set in a matrix according to time sequence to obtain a point feature matrix; Deducing the point feature matrix from the point feature set according to a unit time period to obtain a predicted point matrix in a future period; Determining a future point feature set according to the predicted point matrix, and determining a future coincidence rate in a future period based on the future point feature set; The future overlap rate is determined based on the preset overlap rate standard to obtain a data determination result.

[0020] In a third aspect, the present application provides an electronic device, which adopts the following technical solution: An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned abnormal behavior detection method for an e-government system are implemented.

[0021] In a fourth aspect, the present application provides a computer storage medium, including the following technical solutions: A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned abnormal behavior detection method for an e-government system.

[0022] In summary, this application has the following beneficial technical effects: Acquire data on the system's functional modules and module associations, as well as functional behavior data from historical time periods. This data forms the foundation for constructing the behavior indicator wheel and pointer behavior path, reflecting the architecture and connections between modules within the system. Historical functional behavior data, however, contains records of past system operations and serves as the basis for subsequent analysis. Acquiring this fundamental data provides comprehensive data support for in-depth analysis of system operational behavior. The acquired system functional modules and module association data are organized to produce the behavior indicator wheel and pointer behavior path. The behavior indicator wheel intuitively displays the relationships between system functional modules, providing a clear overview of the system architecture. The pointer behavior path records the interaction sequence and behavior patterns of each module under normal operational processes. These two findings, achieved through the organization and analysis of fundamental data, present the system's complex module relationships and operational processes in a structured manner. This structuring facilitates the rapid and accurate identification of operational behaviors within the system and their conformance to normal processes. It also provides a clear reference standard for subsequent anomaly verification of functional behavior data, effectively improving the efficiency and accuracy of anomaly detection. Performing anomaly verification on functional behavior data can screen out problematic data. For abnormal behavior data, it is input into a pre-set behavior correction model for anomaly correction identification, generating corrected behavior data. The pre-set behavior correction model, trained on a large amount of normal behavior data, accurately identifies abnormal behavior and provides correction recommendations. This process ensures timely detection and correction of abnormal behavior, making functional behavior data more accurate and reliable. Corrected behavior data and functional behavior data are bound to the pointer behavior path according to pre-set correspondences to generate behavior path data. The pre-set correspondences clearly define the associations between different behavior data and pointer behavior paths. This binding operation tightly integrates the behavior data with the operational processes of system modules. Behavior path data not only includes specific operational behaviors but also clarifies their position and sequence within the system's operational processes. This integration approach enables a more comprehensive and in-depth analysis of system operational behavior, clearly demonstrating the contextual relationship of each operational behavior within the overall system operation. When an operator is detected logging into the e-government system, their real-time operational behavior is collected. Real-time operational behavior truly reflects the current state of the system's operation and is directly related to the system's security and stability. Abnormality is determined for real-time operational behavior based on the previously generated behavior pointer wheel and behavior path data. The behavior pointer dial and behavior path data provide accurate reference standards for abnormality judgment. By comparing real-time operation behavior with these standards, it is possible to quickly determine whether the behavior conforms to the normal operation process and module association relationship of the system.This anomaly determination method based on historical data and system architecture can promptly detect improper operations or potential security threats by operators, prevent data leakage, system failures and other problems caused by abnormal operations, and improve the efficiency of abnormal behavior detection and identification in e-government systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is a flowchart of an abnormal behavior detection method for an e-government system in one embodiment of the present application.

[0024] Figure 2 This is a structural diagram of an abnormal behavior detection system for an e-government system according to one embodiment of the present application.

[0025] Figure 3 This is a principle block diagram of an electronic device in one embodiment of the present application. DETAILED DESCRIPTION

[0026] The following is combined with Figure 1 To the attached Figure 3 This application is described in further detail.

[0027] This specific embodiment is merely an explanation of the present application and is not a limitation of the present application. After reading this specification, those skilled in the art may make non-creative modifications to the present embodiment as needed, but as long as they are within the scope of the claims of the present application, they are protected by the patent law.

[0028] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0029] In this document, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document, unless otherwise specified, generally indicates an "or" relationship between the related objects.

[0030] The embodiments of the present application are described in further detail below with reference to the accompanying drawings.

[0031] The embodiment of the present application provides a method for detecting abnormal behavior in an e-government system, which is executed by an electronic device, which can be a server or a terminal device, wherein the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., but is not limited thereto. The terminal device and the server can be directly or indirectly connected via wired or wireless communication, which is not limited in the embodiment of the present application. Figure 1 As shown, the method includes: Step S10: Obtain system function modules and module association data of the e-government system and function behavior data of the e-government system in a historical time period.

[0032] In the embodiments of this application, a system functional module represents a component with a specific function within an e-government system. It refers to an independent unit that is demarcated to implement the various business functions of the e-government system. For example, within an e-government system, the administrative approval module handles the application, acceptance, review, and completion processes for various administrative approval matters, while the information release module is responsible for publishing relevant government policies, announcements, news, and other information to the system for public access. Module-related data refers to data that describes the relationships between the various functional modules in the e-government system. It represents information such as the interaction methods, data flows, and dependencies between different functional modules. For example, there is related data between the administrative approval module and the archives management module. When an administrative approval matter is completed, the relevant approval documents and result data are transferred to the archives management module for storage. This transmission rules and data interface information constitute module-related data. Functional behavior data represents the specific behaviors and operational records exhibited by each functional module during the operation of the e-government system. It refers to data that records the system's behavior at different time points, such as the invocation of functional modules, the execution of operations, and the generation of results. For example, within a historical period of time, information such as the number of times the administrative approval module was called, the time of each call, the type of matters handled, and the approval results (passed or failed) all belong to functional behavior data.

[0033] Step S11: Arrange the system function modules and module-related data to obtain a behavior pointer turntable and a pointer behavior path.

[0034] In an embodiment of the present application, the behavior pointer turntable refers to organizing the system function modules according to certain logic and rules to form a turntable-like structure, in which the pointers are used to point to different function modules. It is used to represent the set of different function modules executed by the system in a specific scenario and the relative position relationship between them. For example, in a government approval process, the behavior pointer turntable contains an application acceptance module, a review module, an approval module, a completion feedback module, etc. The initial position of the pointer points to the application acceptance module. As the approval process progresses, the pointer will point to subsequent modules in turn. The pointer behavior path represents the trajectory of the pointer moving on the behavior pointer turntable, which reflects the calling sequence and execution process between the function modules of the system in different business scenarios. For example, in the above-mentioned government approval process, the pointer behavior path starts from the application acceptance module, passes through the review module, approval module and other modules in turn, and finally reaches the completion feedback module to complete the entire approval process.

[0035] Specifically, when creating a behavior pointer turntable and a pointer behavior path, the first weight value is obtained by performing an application frequency weight determination on the system function module, the second weight value is obtained by performing an abnormal number weight determination on the system function module, and the third weight value is obtained by performing an abnormal consequence weight determination on the system function module. The number of reference branches between each system function module and other system function modules is determined according to the module association data, and the number of reference branches is multiplied by the sum of the first weight value, the second weight value, and the third weight value to obtain the comprehensive weight value corresponding to each system function module. The system function modules are sorted according to the comprehensive weight value, and the system function modules are placed in the initial pointer turntable according to the sorted module sequence to obtain the behavior pointer turntable. A module association determination is performed on each system function module on the behavior pointer turntable according to the module association data, and on the premise of determining that there is an association between the system function modules, a path is constructed between the associated system function modules to obtain the pointer behavior path.

[0036] In the embodiments of the present application, application frequency weighting refers to assigning a weight to a system function module based on the number or frequency of its use within a specific time period. This weighting indicates how frequently a module is used within the e-government system. For example, the household registration management module is accessed daily by a large number of users for services such as household registration transfers and newborn registration. Its application frequency is high, so it has a higher application frequency weight. However, a specific administrative approval module is only used in specific circumstances, has a lower application frequency, and therefore a lower weight. Abnormality weighting refers to assigning a weight based on the number of abnormalities (such as errors, failures, and crashes) that occur during the operation of a system function module. This weighting reflects the stability and reliability of the module. Abnormal consequence weighting indicates the impact of an abnormality in a system function module on the overall system operation, user service, or data security. This weighting is assigned accordingly. It reflects the severity of the abnormality. For example, if an abnormality in the payment processing module causes a user's payment to fail or be duplicated, resulting in financial losses, the abnormal consequence weighting will be higher. However, an abnormality in the information query module only affects the timeliness of user information queries, resulting in relatively minor consequences and a lower weighting. The number of reference branches is determined based on module association data. This refers to the number of times each system function module directly calls or associates with other modules. For example, the user authentication module is called by multiple modules, including the household registration management module, the tax declaration module, and the social security processing module, for user identity verification. Therefore, it has a large number of reference branches. The comprehensive weight value for each system function module is calculated by multiplying the number of reference branches by the sum of the first weight value (application frequency weight), the second weight value (anomaly count weight), and the third weight value (anomaly consequence weight). The formula is: Comprehensive weight value = Number of reference branches × (first weight value + second weight value + third weight value). This takes into account the module's frequency of use, stability, the impact of anomalies, and its associations with other modules.

[0037] For the embodiment of the present application, the first functional module is determined according to the module sequence, and the first functional module is placed in the center wheel corresponding to the initial pointer wheel. The first functional module is the system functional module ranked first in the module sequence. The second functional module set associated with the first functional module in the module sequence and the first module ranking corresponding to each system functional module in the second functional module set are determined. It is judged whether the ranking of the first module meets the preset ranking standard corresponding to the initial pointer wheel. If so, the system functional module in the second functional module set is placed in the first functional wheel corresponding to the initial pointer wheel. If not, the system functional module is retained and the retained system functional module is transferred to the next wheel for determination. The N+1th functional module set associated with the Nth functional module in the module sequence and the Nth module ranking corresponding to each functional module in the N+1th functional module set are determined, where N is greater than or equal to 2. Determine whether the ranking of the Nth module and the ranking of the reserved modules corresponding to the system function modules retained before the Nth function module meet the preset ranking standard. If so, the system function modules in the N+1th function module set and the system function modules retained before the Nth function module are placed in the Nth function wheel corresponding to the initial pointer wheel. If not, the system function modules are retained and transferred to the next wheel for judgment, until all the system function modules in the module sequence are placed in the initial pointer wheel to obtain the behavior pointer wheel.

[0038] Specifically, the initial pointer carousel is a blank carousel structure that has not yet been populated with any system functional modules. It is typically composed of multiple concentric wheels, each of which can accommodate a different number of functional modules. The center wheel of the initial pointer carousel is used to place the most important functional module, while the outer wheels are used to place the less important modules. The preset ranking standard is a pre-set ranking threshold used to determine whether a functional module is eligible for placement in the current functional wheel. For example, the preset ranking standard stipulates that only the top five modules can be placed in the first functional wheel.

[0039] Step S12: Perform abnormal behavior verification on the functional behavior data to determine whether the functional behavior data is abnormal behavior data. If so, input the functional behavior data into a preset behavior correction model for abnormal correction identification to obtain corrected behavior data corresponding to the functional behavior data.

[0040] Specifically, functional behavior data refers to the behavioral data generated by users or system components when performing functions in the e-government system, including operation records, interaction logs, system responses, etc. For example, the login time, operation path, and submitted form data when a user logs into the e-government platform are all considered functional behavior data.

[0041] Abnormal behavior verification examines functional behavior data to determine whether it conforms to expected behavioral patterns or rules. For example, a user's multiple failed login attempts within a short period of time is considered abnormal behavior; a system component's frequent calls to a functional module during non-working hours is also considered abnormal. Abnormal behavior data is functional behavior data that, after abnormal behavior verification, is determined to not conform to expected behavioral patterns or rules. Examples include a user using illegal characters to fill out a form or a system module generating a large number of error requests within a short period of time. The preset behavior correction model is a pre-trained machine learning model or rules engine used to identify and correct abnormal behavior data. This model is trained based on historical abnormal behavior data and normal behavior data, and can identify abnormal behavior types and provide corrective recommendations. Corrective behavior data is generated by analyzing and identifying abnormal behavior data using the preset behavior correction model, generating data or recommendations for correcting abnormal behavior. Examples include corrected valid form data and adjusted system call frequency.

[0042] Step S13: Bind the correction behavior data and the functional behavior data with the pointer behavior path according to a preset corresponding relationship to obtain behavior path data.

[0043] In this embodiment of the present application, the preset correspondence is a predefined mapping relationship between the modified behavior data, the functional behavior data, and the pointer behavior path. The behavior path data is a data structure formed by binding the modified behavior data and the functional behavior data to the pointer behavior path, and is used to record and analyze the association between the behavior path and the data.

[0044] Specifically, design a database table structure, including tables for correction behavior data, functional behavior data, and pointer behavior paths. Define foreign keys or associated fields in the tables to establish correspondences between correction behavior data, functional behavior data, and pointer behavior paths. Use SQL queries or an ORM framework (such as Hibernate) to bind data to corresponding path records. When querying or generating behavior path data, use JOIN operations to connect related tables to obtain the complete behavior path and its data.

[0045] Step S14: When it is detected that the operator has logged into the e-government system, the operator's real-time operation behavior is collected.

[0046] Specifically, operators enter the e-government system's interface by entering authentication information such as a username, password, and verification code. For example, a citizen clicks the "Login" button on the e-government website's homepage and successfully enters the system after entering the correct account and password. Real-time operations are the various immediate actions performed by operators on the system interface after logging into the e-government system and the associated data generated. Examples include actions such as clicking menu options, filling out forms, submitting applications, and querying information, as well as data such as the timestamp of the operation, the object of the operation (such as the specific functional module), and the result of the operation (success or failure).

[0047] Step S15: performing abnormality determination on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result.

[0048] For the embodiment of the present application, the real-time operation behavior is classified, the operator's real-time behavior category is determined, the real-time behavior category is matched with the preset category segmentation standard, and the real-time operational behavior segmentation specification is obtained. The real-time operation behavior is segmented into nodes based on the behavior segmentation specification to obtain multiple behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes. The multiple behavior operation nodes are sorted in sequence according to the time node to obtain an operation node sequence, and the operation node sequence is detected for abnormal behavior sequence according to the behavior pointer dial to obtain a node judgment result. The behavior demonstration data is detected for abnormal behavior data according to the behavior path data to obtain a data judgment result, and the node judgment result and the data judgment result are correspondingly bound and integrated to obtain an abnormal judgment result.

[0049] In the embodiments of the present application, the preset category segmentation criteria are predefined rules or conditions for categorizing real-time operational behaviors. For example, behavior categories are categorized based on the object of the operation (e.g., functional module), the type of operation (e.g., click, input), or the purpose of the operation (e.g., query, submit). The behavior segmentation specification is a specification or criterion derived from classifying real-time operational behaviors based on the preset category segmentation criteria, and is used to guide how to segment operational behaviors into different nodes.

[0050] When performing abnormal behavior sequence detection on an operation node sequence, the positions of the pointer dials corresponding to the multiple behavior operation nodes are determined based on the system function modules corresponding to the multiple behavior operation nodes and the system function modules corresponding to the behavior pointer dial. Based on the positions of the pointer dials, multiple behavior operation nodes are placed in the behavior pointer dial to perform a behavior node abnormality determination simulation to determine whether there is a behavior node abnormality in the operation node sequence. If so, the abnormal module position and the correction module position corresponding to the behavior node abnormality are determined based on the behavior pointer dial, and the abnormal module position and the correction module position are used as the node determination result.

[0051] When detecting abnormal behavior data on behavior demonstration data: determine the path data samples corresponding to the behavior demonstration data based on the behavior nodes corresponding to the behavior demonstration data and the behavior nodes corresponding to the behavior path data, construct a first data type curve based on the behavior demonstration data, and construct a second data type curve based on the path data samples. Split the second data type curve based on whether the path data samples are abnormal, obtaining a third data type curve without abnormal data and a fourth data type curve with abnormal data. Compare the first data type curve with the third data type curve and the fourth data type curve according to data type, respectively, to obtain a first overlap ratio corresponding to the third data type curve and a second overlap ratio with the fourth data type curve. Input the first overlap ratio and the second overlap ratio into a preset overlap ratio standard for determination. If both the first overlap ratio and the second overlap ratio meet the preset overlap ratio standard, perform a behavioral abnormality pre-diagnosis on the second overlap ratio to obtain a data determination result. If not, determine the data abnormality factors corresponding to the first overlap ratio and the second overlap ratio according to the preset overlap ratio standard, and generate a data determination result based on the data abnormality factors.

[0052] Specifically, under the premise that both the first overlap rate and the second overlap rate meet the preset overlap rate standard, in order to determine the possible subsequent behavioral anomalies, the present application adopts the technical means of overlap rate prediction: determine the time overlap rate of the first data type curve and the fourth data type curve in the preset unit time according to the second overlap rate, and construct a overlap rate curve corresponding to the time overlap rate, determine the curve extension vector extending from different unit time points to the next unit time point according to the overlap rate curve, and the overlap rate feature corresponding to each unit time point, determine the extension vector feature based on the curve extension vector, and bind the extension vector feature with the overlap rate feature to obtain a point feature set. Arrange the point feature set in a matrix according to the time sequence to obtain a point feature matrix. Deduct the point feature matrix from the point feature set according to the unit time period to obtain a predicted point matrix in the future period. Determine the future point feature set based on the predicted point matrix, and determine the future overlap rate in the future period based on the future point feature set, judge the future overlap rate based on the preset overlap rate standard, and obtain a data judgment result.

[0053] In the embodiment of the present application, the preset overlap rate standard is a pre-set threshold value or rule for determining whether the curve overlap rate meets the requirements. For example, it is stipulated that the first overlap rate should be greater than 80% and the second overlap rate should be less than 30% to meet the standards.

[0054] From the perspective of data relevance: The correlation between the first overlap rate (the first data type curve and the third data type curve) and normal data: The first data type curve is constructed based on behavioral demonstration data, while the third data type curve is constructed based on path data samples without anomalies. Under normal circumstances, the behavioral demonstration data and the path data samples without anomalies should have a high correlation. For example, in a normal online form filling process, there is a certain regularity between the user's input speed (behavioral demonstration data) and the user's operation sequence and dwell time on the form page (reflected by the path data samples without anomalies). If the user follows the normal process, the first data type curve reflecting the input speed changes and the third data type curve reflecting the time distribution of the operation process should have a high degree of overlap. Therefore, the first overlap rate is set to greater than 80% to ensure a close correlation between the behavioral demonstration data and normal path data. When the overlap rate falls below this threshold, it indicates that the behavioral demonstration data is anomaly. Sensitivity of anomaly detection: A higher first overlap rate threshold can improve the sensitivity of anomaly detection. If the threshold is set too low, some minor anomalies may be overlooked, thus failing to detect potential problems in a timely manner. For example, when a user is entering data, although the overall process seems normal, the input speed suddenly fluctuates abnormally. If the first overlap rate threshold is set too low, this subtle abnormality cannot be detected, while an 80% threshold can better capture this change.

[0055] Second Overlap Rate (First Data Type Curve and Fourth Data Type Curve) Correlation with Abnormal Data: The fourth data type curve is constructed based on path data samples containing abnormal data. Due to the presence of anomalies, the correlation between the behavioral demonstration data and these abnormal path data should be low. For example, in a business process, users should normally access pages in a specific order. However, if the path data sample contains abnormal page jumps (perhaps due to system errors or malicious operations), the overlap rate between the first data type curve, which reflects changes in user input data, and the fourth data type curve, which reflects the time distribution of abnormal page jumps, should be very low. Therefore, the second overlap rate is set below 30% to ensure a clear difference between the behavioral demonstration data and the abnormal path data. When the overlap rate exceeds this threshold, it means that the behavioral demonstration data is also affected by the anomaly. Eliminating the possibility of false positives: A lower second overlap rate threshold can reduce the possibility of false positives. If the threshold is set too high, some normal behavioral demonstration data may be mistakenly classified as abnormal. For example, in some cases, although the path data sample contains some anomalies, the behavioral demonstration data may not be affected and still maintain a normal pattern. If the second overlap rate threshold is set too high, this normal behavioral demonstration data will be mistakenly classified as abnormal.

[0056] From the perspective of data accuracy and reliability: The first overlap rate ensures data consistency: Behavior demonstration data and path data samples should accurately reflect user operations and business processes. A high first overlap rate ensures consistency between the two types of data and reduces data errors. For example, if behavior demonstration data records user input during actual operations, while path data samples record the user's operation trajectory in the system, the two types of data should confirm each other. A low overlap rate may mean that one of the data is recorded incorrectly or inaccurately. It also improves the reliability of data analysis: Accurate and reliable data is the foundation for business analysis and decision-making. A high first overlap rate improves the reliability of data analysis, making the analysis results more valuable. For example, by analyzing the overlap between behavior demonstration data and path data samples, it is possible to understand user behavior habits and business process bottlenecks, providing a basis for system optimization and business improvement.

[0057] The second overlap rate can filter out interference data: In the actual data collection and analysis process, there may be some interference data, such as data noise, abnormal fluctuations, etc. By setting a lower second overlap rate threshold, these interference data can be filtered out, making the analysis results more accurate. For example, if the high overlap rate between the behavior demonstration data and the abnormal path data is caused by data noise, then a lower threshold can minimize this impact. Ensure the accuracy of anomaly detection: Accurate anomaly detection is the key to ensuring the safety and stable operation of the system. A lower second overlap rate threshold can improve the accuracy of anomaly detection, avoid misjudging normal data as abnormal, and ensure that abnormal data can be discovered and processed in a timely manner.

[0058] In an embodiment of the present application, data on system function modules and module associations, as well as functional behavior data from historical time periods, are acquired for an e-government system. This data forms the basis for constructing a behavior indicator carousel and pointer behavior paths, reflecting the architecture and connections between modules within the system. Historical functional behavior data, however, contains records of past system operations and serves as the basis for subsequent analysis. Acquiring this basic data provides comprehensive data support for subsequent in-depth analysis of system operational behavior. The acquired system function modules and module association data are organized to produce a behavior indicator carousel and pointer behavior paths. The behavior indicator carousel intuitively displays the relationships between system function modules, providing a clear overview of the system architecture; the pointer behavior paths record the interaction sequence and behavior patterns of each module under normal operational processes. These two findings, achieved through the organization and analysis of basic data, present the system's complex module relationships and operational processes in a structured manner. This structuring facilitates the rapid and accurate identification of operational behaviors within the system, determining whether they conform to normal processes, and providing a clear reference standard for subsequent anomaly verification of functional behavior data, thereby effectively improving the efficiency and accuracy of anomaly detection. Performing anomaly verification on functional behavior data can filter out problematic data. For abnormal behavior data, it is input into a pre-set behavior correction model for anomaly correction identification, generating corrected behavior data. The pre-set behavior correction model, trained based on a large amount of normal behavior data, accurately identifies abnormal behavior and provides correction recommendations. This process ensures timely detection and correction of abnormal behavior, making functional behavior data more accurate and reliable. Corrected behavior data and functional behavior data are bound to the pointer behavior path according to pre-set correspondences to generate behavior path data. The pre-set correspondences clearly define the associations between different behavior data and pointer behavior paths. This binding operation tightly integrates the behavior data with the operational processes of system modules. Behavior path data not only includes specific operational behaviors but also clarifies their position and sequence within the system's operational processes. This integrated approach enables a more comprehensive and in-depth analysis of system operational behavior, clearly demonstrating the contextual relationship of each operational behavior within the overall system operation. When an operator is detected logging into the e-government system, their real-time operational behavior is collected. Real-time operational behavior truly reflects the current state of the system's operation and is directly related to the system's security and stability. Abnormality is determined for real-time operational behavior based on the previously generated behavior pointer wheel and behavior path data. The behavior pointer dial and behavior path data provide accurate reference standards for abnormality judgment. By comparing real-time operation behavior with these standards, it is possible to quickly determine whether the behavior conforms to the normal operation process and module association relationship of the system.This anomaly determination method based on historical data and system architecture can promptly detect improper operations or potential security threats by operators, prevent data leakage, system failures and other problems caused by abnormal operations, and improve the efficiency of abnormal behavior detection and identification in e-government systems.

[0059] The above embodiment introduces an abnormal behavior detection method for an e-government system from the perspective of method flow. The following embodiment introduces an abnormal behavior detection system for an e-government system from the perspective of a virtual module or virtual unit. Please refer to the following embodiment for details.

[0060] The embodiment of the present application provides an abnormal behavior detection system 20 for an e-government system, such as Figure 2 As shown, Figure 2 This is a schematic diagram of the structure of an abnormal behavior detection system for an e-government system provided in an embodiment of the present application. The system 20 may specifically include: The data acquisition module 21 is used to acquire the system function modules and module association data of the e-government system and the function behavior data of the e-government system in a historical time period; The data sorting module 22 is used to sort the system function modules and module-related data to obtain the behavior pointer turntable and pointer behavior path; The behavior verification module 23 is used to perform abnormal behavior verification on the functional behavior data to determine whether the functional behavior data is abnormal behavior data. If so, the functional behavior data is input into a preset behavior correction model for abnormal correction identification to obtain corrected behavior data corresponding to the functional behavior data; The data binding module 24 is used to bind the correction behavior data and the functional behavior data with the pointer behavior path according to a preset correspondence relationship to obtain behavior path data; The behavior collection module 25 is used to collect the operator's real-time operation behavior after detecting that the operator has logged into the e-government system; The abnormality determination module 26 is used to perform abnormality determination on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result.

[0061] In one possible implementation of the embodiment of the present application, the data sorting module 22 sorts the system function modules and module-related data to obtain the behavior pointer turntable and the pointer behavior path, specifically for: Performing application frequency weight determination on the system function modules to obtain a first weight value; Performing a weighted determination of the number of abnormalities on the system function module to obtain a second weight value; Perform abnormal consequence weight determination on the system function module to obtain a third weight value; Determine the number of reference branches between each system function module and other system function modules according to the module association data, and multiply the number of reference branches by the sum of the first weight value, the second weight value, and the third weight value to obtain a comprehensive weight value corresponding to each system function module; Sort the system function modules according to the comprehensive weight values, and place the system function modules into the initial pointer turntable according to the sorted module sequence to obtain the behavior pointer turntable; According to the module association data, module association is determined for each system function module on the behavior pointer dial, and on the premise of determining that there is association between the system function modules, paths are constructed between the associated system function modules to obtain the pointer behavior path.

[0062] In another possible implementation of the embodiment of the present application, the data sorting module 22 places the system function modules into the initial pointer turntable according to the sorted module sequence to obtain the behavior pointer turntable, specifically for: Determine the first functional module according to the module sequence, and place the first functional module in the center wheel corresponding to the initial pointer wheel. The first functional module is the system functional module ranked first in the module sequence. Determine a set of second functional modules associated with the first functional module in the module sequence and a first module ranking corresponding to each system functional module in the set of second functional modules; Determine whether the ranking of the first module meets the preset ranking standard corresponding to the initial pointer wheel. If so, place the system function module in the second function module set into the first function wheel corresponding to the initial pointer wheel. If not, retain the system function module and transfer the retained system function module to the next wheel for determination. Determine the N+1th functional module set associated with the Nth functional module in the module sequence and the Nth module ranking corresponding to each functional module in the N+1th functional module set, where N is greater than or equal to 2; Determine whether the ranking of the Nth module and the ranking of the reserved modules corresponding to the system function modules retained before the Nth function module meet the preset ranking standard. If so, the system function modules in the N+1th function module set and the system function modules retained before the Nth function module are placed in the Nth function wheel corresponding to the initial pointer wheel. If not, the system function modules are retained and transferred to the next wheel for judgment, until all the system function modules in the module sequence are placed in the initial pointer wheel to obtain the behavior pointer wheel.

[0063] In another possible implementation of the embodiment of the present application, the abnormality determination module 26 performs abnormality determination on the real-time operation behavior based on the behavior pointer dial and the behavior path data, and obtains the abnormality determination result, specifically for: Categorize real-time operation behaviors and determine the operator's real-time behavior category; Matching real-time behavior categories with preset category segmentation criteria to obtain real-time operational behavior segmentation specifications; Perform node segmentation on the real-time operation behavior based on the behavior segmentation specification to obtain multiple behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes; Sort multiple behavior operation nodes in sequence according to time nodes to obtain an operation node sequence; According to the behavior pointer dial, the operation node sequence is tested for abnormal behavior sequence to obtain the node judgment result; Perform abnormal behavior data detection on the behavior demonstration data according to the behavior path data to obtain data judgment results; The node judgment results and data judgment results are correspondingly bound and integrated to obtain the abnormal judgment results.

[0064] In another possible implementation of the embodiment of the present application, when the abnormality determination module 26 detects abnormal behavior sequences of the operation node sequence according to the behavior pointer dial and obtains the node determination result, it is specifically configured to: Determine the positions of the pointer turntables corresponding to the multiple behavior operation nodes according to the system function modules corresponding to the multiple behavior operation nodes and the system function modules corresponding to the behavior pointer turntables; Based on the position of the pointer turntable, multiple behavior operation nodes are placed into the behavior pointer turntable to perform a behavior node anomaly judgment simulation to determine whether there is a behavior node anomaly in the operation node sequence. If so, the abnormal module position and the correction module position corresponding to the behavior node anomaly are determined according to the behavior pointer turntable, and the abnormal module position and the correction module position are used as the node judgment result.

[0065] In another possible implementation of the embodiment of the present application, when the abnormality determination module 26 performs abnormal behavior data detection on the behavior demonstration data according to the behavior path data and obtains the data determination result, it is specifically configured to: Determine the path data sample corresponding to the behavior demonstration data according to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data; Constructing a first data type curve based on the behavior demonstration data and constructing a second data type curve based on the path data samples; Splitting the curve of the second data type based on whether the path data sample is abnormal or not to obtain a curve of the third data type without abnormal data and a curve of the fourth data type with abnormal data; Performing curve overlap comparison on the first data type curve, the third data type curve, and the fourth data type curve according to data types, respectively, to obtain a first overlap ratio corresponding to the third data type curve and a second overlap ratio corresponding to the fourth data type curve; The first overlap rate and the second overlap rate are input into the preset overlap rate standard for judgment. If the first overlap rate and the second overlap rate both meet the preset overlap rate standard, the second overlap rate is pre-diagnosed for behavioral abnormality to obtain a data judgment result. If it does not meet the standard, the data abnormality factors corresponding to the first overlap rate and the second overlap rate are determined according to the preset overlap rate standard, and the data judgment result is generated based on the data abnormality factors.

[0066] In another possible implementation of the embodiment of the present application, when the abnormality determination module 26 performs a behavioral abnormality pre-diagnosis on the second overlap rate and obtains a data determination result, it is specifically configured to: Determine the time overlap rate between the first data type curve and the fourth data type curve within a preset unit time according to the second overlap rate, and construct a overlap rate curve corresponding to the time overlap rate; Determine the curve extension vector of different unit time points extending to the next unit time point and the coincidence rate characteristics corresponding to each unit time point according to the coincidence rate curve; Determine the extension vector feature based on the curve extension vector, and bind the extension vector feature with the coincidence rate feature to obtain a point feature set; Arrange the point feature set in a matrix according to the time sequence to obtain the point feature matrix; The point feature matrix is deduced from the point feature set according to the unit time period to obtain the predicted point matrix in the future period; Determine a future point feature set according to the predicted point matrix, and determine a future coincidence rate in a future period based on the future point feature set; The future overlap rate is determined based on the preset overlap rate standard to obtain a data determination result.

[0067] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the abnormal behavior detection system 20 for the e-government system described above can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here.

[0068] An electronic device is provided in an embodiment of the present application, such as Figure 3 As shown, Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 3The electronic device 300 shown includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the electronic device 300 may further include a transceiver 304. It should be noted that in actual applications, the number of transceivers 304 is not limited to one, and the structure of the electronic device 300 does not constitute a limitation on the embodiments of the present application.

[0069] Processor 301 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 301 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0070] Bus 302 may include a path for transmitting information between the above components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. Bus 302 may be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 3 Only one thick line is used in the diagram, but it does not mean that there is only one bus or one type of bus.

[0071] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0072] The memory 303 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 301. The processor 301 is used to execute the application code stored in the memory 303 to implement the content shown in the above method embodiment.

[0073] Electronic devices include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. They may also include servers, etc. Figure 3 The electronic device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.

[0074] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer-readable storage medium is run on a computer, the computer can execute the corresponding contents of the aforementioned method embodiment.

[0075] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0076] The above are only some of the implementation methods of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for detecting abnormal behavior in an e-government system, characterized in that: include: Obtaining system function modules and module association data of the e-government system and function behavior data of the e-government system in a historical period; Arrange the system function modules and module-related data to obtain a behavior pointer turntable and a pointer behavior path; Performing abnormal behavior verification on the functional behavior data to determine whether the functional behavior data is abnormal behavior data; if so, inputting the functional behavior data into a preset behavior correction model to perform abnormal correction identification to obtain corrected behavior data corresponding to the functional behavior data; Binding the correction behavior data, the functional behavior data and the pointer behavior path according to a preset correspondence to obtain behavior path data; When an operator is detected logging into the e-government system, the operator's real-time operation behavior is collected; An abnormality determination is performed on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result.

2. The abnormal behavior detection method for an e-government system according to claim 1, characterized in that: The system function modules and module-related data are sorted to obtain a behavior pointer turntable and a pointer behavior path, including: Performing application frequency weight determination on the system function module to obtain a first weight value; Performing a weighted determination of the number of abnormalities on the system function module to obtain a second weight value; Performing abnormal consequence weight determination on the system function module to obtain a third weight value; Determining the number of reference branches between each of the system function modules and other system function modules according to the module association data, and multiplying the number of reference branches by the sum of the first weight value, the second weight value, and the third weight value to obtain a comprehensive weight value corresponding to each system function module; Sorting the system function modules according to the comprehensive weight values, and placing the system function modules into an initial pointer turntable according to the sorted module sequence to obtain a behavior pointer turntable; A module association determination is performed on each system function module on the behavior pointer dial according to the module association data, and on the premise of determining that there is an association between the system function modules, a path is constructed between the associated system function modules to obtain a pointer behavior path.

3. The abnormal behavior detection method for an e-government system according to claim 2, characterized in that: The system function modules are placed into the initial pointer turntable according to the sorted module sequence to obtain the behavior pointer turntable, including: Determine a first functional module according to the module sequence, and place the first functional module in the center wheel corresponding to the initial pointer wheel, wherein the first functional module is the system functional module ranked first in the module sequence; Determining a second functional module set associated with the first functional module in the module sequence and a first module ranking corresponding to each system functional module in the second functional module set; Determine whether the ranking of the first module meets the preset ranking standard corresponding to the initial pointer wheel; if so, place the system function module in the second function module set into the first function wheel corresponding to the initial pointer wheel; if not, retain the system function module and transfer the retained system function module to the next wheel for determination; Determine an N+1th functional module set associated with the Nth functional module in the module sequence and an Nth module ranking corresponding to each functional module in the N+1th functional module set, where N is greater than or equal to 2; Determine whether the ranking of the Nth module and the ranking of the reserved modules corresponding to the system function modules retained before the Nth function module meet the preset ranking standard; if so, place the system function modules in the N+1th function module set and the system function modules retained before the Nth function module into the Nth function wheel corresponding to the initial pointer wheel; if not, retain the system function modules and transfer the retained system function modules to the next wheel for determination, until all the system function modules in the module sequence are placed into the initial pointer wheel to obtain the behavior pointer wheel.

4. The abnormal behavior detection method for an e-government system according to claim 1, characterized in that: The performing abnormality determination on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result includes: Classifying the real-time operation behavior to determine the real-time behavior category of the operator; Matching the real-time behavior category with a preset category segmentation standard to obtain the real-time operational behavior segmentation specification; Performing node segmentation on the real-time operation behavior based on the behavior segmentation specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes; Sorting the multiple behavior operation nodes in sequence according to time nodes to obtain an operation node sequence; Perform abnormal behavior sequence detection on the operation node sequence according to the behavior pointer dial to obtain a node determination result; Perform abnormal behavior data detection on the behavior demonstration data according to the behavior path data to obtain a data determination result; The node determination result and the data determination result are correspondingly bound and integrated to obtain an abnormality determination result.

5. The abnormal behavior detection method for an e-government system according to claim 4, characterized in that: The abnormal behavior sequence detection is performed on the operation node sequence according to the behavior pointer dial to obtain a node determination result, including: Determining the positions of the pointer turntables corresponding to the plurality of behavior operation nodes according to the system function modules corresponding to the plurality of behavior operation nodes and the system function modules corresponding to the behavior pointer turntable; Based on the position of the pointer dial, the multiple behavior operation nodes are placed into the behavior pointer dial to perform a behavior node abnormality determination simulation to determine whether there is a behavior node abnormality in the operation node sequence. If so, the abnormal module position and the correction module position corresponding to the behavior node abnormality are determined according to the behavior pointer dial, and the abnormal module position and the correction module position are used as the node determination result.

6. The abnormal behavior detection method for an e-government system according to claim 4, characterized in that: The abnormal behavior data detection is performed on the behavior demonstration data according to the behavior path data to obtain a data determination result, including: Determining a path data sample corresponding to the behavior demonstration data according to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data; constructing a first data type curve based on the behavior demonstration data, and constructing a second data type curve based on the path data sample; Splitting the second data type curve based on whether the path data sample is abnormal or not to obtain a third data type curve without abnormal data and a fourth data type curve with abnormal data; performing curve overlap comparison on the first data type curve, the third data type curve, and the fourth data type curve according to data types, respectively, to obtain a first overlap ratio corresponding to the third data type curve and a second overlap ratio corresponding to the fourth data type curve; The first overlap rate and the second overlap rate are input into a preset overlap rate standard for judgment. If the first overlap rate and the second overlap rate both meet the preset overlap rate standard, the second overlap rate is pre-diagnosed for behavioral abnormality to obtain a data judgment result. If not, the data abnormality factors corresponding to the first overlap rate and the second overlap rate are determined according to the preset overlap rate standard, and a data judgment result is generated based on the data abnormality factors.

7. The abnormal behavior detection method for an e-government system according to claim 6, characterized in that: The performing of behavioral abnormality pre-diagnosis on the second coincidence rate to obtain a data determination result includes: Determine a time overlap rate between the first data type curve and the fourth data type curve within a preset unit time according to the second overlap rate, and construct a overlap rate curve corresponding to the time overlap rate; Determine, based on the coincidence rate curve, a curve extension vector extending from different unit time points to the next unit time point and a coincidence rate feature corresponding to each unit time point; Determining an extension vector feature based on the curve extension vector, and binding the extension vector feature with the coincidence rate feature to obtain a point feature set; Arranging the point feature set in a matrix according to time sequence to obtain a point feature matrix; Deducing the point feature matrix from the point feature set according to a unit time period to obtain a predicted point matrix in a future period; Determining a future point feature set according to the predicted point matrix, and determining a future coincidence rate in a future period based on the future point feature set; The future overlap rate is determined based on the preset overlap rate standard to obtain a data determination result.

8. An abnormal behavior detection system for an e-government system, characterized in that: include: A data acquisition module is used to acquire system function modules and module association data of the e-government system and functional behavior data of the e-government system in a historical period; A data sorting module is used to sort the system function modules and module-related data to obtain a behavior pointer turntable and a pointer behavior path; a behavior verification module, configured to perform abnormal behavior verification on the functional behavior data to determine whether the functional behavior data is abnormal behavior data; if so, input the functional behavior data into a preset behavior correction model to perform abnormal correction identification, and obtain corrected behavior data corresponding to the functional behavior data; a data binding module, configured to bind the correction behavior data, the functional behavior data and the pointer behavior path according to a preset corresponding relationship to obtain behavior path data; The behavior collection module is used to collect the operator's real-time operation behavior after detecting that the operator has logged into the e-government system; The abnormality determination module is used to perform abnormality determination on the real-time operation behavior according to the behavior pointer dial and the behavior path data to obtain an abnormality determination result.

9. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executes the abnormal behavior detection method for an e-government system according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The device stores a computer program that can be loaded by a processor and execute the abnormal behavior detection method for an e-government system according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Persistent annotation of syntax graphs for code optimization

    CN114041117A

  • Method and system for verifying and correcting integrity of flight data and storage medium

    CN119336746A

  • Method of scheduling modules on a carousel

    US20030002515A1

  • Dynamic progressive awareness

    US20190279405A1