Application behavior detection method, apparatus and device, and computer program product

By dynamically adjusting the learning time and generating behavioral category baselines, the problem of high false alarm rate in traditional baseline construction methods under changing scenarios is solved, and more efficient application behavior detection is achieved.

CN120805141APending Publication Date: 2025-10-17CHINA MERCHANTS BANK
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510916854.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Traditional baseline construction methods rely on predefined rules or static baseline templates, resulting in a high false positive rate in scenarios with volatile application operation behaviors.

Method used

By obtaining the historical behavior data of the target application, performing statistical analysis based on the time window, dynamically adjusting the learning time, generating behavior category baselines and pattern baselines, and comparing the target behavior data with the baselines, abnormal behavior can be identified.

Benefits of technology

It reduces the false positive rate of application behavior detection in changing scenarios and improves the accuracy and adaptability of anomaly detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805141A_ABST
    Figure CN120805141A_ABST
Patent Text Reader

Abstract

The invention discloses an application behavior detection method and device, equipment and a computer program product, and relates to the technical field of software security, and the method comprises the steps: obtaining target behavior data of a target application; performing baseline calculation based on the historical behavior data of the target application, and determining an application behavior baseline of the target application; and comparing the target behavior data with the application behavior baseline, and performing target processing on the target application based on a comparison result. According to the application, baseline calculation is carried out through the historical behavior data, the application behavior baseline is determined, the application behavior baseline is updated along with updating of the historical behavior data, compared with a static baseline template, the application behavior detection method can adapt to variable scenes, and the false alarm rate of application behavior detection in the variable scenes is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of software security, and particularly relates to an application behavior detection method and device, equipment and a computer program product. BACKGROUND

[0002] In the field of network security, with the increasing complexity and diversification of network attack means, traditional security protection technology is facing great challenges. As an important security protection means, baseline-based anomaly detection technology is widely used in identifying abnormal behaviors in applications. However, the traditional baseline construction method usually depends on predefined rules or static baseline templates, and these methods have a high false alarm rate when facing the application operation behavior changeable scene.

[0003] The above content is only used to assist in understanding the technical solutions of the present application, and does not represent the acknowledgement of the above content as prior art. SUMMARY

[0004] The main purpose of the present application is to provide an application behavior detection method, device, equipment and computer program product, aiming at solving the technical problem of high false alarm rate of application operation detection.

[0005] To achieve the above purpose, the present application provides an application behavior detection method, which comprises:

[0006] obtaining target behavior data of a target application;

[0007] performing baseline calculation based on historical behavior data of the target application to determine an application behavior baseline of the target application;

[0008] comparing the target behavior data and the application behavior baseline, and performing target processing on the target application based on the comparison result.

[0009] In an embodiment, the step of performing baseline calculation based on the historical behavior data of the target application to determine the application behavior baseline of the target application comprises:

[0010] obtaining historical behavior data of the target application from a first database;

[0011] statistically analyzing the historical behavior data based on a first time window to determine a target execution frequency corresponding to the historical behavior data;

[0012] dynamically adjusting a target learning duration of the historical behavior data based on the target execution frequency;

[0013] comparing the historical behavior data and the target learning duration to determine an application behavior baseline corresponding to the historical behavior data.

[0014] In an embodiment, the step of comparing the historical behavior data with the target learning duration to determine an application behavior baseline corresponding to the historical behavior data comprises:

[0015] comparing the application learning duration of the historical behavior data with the target learning duration, and calculating a behavior execution frequency in the application learning duration when the application learning duration is greater than the target learning duration;

[0016] comparing the behavior execution frequency with the target execution frequency to determine, and performing baseline calculation on the historical behavior data to generate the application behavior baseline corresponding to the historical behavior data when the behavior execution frequency is greater than the target execution frequency.

[0017] In an embodiment, the application behavior baseline comprises a behavior category baseline and a behavior pattern baseline, and the step of performing baseline calculation on the historical behavior data to generate the application behavior baseline corresponding to the historical behavior data comprises:

[0018] traversing the historical behavior data based on a preset behavior category, determining the execution times of the historical behavior data in the corresponding behavior category, and generating a behavior category baseline corresponding to the historical behavior data;

[0019] performing category division on the historical behavior data according to the behavior category, and performing comparison and merging on the category-divided historical behavior data to generate a behavior pattern baseline of the historical behavior data.

[0020] In an embodiment, the step of performing category division on the historical behavior data according to the behavior category, and performing comparison and merging on the category-divided historical behavior data to generate a behavior pattern baseline of the historical behavior data comprises:

[0021] performing category division on the historical behavior data according to the behavior category to generate target category data corresponding to the behavior category;

[0022] extracting behavior features from each target instance of the target category data, comparing the behavior features of each target instance to determine common features and change parameter bits of the target category data;

[0023] merging the behavior features based on the common features and the change parameter bits to obtain a behavior category template corresponding to the target category data;

[0024] combining the behavior category templates of each target category data to generate a behavior pattern baseline of the historical behavior data.

[0025] In an embodiment, the step of comparing the target behavior data with the application behavior baseline and performing target processing on the target application based on a comparison result comprises:

[0026] comparing the target behavior data with the application behavior baseline to obtain a behavior detection result of the target application;

[0027] if the behavior detection result is a behavior detection anomaly, performing alarm aggregation on each of the behavior detection results in a preset alarm dimension, generating target alarm information of the target application, and sending the target alarm information to an alarm platform.

[0028] In an embodiment, the application behavior detection method further comprises:

[0029] obtaining unstructured behavior data in the target behavior data through a large model;

[0030] associating the unstructured behavior data with an external data source, filtering normal behavior data in the unstructured behavior data, and obtaining to-be-detected behavior data in the unstructured behavior data;

[0031] performing execution frequency calculation on the to-be-detected behavior data through a frequency model to obtain a to-be-detected execution frequency of the to-be-detected behavior data;

[0032] when the to-be-detected execution frequency is greater than a preset frequency threshold, determining that the to-be-detected behavior data is normal behavior data.

[0033] In addition, to achieve the above-mentioned purpose, the application further provides an application behavior detection device, which comprises:

[0034] a data acquisition module configured to acquire target behavior data of a target application;

[0035] a baseline calculation module configured to perform baseline calculation based on historical behavior data of the target application to determine an application behavior baseline of the target application;

[0036] a baseline comparison module configured to compare the target behavior data with the application behavior baseline and perform target processing on the target application based on a comparison result.

[0037] In addition, to achieve the above-mentioned purpose, the application further provides an application behavior detection device, which comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the application behavior detection method as described above.

[0038] In addition, to achieve the above object, the application further provides a storage medium, which is a computer readable storage medium, and a computer program is stored on the storage medium, and the computer program is executed by a processor to implement the steps of the application behavior detection method.

[0039] In addition, to achieve the above object, the application further provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps of the application behavior detection method.

[0040] The one or more technical solutions provided by the application have at least the following technical effects:

[0041] The application embodiment provides an application behavior detection method, device, equipment and computer program product, target behavior data of a target application is acquired, baseline calculation is performed based on historical behavior data of the target application, an application behavior baseline of the target application is determined, the target behavior data and the application behavior baseline are compared, and target processing is performed on the target application based on a comparison result. The application behavior baseline is determined by performing baseline calculation on the historical behavior data, and the application behavior baseline is updated along with the update of the historical behavior data. Compared with a static baseline template, the application behavior detection false alarm rate in a variable scene can be reduced. BRIEF DESCRIPTION OF DRAWINGS

[0042] The accompanying drawings incorporated in the specification hereof and forming a part thereof illustrate embodiments consistent with the application and together with the description serve to explain the principles of the application.

[0043] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the accompanying drawings required by the embodiments or the prior art description will be briefly introduced hereinafter. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without creative labor.

[0044] Figure 1 A flowchart is provided for the application behavior detection method embodiment one of the application;

[0045] Figure 2 A flowchart is provided for the application behavior detection method embodiment one of the application;

[0046] Figure 3 A flowchart is provided for the application behavior detection method embodiment one of the application;

[0047] Figure 4A schematic diagram of the module structure of the behavior detection device used in the embodiment of the present application;

[0048] Figure 5 Schematic diagram of the device structure of the hardware operating environment involved in the behavior detection method applied in the embodiments of the present application.

[0049] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0050] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.

[0051] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0052] The main solution of the embodiment of the present application is: obtaining target behavior data of the target application; performing baseline calculation based on the historical behavior data of the target application to determine the application behavior baseline of the target application; comparing the target behavior data with the application behavior baseline, and performing target processing on the target application based on the comparison result.

[0053] In this embodiment, for ease of description, the following description is made with the application behavior detection device as the execution subject.

[0054] In the field of network security, as cyberattacks become increasingly complex and diverse, traditional security protection technologies face significant challenges. Baseline-based anomaly detection technology, as an important security protection measure, is widely used to identify anomalous behavior in applications. However, traditional baseline construction methods often rely on predefined rules or static baseline templates, which can lead to high false positive rates when faced with highly variable application behavior.

[0055] This application provides a solution that calculates the baseline through historical behavior data to obtain the application behavior baseline. The application behavior baseline is updated as the historical behavior data is updated. Compared with the static baseline template, it can adapt to changing scenarios and reduce the false alarm rate of application behavior detection in changing scenarios.

[0056] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, mobile phone, etc., or an electronic device capable of implementing the above functions, an application behavior detection device, etc. The following uses the application behavior detection device as an example to illustrate this embodiment and the following embodiments.

[0057] Based on this, the application embodiment provides an application behavior detection method, referring to Figure 1 , Figure 1 The flowchart of the first embodiment of the application behavior detection method.

[0058] In this embodiment, the application behavior detection method includes steps S11-S13:

[0059] Step S11, obtaining target behavior data of a target application.

[0060] It should be noted that in the present embodiment, the target application refers to an application program that needs to be behavior detected, and the target behavior data refers to various behavior records generated by the application program during the running process, including but not limited to file operations, network access, command execution, JNDI loading, deserialization, etc. These behavior data are important basis for subsequent baseline calculation and anomaly detection. Real-time acquisition of these data is to discover abnormal behaviors in application running in time, and to ensure the security and stability of the application. In this embodiment, the device collects the behavior data of the application in real time through the RASP (Runtime Application Self-Protection, application runtime self-protection) technology, and stores it in the ES database for subsequent processing and analysis. This real-time acquisition method can ensure the timeliness and accuracy of the data, and provide reliable data support for subsequent detection.

[0061] In different implementation scenarios, the source and collection method of the target behavior data may be different. In one possible implementation, the system can collect behavior data by deploying special monitoring agents on the application server. These agents can monitor the running state of the application in real time, and transmit the collected behavior data to the central database. In another implementation, the system can collect behavior data by using the existing log management system, and extract the required behavior information by parsing the application log file. Regardless of which method is used, the key is to ensure that the collected behavior data can comprehensively cover various behavior patterns of the application, so that the subsequent detection can accurately identify abnormal behaviors.

[0062] Specifically, the device collects the behavior data of the target application in real time through the RASP (Runtime Application Self-Protection, application runtime self-protection) technology, and stores it in the ES (Elasticsearch, Elasticsearch) database. The RASP technology can monitor and record the behavior of the application in real time during the application running, ensuring the timeliness and accuracy of the data.

[0063] For example, in a specific embodiment, assume that the target application is an online payment system, which generates a large amount of behavior data during operation, such as user login, transaction query, payment operation, etc. Through the RASP technology, the system can collect these behavior data in real time and store them in the ES database. These data will serve as the basis for subsequent baseline calculation and anomaly detection, helping the system to discover potential security threats, such as abnormal login attempts or illegal payment operations, in a timely manner.

[0064] Step S12, based on the historical behavior data of the target application, baseline calculation is performed to determine the application behavior baseline of the target application,

[0065] It should be noted that the historical behavior data refers to the behavior records generated by the target application in the past period of time, which is used to construct the normal behavior pattern of the application. The purpose of baseline calculation is to determine the behavior characteristics of the application in the normal running state by analyzing the historical behavior data, so as to provide a reference for subsequent anomaly detection.

[0066] In addition, it should be noted that the application behavior baseline is constructed based on the historical behavior data, which is a model used to describe the behavior characteristics of the application in the normal running state, including the behavior category baseline and the behavior pattern baseline. The behavior category baseline is used to describe the execution of the application under different behavior categories, and the behavior pattern baseline is used to describe the common characteristics and change parameter bits of different behavior instances under the same behavior category. By constructing these baselines, the system can more accurately identify abnormal behaviors that deviate from the normal behavior pattern.

[0067] Specifically, the historical behavior data of the target application is obtained from the first database; the historical behavior data is statistically analyzed based on a first time window to determine the target execution frequency corresponding to the historical behavior data; the target learning duration of the historical behavior data is dynamically adjusted based on the target execution frequency; and the historical behavior data and the target learning duration are compared to determine the application behavior baseline corresponding to the historical behavior data.

[0068] For example, in a specific embodiment, assume that the target application is an enterprise resource planning system, which has generated a large amount of behavior data in the past three months, including file operation, network access, command execution, etc. The system obtains these historical behavior data from the ES database, and then performs statistical analysis based on a one-month time window to determine the execution frequency of each behavior category. According to these execution frequencies, the system dynamically adjusts the learning duration and finally determines it as two months. In these two months, the system compares the historical behavior data to determine the behavior category baseline and the behavior pattern baseline. These baselines will serve as a reference for subsequent anomaly detection, helping the system to discover abnormal behaviors in the ERP system, such as unauthorized file access or abnormal network activity, in a timely manner.

[0069] Step S13, comparing the target behavior data with the application behavior baseline, and performing target processing on the target application based on the comparison result.

[0070] It should be noted that in the embodiments of the present application, the target processing refers to performing corresponding processing on the abnormal behavior according to the comparison result, such as alarm, recording or blocking, etc. The purpose of comparison is to identify abnormal behavior deviating from normal behavior pattern by comparing target behavior data with application behavior baseline. This process can ensure that potential security threats can be discovered and handled in time during the running of the application, thereby ensuring the security and stability of the application.

[0071] Specifically, the target behavior data and the application behavior baseline are compared to obtain a behavior detection result of the target application; if the behavior detection result is a behavior detection anomaly, each behavior detection result is aggregated for alarm in a preset alarm dimension, target alarm information of the target application is generated and sent to an alarm platform.

[0072] For example, in a specific embodiment, assuming that the target application is a content management system, the target behavior data collected by the system in real time includes user uploading files, editing content and other operations. The system compares these target behavior data with the previously constructed application behavior baseline and finds that a user has uploaded an abnormally large file, and the uploading behavior of the file does not conform to the normal behavior pattern in the behavior baseline. After the system identifies this abnormal behavior, it performs alarm aggregation according to the preset alarm dimension, generates target alarm information, and sends these information to the alarm platform. At the same time, the system processes the unstructured behavior data through a large model to further confirm whether the behavior is a false alarm. If it is confirmed as an abnormal behavior, the system can take corresponding processing measures, such as blocking the user's uploading operation, to ensure the safe operation of the system.

[0073] Through the above scheme, the application behavior baseline is obtained by baseline calculation based on historical behavior data, and the application behavior baseline is updated as the historical behavior data is updated. Compared with a static baseline template, it can adapt to variable scenarios and reduce the false alarm rate of application behavior detection in variable scenarios.

[0074] Based on the above implementation scheme, in a feasible implementation, the step of performing baseline calculation based on the historical behavior data of the target application to determine the application behavior baseline of the target application includes steps S21-S24:

[0075] Step S21, obtaining the historical behavior data of the target application from the first database.

[0076] It should be noted that the first database generally refers to an ES (Elasticsearch) database, which can also be referred to as a non-relational database, and is used to store unstructured or semi-structured data.

[0077] Specifically, the historical behavior data of the target application is obtained from the ES database, which includes file operations, network access, command execution, JNDI (Java Naming and Directory Interface) loading, deserialization, and other behaviors.

[0078] For example, in a specific embodiment, it is assumed that the target application is an online payment system that generates a large amount of behavior data such as user login, transaction query, payment operation, etc. during operation. These behavior data are collected in real time through RASP technology and stored in the ES database. The device obtains these historical behavior data from the ES database for subsequent baseline calculation to determine the behavior characteristics of the application in the normal operation state.

[0079] Step S22, based on the first time window, the statistical analysis of the historical behavior data is performed to determine the target execution frequency corresponding to the historical behavior data.

[0080] It should be noted that in the embodiments of the present application, the first time window refers to the time range for statistical analysis of historical behavior data, which can be set according to the characteristics and requirements in the application basic information of the target application. In an embodiment of the present application, the application basic information of the application is obtained through RASP technology.

[0081] The target execution frequency refers to the total number of executions of all behavior categories within the first time window. By statistically analyzing the historical behavior data, the device can determine the total execution frequency of all behavior categories, thereby providing data support for subsequent baseline calculation. The purpose of this step is to understand the behavior pattern of the application in the normal operation state, so as to more accurately identify abnormal behavior subsequently.

[0082] Specifically, based on the application basic information of the target application, the first time window is determined, and based on the preset first time window (such as one month), the historical behavior data of the application is statistically analyzed to calculate and determine the execution frequency of the application behavior.

[0083] Step S23, based on the target execution frequency, dynamically adjusting the target learning duration of the historical behavior data.

[0084] It should be noted that the target learning duration refers to the learning time range of the historical behavior data dynamically adjusted by the device according to the target execution frequency.

[0085] Specifically, the device dynamically adjusts the learning duration according to the change trend of the target execution frequency. In an embodiment of the present application, if the execution frequency of the application behavior is high and changes frequently, the learning duration is extended so as to more comprehensively capture the change of the behavior pattern; if the execution frequency of the behavior is low and relatively stable, the learning duration is shortened.

[0086] In step S24, the historical behavior data and the target learning duration are compared to determine the application behavior baseline corresponding to the historical behavior data.

[0087] Specifically, the application learning duration of the historical behavior data and the target learning duration are compared, and when the application learning duration is greater than the target learning duration, the execution frequency of the behavior in the application learning duration is calculated; the execution frequency of the behavior and the target execution frequency are compared and determined, and when the execution frequency of the behavior is greater than the target execution frequency, the historical behavior data is baseline calculated to generate the application behavior baseline corresponding to the historical behavior data.

[0088] Through the above scheme, the baseline can be automatically optimized in learning range according to the change of the behavior frequency by dynamically adjusting the learning duration, so as to avoid misjudgment caused by outdated data or insufficient samples.

[0089] Based on the above implementation scheme, in a feasible implementation, the step of comparing the historical behavior data and the target learning duration to determine the application behavior baseline corresponding to the historical behavior data includes S31-S32.

[0090] In step S31, the application learning duration of the historical behavior data and the target learning duration are compared, and when the application learning duration is greater than the target learning duration, the execution frequency of the behavior in the application learning duration is calculated.

[0091] It should be noted that the application learning duration refers to the time range of actually analyzing and learning the application historical behavior data when the behavior baseline is constructed.

[0092] In addition, it should be noted that the execution frequency of the behavior refers to the execution frequency of the application behavior within the application learning duration. For example, a certain application has executed 100 behavior operations in the past 30 days, and the execution frequency of the behavior of the application is 100 times.

[0093] Specifically, first, the actual learning duration of the historical behavior data (application learning duration) is acquired and compared with the determined target learning duration. If the application learning duration is greater than the target learning duration, it indicates that the system has sufficient historical data for baseline calculation. The number of executions of each behavior category within the application learning duration is counted to generate the total behavior execution frequency. For example, the device counts that the file operation behavior has been executed 120 times and the network access behavior has been executed 240 times within the past 60 days.

[0094] In step S32, the behavior execution frequency and the target execution frequency are compared and determined. When the behavior execution frequency is greater than the target execution frequency, the historical behavior data is subjected to baseline calculation to generate the application behavior baseline corresponding to the historical behavior data.

[0095] Specifically, the counted behavior execution frequency is compared with the preset target execution frequency. If the behavior execution frequency is greater than the target execution frequency, it indicates that the execution frequency is high enough for baseline calculation. The historical behavior data is subjected to baseline calculation to generate the application behavior baseline. The historical behavior data is traversed based on the preset behavior categories to determine the number of executions of the historical behavior data in the corresponding behavior categories, thereby generating the behavior category baseline corresponding to the historical behavior data. The historical behavior data is classified according to the behavior categories, and the classified historical behavior data is compared and merged to generate the behavior pattern baseline of the historical behavior data.

[0096] For better understanding, please refer to Figure 2 , Figure 2 The flowchart of dynamically adjusting the application learning duration to determine the application behavior baseline is provided for one embodiment of the application behavior detection method. First, the application behavior data of each day is acquired and stored in a first database. It is determined whether the application learning duration of the target application based on the updated behavior data in the first database within a period of time exceeds the target learning duration. If not, the application continues to learn. When the application learning duration exceeds the target learning duration, the behavior execution frequency in the application learning duration is counted. It is determined whether the behavior execution frequency is greater than the target execution frequency. If not, the application learning duration is increased until the behavior execution frequency is greater than the target execution frequency, and then the incrementally updated application behavior baseline is generated.

[0097] Through the above scheme, the target learning duration is dynamically adjusted according to the historical behavior data, and the baseline is calculated according to the actual behavior execution frequency to generate more accurate behavior category baseline and behavior pattern baseline. This helps the system to more effectively identify abnormal behaviors and improve the accuracy and adaptability of abnormal detection.

[0098] Based on the above embodiments, in a feasible implementation, the application behavior baseline includes a behavior category baseline and a behavior pattern baseline, and the step of performing baseline calculation on the historical behavior data to generate the application behavior baseline corresponding to the historical behavior data includes S41-S42:

[0099] In step S41, the historical behavior data is traversed based on the preset behavior category, the execution times of the historical behavior data in the corresponding behavior category are determined, and the behavior category baseline corresponding to the historical behavior data is generated.

[0100] It should be noted that the preset behavior category refers to a category defined in advance for classifying application behaviors, including but not limited to application network access, JNDI loading, deserialization, file operation, command execution, and the like.

[0101] In addition, it should be noted that the behavior category baseline refers to a baseline constructed based on historical behavior data, used to describe the execution of the application in different behavior categories. For example, whether the application has executed file operation, network access, command execution, and the like in the past period of time is counted.

[0102] In addition, it should be noted that the behavior pattern baseline refers to a baseline constructed based on historical behavior data, used to describe the common features and change parameter bits of different behavior instances in the same behavior category. For example, for the file operation behavior, the behavior pattern baseline can describe the file path, file size, operation time, and the like.

[0103] Specifically, the device traverses the historical behavior data according to the preset behavior category (such as file operation, network access, command execution, and the like), for each behavior category, the device counts the execution times of behaviors in the category, and according to the execution times, counts whether the historical behavior data of the target application has executed a behavior of a certain category (file operation, network access, command execution, JNDI, port access, deserialization), and according to whether the historical behavior data has executed a behavior of a certain category, generates a behavior category baseline.

[0104] In step S42, the historical behavior data is classified according to the behavior category, the classified historical behavior data is compared and merged, and the behavior pattern baseline of the historical behavior data is generated.

[0105] Specifically, the historical behavior data is classified according to the behavior category to generate target category data; the behavior features such as file path, file size, operation time, and the like are extracted from each target instance of the target category data; the behavior features of each target instance are compared to determine the common features and change parameter bits; the behavior features are merged based on the common features and change parameter bits to obtain a behavior category template; and the behavior pattern baseline is generated based on each behavior category template.

[0106] The embodiment can generate a behavior pattern baseline by classifying and merging, describe common characteristics and change parameter bits of different behavior instances under the same behavior category, more accurately identify abnormal behaviors, and improve the adaptability and accuracy of the baseline; the behavior category baseline and the behavior pattern baseline combine the execution times of the behavior category and the characteristics of the behavior instances, provide multi-dimensional analysis, more comprehensively identify abnormal behaviors, and reduce false positives and false negatives.

[0107] Based on the above implementation, in a feasible implementation, the step of classifying the historical behavior data according to the behavior category, merging the classified historical behavior data, and generating a behavior pattern baseline of the historical behavior data includes S51-S54:

[0108] Step S51, classifying the historical behavior data according to the behavior category, and generating target category data corresponding to the behavior category.

[0109] It should be noted that the target category data refers to the historical behavior data classified according to the behavior category.

[0110] Specifically, the historical behavior data is classified according to a preset behavior category (such as file operation, network access, command execution, etc.); target category data corresponding to each behavior category is generated, that is, behavior data of the same category is grouped.

[0111] Step S52, extracting behavior features from each target instance of the target category data, comparing the behavior features of each target instance, and determining common characteristics and change parameter bits of the target category data.

[0112] It should be noted that the target instance refers to each specific behavior instance in the target category data. The behavior feature refers to a feature extracted from the behavior instance for describing the behavior, such as the timestamp of the behavior, the subject of the behavior, the object of the behavior, etc.

[0113] In addition, it should be noted that the common characteristics of the target category data refer to the characteristics common to all behavior instances under the same category. The change parameter bit refers to the change part between different behavior instances under the same category.

[0114] Specifically, the behavior features such as the timestamp of the behavior, the subject of the behavior, and the object of the behavior are extracted from each target instance; the behavior features of each target instance are compared to determine the common characteristics and the change parameter bits. For example, for file operation behavior, the common characteristics may be that the operation time is within working hours, and the change parameter bits may be the file path and the file size.

[0115] Step S53, merging the behavior features based on the common features and the change parameter bits, to obtain a behavior category template corresponding to the target category data.

[0116] It should be noted that the behavior category template refers to a template generated based on common features and change parameter bits, used to describe the behavior pattern under the same category.

[0117] Specifically, the behavior features are merged based on the common features and the change parameter bits to generate the behavior category template. For example, the template of the file operation behavior can include file path, file size, operation time and other features.

[0118] Step S54, based on the behavior category template of each target category data, the behavior pattern baseline of the historical behavior data is generated by combination.

[0119] Specifically, the behavior category templates are combined to generate the behavior pattern baseline. For example, the behavior pattern baseline can include file operation behavior template, network access behavior template and command execution behavior template, describing the behavior pattern of the application under different behavior categories.

[0120] Through the above scheme, the system can generate a more accurate behavior pattern baseline by category division and comparison and merging, reflecting the behavior pattern of the application under different behavior categories. The dynamically generated behavior pattern baseline can adapt to the change of the application behavior pattern, improving the adaptability and accuracy of the baseline.

[0121] Based on the above implementation scheme, in a feasible implementation, the step of comparing the target behavior data with the application behavior baseline, and performing target processing on the target application based on the comparison result, includes S61-S62:

[0122] Step S61, comparing the target behavior data with the application behavior baseline to obtain a behavior detection result of the target application.

[0123] It should be noted that the behavior detection result refers to the result obtained after comparison, used to indicate whether the target behavior data is abnormal.

[0124] Specifically, the target behavior data collected in real time is compared with the application behavior baseline item by item. The purpose of comparison is to identify the behavior data that does not conform to the baseline, i.e. abnormal behavior. The comparison result will generate a behavior detection result, indicating whether the target behavior data is abnormal.

[0125] Step S62, if the behavior detection result is a behavior detection anomaly, each of the behavior detection results is aggregated for alarm in a preset alarm dimension, target alarm information of the target application is generated, and the target alarm information is sent to an alarm platform.

[0126] It should be noted that the preset alarm dimension refers to a dimension for aggregating alarm information, such as application name, time, behavior type, etc.

[0127] In addition, it should be noted that the target alarm information refers to the aggregated alarm information, which is used to notify relevant personnel or system of abnormal behavior.

[0128] In addition, it should be noted that the alarm platform refers to a platform for receiving and processing alarm information.

[0129] Specifically, if an abnormal behavior is detected, the device will aggregate the abnormal behavior according to the preset alarm dimension (such as application name, time, behavior type, etc.) to generate target alarm information, which includes detailed information of the abnormal behavior, such as behavior type, occurrence time, behavior subject, etc. The target alarm information is sent to the alarm platform to notify relevant personnel or system of the abnormal behavior.

[0130] The above scheme is used to compare the target behavior data with the application behavior baseline, and generate alarm information when an abnormal behavior is detected. The system can more accurately identify abnormal behavior, timely discover and handle potential security threats, and improve the automation level and overall performance of the system.

[0131] Based on the above implementation scheme, in a feasible implementation, the application behavior detection method further includes S71-S74:

[0132] Step S71, obtaining unstructured behavior data in the target behavior data by a large model.

[0133] It should be noted that the large model refers to a machine learning model for processing unstructured data, such as an NLP (Natural Language Processing) model, which can extract and understand information in unstructured data.

[0134] In addition, it should be noted that the unstructured behavior data refers to data in the target behavior data that does not conform to a structured format, such as log text, user input, etc.

[0135] Specifically, the large model is used to extract unstructured behavior data that is difficult to construct from the target behavior data.

[0136] Step S72, the unstructured behavior data is associated with an external data source, normal behavior data in the unstructured behavior data is filtered, and the to-be-detected behavior data in the unstructured behavior data is obtained.

[0137] It should be noted that the external data source refers to a data source for assisting in judging whether the behavior data is normal, such as a user behavior database, a security threat intelligence library, etc.

[0138] In addition, it should be noted that the normal behavior data refers to the behavior performed by the user or other entities in the conventional running process of the application, which conforms to the use mode and security policy expected in the design of the application.

[0139] In addition, it should be noted that the to-be-detected behavior data refers to the unstructured behavior data after filtering, which needs to be further detected to determine whether it is abnormal behavior.

[0140] Specifically, the unstructured behavior data is associated with an external data source (such as a user behavior database, a terminal, a server, etc.). Through association analysis, the known normal behavior data is filtered out, and the to-be-detected behavior data that needs to be further detected is extracted.

[0141] Step S73, the to-be-detected behavior data is subjected to execution frequency calculation by a frequency model, and the to-be-detected execution frequency of the to-be-detected behavior data is obtained.

[0142] It should be noted that the frequency model refers to a model for calculating the execution frequency of behavior data, which is usually based on a statistical analysis method. The to-be-detected execution frequency refers to the execution frequency of the to-be-detected behavior data.

[0143] Specifically, the to-be-detected behavior data includes behavior categories not included in the pre-set behavior categories,

[0144] The execution frequency of the to-be-detected behavior data is calculated by using the frequency model, and the to-be-detected execution frequency of the to-be-detected behavior data is obtained.

[0145] Step S74, when the to-be-detected execution frequency is greater than a pre-set frequency threshold, it is determined that the to-be-detected behavior data is normal behavior data.

[0146] It should be noted that the frequency threshold refers to a pre-set execution frequency threshold, which is used to judge whether the behavior data is normal behavior.

[0147] Specifically, the execution frequency of the to-be-detected behavior data is compared with the pre-set frequency threshold; if the execution frequency of the to-be-detected behavior data is greater than the frequency threshold, it is determined as normal behavior data.

[0148] The above scheme can be used to process unstructured behavior data by a large model (such as a deep learning model), so as to more deeply understand and analyze complex patterns and potential threats in the data. For example, a natural language processing model can analyze the text content in the log and identify possible abnormal behavior descriptions. In combination with correlation analysis of external data sources, normal behavior data can be more accurately filtered out, thereby reducing false positives. At the same time, by further verifying the execution frequency of the behavior data to be detected by the frequency model, the false positive rate can be effectively reduced.

[0149] For the purpose of facilitating understanding of the implementation process of the application behavior detection method obtained by combining the above-mentioned embodiment one, please refer to Figure 3 , Figure 3 A brief flowchart of an application behavior detection method is provided, and specifically:

[0150] First, the target behavior data of the target application is collected in real time by the RASP technology, and data processing is performed. In an embodiment of the present application, the behavior data is obtained by collecting various application behavior logs by the RASP, the formatted behavior data is extracted, and the data is enriched according to the application dimension. After data processing, dynamic learning duration judgment is performed based on the application basic information library. The behavior category baseline judgment is performed based on the behavior category baseline library to determine which preset behavior category the behavior data belongs to. Then, the target behavior data is compared with the baseline in the behavior pattern baseline library to determine whether the behavior of the application is abnormal. If it is abnormal, the alarm information of multiple behaviors is aggregated for alarm aggregation. The alarm information is sent to the alarm platform, and there is a corresponding false positive elimination strategy for each behavior data to reduce the false positive rate. At the same time, the collected target behavior data is also stored in the ES database as historical behavior data. The application behavior baseline is updated based on the historical behavior data at a fixed time period. The fixed time period can be one hour, one day, one week, 30 days, etc. Generally, the fixed time period is 24 hours per day, and the historical behavior data is incrementally updated at a fixed time point every day to update the application behavior baseline. The baseline is calculated based on the historical behavior data of the ES database to obtain the application basic information, generate the application basic information library, obtain the behavior category baseline, generate the behavior category baseline library, and obtain the behavior pattern baseline to generate the behavior pattern baseline library.

[0151] It should be noted that the above examples are only used to understand the present application and do not limit the application behavior detection method. Further simple transformations based on this technical concept are within the scope of the present application.

[0152] The present application also provides an application behavior detection device, please refer to Figure 4 , the application behavior detection device comprises:

[0153] The data acquisition module 401 is configured to acquire target behavior data of a target application.

[0154] The baseline calculation module 402 is configured to perform baseline calculation based on historical behavior data of the target application, and determine an application behavior baseline of the target application.

[0155] The baseline comparison module 403 is configured to compare the target behavior data and the application behavior baseline, and perform target processing on the target application based on a comparison result.

[0156] The application behavior detection device provided in the present application adopts the application behavior detection method in the above embodiments, and can solve the technical problem of high false alarm rate of application operation detection. Compared with the prior art, the application behavior detection device provided in the present application has the same beneficial effects as the application behavior detection method provided in the above embodiments, and other technical features in the application behavior detection device are the same as the features disclosed in the above embodiments, which will not be repeated here.

[0157] The present application provides an application behavior detection device, which comprises at least one processor and a memory in communication connection with the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the application behavior detection method in the above embodiment one.

[0158] Reference will be made to the following description of the embodiments of the present application. Figure 5 The application behavior detection device in the embodiments of the present application can include but is not limited to mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description), PMPs (Portable Media Player), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and the like, and fixed terminals such as digital TVs, desktop computers, and the like. Figure 5 The application behavior detection device shown is only an example, and should not bring any limitation to the functions and use range of the embodiments of the present application.

[0159] As shown in FIG. 1, the application behavior detection device can include a data acquisition module 401, a baseline calculation module 402, a baseline comparison module 403, and a target processing module 404. Figure 5As shown, the application behavior detection device can include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to programs stored in a read-only memory 1002 or loaded from a storage device 1003 into a random access memory 1004. Various programs and data required for the operation of the application behavior detection device are also stored in the random access memory 1004. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. An input / output interface 1006 is also connected to the bus. Generally, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; the storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the application behavior detection device to communicate wirelessly or wired with other devices to exchange data. Although the application behavior detection device with various systems is shown in the figure, it should be understood that all the shown systems are not required to be implemented or possessed. More or less systems can be alternatively implemented or possessed.

[0160] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are performed.

[0161] The application behavior detection device provided by the present application adopts the application behavior detection method in the above-mentioned embodiments, and can solve the technical problem of high false alarm rate of application operation detection. Compared with the prior art, the application behavior detection device provided by the present application has the same beneficial effects as the application behavior detection method provided by the above-mentioned embodiments, and other technical features in the application behavior detection device are the same as the features disclosed in the previous embodiment method, which will not be repeated here.

[0162] It should be understood that various parts of the present disclosure can be implemented in hardware, software, firmware, or a combination thereof. In the above description of embodiments, specific functional, structural, material or characteristic features are combined in a manner that is appropriate for the particular embodiment or examples. However, each feature can also be implemented individually or in any combination.

[0163] The above description is merely illustrative of the application and is not intended to limit the scope of the application. Any variations and modifications that can be made by those skilled in the art without departing from the spirit and scope of the application are intended to be included in the scope of the application. The scope of the application is defined by the appended claims.

[0164] The present application provides a computer-readable storage medium having stored thereon computer-readable program instructions (i.e., a computer program) for performing the behavior detection method of the application in the above-described embodiments.

[0165] The computer-readable storage medium provided by the present application may, for example, be a U disk, but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system or device, or any combination thereof. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present embodiment, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted in any suitable medium, including but not limited to an electrical wire, an optical cable, an RF (Radio Frequency) cable, etc., or any suitable combination thereof.

[0166] The above-described computer-readable storage medium can be included in the behavior detection device of the application or can exist separately without being assembled into the behavior detection device of the application.

[0167] The computer readable storage medium described above carries one or more programs, when the one or more programs are executed by the behavior detection device, cause the behavior detection device to: acquire target behavior data of a target application; perform baseline calculation based on historical behavior data of the target application, to determine an application behavior baseline of the target application; compare the target behavior data with the application behavior baseline, and perform target processing on the target application based on a comparison result.

[0168] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0169] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present application. In this regard, each block in the flow diagrams or block diagrams can represent a module, a procedure, or a part of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in a different order than that noted in the figures. For example, two blocks noted in succession can in fact be executed substantially concurrently or in the opposite order, depending on the functionality involved. It is also noted that each block in the block diagrams and / or flow diagrams, and combinations of blocks in the block diagrams and / or flow diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0170] The modules involved in the embodiments of the present application can be implemented in the form of software or in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.

[0171] The readable storage medium provided by the application is a computer readable storage medium, which stores computer readable program instructions (i.e. computer programs) for executing the behavior detection method of the application, and can solve the technical problem of high false alarm rate of application operation detection. Compared with the prior art, the computer readable storage medium provided by the application has the same beneficial effects as the behavior detection method of the application provided by the above-mentioned embodiments, and will not be repeated here.

[0172] The application also provides a computer program product comprising a computer program, which, when executed by a processor, implements the steps of the behavior detection method of the application as described above.

[0173] The computer program product provided by the application can solve the technical problem of high false alarm rate of application operation detection. Compared with the prior art, the computer program product provided by the application has the same beneficial effects as the behavior detection method of the application provided by the above-mentioned embodiments, and will not be repeated here.

[0174] The above-mentioned is only part of the embodiments of the application, and does not limit the patent scope of the application, and any equivalent structural transformation, direct / indirect application in other related technical fields within the technical concept of the application, and the contents of the specification and drawings of the application are included in the patent protection scope of the application.

Claims

1. A method for detecting application behavior, characterized in that: The behavior detection method of the application includes: Obtain target behavior data of the target application; Performing a baseline calculation based on the historical behavior data of the target application to determine an application behavior baseline of the target application; The target behavior data is compared with the application behavior baseline, and target processing is performed on the target application based on the comparison result.

2. The application behavior detection method according to claim 1, characterized in that: The step of performing baseline calculation based on the historical behavior data of the target application to determine the application behavior baseline of the target application includes: Acquire historical behavior data of the target application from a first database; performing statistical analysis on the historical behavior data based on a first time window to determine a target execution frequency corresponding to the historical behavior data; Dynamically adjusting the target learning duration of the historical behavior data based on the target execution frequency; The historical behavior data is compared with the target learning duration to determine an application behavior baseline corresponding to the historical behavior data.

3. The application behavior detection method according to claim 2, characterized in that: The step of comparing the historical behavior data with the target learning duration to determine the application behavior baseline corresponding to the historical behavior data includes: Comparing the application learning duration of the historical behavior data with the target learning duration, and when the application learning duration is greater than the target learning duration, calculating the behavior execution frequency within the application learning duration; The behavior execution frequency is compared with the target execution frequency. When the behavior execution frequency is greater than the target execution frequency, a baseline calculation is performed on the historical behavior data to generate an application behavior baseline corresponding to the historical behavior data.

4. The application behavior detection method according to claim 3, characterized in that: The application behavior baseline includes a behavior category baseline and a behavior pattern baseline. The step of performing baseline calculation on the historical behavior data to generate the application behavior baseline corresponding to the historical behavior data includes: Traversing the historical behavior data based on preset behavior categories, determining the number of executions of the historical behavior data under the corresponding behavior category, and generating a behavior category baseline corresponding to the historical behavior data; The historical behavior data is categorized according to the behavior categories, and the categorized historical behavior data is compared and merged to generate a behavior pattern baseline of the historical behavior data.

5. The application behavior detection method according to claim 4, characterized in that: The steps of classifying the historical behavior data according to the behavior categories, comparing and merging the classified historical behavior data, and generating a behavior pattern baseline of the historical behavior data include: Classify the historical behavior data according to the behavior category, and generate target category data corresponding to the behavior category; extracting behavioral features from each target instance of the target category data, comparing the behavioral features of each target instance, and determining common features and change parameter bits of the target category data; Merging the behavior features based on the common features and the change parameter bits to obtain a behavior category template corresponding to the target category data; Based on the behavior category templates of each of the target category data, a behavior pattern baseline of the historical behavior data is generated in combination.

6. The application behavior detection method according to claim 1, characterized in that: The step of comparing the target behavior data with the application behavior baseline and performing target processing on the target application based on the comparison result includes: Comparing the target behavior data with the application behavior baseline to obtain a behavior detection result of the target application; If the behavior detection result is a behavior detection anomaly, each behavior detection result is aggregated according to a preset alarm dimension to generate target alarm information of the target application and send the target alarm information to the alarm platform.

7. The application behavior detection method according to claim 1, characterized in that: The application behavior detection method further includes: Acquiring unstructured behavior data in the target behavior data through a large model; Associating the unstructured behavior data with an external data source, filtering normal behavior data in the unstructured behavior data, and obtaining behavior data to be detected in the unstructured behavior data; Calculating the execution frequency of the behavior data to be detected by using a frequency model to obtain the execution frequency of the behavior data to be detected; When the execution frequency to be detected is greater than a preset frequency threshold, it is determined that the behavior data to be detected is normal behavior data.

8. An application behavior detection device, characterized in that: The application behavior detection device includes: A data acquisition module is used to obtain target behavior data of a target application; A baseline calculation module, configured to perform baseline calculation based on the historical behavior data of the target application to determine the application behavior baseline of the target application; The baseline comparison module is used to compare the target behavior data with the application behavior baseline, and perform target processing on the target application based on the comparison result.

9. An application behavior detection device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the application behavior detection method according to any one of claims 1 to 7.

10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the application behavior detection method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Operation and maintenance risk control method and system based on behavior baseline, medium and product

    CN121478598A