Artificial intelligence-based application software user behavior analysis system

By using an AI-based application software user behavior analysis system, which leverages deep learning and federated learning technologies to dynamically identify abnormal behaviors, the system solves the problems of insufficient ability to identify new types of attacks and data silos in traditional methods, and achieves efficient cross-departmental collaborative defense and real-time response.

CN120597265BActive Publication Date: 2025-12-16JINAN GRUBER SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510688046.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-12-16
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

Traditional application software user behavior analysis methods rely on static rules and static statistical models, which cannot dynamically learn complex behavioral patterns, lack the ability to identify new types of attacks, have poor real-time performance, and analyze behavioral data from different business modules in isolation, making it impossible to correlate them across scenarios, resulting in high false positives and false negatives and poor real-time performance.

Method used

An AI-based user behavior analysis system is adopted, including a behavior gene mapping module, a fraud prevention module, a causal tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, and an adversarial simulation module. Combining deep learning and federated learning technologies, the system dynamically updates the model to identify abnormal behavior and achieves collaborative defense across departments and business lines.

Benefits of technology

It significantly improves the detection accuracy and response efficiency of complex risk behaviors, enabling it to respond to new behavioral data in seconds, identify hidden anomalies, solve the data silo problem, and achieve an upgrade from passive defense to proactive perception.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597265B_ABST
    Figure CN120597265B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of behavior analysis, in particular to an application software user behavior analysis system based on artificial intelligence, which comprises a behavior gene map module, a fraud confrontation module, a cause and effect tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, a confrontation simulation module and a dynamic updating module; the behavior gene map module is used for generating a unique feature identifier of user behavior. The application breaks through the limitations of traditional methods through artificial intelligence technology, automatically extracts the space-time correlation features of user behavior by using deep learning, can identify hidden abnormalities without manually defining rules, combines an incremental learning and a federal updating mechanism, and the model can respond to new behavior data in seconds, triggers accurate interception in the early stage of an attack, and significantly improves the detection accuracy and response efficiency of complex risk behaviors through an intelligent, dynamic and collaborative analysis architecture, and provides an upgrade from passive defense to active perception for application software security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of behavior analysis, in particular to an application software user behavior analysis system based on artificial intelligence. BACKGROUND

[0002] Application software user behavior refers to all interactive operations and related data generated by a user in the process of using software, including but not limited to login, clicking, page jumping, transaction payment, data uploading / downloading, permission calling and the like. The behaviors contain both explicit operations and implicit features, and can reflect the real intention, habits and potential risks of the user.

[0003] However, generally, traditional analysis methods mainly rely on rule engines and static statistical models, such as threshold-based anomaly detection or fixed rule matching. Such methods need to manually define risk features in advance, and can only identify known and fixed-pattern attack behaviors. The core shortcomings of such methods are weak generalization ability, high false positives and false negatives, poor real-time performance and data silos, and the methods cannot dynamically learn complex behavior patterns and lack the ability to identify new attacks. Static rules are difficult to distinguish between high-frequency operations of normal users and malicious behaviors, and the methods still rely on offline log analysis, making it difficult to block ongoing attacks in a timely manner. The behavior data of different business modules is analyzed in isolation, and it is impossible to correlate cross-scenario risks.

[0004] Therefore, the application provides an application software user behavior analysis system based on artificial intelligence to solve the above technical problems. SUMMARY

[0005] The application aims to provide an application software user behavior analysis system based on artificial intelligence to solve the problems in the background art.

[0006] To achieve the above-mentioned purpose, the application provides the following technical solutions.

[0007] The first aspect of the application is:

[0008] The application provides an application software user behavior analysis system based on artificial intelligence, which comprises a behavior gene map module, a fraud confrontation module, a cause and effect tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, an adversarial simulation module and a dynamic updating module.

[0009] The behavior gene mapping module is used to generate a unique feature identifier of user behavior, distinguish normal and abnormal patterns, the fraud confrontation module is used to identify and block false transactions, hidden fraud behaviors such as brushing, the causal tracing module is used to analyze the root cause of high-risk behaviors and the relationship between event chains, the meta-analysis module is used to detect illegal communication without decrypting encrypted content, the dynamic permission module is used to limit high-risk permission operations in real time, the behavior tracking module is used to quantify the change of user behavior confusion degree, detect social engineering attacks, the confrontation simulation module is used to simulate attacker behavior to optimize the detection model, and the dynamic updating module is used to update the model in multiple systems.

[0010] Preferably, the behavior gene mapping module further comprises a gene sequence coding unit and a mapping dynamic updating unit;

[0011] The gene sequence coding unit extracts the time, frequency and path features of user click, login and payment operation sequences through Transformer time series modeling to generate dynamic behavior gene coding;

[0012] The mapping dynamic updating unit updates the user-behavior association graph in real time by fusing new behavior data through the GraphSAGE incremental graph embedding algorithm, and captures long-term latent APT attack features.

[0013] Preferably, the fraud confrontation module further comprises a multi-modal fraud detection unit and an adversarial sample generation unit;

[0014] The multi-modal fraud detection unit correlates user device IP, IMEI fingerprint, page jump sequence operation path, amount and frequency transaction data through the ST-GNN spatio-temporal graph neural network to identify distributed team brushing behavior;

[0015] The adversarial sample generation unit simulates attacker behavior through the conditional generative adversarial network to generate fraud sample injection training sets, and enhances the robustness of the model to new sheep-shearing methods.

[0016] Preferably, the causal tracing module further comprises an event chain mining unit and a context association unit;

[0017] The event chain mining unit models the causal relationship between user behavior and system logs through the Bayesian causal network to trace the abuse path of internal personnel data leakage;

[0018] The context association unit integrates external SMS records and application internal login behavior cross-module data in social engineering attacks through a multi-hop attention mechanism to identify the complete link of phishing attacks.

[0019] Preferably, the meta-analysis module further comprises a metadata topology analysis unit and a hidden channel identification unit;

[0020] The metadata topology analysis unit analyzes the communication frequency, object distribution, and time interval of the encrypted session through time series anomaly detection to identify dark web transaction instruction transmission patterns.

[0021] The covert channel identification unit monitors the hidden channel that transmits instructions using packet length in encrypted traffic through information entropy mutation detection, and blocks the data return behavior of APT attacks.

[0022] Preferably, the dynamic permission module further comprises a permission path mapping unit and a sandbox behavior simulation unit.

[0023] The permission path mapping unit dynamically generates a minimum permission policy by associating employee roles, historical operations, and sensitive data access records through knowledge graph technology.

[0024] The sandbox behavior simulation unit isolates high-risk operations for bulk data export through virtualization container technology, records abnormal behavior in the simulation environment, and triggers an alarm.

[0025] Preferably, the behavior tracking module further comprises an entropy value baseline modeling unit and an entropy increase alarm unit.

[0026] The entropy value baseline modeling unit calculates the click randomness and session interval interaction entropy value of user historical behavior through Gaussian mixture model to establish an individualized normal baseline.

[0027] The entropy increase alarm unit detects and compares the current behavior entropy value with the baseline in real time through KL divergence to identify abnormal interactions such as sudden frequent blacklisting of others after account hijacking.

[0028] Preferably, the adversarial simulation module further comprises a red team strategy generation unit and a blue team defense evolution unit.

[0029] The red team strategy generation unit trains an AI attack agent through PPO algorithm reinforcement learning to simulate dynamic IP switching and human verification bypassing automated script attacks.

[0030] The blue team defense evolution unit dynamically adjusts detection rule thresholds through a co-evolution algorithm to counter bypass samples generated by the red team, forming an attack-defense game closed loop.

[0031] Preferably, the dynamic update module further comprises a federated feature alignment unit and a differential privacy aggregation unit.

[0032] The federated feature alignment unit unifies user behavior feature spaces of different business lines through FedMA heterogeneous data alignment algorithm.

[0033] The differential privacy aggregation unit encrypts and aggregates model parameters of each node through secure multi-party computation to prevent training data leakage and support cross-department joint confrontation against internal threats.

[0034] In another aspect, based on the above system, the application further provides an application software user behavior analysis method based on artificial intelligence, comprising the following steps:

[0035] S1. Behavior gene encoding generation and graph updating: input the timestamp, path and context features of the user click, login and payment operation sequence data, and the operation sequence X={x1, x2, …, x n}, wherein x i is the i-th operation feature vector, and the behavior gene encoding is generated through a multi-head self-attention mechanism, as shown in formula (1):

[0036]

[0037] In the formula, Q, K and V are query, key and value matrices, d k is a dimension scaling factor, and the output is a time sequence feature The user behavior association graph is updated using an incremental graph embedding algorithm, as shown in formula (2):

[0038]

[0039] In the formula, is the embedding of node v at the k-th layer, is a neighbor node, and AGGREGATE is an aggregation function outputting dynamic behavior gene encoding Z and the updated user behavior graph;

[0040] S2. Multimodal detection of hidden fraudulent behavior: input the behavior encoding Z generated in S1, IP and IMEI device fingerprints, amount and frequency transaction data, perform spatio-temporal graph modeling, construct a spatio-temporal graph G=(V, E, A), wherein the node V represents a user / device, the edge E represents a transaction or behavior association, and A is an adjacency matrix, detect abnormal transactions through spatio-temporal graph convolution, as shown in formula (3):

[0041]

[0042] In the formula, is a self-loop adjacency matrix, is a degree matrix, and H (l) is the l-th layer node feature outputting a fraud probability score P∈[0,1], and marking high-risk transactions;

[0043] S3. Behavior entropy baseline modeling and alarm: input the click randomness and inter-session interaction entropy features of the user historical behavior sequence, use a Gaussian mixture model to fit the historical entropy value distribution, as shown in formula (4):

[0044]

[0045] In the formula, πk is a mixing coefficient, μ k , Σ k is the mean and covariance of the kth Gaussian distribution, and the current behavior entropy H t is calculated in real time, see formula (5):

[0046]

[0047] The entropy value mutation is detected by KL divergence, see formula (6):

[0048]

[0049] In the formula, P is the current entropy distribution, Q is the baseline distribution, D KL When θ, the entropy change alarm signal and the abnormal behavior type are triggered, the alarm output is triggered;

[0050] S4. Cross-module data collaboration and dynamic update: input S1 behavior encoding Z, S2 fraud score PS3 entropy change alarm signal, and multi-service line feature Z 支付, Z 社交 isomeric alignment, see formula (7);

[0051]

[0052] In the formula, W is the mapping matrix, m is the sample number, and the global model parameter θ global is updated using differential privacy encryption, see formula (8):

[0053]

[0054] In the formula, θ k is the kth local model parameter, σ is the noise intensity, and the updated global detection model and cross-service line feature mapping are output.

[0055] Compared with the prior art, the beneficial effects of the present application are:

[0056] The application breaks through the limitations of traditional methods through artificial intelligence technology, automatically extracts the spatio-temporal correlation features of user behavior by deep learning, identifies hidden anomalies without manual definition rules, combines incremental learning and federal update mechanism, the model can respond to new behavior data in seconds, triggers accurate interception at the initial stage of attack, constructs a panoramic view of user behavior through multi-modal fusion, breaks through the blind area of traditional single-point detection, introduces attack and defense game mechanism to make the system continuously evolve to resist new attack means, uses federal learning and differential privacy technology to realize cross-department and cross-business line collaborative defense on the premise of protecting user data privacy, breaks the data island problem, and the like. Through the intelligent, dynamic and collaborative analysis architecture, the detection accuracy and response efficiency of complex risk behaviors are significantly improved, and passive defense is upgraded to active perception for application software security. BRIEF DESCRIPTION OF DRAWINGS

[0057] Figure 1 The application is an application software user behavior analysis system based on artificial intelligence.

[0058] Figure 2 The application is an application software user behavior analysis method based on artificial intelligence. DETAILED DESCRIPTION

[0059] The technical solutions in the embodiments of the application will be described below in conjunction with the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, rather than all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the application.

[0060] Embodiment 1, please refer to Figure 1 The application provides an application software user behavior analysis system based on artificial intelligence, which comprises a behavior gene map module, a fraud confrontation module, a cause and effect tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, an attack simulation module and a dynamic update module.

[0061] The behavior gene map module is used to generate a unique feature identifier of user behavior, and to distinguish between normal and abnormal patterns. The fraud confrontation module is used to identify and block false transactions and hidden fraud behaviors. The cause and effect tracing module is used to analyze the root cause of high-risk behaviors and the relationship between event chains. The meta-analysis module is used to detect illegal communication without decrypting encrypted content. The dynamic permission module is used to limit high-risk permission operations in real time. The behavior tracking module is used to quantify the change in user behavior confusion degree and detect social engineering attacks. The attack simulation module is used to simulate attacker behavior to optimize the detection model. The dynamic update module is used to update the model in collaboration with multiple systems.

[0062] It should also be noted that the behavioral gene mapping module includes gene sequence coding units and dynamic map update units;

[0063] Gene sequence coding units extract the time, frequency, and path features of user click, login, and payment operation sequences through Transformer time series modeling to generate dynamic behavioral gene codes;

[0064] The graph dynamic update unit uses the GraphSAGE incremental graph embedding algorithm to fuse new behavioral data in real time, update the user-behavior association graph, and capture the characteristics of long-term latent APT attacks.

[0065] It should also be noted that the fraud countermeasure module includes a multimodal fraud detection unit and an adversarial sample generation unit;

[0066] The multimodal fraud detection unit uses the ST-GNN spatiotemporal graph neural network to associate user device IP, IMEI fingerprint, page jump sequence operation path, amount and frequency transaction data to identify distributed group fraudulent activities.

[0067] The adversarial sample generation unit simulates attacker behavior through a conditional generative adversarial network, generates fraudulent samples, and injects them into the training set to enhance the model's robustness against novel fraudulent practices.

[0068] It should also be noted that the causal tracing module includes an event chain mining unit and a context association unit;

[0069] The event chain mining unit models the causal relationship between user behavior and system logs using Bayesian causal networks to trace the path of internal personnel's abuse of privileges in data leakage.

[0070] The context association unit integrates cross-module data of external SMS records and in-application login behavior in social engineering attacks through a multi-hop attention mechanism to identify the complete chain of phishing attacks.

[0071] It should also be noted that the meta-analysis module includes a metadata topology analysis unit and a hidden channel identification unit;

[0072] The metadata topology analysis unit analyzes the communication frequency, object distribution, and time interval of encrypted sessions through time series anomaly detection to identify dark web transaction instruction transmission patterns;

[0073] The covert channel identification unit monitors encrypted traffic for covert channels that use message length to transmit instructions by detecting information entropy mutations, thereby blocking the data backhaul behavior of APT attacks.

[0074] It should also be noted that the dynamic permission module includes a permission path mapping unit and a sandbox behavior simulation unit;

[0075] The permission path mapping unit dynamically generates a minimum permission policy by associating employee roles, historical operations, and sensitive data access records through knowledge graph technology.

[0076] The sandbox behavior simulation unit isolates high-risk operations for batch data export through virtual container technology, records abnormal behavior in the simulation environment, and triggers an alarm.

[0077] It should be noted that the behavior tracking module also includes an entropy value baseline modeling unit and an entropy increase alarm unit.

[0078] The entropy value baseline modeling unit calculates the click randomness and session interval interaction entropy value of user historical behavior through a Gaussian mixture model to establish an individualized normal baseline.

[0079] The entropy increase alarm unit detects and compares the current behavior entropy value with the baseline in real time through KL divergence to identify sudden frequent blacklisting of others after account hijacking.

[0080] It should be noted that the countermeasure simulation module also includes a red team strategy generation unit and a blue team defense evolution unit.

[0081] The red team strategy generation unit trains an AI attack agent through PPO algorithm reinforcement learning to simulate dynamic IP switching and human verification bypassing automated script attacks.

[0082] The blue team defense evolution unit dynamically adjusts detection rule thresholds through a co-evolution algorithm to counter bypass samples generated by the red team, forming an attack-defense game closed loop.

[0083] It should be noted that the dynamic update module also includes a federated feature alignment unit and a differential privacy aggregation unit.

[0084] The federated feature alignment unit aligns user behavior feature spaces of different business lines through the FedMA heterogeneous data alignment algorithm.

[0085] The differential privacy aggregation unit aggregates model parameters of each node through secure multi-party computation encryption to prevent training data leakage and support cross-department joint countermeasures against internal threats.

[0086] Embodiment 2, please refer to Figure 2 In practical applications, the application software user behavior analysis method based on the above system includes the following steps:

[0087] S1. Behavior gene encoding generation and graph update: input the timestamp, path, and context features of user click, login, and payment operation sequence data, and generate behavior gene encoding through multi-head self-attention mechanism for operation sequence X = {x1, x2, …, x n}, where x i i is the i-th operation feature vector.

[0088]

[0089] where Q, K, V are query, key, value matrix, d k is the dimension scaling factor, and the output is the time series feature Update the user behavior association graph using the incremental graph embedding algorithm, see equation (2):

[0090]

[0091] where, is the embedding of node v at the kth layer, is the neighbor node, and AGGREGATE is the aggregation function output dynamic behavior gene code Z and the updated user behavior graph;

[0092] Generate behavior gene code and update the graph through step S1;

[0093] Through the multi-head self-attention mechanism of Transformer, capture the long-range dependency relationship in the user operation sequence, such as the association between high-frequency clicks and low-frequency payments across pages, solve the problem of insufficient modeling of long-term time series features in traditional RNN models, and improve the early identification ability of abnormal behaviors such as APT attacks;

[0094] Adopt incremental graph embedding, without the need for full data retraining, dynamically integrate new user behavior such as new device login, reduce the update delay of the association graph from hours to seconds, and ensure real-time capture of latent attacks such as long-term low-frequency data theft;

[0095] Encode user behavior into low-dimensional gene features, which reduces storage space occupancy by more than 70% compared to original log data, while retaining key behavior semantics;

[0096] S2. Multimodal detection of hidden fraudulent behavior: input the behavior code Z generated in S1, IP and IMEI device fingerprint, transaction data of amount and frequency, perform spatio-temporal graph modeling, construct a spatio-temporal graph G=(V,E,A), where node V represents user / device, edge E represents transaction or behavior association, and A is the adjacency matrix. Detect abnormal transactions through spatio-temporal graph convolution, see equation (3):

[0097]

[0098] where, is the self-loop adjacency matrix, is the degree matrix, H (l) is the lth layer node feature output fraud probability score P∈[0,1], and marks high-risk transactions;

[0099] Multimodal detection of covert fraudulent behavior is performed through step S2;

[0100] Spatiotemporal graph convolution jointly models device fingerprints such as IP addresses, operation paths such as page navigation order, and transaction amounts such as sudden large transfers, thereby increasing the detection accuracy of distributed group fraud from 65% to 92% using traditional rules.

[0101] By generating adversarial examples such as injecting fake transaction data, the model's false positive rate against new coupon-grabbing methods, such as bulk coupon collection, is reduced by 40%, and the model's robustness is significantly enhanced.

[0102] The parallel computing architecture of spatiotemporal graph convolution supports processing 100,000 transaction requests per second, with detection latency controlled within 50ms, meeting the needs of high-concurrency scenarios.

[0103] S3. Behavioral Entropy Variation Baseline Modeling and Alarm: Input the click randomness and session interval interaction entropy characteristics of the user's historical behavior sequence, and use a Gaussian mixture model to fit the historical entropy value distribution, as shown in Equation (4):

[0104]

[0105] In the formula, π k μ is the mixing coefficient. k ,Σ k Given the mean and covariance of the k-th Gaussian distribution, calculate the entropy value H of the current behavior in real time. t See equation (5):

[0106]

[0107] The entropy abrupt change is detected by KL divergence, as shown in equation (6):

[0108]

[0109] In the formula, P is the current entropy distribution, Q is the baseline distribution, and D is the base case distribution. KL When the value is greater than θ, an alarm is triggered to output an entropy change alarm signal and an abnormal behavior type.

[0110] Behavioral entropy baseline modeling and alarming are performed through step S3;

[0111] Gaussian mixture model fits the entropy distribution of users' historical behavior, avoiding false alarms caused by the group baseline, such as normal high-frequency operations of active users being misjudged as abnormal, reducing the individual false alarm rate by 35%.

[0112] KL divergence measures the difference between the current behavior entropy and the baseline, which can identify abnormal interactions within 0.5 seconds after account hijacking, such as suddenly and frequently blocking others, with a response speed 3 times faster than the threshold method.

[0113] The entropy value calculation reduces the influence of accidental operations such as accidental touch clicks on the overall entropy value through probability density weighting, and the false alarm rate is reduced by 25%;

[0114] S4. Cross-module data collaboration and dynamic update: input S1 behavior encoding Z, S2 fraud score PS3 entropy change alarm signal, multi-service line feature Z 支付, Z 社交 Heterogeneous alignment is performed, see equation (7);

[0115]

[0116] In the formula, W is a mapping matrix, m is the number of samples, and the global model parameter θ is updated using differential privacy encryption global , see equation (8):

[0117]

[0118] In the formula, θ k is the kth local model parameter, σ is the noise intensity, and the updated global detection model and cross-service line feature mapping are output;

[0119] Cross-module data collaboration and dynamic update are performed through step S4;

[0120] Federal feature alignment maps the feature space of payment services to a unified dimension, and the detection coverage of cross-service attacks such as payment fraud initiated by using social relationship chains is improved from 58% to 85%;

[0121] Differential privacy aggregation adds Gaussian noise to the model parameters, ensuring that the risk of leakage of sensitive information such as transaction records is reduced by 99% when cross-department data is jointly trained;

[0122] The federal update mechanism supports global model synchronization once an hour, and the deployment time of defense strategies for new attacks such as variant phishing links is shortened from 24 hours to 2 hours.

[0123] In the description of the present specification, the description of the terms "one embodiment", "example", "specific example" and the like means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0124] The preferred embodiments of the application disclosed above are only to facilitate the elucidation of the application. The preferred embodiments do not describe all the details of the application and limit the application to the specific embodiments described. Obviously, many modifications and variations can be made in light of the teachings above. The description is chosen and described in order to best explain the principles of the application and its practical application to thereby enable others skilled in the art to best utilize the application and get the best results from the application. The application is only limited by the claims and their full scope and equivalents.

Claims

1. An application software user behavior analysis system based on artificial intelligence, characterized in that, It includes a behavioral gene mapping module, a fraud prevention module, a causal tracing module, a meta-analysis module, a dynamic permission module, a behavior tracking module, an adversarial simulation module, and a dynamic update module; The behavioral gene mapping module is used to generate unique feature identifiers for user behavior, distinguishing between normal and abnormal patterns. The fraud prevention module is used to identify and block fraudulent activities such as fake transactions and order-brushing. The causal tracing module is used to analyze the root causes and event chain relationships of high-risk behaviors. The meta-analysis module is used to detect illegal communication without cracking encrypted content. The dynamic permission module is used to restrict high-risk permission operations in real time. The behavior tracking module is used to quantify changes in the disorder of user behavior and detect social engineering attacks. The adversarial simulation module is used to simulate attacker behavior to optimize the detection model. The dynamic update module is used for multi-system collaborative model updates. The behavioral gene mapping module also includes a gene sequence coding unit and a dynamic map update unit; The gene sequence coding unit is used to extract the time, frequency, and path features of user click, login, and payment operation sequences to generate dynamic behavior gene coding. The graph dynamic update unit is used to integrate new behavioral data in real time, update the user-behavior association graph, and capture the characteristics of long-term latent APT attacks. The fraud countermeasure module also includes a multimodal fraud detection unit and an adversarial sample generation unit; The multimodal fraud detection unit is used to associate user device IP, IMEI fingerprint, page jump order operation path, amount and frequency transaction data to identify distributed group fraudulent behavior; The adversarial sample generation unit simulates attacker behavior through a conditional generative adversarial network, generates fraudulent samples, and injects them into the training set to enhance the model's robustness against novel fraudulent practices. The behavior tracking module also includes an entropy baseline modeling unit and an entropy increase alarm unit; The entropy baseline modeling unit is used to calculate the click randomness and session interval interaction entropy of user's historical behavior, and to establish an individualized normal baseline. The entropy increase alarm unit is used to compare the current behavior entropy value with the baseline in real time to identify sudden and frequent blocking of others' abnormal interactions after account hijacking. The dynamic update module also includes a federated feature alignment unit and a differential privacy aggregation unit; The federal feature alignment unit is used to unify the user behavior feature space of different business lines such as payment and social networking. The differential privacy aggregation unit is used to aggregate model parameters from each node to prevent training data leakage and support cross-departmental collaboration in combating internal threats.

2. The application software user behavior analysis system based on artificial intelligence according to claim 1, characterized in that, The causal tracing module also includes an event chain mining unit and a context association unit; The event chain mining unit is used to model the causal relationship between user behavior and system logs, and to trace the path of internal personnel's abuse of permissions in data leakage. The context association unit is used to integrate cross-module data of external SMS records and in-application login behavior in social engineering attacks to identify the complete chain of phishing attacks.

3. The application software user behavior analysis system based on artificial intelligence according to claim 1, characterized in that, The meta-analysis module also includes a metadata topology analysis unit and a hidden channel identification unit; The metadata topology analysis unit is used to detect and analyze the communication frequency, object distribution, and time interval of encrypted sessions, and to identify the dark web transaction instruction transmission pattern. The hidden channel identification unit is used to monitor the hidden channel in encrypted traffic that uses message length to transmit instructions, thereby blocking the data backhaul behavior of APT attacks.

4. The application software user behavior analysis system based on artificial intelligence according to claim 1, characterized in that, The dynamic permission module also includes a permission path mapping unit and a sandbox behavior simulation unit; The permission path mapping unit is used to associate employee roles, historical operations and sensitive data access records, and dynamically generate the least privilege policy. The sandbox behavior simulation unit is used to isolate high-risk operations such as batch data export, record abnormal behaviors in the simulation environment, and trigger alarms.

5. The application software user behavior analysis system based on artificial intelligence according to claim 1, characterized in that, The adversarial simulation module also includes a red team strategy generation unit and a blue team defense evolution unit; The red team strategy generation unit is used to train AI attack agents and simulate dynamic IP switching and human-machine verification bypass automated script attacks. The blue team defense evolution unit is used to dynamically adjust the detection rule threshold to counter the bypass samples generated by the red team, forming a closed loop of attack and defense game.

6. The user behavior analysis method of the application software user behavior analysis system based on artificial intelligence as described in any one of claims 1 to 5, characterized in that, Includes the following steps: S1. Behavioral Gene Coding Generation and Map Update: Input the timestamps, paths, and contextual features of user click, login, and payment operation sequence data, and process the operation sequences... ,in, For the first The feature vector of the second operation is used to generate behavioral gene encoding through a multi-head self-attention mechanism, as shown in equation (1): (1); In the formula, Q, K, and V are the query, key, and value matrices, The scaling factor is used to determine the dimensionality, and the output is a time-series feature. The user behavior association graph is updated using an incremental graph embedding algorithm, as shown in equation (2): (2); In the formula, For nodes In the Layer embedding, For neighboring nodes, AGGREGATE is the aggregation function that outputs the dynamic behavior gene encoding. and the updated user behavior graph; S2. Multimodal Detection of Covert Fraudulent Behaviors: Input the behavior code Z, IP and IMEI device fingerprints, transaction amount and frequency data generated by S1, perform spatiotemporal graph modeling, and construct the spatiotemporal graph. Node V represents a user / device, edge E represents a transaction or behavior association, and A is the adjacency matrix. Abnormal transactions are detected by spatiotemporal graph convolution, as shown in equation (3): (3); In the formula, For a self-loop ordered matrix, For degree matrix, For the first Layer node feature output fraud probability score Mark high-risk transactions; S3. Behavioral entropy change baseline modeling and alarm: Input the click randomness and session interval interaction entropy characteristics of the user's historical behavior sequence, and use a Gaussian mixture model to fit the historical entropy value distribution, as shown in equation (4): (4); In the formula, The mixing coefficient, For the first The mean and covariance of a Gaussian distribution are used to calculate the entropy value of the current behavior in real time. See equation (5): (5); The entropy abrupt change is detected by KL divergence, as shown in equation (6): (6); In the formula, Given the current entropy distribution, For baseline distribution, The alarm outputs entropy change alarm signals and abnormal behavior types are triggered at any time. S4. Cross-module data collaboration and dynamic updates: Input behavior code Z from S1, fraud score from S2. Entropy change alarm signal, for multi-service line characteristics Perform heterogeneous alignment, see equation (7); (7); In the formula, W is the mapping matrix, m is the number of samples, and differential privacy encryption is used to update the global model parameters. See equation (8): (8); In the formula, For the first One local model parameter, The updated global detection model and cross-business line feature mapping are output for noise intensity.

Citation Information

Patent Citations

  • DDoS attack real-time detection and traceability analysis method based on knowledge graph

    CN119728286A

  • Generalized behavior analytics framework for detecting and preventing different types of API security vulnerabilities

    US20240430282A1