High-risk operation identification method based on access behavior frequency
By building a chain response mapping structure and path truncation test for port access behavior, it is possible to identify silent but with core linkage functions in the system, which solves the problem of not being able to identify passively activated ports in the existing technology, and enhances the defense ability of the induce chain attack mode.
Patent Information
- Application Number
- CN202511095383.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-09-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When identifying high-risk operations, the prior art cannot effectively identify passive activation ports that are in a silent state but have the core linkage function of the system, and cannot perceive the inducing chain attack pattern, resulting in a decrease in recognition of recognition capabilities.
By building a chain response mapping structure for port access behavior, combining path truncation testing and structural independence indicator calculation, latent high-risk ports are identified.
Effectively identifying high-risk ports in silent states enhances the risk linkage modeling ability of chain-induced attack mode and breaks through the limitations of traditional frequency-driven recognition mode.
Smart Images

Figure CN120602235A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of port behavior chain analysis, and more specifically, to a method for identifying high-risk operations based on access behavior frequency. Background Art
[0002] In current high-risk operation identification systems, deep learning technology is widely used for port-level risk monitoring. These algorithms typically rely on explicit features such as port access frequency, communication protocol type, and contextual behavior sequences. Through large-scale sample training, they form port risk profiles and use them to classify potential threats or identify anomalies. In typical scenarios, frequently accessed ports are more likely to be identified as sensitive nodes by the system, triggering further analysis and alerts. However, in real-world attack environments, threat actors have gradually abandoned the method of directly initiating high-frequency access to target ports and instead adopted more covert manipulation methods. A distributed induction chain structure is constructed. First, it frequently accesses edge ports with low permissions and often considered safe in multiple systems. It then uses the task forwarding logic, policy response process, or operation and maintenance scheduling mechanism between system services to indirectly activate core ports with functional associations. Although these passively triggered ports are functionally critical in the system, their access behavior does not originate from direct operations by the attacker, so they often remain silent in frequency, resulting in the system's perception model being unable to identify them as high-risk targets. More seriously, during the training of deep learning models, these silent ports, lacking obvious risk behavior characteristics, are likely to be mistakenly classified as low-risk samples, leading to risk label contamination during model training. As the model is iteratively optimized, the risk weights of these ports, which should have been the focus, are continuously weakened, resulting in a structural decline in the system's overall recognition capability. Furthermore, existing behavioral modeling methods are mostly limited to windowed sequence analysis or context-based association modeling based on short-term dependencies. They lack the ability to deeply explore the logical linkages within the operational chain, making it difficult to reconstruct the causal path from edge access to core port activation. In summary, the system's mechanism for assessing port risk has fundamental structural flaws. As attack methods evolve toward logical manipulation and chain-based induction, the security of a port is no longer determined by its access behavior itself, but rather by its linkage and response role within the system's behavioral chain. Existing systems are unable to perceive this paradox—functionally at the core and behaviorally silent—and ultimately fail to identify the risks of potentially high-risk ports. In summary, the current risk monitoring mechanism for port frequency and behavior identification faces a problem that is easily amplified. That is, the system lacks the ability to identify passively activated ports and cannot deduce potential logical risks from the access chain structure, thereby losing effective defense against induced chain attack modes as a whole. Summary of the Invention
[0003] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a high-risk operation identification method based on the frequency of access behavior. By constructing a chain response mapping structure of port access behavior and combining path truncation test with structural independence index calculation, latent high-risk ports that are in a silent state but have system core linkage functions are identified to solve the problem of "passive activation ports are difficult to identify and lack of perception of induced chain attack paths" raised in the above-mentioned background technology.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for identifying high-risk operations based on access behavior frequency, comprising: S1. In the target system, record the starting port, response port, trigger time, and execution order of the access request, and build an access behavior chain according to the access conduction path; S2. Count the access frequency of each port within a preset time window, set an interval consisting of an upper limit and a lower limit of the access frequency, and define the ports whose access frequency falls within the interval as the target analysis port set; ports whose access frequency is higher than the upper limit or lower than the lower limit are retained only if they are identified as belonging to the chain response mapping relationship set; S3. Taking each port in the target analysis port set as the chain starting point, extract the access behavior chain activated by it within a unit time, and form a chain response mapping relationship set based on the response path between the terminal response port and the starting port of the access behavior chain; S4. For each chain in the chain response mapping relationship set, set the middle node as the truncation point, block the access instructions after the truncation point, re-execute the access operation of the chain starting port, and collect the result status of whether the terminal response port is activated by the system scheduling; S5. For the terminal response ports that are still activated after the truncation test in S4, the total number of response paths, the number of redundant paths, and the number of passive activations in all chain response mapping relationship sets are counted as the path feature set, and the structural independence index value is calculated based on the path feature set.
[0005] In a preferred embodiment, in S1, each chain structure of the access behavior chain includes an upstream trigger port, a downstream response port, and a logical sequence relationship between the two; In S3, each chain response mapping relationship in the chain response mapping relationship set includes a start port, a path structure, and a terminal response port; In S5, the structural independence index value is used to measure the path dependence strength and independent activation capability of the terminal response port in the system access chain.
[0006] In a preferred embodiment, it also includes S6: defining the terminal response port whose structural independence index value is greater than the preset index threshold as a latent high-risk port, generating a latent high-risk port list, and updating the corresponding access control level, security response level and policy configuration parameters for each port in the latent high-risk port list.
[0007] In a preferred embodiment, in S6, for the terminal response port identified as a latent high-risk port, an activation intervention model is constructed based on its policy level fluctuation, access behavior change trend, and structural response strength; the activation intervention model includes a policy response oscillation function, a reset condition, a policy priority reset function, and a policy update; By calculating the value of the policy response oscillation function of the port and comparing it with the corresponding preset threshold, it is determined whether the reset condition is met. When the reset condition is met, the policy priority reset function is executed to output the updated access control level, security response level and policy configuration parameters; The strategy response oscillation function is expressed as: ; The homing condition is expressed as: ; The policy priority return function is expressed as: ; ; ; ; Build strategy update output: ; in is the port number; time represents the time variable in the continuous risk control cycle; Represents the total number of discrete time steps in the entire risk control cycle; 、 Respectively represent the start time and end time of the current risk control cycle; No. The value of the policy response oscillation function of each port; Indicates time Moment, The policy level function value corresponding to each port; Indicates time Moment, The policy fluctuation slope correction coefficient of each port; Indicates time Moment, The strategic acceleration correction factor of each port; in Relative to the preset threshold value; is the policy priority return function value; is the port access behavior change rate; No. ports at a time Frequency of visits when To record the intensity of strategic intervention; For the The number of times the policy of a port is adjusted in the current cycle; To respond to the structural fluctuation intensity; For the The activation standard deviation of each port in the chain response path; Indicates the The normalized average frequency of activation of a port in all chain response paths; Indicates the Output results of access control level of each port; Indicates the Output results of security response levels of each port; Indicates the A set of policy configuration parameters corresponding to each port; Indicates that The calculation results are assigned to multiple parameter items in the brackets in sequence to form the updated configuration output.
[0008] In a preferred embodiment, S3 also includes: in the target analysis port set, a unit time window is set for each target analysis port, and the access request chain triggered by it within the time window is recorded. The access request chain is triggered by the target analysis port as the starting port, and is transmitted layer by layer along the scheduling logic preset within the system until the last port in the access request chain that is scheduled to perform a response operation is used as the terminal response port. The system structurally marks each access node and its corresponding request relationship in the access request chain according to the actual call sequence and the associated scheduling event, thereby completing the extraction of the access behavior chain; Based on the extracted access behavior chains, the system establishes a path mapping relationship between the starting port and the terminal response port in each chain, and defines the port conduction path corresponding to the access behavior chain as a chain response path. The node sequence, interaction mode, and response event contained in the chain response path are used as path elements in the chain response mapping structure. The mapping structures corresponding to all chain response paths with continuous paths between the starting ports and the terminal response ports, complete node scheduling logic and no undefined interrupt nodes are unified and collected to construct a chain response mapping relationship set.
[0009] In a preferred embodiment, the total number of response paths is described in S5 by constructing a path coverage function: ; The number of redundant paths is characterized by the path redundancy deviation function: ; The response fluctuation function is constructed to quantify the change amplitude and fluctuation trend of the number of passive activations in the time series: ; Calculate the structural independence index value: ; in Indicates the current number is The terminal response port; Indicates the total number of chains in the chain response mapping relationship; chain Indicates the The set of ports included in a chain response path; the chain Indicates the The set of ports included in the chained response path; Indicates that the port Appears in the chain The value is 1 when it is in the middle, otherwise it is 0; Indicates port The total number of response paths involved; Indicates chain The total number of port nodes in Indicates chain The total number of port nodes; Indicates chain With chain The number of public port nodes; Indicates port Path redundancy bias reflected in all chains; Indicates port The total number of passive activation records; Indicates the In the passive activation event, the port Response delay time; Indicates port The cumulative value of response fluctuation; Indicates port The structural independence index value of .
[0010] Technical effects and advantages of the present invention: 1. This solution effectively addresses the structural flaws of the existing high-risk operation identification mechanism in identifying silent passive ports. By constructing a chain response mapping relationship set and a truncation test mechanism, it reveals the response role of the port in the logical control chain, enabling the system to identify latent high-risk ports that have long been hidden outside the traditional frequency model due to indirect access.
[0011] 2. This solution transforms port behavior from isolated access events into a response structure with logical continuity by constructing a chain of access behavior and path mapping relationships. This enables causal path restoration from edge access to core triggering, enhancing the system's ability to model risk linkage relationships under chain-induced attack patterns.
[0012] 3. By introducing a structural independence index value, the influence and independence of ports in the system response structure are quantified through a comprehensive evaluation of the total number of paths, the number of redundant paths, and passive activation behavior, breaking through the limitation of the traditional frequency-driven recognition model that relies heavily on behavioral sample labels.
[0013] 4. Adopt the truncation test strategy to intervene in the intermediate nodes of the chain response path, reconstruct the chain response state, and then identify the independent response capability of the port without direct upstream activation, so that the system can distinguish the abnormal behavior path that depends on the link structure activation. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 The figure is a flow chart of the method steps of the present invention. DETAILED DESCRIPTION
[0015] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0016] Refer to the instruction manual Figure 1 According to an embodiment of the present invention, a method for identifying high-risk operations based on access behavior frequency includes: S1. Build an access behavior chain: In the target system, the starting port, response port, trigger time, and execution order of the access request are recorded, and the access behavior chain is constructed according to the access conduction path; S2. Filter the port set whose behavior frequency is within the determinable range: The access frequency of each port within a preset time window is counted. An interval consisting of an upper and lower access frequency limit is set, and ports with access frequencies within this interval are defined as the target analysis port set. Ports with access frequencies above the upper or lower access frequency limit are retained only if they are identified as belonging to the chain response mapping relationship set. The reason for retaining them only if they are identified as belonging to the chain response mapping relationship set is that ports with excessively high or low access frequencies may represent abnormal behavior or irrelevant noise in most cases, and their direct participation in subsequent analysis will lead to misjudgment or waste of resources. However, if these ports have structural participation in the chain response path constructed by the system, that is, they are connected by link trigger relationships as starting or ending response nodes, it means that they still have actual linkage in the access behavior chain and may carry the transmission risk of the critical path. Therefore, the system needs to perform structural judgment on them. Only when they are structurally related are they retained, ensuring that subsequent analysis focuses on key ports with both abnormal behavior characteristics and structural influence. S3. Generate a chain response mapping relationship set for the target analysis port: Taking each port in the target analysis port set as the chain starting point, extract the access behavior chain activated in unit time, and form a chain response mapping relationship set with the response path between the terminal response port and the starting port of the access behavior chain; S4. Perform a truncation test on the chain structure and collect response changes: For each chain in the chain response mapping relationship set, an intermediate node is set as a truncation point, access instructions after the truncation point are blocked, and access operations on the chain's starting port are re-executed to collect the result status of whether the terminal response port is activated by the system scheduling. It should be noted that S4 actively intervenes in the chain response path to detect the true dependency relationship between ports. During the specific execution process, each chain path in the chain response mapping relationship set can be tested one by one through the system. First, an intermediate node in the path is selected as the truncation point, and then the node and all subsequent access instructions are manually blocked to artificially construct an interrupt response chain. The system then reactivates the starting port of the chain to observe whether the terminal response port is still activated by the system scheduling under the interruption condition. If the terminal response port is still activated under the condition of losing some path support, it means that its scheduling may have multi-path triggering or redundant dependence, and is not completely dependent on the truncated path. Otherwise, it indicates that the path has strong structural constraints. The essence of the S4 operation is to construct a controlled intervention scenario to verify the strong response coupling relationship between the nodes in the link, providing a structural independence basis for the subsequent identification of critical ports with latent high-risk characteristics. S5. Calculate the structural independence index of the terminal response port: For the terminal response ports that are still activated after the truncation test in S4, the total number of response paths, the number of redundant paths, and the number of passive activations in all chain response mapping relationship sets are counted as the path feature set, and the structural independence index value is calculated based on the path feature set.
[0017] In S1, each chain structure of the access behavior chain includes an upstream trigger port, a downstream response port, and a logical sequence relationship between the two; In S3, each chain response mapping relationship in the chain response mapping relationship set includes a start port, a path structure, and a terminal response port; In S5, the structural independence index value is used to measure the path dependence strength and independent activation capability of the terminal response port in the system access chain.
[0018] Also included: S6, identifying latent high-risk ports and updating risk control policy parameter sets: The terminal response port whose structural independence index value is greater than the preset index threshold is defined as a latent high-risk port, a latent high-risk port list is generated, and the corresponding access control level, security response level and policy configuration parameters of each port in the latent high-risk port list are updated.
[0019] It should be noted that in the formula structure involved in this solution, dimensionless terms can serve as proportionality or structural adjustment factors. When combined with quantities with units, they only play a numerical scaling role and do not introduce new physical dimensions. Therefore, they will not change or confuse the overall unit system of expression. This combination of "dimensionless terms and units" can be understood as a composite structural expression commonly used in mathematical and physical modeling, conforming to the principle of dimensional consistency and having a clear physical interpretation basis. Secondly, in the formula structure of this scheme, if multiple variables with different physical units are involved, including but not limited to time, mass or energy variables, their joint appearance is to express the collaborative modeling relationship of multiple physical mechanisms. Each variable can be formed into a unified structure through function mapping, ratio combination or normalization adjustment. The units and meanings are clear, and the overall expression conforms to the principle of dimensional consistency and the common formula of engineering modeling. Any constants, weights, adjustment factors, threshold parameters, and proportional coefficients involved in this solution are all adjustable control parameters for different application environments. Their values depend on the target device configuration, data input characteristics, and performance optimization goals. During the implementation phase, they are set within a reasonable range through model verification, performance constraints, or engineering calibration. Although these parameters do not have preset unique values, they have clear adjustment logic and calculation paths and are part of the deterministic setting process in engineering implementation. The purpose of such setting is to ensure that the solution is both universally adaptable, reproducible, and operable, without affecting its technical clarity and feasibility. In S6, for terminal response ports identified as latent high-risk ports, an activation intervention model is constructed based on their policy level fluctuations, access behavior change trends, and structural response strength. The activation intervention model includes a policy response oscillation function, resetting conditions, a policy priority resetting function, and policy updates. By calculating the value of the policy response oscillation function of the port and comparing it with the corresponding preset threshold, it is determined whether the reset condition is met. When the reset condition is met, the policy priority reset function is executed to output the updated access control level, security response level and policy configuration parameters; The strategy response oscillation function is expressed as: ; The homing condition is expressed as: ; The policy priority return function is expressed as: ; ; ; ; Build strategy update output: ; in is the port number, indicating the Terminal response ports identified as latent high-risk ports; time represents the time variable in the continuous risk control cycle; Represents the total number of discrete time steps in the entire risk control cycle; 、 Respectively represent the start time and end time of the current risk control cycle; No. The value of the strategy response oscillation function of each port is used to quantify the dynamic fluctuation intensity of its strategy level; Indicates time Moment, The policy level function value corresponding to each port. The policy level function is used to represent the comprehensive policy status strength of a port at a certain moment. It is constructed by weighted combination of the access control level and security response level corresponding to the port at that moment. The access control level reflects the access control strength granted to the port in the current system policy, including full permission, conditional permission or restricted access. The security response level represents the security processing strength set by the system after detecting that the port is activated, such as whether interception, isolation, alarm or audit needs to be triggered. The system will output the access level value and security response level value corresponding to the port at each moment. The two are added after unified coding processing to form a continuously changing policy level numerical curve, which is used to describe the fluctuation of the policy strength of the port throughout the risk control cycle and serve as the basic quantity for subsequent oscillation amplitude calculation and policy return judgment. In addition, the policy level fluctuation is characterized by the change trend and strength of the policy level function over time. The two constitute a unified description of policy status changes. Indicates time Moment, The policy fluctuation slope correction coefficient of each port indicates the degree of system response to the policy change rate. The value of the policy fluctuation slope correction coefficient includes the sensitivity setting based on the system to the policy level change rate. It can be normalized and calculated based on the historical false alarm rate, intervention effectiveness, or system stability feedback after the policy change. The larger the value, the more sensitive the system is to changes in the strategy level. Smaller changes will amplify its impact in the oscillation function. The smaller the value, the more the system allows the strategy level to fluctuate within a certain range without triggering excessive response; Indicates time Moment, The policy acceleration correction coefficient for each port is used to reflect the impact of the severity of policy level changes on the system. In addition, the value of the policy acceleration correction coefficient is set according to the system's tolerance for the severity of policy level changes, including normalization adjustment based on indicators such as resource consumption after policy jumps, chain triggering, and risk management pressure. The larger the policy acceleration correction coefficient, the more sensitive the system is to drastic changes. Even if a sudden change occurs in a short period of time, its impact on oscillation will be significantly amplified. The smaller the policy acceleration correction coefficient, the higher the system's tolerance for rapid policy jumps and the relatively stable response. in Relative to The preset threshold, if , then the port policy status is considered to be stable; The policy priority resetting function value is used as the basis for calculating the final update result of the port policy level. is the port access behavior change rate, which indicates the change trend of the port access frequency; No. ports at a time Frequency of visits when Policy intervention intensity record, which indicates the degree of system or manual intervention on the port policy in the current cycle; For the The number of times the policy of a port has been adjusted in the current cycle, including automatic and manual intervention; represents the natural logarithm function; The response structure fluctuation intensity is used to represent the behavioral instability of the port in the chain response structure; For the The activation standard deviation of a port in the chain response path is used to measure the behavioral fluctuation range of its participation path; Indicates the The normalized average activation frequency of a port in all chain response paths is used to represent its structural participation baseline frequency; Indicates the Output results of access control level of each port; Indicates the Output results of security response levels of each port; Indicates the The policy configuration parameter set corresponding to each port, including but not limited to rate limit rules, trigger conditions, isolation levels, etc. Indicates that The calculation results are assigned to multiple parameter items in the left brackets in sequence to form the updated configuration output.
[0020] S3 also includes: in the target analysis port set, for each target analysis port, setting a unit time window, recording the access request chain triggered by it within the time window, wherein the access request chain is triggered by the target analysis port as the starting port, and is transmitted layer by layer along the scheduling logic preset within the system until the last port in the access request chain that is scheduled to perform a response operation is used as the terminal response port. The system structurally marks each access node and its corresponding request relationship in the access request chain according to the actual call sequence and the associated scheduling event, thereby completing the extraction of the access behavior chain; Based on the extracted access behavior chains, the system establishes a path mapping relationship between the starting port and the terminal response port in each chain, and defines the port conduction path corresponding to the access behavior chain as a chain response path. The node sequence, interaction mode, and response event contained in the chain response path are used as path elements in the chain response mapping structure. The mapping structures corresponding to all chain response paths with continuous paths between the starting ports and the terminal response ports, complete node scheduling logic, and no undefined interruption nodes are unified and collected to construct a chain response mapping relationship set, which serves as the basic data structure for subsequent structural fluctuation analysis and strategy determination.
[0021] In S5, the total number of response paths is described by constructing a path coverage function: ; The path redundancy deviation function is used to characterize the structural complexity and overlap distribution differences implied by the number of redundant paths: ; The response fluctuation function is constructed to quantify the change amplitude and fluctuation trend of the number of passive activations in the time series: ; Calculate the structural independence index value: ; in Indicates the current number is The terminal response port; Indicates the total number of chains in the chain response mapping relationship; chain Indicates the The set of ports included in a chain response path; the chain Indicates the A set of ports included in a chain response path; and Respectively represent ports The two different chain response paths associated; Indicates that the port Appears in the chain The value is 1 when it is in the middle, otherwise it is 0; Indicates port The total number of response paths involved, that is, the number of path coverage; Indicates chain The total number of port nodes in Indicates chain The total number of port nodes; Indicates chain With chain The number of public port nodes; Indicates port The path redundancy deviation reflected in all chains refers to the structural complexity and overlap distribution differences implied by the number of redundant paths, rather than just the number of paths. Used to measure its redundant structure participation; Indicates port The total number of passive activation records; Indicates the In the passive activation event, the port Response delay time; Indicates the In the passive activation event, the port Response delay time; In the structural response fluctuation function, introduce This is to amplify the effects of activation changes in later scheduling cycles and enhance sensitivity to time delay fluctuations; Indicates port The cumulative value of response fluctuation is used to measure the instability of its activation behavior in the time dimension; Indicates port The larger the structural independence index value, the more likely the port is to exist in multiple response paths in an independent or redundant form, which poses a potential risk.
[0022] It should be noted that this solution takes the dynamic identification of latent high-risk ports as its core goal, focusing on the construction of access behavior chains, the extraction of response path structures, the evaluation of structural features, and the updating of policy parameters. The overall logic of this solution begins by extracting the access behavior of each port in the system within a preset time window, forming an access behavior chain consisting of the starting port, path structure, and terminal response port. Then, based on the upper and lower limits of the access frequency, a frequency screening interval is constructed, and the ports within the interval are set as the target analysis port set. To avoid missing potential risk ports, the chain response relationship of ports outside the interval is verified and only those that are confirmed to be part of the chain response mapping structure are retained. When entering the response path analysis phase, starting with the target analysis port, a unit time window is set to extract the access request chain triggered by the system scheduling logic, and the access nodes and request relationships are structurally marked to extract the access behavior chain. Through the path conduction process between the starting port and the terminal response port in the behavior chain, a chain response path is established, and the path structures that meet the structural closure conditions are summarized to form a chain response mapping relationship set. Structural closure means that the path starts from the starting port and can be completely transmitted to the response terminal through the system's effective scheduling logic without repeated loops or invalid branches. Based on the chain response structure, a truncation test is performed on each chain structure. The intermediate node is selected to block the subsequent access instructions, and the starting port operation is re-executed to confirm whether the terminal response port is still activated, thereby determining its structural dependency. If the terminal response port is still scheduled by the system after truncation, it indicates that its activation has a certain degree of independence or structural redundancy. The system further counts the total number of paths appearing in the response path structure, the number of redundant paths, and the number of passive activations to form a path feature set, and calculates the structural independence index based on this. Finally, ports with structural independence index values greater than the preset threshold are identified as latent high-risk ports, forming a list of high-risk ports, and an activation intervention model is constructed for each port in the list; in the intervention model, the system comprehensively evaluates the dynamic risk performance of each port based on the fluctuation trend, fluctuation slope and fluctuation acceleration of the policy level function, as well as the changes in the response behavior intensity and historical policy intervention records, and updates its access control level, security response level and policy parameters accordingly.
[0023] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for identifying high-risk operations based on access behavior frequency, characterized in that: include: S1. In the target system, record the starting port, response port, trigger time, and execution order of the access request, and build an access behavior chain according to the access conduction path; S2. Count the access frequency of each port within a preset time window, set an interval consisting of an upper limit and a lower limit of the access frequency, and define the ports whose access frequency falls within the interval as the target analysis port set; ports whose access frequency is higher than the upper limit or lower than the lower limit are retained only if they are identified as belonging to the chain response mapping relationship set; S3. Taking each port in the target analysis port set as the chain starting point, extract the access behavior chain activated by it within a unit time, and form a chain response mapping relationship set based on the response path between the terminal response port and the starting port of the access behavior chain; S4. For each chain in the chain response mapping relationship set, set the middle node as the truncation point, block the access instructions after the truncation point, re-execute the access operation of the chain starting port, and collect the result status of whether the terminal response port is activated by the system scheduling; S5. For the terminal response ports that are still activated after the truncation test in S4, the total number of response paths, the number of redundant paths, and the number of passive activations in all chain response mapping relationship sets are counted as the path feature set, and the structural independence index value is calculated based on the path feature set.
2. The method for identifying high-risk operations based on access behavior frequency according to claim 1, characterized in that: In S1, each chain structure of the access behavior chain includes an upstream trigger port, a downstream response port, and a logical sequence relationship between the two; In S3, each chain response mapping relationship in the chain response mapping relationship set includes a start port, a path structure, and a terminal response port; In S5, the structural independence index value is used to measure the path dependence strength and independent activation capability of the terminal response port in the system access chain.
3. The method for identifying high-risk operations based on access behavior frequency according to claim 2, characterized in that: It also includes S6: defining the terminal response port whose structural independence index value is greater than the preset index threshold as a latent high-risk port, generating a latent high-risk port list, and updating the corresponding access control level, security response level and policy configuration parameters for each port in the latent high-risk port list.
4. The method for identifying high-risk operations based on access behavior frequency according to claim 3, characterized in that: In S6, for terminal response ports identified as latent high-risk ports, an activation intervention model is constructed based on their policy level fluctuations, access behavior change trends, and structural response strength. The activation intervention model includes a policy response oscillation function, resetting conditions, a policy priority resetting function, and policy updates. By calculating the value of the policy response oscillation function of the port and comparing it with the corresponding preset threshold, it is determined whether the reset condition is met. When the reset condition is met, the policy priority reset function is executed to output the updated access control level, security response level and policy configuration parameters; The strategy response oscillation function is expressed as: ; The homing condition is expressed as: ; The policy priority return function is expressed as: ; ; ; ; Build strategy update output: ; in is the port number; time represents the time variable in the continuous risk control cycle; Represents the total number of discrete time steps in the entire risk control cycle; 、 Respectively represent the start time and end time of the current risk control cycle; No. The value of the policy response oscillation function of each port; Indicates time Moment, The policy level function value corresponding to each port; Indicates time Moment, The policy fluctuation slope correction coefficient of each port; Indicates time Moment, The strategic acceleration correction factor of each port; in Relative to the preset threshold value; is the policy priority return function value; is the port access behavior change rate; No. ports at a time Frequency of visits when To record the intensity of strategic intervention; For the The number of times the policy of a port is adjusted in the current cycle; To respond to the structural fluctuation intensity; For the The activation standard deviation of each port in the chain response path; Indicates the The normalized average frequency of activation of a port in all chain response paths; Indicates the Output results of access control level of each port; Indicates the Output results of security response levels of each port; Indicates the A set of policy configuration parameters corresponding to each port; Indicates that The calculation results are assigned to multiple parameter items in the brackets in sequence to form the updated configuration output.
5. The method for identifying high-risk operations based on access behavior frequency according to claim 4, characterized in that: S3 also includes: in the target analysis port set, for each target analysis port, setting a unit time window, recording the access request chain triggered by it within the time window, wherein the access request chain is triggered by the target analysis port as the starting port, and is transmitted layer by layer along the scheduling logic preset within the system until the last port in the access request chain that is scheduled to perform a response operation is used as the terminal response port. The system structurally marks each access node and its corresponding request relationship in the access request chain according to the actual call sequence and the associated scheduling event, thereby completing the extraction of the access behavior chain; Based on the extracted access behavior chains, the system establishes a path mapping relationship between the starting port and the terminal response port in each chain, and defines the port conduction path corresponding to the access behavior chain as a chain response path. The node sequence, interaction mode, and response event contained in the chain response path are used as path elements in the chain response mapping structure. The mapping structures corresponding to all chain response paths with continuous paths between the starting ports and the terminal response ports, complete node scheduling logic and no undefined interrupt nodes are unified and collected to construct a chain response mapping relationship set.
6. The method for identifying high-risk operations based on access behavior frequency according to claim 5, characterized in that: In S5, the total number of response paths is described by constructing a path coverage function: ; The number of redundant paths is characterized by the path redundancy deviation function: ; The response fluctuation function is constructed to quantify the variation and fluctuation trend of the number of passive activations in the time series: ; Calculate the structural independence index value: ; in Indicates the current number is The terminal response port; Indicates the total number of chains in the chain response mapping relationship; chain Indicates the The set of ports included in a chain response path; the chain Indicates the The set of ports included in the chained response path; Indicates that the port Appears in the chain The value is 1 when it is in the middle, otherwise it is 0; Indicates port The total number of response paths involved; Indicates chain The total number of port nodes in Indicates chain The total number of port nodes; Indicates chain With chain The number of public port nodes; Indicates port Path redundancy bias reflected in all chains; Indicates port The total number of passive activation records; Indicates the In the passive activation event, the port Response delay time; Indicates port The cumulative value of response fluctuation; Indicates port The structural independence index value of .
Citation Information
Cited By
Access security protection method and system based on user behavior portrait
CN121396653A