An abnormal behavior detection method and system for an e-government system

By constructing a behavior pointer turntable and path, and combining it with a preset model to determine abnormal behaviors in the e-government system, the problem of low detection efficiency caused by complex operation behavior paths is solved, and efficient and accurate abnormal behavior identification and correction are achieved, thus ensuring system security.

CN120492456BActive Publication Date: 2026-01-02WUHAN ZHONGLIAN HENGXING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510579454.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2026-01-02
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The operational behavior paths in e-government systems are complex and varied, making them difficult to describe with simple and fixed rules, resulting in low efficiency in detecting and identifying abnormal behavior.

Method used

By acquiring system functional modules and module-related data, as well as historical behavior data, a behavior pointer turntable and pointer behavior path are constructed. Anomalies are determined by combining the preset behavior correction model, and operational behaviors are collected in real time and compared with historical data to identify and correct abnormal behaviors.

Benefits of technology

It improves the efficiency and accuracy of abnormal behavior detection, enables timely detection and correction of abnormal operations, prevents data leakage and system failure, and ensures the safe and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120492456B_ABST
    Figure CN120492456B_ABST
Patent Text Reader

Abstract

The application relates to an abnormal behavior detection method and system for an e-government system, and relates to the technical field of anomaly detection, which comprises the following steps: acquiring system function modules, module association data and function behavior data, arranging the system function modules and the module association data, obtaining a behavior pointer carousel and a pointer behavior path, performing abnormal behavior checking on the function behavior data, determining whether the function behavior data is abnormal behavior data, if yes, inputting the function behavior data into a preset behavior correction model to perform abnormal correction identification, obtaining corrected behavior data, binding the corrected behavior data, the function behavior data and the pointer behavior path according to a preset corresponding relationship to obtain behavior path data, collecting real-time operation behaviors of an operator, performing abnormal determination on the real-time operation behaviors according to the behavior pointer carousel and the behavior path data, and obtaining an abnormal determination result. The application improves the abnormal behavior detection and identification efficiency of the e-government system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of anomaly detection, in particular to an abnormal behavior detection method and system for an e-government system. BACKGROUND

[0002] With the rapid development of information technology, e-government systems play an increasingly important role in daily office work, public service provision and government management of government departments. E-government systems integrate a large number of functional modules, which are interrelated and work together to realize digital processing and efficient flow of government business. However, e-government systems face many security challenges and business specification problems during operation. Among them, the detection and processing of abnormal operation behavior is a key link to ensure the safe and stable operation of the system and the compliance of government business.

[0003] E-government systems usually include multiple functional modules, such as administrative approval, document circulation, information release, data statistics, etc. There are complex relationships between different modules. The diversity and correlation of these modules make the behavior path of the operator in the system complex and variable. For example, when handling an administrative approval business, the operator needs to access multiple functional modules in sequence and operate according to a specific process order. Due to the differences between different business scenarios and processes, the behavior path of the operator is difficult to describe with simple and fixed rules, which makes it difficult to accurately identify normal and abnormal operation behaviors, thereby reducing the efficiency of abnormal behavior detection and identification of e-government systems. SUMMARY

[0004] To solve at least one of the above technical problems, the application provides an abnormal behavior detection method and system for an e-government system.

[0005] In a first aspect, the application provides an abnormal behavior detection method for an e-government system, which adopts the following technical solution:

[0006] An abnormal behavior detection method for an e-government system, comprising:

[0007] Obtaining system functional modules and module association data of the e-government system and functional behavior data of the e-government system in a historical time period;

[0008] Organizing the system functional modules and module association data to obtain a behavior pointer carousel and a pointer behavior path;

[0009] The function behavior data is subjected to abnormal behavior checking to determine whether the function behavior data is abnormal behavior data, and if so, the function behavior data is input into a preset behavior correction model for abnormal correction recognition to obtain corrected behavior data corresponding to the function behavior data;

[0010] The corrected behavior data and the function behavior data are bound to the pointer behavior path according to a preset correspondence to obtain behavior path data;

[0011] When it is detected that an operator logs in to the e-government system, real-time operation behavior of the operator is collected;

[0012] The real-time operation behavior is subjected to abnormality determination according to the behavior pointer carousel and the behavior path data to obtain an abnormality determination result.

[0013] By adopting the technical scheme, the system function module and module associated data of the e-government system and the function behavior data in the historical time period are obtained. The system function module and module associated data are the basis for constructing the behavior pointer dial and the pointer behavior path, and reflect the architecture and connection of each module in the system. The historical function behavior data contains the past operation records of the system and is the basis for subsequent analysis. Through the acquisition of the basic data, comprehensive data support is provided for the in-depth analysis of the subsequent system operation behavior. The system function module and module associated data obtained are sorted to obtain the behavior pointer dial and the pointer behavior path. The behavior pointer dial can intuitively show the association relationship between the system function modules, so that the system architecture is clearly presented. The pointer behavior path records the interaction sequence and behavior mode of each module under the normal operation process. These two achievements are obtained by sorting and analyzing the basic data, and they structure the complex module relationship and operation process of the system. This structuring helps to quickly and accurately locate the operation behavior in the system and determine whether it conforms to the normal process, providing a clear reference standard for subsequent abnormal behavior checking of the function behavior data, thereby effectively improving the efficiency and accuracy of abnormal behavior detection. The abnormal behavior checking of the function behavior data can filter out the problematic data. For the case of determining abnormal behavior data, input it into the preset behavior correction model for abnormal correction identification to obtain corrected behavior data. The preset behavior correction model is trained based on a large amount of normal behavior data and can accurately identify abnormal behavior and give correction suggestions. This process ensures that abnormal behavior can be discovered and corrected in a timely manner, making the function behavior data more accurate and reliable. The corrected behavior data and the function behavior data are bound according to the preset correspondence and the pointer behavior path to obtain behavior path data. The preset correspondence clearly defines the association between different behavior data and the pointer behavior path. Through this binding operation, the behavior data is closely combined with the operation process of the system module. The behavior path data not only contains specific operation behavior, but also clearly defines the position and sequence of these behaviors in the system operation process. This integration method makes the analysis of system operation behavior more comprehensive and in-depth, and the context relationship of each operation behavior in the overall operation of the system can be clearly seen. When the operator logs in to the e-government system, the real-time operation behavior of the operator is collected. The real-time operation behavior is a true reflection of the current time in the system running process and is directly related to the safe and stable operation of the system. The real-time operation behavior is determined for abnormality according to the behavior pointer dial and the behavior path data obtained before. The behavior pointer dial and the behavior path data provide accurate reference standards for abnormality determination. By comparing the real-time operation behavior with these standards, it can be quickly determined whether the behavior conforms to the normal operation process and module association relationship of the system.The abnormality determination method based on historical data and system architecture can timely find improper operation of operators or potential security threats, prevent data leakage, system failure and other problems caused by abnormal operation, and improve the abnormal behavior detection and identification efficiency of the e-government system.

[0014] The application can be further configured in a preferred example to: the system function modules and module association data are sorted to obtain behavior pointer dials and pointer behavior paths, including:

[0015] The application frequency weight of the system function module is determined to obtain a first weight value;

[0016] The abnormal number weight of the system function module is determined to obtain a second weight value;

[0017] The abnormal consequence weight of the system function module is determined to obtain a third weight value;

[0018] The reference branch number of each system function module and other system function modules is determined according to the module association data, and the reference branch number is multiplied by the sum of the first weight value, the second weight value and the third weight value to obtain a comprehensive weight value corresponding to each system function module;

[0019] The system function modules are sorted according to the comprehensive weight value, and the system function modules are respectively placed in the initial pointer dial according to the sorted module sequence to obtain the behavior pointer dial;

[0020] The module association of each system function module on the behavior pointer dial is determined according to the module association data, and the path between the system function modules with association is constructed under the premise that the system function modules with association exist to obtain the pointer behavior path.

[0021] The application can be further configured in a preferred example to: the system function modules are respectively placed in the initial pointer dial according to the sorted module sequence to obtain the behavior pointer dial, including:

[0022] The first function module is determined according to the module sequence, and the first function module is placed in the center dial corresponding to the initial pointer dial, and the first function module is the first ranked system function module in the module sequence;

[0023] A second function module set associated with the first function module in the module sequence and a first module rank corresponding to each system function module in the second function module set are determined;

[0024] determining whether the first module rank meets a preset rank standard corresponding to the initial pointer carousel, if yes, placing the system function module in the second function module set into the first function carousel corresponding to the initial pointer carousel, if not, retaining the system function module and transferring the retained system function module to the next carousel for determination;

[0025] determining an Nth module rank corresponding to the Nth function module and an (N+1)th function module set associated with the Nth function module in the module sequence, wherein N is greater than or equal to 2;

[0026] determining whether the Nth module rank meets a retained module rank corresponding to the system function module retained before the Nth function module, if yes, placing the system function module in the (N+1)th function module set and the system function module retained before the Nth function module into the Nth function carousel corresponding to the initial pointer carousel, if not, retaining the system function module and transferring the retained system function module to the next carousel for determination, until all the system function modules in the module sequence are placed into the initial pointer carousel, to obtain a behavior pointer carousel.

[0027] In a preferred example, the application can be further configured to: determining an abnormality of the real-time operation behavior according to the behavior pointer carousel and the behavior path data, to obtain an abnormality determination result, which includes:

[0028] classifying the real-time operation behavior to determine a real-time behavior category of the operator;

[0029] matching the real-time behavior category with a preset category segmentation standard to obtain a behavior segmentation specification of the real-time operation;

[0030] segmenting the real-time operation behavior based on the behavior segmentation specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes;

[0031] sequentially ordering the plurality of behavior operation nodes according to time nodes to obtain an operation node sequence;

[0032] detecting an abnormal behavior sequence of the operation node sequence according to the behavior pointer carousel to obtain a node determination result;

[0033] detecting an abnormal behavior data of the behavior demonstration data according to the behavior path data to obtain a data determination result;

[0034] correspondingly binding and integrating the node determination result and the data determination result to obtain an abnormality determination result.

[0035] The application can be further configured in a preferred example as follows: the abnormal behavior sequence detection on the operation node sequence according to the behavior pointer carousel obtains a node determination result, including:

[0036] According to the system function module corresponding to the plurality of behavior operation nodes and the system function module corresponding to the behavior pointer carousel, the pointer carousel position corresponding to the plurality of behavior operation nodes is determined;

[0037] The plurality of behavior operation nodes are placed into the behavior pointer carousel based on the pointer carousel position for behavior node abnormality determination simulation, to determine whether the operation node sequence has behavior node abnormality, if so, the abnormal module position and the correction module position corresponding to the behavior node abnormality are determined according to the behavior pointer carousel, and the abnormal module position and the correction module position are taken as the node determination result.

[0038] The application can be further configured in a preferred example as follows: the abnormal behavior data detection on the behavior demonstration data according to the behavior path data obtains a data determination result, including:

[0039] According to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data, the path data sample corresponding to the behavior demonstration data is determined;

[0040] A first data type curve is constructed based on the behavior demonstration data, and a second data type curve is constructed based on the path data sample;

[0041] The second data type curve is curve split based on whether the path data sample is abnormal, to obtain a third data type curve without abnormal data and a fourth data type curve with abnormal data;

[0042] The first data type curve, the third data type curve and the fourth data type curve are curve superimposed and compared according to data type, to obtain a first superimposition rate corresponding to the third data type curve and a second superimposition rate corresponding to the fourth data type curve;

[0043] The first superimposition rate and the second superimposition rate are input into a preset superimposition rate standard for determination, if the first superimposition rate and the second superimposition rate both meet the preset superimposition rate standard, the second superimposition rate is pre-diagnosed for behavior abnormality, to obtain a data determination result, if not, the data abnormal factors corresponding to the first superimposition rate and the second superimposition rate are determined according to the preset superimposition rate standard, and a data determination result is generated according to the data abnormal factors.

[0044] The application can be further configured in a preferred example to: the second coincidence rate is abnormally diagnosed to obtain a data judgment result, including:

[0045] According to the second coincidence rate, the time coincidence rate of the first data type curve and the fourth data type curve in a preset unit time is determined, and a coincidence rate curve corresponding to the time coincidence rate is constructed;

[0046] According to the coincidence rate curve, a curve extension vector of each unit time point position extending to the next unit time point position and a coincidence rate feature corresponding to each unit time point position are determined;

[0047] Based on the curve extension vector, an extension vector feature is determined, and the extension vector feature and the coincidence rate feature are bound to obtain a point feature set;

[0048] The point feature set is arranged in a matrix according to time sequence to obtain a point feature matrix;

[0049] The point feature matrix is deduced according to the unit time period to obtain a predicted point matrix in a future period;

[0050] According to the predicted point matrix, a future point feature set is determined, and a future coincidence rate in a future period is determined based on the future point feature set;

[0051] Based on the preset coincidence rate standard, the future coincidence rate is judged to obtain a data judgment result.

[0052] In a second aspect, the application provides an abnormal behavior detection system for an e-government system, which adopts the following technical solution:

[0053] An abnormal behavior detection system for an e-government system, comprising:

[0054] A data acquisition module is configured to acquire system function modules and module associated data of an e-government system and function behavior data of the e-government system in a historical time period;

[0055] A data arrangement module is configured to arrange the system function modules and the module associated data to obtain a behavior pointer dial and a pointer behavior path;

[0056] A behavior verification module is configured to verify the function behavior data for abnormal behavior, determine whether the function behavior data is abnormal behavior data, and if so, input the function behavior data into a preset behavior correction model for abnormal correction identification to obtain corrected behavior data corresponding to the function behavior data;

[0057] a data binding module, configured to bind the corrected behavior data and the function behavior data to the pointer behavior path according to a preset correspondence relationship, to obtain behavior path data;

[0058] a behavior collection module, configured to collect real-time operation behaviors of an operator when it is detected that the operator logs in the e-government system;

[0059] an abnormality determination module, configured to determine whether the real-time operation behaviors are abnormal according to the behavior pointer carousel and the behavior path data, to obtain an abnormality determination result.

[0060] In a possible implementation, when the data arrangement module arranges the system function modules and the module association data to obtain the behavior pointer carousel and the pointer behavior path, the data arrangement module is specifically configured to:

[0061] determine an application frequency weight of the system function modules, to obtain a first weight value;

[0062] determine an abnormality frequency weight of the system function modules, to obtain a second weight value;

[0063] determine an abnormality consequence weight of the system function modules, to obtain a third weight value;

[0064] determine a reference branch number of each system function module according to the module association data, and perform a product operation on the reference branch number and a sum of the first weight value, the second weight value and the third weight value, to obtain a comprehensive weight value corresponding to each system function module;

[0065] sort the system function modules according to the comprehensive weight values, and place the system function modules in an initial pointer carousel according to the sorted module sequence, to obtain the behavior pointer carousel;

[0066] determine module association between each system function module on the behavior pointer carousel according to the module association data, and construct a path between the system function modules with association, to obtain the pointer behavior path.

[0067] In another possible implementation, when the data arrangement module places the system function modules in the initial pointer carousel according to the sorted module sequence, to obtain the behavior pointer carousel, the data arrangement module is specifically configured to:

[0068] determine a first function module according to the module sequence, and place the first function module in a center wheel disc corresponding to the initial pointer carousel, the first function module being a system function module ranked first in the module sequence;

[0069] determining a second function module set associated with the first function module in the module sequence and a first module rank corresponding to each system function module in the second function module set;

[0070] determining whether the first module rank meets a preset rank standard corresponding to the initial pointer carousel, if yes, placing the system function module in the second function module set into a first function carousel corresponding to the initial pointer carousel, if not, retaining the system function module and transferring the retained system function module to a next carousel determination;

[0071] determining an N+1 function module set associated with the N function module in the module sequence and an N module rank corresponding to each function module in the N+1 function module set, where N is greater than or equal to 2;

[0072] determining whether the N module rank meets a retained module rank corresponding to the system function module retained before the N function module, if yes, placing the system function module in the N+1 function module set and the system function module retained before the N function module into an N function carousel corresponding to the initial pointer carousel, if not, retaining the system function module and transferring the retained system function module to a next carousel determination until all the system function modules in the module sequence are placed into the initial pointer carousel, obtaining a behavior pointer carousel.

[0073] In another possible implementation, when the abnormality determination module determines the real-time operation behavior according to the behavior pointer carousel and the behavior path data to obtain an abnormality determination result, the abnormality determination module is specifically configured to:

[0074] performing category division on the real-time operation behavior to determine a real-time behavior category of the operator;

[0075] matching the real-time behavior category with a preset category division standard to obtain a behavior division specification of the real-time operation;

[0076] performing node division on the real-time operation behavior based on the behavior division specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes;

[0077] sequentially sorting the plurality of behavior operation nodes according to time nodes to obtain an operation node sequence;

[0078] performing abnormal behavior sequence detection on the operation node sequence according to the behavior pointer carousel to obtain a node determination result;

[0079] According to the behavior path data, the behavior demonstration data is subjected to abnormal behavior data detection, and a data determination result is obtained.

[0080] The node determination result and the data determination result are correspondingly bound and integrated, and an abnormal determination result is obtained.

[0081] In another possible implementation, when the abnormal determination module detects an abnormal behavior sequence of the operation node sequence according to the behavior pointer carousel, a node determination result is obtained.

[0082] According to the system function module corresponding to the plurality of behavior operation nodes and the system function module corresponding to the behavior pointer carousel, a pointer carousel position corresponding to the plurality of behavior operation nodes is determined.

[0083] The plurality of behavior operation nodes are placed into the behavior pointer carousel based on the pointer carousel position, and behavior node abnormality determination simulation is performed, to determine whether the operation node sequence has behavior node abnormality.

[0084] In another possible implementation, when the abnormal determination module detects an abnormal behavior data of the behavior demonstration data according to the behavior path data, a data determination result is obtained.

[0085] According to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data, a path data sample corresponding to the behavior demonstration data is determined.

[0086] A first data type curve is constructed based on the behavior demonstration data, and a second data type curve is constructed based on the path data sample.

[0087] According to whether the path data sample is abnormal or not, the second data type curve is subjected to curve splitting, to obtain a third data type curve without abnormal data and a fourth data type curve with abnormal data.

[0088] The first data type curve, the third data type curve, and the fourth data type curve are subjected to curve coincidence comparison according to data types, to obtain a first coincidence rate corresponding to the third data type curve and a second coincidence rate corresponding to the fourth data type curve.

[0089] The first coincidence rate and the second coincidence rate are input into a preset coincidence rate criterion for determination, if the first coincidence rate and the second coincidence rate both meet the preset coincidence rate criterion, a behavior anomaly pre-diagnosis is performed on the second coincidence rate to obtain a data determination result, if not, a data anomaly factor corresponding to the first coincidence rate and the second coincidence rate is determined according to the preset coincidence rate criterion, and a data determination result is generated according to the data anomaly factor.

[0090] In another possible implementation, when the behavior anomaly pre-diagnosis is performed on the second coincidence rate to obtain the data determination result, the anomaly determination module is specifically configured to:

[0091] The time coincidence rate of the first data type curve and the fourth data type curve in a preset unit time is determined according to the second coincidence rate, and a coincidence rate curve corresponding to the time coincidence rate is constructed;

[0092] The curve extension vector of each unit time point to a next unit time point and the coincidence rate feature corresponding to each unit time point are determined according to the coincidence rate curve;

[0093] The extension vector feature is determined based on the curve extension vector, and the extension vector feature is bound with the coincidence rate feature to obtain a point feature set;

[0094] The point feature set is arranged in a matrix according to time sequence to obtain a point feature matrix;

[0095] The point feature set is deduced according to a unit time period according to the point feature matrix to obtain a predicted point matrix in a future period;

[0096] A future point feature set is determined according to the predicted point matrix, and a future coincidence rate in the future period is determined based on the future point feature set;

[0097] The future coincidence rate is determined based on the preset coincidence rate criterion to obtain a data determination result.

[0098] In a third aspect, the present application provides an electronic device, which adopts the following technical solution:

[0099] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the above-mentioned anomaly behavior detection method for an e-government system when executing the computer program.

[0100] In a fourth aspect, the present application provides a computer storage medium, which adopts the following technical solution:

[0101] A computer readable storage medium stores a computer program, the computer program is executed by a processor to implement the steps of the above-mentioned method for detecting abnormal behavior of an e-government system.

[0102] In summary, the present application has the following beneficial technical effects:

[0103] The system function modules and module association data of the e-government system and the function behavior data in the historical time period are acquired. The system function modules and module association data are the basis for constructing the behavior pointer dial and the pointer behavior path, and reflect the architecture and connection of each module in the system. The historical function behavior data contains the past operation records of the system and is the basis for subsequent analysis. Through the acquisition of the basic data, comprehensive data support is provided for the in-depth analysis of the subsequent system operation behavior. The acquired system function modules and module association data are sorted to obtain the behavior pointer dial and the pointer behavior path. The behavior pointer dial can intuitively show the association relationship between the system function modules, making the system architecture clear. The pointer behavior path records the interaction sequence and behavior mode of each module under the normal operation process. These two results are obtained by sorting and analyzing the basic data, and they structure the complex module relationship and operation process of the system. This structure helps to quickly and accurately locate the operation behavior in the system and determine whether it conforms to the normal process, providing a clear reference standard for subsequent abnormal behavior checking of the function behavior data, thereby effectively improving the efficiency and accuracy of abnormal behavior detection. The function behavior data is checked for abnormal behavior, and the data with abnormal behavior is identified and corrected. The preset behavior correction model is trained based on a large amount of normal behavior data and can accurately identify abnormal behavior and give correction suggestions. This process ensures that abnormal behavior can be discovered and corrected in a timely manner, making the function behavior data more accurate and reliable. The corrected behavior data and the function behavior data are bound according to the preset correspondence and the pointer behavior path to obtain the behavior path data. The preset correspondence clearly defines the association between different behavior data and the pointer behavior path. Through this binding operation, the behavior data is closely combined with the operation process of the system modules. The behavior path data not only contains specific operation behavior, but also clearly defines the position and sequence of these behaviors in the system operation process. This integration method makes the analysis of system operation behavior more comprehensive and in-depth, and clearly shows the contextual relationship of each operation behavior in the overall operation of the system. When an operator logs in to the e-government system, the real-time operation behavior of the operator is collected. The real-time operation behavior is a true reflection of the current time in the system operation process and is directly related to the safe and stable operation of the system. The real-time operation behavior is judged for abnormality according to the behavior pointer dial and the behavior path data obtained previously. The behavior pointer dial and the behavior path data provide accurate reference standards for abnormality judgment. By comparing the real-time operation behavior with these standards, it can be quickly determined whether the behavior conforms to the normal operation process and module association relationship of the system.The abnormality determination method based on historical data and system architecture can timely find improper operation of the operator or potential security threats, prevent data leakage, system failure and other problems caused by abnormal operation, and improve the abnormal behavior detection and identification efficiency of the e-government system. BRIEF DESCRIPTION OF DRAWINGS

[0104] Figure 1 is a flowchart of an abnormal behavior detection method for an e-government system in an embodiment of the present application.

[0105] Figure 2 is a structural schematic diagram of an abnormal behavior detection system for an e-government system in an embodiment of the present application.

[0106] Figure 3 is a principle block diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0107] The following will be described in detail below in combination with the accompanying drawings. Figure 1 to the accompanying drawings Figure 3 The present application will be further described in detail.

[0108] The present embodiment is merely an explanation of the present application, and is not a limitation of the present application. Those skilled in the art can make modifications to the present embodiment without creative contribution after reading the present specification, and the present application is protected by the patent law as long as it is within the scope of the claims.

[0109] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme of the embodiments of the present application will be described clearly and completely below in combination with the drawings of the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the present application.

[0110] In addition, the term "and / or" in the present document is merely to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that there are three cases of A alone, A and B together, and B alone. In addition, the character " / " in the present document generally represents an "or" relationship between the associated objects unless otherwise specified.

[0111] The embodiments of the present application will be described in further detail below in combination with the drawings of the specification.

[0112] The embodiment of the present application provides an abnormal behavior detection method for an e-government system, which is executed by an electronic device, and the electronic device can be a server or a terminal device. The server can be a physical server, a server cluster composed of multiple physical servers or a distributed system, or a cloud server providing cloud computing services. The terminal device can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited to this. The terminal device and the server can be directly or indirectly connected through wired or wireless communication, and the embodiment of the present application does not limit this. Figure 1 The method comprises the following steps.

[0113] Step S10: Obtain system function modules and module association data of the e-government system and function behavior data of the e-government system in a historical time period.

[0114] For the embodiment of the present application, the system function module represents a component part with a specific function in the e-government system. It refers to an independent unit divided for realizing various business functions of the e-government system. For example, an administrative examination and approval module and an information publishing module in an e-government system, the administrative examination and approval module is used for processing the application, acceptance, examination and settlement of various administrative examination and approval matters; the information publishing module is responsible for publishing the relevant policies, announcements, news and other information of the government to the system for public inquiry. The module association data refers to data for describing the mutual relationship between various function modules in the e-government system. It is used to represent the interaction mode, data flow and dependency relationship between different function modules. For example, there is association data between the administrative examination and approval module and the archive management module, when the administrative examination and approval matter is settled, the relevant examination and approval files and result data are transmitted to the archive management module for storage, and these transmission rules and data interface information belong to the module association data. The function behavior data represents the specific behavior and operation record of each function module in the running process of the e-government system. It refers to the data recording the behavior of the function module being called, performing operation and generating result at different time points. For example, in the historical time period, the number of times of calling the administrative examination and approval module, the time of each call, the type of handled matter, the examination result (pass or fail) and other information belong to the function behavior data.

[0115] Step S11: Organize the system function modules and the module association data to obtain a behavior pointer carousel and a pointer behavior path.

[0116] In the embodiments of the present application, the behavior pointer carousel refers to organizing system function modules according to certain logic and rules to form a structure similar to a carousel, in which a pointer is used to point to different function modules. It is used to represent the set of different function modules executed by the system and the relative position relationship between them in a specific scenario. For example, in a government approval process, the behavior pointer carousel includes an application acceptance module, an audit module, an approval module, a settlement feedback module, etc. The initial position of the pointer points to the application acceptance module, and as the approval process advances, the pointer will point to the subsequent modules in turn. The pointer behavior path represents the trajectory of the pointer moving on the behavior pointer carousel, which reflects the calling order and execution process between function modules of the system in different business scenarios. For example, in the above-mentioned government approval process, the pointer behavior path is from the application acceptance module, through the audit module, the approval module, etc., and finally arrives at the settlement feedback module, completing the entire approval process.

[0117] Specifically, in creating the behavior pointer carousel and the pointer behavior path, the application frequency weight of the system function modules is determined to obtain a first weight value, the abnormal number weight of the system function modules is determined to obtain a second weight value, the abnormal consequence weight of the system function modules is determined to obtain a third weight value, the reference branch number of each system function module and other system function modules is determined according to the module association data, and the reference branch number is multiplied by the sum of the first weight value, the second weight value and the third weight value to obtain the comprehensive weight value corresponding to each system function module. The system function modules are sorted according to the comprehensive weight value, and the system function modules are respectively placed into the initial pointer carousel according to the sorted module sequence to obtain the behavior pointer carousel. The module association of each system function module on the behavior pointer carousel is determined according to the module association data, and the path between the system function modules with association is constructed on the premise that the system function modules have association to obtain the pointer behavior path.

[0118] For the embodiments of the present application, the application frequency weight determination refers to assigning a weight value to a system function module according to the number of times or frequency of use of the module in a specific time period. It is used to represent the frequency of use of the module in the e-government system. For example, the household management module is accessed by a large number of users every day for handling account migration, newborn registration and other businesses, and has a high application frequency, so the application frequency weight value is large; while the specific administrative approval module is only used in specific circumstances, the application frequency is low, and the weight value is small. The abnormal number weight determination refers to assigning a weight value to a system function module according to the number of times of abnormality (such as error, failure, crash, etc.) of the module in the running process. It reflects the stability and reliability of the module. The abnormal consequence weight determination represents the impact degree of the system function module on the overall operation of the system, user service or data security after the abnormality, and the weight value assigned according to it. It reflects the severity of the abnormality. For example, if the payment processing module has an abnormality, it will cause the user's payment to fail or repeat payment, resulting in economic loss to the user, so the abnormal consequence weight value of the module is high; while the abnormality of the information query module only affects the timeliness of the user's information query, the consequence is relatively light, and the weight value is low. The reference branch number is determined according to the module associated data, that is, the number of reference branches of each system function module to other system function modules, that is, the number of times the module is directly called or associated by other modules. For example, the user authentication module is called by the household management module, the tax declaration module, the social security handling module and other modules for user identity authentication, so the reference branch number of the module is large. The comprehensive weight value is the product operation of the reference branch number and the sum of the first weight value (application frequency weight), the second weight value (abnormal number weight) and the third weight value (abnormal consequence weight), and the weight value corresponding to each system function module is obtained, which is expressed by the formula: comprehensive weight value = reference branch number × (first weight value + second weight value + third weight value). The use frequency, stability and abnormality impact degree of the module and the association with other modules are comprehensively considered.

[0119] For the embodiments of the present application, the first function module is determined according to the module sequence, and the first function module is placed in the center wheel disc corresponding to the initial pointer carousel, the first function module is the system function module ranked first in the module sequence, the second function module set associated with the first function module in the module sequence and the first module rank corresponding to each system function module in the second function module set are determined, whether the first module rank meets the preset rank standard corresponding to the initial pointer carousel is judged, if yes, the system function modules in the second function module set are placed in the first function wheel disc corresponding to the initial pointer carousel, if not, the system function modules are retained, and the retained system function modules are transferred to the next wheel disc determination. The (N+1)th function module set associated with the Nth function module in the module sequence and the Nth module rank corresponding to each function module in the (N+1)th function module set are determined, N is greater than or equal to 2. Whether the Nth module rank meets the preset rank standard corresponding to the system function modules retained before the Nth function module is judged, if yes, the system function modules in the (N+1)th function module set and the system function modules retained before the Nth function module are placed in the Nth function wheel disc corresponding to the initial pointer carousel, if not, the system function modules are retained, and the retained system function modules are transferred to the next wheel disc determination, until all the system function modules in the module sequence are placed in the initial pointer carousel, and the behavior pointer carousel is obtained.

[0120] Specifically, the initial pointer carousel refers to a blank carousel structure that has not yet placed any system function module, and is usually composed of multiple concentric wheel discs, each wheel disc can place different number of function modules. The center wheel disc of the initial pointer carousel is used to place the most important function module, and the peripheral wheel discs are used to place the less important modules in turn. The preset rank standard is a rank threshold value preset for judging whether the function module has the qualification to be placed in the current function wheel disc. For example, the preset rank standard stipulates that only the modules ranked in the top 5 can be placed in the first function wheel disc.

[0121] Step S12: Abnormal behavior verification is performed on the function behavior data to determine whether the function behavior data is abnormal behavior data, if yes, the function behavior data is input into a preset behavior correction model for abnormal correction identification to obtain corrected behavior data corresponding to the function behavior data.

[0122] Specifically, the function behavior data refers to the behavior data generated by the user or system component in the e-government system when performing functions, including operation records, interaction logs, system responses, etc. For example, the login time, operation path, submitted form data, etc. of the user when logging in to the e-government platform all belong to the function behavior data.

[0123] Abnormal behavior verification is to check the functional behavior data to determine whether it conforms to the expected behavior pattern or rule. For example, the user's multiple login failures in a short period of time are considered abnormal behavior; the frequent invocation of a certain functional module by a system component during a non-working time period is also determined to be abnormal. Abnormal behavior data is functional behavior data that is determined to be inconsistent with the expected behavior pattern or rule after abnormal behavior verification. For example, a user filling out a form with illegal characters, a system module generating a large number of error requests in a short period of time, etc. The preset behavior correction model is a pre-trained machine learning model or rule engine used to identify and correct abnormal behavior data. This model is trained based on historical abnormal behavior data and normal behavior data, and can identify the type of abnormal behavior and make correction suggestions. Corrected behavior data is data or suggestions generated by the preset behavior correction model to correct abnormal behavior after analyzing and identifying abnormal behavior data. For example, corrected legal form data, adjusted system call frequency, etc.

[0124] Step S13: Bind the corrected behavior data and the functional behavior data according to the preset correspondence relationship with the pointer behavior path to obtain behavior path data.

[0125] In an embodiment of the present application, the preset correspondence relationship is a mapping relationship between the pre-defined corrected behavior data, functional behavior data and pointer behavior path. The behavior path data is a data structure formed by binding the corrected behavior data and the functional behavior data with the pointer behavior path, and is used to record and analyze the association between the behavior path and the data.

[0126] Specifically, a database table structure is designed, including a corrected behavior data table, a functional behavior data table and a pointer behavior path table. The corresponding relationship between the corrected behavior data, the functional behavior data and the pointer behavior path is established by defining foreign keys or association fields in the table. The data is bound to the corresponding path record through SQL query or ORM framework (such as Hibernate). When querying or generating behavior path data, the related tables are associated through JOIN operation to obtain the complete behavior path and its data.

[0127] Step S14: When an operator logs in to the e-government system, the real-time operation behavior of the operator is collected.

[0128] Specifically, the operator enters the operation interface of the e-government system by inputting identity verification information such as a user name, a password, and a verification code. For example, a citizen clicks the “Login” button on the homepage of the e-government website, enters the correct account and password, and successfully enters the system. Real-time operation behavior refers to various instant operation actions and related data generated by the operator on the system interface after logging into the e-government system. For example, clicking menu options, filling out forms, submitting applications, querying information, and other operations, as well as data such as the time stamp of the operation, the object of the operation (such as a specific function module), and the result of the operation (success or failure).

[0129] Step S15: Abnormality determination of real-time operation behavior is performed according to the behavior pointer carousel and the behavior path data, and an abnormality determination result is obtained.

[0130] For the embodiments of the present application, the real-time operation behavior is classified to determine the real-time behavior category of the operator, the real-time behavior category is matched with the preset category segmentation standard to obtain the behavior segmentation specification of real-time operation, the real-time operation behavior is segmented based on the behavior segmentation specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes. The plurality of behavior operation nodes are sequentially sorted according to time nodes to obtain an operation node sequence, the operation node sequence is subjected to abnormal behavior sequence detection according to the behavior pointer carousel to obtain a node determination result, the behavior demonstration data is subjected to abnormal behavior data detection according to the behavior path data to obtain a data determination result, and the node determination result and the data determination result are correspondingly bound and integrated to obtain an abnormality determination result.

[0131] In the embodiments of the present application, the preset category segmentation standard is a rule or condition predefined for classifying real-time operation behavior categories. For example, the behavior categories are classified according to the object of the operation (such as a function module), the operation type (such as clicking or inputting), and the operation purpose (such as querying or submitting). The behavior segmentation specification is a specification or criterion obtained after classifying the real-time operation behavior based on the preset category segmentation standard, which is used to guide how to segment the operation behavior into different nodes.

[0132] In the abnormal behavior sequence detection of the operation node sequence: the pointer carousel positions corresponding to the plurality of behavior operation nodes are determined according to the system function modules corresponding to the plurality of behavior operation nodes and the system function modules corresponding to the behavior pointer carousel. The plurality of behavior operation nodes are placed in the behavior pointer carousel based on the pointer carousel positions for behavior node abnormality determination simulation to determine whether the operation node sequence has a behavior node abnormality. If so, the abnormal module position and the correction module position corresponding to the behavior node abnormality are determined according to the behavior pointer carousel, and the abnormal module position and the correction module position are taken as the node determination result.

[0133] In the abnormal behavior data detection on the behavior demonstration data: the path data sample corresponding to the behavior demonstration data is determined according to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data, the first data type curve is constructed based on the behavior demonstration data, and the second data type curve is constructed based on the path data sample. Whether the path data sample is abnormal or not, the second data type curve is curve split to obtain the third data type curve without abnormal data and the fourth data type curve with abnormal data. The first data type curve and the third data type curve and the fourth data type curve are compared according to the data type, and the first coincidence rate corresponding to the third data type curve and the second coincidence rate of the fourth data type curve are obtained. The first coincidence rate and the second coincidence rate are input into the preset coincidence rate standard for judgment. If the first coincidence rate and the second coincidence rate both meet the preset coincidence rate standard, the second coincidence rate is diagnosed for behavior anomaly, and a data judgment result is obtained. If not, the data anomaly factors corresponding to the first coincidence rate and the second coincidence rate are determined according to the preset coincidence rate standard, and the data judgment result is generated according to the data anomaly factors.

[0134] Specifically, under the premise that the first coincidence rate and the second coincidence rate both meet the preset coincidence rate standard, in order to determine the subsequent possible behavior anomaly, the application adopts the technical means of coincidence rate prediction: the time coincidence rate of the first data type curve and the fourth data type curve in a preset unit time is determined according to the second coincidence rate, and a coincidence rate curve corresponding to the time coincidence rate is constructed. The curve extension vector of each unit time point to the next unit time point and the coincidence rate feature corresponding to each unit time point are determined according to the coincidence rate curve. The extension vector feature is determined based on the curve extension vector, and the extension vector feature and the coincidence rate feature are bound to obtain a point feature set. The point feature set is arranged in a matrix according to the time sequence to obtain a point feature matrix. The point feature set is deduced according to the unit time period to obtain a predicted point matrix in the future period. The future point feature set is determined according to the predicted point matrix, and the future coincidence rate in the future period is determined based on the future point feature set. The future coincidence rate is judged based on the preset coincidence rate standard to obtain a data judgment result.

[0135] In the embodiment of the application, the preset coincidence rate standard is a threshold or rule preset for judging whether the curve coincidence rate meets the requirements. For example, it is stipulated that the first coincidence rate should be greater than 80% and the second coincidence rate should be less than 30% to meet the standard.

[0136] From the perspective of data correlation:

[0137] Normal data correlation of the first overlap rate (first data type curve vs. third data type curve): The first data type curve is constructed based on the behavior demonstration data, and the third data type curve is constructed based on the path data samples without abnormal data. In normal cases, the behavior demonstration data should have a high correlation with the path data samples without abnormalities. For example, in a normal online form filling process, there is a certain regularity between the user's input data speed (behavior demonstration data) and the user's operation sequence and dwell time on the form page (reflected by the path data samples without abnormalities). If the user operates according to the normal process, the first data type curve reflecting the change of input speed and the third data type curve reflecting the time distribution in the operation process should be highly overlapped. Therefore, setting the first overlap rate to be greater than 80% is to ensure that there is a close correlation between the behavior demonstration data and the normal path data, and when the overlap rate is below this threshold, it means that the behavior demonstration data is abnormal. Sensitivity of anomaly detection: A higher first overlap rate threshold can improve the sensitivity of anomaly detection. If the threshold is set too low, some minor abnormal data may be ignored, and potential problems may not be discovered in time. For example, when the user is entering data, although the overall process appears to be normal, the input speed suddenly fluctuates abnormally. If the first overlap rate threshold is set too low, this subtle anomaly cannot be detected, but an 80% threshold can better capture such changes.

[0138] Abnormal data correlation of the second overlap rate (first data type curve vs. fourth data type curve): The fourth data type curve is constructed based on path data samples with abnormal data. Due to the existence of abnormalities, the correlation between behavior demonstration data and these abnormal path data should be low. For example, in a business process, users should normally access each page in a specific order, but if there is an abnormal page jump (possibly due to system error or malicious operation) in the path data sample, the overlap rate between the first data type curve reflecting the user's input data change and the fourth data type curve reflecting the time distribution of abnormal page jumps should be very low. Therefore, setting the second overlap rate to be less than 30% is to ensure that there is a clear difference between the behavior demonstration data and the abnormal path data, and when the overlap rate is higher than this threshold, it means that the behavior demonstration data is also affected by the anomaly. Reduce the possibility of false positives: A lower second overlap rate threshold can reduce the possibility of false positives. If the threshold is set too high, some normal behavior demonstration data may be misjudged as abnormal. For example, in some cases, although there are some abnormalities in the path data sample, the behavior demonstration data may not be affected and still maintain a normal pattern. If the second overlap rate threshold is set too high, it will incorrectly determine these actually normal behavior demonstration data as abnormal.

[0139] From the perspective of data accuracy and reliability:

[0140] The first coincidence rate can ensure data consistency: behavior demonstration data and path data samples should accurately reflect user operation behavior and business processes. High first coincidence rate can ensure consistency between the two kinds of data, reducing data errors. For example, if the behavior demonstration data records the user's input content in actual operation, and the path data sample records the user's operation trajectory in the system, the two kinds of data should confirm each other. If the coincidence rate is low, it may mean that one of the data has recording errors or inaccuracy. It also improves the reliability of data analysis: accurate and reliable data is the basis when conducting business analysis and decision-making. High first coincidence rate can improve the reliability of data analysis, making the analysis results more valuable. For example, by analyzing the coincidence of behavior demonstration data and path data samples, we can understand the user's behavior habits and the bottlenecks of business processes, thus providing the basis for system optimization and business improvement.

[0141] The second coincidence rate can filter out interference data: in the actual data collection and analysis process, there may be some interference data, such as data noise, abnormal fluctuations, etc. By setting a lower second coincidence rate threshold, these interference data can be filtered out, making the analysis results more accurate. For example, if the high coincidence rate of behavior demonstration data and abnormal path data is caused by data noise, a lower threshold can minimize this impact. Ensure the accuracy of anomaly detection: accurate anomaly detection is the key to ensuring the safe and stable operation of the system. A lower second coincidence rate threshold can improve the accuracy of anomaly detection, avoiding misjudgment of normal data as abnormal, while also ensuring that abnormal data can be discovered and processed in a timely manner.

[0142] In the embodiments of the present application, the system function modules and module association data of the e-government system and the function behavior data in the historical time period are acquired. The system function modules and module association data are the basis for constructing the behavior pointer dial and the pointer behavior path, and reflect the architecture and connection of each module in the system. The historical function behavior data contains the past operation records of the system and is the basis for subsequent analysis. Through the acquisition of the basic data, comprehensive data support is provided for the in-depth analysis of the subsequent system operation behavior. The acquired system function modules and module association data are sorted to obtain the behavior pointer dial and the pointer behavior path. The behavior pointer dial can intuitively show the association relationship between the system function modules, so that the system architecture is clearly presented. The pointer behavior path records the interaction sequence and behavior mode of each module under the normal operation process. These two achievements are obtained by sorting and analyzing the basic data, and they structure the complex module relationship and operation process of the system. This structuring helps to quickly and accurately locate the position of the operation behavior in the system and determine whether it conforms to the normal process, providing a clear reference standard for subsequent abnormal behavior checking of the function behavior data, thereby effectively improving the efficiency and accuracy of abnormal behavior detection. The abnormal behavior checking of the function behavior data can filter out the problematic data. For the case of determining abnormal behavior data, input it into the preset behavior correction model for abnormal correction identification to obtain corrected behavior data. The preset behavior correction model is trained based on a large amount of normal behavior data and can accurately identify abnormal behavior and give correction suggestions. This process ensures that abnormal behavior can be discovered and corrected in a timely manner, making the function behavior data more accurate and reliable. The corrected behavior data and the function behavior data are bound according to the preset correspondence and the pointer behavior path to obtain behavior path data. The preset correspondence clearly defines the association between different behavior data and the pointer behavior path. Through this binding operation, the behavior data is closely combined with the operation process of the system modules. The behavior path data not only contains specific operation behavior, but also clearly defines the position and sequence of these behaviors in the system operation process. This integration method makes the analysis of system operation behavior more comprehensive and in-depth, and the upper and lower relationships of each operation behavior in the overall operation of the system can be clearly seen. When an operator logs in to the e-government system, the real-time operation behavior of the operator is collected. The real-time operation behavior is a true reflection of the current time in the system running process and is directly related to the safe and stable operation of the system. The real-time operation behavior is judged for abnormality according to the behavior pointer dial and the behavior path data obtained before. The behavior pointer dial and the behavior path data provide accurate reference standards for abnormality judgment. By comparing the real-time operation behavior with these standards, it can be quickly judged whether the behavior conforms to the normal operation process and module association relationship of the system.This anomaly detection method, based on historical data and system architecture, can promptly identify improper operations or potential security threats by operators, preventing data leaks, system failures, and other problems caused by abnormal operations, thereby improving the efficiency of abnormal behavior detection and identification in e-government systems.

[0143] The above embodiments describe an abnormal behavior detection method for e-government systems from the perspective of method flow. The following embodiments describe an abnormal behavior detection system for e-government systems from the perspective of virtual modules or virtual units. For details, please refer to the following embodiments.

[0144] This application provides an abnormal behavior detection system 20 for e-government systems, such as... Figure 2 As shown, Figure 2 This is a schematic diagram of an abnormal behavior detection system for an e-government system provided in an embodiment of this application. The system 20 specifically may include:

[0145] Data acquisition module 21 is used to acquire system function modules and module association data of the e-government system, as well as functional behavior data of the e-government system within a historical time period;

[0146] Data processing module 22 is used to process the system functional modules and module-related data to obtain the behavior pointer turntable and pointer behavior path;

[0147] The behavior verification module 23 is used to perform abnormal behavior verification on the functional behavior data, determine whether the functional behavior data is abnormal behavior data, and if so, input the functional behavior data into the preset behavior correction model for abnormal correction identification, and obtain the corrected behavior data corresponding to the functional behavior data.

[0148] The data binding module 24 is used to bind the correction behavior data and the function behavior data to the pointer behavior path according to the preset correspondence relationship to obtain the behavior path data;

[0149] The behavior collection module 25 is used to collect the real-time operation behavior of the operator after detecting that the operator has logged into the e-government system;

[0150] The anomaly determination module 26 is used to determine anomalies in real-time operation behavior based on the behavior pointer turntable and behavior path data, and obtain the anomaly determination result.

[0151] In one possible implementation of this application embodiment, when the data processing module 22 processes the system functional modules and module-related data to obtain the behavior pointer turntable and pointer behavior path, it is specifically used for:

[0152] The application frequency weight of the system functional modules is determined to obtain the first weight value;

[0153] The abnormal number weight determination is performed on the system function modules to obtain a second weight value;

[0154] The abnormal consequence weight determination is performed on the system function modules to obtain a third weight value;

[0155] The reference branch number of each system function module to other system function modules is determined according to the module association data, and the reference branch number is multiplied by the sum of the first weight value, the second weight value and the third weight value to obtain a comprehensive weight value corresponding to each system function module;

[0156] The system function modules are sorted according to the comprehensive weight value, and the system function modules are respectively placed into the initial pointer carousel according to the sorted module sequence to obtain a behavior pointer carousel;

[0157] The module association determination is performed on each system function module in the behavior pointer carousel according to the module association data, and the path construction is performed between the system function modules with association on the premise that the association exists between the system function modules to obtain a pointer behavior path.

[0158] In another possible implementation manner of the embodiment, the data arrangement module 22 is specifically used for:

[0159] The first function module is determined according to the module sequence, and the first function module is placed into the center wheel disc corresponding to the initial pointer carousel, the first function module being the system function module ranked first in the module sequence;

[0160] The second function module set associated with the first function module in the module sequence and the first module rank corresponding to each system function module in the second function module set are determined;

[0161] It is judged whether the first module rank meets the preset rank standard corresponding to the initial pointer carousel, if yes, the system function modules in the second function module set are placed into the first function wheel disc corresponding to the initial pointer carousel, if not, the system function modules are reserved, and the reserved system function modules are transferred to the next wheel disc determination;

[0162] The N+1 function module set associated with the N function module in the module sequence and the N module rank corresponding to each function module in the N+1 function module set are determined, N being greater than or equal to 2;

[0163] determining whether the reserved module sequence corresponding to the system function modules before the Nth function module meets the preset sequence criterion, if yes, placing the system function modules in the N+1th function module set and the system function modules before the Nth function module into the Nth function wheel corresponding to the initial pointer carousel, if not, reserving the system function modules and transferring the reserved system function modules to the next wheel for determination until all the system function modules in the module sequence are placed into the initial pointer carousel to obtain the behavior pointer carousel.

[0164] In another possible implementation of the embodiment of the application, when the abnormality determination module 26 determines the real-time operation behavior according to the behavior pointer carousel and the behavior path data to obtain an abnormality determination result, the abnormality determination module 26 is specifically configured to:

[0165] performing category division on the real-time operation behavior to determine the real-time behavior category of the operator;

[0166] matching the real-time behavior category with a preset category division criterion to obtain a behavior division specification of the real-time operation;

[0167] performing node division on the real-time operation behavior based on the behavior division specification to obtain a plurality of behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes;

[0168] sequentially sorting the plurality of behavior operation nodes according to time nodes to obtain an operation node sequence;

[0169] performing abnormal behavior sequence detection on the operation node sequence according to the behavior pointer carousel to obtain a node determination result;

[0170] performing abnormal behavior data detection on the behavior demonstration data according to the behavior path data to obtain a data determination result;

[0171] correspondingly binding and integrating the node determination result and the data determination result to obtain the abnormality determination result.

[0172] In another possible implementation of the embodiment of the application, when the abnormality determination module 26 performs abnormal behavior sequence detection on the operation node sequence according to the behavior pointer carousel to obtain a node determination result, the abnormality determination module 26 is specifically configured to:

[0173] determining the pointer carousel positions corresponding to the plurality of behavior operation nodes according to the system function modules corresponding to the plurality of behavior operation nodes and the system function modules corresponding to the behavior pointer carousel;

[0174] The plurality of behavior operation nodes are placed into the behavior pointer carousel based on the pointer carousel position for behavior node anomaly determination simulation, to determine whether the operation node sequence has behavior node anomaly, if so, the abnormal module position and the correction module position corresponding to the behavior node anomaly are determined according to the behavior pointer carousel, and the abnormal module position and the correction module position are taken as the node determination result.

[0175] In another possible implementation of the embodiment of the application, when the abnormal determination module 26 detects the abnormal behavior data from the behavior demonstration data according to the behavior path data to obtain the data determination result, it is specifically used for:

[0176] determining the path data sample corresponding to the behavior demonstration data according to the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data;

[0177] constructing a first data type curve based on the behavior demonstration data, and constructing a second data type curve based on the path data sample;

[0178] performing curve splitting on the second data type curve based on whether the path data sample is abnormal, to obtain a third data type curve without abnormal data and a fourth data type curve with abnormal data;

[0179] performing curve coincidence comparison of the first data type curve with the third data type curve and the fourth data type curve according to the data type, to obtain a first coincidence rate corresponding to the third data type curve and a second coincidence rate corresponding to the fourth data type curve;

[0180] inputting the first coincidence rate and the second coincidence rate into a preset coincidence rate standard for determination, if both the first coincidence rate and the second coincidence rate meet the preset coincidence rate standard, performing behavior abnormality pre-diagnosis on the second coincidence rate to obtain the data determination result, if not, determining the data abnormality factors corresponding to the first coincidence rate and the second coincidence rate according to the preset coincidence rate standard, and generating the data determination result according to the data abnormality factors.

[0181] In another possible implementation of the embodiment of the application, when the abnormal determination module 26 performs behavior abnormality pre-diagnosis on the second coincidence rate to obtain the data determination result, it is specifically used for:

[0182] determining a time coincidence rate of the first data type curve and the fourth data type curve within a preset unit time according to the second coincidence rate, and constructing a coincidence rate curve corresponding to the time coincidence rate;

[0183] determining a curve extension vector of each unit time point to the next unit time point and a coincidence rate feature corresponding to each unit time point according to the coincidence rate curve;

[0184] Determine the extension vector feature based on the curve extension vector, and bind the extension vector feature with the coincidence rate feature to obtain a point feature set;

[0185] Arrange the point feature set in a matrix according to the time sequence to obtain a point feature matrix;

[0186] Derive the point feature set according to the unit time period to obtain a predicted point matrix in a future period;

[0187] Determine a future point feature set according to the predicted point matrix, and determine a future coincidence rate in the future period based on the future point feature set;

[0188] Determine the future coincidence rate based on a preset coincidence rate standard to obtain a data determination result.

[0189] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the abnormal behavior detection system 20 for the e-government system described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0190] An electronic device is provided in the embodiments of the present application, as shown in Figure 3 Figure 3 A structural schematic diagram of an electronic device provided in the embodiments of the present application. Figure 3 The electronic device 300 shown in the figure includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, such as through a bus 302. Optionally, the electronic device 300 can also include a transceiver 304. It should be noted that in actual applications, the transceiver 304 is not limited to one, and the structure of the electronic device 300 does not constitute a limitation on the embodiments of the present application.

[0191] The processor 301 can be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can realize or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure content of the present application. The processor 301 can also be a combination of computing functions, such as one or more microprocessor combinations, combinations of DSP and microprocessor, etc.

[0192] ​The bus 302 can include a path that transmits information between the above-described components. The bus 302 can be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 302 can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, Figure 3 Only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0193] The memory 303 can be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.

[0194] The memory 303 is used to store application program codes for implementing the scheme of the present application, and is controlled to execute by the processor 301. The processor 301 is used to execute the application program codes stored in the memory 303 to realize the content shown in the foregoing method embodiments.

[0195] The electronic device includes, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a vehicle-mounted terminal (for example, a car navigation terminal), and the like, and a fixed terminal such as a digital TV, a desktop computer, and the like. It can also be a server, etc. Figure 3 The electronic device shown is only an example, and should not bring any limitation to the function and use range of the embodiments of the present application.

[0196] The embodiments of the present application provide a computer readable storage medium, which stores computer programs, and when the computer programs run on a computer, the computer can execute the corresponding content in the foregoing method embodiments.

[0197] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in a sequential order following the arrows, the steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated otherwise herein, the execution of the steps is not strictly limited to the order indicated by the arrows, and can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order is not necessarily sequential, but can be round-robin or alternating with at least some of the other steps or sub-steps or stages of other steps.

[0198] The above is only some embodiments of the present application, and it should be pointed out that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should also be considered as the protection scope of the present application.

Claims

1. A method for detecting abnormal behavior in e-government systems, characterized in that, include: Obtain system function modules and module association data of the e-government system, as well as functional behavior data of the e-government system within historical time periods; The system functional modules and their associated data are organized to obtain a behavior pointer carousel and pointer behavior paths. The pointer behavior paths are obtained by: sorting the system functional modules according to a comprehensive weight value, and placing the system functional modules into an initial pointer carousel according to the sorted module sequence to obtain a behavior pointer carousel; determining the module association of each system functional module on the behavior pointer carousel according to the module association data; and constructing paths between the associated system functional modules, based on the premise that there is an association between the system functional modules, to obtain pointer behavior paths. The functional behavior data is subjected to abnormal behavior verification to determine whether the functional behavior data is abnormal behavior data. If so, the functional behavior data is input into a preset behavior correction model for abnormal correction identification to obtain corrected behavior data corresponding to the functional behavior data. The correction behavior data and the functional behavior data are bound to the pointer behavior path according to a preset correspondence to obtain behavior path data; Once an operator is detected logging into the e-government system, the operator's real-time operational behavior is collected. Anomaly determination is performed on the real-time operation behavior based on the behavior pointer turntable and the behavior path data to obtain the anomaly determination result.

2. The method for detecting abnormal behavior in an e-government system according to claim 1, characterized in that, The process of organizing the system functional modules and their associated data to obtain the behavior pointer carousel and pointer behavior paths includes: The application frequency weight of the system functional modules is determined to obtain a first weight value; An anomaly count weight is determined for the system functional modules to obtain a second weight value; An abnormal consequence weight determination is performed on the system functional modules to obtain a third weight value; The number of reference branches between each system functional module and other system functional modules is determined based on the module association data. The number of reference branches is then multiplied by the sum of the first weight value, the second weight value, and the third weight value to obtain the comprehensive weight value corresponding to each system functional module. The system functional modules are sorted according to the comprehensive weight value, and the system functional modules are placed into the initial pointer wheel according to the sorted module sequence to obtain the behavior pointer wheel; Based on the module association data, each system function module on the behavior pointer turntable is determined to be associated with another system function module. If an association is found between the system function modules, a path is constructed between the associated system function modules to obtain the pointer behavior path.

3. The method for detecting abnormal behavior in an e-government system according to claim 2, characterized in that, The step of placing the system functional modules into the initial pointer wheel according to the sorted module sequence to obtain the behavior pointer wheel includes: The first functional module is determined according to the module sequence, and the first functional module is placed into the central wheel corresponding to the initial pointer wheel. The first functional module is the system functional module ranked first in the module sequence. Determine the set of second functional modules that are associated with the first functional module in the module sequence, and the first module ranking corresponding to each system functional module in the second functional module set; Determine whether the ranking of the first module meets the preset ranking standard corresponding to the initial pointer wheel. If it does, place the system function module in the second function module set into the first function wheel corresponding to the initial pointer wheel. If it does not meet the standard, retain the system function module and transfer the retained system function module to the next wheel for determination. Determine the set of N+1 functional modules that are associated with the Nth functional module in the module sequence, and the Nth module rank corresponding to each functional module in the N+1 functional module set, where N is greater than or equal to 2; Determine whether the ranking of the Nth module and the ranking of the reserved system function modules corresponding to the Nth functional module meet the preset ranking criteria. If they do, place the system function modules in the N+1th functional module set and the system function modules previously reserved for the Nth functional module into the Nth functional wheel corresponding to the initial pointer wheel. If they do not meet the criteria, retain the system function modules and move them to the next wheel for judgment until all system function modules in the module sequence are placed into the initial pointer wheel, thus obtaining the behavior pointer wheel.

4. The method for detecting abnormal behavior in an e-government system according to claim 1, characterized in that, The step of determining anomalies in the real-time operation behavior based on the behavior pointer wheel and the behavior path data, and obtaining an anomaly determination result, includes: The real-time operational behaviors are categorized to determine the operator's real-time behavior category; The real-time behavior category is matched with a preset category segmentation standard to obtain the behavior segmentation specification of the real-time operation behavior; Based on the behavior segmentation specification, the real-time operation behavior is segmented into nodes to obtain multiple behavior operation nodes and behavior demonstration data corresponding to the behavior operation nodes. The multiple action operation nodes are sorted sequentially according to time nodes to obtain the operation node sequence; The abnormal behavior sequence is detected based on the behavior pointer turntable to obtain the node determination result; Based on the behavior path data, abnormal behavior data detection is performed on the behavior demonstration data to obtain data judgment results; The node determination results and the data determination results are bound and integrated to obtain the anomaly determination results.

5. The method for detecting abnormal behavior in an e-government system according to claim 4, characterized in that, The step of performing abnormal behavior sequence detection on the operation node sequence based on the behavior pointer turntable to obtain the node determination result includes: The position of the pointer wheel corresponding to the multiple action operation nodes is determined based on the system function modules corresponding to the multiple action operation nodes and the system function modules corresponding to the action pointer wheel. Based on the position of the pointer wheel, the multiple behavior operation nodes are placed into the behavior pointer wheel to simulate behavior node anomaly determination, and it is determined whether there is a behavior node anomaly in the operation node sequence. If there is, the position of the abnormal module and the position of the correction module corresponding to the behavior node anomaly are determined according to the behavior pointer wheel, and the position of the abnormal module and the position of the correction module are used as the node determination result.

6. The method for detecting abnormal behavior in an e-government system according to claim 4, characterized in that, The step of detecting abnormal behavior data in the behavior demonstration data based on the behavior path data to obtain a data judgment result includes: The path data sample corresponding to the behavior demonstration data is determined based on the behavior node corresponding to the behavior demonstration data and the behavior node corresponding to the behavior path data. A first data type curve is constructed based on the behavioral demonstration data, and a second data type curve is constructed based on the path data sample. Based on whether the path data samples are abnormal, the second data type curve is split to obtain the third data type curve without abnormal data and the fourth data type curve with abnormal data. The curves of the first data type, the third data type, and the fourth data type are compared according to their data types to obtain a first overlap rate corresponding to the third data type curve and a second overlap rate corresponding to the fourth data type curve. The first overlap rate and the second overlap rate are input into a preset overlap rate standard for judgment. If both the first overlap rate and the second overlap rate meet the preset overlap rate standard, behavioral abnormality pre-diagnosis is performed on the second overlap rate to obtain a data judgment result. If they do not meet the standard, the data abnormality factors corresponding to the first overlap rate and the second overlap rate are determined according to the preset overlap rate standard, and a data judgment result is generated based on the data abnormality factors.

7. The method for detecting abnormal behavior in an e-government system according to claim 6, characterized in that, The behavioral anomaly pre-diagnosis of the second overlap rate, and the resulting data judgment, include: The time overlap rate between the first data type curve and the fourth data type curve within a preset unit time is determined based on the second overlap rate, and an overlap rate curve corresponding to the time overlap rate is constructed. Based on the overlap rate curve, determine the curve extension vector extending from different unit time points to the next unit time point, as well as the overlap rate characteristics corresponding to each unit time point. Based on the curve extension vector, the extension vector features are determined, and the extension vector features are bound with the overlap rate features to obtain a set of point features; The point feature set is arranged into a matrix according to time sequence to obtain the point feature matrix; The point feature matrix is ​​used to extrapolate the point feature set according to a unit time period to obtain the predicted point matrix for the future period. The future point feature set is determined based on the predicted point matrix, and the future overlap rate within the future period is determined based on the future point feature set. The future overlap rate is determined based on the preset overlap rate standard to obtain the data determination result.

8. An abnormal behavior detection system for e-government systems, characterized in that, include: The data acquisition module is used to acquire system function modules and module-related data of the e-government system, as well as functional behavior data of the e-government system within a historical time period. The data processing module is used to process the system functional modules and their associated data to obtain a behavior pointer carousel and pointer behavior paths. The pointer behavior paths are obtained by: sorting the system functional modules according to a comprehensive weight value, placing the system functional modules into an initial pointer carousel according to the sorted module sequence to obtain a behavior pointer carousel, determining the module association of each system functional module on the behavior pointer carousel according to the module association data, and constructing paths between the associated system functional modules to obtain pointer behavior paths, provided that there is an association between the system functional modules. The behavior verification module is used to perform abnormal behavior verification on the functional behavior data, determine whether the functional behavior data is abnormal behavior data, and if so, input the functional behavior data into the preset behavior correction model for abnormal correction identification to obtain the corrected behavior data corresponding to the functional behavior data. The data binding module is used to bind the correction behavior data and the functional behavior data to the pointer behavior path according to a preset correspondence to obtain behavior path data; The behavior collection module is used to collect the real-time operation behavior of the operator after detecting that the operator has logged into the e-government system; The anomaly determination module is used to determine anomalies in the real-time operation behavior based on the behavior pointer turntable and the behavior path data, and obtain anomaly determination results.

9. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as any one of claims 1 to 7 for anomaly detection methods for e-government systems.

10. A computer-readable storage medium, characterized in that, The system stores a computer program capable of being loaded by a processor and executed as any one of the abnormal behavior detection methods for e-government systems as described in claims 1 to 7.

Citation Information

Patent Citations

  • Persistent annotation of syntax graphs for code optimization

    CN114041117A

  • Method and system for verifying and correcting integrity of flight data and storage medium

    CN119336746A