Building abnormal intrusion detection equipment and method combined with behavior pattern analysis
By combining building anomaly intrusion detection equipment and methods with behavioral pattern analysis, the false alarm and missed alarm problems caused by the single verification method of existing building security systems are solved, automated anomaly identification and rapid response are achieved, and detection accuracy and safety are improved.
Patent Information
- Application Number
- CN202511022156.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-07-24
AI Technical Summary
Existing building security systems rely on a single verification method and are easily affected by imitation and forgery, resulting in false alarms and missed alarms, and low security.
Building intrusion detection equipment and methods combined with behavioral pattern analysis can achieve automated anomaly identification and rapid response through operation log acquisition, pattern feature analysis, random verification parameters and data network structure.
It improves the accuracy and security of detection, reduces false alarms and missed alarms, optimizes resource allocation, reduces labor costs, enhances system security, and enables rapid response and positioning of abnormal locations.
Smart Images

Figure CN120526517B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a building abnormal intrusion detection device and method combined with behavior pattern analysis. Background Art
[0002] Building intrusion detection is an important component of smart buildings. It can detect and identify potential threats in real time and protect the safety of assets and personnel. However, the behavioral pattern detection methods of existing technologies often rely on static rules and thresholds, which are prone to false positives or missed negatives. For example, the occasional behavior of normal users may be mistakenly identified as abnormal, resulting in unnecessary alarms, affecting user experience and trust. In addition, the building security of existing technologies usually relies on only a single authentication method, such as passwords, making buildings vulnerable to security threats such as phishing attacks and password cracking. Attackers can easily imitate user identities, causing system intrusion, thereby increasing security risks. Summary of the Invention
[0003] This application provides a building intrusion detection device and method combined with behavioral pattern analysis, aiming to solve the technical problem that building security in the existing technology usually relies on a single verification method, is easily affected by imitation and forgery, and leads to false alarms, missed alarms, and thus low security.
[0004] The first aspect disclosed in the present application provides a building abnormal intrusion detection device combined with behavior pattern analysis, the device including: an operation log acquisition unit, the operation log acquisition unit is used to connect to the building monitoring system and obtain operation logs, and the operation logs are used to construct a data network structure according to the building distribution; a pattern feature analysis unit, the pattern feature analysis unit is used to perform operation behavior pattern feature analysis of the identification and verification system according to the operation logs to obtain identification behavior specification features; a pattern abnormality identification unit, the pattern abnormality identification unit is used to construct an identification module using the identification behavior specification features, and perform operation behavior pattern abnormality identification on the building identification and verification system through the identification module to obtain a first identification result; a verification parameter acquisition unit, the verification parameter acquisition unit is used to construct a random identification module, activate the random identification module according to the first identification result, and obtain random verification parameters; an abnormal position positioning unit, the abnormal position positioning unit is used to obtain a verification result according to the random verification parameters, send building abnormal intrusion information when the verification requirements are not met, and locate the abnormal building position based on the data network structure.
[0005] The second aspect disclosed in the present application provides a method for detecting abnormal building intrusions in combination with behavior pattern analysis. The method is implemented by the above-mentioned abnormal building intrusion detection device in combination with behavior pattern analysis. The method includes: connecting to a building monitoring system to obtain operation logs, and constructing a data network structure according to the operation logs according to the building distribution; performing operation behavior pattern feature analysis of the identification and verification system according to the operation logs to obtain identification behavior specification features; using the identification behavior specification features to construct an identification module, and performing operation behavior pattern abnormality identification on the building identification and verification system through the identification module to obtain a first identification result; constructing a random identification module, activating the random identification module according to the first identification result, and obtaining random verification parameters; obtaining a verification result according to the random verification parameters, and when the verification requirements are not met, sending building abnormal intrusion information, and locating the abnormal building position based on the data network structure.
[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0007] By connecting to building monitoring systems to obtain operation logs and construct a data network structure, data from various monitoring devices can be effectively managed and integrated. Risk level labels can be used to identify and prioritize high-risk areas, optimize the allocation of monitoring resources, and reduce resource waste. This centralized management method improves the efficiency of system resource utilization. By analyzing operation logs to identify normal behavior patterns, which are used as a benchmark for comparison with abnormal behavior, abnormal operations can be accurately identified, reducing false positives and missed alerts, and improving detection accuracy. By using the characteristics of recognized behavioral specifications to build an identification module, the building identification and verification system can identify abnormal operation behavior patterns, realizing an automated data analysis and verification process, reducing reliance on manual intervention, improving operational efficiency and accuracy, and reducing labor costs. The introduction of randomized verification parameters means that users face different verification methods each time they verify, making it more difficult for attackers to imitate or crack the verification process, increasing system security and improving the overall security protection level. When verification fails or times out, abnormal intrusion information is promptly sent, and the location of the abnormal building is located based on the data network structure. This rapid response mechanism enables the swift implementation of necessary security measures when a threat occurs, achieving timely on-site response and handling.
[0008] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1A schematic diagram of the structure of a building intrusion detection device combined with behavioral pattern analysis provided in an embodiment of the present application;
[0010] Figure 2 A flow chart of a method for detecting abnormal building intrusions combined with behavioral pattern analysis provided in an embodiment of the present application.
[0011] Explanation of reference numerals: operation log acquiring unit 10 , pattern feature analyzing unit 20 , pattern anomaly identifying unit 30 , verification parameter acquiring unit 40 , anomaly position locating unit 50 . DETAILED DESCRIPTION
[0012] The embodiments of the present application provide a building intrusion detection device and method combined with behavioral pattern analysis, thereby solving the technical problem that building security in the prior art usually relies on a single verification method, is easily affected by imitation and forgery, and leads to false alarms, missed alarms, and thus low security.
[0013] After introducing the basic principles of this application, various non-limiting embodiments of this application will be specifically described below in conjunction with the accompanying drawings. It should be understood that the specific embodiments described here are only used to explain this application and are not used to limit this application.
[0014] Example 1, as Figure 1 As shown, an embodiment of the present application provides a building abnormal intrusion detection device combined with behavior pattern analysis, the device comprising:
[0015] An operation log acquisition unit 10 is used to connect to a building monitoring system and acquire operation logs, and the operation logs are used to construct a data network structure according to the building distribution; a pattern feature analysis unit 20 is used to perform operation behavior pattern feature analysis of the identification and verification system based on the operation logs to obtain identification behavior specification features; a pattern anomaly identification unit 30 is used to construct an identification module using the identification behavior specification features, and perform operation behavior pattern anomaly identification on the building identification and verification system through the identification module to obtain a first identification result; a verification parameter acquisition unit 40 is used to construct a random identification module, activate the random identification module according to the first identification result, and obtain random verification parameters; an abnormal position positioning unit 50 is used to obtain a verification result according to the random verification parameters, and when the verification requirements are not met, send building abnormal intrusion information and locate the abnormal building position based on the data network structure.
[0016] Furthermore, the connecting to the building monitoring system and obtaining the operation log includes:
[0017] Obtain risk entrances for abnormal building intrusions and establish risk level labels for the risk entrances; filter target risk entrances based on the risk level labels and extract associated building monitoring interfaces for the target risk entrances; set data collection frequencies according to the risk level labels and obtain the operation logs through the associated building monitoring interfaces.
[0018] Furthermore, it also includes:
[0019] A correlation analysis of multi-source monitoring devices is performed based on the target risk entry to determine the correlation coefficient of the multi-source monitoring system, wherein the correlation analysis is determined by a fusion correlation evaluation of the coverage, acquisition frequency, and recognition degree of each monitoring device for the target risk entry; weights are allocated according to the correlation coefficient to construct a multi-source monitoring feature layer, where each feature layer corresponds to a monitoring device; feature aggregation is performed from bottom to top based on the multi-source monitoring feature layer, and the weight of the aggregated features of each layer is calculated according to the allocated weight of each feature layer to construct a monitoring feature aggregation framework.
[0020] Furthermore, extracting the associated building monitoring interface of the target risk entrance includes:
[0021] According to the correlation coefficient between the multi-source monitoring system and the target risk entry, a mapping relationship between the monitoring feature aggregation framework and the monitoring equipment data interface is established to determine the associated building monitoring interface.
[0022] Furthermore, the operation behavior pattern characteristics of the identification and verification system are analyzed based on the operation log to obtain the identification behavior specification characteristics, including:
[0023] The operation log is decomposed according to preset dimensions to construct multi-dimensional data blocks, wherein the preset dimensions include: time dimension, space dimension, user dimension, device dimension, and environment dimension; based on the multi-dimensional data blocks, static features are extracted, wherein the static features are structured data that do not change over time; the static features are input into a multi-layer perceptron for hierarchical feature processing according to the multi-dimensional data blocks, wherein each layer of the multi-layer perceptron uses an activation function to perform nonlinear feature extraction on the static features to obtain a static feature representation vector; based on the multi-dimensional data blocks, time series features are extracted, wherein the time series features include the timestamp and operation time interval of the operation log; the time series features are input into a recurrent neural network, and the feature dependency in the time series is captured through a memory and forgetting mechanism, and a time series dependency feature is output; the static feature representation vector and the time series dependency feature are spliced together through a connection layer, and the spliced features are input into a fully connected layer for feature fusion to obtain the recognition behavior specification feature.
[0024] Furthermore, obtaining the random verification parameter includes:
[0025] Obtain the number and type of verification means; set a user random verification threshold; set a verification means sequence identifier based on the number and type of verification means, the number of the verification means sequence identifiers is the same as the number of verification means, and the verification means sequence identifiers are mapped and associated with the verification means types; use the user random verification threshold and the verification means sequence identifier to construct a random matrix, wherein the row elements of the random matrix are the user random verification threshold amounts and the column elements are the verification means; perform random acquisition of verification means on the random matrix through a random function to determine the random verification parameters.
[0026] Furthermore, the random matrix is verified by a random function to obtain the random matrix randomly and determine the random verification parameter, including:
[0027] According to the number of column elements in the random matrix, the rounding range of the random function is set, and a random integer is obtained through the random function; a random verification parameter is obtained from the random matrix according to the random integer, and the row elements are covered according to the random acquisition number; when all the row elements in the random matrix are covered, the random identification module is locked and an early warning message is sent.
[0028] Furthermore, when the verification requirements are not met, sending the building abnormal intrusion information includes:
[0029] When the verification result is not passed or is not obtained within a timeout period, it is determined that the verification requirement is not met and the building abnormal intrusion information is sent.
[0030] Through the subsequent detailed description of the building abnormal intrusion detection method combined with behavioral pattern analysis in this specification, technical personnel in this field can clearly understand the building abnormal intrusion detection device combined with behavioral pattern analysis in this embodiment. Since it corresponds to the method disclosed in the embodiment, the description is relatively simple. For relevant details, please refer to the method part.
[0031] Example 2, based on the same inventive concept as the building abnormal intrusion detection device combined with behavior pattern analysis in the above embodiment, such as Figure 2 As shown, the embodiment of the present application provides a building abnormal intrusion detection method combined with behavior pattern analysis, the method comprising:
[0032] Connect to the building monitoring system to obtain operation logs, and construct a data network structure based on the operation logs according to the building distribution.
[0033] Establish a data interface connection with the building monitoring system. The building monitoring system usually includes multiple devices such as cameras, access control systems, alarms, etc. Through the interfaces of these devices, you can access the corresponding operation log data, such as access control logs, access control system records, system administrator's operation records, etc. Since the operation logs may come from different monitoring devices in multiple buildings, the log data needs to be classified. The classification standard can be based on the physical distribution of the building. For example, based on the independent identifier of each building, the log data of different buildings can be distinguished, and the log data can be constructed into a data network structure according to the distribution of the buildings. For example, each building is regarded as a node in the network, and each monitoring device in the building is regarded as a sub-node. Connections can be established between these nodes. The basis of the connection can be the communication between devices, the flow path of personnel between buildings, etc.
[0034] An operation behavior pattern feature analysis of the identification and verification system is performed based on the operation log to obtain identification behavior specification features.
[0035] To accurately capture the behavioral characteristics of users and devices, logs require multi-dimensional analysis, encompassing time, space, user, device, and environment. Within the resulting multi-dimensional data, some features are relatively fixed or invariant over time. These are known as static features. Static features are extracted from operation logs to form a structured data representation that remains constant over time. In addition to static features, some behavioral patterns within multi-dimensional data are also affected by temporal variations. These are known as time series features, which capture temporal patterns in operations.
[0036] The static features are input into a multilayer perceptron for processing. The behavioral patterns in the operation logs are not simple linear relationships. Therefore, the static features are nonlinearly transformed through the activation functions of each layer of the multilayer perceptron to extract deeper behavioral patterns. The multilayer perceptron processes the input features layer by layer. Each layer further extracts the potential features of the behavioral pattern through weights and activation functions, and finally outputs a high-dimensional feature vector to obtain the static feature representation vector.
[0037] The time series features are input into the recurrent neural network for processing. The recurrent neural network has a memory and forgetting mechanism, which can capture the dependencies of the time series in the operation log and output the time series dependency features. The time series features processed by the recurrent neural network can be used to predict the next possible operation behavior pattern. If the actual behavior is significantly different from the predicted behavior, it may be an abnormal signal.
[0038] The static feature representation vector obtained is spliced with the time series dependency feature through the connection layer to form a comprehensive feature representation, and the final recognition behavior specification feature is generated. This feature is the baseline of normal operation behavior and is used to identify whether there are abnormalities in the operation behavior, providing a basis for subsequent anomaly detection.
[0039] An identification module is constructed using the identification behavior specification features, and abnormal operation behavior patterns of the building identification and verification system are identified through the identification module to obtain a first identification result.
[0040] A recognition module is constructed based on identifying behavioral norm features. The module uses these features as judgment criteria to determine whether the current behavior deviates from the normal behavior pattern. For example, anomalies are identified through unsupervised learning methods such as clustering, isolation forest, support vector machine, etc. These models can learn to identify the normal patterns of behavioral norm features and report anomalies when encountering behaviors that are significantly different from the training data.
[0041] Receive real-time operation logs obtained from the building monitoring system, extract behavioral features consistent with previous ones from the real-time operation logs, including static features and time series features, and send these features to the recognition module to match them with the recognition behavior specification features. The recognition module compares the features of the current operation with the historical behavior specifications. If some features deviate from the normal behavior specifications, they are marked as abnormal and the first recognition result is output. The first recognition result includes the recognition result label, the cause of the abnormality, etc., for example, which feature or behavior pattern triggered the anomaly detection.
[0042] A random recognition module is constructed, and the random recognition module is activated according to the first recognition result to obtain a random verification parameter.
[0043] Construct a random identification module. Its main function is to further verify whether the behavior detected by the system is normal user operation by introducing random factors, preventing attackers from imitating the behavior patterns of legitimate users. After the identification module obtains the first recognition result, it determines whether further verification is required based on preset rules. Typically, when the behavior is detected close to the abnormality threshold—for example, when the behavior is considered normal but has a certain degree of uncertainty—the random verification module is activated. A preset activation threshold can be set, and when the uncertainty of the recognition result exceeds this threshold, the random identification module is activated. When the random identification module is activated, a set of random verification parameters is generated to guide the subsequent verification operation.
[0044] A verification result is obtained according to the random verification parameter. When the verification requirement is not met, building abnormal intrusion information is sent, and the abnormal building position is located based on the data network structure.
[0045] Once the random verification parameters are determined, the user is required to perform additional verification using a randomly selected method. For example, they may first enter their password, then verify their fingerprint, and finally enter a dynamic verification code. If the user successfully completes the random verification within the specified time, the operation is deemed legitimate and the successful verification is recorded. Conversely, if the user fails to meet the random verification requirements, the operation is deemed an abnormal behavior, and a building intrusion anomaly message is generated and sent to the designated security team or administrator, notifying them of the potential intrusion risk and triggering a physical security response. Through the previously established data network structure, the source of the abnormal behavior and the location of the abnormal building are quickly located, ensuring that security threats can be quickly responded to and addressed.
[0046] Furthermore, the connecting to the building monitoring system and obtaining the operation log includes:
[0047] Obtain risk entrances for abnormal building intrusions and establish risk level labels for the risk entrances; filter target risk entrances based on the risk level labels and extract associated building monitoring interfaces for the target risk entrances; set data collection frequencies according to the risk level labels and obtain the operation logs through the associated building monitoring interfaces.
[0048] Risky entrances refer to physical areas or equipment in a building that may be vulnerable to intrusion or present a higher security risk. These include access control systems, windows, ventilation systems and fire exits, parking entrances, elevators, and stairways. A risk level label is created for each risky entrance, and the risk level labels are divided according to the security risk of different entrances. Common risk level classification criteria include historical data, which determines the historical risk of a particular entrance based on past intrusion records and alarm data; location and environment, which affects the physical location of the entrance, such as proximity to busy streets, low floors, and the surrounding environment, such as the presence of easily climbable facilities and the coverage of surveillance cameras. Risky entrances are classified according to these criteria, and a risk level label is generated for each risky entrance.
[0049] Based on the risk level labels, high-risk entrances requiring special attention are selected as target risk entrances for analysis. Each risk entrance is associated with a different monitoring device or sensor, which serves as the source of data collected by the system. Based on the target risk entrance, the associated building monitoring interface is extracted. For example, a gravity sensor installed on a window can detect abnormal vibration or opening movement, triggering a timely alarm. A high-definition camera installed at the entrance can monitor the behavior of people entering and leaving in real time, recording video data and performing image recognition.
[0050] The data collection frequency is adjusted based on the risk level label. Specifically, high-risk entrances typically require real-time data collection. For example, cameras need to record real-time video 24 hours a day, and access control systems need to record every door opening and closing action in real time. The data collection frequency for medium-risk entrances can be appropriately reduced, for example, to once every 10 minutes, or increased only during specific time periods, such as at night or when unmanned. For low-risk areas, data can be collected only during specific events, such as alarm triggers and regular inspections, to reduce system resource usage. This data collection frequency controls the associated building monitoring interface to collect data and obtain the operation log.
[0051] Furthermore, it also includes:
[0052] A correlation analysis of multi-source monitoring devices is performed based on the target risk entry to determine the correlation coefficient of the multi-source monitoring system, wherein the correlation analysis is determined by a fusion correlation evaluation of the coverage, acquisition frequency, and recognition degree of each monitoring device for the target risk entry; weights are allocated according to the correlation coefficient to construct a multi-source monitoring feature layer, where each feature layer corresponds to a monitoring device; feature aggregation is performed from bottom to top based on the multi-source monitoring feature layer, and the weight of the aggregated features of each layer is calculated according to the allocated weight of each feature layer to construct a monitoring feature aggregation framework.
[0053] Multi-source monitoring devices refer to the various devices used to monitor risk entrances in building monitoring systems, such as cameras, infrared sensors, and access control systems. These devices are often distributed in different locations and provide data for different monitoring needs. The correlation analysis of multi-source monitoring devices is conducted based on the target risk entrance. Specifically, the coverage of the monitoring devices is analyzed. Each monitoring device can usually only cover a specific physical space. The coverage of each device for the target risk entrance is calculated. The data collection frequency of different devices directly affects the response speed and detection accuracy of the system. For example, the data collection frequency of real-time monitoring cameras is higher than that of timed-trigger sensors, so their monitoring correlation with the target risk entrance is also stronger. The collection frequency of each monitoring device is evaluated. The recognition analysis is also conducted. Recognition refers to the ability of monitoring devices to effectively distinguish between normal and abnormal behavior. For example, high-definition cameras can provide clearer images, which facilitates the system to perform facial recognition or behavioral pattern recognition and has a higher recognition degree. Simple sensors, such as vibration sensors, can only detect simple physical phenomena and have a lower recognition degree.
[0054] Based on the above-mentioned coverage, collection frequency and recognition, a correlation coefficient is calculated for each monitoring device. The correlation coefficient reflects the strength of the correlation between a certain monitoring device and the target risk entrance. The comprehensive correlation of each device can be calculated according to the weights of coverage, collection frequency and recognition to obtain the correlation coefficient of the multi-source monitoring system. The higher the correlation coefficient, the better the monitoring effect of the device on the target risk entrance.
[0055] Weights are assigned based on the correlation coefficient, and corresponding weights are given to each device in the multi-source monitoring system. Devices with higher correlation coefficients are assigned greater weights to ensure that the data of these devices dominates the subsequent analysis process. Each monitoring device is divided into different feature layers according to its weight. The feature layer can be understood as a hierarchical monitoring architecture. Each layer corresponds to a monitoring device. Each feature layer independently processes the data of its corresponding device to ensure the hierarchical and detailed nature of data analysis.
[0056] Feature aggregation involves combining data from different feature layers to generate a comprehensive monitoring feature. The goal is to achieve more comprehensive and accurate anomaly identification capabilities through layer-by-layer aggregation without losing individual device features. First, starting with the lowest feature layer, such as low-frequency data sources, preliminary aggregation is performed on this data. For example, entry and exit times from access control logs can be combined with alarm system data to determine if there are any unusual movements. Next, data from auxiliary monitoring devices is aggregated. For example, data from infrared sensors and vibration sensors can be combined to determine if there are any unusual intrusions. Finally, data from the primary monitoring device, such as the video stream from an HD camera, is combined with the previously aggregated results to generate a comprehensive feature representation. During the aggregation process, different feature layers are weighted according to their assigned weights. Feature layers with higher weights have a greater impact on the final aggregation result. Ultimately, a monitoring feature aggregation framework is constructed. This framework incorporates comprehensive features aggregated from multiple devices and multiple layers for real-time detection and response to unusual intrusions in buildings.
[0057] Furthermore, extracting the associated building monitoring interface of the target risk entrance includes:
[0058] According to the correlation coefficient between the multi-source monitoring system and the target risk entry, a mapping relationship between the monitoring feature aggregation framework and the monitoring equipment data interface is established to determine the associated building monitoring interface.
[0059] Each monitoring device provides a specific type of data, which is transmitted to the system through the device's data interface. The monitoring device data interface includes camera interface, sensor interface, access control system interface, etc. Mapping rules are established based on the correlation coefficient of each monitoring device. For example, for devices with a high correlation coefficient, such as cameras with a large coverage area and a high monitoring frequency, their real-time data streams are preferentially connected to the monitoring feature aggregation framework to ensure that these data have a higher weight in the analysis. For devices with a low correlation coefficient, their data can be used as a supplementary data source and enabled under specific conditions. When the mapping relationship is established, the associated building monitoring interface of each target risk entrance is determined. These interfaces are the data sources of the monitoring equipment directly related to the target risk entrance. They provide real-time monitoring data and can be dynamically adjusted according to the characteristics of the risk entrance.
[0060] Furthermore, the operation behavior pattern characteristics of the identification and verification system are analyzed based on the operation log to obtain the identification behavior specification characteristics, including:
[0061] The operation log is decomposed according to preset dimensions to construct multi-dimensional data blocks, wherein the preset dimensions include: time dimension, space dimension, user dimension, device dimension, and environment dimension; based on the multi-dimensional data blocks, static features are extracted, wherein the static features are structured data that do not change over time; the static features are input into a multi-layer perceptron for hierarchical feature processing according to the multi-dimensional data blocks, wherein each layer of the multi-layer perceptron uses an activation function to perform nonlinear feature extraction on the static features to obtain a static feature representation vector; based on the multi-dimensional data blocks, time series features are extracted, wherein the time series features include the timestamp and operation time interval of the operation log; the time series features are input into a recurrent neural network, and the feature dependency in the time series is captured through a memory and forgetting mechanism, and a time series dependency feature is output; the static feature representation vector and the time series dependency feature are spliced together through a connection layer, and the spliced features are input into a fully connected layer for feature fusion to obtain the recognition behavior specification feature.
[0062] Operation logs are broken down into different preset dimensions. These dimensions help analyze operational behavior from multiple perspectives, capturing behavioral patterns and potential anomalies. Each dimension corresponds to its own unique features that can be extracted. Combining these features can better describe and learn user behavior patterns. Preset dimensions include: the time dimension, which includes the specific time, timestamp, and time interval of the operation. This dimension can help capture the patterns of behavior changes over time; the spatial dimension, which includes the geographic location or location within the building where the operation occurred. The spatial dimension can reflect the physical distribution of user activities; the user dimension, which includes the user's identity information, permission level, and historical behavior patterns. This dimension helps identify the legitimacy of user operation behavior and whether it conforms to their usual behavior patterns; the device dimension, which includes the device type, functional attributes of the device, and status information of the device. The device dimension reflects the relationship between the device and the operation, such as the status of devices such as cameras, sensors, and access control systems; and the environmental dimension, which includes environmental variables such as weather and building activity that may affect operational behavior.
[0063] Extract static features from data blocks of different dimensions. Static features refer to structured data that does not change over time. For example, physical location features are extracted from the spatial dimension, such as the entrance locations commonly used by users and the coverage range of cameras. Fixed features such as user identity information and permission levels are extracted from the user dimension to help determine whether the user has the authority to perform specific operations.
[0064] The multilayer perceptron is a feedforward neural network used to process high-dimensional static features. The extracted static features are input into the multilayer perceptron for nonlinear feature extraction. Specifically, the multilayer perceptron processes the input features through multiple hidden layers. In each layer, the network applies an activation function, such as ReLU, to capture the nonlinear relationship in the static features. Each layer generates a new high-dimensional feature representation, reflecting the more complex associations between static features. After multi-layer processing, a high-dimensional static feature representation vector is generated.
[0065] Time series features are extracted from multi-dimensional data blocks. These features are used to analyze the patterns of operational behavior over time. Time series features include the timestamp and operation time interval of the operation log. The timestamp is the specific time record of each operation, which can provide the precise time when the operation occurred, for example, the specific time point when a user performed a certain operation. The operation time interval refers to the time difference between two consecutive operations and is used to analyze the user's operating habits and behavioral patterns. For example, under normal circumstances, how long is the time interval between operations of a user? If the time interval of a certain operation is abnormal, it may indicate potential abnormal behavior.
[0066] Inputting time series features into recurrent neural networks, particularly long short-term memory networks, is used to capture feature dependencies in time series. Recurrent neural networks can process sequential data, using their hidden states to memorize previous inputs, thereby taking previous information into account when processing the current input. This capability is particularly useful for processing time series features, as the current state of time series data is often closely related to the previous state. Long short-term memory networks introduce a forget gate that selectively forgets no longer needed information. This is crucial for preventing the vanishing gradient problem, allowing the model to maintain effective learning capabilities when processing longer sequences.
[0067] The recurrent neural network gradually processes the input time series data, updates its internal state at each time step, thereby learning the time series dependency features, and finally outputs a feature vector that reflects the feature dependency relationship of each time point in the time series. These dependencies are used for subsequent anomaly detection and behavior analysis.
[0068] The static feature representation vector and the time series dependency features are concatenated through the connection layer. The concatenated feature vector contains both static and dynamic information about the action, forming a rich feature representation that preserves both static and dynamic features. The concatenated features are then fused through the fully connected layer, further extracting important information from the features through a weighted summation, improving their expressiveness and ultimately yielding the behavioral recognition standard features.
[0069] Furthermore, obtaining the random verification parameter includes:
[0070] Obtain the number and type of verification means; set a user random verification threshold; set a verification means sequence identifier based on the number and type of verification means, the number of the verification means sequence identifiers is the same as the number of verification means, and the verification means sequence identifiers are mapped and associated with the verification means types; use the user random verification threshold and the verification means sequence identifier to construct a random matrix, wherein the row elements of the random matrix are the user random verification threshold amounts and the column elements are the verification means; perform random acquisition of verification means on the random matrix through a random function to determine the random verification parameters.
[0071] Determine the available authentication methods, including their number and type. Authentication methods are typically used to enhance system security by ensuring the legitimacy of operations through multiple verification methods. Authentication methods can be categorized into various types, including passwords / PINs, biometrics, dynamic verification codes, and security keys. The number and type of currently available authentication methods can be obtained by accessing the configuration file or the management console.
[0072] Set a user random verification threshold, which determines how many random verification methods are required during the verification process. The random verification threshold can be dynamically adjusted based on the system's security requirements, user behavior characteristics, or historical operation data. For example, in high-risk situations, a higher threshold can be set to increase the number of verification methods.
[0073] Assign a unique identifier to each verification method for use during random verification. These identifiers can be numbers, letters, etc. The number of verification method sequence identifiers should match the number of verification methods, ensuring that each method has a corresponding identifier. Create a mapping table to associate each verification method type with its corresponding sequence identifier. This way, during random verification, you can quickly retrieve the required verification method type from the mapping table based on the randomly generated verification method sequence identifier.
[0074] According to the user's random verification threshold and the verification means sequence identifier, a random matrix is filled and constructed. The matrix is used to store various verification means information related to the user's random verification for subsequent random acquisition. Specifically, the row elements of the matrix represent the user's random verification threshold. For example, if the user's random verification threshold is 3, the first row of the matrix contains 3 verification means; the column elements of the matrix represent the available verification means sequence identifiers. For example, if verification means such as passwords, fingerprints, and dynamic verification codes are provided, each means will correspond to a column.
[0075] A random function is used to select rows and columns in a random matrix to determine the specific verification method required for the current verification. The verification method obtained by the random function generates a set of random verification parameters for the subsequent verification process. Each time the user performs an operation, a different verification method can be selected according to the new random verification parameters. For example, if a fingerprint and password are used in the first verification, then a fingerprint and a dynamic verification code may be used in the next verification, thereby enhancing security and randomness.
[0076] Furthermore, the random matrix is verified by a random function to obtain the random matrix randomly and determine the random verification parameter, including:
[0077] According to the number of column elements in the random matrix, the rounding range of the random function is set, and a random integer is obtained through the random function; a random verification parameter is obtained from the random matrix according to the random integer, and the row elements are covered according to the random acquisition number; when all the row elements in the random matrix are covered, the random identification module is locked and an early warning message is sent.
[0078] Get the number of column elements in the random matrix, which represents the number of available verification methods. For example, if the random matrix has 4 verification methods, the number of column elements is 4. Based on the number of column elements, set the rounding range of the random function from 1 to N, where N is the number of column elements, to ensure that the generated random integers are always within the valid range.
[0079] A random integer is obtained through a random function, that is, an integer is randomly selected from the integer range of 1 to N. The formula of the random function is as follows:
[0080] ;
[0081] in, Indicates that random integers are uniformly generated in the range from 1 to N. Represents a random floating point number between 0 and 1, Indicates expanding the floating point number to the range of 0 to N. Indicates rounding down to ensure the result is an integer. This means that the range is adjusted to 1 to N, because rounding down will make the random number range from 0 to N-1. In this way, the entire formula can generate a random integer from 1 to N.
[0082] Using the generated random integer as an index, retrieve the corresponding column element from the random matrix to determine the current verification method. For example, if the random integer is 2 and the second column of the random matrix corresponds to a dynamic verification code, then the current verification method is the dynamic verification code. After obtaining the random verification parameters, overwrite the corresponding row element, for example, marking it as "used" or "overwritten", indicating that the verification method in this row has been selected for the current verification. This prevents the same verification method from being reused in the same verification.
[0083] If all row elements are covered, it means that the current random verification process has exhausted all available verification methods. In this case, the random identification module is locked to prevent the random identification module from making any new verification requests to protect the system from continuous attacks. This mechanism prevents repeated attempts and ensures the security and effectiveness of the system.
[0084] Furthermore, when the verification requirements are not met, sending the building abnormal intrusion information includes:
[0085] When the verification result is not passed or is not obtained within a timeout period, it is determined that the verification requirement is not met and the building abnormal intrusion information is sent.
[0086] If a user fails the randomly selected verification method, the event is recorded and marked as failed. If a user fails to complete the required verification within the set time, for example, by not entering the dynamic verification code in time, the event is marked as timed out. If either of these situations occurs, the verification fails to meet the requirements and an abnormal building intrusion message is immediately generated and sent to the relevant personnel. This information includes the event type, user identity, timestamp, and operation location, ensuring that the system can respond to potential security threats in a timely manner and protect building safety.
[0087] In summary, the method for detecting abnormal building intrusions combined with behavioral pattern analysis provided by the embodiments of the present application has the following technical effects:
[0088] By connecting to building monitoring systems to obtain operation logs and construct a data network structure, data from various monitoring devices can be effectively managed and integrated. Risk level labels can be used to identify and prioritize high-risk areas, optimize the allocation of monitoring resources, and reduce resource waste. This centralized management method improves the efficiency of system resource utilization. By analyzing operation logs to identify normal behavior patterns, which are used as a benchmark for comparison with abnormal behavior, abnormal operations can be accurately identified, reducing false positives and missed alerts, and improving detection accuracy. By using the characteristics of recognized behavioral specifications to build an identification module, the building identification and verification system can identify abnormal operation behavior patterns, realizing an automated data analysis and verification process, reducing reliance on manual intervention, improving operational efficiency and accuracy, and reducing labor costs. The introduction of randomized verification parameters means that users face different verification methods each time they verify, making it more difficult for attackers to imitate or crack the verification process, increasing system security and improving the overall security protection level. When verification fails or times out, abnormal intrusion information is promptly sent, and the location of the abnormal building is located based on the data network structure. This rapid response mechanism enables the swift implementation of necessary security measures when a threat occurs, achieving timely on-site response and handling.
[0089] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. Building intrusion detection equipment combined with behavioral pattern analysis is characterized by: The device comprises: An operation log acquisition unit, the operation log acquisition unit is used to connect to the building monitoring system to obtain operation logs, and the operation logs are used to construct a data network structure according to the building distribution; A pattern feature analysis unit, configured to analyze the operation behavior pattern features of the identification and verification system according to the operation log to obtain identification behavior specification features; A pattern anomaly recognition unit, the pattern anomaly recognition unit being configured to construct an identification module using the identification behavior specification features, and to perform operation behavior pattern anomaly recognition on the building identification and verification system through the identification module to obtain a first recognition result; a verification parameter acquisition unit, the verification parameter acquisition unit being configured to construct a random recognition module, activate the random recognition module according to the first recognition result, and acquire a random verification parameter; an abnormal location locating unit, configured to obtain a verification result based on the random verification parameter, send building abnormal intrusion information when the verification requirement is not met, and locate the abnormal building location based on the data network structure; The connecting to the building monitoring system and obtaining the operation log includes: Obtain risk entrances for abnormal building intrusions and establish risk level labels for the risk entrances; Filter target risk entrances according to the risk level labels, and extract associated building monitoring interfaces of the target risk entrances; Setting a data collection frequency according to the risk level label, and obtaining the operation log through the associated building monitoring interface; The operation behavior pattern feature analysis of the identification and verification system is performed based on the operation log to obtain the identification behavior specification features, including: Decomposing the operation log according to preset dimensions to construct multi-dimensional data blocks, wherein the preset dimensions include: time dimension, space dimension, user dimension, device dimension, and environment dimension; Extracting static features based on the multi-dimensional data blocks, where the static features are structured data that does not change over time; Inputting the static features into a multilayer perceptron for hierarchical feature processing according to multidimensional data blocks, wherein each layer of the multilayer perceptron uses an activation function to perform nonlinear feature extraction on the static features to obtain a static feature representation vector; Extracting time series features based on the multi-dimensional data block, the time series features including a timestamp and an operation time interval of the operation log; Input the time series features into a recurrent neural network, capture the feature dependencies in the time series through a memory and forgetting mechanism, and output the time series dependency features; The static feature representation vector and the time series dependency feature are spliced together through a connection layer, and the spliced features are input into a fully connected layer for feature fusion to obtain the recognition behavior specification feature; The obtaining of random verification parameters includes: Obtain the number and types of verification methods; Set user random verification threshold; According to the number and type of the verification means, a verification means sequence identifier is set, the number of the verification means sequence identifiers is the same as the number of verification means, and the verification means sequence identifiers are mapped and associated with the verification means types; Using the user random verification threshold and the verification means sequence identifier, a random matrix is constructed, wherein the row elements of the random matrix are the user random verification thresholds and the column elements are the verification means; The random matrix is randomly obtained by verification means through a random function to determine the random verification parameter.
2. The building intrusion detection device combined with behavior pattern analysis according to claim 1, characterized in that: Also includes: Performing a correlation analysis of multi-source monitoring devices based on the target risk entry to determine a correlation coefficient of the multi-source monitoring system, wherein the correlation analysis is determined by performing a fusion correlation evaluation of the coverage, acquisition frequency, and recognition degree of each monitoring device for the target risk entry; Weights are assigned according to the correlation coefficients to construct a multi-source monitoring feature layer, where each feature layer corresponds to a monitoring device; Based on the multi-source monitoring feature layer, feature aggregation is performed from bottom to top, and the weight of aggregated features of each layer is calculated according to the allocated weight of each feature layer to construct a monitoring feature aggregation framework.
3. The building intrusion detection device combined with behavior pattern analysis as claimed in claim 2, characterized in that: Extracting the associated building monitoring interface of the target risk entrance, including: According to the correlation coefficient between the multi-source monitoring system and the target risk entry, a mapping relationship between the monitoring feature aggregation framework and the monitoring equipment data interface is established to determine the associated building monitoring interface.
4. The building intrusion detection device combined with behavior pattern analysis according to claim 1, characterized in that: The randomly obtaining verification means of the random matrix by using a random function to determine the random verification parameter includes: According to the number of column elements in the random matrix, a rounding range of the random function is set, and a random integer is obtained by the random function; Obtaining random verification parameters from the random matrix according to the random integer, and overwriting row elements according to the number of random acquisitions; When all row elements in the random matrix are covered, the random identification module is locked and sends a warning message.
5. The building intrusion detection device combined with behavior pattern analysis as claimed in claim 1, characterized in that: When the verification requirements are not met, sending building abnormal intrusion information includes: When the verification result is not passed or is not obtained within a timeout period, it is determined that the verification requirement is not met and the building abnormal intrusion information is sent.
6. The building abnormal intrusion detection method combined with behavioral pattern analysis is characterized by: Based on the implementation of the building abnormal intrusion detection device combined with behavior pattern analysis according to any one of claims 1 to 5, the method includes: Connecting to the building monitoring system to obtain operation logs, and constructing a data network structure based on the operation logs according to the building distribution; Analyze the operational behavior pattern characteristics of the identification and verification system according to the operation log to obtain the identification behavior specification characteristics; Using the recognition behavior specification features to construct a recognition module, and using the recognition module to identify abnormal operation behavior patterns of the building recognition and verification system to obtain a first recognition result; Constructing a random recognition module, activating the random recognition module according to the first recognition result, and obtaining a random verification parameter; A verification result is obtained according to the random verification parameter. When the verification requirement is not met, building abnormal intrusion information is sent, and the abnormal building position is located based on the data network structure.