Application software user behavior analysis system based on artificial intelligence

Through the AI-based application software user behavior analysis system, deep learning and federated learning technologies are used to dynamically identify and respond to abnormal behaviors, solving the problem of insufficient ability to identify new attacks in traditional methods, achieving efficient cross-departmental collaborative defense, and improving the security of application software.

CN120597265AActive Publication Date: 2025-09-05JINAN GRUBER SOFTWARE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510688046.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-09-05
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

Traditional user behavior analysis methods for application software rely on static rules and static statistical models, are unable to dynamically learn complex behavior patterns, lack the ability to identify new attacks, have poor real-time performance, and analyze behavioral data from different business modules in isolation, making it impossible to block attacks in a timely manner.

Method used

It adopts an AI-based application software user behavior analysis system, including a behavioral gene map module, a fraud countermeasure module, a causal tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, and an adversarial simulation module. It combines deep learning and federated learning technologies to dynamically update the model to identify abnormal behavior and respond in real time.

Benefits of technology

It achieves a response to new attacks within seconds, improves the detection accuracy and response efficiency of complex risk behaviors, solves the problem of data silos, provides collaborative defense capabilities across departments and business lines, and significantly improves the security of application software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597265A_ABST
    Figure CN120597265A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of behavior analysis, in particular to an application software user behavior analysis system based on artificial intelligence, which comprises a behavior genetic map module, a fraud confrontation module, a causal traceability module, a meta-analysis module, a dynamic authority module, a behavior tracking module, a confrontation simulation module and a dynamic updating module. And the behavior gene map module is used for generating a unique feature identifier of the user behavior. According to the method, limitation of a traditional method is broken through through an artificial intelligence technology, time-space correlation characteristics of user behaviors are automatically extracted through deep learning, hidden anomalies can be recognized without manually defining rules, incremental learning and a federal updating mechanism are combined, the model can respond to new behavior data in a second level, accurate interception is triggered at the initial stage of attack, and the attack speed is improved. Through an intelligent, dynamic and collaborative analysis architecture, the detection precision and response efficiency of complex risk behaviors are remarkably improved, and upgrading from passive defense to active perception is provided for application software security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of behavior analysis, and in particular to an application software user behavior analysis system based on artificial intelligence. Background Art

[0002] Application software user behavior refers to all interactive operations and related data generated by users during the use of the software, including but not limited to login, clicks, page jumps, transaction payments, data upload / download, permission calls and other actions. These behaviors include both explicit operations and implicit features, and can reflect the user's true intentions, habits and potential risks.

[0003] However, traditional analysis methods generally rely primarily on rule engines and static statistical models, such as threshold-based anomaly detection or fixed rule matching. These methods require manual pre-definition of risk signatures and can only identify known, fixed-pattern attack behaviors. Their core drawbacks include weak generalization, high false positives and negatives, poor real-time performance, and data silos. They are unable to dynamically learn complex behavioral patterns and lack the ability to identify new types of attacks. Static rules struggle to distinguish between high-frequency user operations and malicious behavior. They also rely on offline log analysis, making it difficult to promptly block ongoing attacks. Behavioral data from different business modules is analyzed in isolation, making it impossible to correlate cross-scenario risks.

[0004] Based on this, the present invention provides an application software user behavior analysis system based on artificial intelligence to solve the technical problems raised above. Summary of the Invention

[0005] The purpose of the present invention is to provide an application software user behavior analysis system based on artificial intelligence to solve the problems raised by the above background technology.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] The first aspect of the present invention:

[0008] The present invention proposes an artificial intelligence-based application software user behavior analysis system, which includes a behavioral gene map module, a fraud countermeasure module, a causal traceability module, a meta-analysis module, a dynamic permission module, a behavior tracking module, a countermeasure simulation module, and a dynamic update module;

[0009] The behavioral gene map module is used to generate a unique characteristic identifier of user behavior and distinguish between normal and abnormal patterns. The fraud countermeasure module is used to identify and block false transactions and hidden fraud behaviors such as order brushing. The causal tracing module is used to analyze the root causes and event chain relationships of high-risk behaviors. The meta-analysis module is used to detect illegal communications without cracking encrypted content. The dynamic permission module is used to restrict high-risk permission operations in real time. The behavior tracking module is used to quantify changes in the chaos of user behavior and detect social engineering attacks. The countermeasure simulation module is used to simulate the attacker's behavior to optimize the detection model. The dynamic update module is used to collaboratively update the model for multiple systems.

[0010] Preferably, the behavioral gene map module further includes a gene sequence encoding unit and a map dynamic updating unit;

[0011] The gene sequence encoding unit extracts the time, frequency, and path characteristics of the user's click, login, and payment operation sequences through Transformer time series modeling to generate dynamic behavior gene encoding;

[0012] The graph dynamic update unit integrates new behavior data in real time through the GraphSAGE incremental graph embedding algorithm, updates the user-behavior association graph, and captures long-term latent APT attack characteristics.

[0013] Preferably, the fraud countermeasure module further comprises a multimodal fraud detection unit and an adversarial sample generation unit;

[0014] The multimodal fraud detection unit uses the ST-GNN spatiotemporal graph neural network to associate user device IP, IMEI fingerprint, page jump sequence operation path, amount and frequency transaction data to identify distributed gang fraud behavior;

[0015] The adversarial sample generation unit simulates the attacker's behavior through a conditional generative adversarial network, generates fraudulent samples and injects them into the training set, thereby enhancing the model's robustness against new fraudulent methods.

[0016] Preferably, the causal tracing module further includes an event chain mining unit and a context association unit;

[0017] The event chain mining unit models the causal relationship between user behavior and system logs through a Bayesian causal network, tracing the path of abuse of authority caused by internal personnel data leakage;

[0018] The context association unit integrates external SMS records and in-application login behavior cross-module data in social engineering attacks through a multi-hop attention mechanism to identify the complete link of phishing attacks.

[0019] Preferably, the meta-analysis module further comprises a metadata topology analysis unit and a covert channel identification unit;

[0020] The metadata topology analysis unit analyzes the communication frequency, object distribution, and time interval of the encrypted session through time series anomaly detection to identify the dark web transaction instruction transmission pattern;

[0021] The covert channel identification unit monitors the covert channel using message length to transmit instructions in encrypted traffic through information entropy mutation detection, thereby blocking the data return behavior of APT attacks.

[0022] Preferably, the dynamic permission module further includes a permission path mapping unit and a sandbox behavior simulation unit;

[0023] The permission path mapping unit associates employee roles, historical operations, and sensitive data access records through knowledge graph technology to dynamically generate a minimum permission policy;

[0024] The sandbox behavior simulation unit isolates high-risk operations of exporting batch data through virtualization container technology, records abnormal behaviors in the simulation environment and triggers alarms.

[0025] Preferably, the behavior tracking module further includes an entropy baseline modeling unit and an entropy increase alarm unit;

[0026] The entropy baseline modeling unit calculates the click randomness and session interval interaction entropy of the user's historical behavior through a Gaussian mixture model to establish an individualized normal baseline;

[0027] The entropy increase alarm unit compares the current behavior entropy value with the baseline in real time through KL divergence detection to identify abnormal interactions such as sudden and frequent blocking of others after account hijacking.

[0028] Preferably, the confrontation simulation module further includes a red team strategy generation unit and a blue team defense evolution unit;

[0029] The red team strategy generation unit trains the AI ​​attack agent through PPO algorithm reinforcement learning, simulating dynamic IP switching and human-machine verification to bypass automated script attacks;

[0030] The blue team's defense evolution unit dynamically adjusts the detection rule threshold through a collaborative evolution algorithm to counter the bypass samples generated by the red team, forming an attack and defense game closed loop.

[0031] Preferably, the dynamic update module further includes a federated feature alignment unit and a differential privacy aggregation unit;

[0032] The federated feature alignment unit unifies the user behavior feature spaces of different payment and social business lines through the FedMA heterogeneous data alignment algorithm;

[0033] The differential privacy aggregation unit encrypts and aggregates the model parameters of each node through secure multi-party computing, preventing the leakage of training data and supporting cross-departmental joint efforts to combat internal threats.

[0034] On the other hand, based on the above system, the present invention also proposes an application software user behavior analysis method based on artificial intelligence, comprising the following steps:

[0035] S1. Behavioral gene coding generation and graph update: Input the timestamp, path and context features of the user's click, login and payment operation sequence data, and perform the operation sequence X = {x1, x2, ..., x n}, where x i is the feature vector of the i-th operation, and the behavior gene encoding is generated through the multi-head self-attention mechanism, as shown in formula (1):

[0036]

[0037] Where Q, K, V are query, key, and value matrices, d k is the dimension scaling factor, and the output is the time series feature Use the incremental graph embedding algorithm to update the user behavior association graph, see formula (2):

[0038]

[0039] Where, is the embedding of node v in layer k, is a neighbor node, AGGREGATE is the aggregation function that outputs the dynamic behavior gene code Z and the updated user behavior graph;

[0040] S2. Multimodal detection of covert fraudulent behavior: Input the behavior code Z generated by S1, IP and IMEI device fingerprints, amount and frequency transaction data, perform spatiotemporal graph modeling, and construct a spatiotemporal graph G = (V, E, A), where nodes V represent users / devices, edges E represent transaction or behavior associations, and A is the adjacency matrix. Abnormal transactions are detected through spatiotemporal graph convolution, as shown in Equation (3):

[0041]

[0042] Where, is the self-loop connection matrix, is the degree matrix, H (l) Output fraud probability score P∈[0,1] for the l-th layer node features and mark high-risk transactions;

[0043] S3. Behavioral entropy change baseline modeling and alerting: Input the click randomness and session interval interaction entropy features of the user's historical behavior sequence, and use the Gaussian mixture model to fit the historical entropy value distribution, as shown in formula (4):

[0044]

[0045] Where, πk is the mixing coefficient, μ k ,Σ k is the mean and covariance of the kth Gaussian distribution, and the current behavior entropy value H is calculated in real time t , see formula (5):

[0046]

[0047] The KL divergence is used to detect the entropy mutation, as shown in formula (6):

[0048]

[0049] Where P is the current entropy distribution, Q is the baseline distribution, and D KL >θ triggers the alarm to output the entropy change alarm signal and abnormal behavior type;

[0050] S4. Cross-module data collaboration and dynamic update: Input S1's behavior code Z, S2's fraud score, and PS3's entropy change warning signal, and perform dynamic update on multiple business line features Z. 支付, Z 社交 Perform heterogeneous alignment, see formula (7);

[0051]

[0052] Where W is the mapping matrix, m is the number of samples, and differential privacy encryption is used to update the global model parameter θ global , see formula (8):

[0053]

[0054] Where θ k is the kth local model parameter, and σ is the global detection model and cross-business line feature map after the noise intensity output update.

[0055] Compared with the prior art, the present invention has the following beneficial effects:

[0056] The present invention breaks through the limitations of traditional methods through artificial intelligence technology, uses deep learning to automatically extract the spatiotemporal correlation characteristics of user behavior, and can identify hidden anomalies without manually defining rules. Combined with incremental learning and federated update mechanisms, the model can respond to new behavioral data in seconds, triggering precise interception at the early stage of an attack, and constructing a panoramic view of user behavior through multimodal fusion, breaking the blind spots of traditional single-point detection, introducing an attack and defense game mechanism, allowing the system to continuously evolve to resist new attack methods, and adopting federated learning and differential privacy technology to achieve cross-departmental and cross-business line collaborative defense while protecting user data privacy, solving the problem of data islands. In summary, the present invention significantly improves the detection accuracy and response efficiency of complex risk behaviors through an intelligent, dynamic, and collaborative analysis architecture, providing an upgrade from passive defense to active perception for application software security. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 This is an artificial intelligence-based application software user behavior analysis system of the present invention;

[0058] Figure 2 This invention provides an application software user behavior analysis method based on artificial intelligence. DETAILED DESCRIPTION

[0059] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0060] Example 1, please refer to Figure 1 , the present invention proposes an application software user behavior analysis system based on artificial intelligence, including a behavioral gene map module, a fraud confrontation module, a causal tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, a confrontation simulation module and a dynamic update module;

[0061] Among them, the behavioral gene map module is used to generate a unique characteristic identifier of user behavior and distinguish between normal and abnormal patterns. The fraud countermeasure module is used to identify and block false transactions and hidden fraud behaviors. The causal tracing module is used to analyze the root causes and event chain relationships of high-risk behaviors. The meta-analysis module is used to detect illegal communications without cracking encrypted content. The dynamic permission module is used to restrict high-risk permission operations in real time. The behavior tracking module is used to quantify changes in the chaos of user behavior and detect social engineering attacks. The adversarial simulation module is used to simulate attacker behavior to optimize the detection model. The dynamic update module is used to collaboratively update the model for multiple systems.

[0062] It should also be noted that the behavioral gene map module also includes a gene sequence encoding unit and a map dynamic update unit;

[0063] The gene sequence encoding unit extracts the time, frequency, and path characteristics of user click, login, and payment operation sequences through Transformer time series modeling to generate dynamic behavior gene encoding;

[0064] The graph dynamic update unit uses the GraphSAGE incremental graph embedding algorithm to integrate new behavioral data in real time, update the user-behavior association graph, and capture long-term latent APT attack characteristics.

[0065] It should also be noted that the fraud adversarial module also includes a multimodal fraud detection unit and an adversarial sample generation unit;

[0066] The multimodal fraud detection unit uses the ST-GNN spatiotemporal graph neural network to associate user device IP, IMEI fingerprint, page jump sequence operation path, amount and frequency transaction data to identify distributed gang fraud behavior;

[0067] The adversarial sample generation unit simulates attacker behavior through a conditional generative adversarial network, generates fraudulent samples and injects them into the training set, thereby enhancing the model's robustness against new methods of wool-stealing.

[0068] It should also be noted that the causal tracing module also includes an event chain mining unit and a context association unit;

[0069] The event chain mining unit uses Bayesian causal networks to model the causal relationship between user behavior and system logs, tracing the path of abuse of authority leading to data leakage by insiders;

[0070] The context association unit integrates cross-module data of external SMS records and in-application login behaviors in social engineering attacks through a multi-hop attention mechanism to identify the complete link of phishing attacks.

[0071] It should also be noted that the meta-analysis module also includes a metadata topology analysis unit and a covert channel identification unit;

[0072] The metadata topology analysis unit analyzes the communication frequency, object distribution, and time interval of encrypted sessions through time series anomaly detection to identify dark web transaction instruction transmission patterns;

[0073] The covert channel identification unit monitors the covert channels that use message length to transmit instructions in encrypted traffic through information entropy mutation detection, blocking the data return behavior of APT attacks.

[0074] It should also be noted that the dynamic permission module also includes a permission path mapping unit and a sandbox behavior simulation unit;

[0075] The permission path mapping unit uses knowledge graph technology to associate employee roles, historical operations, and sensitive data access records to dynamically generate a minimum privilege policy.

[0076] The sandbox behavior simulation unit uses virtualization container technology to isolate high-risk operations such as batch export of data, record abnormal behaviors in the simulation environment, and trigger alarms.

[0077] It should also be noted that the behavior tracking module also includes an entropy baseline modeling unit and an entropy increase alarm unit;

[0078] The entropy baseline modeling unit uses a Gaussian mixture model to calculate the click randomness of user historical behavior and the session interval interaction entropy value to establish an individualized normal baseline;

[0079] The entropy increase alarm unit compares the current behavior entropy value with the baseline in real time through KL divergence detection to identify abnormal interactions such as sudden and frequent blocking of others after account hijacking.

[0080] It should also be noted that the adversarial simulation module also includes a red team strategy generation unit and a blue team defense evolution unit;

[0081] The red team strategy generation unit uses the PPO algorithm to reinforce learning and train AI attack agents, simulating dynamic IP switching and human-machine verification to bypass automated script attacks;

[0082] The blue team's defense evolution unit dynamically adjusts the detection rule threshold through a collaborative evolution algorithm to counter the bypass samples generated by the red team, forming a closed loop of attack and defense game.

[0083] It should also be noted that the dynamic update module also includes a federated feature alignment unit and a differential privacy aggregation unit;

[0084] The federated feature alignment unit unifies the user behavior feature spaces of different payment and social business lines through the FedMA heterogeneous data alignment algorithm;

[0085] The differential privacy aggregation unit encrypts and aggregates the model parameters of each node through secure multi-party computing to prevent the leakage of training data and support cross-departmental joint efforts to combat internal threats.

[0086] Example 2, please refer to Figure 2 In actual application, the application software user behavior analysis method based on the above system includes the following steps:

[0087] S1. Behavioral gene coding generation and graph update: Input the timestamp, path and context features of the user's click, login and payment operation sequence data, and perform the operation sequence X = {x1, x2, ..., x n}, where x i is the feature vector of the i-th operation, and the behavior gene encoding is generated through the multi-head self-attention mechanism, as shown in formula (1):

[0088]

[0089] Where Q, K, V are query, key, and value matrices, d k is the dimension scaling factor, and the output is the time series feature Use the incremental graph embedding algorithm to update the user behavior association graph, see formula (2):

[0090]

[0091] Where, is the embedding of node v in layer k, is a neighbor node, AGGREGATE is the aggregation function that outputs the dynamic behavior gene code Z and the updated user behavior graph;

[0092] Generate behavioral gene codes and update the map through step S1;

[0093] The Transformer's multi-head self-attention mechanism captures long-range dependencies in user operation sequences, such as the correlation between high-frequency clicks and low-frequency payments across pages. This addresses the inadequacy of traditional RNN models in modeling long-term temporal features and improves the ability to identify abnormal behaviors such as APT attacks at an early stage.

[0094] Incremental graph embedding dynamically integrates new user behaviors, such as newly logged-in devices, without requiring full data retraining. This reduces the latency of updating the association graph from hours to seconds, ensuring real-time detection of latent attacks such as long-term, low-frequency data theft.

[0095] Encoding user behavior into low-dimensional genetic features reduces storage space by over 70% compared to raw log data while preserving key behavioral semantics.

[0096] S2. Multimodal detection of covert fraudulent behavior: Input the behavior code Z generated by S1, IP and IMEI device fingerprints, amount and frequency transaction data, perform spatiotemporal graph modeling, and construct a spatiotemporal graph G = (V, E, A), where nodes V represent users / devices, edges E represent transaction or behavior associations, and A is the adjacency matrix. Abnormal transactions are detected through spatiotemporal graph convolution, as shown in Equation (3):

[0097]

[0098] Where, is the self-loop connection matrix, is the degree matrix, H (l) Output fraud probability score P∈[0,1] for the l-th layer node features and mark high-risk transactions;

[0099] Performing multimodal detection of concealed fraudulent behavior through step S2;

[0100] Spatiotemporal graph convolution jointly models device fingerprints such as IP addresses, operation paths such as page jump sequences, and transaction amounts such as sudden large transfers, increasing the detection accuracy of distributed group fraud from 65% to 92% based on traditional rules.

[0101] By generating adversarial examples, such as injecting fake transaction data, the model's misjudgment rate for new methods of profiteering, such as bulk coupon redemption, was reduced by 40%, significantly enhancing the model's robustness.

[0102] The parallel computing architecture of spatiotemporal graph convolution supports processing 100,000 transaction requests per second, with detection latency controlled within 50ms, meeting the needs of high-concurrency scenarios.

[0103] S3. Behavioral entropy change baseline modeling and alerting: Input the click randomness and session interval interaction entropy features of the user's historical behavior sequence, and use the Gaussian mixture model to fit the historical entropy value distribution, as shown in formula (4):

[0104]

[0105] Where, π k is the mixing coefficient, μ k ,Σ k is the mean and covariance of the kth Gaussian distribution, and the current behavior entropy value H is calculated in real time t , see formula (5):

[0106]

[0107] The KL divergence is used to detect the entropy mutation, as shown in formula (6):

[0108]

[0109] Where P is the current entropy distribution, Q is the baseline distribution, and D KL >θ triggers the alarm to output the entropy change alarm signal and abnormal behavior type;

[0110] Perform behavioral entropy change baseline modeling and alarming in step S3;

[0111] The Gaussian mixture model fits the entropy distribution of historical user behavior to avoid false positives caused by group baselines, such as misjudging normal high-frequency operations of active users as abnormalities. This reduces the individual false positive rate by 35%.

[0112] KL divergence quantifies the difference between the current behavioral entropy and the baseline, and can identify abnormal interactions within 0.5 seconds after account hijacking, such as sudden and frequent blocking of others. The response speed is 3 times faster than the threshold method.

[0113] Entropy calculation is weighted by probability density to reduce the impact of occasional operations such as accidental touches on the overall entropy value, reducing the false alarm rate by 25%;

[0114] S4. Cross-module data collaboration and dynamic update: Input S1's behavior code Z, S2's fraud score, and PS3's entropy change warning signal, and perform dynamic update on multiple business line features Z. 支付, Z 社交 Perform heterogeneous alignment, see formula (7);

[0115]

[0116] Where W is the mapping matrix, m is the number of samples, and differential privacy encryption is used to update the global model parameter θ global , see formula (8):

[0117]

[0118] Where θ k is the kth local model parameter, σ is the global detection model and cross-business line feature map after the noise intensity output is updated;

[0119] Perform cross-module data collaboration and dynamic update through step S4;

[0120] Federated feature alignment maps the payment service feature space to a unified dimension, increasing the detection coverage of cross-service attacks, such as payment fraud initiated by leveraging social network relationships, from 58% to 85%.

[0121] Differential privacy aggregation adds Gaussian noise to model parameters, ensuring that the risk of leaking user sensitive information such as transaction records is reduced by 99% when cross-departmental data is jointly trained;

[0122] The federated update mechanism supports hourly global model synchronization, reducing the deployment time of defense strategies for new attacks such as variant phishing links from 24 hours to 2 hours.

[0123] Throughout this specification, references to terms such as "one embodiment," "example," or "specific example" indicate that the specific features, structures, materials, or characteristics described in conjunction with that embodiment or example are included in at least one embodiment or example of the present invention. In this specification, schematic representations of these terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0124] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to the specific embodiments described. Obviously, many modifications and variations are possible based on the content of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. The application software user behavior analysis system based on artificial intelligence is characterized by: It includes behavioral gene mapping module, fraud confrontation module, causal tracing module, meta-analysis module, dynamic authority module, behavior tracking module, confrontation simulation module and dynamic update module; The behavioral gene map module is used to generate a unique characteristic identifier of user behavior and distinguish between normal and abnormal patterns. The fraud countermeasure module is used to identify and block false transactions and hidden fraud behaviors such as order brushing. The causal tracing module is used to analyze the root causes and event chain relationships of high-risk behaviors. The meta-analysis module is used to detect illegal communications without cracking encrypted content. The dynamic permission module is used to restrict high-risk permission operations in real time. The behavior tracking module is used to quantify changes in the chaos of user behavior and detect social engineering attacks. The countermeasure simulation module is used to simulate the attacker's behavior to optimize the detection model. The dynamic update module is used to collaboratively update the model for multiple systems.

2. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The behavioral gene map module also includes a gene sequence encoding unit and a map dynamic update unit; The gene sequence encoding unit is used to extract the time, frequency, and path characteristics of the user's click, login, and payment operation sequences to generate dynamic behavior gene codes; The graph dynamic update unit is used to integrate new behavior data in real time, update the user-behavior association graph, and capture long-term latent APT attack characteristics.

3. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The fraud countermeasure module further includes a multimodal fraud detection unit and an adversarial sample generation unit; The multimodal fraud detection unit is used to associate user device IP, IMEI fingerprint, page jump sequence operation path, amount and frequency transaction data to identify distributed gang fraud behavior; The adversarial sample generation unit simulates the attacker's behavior through a conditional generative adversarial network, generates fraudulent samples and injects them into the training set, thereby enhancing the model's robustness against new fraudulent methods.

4. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The causal tracing module also includes an event chain mining unit and a context association unit; The event chain mining unit is used to model the causal relationship between user behavior and system logs, and to trace the path of abuse of authority caused by internal personnel data leakage; The context association unit is used to integrate external SMS records and in-application login behavior cross-module data in social engineering attacks to identify the complete link of phishing attacks.

5. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The meta-analysis module also includes a metadata topology analysis unit and a covert channel identification unit; The metadata topology analysis unit is used to detect and analyze the communication frequency, object distribution, and time interval of the encrypted session, and identify the dark web transaction instruction transmission pattern; The covert channel identification unit is used to monitor the covert channel using message length to transmit instructions in encrypted traffic, and block the data return behavior of APT attacks.

6. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The dynamic permission module also includes a permission path mapping unit and a sandbox behavior simulation unit; The permission path mapping unit is used to associate employee roles, historical operations and sensitive data access records, and dynamically generate a minimum privilege policy; The sandbox behavior simulation unit is used to isolate high-risk operations of exporting batch data, record abnormal behaviors in the simulation environment and trigger alarms.

7. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The behavior tracking module also includes an entropy baseline modeling unit and an entropy increase alarm unit; The entropy baseline modeling unit is used to calculate the click randomness of the user's historical behavior and the session interval interaction entropy value to establish an individualized normal baseline; The entropy increase alarm unit is used to compare the current behavior entropy value with the baseline in real time, and identify abnormal interactions such as sudden and frequent blocking of others after account hijacking.

8. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The confrontation simulation module also includes a red team strategy generation unit and a blue team defense evolution unit; The red team strategy generation unit is used to train AI attack agents, simulate dynamic IP switching, and bypass automated script attacks for human-machine verification; The blue team defense evolution unit is used to dynamically adjust the detection rule threshold to counter the bypass samples generated by the red team, forming an attack and defense game closed loop.

9. The artificial intelligence-based application software user behavior analysis system according to claim 1, characterized in that: The dynamic update module also includes a federated feature alignment unit and a differential privacy aggregation unit; The federated feature alignment unit is used to unify the user behavior feature spaces of different payment and social business lines; The differential privacy aggregation unit is used to aggregate the model parameters of each node, prevent the leakage of training data, and support cross-departmental joint efforts to combat internal threats.

10. The method for analyzing user behavior of application software based on artificial intelligence according to any one of claims 1 to 9, characterized in that: The following steps are involved: S1. Behavioral gene coding generation and graph update: Input the timestamp, path and context features of the user's click, login and payment operation sequence data, and perform the operation sequence X = {x1, x2, ..., x n }, where x i is the feature vector of the i-th operation, and the behavior gene encoding is generated through the multi-head self-attention mechanism, as shown in formula (1): Where Q, K, V are query, key, and value matrices, d k is the dimension scaling factor, and the output is the time series feature Use the incremental graph embedding algorithm to update the user behavior association graph, see formula (2): Where, is the embedding of node v in layer k, is a neighbor node, AGGREGATE is the aggregation function that outputs the dynamic behavior gene code Z and the updated user behavior graph; S2. Multimodal detection of covert fraudulent behavior: Input the behavior code Z generated by S1, IP and IMEI device fingerprints, amount and frequency transaction data, perform spatiotemporal graph modeling, and construct a spatiotemporal graph G = (V, E, A), where nodes V represent users / devices, edges E represent transaction or behavior associations, and A is the adjacency matrix. Abnormal transactions are detected through spatiotemporal graph convolution, as shown in Equation (3): Where, is the self-loop connection matrix, is the degree matrix, H ( l) Output fraud probability score P∈[0,1] for the l-th layer node features and mark high-risk transactions; S3. Behavioral entropy change baseline modeling and alerting: Input the click randomness and session interval interaction entropy features of the user's historical behavior sequence, and use the Gaussian mixture model to fit the historical entropy value distribution, as shown in formula (4): Where, π k is the mixing coefficient, μ k ,Σ k is the mean and covariance of the kth Gaussian distribution, and the current behavior entropy value H is calculated in real time t , see formula (5): The KL divergence is used to detect the entropy mutation, as shown in formula (6): Where P is the current entropy distribution, Q is the baseline distribution, and D KL >θ triggers the alarm to output the entropy change alarm signal and abnormal behavior type; S4. Cross-module data collaboration and dynamic update: Input S1's behavior code Z, S2's fraud score, and PS3's entropy change warning signal, and perform dynamic update on multiple business line features Z. 支付, Z 社交 Perform heterogeneous alignment, see formula (7); Where W is the mapping matrix, m is the number of samples, and differential privacy encryption is used to update the global model parameter θ global , see formula (8): Where θ k is the kth local model parameter, and σ is the global detection model and cross-business line feature map after the noise intensity output update.

Citation Information

Patent Citations

  • DDoS attack real-time detection and traceability analysis method based on knowledge graph

    CN119728286A

  • Network security dynamic early warning method and system based on knowledge graph

    CN119788344A

  • Generalized behavior analytics framework for detecting and preventing different types of API security vulnerabilities

    US20240430282A1