Security risk monitoring method and device, equipment, storage medium and program product

By building a user relationship network based on user characteristics and location information and determining the security risk level, the problem of potential security risks for people within the network is solved, and effective monitoring and early warning of high-confidentiality parks are achieved.

CN120692149APending Publication Date: 2025-09-23CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410336234.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-21
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

Existing network security monitoring methods fail to promptly detect potential security risks posed by network insiders in the internal network, resulting in the inability to detect and prevent security risks within the legitimate area.

Method used

Based on the network business information and location information of multiple users in the park, user characteristics are determined, user relationship networks are built, communities are divided, and risk warnings are issued based on users' network business information and security risk levels.

Benefits of technology

It has achieved effective detection and early warning of user behavior in highly confidential campuses, and can timely discover and prevent potential internal security risks and prevent the spread of risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692149A_ABST
    Figure CN120692149A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a security risk monitoring method and device, equipment, a storage medium and a program product, and the method comprises the steps: determining the user characteristics of each user based on the network service information and position information of each user in a plurality of users in a park; constructing a user relation network based on the user characteristics of each user; wherein the user relation network comprises a plurality of communities, and each community in the plurality of communities is composed of at least one user node and an edge formed between the at least one user node; determining a security risk level of each user based on the network service information of each user and the user relationship network; and carrying out risk early warning on the plurality of users in the park based on the security risk level of each user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a security risk monitoring method, apparatus, device, storage medium, and program product. Background Art

[0002] With the popularization and construction of 5G private networks, some high-security and confidential industries have higher requirements for network security. Firewalls and other measures can resist attacks from external networks, but there are greater network security risks within the network. The behavior of people inside the network may launch attacks from within the network intentionally or unintentionally. In addition, the network security monitoring methods in related technologies cannot detect potential security risks of internal personnel in a timely manner, resulting in internal personnel conducting business with security risks in legal areas. Summary of the Invention

[0003] To solve the above technical problems, the embodiments of the present application provide a security risk monitoring method, apparatus, device, storage medium and program product.

[0004] The security risk monitoring method provided in the embodiment of the present application includes:

[0005] Determining user characteristics of each user based on network service information and location information of each user among multiple users in the park;

[0006] Based on the user characteristics of each user, a user relationship network is constructed; wherein the user relationship network includes a plurality of communities, and each of the plurality of communities is composed of at least one user node and an edge formed between the at least one user node;

[0007] Determining a security risk level of each user based on the network service information of each user and the user relationship network;

[0008] Based on the security risk level of each user, risk warnings are issued to the multiple users in the park.

[0009] The security risk monitoring device provided in the embodiment of the present application includes:

[0010] A processing unit is configured to determine a user characteristic of each user among a plurality of users in the campus based on network service information and location information of the user; and construct a user relationship network based on the user characteristic of each user; wherein the user relationship network includes a plurality of communities, each of the plurality of communities being composed of at least one user node and an edge formed between the at least one user node;

[0011] a determining unit, configured to determine a security risk level of each user based on the network service information of each user and the user relationship network;

[0012] An early warning unit is used to issue risk warnings to the multiple users in the park based on the security risk level of each user.

[0013] The processing device provided in the embodiment of the present application includes: a processor and a memory, the memory is used to store computer programs, and the processor is used to call and run the computer program stored in the memory to execute any one of the security risk monitoring methods provided in the embodiment of the present application.

[0014] The computer-readable storage medium provided in the embodiments of the present application is used to store a computer program, and the computer program enables a computer to execute any one of the security risk monitoring methods provided in the embodiments of the present application.

[0015] An embodiment of the present application provides a computer program product, including computer program instructions, which enable a computer to execute any of the above-mentioned security risk monitoring methods.

[0016] In the technical solution of the embodiment of the present application, the user characteristics of each user are determined based on the network business information and location information of each user among multiple users in the park, and a user relationship network is constructed based on the user characteristics of each user, wherein the user relationship network includes multiple communities, and each community is composed of at least one user node and at least one edge formed between user nodes. Then, based on the network business information and user relationship network of each user, the security risk level of each user is determined, and thus based on the security risk level of each user, risk warnings are issued to multiple users in the park. In this way, community detection is performed on all network users in the high-confidentiality park in combination with the user's network business situation and location information, and a community network based on network business data and business location information can be constructed, so that the community division results are more reasonable and more in line with the characteristics of the high-confidentiality park. At the same time, combined with the security risk level of each user, abnormal behavior in the park can be detected more effectively, and users with security risks can be warned and controlled in advance. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A flowchart of a security risk monitoring method provided in an embodiment of the present application;

[0018] Figure 2 A schematic diagram of the module composition of the security risk monitoring solution provided in an embodiment of the present application;

[0019] Figure 3 A schematic diagram of the structure of a security risk monitoring device provided in an embodiment of the present application;

[0020] Figure 4 A schematic diagram of the structure of the processing equipment provided in an embodiment of the present application. DETAILED DESCRIPTION

[0021] The following will describe the technical solutions in the embodiments of this application in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0022] It should be noted that in the embodiments of the present application, the term "and / or" is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the embodiments of the present application, the character " / " generally indicates that the associated objects are in an "or" relationship.

[0023] In the description of the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship between indication and being indicated, configuration and being configured, etc.

[0024] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0025] With the popularization and construction of 5G private networks, some high-security and confidential industries have higher requirements for network security. Firewalls and other measures can resist attacks from external networks, but there are greater network security risks within the network. The behavior of people inside the network may launch attacks from within the network intentionally or unintentionally. At this time, it is very important to monitor and analyze the behavior of people within the network, detect possible network security incidents, and control them in a timely manner.

[0026] The network security monitoring methods in related technologies are divided into the following situations:

[0027] (1) Cybersecurity incidents and regulatory bodies are associated and matched through a comprehensive database. When a cybersecurity incident is detected, a work order is automatically sent to the regulatory body.

[0028] (2) Call the multi-step network attack prediction model to process the attack and defense strategy data of the target object and predict the network security events of the target object.

[0029] (3) Detect the characteristics of the user terminal's login behavior to determine whether the user terminal is allowed to log in, and detect the characteristics of the user's operation behavior and / or the characteristics of IT assets to determine whether an attack has occurred. If an attack has occurred, trace the source of the attack.

[0030] However, the above network security monitoring methods still have the following shortcomings:

[0031] (1) It mainly detects network security incidents that have already occurred. At the same time, network security incidents are usually caused by external attacks, and the detection and prevention are not combined with the behavior of internal personnel.

[0032] (2) Failure to consider that the park staff may engage in some seemingly normal behaviors that may actually cause unknown risks, such as conducting non-confidential activities in confidential areas, or making abnormal stops, resulting in the inability to detect risks in a timely manner.

[0033] (3) It is unable to prevent legitimate personnel from conducting business that poses security risks in legitimate areas.

[0034] To solve the above problems, this application proposes a technical solution for security risk monitoring, which controls and manages relevant network security incidents from the network side, fundamentally solves network security incidents, prevents their spread, and ensures the safety of the entire confidential park.

[0035] To facilitate understanding of the technical solutions of the embodiments of the present application, the technical solutions of the present application are described in detail below through specific embodiments. The above related technologies can be combined arbitrarily with the technical solutions of the embodiments of the present application as optional solutions, and all of them fall within the scope of protection of the embodiments of the present application. The embodiments of the present application include at least part of the following contents.

[0036] This application embodiment proposes a security risk monitoring method. Figure 1 This is a flow chart of the security risk monitoring method according to an embodiment of the present application. Figure 1 As shown, the method may include the following steps:

[0037] Step 101: Determine user characteristics of each user based on network service information and location information of each user among multiple users in the campus.

[0038] In some implementations, before implementing step 101, network information within the park and user information of each user may also be obtained, and the network information within the park and the user information of each user may be associated and merged to obtain network service information and location information of each user within the park.

[0039] In an embodiment of the present application, after obtaining all network information and user information of each user in the park, all information can be associated and merged based on information such as the user's mobile phone number, International Mobile Subscriber Identity (IMSI) number, etc., thereby obtaining all business behavior data of each user in the park and the location where the business behavior occurs.

[0040] Here, network information includes Session Initialization Protocol (SIP) call data, other network service call data, Measurement Report (MR) data, base station information data, etc. User information includes asset data, regional security level, user's mobile phone number, IMSI number, etc. Among them, user information is obtained by users within the park based on their own situation. The regional security level is based on the security level of each area within the park. The park can divide different areas into three levels: low, medium, and high according to their actual situation. SIP call data and other network service call data are obtained by Deep Packet Inspection (DPI) equipment connected to the core network of the park's confidential private network. MR data is obtained by reporting from user terminals to base stations. Base station information data is obtained through base stations deployed in the park.

[0041] In some embodiments, when implementing step 101, feature extraction can be performed on the network service information and location information of each user in the park based on feature engineering to obtain user features of each user. The feature engineering method used and the number of feature engineering operations used are not limited herein.

[0042] Here, the user characteristics of each user include business characteristics, location characteristics and relationship characteristics; the business characteristics of each user refer to the network business characteristics of the user, which can reflect the main business situation of the user in the park; the location characteristics of each user refer to the location characteristics of the user when conducting network business, which can reflect the location where the user often stays in the park; the relationship characteristics of each user refer to the business relationship characteristics between the user and other users, including voice call relationships, network business relationships and location relationships where they stay at the same time.

[0043] It should be noted that MR data can be used to find the user's specific latitude and longitude information. If this information is not available, the user's specific location can be obtained based on the information of the base stations in the park and the base station three-point positioning method.

[0044] Step 102: Build a user relationship network based on the user characteristics of each user.

[0045] The user relationship network includes multiple communities, and each of the multiple communities is composed of at least one user node and at least one edge formed between the user nodes.

[0046] In the embodiment of the present application, the voice and network business communication behaviors of users in the park are the reflection of the social behaviors of users in the real society in the network, and there is a close correlation between the two behaviors. Therefore, the communication network of user voice and network business can be regarded as a social network, that is, a user relationship network can be constructed based on the user characteristics of each user, and because there are associations between users, several communities can be logically constituted, that is, the user relationship network actually includes multiple communities, and each community is composed of at least one user node and at least one edge formed between user nodes. Moreover, since the community is a cluster structure, the connection between user nodes within the community is closer, and the connection between communities is relatively sparse. In the real world, community structures usually exist in an overlapping manner, that is, there are overlapping areas between communities, and a user node may belong to multiple communities at the same time.

[0047] In some implementations, step 102 may be implemented through steps s1-s2, specifically including:

[0048] Step s1: Based on the relationship characteristics of each user, each user is divided into communities to obtain the community division results of each user;

[0049] Step s2: Based on the community division results of each user, a user relationship network is constructed.

[0050] In the embodiments of the present application, each user can be divided into communities using a community detection algorithm based on the relationship features in each user's user profile, thereby obtaining a community division result for each user. A user relationship network can then be constructed based on the community division results for each user. Community detection algorithms include, but are not limited to, overlapping community detection algorithms based on adjacency matrices and overlapping community detection algorithms based on streaming edge analysis.

[0051] In some embodiments, when implementing step s1, it can be implemented through steps ss1-ss5, specifically including:

[0052] Step ss1: Based on the relationship features of each user, an undirected relationship graph between multiple users is constructed.

[0053] The undirected relationship graph is composed of at least one user node and at least one edge formed between the user nodes;

[0054] Step ss2: Based on the undirected relationship graph, construct the adjacency matrix of the undirected relationship graph.

[0055] Among them, each element in the adjacency matrix represents the similarity between two user nodes.

[0056] Step ss3: Perform spectral clustering on the adjacency matrix to obtain the first partitioning result for each user.

[0057] In an embodiment of the present application, after constructing an undirected relationship graph between multiple users based on the relationship features of each user, and constructing an adjacency matrix of the undirected relationship graph based on the undirected relationship graph, since each element in the adjacency matrix represents the similarity between two user nodes, spectral clustering can be performed on the adjacency matrix based on the similarity between the user nodes, thereby dividing the user nodes and obtaining a first division result for each user.

[0058] Here, spectral clustering is a graph theory clustering method. It divides a weighted undirected graph into two or more optimal subgraphs. The purpose is to make the subgraphs as similar as possible and the distances between subgraphs as far as possible. Its basic idea is to use the similarity matrix (Laplacian matrix) of the sample data to perform eigendecomposition, and then perform clustering based on the eigenvectors obtained after the decomposition.

[0059] Step ss4: Perform streaming edge analysis on the undirected relationship graph to obtain the second partitioning result for each user.

[0060] In an embodiment of the present application, the degree information (degree) of a user node in an undirected relationship graph can measure the closeness between the user node and its community, and the number of edges within a community is much greater than the number of edges between communities. Therefore, based on the assumption that the probability of any edge in the undirected relationship graph being an edge within a community is much greater than the probability of being an edge between communities, a streaming edge analysis can be performed on each edge in the undirected relationship graph to obtain the second partitioning result for each user.

[0061] Step ss5: Based on the first division result of each user and the second division result of each user, a community division result of each user is obtained.

[0062] In an embodiment of the present application, after obtaining the first and second division results for each user, due to the complexity of the business interaction network of campus users, the first and second division results can be cross-validated to finally obtain the community division result for each user.

[0063] In some embodiments, when implementing step ss3, it can be implemented through steps w1-w4, specifically including:

[0064] Step w1: Regularize the adjacency matrix to obtain the Laplace matrix.

[0065] Step w2: Perform spectral decomposition on the Laplace matrix to obtain multiple eigenvalues ​​and eigenvectors corresponding to the multiple eigenvalues.

[0066] Among them, each eigenvalue and the eigenvector corresponding to each eigenvalue respectively represent the similarity between a user node and other user nodes and the community where the user node is located.

[0067] Step w3: Arrange multiple eigenvalues ​​in ascending order, and select the eigenvectors corresponding to the first k eigenvalues, where k is a positive integer.

[0068] Step w4: Cluster the eigenvectors corresponding to the first k eigenvalues, and divide the user nodes with similarity greater than the similarity threshold into the same community to obtain the first division result for each user.

[0069] In an embodiment of the present application, in the process of implementing spectral clustering of the adjacency matrix, the adjacency matrix is ​​first regularized to obtain a Laplace matrix, and then the Laplace matrix is ​​spectrally decomposed (eigendecomposition) to obtain multiple eigenvalues ​​and eigenvectors corresponding to the multiple eigenvalues, wherein each eigenvalue and the eigenvector corresponding to each eigenvalue respectively represent the similarity between a user node and other user nodes and the community where the user node is located. Then, these multiple eigenvalues ​​are arranged in ascending order, and the eigenvectors corresponding to the first k eigenvalues ​​are selected. The K-means algorithm or other clustering algorithm is used to cluster the eigenvectors corresponding to these k eigenvalues, and user nodes with similarity greater than the similarity threshold are divided into the same community, thereby completing the community division of all user nodes and obtaining the first division result for each user.

[0070] In some embodiments, when implementing step ss4, it can be implemented through steps k1-k4, specifically including:

[0071] Step k1: Based on the degree of each user node in the undirected relationship graph, determine the number of neighboring user nodes of each user node.

[0072] The neighbor user nodes of each user node are user nodes that share an edge with the user node.

[0073] Step k2: Based on the community where each user node is located and the number of neighboring user nodes of each user node, determine the number of neighboring user nodes in the community where each user node is located.

[0074] Step k3: Based on the number of neighboring user nodes of each user node and the number of neighboring user nodes in the community where each user node is located, determine the contribution of each user node to the community where it is located.

[0075] Step k4: Based on the degree of each user node and the contribution of each user node to the community, each user node is divided into communities to obtain a second division result for each user.

[0076] In some embodiments, when implementing step k4, it can be implemented through steps kk1-kk2, specifically including:

[0077] Step kk1: For each edge in the undirected relationship graph, select an edge in order and get the degree of the user nodes at both ends of the edge;

[0078] Step kk2: Based on the degrees of the user nodes at both ends of the edge and the contributions of the user nodes at both ends of the edge to their respective communities, the user nodes at both ends of the edge are divided into communities to obtain the division results of the user nodes at both ends of the edge; wherein the number of edges within a community is greater than the number of edges between communities.

[0079] In some embodiments, when implementing step ss5, it can be implemented through steps t1-t3, specifically including:

[0080] Step t1: Take the intersection of the first division result of each user and the second division result of each user to obtain the intersection result of each user.

[0081] Step t2: Take the union of the first division result of each user and the second division result of each user to obtain the union result of each user.

[0082] Step t3: Based on the intersection result of each user and the union result of each user, the community division result of each user is obtained.

[0083] In an embodiment of the present application, after the overlapping community detection algorithm based on the adjacency matrix and the overlapping community detection algorithm based on the streaming edge analysis obtain the first partitioning result and the second partitioning result of each user, it is necessary to calculate the cross-validation metric, that is, calculate the intersection and union of the two partitioning results. After the cross-validation metric is calculated, the size of the cross-validation intersection and union is used to determine the community affiliation of each user node.

[0084] In some embodiments, when implementing step t3, it can be implemented through steps tt1-tt2, specifically including:

[0085] Step tt1: For each user, if the difference between the intersection result and the union result of the user is less than a threshold, the user is divided into a community.

[0086] Step tt2: If the difference between the intersection result of the user and the union result of the user is greater than or equal to the threshold, the user is divided into different communities.

[0087] In this embodiment of the present application, for user node i, the cross-validation intersection is defined as:

[0088] C intersection(i) = A1 i ∩A2 i (1)

[0089] The cross-validation union is defined as:

[0090] C union (i) = A1 i ∪A2 i (2)

[0091] Among them, A1 i represents the first partition result of user node i, A2 i Represents the second partition result of user node i.

[0092] If |C intersection (i) |Close to |C union (i)|, that is, the difference between the intersection result and the union result of the user is less than the threshold, which means that the community division of the two algorithms on user node i is relatively consistent, then node i is divided into a community. If |C intersection (i) | is significantly smaller than |C union (i)|, that is, the difference between the intersection result and the union result of the user is greater than or equal to the threshold, indicating that the community division of the two algorithms on user node i is quite different, and user node i is divided into different communities.

[0093] Therefore, the community belonging of user node i can be expressed as a threshold-based decision formula:

[0094] |C intersection (i)|≥Threshold·|C union (i)| (3)

[0095] The threshold value is selected in the range of 0.01-0.09. A parameter search method can be used to determine the community division results using different thresholds in steps of 0.01. The results are then compared with the true community labels, and the Normalized Mutual Information (NMI) value is calculated. Based on the NMI value, the threshold with the highest NMI is selected as the optimal threshold. The community division results obtained based on the optimal threshold are most consistent with the true community division results.

[0096] Step 103: Determine the security risk level of each user based on the network service information and user relationship network of each user.

[0097] In an embodiment of the present application, after a user relationship network of multiple users in a campus is constructed, the security risk level of each user can be determined based on the network service information and user relationship network of each user.

[0098] In some embodiments, based on the network business information of each user, the network business address accessed by each user can be compared with the security event feature library to determine whether the network business address accessed by each user is a network security event, and to determine the number of network security events that occurred to each user, where network security events include three levels of hazard: high risk, medium risk, and low risk; then, based on the number of network security events that occurred to each user within a preset time, the hazard level corresponding to each network security event, and the security level of the community (region) where each user is located, the security risk level of each user is determined, where the security risk level includes four levels: none, low, medium, and high.

[0099] Here, based on the user's network service information, network security incidents can be divided into three categories: malicious propagation incidents, malicious controlled incidents, and network security threat incidents. The specific classification is as follows:

[0100] Malicious program transmission events: events in which users download harmful programs or harmful programs are transmitted.

[0101] Malicious controlled events: network security events caused by hosts being remotely controlled by malicious programs such as zombies, Trojans, remote control programs, backdoors, etc., as well as monitoring of other host controlled events caused by non-malicious programs.

[0102] Network security threat events: mainly include malicious traffic such as WEB application attacks, network sniffing, network attacks, system attacks, vulnerability exploitation attacks such as cache overflows, network scanning and eavesdropping behaviors such as network scanning, sniffing, and eavesdropping, brute force attacks, SQL injection attacks, cross-site scripting attacks, file inclusion, command code execution, SML entity attacks, file upload / download, path traversal, deserialization attacks, webshell and other attack behaviors.

[0103] In some embodiments, since some users may move to different communities after a period of time, and some new users may join existing communities or create new communities, new user behavior information (user characteristics) may be collected at every preset period, and updated community division results for each user may be obtained. Based on the updated community division results for each user, the user relationship network may be updated.

[0104] In some implementations, the community division results of each user at different times can also be compared, that is, the user relationship network and the updated user relationship network are compared to distinguish outlier user nodes and user nodes with large changes in community division, and mark them as suspicious outlier users, while the remaining user nodes are marked as normal users.

[0105] Here, an outlier user node refers to a user node that has weak connection strength with other user nodes or is not connected.

[0106] Here, for a user node that belongs to only one community, if the user node is divided into other communities after the community division result is updated, the user node is classified as a user node with a large change in community division; for a user node that belongs to multiple communities (overlapping communities), if the number of communities to which the user node is divided after the community division result is updated is greater than 50% of the number of communities to which the user node belonged before the update, the user node is classified as a user node with a large change in community division.

[0107] In some implementations, if a user in the campus has not experienced any network security incidents and is marked as a normal user, their security risk level is zero; if they are marked as suspicious outliers, their security risk level is low. The specific method for determining the security risk level of other users who have experienced network security incidents is as follows:

[0108] User security risk level is low:

[0109] (1) The number of low-risk network security incidents < 10 ∩ the security level of the user's area = low;

[0110] (2) The number of medium-risk network security incidents < 5 ∩ the security level of the user's area = low;

[0111] User security risk level is medium:

[0112] (3) The number of medium-risk network security incidents < 15 ∩ the security level of the user's area = medium;

[0113] (4) The number of low-risk network security incidents < 20 ∩ the security level of the user's area = medium;

[0114] (5) The number of high-risk cybersecurity incidents is less than 15;

[0115] User security risk level is high:

[0116] (6) The number of high-risk network security incidents ≥ 15 ∩ the security level of the user's area = medium;

[0117] (7) The number of medium-risk network security incidents ≥ 15 ∩ the security level of the user's area = medium;

[0118] (8) The number of low-risk network security incidents ≥ 20 ∩ the security level of the user's area = medium;

[0119] (9) The security level of the area where the user is located = high.

[0120] Step 104: Based on the security risk level of each user, risk warnings are issued to multiple users in the park.

[0121] In this embodiment of the application, after determining the security risk level of all users in the park, if a user's security risk level is any of the three levels of low, medium, or high, all users in the community in which the user resides are linked based on the user's relationship network. The security risk level of all users in the same community is set to low, and they are marked as suspected risk users. This can provide users in the entire community with advance warnings to prevent the spread of security risk incidents.

[0122] In some implementations, after determining each user's security risk level, corresponding control measures can be taken based on the user's security risk level. These control measures primarily focus on network-side control and can fundamentally curb user network access and other security-risky behaviors, including blacklisting and remote termination.

[0123] Here, adding a user to a blacklist is a temporary control measure. When a user's security risk level is low or medium, the user can be added to the blacklist, and the user will not be able to access the network. When the security risk level of a blacklisted user drops to zero, the user can be removed from the blacklist, and the user can access the network normally and perform corresponding services. When the user's risk level is high, the user can be remotely killed. At this time, the key in the corresponding Subscriber Identity Module (SIM) card will be cleared, causing the SIM card to be completely scrapped and the user will no longer be able to use the SIM card. This can effectively and timely curb the spread of network security risk incidents. After there are no new network security incidents in the campus, the status of all campus users will be restored, the blacklisted users will be removed from the blacklist, and the remotely killed users will have their cards rewritten. At the same time, the security risk level of all campus users will be reset to zero.

[0124] In the technical solution of the embodiment of the present application, the user characteristics of each user are determined based on the network business information and location information of each user among multiple users in the park, and a user relationship network is constructed based on the user characteristics of each user, wherein the user relationship network includes multiple communities, and each community is composed of at least one user node and at least one edge formed between user nodes. Then, based on the network business information and user relationship network of each user, the security risk level of each user is determined, and thus based on the security risk level of each user, risk warnings are issued to multiple users in the park. In this way, community detection is performed on all network users in the high-confidentiality park in combination with the user's network business situation and location information, and a community network based on network business data and business location information can be constructed, so that the community division results are more reasonable and more in line with the characteristics of the high-confidentiality park. At the same time, combined with the security risk level of each user, abnormal behavior in the park can be detected more effectively, and users with security risks can be warned and controlled in advance.

[0125] Figure 2 This is a schematic diagram of the module composition of the security risk monitoring solution of the embodiment of the present application, such as Figure 2 As shown in the figure, the overall solution consists of four modules, including:

[0126] Data processing module

[0127] (1) Obtain key data within the park

[0128] Key data is primarily composed of several data sources: the user's mobile phone number, IMSI number, asset data, SIP call bill data, other network service call bill data, MR data, base station information data, and regional security level. Among them, the user's mobile phone number, IMSI number, asset data, and regional security level are user information, which is obtained by users within the park based on their own circumstances. The regional security level is determined based on the security level of each area within the park. The park can divide different areas into three levels: low, medium, and high based on their actual conditions. SIP call bill data and other network service call bill data are obtained by DPI equipment connected to the park's confidential private network core network. MR data is obtained by user terminals reporting to base stations. Base station information data is obtained from base stations deployed within the park.

[0129] (2) Data association and merging

[0130] After obtaining all key data, all information can be associated and merged based on the user's mobile phone number, IMSI number and other information, thereby obtaining all business behavior data of each user in the park and the location where the business behavior occurred.

[0131] Community Discovery Module

[0132] (1) Feature extraction

[0133] After obtaining relevant data on all users in the park based on the data processing module, feature extraction is performed on the data based on the feature engineering module to obtain three main features: user business features, user location features, and user relationship features.

[0134] User service characteristics include all voice and network service characteristics of the user, which can reflect the user's main business situation in the park; user location characteristics mainly include the location characteristics of the user when conducting related voice and network services, which can reflect the location where the user often stays in the park, and the specific latitude and longitude information of the person can be obtained from the MR data. If this information is not available, the specific location of the user can be obtained through the base station three-point positioning method based on the information of the base station in the park; user relationship characteristics mainly include the business relationship characteristics between users, including voice call relationship, network business relationship and location relationship where they stay at the same time.

[0135] (2) Construction of user relationship network

[0136] The voice and online interactions users engage in within the campus reflect their social behaviors in the real world, and there is a close connection between these two behaviors. Therefore, the user voice and online interaction network can be viewed as a social network. Based on each user's characteristics, a user relationship network is constructed. Because users are associated with each other, they can logically form several communities. In other words, the user relationship network actually comprises multiple communities, each composed of at least one user node and at least one edge between them. Furthermore, because communities are clustered, user nodes are more closely connected within a community, while connections between communities are sparser. In the real world, community structures often overlap, with overlapping areas between communities, and a user node may belong to multiple communities simultaneously.

[0137] This application mainly uses a large-scale network overlapping community detection algorithm with linear complexity to divide users into communities, including overlapping community detection based on adjacency matrix and overlapping community detection based on streaming analysis. After obtaining the two division results, the two division results are cross-validated to improve detection accuracy. The main ideas for user community division are as follows:

[0138] Overlapping community detection based on the adjacency matrix. Based on the relationship characteristics of each user, an undirected relationship graph between multiple users is constructed. After constructing the adjacency matrix of the undirected relationship graph based on the undirected relationship graph, each element in the adjacency matrix represents the similarity between two user nodes. Therefore, spectral clustering can be performed on the adjacency matrix based on the similarity between user nodes, thereby partitioning the user nodes and obtaining the first partition result for each user.

[0139] Overlapping community detection based on streaming edge analysis. The degree information (degree) of a user node in an undirected graph can measure the closeness between the user node and its community. Since the number of edges within a community is much greater than the number of edges between communities, we can perform streaming edge analysis on each edge in the undirected graph based on the assumption that the probability of an edge being within a community is much greater than the probability of being an edge between communities, and obtain the second partition result for each user. The algorithm processes each edge in a streaming manner and only processes each edge once, which can quickly process large-scale networks and requires little memory.

[0140] (3) Cross-validation

[0141] Due to the complexity of the user relationship network within the campus, after obtaining the first and second partitioning results for each user using the adjacency matrix-based overlapping community detection algorithm and the streaming edge analysis-based overlapping community detection algorithm, a cross-validation metric must be calculated. This involves calculating the intersection and union of these two partitioning results. After calculating the cross-validation metric, the size of this cross-validation intersection and union is used to determine the community affiliation of each user node. The details of cross-validation can be found in steps tt1-tt2 above and are not detailed here.

[0142] Risk monitoring module

[0143] The risk monitoring module is mainly divided into two parts: risk detection and risk warning.

[0144] (1) Risk detection

[0145] After constructing a user relationship network for multiple users within the campus, the network service addresses accessed by each user can be compared with the security event signature database based on each user's network service information to determine whether the network service addresses accessed by each user represent network security events, and to determine the number of network security events that occurred for each user. Furthermore, since some users may move to different communities over time, and some new users may join existing communities or create new communities, new user behavior information (user features) can be collected at predetermined intervals, and updated community segmentation results for each user can be obtained. Based on the updated community segmentation results for each user, the user relationship network can be updated. The user relationship network can then be compared with the updated user relationship network to identify outlier user nodes and user nodes with significant changes in community segmentation. These nodes can be marked as suspicious outlier users, while the remaining user nodes are marked as normal users.

[0146] Based on the user's network service information, network security incidents can be divided into three categories: malicious propagation incidents, malicious controlled incidents, and network security threat incidents. The specific classification is as follows:

[0147] Malicious program transmission events: events in which users download harmful programs or harmful programs are transmitted.

[0148] Malicious controlled events: network security events caused by hosts being remotely controlled by malicious programs such as zombies, Trojans, remote control programs, backdoors, etc., as well as monitoring of other host controlled events caused by non-malicious programs.

[0149] Network security threat events: mainly include malicious traffic such as WEB application attacks, network sniffing, network attacks, system attacks, vulnerability exploitation attacks such as cache overflows, network scanning and eavesdropping behaviors such as network scanning, sniffing, and eavesdropping, brute force attacks, SQL injection attacks, cross-site scripting attacks, file inclusion, command code execution, SML entity attacks, file upload / download, path traversal, deserialization attacks, webshell and other attack behaviors.

[0150] Taking into account factors such as the importance of the objects affected by the cybersecurity incident, the severity of the business losses and the severity of the social harm, all cybersecurity incidents are divided into three levels of hazard: high risk, medium risk and low risk.

[0151] The security level of a campus user is determined based on the number of security incidents that occurred within an hour, the corresponding threat level, and the security level of the area where the user's business is located. If a campus user has not experienced any network security incidents and is marked as a normal user, their security risk level is zero. If they are marked as a suspicious outlier user, their security risk level is low. The security risk level of other users who have experienced network security incidents is determined as follows:

[0152] User security risk level is low:

[0153] 1) The number of low-risk network security incidents is less than 10 ∩ the security level of the user's area = low;

[0154] 2) The number of medium-risk network security incidents is less than 5 ∩ the security level of the user's area = low;

[0155] User security risk level:

[0156] 1) The number of medium-risk network security incidents is less than 15 ∩ the security level of the user's area = medium;

[0157] 2) The number of low-risk network security incidents is less than 20 ∩ the security level of the user's area = medium;

[0158] 3) The number of high-risk cybersecurity incidents is less than 15;

[0159] User security risk level is high:

[0160] 1) The number of high-risk network security incidents is ≥ 15 ∩ the security level of the user's area = medium;

[0161] 2) The number of medium-risk network security incidents is ≥ 15 ∩ the security level of the user's area = medium;

[0162] 3) The number of low-risk network security incidents is ≥ 20 ∩ the security level of the user's area = medium;

[0163] 4) The security level of the area where the user is located = high.

[0164] (2) Risk warning

[0165] After determining the security risk level of all users within the campus, if a user's security risk level is low, medium, or high, all users in their community are linked based on their relationship network. The security risk level of all users in the same community is set to low, and they are marked as suspected risk users. This provides early warning to users throughout the community, preventing the spread of security risk incidents.

[0166] Risk management module

[0167] The risk control module mainly takes corresponding control measures on users based on their security risk levels within the park. The control measures are mainly based on network-side control, which can fundamentally curb users' network access and other behaviors, including adding them to blacklists and remote killing measures. Among them, adding them to blacklists is a temporary control measure. When the user's risk level is low or medium, the user can be added to the blacklist. After being added to the blacklist, the user will not be able to access the network. When the security risk level of the user in the blacklist is reduced to zero, the user can be removed from the blacklist. At this time, the user can access the network normally and perform corresponding services; when the user's risk level is high, the user can be remotely killed. At this time, the key in the corresponding user's SIM card will be cleared, causing the SIM card to be completely scrapped and the user will no longer be able to use it. This can effectively and timely curb the spread of network security risk events.

[0168] Finally, after there are no new network security incidents in the park, the status of all park users will be restored, blacklisted users will be removed from the blacklist, and users who have been remotely killed will have their cards rewritten. At the same time, the security risk level of all park users will be reset to none.

[0169] This application is based on analyzing the core network traffic data. It can know the user's current access to the base station and the time of going online and offline based on the user signaling plane traffic data. Once the user terminal is connected to the base station, it can timely perceive the user's online through the analysis of the core network signaling plane traffic, determine whether the user is in a confidential area through the base station location, and build the user relationship network of the park based on the community discovery method. At the same time, based on the user plane traffic data, it can know whether the user is currently conducting abnormal network activities, and comprehensively judge whether there is a security risk in the park user behavior. Combined with the security level of the area where the user's business occurs, the security level of the user's current behavior is judged, and control measures are taken on the user in a timely manner according to different security levels. At the same time, the community where the risk user is located and other closely related users are determined based on the user relationship network, and security control is carried out on them to ensure that the security risk incident does not spread, and timely contain and locate specific personnel to effectively protect the network security of the entire park.

[0170] The present application also provides a security risk monitoring device. Figure 3 This is a schematic diagram of the structure of the security risk monitoring device according to an embodiment of the present application. Figure 3 As shown, the device includes:

[0171] Processing unit 301 is configured to determine user characteristics of each user based on network service information and location information of each user in the campus; and construct a user relationship network based on the user characteristics of each user; wherein the user relationship network includes multiple communities, each of the multiple communities being composed of at least one user node and at least one edge formed between the user nodes.

[0172] The determining unit 302 is configured to determine the security risk level of each user based on the network service information and user relationship network of each user.

[0173] The early warning unit 303 is used to issue risk early warnings to multiple users in the park based on the security risk level of each user.

[0174] In some embodiments, the processing unit 301 is further specifically configured to divide each user into communities based on the relationship characteristics of each user to obtain a community division result for each user; and to construct a user relationship network based on the community division result for each user; wherein the user characteristics of each user include business characteristics, location characteristics, and relationship characteristics.

[0175] In some embodiments, the processing unit 301 is further specifically configured to construct an undirected relationship graph between multiple users based on the relationship features of each user; wherein the undirected relationship graph is composed of at least one user node and at least one edge formed between the user nodes; construct an adjacency matrix of the undirected relationship graph based on the undirected relationship graph; wherein each element in the adjacency matrix represents the similarity between two user nodes; perform spectral clustering on the adjacency matrix to obtain a first partitioning result for each user; perform streaming edge analysis on the undirected relationship graph to obtain a second partitioning result for each user; and obtain a community partitioning result for each user based on the first partitioning result and the second partitioning result of each user.

[0176] In some embodiments, the processing unit 301 is further specifically configured to perform regularization processing on the adjacency matrix to obtain a Laplace matrix; perform spectral decomposition on the Laplace matrix to obtain multiple eigenvalues ​​and eigenvectors corresponding to the multiple eigenvalues; wherein each eigenvalue and the eigenvector corresponding to each eigenvalue respectively represent the similarity between a user node and other user nodes and the community in which the user node is located; arrange the multiple eigenvalues ​​in ascending order, select the eigenvectors corresponding to the first k eigenvalues, where k is a positive integer; cluster the eigenvectors corresponding to the first k eigenvalues, and divide the user nodes whose similarity is greater than a similarity threshold into the same community to obtain a first division result for each user.

[0177] In some embodiments, the processing unit 301 is further specifically configured to determine the number of neighbor user nodes of each user node based on the degree of each user node in the undirected relationship graph; wherein the neighbor user node of each user node is a user node that shares an edge with the user node; determine the number of neighbor user nodes in the community where each user node is located based on the community where each user node is located and the number of neighbor user nodes of each user node; determine the contribution of each user node to the community where it is located based on the number of neighbor user nodes of each user node and the number of neighbor user nodes in the community where each user node is located; and perform community division on each user node based on the degree of each user node and the contribution of each user node to the community where it is located, to obtain a second division result for each user.

[0178] In some embodiments, the processing unit 301 is further specifically configured to sequentially select an edge for each edge in the undirected relationship graph, and obtain the degrees of the user nodes at both ends of the edge; based on the degrees of the user nodes at both ends of the edge and the contributions of the user nodes at both ends of the edge to their respective communities, divide the user nodes at both ends of the edge into communities, and obtain the division results of the user nodes at both ends of the edge; wherein the number of edges within a community is greater than the number of edges between communities.

[0179] In some embodiments, the processing unit 301 is further specifically configured to take the intersection of each user's first segmentation result and each user's second segmentation result to obtain the intersection result of each user; take the union of each user's first segmentation result and each user's second segmentation result to obtain the union result of each user; and obtain the community segmentation result of each user based on the intersection result of each user and the union result of each user.

[0180] In some embodiments, the determination unit 302 is specifically used to compare the network business address accessed by each user with the security event feature library based on the network business information of each user, and determine the number of network security events that have occurred for each user; based on the number of network security events that have occurred for each user within a preset time, the hazard level corresponding to each network security event, and the security level of each user's community, determine the security risk level of each user; wherein, network security events include three hazard levels: high risk, medium risk, and low risk, the security level of each user's community includes three levels: low, medium, and high, and the security risk level of each user includes four levels: none, low, medium, and high.

[0181] In the technical solution of the embodiment of the present application, the user characteristics of each user are determined based on the network business information and location information of each user among multiple users in the park, and a user relationship network is constructed based on the user characteristics of each user, wherein the user relationship network includes multiple communities, and each community is composed of at least one user node and at least one edge formed between user nodes. Then, based on the network business information and user relationship network of each user, the security risk level of each user is determined, and thus based on the security risk level of each user, risk warnings are issued to multiple users in the park. In this way, community detection is performed on all network users in the high-confidentiality park in combination with the user's network business situation and location information, and a community network based on network business data and business location information can be constructed, so that the community division results are more reasonable and more in line with the characteristics of the high-confidentiality park. At the same time, combined with the security risk level of each user, abnormal behavior in the park can be detected more effectively, and users with security risks can be warned and controlled in advance.

[0182] Those skilled in the art should understand that Figure 3 The functions implemented by each unit in the security risk monitoring device shown can be understood by referring to the relevant description of the aforementioned method. Figure 3 The functions of the various units in the security risk monitoring device shown can be implemented by a program running on a processor, or by a specific logic circuit.

[0183] Figure 4 It is a structural diagram of a processing device provided in an embodiment of the present application. Figure 4The processing device shown includes a processor 401, which can call and run a computer program from a memory to implement the method in the embodiment of the present application.

[0184] Alternatively, as Figure 4 As shown, the processing device may further include a memory 402. The processor 401 may call and run a computer program from the memory 402 to implement the method in the embodiment of the present application.

[0185] The memory 402 may be a separate device independent of the processor 401 , or may be integrated into the processor 401 .

[0186] Alternatively, as Figure 4 As shown, the processing device may further include a transceiver 403 , and the processor 401 may control the transceiver 403 to communicate with other devices, specifically, to send information or data to other devices, or to receive information or data sent by other devices.

[0187] The transceiver 403 may include a transmitter and a receiver. The transceiver 403 may further include an antenna, and the number of antennas may be one or more.

[0188] The processing device can specifically be the security risk monitoring device of the embodiment of the present application, and the processing device can implement the corresponding processes implemented by the security risk monitoring device in each method of the embodiment of the present application. For the sake of brevity, they will not be repeated here.

[0189] During implementation, each step of the above-mentioned method embodiment can be completed by hardware integrated logic circuits in a processor or instructions in the form of software. The above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above-mentioned method in combination with its hardware.

[0190] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0191] It should be understood that the above-mentioned memories are exemplary but not restrictive. For example, the memories in the embodiments of the present application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM RAM (DR RAM), etc. In other words, the memories in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.

[0192] The present invention also provides a computer-readable storage medium for storing a computer program. This computer-readable storage medium can be applied to the security risk monitoring device in the present invention. The computer program causes a computer to execute the corresponding processes implemented by the security risk monitoring device in the various methods of the present invention. For the sake of brevity, these procedures are not further described here.

[0193] The present application also provides a computer program product, including computer program instructions. This computer program product can be applied to the security risk monitoring device in the present application, and the computer program instructions cause a computer to execute the corresponding processes implemented by the security risk monitoring device in the various methods of the present application. For the sake of brevity, these instructions are not further described here.

[0194] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0195] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0196] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0197] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0198] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0199] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0200] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A security risk monitoring method, characterized in that: The method comprises: Determining user characteristics of each user based on network service information and location information of each user among multiple users in the park; Based on the user characteristics of each user, a user relationship network is constructed; wherein the user relationship network includes a plurality of communities, and each of the plurality of communities is composed of at least one user node and an edge formed between the at least one user node; Determining a security risk level of each user based on the network service information of each user and the user relationship network; Based on the security risk level of each user, risk warnings are issued to the multiple users in the park.

2. The method according to claim 1, characterized in that The user characteristics of each user include business characteristics, location characteristics and relationship characteristics; The step of constructing a user relationship network based on the user characteristics of each user includes: Based on the relationship characteristics of each user, each user is divided into communities to obtain a community division result for each user; The user relationship network is constructed based on the community division result of each user.

3. The method according to claim 2, characterized in that The dividing each user into communities based on the relationship features of each user to obtain a community division result for each user includes: Based on the relationship feature of each user, construct an undirected relationship graph between the multiple users; wherein the undirected relationship graph is composed of the at least one user node and the edges formed between the at least one user node; Based on the undirected relationship graph, construct an adjacency matrix of the undirected relationship graph; wherein each element in the adjacency matrix represents the similarity between two user nodes; Performing spectral clustering on the adjacency matrix to obtain a first partitioning result for each user; Performing streaming edge analysis on the undirected relationship graph to obtain a second partitioning result for each user; A community division result for each user is obtained based on the first division result for each user and the second division result for each user.

4. The method according to claim 3, characterized in that The performing spectral clustering on the adjacency matrix to obtain the first division result of each user includes: Regularizing the adjacency matrix to obtain a Laplace matrix; Performing spectral decomposition on the Laplace matrix to obtain a plurality of eigenvalues ​​and eigenvectors corresponding to the plurality of eigenvalues; wherein each eigenvalue and the eigenvector corresponding to each eigenvalue respectively represent the similarity between a user node and other user nodes and the community to which the user node belongs; Arrange the multiple eigenvalues ​​in ascending order, and select the eigenvectors corresponding to the first k eigenvalues, where k is a positive integer; The eigenvectors corresponding to the first k eigenvalues ​​are clustered, and user nodes with similarities greater than a similarity threshold are divided into the same community to obtain a first division result for each user.

5. The method according to claim 3, characterized in that The performing streaming edge analysis on the undirected relationship graph to obtain the second division result for each user includes: Determining the number of neighboring user nodes of each user node based on the degree of each user node in the undirected relationship graph; wherein the neighboring user nodes of each user node are user nodes that share an edge with the user node; Determine the number of neighboring user nodes in the community where each user node is located based on the community where each user node is located and the number of neighboring user nodes of each user node; Determining the contribution of each user node to the community based on the number of neighboring user nodes of each user node and the number of neighboring user nodes in the community where each user node is located; Based on the degree of each user node and the contribution of each user node to the community, each user node is divided into communities to obtain a second division result for each user.

6. The method according to claim 5, characterized in that The performing community division on each user node based on the degree of each user node and the contribution of each user node to the community to obtain a second division result for each user includes: For each edge in the undirected relationship graph, select an edge in order and obtain the degree of the user nodes at both ends of the edge; Based on the degrees of the user nodes at both ends of the edge and the contributions of the user nodes at both ends of the edge to their respective communities, the user nodes at both ends of the edge are divided into communities to obtain the division results of the user nodes at both ends of the edge; wherein the number of edges within a community is greater than the number of edges between communities.

7. The method according to claim 4 or 6, characterized in that The obtaining of the community division result of each user based on the first division result of each user and the second division result of each user includes: Taking the intersection of the first division result of each user and the second division result of each user to obtain the intersection result of each user; Taking a union of the first division result of each user and the second division result of each user to obtain a union result of each user; Based on the intersection result of each user and the union result of each user, a community division result of each user is obtained.

8. The method according to claim 7, characterized in that The determining the security risk level of each user based on the network service information of each user and the user relationship network includes: Based on the network service information of each user, the network service address accessed by each user is compared with the security event signature database to determine the number of network security events that occurred for each user; Determine the security risk level of each user based on the number of network security incidents that occurred to each user within a preset period, the hazard level corresponding to each network security incident, and the security level of the community where each user resides; Among them, the network security incidents include three levels of hazard: high risk, medium risk and low risk; the security level of the community where each user is located includes three levels: low, medium and high; and the security risk level of each user includes four levels: none, low, medium and high.

9. A security risk monitoring device, characterized in that: The device comprises: A processing unit is configured to determine a user characteristic of each user among a plurality of users in the campus based on network service information and location information of the user; and construct a user relationship network based on the user characteristic of each user; wherein the user relationship network includes a plurality of communities, each of the plurality of communities being composed of at least one user node and an edge formed between the at least one user node; a determining unit, configured to determine a security risk level of each user based on the network service information of each user and the user relationship network; An early warning unit is used to issue risk warnings to the multiple users in the park based on the security risk level of each user.

10. A processing device, characterized in that The device includes: a processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to perform the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that A computer program is stored thereon, the computer program causing a computer to execute the method according to any one of claims 1 to 8.

12. A computer program product, characterized in that The method comprises computer program instructions for causing a computer to execute the method according to any one of claims 1 to 8.