Method and device for analyzing and identifying abnormal behaviors of user and electronic equipment

By generating standard logs and calculating baseline data using a baseline algorithm, the problem of low efficiency in user entity behavior analysis in the existing technology is solved, and automatic monitoring and analysis of abnormal user operations is achieved.

CN120704974APending Publication Date: 2025-09-26SHUAN YUNZHI (HANGZHOU) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410346480.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-25
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing user entity behavior analysis methods require customized analysis of each enterprise's input logs, which is inefficient, difficult to match and analyze logs of different categories, and the reliability of the analysis results is difficult to guarantee.

Method used

By obtaining the logs to be processed, generating standard logs according to the preset processing rules, and calculating the baseline data using the preset baseline algorithm, generating relevant alarm events according to the preset alarm rules, it is possible to automatically match the baseline value and monitor abnormal user operations.

Benefits of technology

It improves the efficiency of rule building for abnormal user behavior analysis, solves the problem that direct matching cannot be achieved using log analysis when the actual internal logs of users are diverse, and realizes automatic monitoring of abnormal user operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120704974A_ABST
    Figure CN120704974A_ABST
Patent Text Reader

Abstract

The invention relates to a user abnormal behavior analysis and recognition method and device and electronic equipment, and the method comprises the steps: obtaining a to-be-processed log, generating a standard log according to the to-be-processed log and corresponding basic data and a preset processing rule, carrying out the calculation of the standard log according to a preset baseline algorithm, obtaining baseline data, and carrying out the analysis and recognition of a user abnormal behavior. And generating a related alarm event corresponding to the baseline data according to a preset alarm rule. Through the method, the problem that direct matching cannot be achieved when logs are directly used for analysis under the condition that actual internal logs of a user are diversified is solved, baseline values are automatically matched, abnormal operation of the user is monitored, the rule construction efficiency of abnormal behavior analysis of the user is improved, and the capability of abnormal analysis based on multiple log sources is promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, device, and electronic device for analyzing and identifying abnormal user behavior. Background Art

[0002] Existing user-entity behavior analysis is typically based on the various logs available within an enterprise (device logs, application logs, network logs, logs provided by other security systems, etc.), and then analyzed using various analytical methods. Commonly used analytical methods include basic analysis such as pattern matching analysis, signature analysis, statistical analysis, and threshold analysis, as well as advanced analysis such as supervised and unsupervised machine learning. These methods are used to analyze and evaluate users and other entities, such as hosts, application systems, networks, and databases, to identify potential abnormal events related to activities that are abnormal compared to the standard user or entity profile or behavior. Due to the significant differences in the equipment, systems, and applications used within each target enterprise, the logs provided also vary greatly, making the above-mentioned analysis methods highly dependent on the log format that each enterprise needs to analyze.

[0003] In actual use, existing user entity behavior analysis methods require customized analysis methods for the input logs of each enterprise. Manual intervention is required to standardize the logs, adjust the analysis algorithms, and debug the preliminary results. This is inefficient and makes it difficult to match and analyze logs of different categories. The reliability of the analysis results is also difficult to guarantee, and a certain period of time is required for debugging and adaptation. Summary of the Invention

[0004] In view of this, the present application proposes a method for analyzing and identifying abnormal user behavior to solve the problems reflected in the above background technology.

[0005] According to one aspect of the present application, a method for analyzing and identifying abnormal user behavior is provided, comprising:

[0006] Get the logs to be processed;

[0007] Generate a standard log according to the log to be processed and the corresponding basic data according to the preset processing rules;

[0008] Calculate the standard log according to a preset baseline algorithm to obtain baseline data;

[0009] According to the preset alarm rules, relevant alarm events corresponding to the baseline data are generated.

[0010] As an optional implementation scheme of this application, obtaining logs to be processed includes:

[0011] Select the basic data source required for behavioral analysis;

[0012] Configure log output according to business needs and the basic data source, and generate logs to be processed.

[0013] As an optional implementation scheme of the present application, the preset processing rules are standardized processing rules and attribute supplementary rules; the to-be-processed log and the corresponding basic data are used to generate a standard log according to the preset processing rules, including:

[0014] Splitting the log to be processed into records with multiple attributes according to standardized processing rules;

[0015] If the multi-attribute record has missing information, the basic data is used to supplement the corresponding information according to the attribute supplementation rule;

[0016] The complete multi-attribute record set is saved as a standard log.

[0017] As an optional embodiment of this application, it also includes:

[0018] Create a baseline calculation task;

[0019] Determining a baseline value calculation script and an alarm rule script in the baseline calculation task according to the business requirements and the basic data source;

[0020] When scheduling the baseline calculation task, the baseline data of the log to be processed is calculated according to the baseline value script;

[0021] Run the alarm rule script, and if the baseline data exceeds a threshold, generate a corresponding alarm event.

[0022] As an optional embodiment of this application, it also includes:

[0023] Preset entity alarm report sending time interval;

[0024] Generate an entity alarm report according to the occurrence process of the relevant alarm event;

[0025] The entity alarm report is sent regularly according to the sending time interval.

[0026] As an optional implementation scheme of the present application, the scheduled sending method is one of short messages or emails.

[0027] As an optional embodiment of this application, it also includes:

[0028] Preset the time interval for extracting standard logs;

[0029] When scheduling a baseline calculation task, sequentially extracting the standard logs according to the time interval for extracting the standard logs;

[0030] The standard log is calculated according to the baseline value script and the alarm rule script in the baseline calculation task to generate relevant alarm events.

[0031] This application also provides a device for analyzing and identifying abnormal user behavior, including:

[0032] Get log module, used to get logs to be processed;

[0033] A standard log module is used to generate a standard log according to the log to be processed and the corresponding basic data according to preset processing rules;

[0034] A baseline data module is used to calculate the standard log according to a preset baseline algorithm to obtain baseline data;

[0035] The event generation module is used to generate relevant alarm events corresponding to the baseline data according to preset alarm rules.

[0036] As an optional implementation scheme of this application, obtaining a log module includes:

[0037] Obtain basic data source module, used to select the basic data source required for behavior analysis;

[0038] The log output module is configured to configure the log output according to business requirements and the basic data source, and generate logs to be processed.

[0039] The present application also provides an electronic device, comprising:

[0040] processor;

[0041] a memory for storing processor-executable instructions;

[0042] Wherein, the processor is configured to implement the above-mentioned method for analyzing and identifying abnormal user behavior when executing the executable instructions.

[0043] Beneficial effects of this application:

[0044] This method obtains pending logs, generates standard logs based on the pending logs and corresponding basic data according to preset processing rules, calculates the standard logs using a preset baseline algorithm to obtain baseline data, and generates relevant alarm events corresponding to the baseline data according to preset alarm rules. This solves the problem of inability to directly analyze logs due to the diversity of users' actual internal logs, automatically matching baseline values ​​and monitoring abnormal user operations.

[0045] Other features and aspects of the present application will become apparent from the following detailed description of exemplary embodiments with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate exemplary embodiments, features, and aspects of the application and, together with the description, serve to explain the principles of the application.

[0047] Figure 1 A flowchart illustrating a method for analyzing and identifying abnormal user behavior according to an embodiment of the present application;

[0048] Figure 2 An architectural diagram illustrating a method for analyzing and identifying abnormal user behavior according to an embodiment of the present application;

[0049] Figure 3 A block diagram of a device for analyzing and identifying abnormal user behavior according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0050] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0051] It should be understood that the terms "center", "longitudinal", "lateral", "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", "clockwise", "counterclockwise", "axial", "radial", "circumferential" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application or simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.

[0052] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. Throughout the description of this application, "plurality" means two or more, unless otherwise specifically defined.

[0053] The word “exemplary” is used exclusively herein to mean “serving as an example, example, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.

[0054] In addition, numerous specific details are provided in the detailed description below to better illustrate the present application. Those skilled in the art will appreciate that the present application can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art are not described in detail in order to highlight the main purpose of the present application.

[0055] In computers, log files are files that record events that occur during the operation of an operating system or other software, or messages between different users of communication software. They play an important role in processing historical data, tracing diagnostic problems, and understanding system activities.

[0056] User and Entity Behavior Analytics (UEBA) identifies potential incidents related to activities that are anomalous to the standard profile or behavior of users or entities. These activities include unusual access to systems by trusted internal or third-party personnel, or intrusions by external attackers that bypass security controls.

[0057] Example 1

[0058] Figure 1 The flowchart of the method for analyzing and identifying abnormal user behavior according to an embodiment of the present application is shown. The method can no longer rely too much on a specific log format when analyzing user entity behavior, and provides a more unified analysis method for user entity behavior analysis. Figure 1 As shown, the flow chart includes:

[0059] S100, obtaining logs to be processed;

[0060] In this embodiment, the log to be processed is obtained by the user behavior analysis party receiving the log output by the log provider.

[0061] S200, generating a standard log according to the log to be processed and the corresponding basic data according to preset processing rules;

[0062] After receiving the log to be processed, the user behavior analysis party accesses the corresponding basic data according to the granted authority, performs standardization processing and attribute supplement on the log to be processed based on the basic data, and obtains a standard log in the unified format of the user behavior analysis party.

[0063] S300, calculating the standard log according to a preset baseline algorithm to obtain baseline data;

[0064] Based on the standard log, develop a script for calculating the baseline value suitable for it, use the script to run the baseline algorithm, generate and save the baseline data.

[0065] S400: Generate relevant alarm events corresponding to the baseline data according to preset alarm rules.

[0066] Based on the saved baseline data and pre-established alarm rules, it is determined whether the baseline data exceeds the abnormal threshold. If so, a relevant alarm event is generated.

[0067] As an optional implementation scheme of the present application, in step S100, obtaining a log to be processed includes:

[0068] S101, selecting the basic data source required for behavior analysis;

[0069] In this embodiment, the log provider and user behavior analyst select the basic data sources needed for analysis based on the specific circumstances of their respective industries and businesses. For example, a log provider provides desensitized DLP (Data Leak Prevention) logs that contain information such as labor contracts. Behavioral analysis of DLP logs requires relevant data from this basic data. Since basic DLP data includes personnel data and device data, these two data are the basic data sources required for DLP log analysis.

[0070] S102: Configure log output according to business requirements and the basic data source to generate the log to be processed.

[0071] The log provider configures log output tasks based on the underlying data source. Once received by the user behavior analyst, the output logs are considered pending logs. For example, the log provider cannot directly send personnel and device data to the user behavior analyst. Instead, the provider must combine these data with the DLP log to generate a new log for output and send to the user behavior analyst.

[0072] As an optional implementation scheme of the present application, the preset processing rules are standardized processing rules and attribute supplementary rules; the to-be-processed log and the corresponding basic data are used to generate a standard log according to the preset processing rules, including:

[0073] In this embodiment, the standardized processing rule is: if the log is not in key-value (a database that stores data in key-value pairs) format, split the single-line log into records with multiple attributes.

[0074] The attribute supplement rule is: supplement the missing information in the log based on the relevant basic data.

[0075] Splitting the log to be processed into records with multiple attributes according to standardized processing rules;

[0076] For example, the access log of a web-based application is not in key-value format. It is split into records with multiple attributes, such as the IP address used, the access person, and the work number.

[0077] If the multi-attribute record has missing information, the basic data is used to supplement the corresponding information according to the attribute supplementation rule;

[0078] For example, the relevant basic data in the web-based application access log configured and output by the log provider is missing some access user information. The user behavior analyst can read the basic data source of the web application access log based on the access permissions configured by the relevant third party. The basic data source will record the computer IP addresses used by all personnel. Therefore, the name and work number of the access user can be supplemented in the log based on the IP address.

[0079] The complete multi-attribute record set is saved as a standard log.

[0080] After the split multi-attribute records, some of them need to be supplemented with missing information. After the supplement is completed, the set of all multi-attribute records belonging to the log to be processed is saved as a standard log.

[0081] As an optional embodiment of this application, it also includes:

[0082] Create a baseline calculation task;

[0083] In this embodiment, the baseline calculation task is created by the baseline task management module of the user behavior analysis party.

[0084] According to the business requirements and the basic data source, a baseline value calculation script and an alarm rule script are determined in the baseline calculation task.

[0085] Different types of logs require different underlying data sources depending on business needs, so a single baseline value calculation method cannot be used for all logs. Based on business needs and underlying data sources, develop baseline value scripts and alarm rule scripts that meet your needs. Alarm rule scripts are developed based on actual potential alarm events and are not limited here.

[0086] When scheduling the baseline calculation task, the baseline data of the log to be processed is calculated according to the baseline value script;

[0087] The baseline calculation task doesn't run immediately after the baseline calculation script and alarm rule script are determined. Instead, it needs to be scheduled into the execution sequence of all tasks to ensure orderly execution. After scheduling the execution sequence of the baseline calculation tasks, when the baseline calculation task is executed, it calculates the baseline data for the logs to be processed according to the baseline calculation script configured in it.

[0088] Run the alarm rule script, and if the baseline data exceeds a threshold, generate a corresponding alarm event.

[0089] After the baseline data is generated, the alarm rule script is run to determine whether the baseline data exceeds the threshold for forming an alarm event. If it exceeds the threshold, an alarm event is determined, and the specific alarm event is further determined based on the baseline data.

[0090] As an optional embodiment of this application, it also includes:

[0091] Preset entity alarm report sending time interval;

[0092] In this embodiment, a suitable time interval is set for the generated entity alarm report to be sent regularly for the user to view.

[0093] Generate an entity alarm report according to the occurrence process of the relevant alarm event;

[0094] In this embodiment, the baseline alarm module of the user behavior analysis party generates relevant alarm events according to the alarm rule script. The relevant alarm events are generally a message. The occurrence process of the alarm events in the message is integrated and an alarm report is generated. The format of the alarm report can be a common PDF format file, which is convenient for relevant personnel to understand the situation recorded in the log.

[0095] The entity alarm report is sent regularly according to the sending time interval.

[0096] In this embodiment, the generated entity alarm report is not scheduled for delivery immediately. Instead, it is sent to relevant personnel for review at a predetermined time interval based on the time the entity alarm report is generated. For example, the entity alarm report is sent to the user two minutes after the time the entity alarm report is generated.

[0097] As an optional implementation scheme of the present application, the scheduled sending method is one of short messages or emails.

[0098] The method of sending the entity alarm report can be a short message or email, or other convenient communication methods, depending on user needs and is not limited here.

[0099] As an optional embodiment of this application, it also includes:

[0100] Preset the time interval for extracting standard logs;

[0101] In this embodiment, as logs from various log providers are continuously output, the user behavior analysis provider receives them and continuously standardizes the logs to be processed, generating standard logs. However, baseline calculation for standard logs takes time to complete. The time required to apply the baseline algorithm to each standard log and complete the calculation is not fixed, and the calculation speed is affected by the information in the standard log. Therefore, the standard logs are stored centrally in a standardized order. The time interval for extracting standard logs is set based on the majority of the calculation time.

[0102] When scheduling a baseline calculation task, the standard logs are sequentially extracted according to the time interval for extracting the standard logs.

[0103] Scheduling the baseline calculation task means entering the process of calculating the baseline values ​​of each standard log and determining whether there is an alarm event. In this process, the baseline calculation module of the user behavior analysis party extracts standard logs from the standard log storage location according to the baseline calculation task.

[0104] The standard log is calculated according to the baseline value script and the alarm rule script in the baseline calculation task to generate relevant alarm events.

[0105] The baseline algorithm is used to calculate the baseline of the extracted standard logs and the baseline value is cached. Alarms are generated based on the threshold values ​​configured in the baseline task.

[0106] This method utilizes baseline-based user behavior analysis and calculations to perform baseline calculations and anomaly matching assessments for single or cross-classified logs, using a unified algorithm for log behavior classification. This improves the efficiency of building rules for abnormal user behavior analysis and advances the ability to analyze anomalies based on multiple log sources. This solves the problem of inability to directly analyze logs due to the diversity of actual internal user logs, automatically matching baseline values ​​and monitoring abnormal user operations.

[0107] Example 2

[0108] Based on the same principle as the above method, a user behavior analysis system is proposed. The system architecture is as follows: Figure 2 As shown, the following modules are involved: log data source, log standardization management, baseline task management, basic data management, baseline calculation module, user operation interface, standardized log, and basic data.

[0109] Log data source: Configure log output tasks.

[0110] Log standardization management: used to manage log sources, establish log reception and governance rules, create log receivers, and save logs into the database.

[0111] Baseline task management: Create baseline processing task scripts and schedule baseline tasks.

[0112] Basic data management: used to manage basic data and synchronize basic data with the user behavior analysis system.

[0113] Baseline calculation module: extracts standard log information regularly according to the baseline task, calculates the baseline according to the baseline algorithm and caches the baseline value, and issues alarms according to the threshold configured by the baseline task.

[0114] User operation interface: system web operation interface.

[0115] Standardized log: used to convert received logs into standard logs and save them.

[0116] Basic data: basic data sources from third parties.

[0117] Here's how to use the system:

[0118] Step 1: Log providers and user behavior analysts select the basic data sources needed for analysis based on their specific industries and businesses. A third party will configure access permissions for the log providers and user behavior analysts, enabling them to access basic data, such as personnel information, device information, application information, and account information. The user behavior analysts will synchronize this basic data into the user behavior analysis system through basic data management.

[0119] Step 2: Log Standardization Management Create a log collector to receive the logs output by the log data source configuration.

[0120] For example, if you receive a DLP log that has been desensitized, it contains:

[0121] {

[0122] "log_uuid":

[0123] "5213a35327dff92cf170195ab7d0588752a2579a8f9c7914ee8c60e7718076aa",

[0124] "log_event_id":

[0125] "5321ddd1cc31304836d1cedf8a654492f2754956a9256bb427571109f3318c0f",

[0126] "log_create_time":"2023-06-05T14:15:35",

[0127] "log_priority":"low",

[0128] "log_event_type":"dlp",

[0129] "generic_opt_content":"Release",

[0130] "device_ip":"192.168.10.3",

[0131] "device_mac":"A0-AF-BD-30-E2-3",

[0132] "file hash":

[0133] "5a1305a0582d711d6bf6520d154046dc5fb0842907f416addd9627d92147748a",

[0134] "file_name":"Labor Contractguocc.pdf",

[0135] "file_size":442482,

[0136] "file_system_type":"windows",

[0137] "file_type":"pdf",

[0138] "program_name":"vim",

[0139] "rule_policy":"",

[0140] "data_class":"Enterprise Secret Class",

[0141] "data_level":2,

[0142] "data_tag":"Create sensitive files",

[0143] "sensitive_content":"",

[0144] }

[0145] The basic data are:

[0146] Personnel data:

[0147] {

[0148] "person_uuid":"73776ae9-e629-4ff3-ad2b-ecf7d0d4c95f",

[0149] "person_name":"Lin xshu",

[0150] "person_status":"Resignation handover period",

[0151] "person_ctpositionname":"General Staff",

[0152] "person_type":"Enterprise Employee",

[0153] "person_cellphone_no":"13391xxx285",

[0154] "person_identity_card":"31011292xxxx20123",

[0155] "person_mail":"linmxxxxx@datasafe-tech.com",

[0156] "person_entry_time":"2023-02-16 16:23:23.29",

[0157] "person_leave_office_time":"",

[0158] "person_area_name":"",

[0159] "person_main_account":"linmeishu",

[0160] "account":"linmeishu",

[0161] "device_dept": "Decision-making and Management Department",

[0162] }

[0163] Device data:

[0164] {

[0165] "device_uuid":

[0166] "d8cd4f5ce082147ca5bbdb899954ad019bd123ebc90e3d0e01075c111bb8cc7e",

[0167] "device_status":"Online",

[0168] "device_name":"dataset-pc-3",

[0169] "device_dept": "Decision-making and Management Department",

[0170] "device_type":"Office Computer",

[0171] "device_owner":"Lin xshu",

[0172] "device_vendor": "Xiaomi",

[0173] "device_value":"low",

[0174] "device_ip":"192.168.10.3",

[0175] "device_mac":"A0-AF-BD-30-E2-3",

[0176] "device_network_domain":"Local Area Network",

[0177] }

[0178] Step 3: Standardize logs: Configure standardized processing and attribute supplementation rules based on the input logs and basic data, and save the input logs as standard logs.

[0179] For example, the original DLP logs mentioned above are supplemented with the attributes of the basic data and then stored in the database. Subsequent behavioral analysis is based on the stored logs, that is, standard logs.

[0180] {

[0181] "log_ueba_flow_id":"topic_dlp",

[0182] "log_uuid":

[0183] "5213a35327dff92cf170195ab7d0588752a2579a8f9c7914ee8c60e7718076aa",

[0184] "log_event_id":

[0185] "5321ddd1cc31304836d1cedf8a654492f2754956a9256bb427571109f3318c0f",

[0186] "log_create_time":"2023-06-05T14:15:35",

[0187] "log_priority":"low",

[0188] "log_event_type":"dlp",

[0189] "generic_opt_content":"Release",

[0190] "src_person_uuid":"73776ae9-e629-4ff3-ad2b-ecf7d0d4c95f",

[0191] "src_person_name":"Lin xshu",

[0192] "src_person_status":"Resignation handover period",

[0193] "src_person_ctpositionname":"General Staff",

[0194] "src_person_type":"Enterprise Employee",

[0195] "src_person_cellphone_no":"13391xxx285",

[0196] "src_person_identity_card":"31011292xxxx20123",

[0197] "src_person_mail":"linmxxxxx@datasafe-tech.com",

[0198] "src_person_entry_time":"2023-02-16 16:23:23.29",

[0199] "src_person_leave_office_time":"",

[0200] "src_person_area_name":"",

[0201] "src_person_main_account":"linmeishu",

[0202] "src_account":"linmeishu",

[0203] "src_device_uuid":

[0204] "d8cd4f5ce082147ca5bbdb899954ad019bd123ebc90e3d0e01075c111bb8cc7e",

[0205] "src_device_status":"Online",

[0206] "src_device_name":"dataset-pc-3",

[0207] "src_device_dept":"Decision Management Department",

[0208] "src_device_type":"Office Computer",

[0209] "src_device_owner":"Lin xshu",

[0210] "src_device_vendor":"Xiaomi",

[0211] "src_device_value":"low",

[0212] "src_device_ip":"192.168.10.3",

[0213] "src_device_mac":"A0-AF-BD-30-E2-3",

[0214] "src_device_network_domain":"Local Area Network",

[0215] "file_hash":

[0216] "5a1305a0582d711d6bf6520d154046dc5fb0842907f416addd9627d92147748a",

[0217] "file_name":"Labor Contractguocc.pdf",

[0218] "file_size":442482,

[0219] "file_system_type":"windows",

[0220] "file_type":"pdf",

[0221] "program_name":"vim",

[0222] "rule_policy":"",

[0223] "data_class":"Enterprise Secret Class",

[0224] "data_level":2,

[0225] "data_tag":"Create sensitive files",

[0226] "sensitive_content":"",

[0227] "netflow_app_protocol_type":""

[0228] }

[0229] Step 4: Create a baseline calculation task based on the saved standard log, determine the baseline value calculation script and alarm rule script, and save them.

[0230] Step 5: Baseline Task Management: After the baseline task is scheduled, the baseline calculation module periodically extracts standard logs from the standardized logs, performs calculations according to the baseline algorithm, generates and saves baseline data. Simultaneously, the baseline alarm module, a submodule within the baseline calculation module, generates relevant alarm events based on the baseline alarm judgment rules and produces a physical alarm report.

[0231] For example, after processing multiple logs stored in step 3, the standard deviation of the src_device_dept attribute is calculated hourly to form baseline data. For example: (1)

[0233] {"src_device_dept":"Decision Management Department

[0234] ","time":"2023-12-14:10:00:00","count":234.23}

[0235] The standard deviation of the src_person_uuid attribute is calculated every minute to form comparative data.

[0236] For example: (2)

[0238] {"src_person_uuid":

[0239] "73776ae9-e629-4ff3-ad2b-ecf7d0d4c95f","time":"2023-12-14:10:00:00","count":150.23}

[0240] The threshold value can be set as whether the count of (2) is greater than the count of (1) by 3 times the standard deviation and for 3 consecutive times. If the above conditions are met, an alarm is issued. It is also possible to make a comprehensive judgment based on the alarm results of multiple dimensions, such as src_device_dept and src_person_type.

[0241] Step 6: Send the entity alarm report according to the sending method configured by the user.

[0242] The sending method is short message or email.

[0243] This system architecture primarily utilizes a user behavior analysis platform. By standardizing device logs, system logs, application logs, and other source logs, correlating basic data with complete attributes, and then using a standard baseline algorithm to calculate baseline values ​​for related entities, the results are categorized and saved as entity baseline data. Secondary operations are then performed using the entity baseline data to generate abnormal behavior events for the entity.

[0244] Example 3

[0245] Based on the same principle as the above method, a device for analyzing and identifying abnormal user behavior is also proposed. Figure 3 A device 100 for analyzing and identifying abnormal user behavior according to an embodiment of the present disclosure includes:

[0246] 110, a log acquisition module, used to acquire logs to be processed;

[0247] 120, a standard log module, configured to generate a standard log based on the to-be-processed log and the corresponding basic data according to preset processing rules;

[0248] 130, a baseline data module, configured to calculate the standard log according to a preset baseline algorithm to obtain baseline data;

[0249] 140, generating an event module, configured to generate relevant alarm events corresponding to the baseline data according to preset alarm rules.

[0250] As an optional implementation scheme of this application, obtaining a log module includes:

[0251] 111, obtaining a basic data source module, for selecting a basic data source required for behavior analysis;

[0252] 112. Configure a log output module, configured to configure log output according to business requirements and the basic data source, and generate logs to be processed.

[0253] Obviously, those skilled in the art should understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned control methods. The modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Alternatively, they can be implemented by program codes executable by the computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.

[0254] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned control method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD). The storage medium can also include a combination of the above-mentioned types of memory.

[0255] Example 4

[0256] Furthermore, an electronic device is proposed, comprising:

[0257] processor;

[0258] a memory for storing processor-executable instructions;

[0259] The processor is configured to implement the method for analyzing and identifying abnormal user behavior as described in Example 1 when executing the executable instructions.

[0260] The electronic device of the embodiment of the present disclosure includes a processor and a memory for storing processor-executable instructions, wherein the processor is configured to implement any of the above-mentioned methods for analyzing and identifying abnormal user behavior when executing the executable instructions.

[0261] It should be noted that the number of processors can be one or more. Furthermore, the electronic device in the embodiments of the present disclosure may also include an input device and an output device. The processor, memory, input device, and output device may be connected via a bus or other means, which are not specifically limited herein.

[0262] The memory, as a computer-readable storage medium for the method for analyzing and identifying abnormal user behavior, can be used to store software programs, computer-executable programs, and various modules, such as the program or module corresponding to the method for analyzing and identifying abnormal user behavior in the embodiments of the present disclosure. The processor executes the software programs or modules stored in the memory to perform various functional applications and data processing in the electronic device.

[0263] The input device can be used to receive input numbers or signals. The signals can be key signals related to user settings and function control of the device / terminal / server. The output device can include a display device such as a display screen.

[0264] The embodiments of the present application have been described above. The above description is illustrative and not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or improvements to the technology in the market, or to enable other persons skilled in the art to understand the embodiments disclosed herein.

Claims

1. A method for analyzing and identifying abnormal user behavior, characterized in that: include: Get the logs to be processed; Generate a standard log according to the log to be processed and the corresponding basic data according to the preset processing rules; Calculate the standard log according to a preset baseline algorithm to obtain baseline data; According to the preset alarm rules, relevant alarm events corresponding to the baseline data are generated.

2. The method for analyzing and identifying abnormal user behavior according to claim 1, characterized in that: Get pending logs, including: Select the basic data source required for behavioral analysis; Configure log output according to business requirements and the basic data source to generate the log to be processed.

3. The method for analyzing and identifying abnormal user behavior according to claim 1, characterized in that: The preset processing rules are standardized processing rules and attribute supplementary rules; the log to be processed and the corresponding basic data are used to generate a standard log according to the preset processing rules, including: Splitting the log to be processed into records with multiple attributes according to standardized processing rules; If the multi-attribute record has missing information, the basic data is used to supplement the corresponding information according to the attribute supplementation rule; The complete multi-attribute record set is saved as a standard log.

4. The method for analyzing and identifying abnormal user behavior according to claim 2, characterized in that: Also includes: Create a baseline calculation task; Determining a baseline value calculation script and an alarm rule script in the baseline calculation task according to the business requirements and the basic data source; When scheduling the baseline calculation task, the baseline data of the log to be processed is calculated according to the baseline value script; The baseline data is used in the alarm rule script to generate corresponding alarm events.

5. The method for analyzing and identifying abnormal user behavior according to any one of claims 1 to 4, characterized in that: Also includes: Preset entity alarm report sending time interval; Generate an entity alarm report according to the occurrence process of the relevant alarm event; The entity alarm report is sent regularly according to the sending time interval.

6. The method for analyzing and identifying abnormal user behavior according to claim 5, characterized in that: The scheduled sending method is either a short message or an email.

7. The method for analyzing and identifying abnormal user behavior according to claim 3, characterized in that: Also includes: Preset the time interval for extracting standard logs; When scheduling a baseline calculation task, sequentially extracting the standard logs according to the time interval for extracting the standard logs; The standard log is calculated according to the baseline value script and the alarm rule script in the baseline calculation task to generate relevant alarm events.

8. A device for analyzing and identifying abnormal user behavior, characterized in that: include: Get log module, used to get logs to be processed; A standard log module is used to generate a standard log according to the log to be processed and the corresponding basic data according to preset processing rules; A baseline data module is used to calculate the standard log according to a preset baseline algorithm to obtain baseline data; The event generation module is used to generate relevant alarm events corresponding to the baseline data according to preset alarm rules.

9. The device for analyzing and identifying abnormal user behavior according to claim 8, characterized in that: Get the log module, including: Obtain basic data source module, used to select the basic data source required for behavior analysis; The log output module is configured to configure the log output according to business requirements and the basic data source, and generate logs to be processed.

10. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the method for analyzing and identifying abnormal user behavior as described in any one of claims 1 to 7 when executing the executable instructions.