Client anomaly detection method, device and equipment, computer medium and product

By determining user role types and information entropy values ​​in hybrid apps to identify client anomalies, the timeliness and accuracy of anomaly detection in hybrid apps are solved, achieving efficient client anomaly detection.

CN120915566APending Publication Date: 2025-11-07CHINA CONSTRUCTION BANK +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511198446.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing technologies cannot detect client anomalies in a timely manner in hybrid apps, and the accuracy of anomaly detection is low, resulting in inefficiency due to reliance on manual auditing.

Method used

By determining the target user role type of the client, obtaining the target baseline entropy value based on the preset relationship, and combining the information entropy value to judge abnormal client call behavior, the server and client share the task of collecting data, and set the baseline entropy value for different user role types to improve detection accuracy.

Benefits of technology

It enables timely detection of client-side anomalies, improves the accuracy of anomaly detection, reduces manpower consumption and false positives, and enhances security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915566A_ABST
    Figure CN120915566A_ABST
Patent Text Reader

Abstract

The invention discloses a client anomaly detection method, device and equipment, a computer medium and a product, and is applied to the field of client anomaly detection.The method comprises the steps that in response to user identity information logging in a to-be-detected client, a target user role type corresponding to the to-be-detected client is determined; based on the target user role type, a target reference entropy value corresponding to the target user role type is determined from a preset relation, and the preset relation is a corresponding relation between the user role type and the reference entropy value; determining an information entropy value corresponding to an abnormal calling behavior according to the abnormal calling behavior executed by the to-be-detected client in a preset time window when a user of the target user role type logs in the to-be-detected client; under the condition that the information entropy value is greater than the target reference entropy value, the to-be-detected client side is abnormal. According to the method, whether the client is abnormal or not can be found in time, and the accuracy of abnormal detection of the client is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of client exception detection, and particularly relates to a client exception detection method and device, equipment, computer storage medium and computer program product. BACKGROUND

[0002] A hybrid APP (Hybrid Application) is a mobile application development mode that combines the technical advantages of a native APP (Native App) and a web APP (Web App). The hybrid APP builds the basic framework and core functions of the application through native code, and embeds web technology (such as HTML5, CSS, and JavaScript) to develop part of the interface and business logic, thereby achieving a balance between cross-platform operation and efficient development.

[0003] The hybrid APP has advantages such as cross-platform compatibility, hot updating capability, and rapid iteration, but also has some security risks. For example, the flexibility of iteration can lead to malicious code being implanted in the hybrid APP during hot updating, and attackers can use the implanted malicious code to steal data, maliciously manipulate, or engage in other illegal activities, thereby causing security risks to users.

[0004] Currently, the solution to client malicious intrusion mainly involves the following aspects after the intrusion occurs. On the one hand, abnormal situations are found through server log auditing, and then abnormal accounts are disabled for disposal. However, the attacker has already achieved the attack purpose, and it is impossible to achieve the effect of stopping the attacker in time. On the other hand, the existing technology requires log auditors to have strong professional quality, and depends on the ability of the auditors. In addition, the log volume is large, and a large amount of human resources is consumed. Errors or omissions may occur due to fatigue or insufficient professional ability of the auditors, and the detection accuracy of the client exception is low. SUMMARY

[0005] The embodiments of the application provide a client exception detection method, device, equipment, computer storage medium, and computer program product, which can not only discover whether the client is abnormal in time, but also improve the accuracy of client exception detection.

[0006] In a first aspect, the embodiments of the application provide a client exception detection method, which comprises the following steps.

[0007] In response to user identity information of a client to be detected, a target user role type corresponding to the client to be detected is determined.

[0008] Based on the target user role type, a target reference entropy value corresponding to the target user role type is determined from a preset relationship, and the preset relationship is a corresponding relationship between a user role type and a reference entropy value.

[0009] determine an information entropy value corresponding to the abnormal calling behavior according to the abnormal calling behavior performed by the to-be-detected client within the preset time window in which the user of the target user role type logs in the to-be-detected client;

[0010] In a case where the information entropy value is greater than the target reference entropy value, the to-be-detected client is abnormal.

[0011] In some possible implementation manners, the determining the information entropy value corresponding to the abnormal calling behavior according to the abnormal calling behavior performed by the to-be-detected client within the preset time window in which the user of the target user role type logs in the to-be-detected client includes:

[0012] collecting an operation behavior performed by the to-be-detected client within the preset time window in which the user of the target user role type logs in the to-be-detected client;

[0013] In a case where there is an abnormal calling server sensitive data interface behavior in the operation behavior, determining an information entropy value corresponding to the abnormal calling server sensitive data interface of the to-be-detected client.

[0014] In some possible implementation manners, the determining the information entropy value corresponding to the abnormal calling behavior according to the abnormal calling behavior performed by the to-be-detected client within the preset time window in which the user of the target user role type logs in the to-be-detected client includes:

[0015] receiving the information entropy value corresponding to the abnormal calling mobile device sensitive permission of the to-be-detected client sent by the to-be-detected client;

[0016] determining the received information entropy value as the information entropy value corresponding to the abnormal calling behavior.

[0017] In some possible implementation manners, the preset relationship is obtained in the following manner:

[0018] obtaining a user role type;

[0019] determining a set of original information entropy values corresponding to a preset number of normal clients based on the user role type;

[0020] averaging the set of original information entropy values to obtain a reference value of original information entropy as an original reference entropy value;

[0021] determining a reference entropy value corresponding to the user role type based on the original reference entropy value and a preset standard deviation;

[0022] associating the user role type with the corresponding reference entropy value to obtain the preset relationship.

[0023] In some possible implementation manners, the method further includes:

[0024] obtaining a number of normal clients corresponding to the user role type as a normal client number;

[0025] updating the reference entropy value according to a size of the normal client number and a preset number.

[0026] In some possible implementation manners, the updating the reference entropy value according to the size of the normal client number and the preset number includes:

[0027] in a case where the preset number is less than the normal client number, adding the information entropy value corresponding to the to-be-detected client to the original information entropy value set to obtain an updated original information entropy value set as a first updated original information entropy value set;

[0028] changing the preset number to an updated number;

[0029] averaging the first updated original information entropy value set based on the updated number to obtain a reference value of an updated original information entropy as a first updated original reference entropy value;

[0030] determining a first updated reference entropy value corresponding to the user role type based on the first updated original reference entropy value and a preset standard deviation.

[0031] In some possible implementation manners, the method further includes:

[0032] in a case where the preset number is not less than the normal client number, removing an original information entropy value in the original information entropy value set that meets a preset condition in collection time;

[0033] adding the information entropy value corresponding to the to-be-detected client to the original information entropy value set to obtain an updated original information entropy value set as a second updated original information entropy value set;

[0034] averaging the second updated original information entropy value set based on the preset number to obtain a reference value of an updated original information entropy as a second updated original reference entropy value;

[0035] determining a second updated reference entropy value corresponding to the user role type based on the second updated original reference entropy value and a preset standard deviation.

[0036] In some possible implementation manners, the determining the information entropy value corresponding to the abnormal calling of the sensitive data interface of the server by the to-be-detected client includes:

[0037] obtain a name of a service end sensitive data interface called abnormally by the to-be-detected client and a corresponding number of times;

[0038] determine an information entropy value corresponding to the service end sensitive data interface called abnormally by the to-be-detected client based on the name of the service end sensitive data interface called abnormally by the to-be-detected client and the corresponding number of times.

[0039] In some possible implementation manners, the receiving of the information entropy value corresponding to the to-be-detected client abnormally calling the mobile device sensitive permission by the to-be-detected client includes:

[0040] receiving the information entropy value corresponding to the number of times of the to-be-detected client abnormally calling the mobile device sensitive permission sent by the to-be-detected client, the number of times of the to-be-detected client abnormally calling the mobile device sensitive permission being collected by the to-be-detected client.

[0041] In the second aspect, an embodiment of the present application provides a client exception detection device, and the device includes:

[0042] a first determination unit configured to determine a target user role type corresponding to the to-be-detected client in response to user identity information of a user logging in the to-be-detected client;

[0043] a second determination unit configured to determine a target reference entropy value corresponding to the target user role type from a preset relationship based on the target user role type, the preset relationship being a corresponding relationship between a user role type and a reference entropy value;

[0044] a third determination unit configured to determine an information entropy value corresponding to an abnormal calling behavior of the to-be-detected client based on the abnormal calling behavior of the to-be-detected client performed within a preset time window of the user logging in the to-be-detected client in the target user role type;

[0045] a determination unit configured to determine that the to-be-detected client is abnormal in a case where the information entropy value is greater than the target reference entropy value.

[0046] In the third aspect, an embodiment of the present application provides a client exception detection device, and the device includes:

[0047] a processor and a memory storing computer program instructions; and the processor implements the client exception detection method of any one of the preceding embodiments when executing the computer program instructions.

[0048] In the fourth aspect, an embodiment of the present application provides a computer storage medium, and the computer readable storage medium stores computer program instructions, and the computer program instructions are executed by a processor to implement the client exception detection method of any one of the preceding embodiments.

[0049] In a fifth aspect, an embodiment of the present application provides a computer program product. Instructions in the computer program product, when executed by a processor of an electronic device, enable the electronic device to perform the client exception detection method of any one of the above.

[0050] The client exception detection method, device, equipment, computer storage medium and computer program product provided by the embodiments of the present application can determine different reference entropy values based on different user role types corresponding to the client to be detected, then compare the information entropy value corresponding to the abnormal calling behavior of the client to be detected within the preset time window of the user logging in the client to be detected in the target user role type with the reference entropy value, and further determine whether the client to be detected is abnormal. The method uses the information entropy value corresponding to the abnormal calling behavior of the client to be detected to determine the client exception, which can timely determine whether the client is abnormal. At the same time, by setting different reference entropy values for different user role types logging in the client to be detected, the accuracy of the client exception detection can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiments of the present application will be briefly introduced. Those skilled in the art can obtain other drawings according to these drawings without creating any creative labor.

[0052] Figure 1 is a flowchart of the client exception detection method provided by an embodiment of the present application;

[0053] Figure 2 is a flowchart of obtaining a preset relationship provided by an embodiment of the present application;

[0054] Figure 3 is a structural diagram of the client exception detection device provided by another embodiment of the present application;

[0055] Figure 4 is a structural diagram of the client exception detection equipment provided by another embodiment of the present application. DETAILED DESCRIPTION

[0056] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application more clear and apparent, the present application will be further described in detail below with reference to the drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, but not to limit the present application. The present application can be implemented without some of the specific details by those skilled in the art. The following description of the embodiments is only intended to provide a better understanding of the present application by showing examples of the present application.

[0057] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one from another entity or action, without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0058] It should be noted that the acquisition, storage, use and processing of data in the embodiments of the present application comply with the relevant provisions of national laws and regulations.

[0059] It should be noted that in the embodiments of the present application, some industry existing schemes of software, components, models, etc. may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the scheme.

[0060] Hybrid Application is a mobile application development mode that combines the technical advantages of Native App and Web App. It builds the basic framework and core functions of the application through native code, while embedding web technology (such as HTML5, CSS, JavaScript) to develop part of the interface and business logic, achieving a balance between cross-platform operation and efficient development.

[0061] Hybrid Application has cross-platform compatibility, hot update capability, rapid iteration and other advantages, but also has some security risks, for example, the flexibility of iteration can lead to malicious code being implanted in the process of hot updating of Hybrid Application, and attackers can use the implanted malicious code for data theft, malicious manipulation or other illegal activities, causing security risks to users.

[0062] Currently, the solution to the malicious intrusion of the client mainly includes the following two aspects: on the one hand, after the intrusion occurs, the abnormal situation is found through the server log auditing mode, and then the abnormal account is disposed through the disabling mode, but the attacker has achieved the attack purpose, and the effect of stopping the attacker in time cannot be achieved. On the other hand, the existing technology needs the log auditing personnel to have strong professional quality, depends on the ability of the auditing personnel, and the log quantity is large, the human resources consumed are many, there are errors or omissions caused by fatigue or insufficient professional ability of the auditing personnel, and the detection precision of the client exception is low.

[0063] In order to solve the problems in the prior art, the embodiment of the present application provides a client exception detection method, device, equipment, computer storage medium and computer program product.

[0064] Firstly, the client exception detection method provided by the embodiment of the present application is introduced.

[0065] Figure 1 The flowchart of the client exception detection method provided by the embodiment of the present application is shown. As shown in the figure, Figure 1 The method can include the following steps:

[0066] S110, in response to the user identity information of the login client to be detected, determining the target user role type corresponding to the client to be detected.

[0067] In the embodiment, the client to be detected refers to the client currently needing to be detected.

[0068] The user identity information refers to the identification information provided by the user when logging in the client to prove the identity. The user identity information can be the account information of the user, such as the user name, mobile phone number, email, etc., or the authentication information, such as password, verification code, biological feature information (fingerprint, face), Token token, etc.

[0069] The target user role type refers to the category label divided for the user according to the business rule or system setting, which is used to define the permission range, behavior characteristic baseline or business attribute of the user. For example, according to the permission division, the user role type can include: ordinary user, VIP user, administrator, etc.

[0070] It should be noted that the reason why the target user role type corresponding to the client to be detected is determined is that different role types correspond to different operation permissions, for example, the administrator can access the sensitive configuration, and the ordinary user can only use the basic function. After determining the role type, the system can limit the function range of the client to be detected, so as to avoid the overreach operation, for example, the client of the ordinary user role trying to call the administrator interface can be directly intercepted.

[0071] S120, determine a target reference entropy value corresponding to the target user role type from the preset relationship based on the target user role type, the preset relationship being a correspondence between user role types and reference entropy values.

[0072] Information entropy is a quantitative indicator for measuring the uncertainty (or degree of disorder) of a random variable. For client behavior, normal behavior has stable regularity. Normal operation of a client (such as user clicks, system calls, data transmission, etc.) usually follows certain patterns (such as operation frequency, resource access distribution, interaction sequence probability, etc.), and this regularity will make the probability distribution of the behavior relatively concentrated, and the information entropy value will be in a relatively low and stable range. Abnormal behavior (such as malicious attacks, system failures, abnormal operations, etc.) will introduce new patterns, break the original rules (such as sudden high-frequency access to abnormal resources, disordered operation sequences, sudden changes in feature distribution, etc.), causing the probability distribution of the behavior to become dispersed or disordered, and the information entropy value will significantly deviate from the normal range (increase or decrease, depending on the type of anomaly).

[0073] When detecting anomalies in a client based on information entropy, the normal behavior characteristics of different user roles differ significantly, for example, the entropy value of an administrator operation is higher than that of a normal user. After determining the target role type, the system can call the behavior reference of the role, that is, the target reference entropy value corresponding to the target user role type, which can also be referred to as an information entropy reference value or an information entropy threshold value. By setting different reference entropy values for different user role types of the login client to be detected, the administrator reference entropy value is avoided for judging normal user behavior, reducing false positives, and thus the accuracy of client anomaly detection can be improved.

[0074] Referring to Figure 2 In some embodiments, the preset relationship can be obtained in the following manner:

[0075] S1201, obtain a user role type;

[0076] S1202, determine a set of original information entropy values corresponding to a preset number of normal clients based on the user role type;

[0077] For different user roles, the original information entropy values corresponding to d normal clients can be collected to obtain a set of original information entropy values, which can also be referred to as a data queue QC.

[0078] The information entropy value can be obtained using the information entropy formula:

[0079] H(X) = -∑ i P(x i )log2P(x i ) (1)

[0080] S1203, average the original information entropy value set to obtain a reference value of the original information entropy as an original reference entropy value;

[0081] In this embodiment, the reference value of the original information entropy is the average of the d normal client entropy values, that is, the original reference entropy value (which can also be referred to as a threshold value) is obtained by using the following formula:

[0082]

[0083] S1204, determining a reference entropy value corresponding to the user role type based on the original reference entropy value and a preset standard deviation;

[0084] In this embodiment, the reference entropy value corresponding to the user role type is obtained by using the following formula:

[0085] H = H u ± 2σ (3)

[0086] wherein H is the reference entropy value corresponding to the user role type, H u is the original reference entropy value, and σ is the standard deviation.

[0087] S1205, associating the user role type with the corresponding reference entropy value to obtain a preset relationship.

[0088] Since different user role types correspond to different reference entropy values, after associating the user role type with the corresponding reference entropy value, the preset relationship is finally obtained.

[0089] By setting different reference entropy values for different user role types of the login-to-be-detected client, it is avoided to judge the normal user behavior by using the administrator reference entropy value, which can reduce misjudgment and improve the accuracy of the client anomaly detection.

[0090] S130, determining an information entropy value corresponding to the abnormal calling behavior according to the abnormal calling behavior performed by the target user role type of the user of the to-be-detected client within a preset time window of logging into the to-be-detected client.

[0091] In some embodiments, determining an information entropy value corresponding to the abnormal calling behavior according to the abnormal calling behavior performed by the target user role type of the user of the to-be-detected client within a preset time window of logging into the to-be-detected client can include:

[0092] Collecting an operation behavior performed by the target user role type of the user of the to-be-detected client within a preset time window of logging into the to-be-detected client;

[0093] In the case that there is an abnormal calling server sensitive data interface behavior in the operation behavior, determining an information entropy value corresponding to the abnormal calling server sensitive data interface of the to-be-detected client.

[0094] In some embodiments, determining the information entropy value corresponding to the service-side sensitive data interface called abnormally by the to-be-detected client can include:

[0095] Obtaining the name of the service-side sensitive data interface called abnormally by the to-be-detected client and the corresponding number of times;

[0096] Based on the name of the service-side sensitive data interface called abnormally by the to-be-detected client and the corresponding number of times, determining the information entropy value corresponding to the service-side sensitive data interface called abnormally by the to-be-detected client.

[0097] It should be noted that the behavior of the service-side sensitive data interface called abnormally by the to-be-detected client is collected by the service side. The service side collects the name of the service-side sensitive data interface called abnormally by the to-be-detected client and the corresponding number of times within a sliding window, and calculates the corresponding information entropy value, so as to determine whether the to-be-detected client is abnormal according to the information entropy value.

[0098] In this way, the behavior of the service-side sensitive data interface called abnormally by the to-be-detected client is collected by the service side. The service side is the direct receiver of the interface call and can record the call request of the client (including the interface name, the number of times, the timestamp, etc.) completely, avoiding the tampering risk of the local collection of the client and improving the accuracy of the detection.

[0099] In some embodiments, determining the information entropy value corresponding to the abnormal calling behavior can include:

[0100] Receiving the information entropy value corresponding to the mobile device sensitive permission called abnormally by the to-be-detected client sent by the to-be-detected client;

[0101] Determining the received information entropy value as the information entropy value corresponding to the abnormal calling behavior.

[0102] In some embodiments, receiving the information entropy value corresponding to the mobile device sensitive permission called abnormally by the to-be-detected client sent by the to-be-detected client can include:

[0103] Receiving the information entropy value corresponding to the number of times of the mobile device sensitive permission called abnormally by the to-be-detected client sent by the to-be-detected client, and the number of times of the mobile device sensitive permission called abnormally by the to-be-detected client is collected by the to-be-detected client.

[0104] It should be noted that the behavior of the client to be detected abnormally calling the sensitive permissions of the mobile device is collected by the client to be detected, the client to be detected collects the number of times of the client to be detected abnormally calling the sensitive permissions of the mobile device, and the corresponding information entropy value is calculated, and the calculated information entropy value is sent to the server, so that the server judges whether the client to be detected is abnormal based on the information entropy value.

[0105] In this way, the behavior of the client to be detected abnormally calling the sensitive permissions of the mobile device is collected by the client Native layer, and the permission calling of the mobile device (such as calling the camera) is the interaction between the client and the system bottom layer. The Native layer (native code layer) is a direct interface between the client and the device system, and can most accurately capture the raw data of the permission calling (including the calling time, frequency, and triggering scene), avoiding the delay or omission that may exist when the web layer (such as the H5 layer of the Hybrid App) collects, and improving the accuracy of detection.

[0106] In this way, according to the occurrence scene of the abnormal type, the data collection responsibility is allocated to the server and the client, the client and the server calculate the information entropy value from different dimensions respectively, through accurate classification, the pertinence and efficiency of abnormal detection are realized. The server does not need to collect the device permission data (collected by the client locally), and the client does not need to upload the redundant information of the interface calling (recorded directly by the server), reducing the cross-end data transmission amount; the client Native layer collects the permission data and can be directly processed locally (such as counting the number of times), without the need to upload the raw log in full amount, reducing the client energy consumption and network bandwidth occupation; the server focuses on the analysis of the interface calling data, and the client focuses on the analysis of the permission calling data, the division of labor is clear, and the performance bottleneck caused by processing full amount of data by a single party (such as the server) can be avoided.

[0107] S140, in the case that the information entropy value is greater than the target reference entropy value, the client to be detected is abnormal.

[0108] After determining the information entropy value corresponding to the abnormal calling behavior, the information entropy value is compared with the target reference entropy value corresponding to the target user role type. In the case that the information entropy value is greater than the target reference entropy value, the client to be detected is abnormal; in the case that the information entropy value is not greater than the target reference entropy value, the client to be detected is normal.

[0109] It should be noted that in the case that it is determined that the client to be detected is abnormal, an alarm can be issued, and manual intervention is performed to confirm whether the client to be detected is abnormal. In the case that it is confirmed by manual that the client to be detected is indeed abnormal, the client to be detected is marked as abnormal, and in the case that it is confirmed by manual that the client to be detected is indeed not abnormal, the client to be detected is marked as normal.

[0110] In actual application, the different benchmark entropy values corresponding to different user role types can also be updated adaptively according to the collected information entropy. If the information entropy value of the to-be-detected client in the current sliding period is within the range of the benchmark entropy value or is outside the range of the benchmark entropy value but is manually marked as normal, the benchmark entropy value can be updated.

[0111] In some embodiments, the number of normal clients corresponding to the user role type can be acquired as the number of normal clients; and the benchmark entropy value is updated according to the size of the number of normal clients and the preset number.

[0112] In this way, the benchmark entropy value for judging whether to be abnormal is updated according to the collected data, which can make the judgment standard closer to the actual situation and further improve the accuracy of client anomaly detection.

[0113] In some embodiments, updating the benchmark entropy value according to the size of the number of normal clients and the preset number can include:

[0114] In the case where the preset number is less than the number of normal clients, the information entropy value corresponding to the to-be-detected client is added to the original information entropy value set to obtain an updated original information entropy value set as a first updated original information entropy value set;

[0115] The preset number is changed to an updated number;

[0116] The first updated original information entropy value set is averaged based on the updated number to obtain an updated original information entropy benchmark value as a first updated original benchmark entropy value;

[0117] The first updated benchmark entropy value corresponding to the user role type is determined based on the first updated original benchmark entropy value and a preset standard deviation.

[0118] In this embodiment, the preset number can be the sample number selected when the original information entropy value corresponding to the normal client is calculated, for example, d normal client corresponding original information entropy values are selected as samples to obtain a corresponding entropy value queue QC. For example, there are 50 normal original information entropy value samples in the queue of the normal user role, and d = 50.

[0119] The total number of clients can refer to the total number of all "normal clients" under the user role (i.e., the total number of clients recognized by the system, belonging to the role and having no abnormal records). For example, there are 100 normal clients in the normal user role, and the total number of clients = 100.

[0120] When the "update condition" (information entropy value is normal or manually confirmed to be normal) and "current number d < total number of clients" are met, the following operations can be performed:

[0121] Add new samples: add the normal information entropy value of the current client to be detected to the tail of the corresponding role queue QC. For example, the queue QC of the normal user role originally has 50 samples (d = 50), the total number of clients is 100, and the information entropy value is normal this time. The new information entropy value is added to the queue QC, and d becomes 51 at this time.

[0122] Recalculate the reference entropy value and the threshold value: based on the updated queue (containing new samples), recalculate the threshold value (original reference entropy value) of the role. Based on the threshold value, further obtain the reference entropy value, that is, the first updated reference entropy value.

[0123] It should be noted that the determination process of the first updated reference entropy value is similar to the determination process of the reference entropy value described above. For details, please refer to the determination process of the reference entropy value described above, which will not be described here.

[0124] In this way, when the number of samples (d) in the queue has not covered all normal clients of the role, new normal samples are continuously added to gradually "fill" the queue, so that the reference entropy value and the threshold value more comprehensively reflect the overall normal behavior characteristics of the role, avoid the deviation of the reference entropy value caused by insufficient sample size, and further improve the accuracy of client anomaly detection.

[0125] In some embodiments, in the case where the preset number is not less than the number of normal clients, the original information entropy values in the original information entropy value set that meet the preset condition are removed;

[0126] Add the information entropy value corresponding to the client to be detected to the original information entropy value set to obtain the updated original information entropy value set as the second updated original information entropy value set;

[0127] Based on the preset number, the second updated original information entropy value set is averaged to obtain the reference value of the updated original information entropy as the second updated reference entropy value;

[0128] Based on the second updated reference entropy value and the preset standard deviation, the second updated reference entropy value corresponding to the user role type is determined.

[0129] In this embodiment, when the "update condition" (normal information entropy value or manual confirmation of normal) and "current number d ≥ total number of clients" are met, the following operations can be performed:

[0130] Discarding the old information entropy value at the head of the queue: the queue adopts the rule of "first in, first out (FIFO)", and removes the information entropy value sample that is the earliest to join the queue (the element pointed to by the head of the queue). For example, assuming that the total number of clients of the ordinary user role is 100 (i.e., the fixed length of the queue QC is 100), there are already 100 samples in the queue (d = 100), and the earliest sample is the information entropy value of client A one hour ago, which is removed from the queue at this time.

[0131] Adding a new normal information entropy value at the tail of the queue: the information entropy value of the client that meets the condition this time is added to the tail of the queue. For example, after removing the old information entropy value of client A, the normal information entropy value of client B just collected is added to the tail of the queue QC, and the length of the queue remains 100 (d remains 100).

[0132] Recomputing the threshold value and the reference entropy value: based on the updated queue (containing the new sample), the threshold value (the original reference entropy value) of the role is recalculated, and based on the threshold value, the reference entropy value, i.e., the second updated reference entropy value, is further obtained.

[0133] It should be noted that the determination process of the second updated reference entropy value is similar to the determination process of the reference entropy value described above, and details can be referred to the determination process of the reference entropy value described above, which will not be described here in detail.

[0134] In this way, when the sample quantity reaches the total number of clients, the length of the queue is maintained stable by the way of "replacing the old with the new", and it is ensured that the reference entropy value and the threshold value are always calculated based on the latest normal behavior sample. Both the interference of old data on the reference and the rationality of the sample size are avoided, so that the abnormal detection can adapt to the dynamic changes of user behavior for a long time, and the accuracy of detection is improved.

[0135] The client abnormal detection method, device, equipment, computer storage medium and computer program product provided in the embodiments of the present application can determine different reference entropy values based on different user role types corresponding to the client to be detected, then compare the information entropy value corresponding to the abnormal calling behavior of the client to be detected within the preset time window of the user logging in the client to be detected in the target user role type with the reference entropy value, and further determine whether the client to be detected is abnormal. The method uses the information entropy value corresponding to the abnormal calling behavior of the client to be detected to determine whether the client is abnormal, which can timely find whether the client is abnormal. At the same time, by setting different reference entropy values for different user role types logging in the client to be detected, the accuracy of client abnormal detection can be improved.

[0136] Based on the client abnormal detection method provided in the above embodiments, the present application also provides a specific implementation mode of a client abnormal detection device. Please refer to the following embodiments.

[0137] Firstly,Figure 3 The client exception detection apparatus 300 provided by the embodiments of the present application comprises:

[0138] The first determination module 310 is configured to determine a target user role type corresponding to the client to be detected in response to the user identity information of the client to be detected being logged in;

[0139] The second determination module 320 is configured to determine a target reference entropy value corresponding to the target user role type from a preset relationship based on the target user role type, the preset relationship being a corresponding relationship between a user role type and a reference entropy value;

[0140] The third determination module 330 is configured to determine an information entropy value corresponding to the abnormal calling behavior according to the abnormal calling behavior performed by the client to be detected within a preset time window of the user of the target user role type logging in the client to be detected;

[0141] The determination module 340 is configured to determine that the client to be detected is abnormal in the case where the information entropy value is greater than the target reference entropy value.

[0142] In some possible implementation manners, the third determination module 330 can be further configured to:

[0143] Collect an operation behavior performed by the client to be detected within the preset time window of the user of the target user role type logging in the client to be detected;

[0144] In the case where the operation behavior comprises an abnormal calling of a server sensitive data interface behavior, determine an information entropy value corresponding to the abnormal calling of the server sensitive data interface by the client to be detected.

[0145] In some possible implementation manners, the third determination module 330 can be further configured to:

[0146] Receive an information entropy value corresponding to the abnormal calling of the mobile device sensitive permission by the client to be detected sent by the client to be detected;

[0147] Determine the received information entropy value as the information entropy value corresponding to the abnormal calling behavior.

[0148] In some possible implementation manners, the preset relationship is obtained in the following manner:

[0149] Obtain a user role type;

[0150] Determine a set of original information entropy values corresponding to a preset number of normal clients based on the user role type;

[0151] Average the set of original information entropy values to obtain a reference value of the original information entropy as an original reference entropy value;

[0152] Determine the baseline entropy value corresponding to the user role type based on the original baseline entropy value and the preset standard deviation.

[0153] Associate the user role type with the corresponding baseline entropy value to obtain a preset relationship.

[0154] In some possible implementation manners, the client anomaly detection apparatus 300 can also be used for:

[0155] Obtain the number of normal clients corresponding to the user role type as the number of normal clients.

[0156] Update the baseline entropy value according to the number of normal clients and the preset number.

[0157] In some possible implementation manners, updating the baseline entropy value according to the number of normal clients and the preset number includes:

[0158] In a case where the preset number is less than the number of normal clients, add the information entropy value corresponding to the client to be detected to the original information entropy value set to obtain an updated original information entropy value set as a first updated original information entropy value set.

[0159] Change the preset number to an updated number.

[0160] Obtain the baseline value of the updated original information entropy based on the first updated original information entropy value set and the preset standard deviation as a first updated baseline entropy value.

[0161] Determine the first updated baseline entropy value corresponding to the user role type based on the first updated baseline entropy value and the preset standard deviation.

[0162] In some possible implementation manners, updating the baseline entropy value according to the number of normal clients and the preset number includes:

[0163] In a case where the preset number is not less than the number of normal clients, remove the original information entropy value in the original information entropy value set that meets the preset condition.

[0164] Add the information entropy value corresponding to the client to be detected to the original information entropy value set to obtain an updated original information entropy value set as a second updated original information entropy value set.

[0165] Obtain the baseline value of the updated original information entropy based on the preset number and the second updated original information entropy value set as a second updated baseline entropy value.

[0166] Determine the second updated baseline entropy value corresponding to the user role type based on the second updated baseline entropy value and the preset standard deviation.

[0167] In some possible implementation manners, the third determining module 330 can be further configured to:

[0168] obtain the name of the sensitive data interface of the server called by the client to be detected abnormally and the corresponding number of times;

[0169] determine the information entropy value corresponding to the sensitive data interface of the server called by the client to be detected abnormally based on the name of the sensitive data interface of the server called by the client to be detected abnormally and the corresponding number of times.

[0170] In some possible implementation manners, the third determining module 330 can be further configured to:

[0171] receive the information entropy value corresponding to the number of times of calling the sensitive permission of the mobile device by the client to be detected abnormally, the number of times of calling the sensitive permission of the mobile device by the client to be detected abnormally being collected by the client to be detected.

[0172] The various modules of the client anomaly detection apparatus provided by the embodiments of the present application can realize Figure 1 The various steps of the client anomaly detection method provided by the embodiments of the present application can realize the functions of the steps and achieve the corresponding technical effects. For brevity, the functions of the steps will not be described herein.

[0173] Referring to Figure 4 The client anomaly detection method in the above embodiments can provide a client anomaly detection device, which includes a processor 410 and a memory 420 storing computer program instructions; and the processor 410 implements any of the client anomaly detection methods in the above embodiments when executing the computer program instructions.

[0174] The client anomaly detection method in the above embodiments can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; and the computer program instructions are executed by a processor to implement any of the client anomaly detection methods in the above embodiments.

[0175] The embodiments of the present application further provide a computer program product including a computer program, and the computer program is executed by a processor to implement any of the client anomaly detection methods in the above embodiments.

[0176] It should be further noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, or in an order different from the embodiments, or some steps can be executed simultaneously.

[0177] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0178] The above is merely specific implementation of the present application, and those skilled in the art can clearly understand the specific working processes of the system, module and unit described above for the convenience and brevity of description, which can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein. It should be understood that the protection scope of the present application is not limited in this way, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed in the present application, and these modifications or replacements should be covered within the protection scope of the present application.

Claims

1. A client anomaly detection method, characterized by, The method comprises the following steps: In response to the login of the user identity information of the client to be detected, the target user role type corresponding to the client to be detected is determined; Based on the target user role type, the target reference entropy value corresponding to the target user role type is determined from the preset relationship, which is the corresponding relationship between the user role type and the reference entropy value; According to the abnormal calling behavior of the client to be detected within the preset time window of the user login of the client to be detected in the target user role type, the information entropy value corresponding to the abnormal calling behavior is determined; If the information entropy value is greater than the target reference entropy value, the client to be detected is abnormal.

2. The client anomaly detection method of claim 1, wherein, The method comprises the following steps: Collect the operation behavior of the client to be detected within the preset time window of the user login of the client to be detected in the target user role type; If there is an abnormal calling server sensitive data interface behavior in the operation behavior, the information entropy value corresponding to the abnormal calling server sensitive data interface of the client to be detected is determined.

3. The client anomaly detection method of claim 1, wherein, The method comprises the following steps: Receive the information entropy value corresponding to the abnormal calling mobile device sensitive permission of the client to be detected sent by the client to be detected; The received information entropy value is determined as the information entropy value corresponding to the abnormal calling behavior.

4. The client anomaly detection method of claim 1, wherein, The preset relationship is obtained in the following way: Obtain the user role type; Based on the user role type, the original information entropy value set corresponding to the preset number of normal clients is determined; The original information entropy value set is averaged to obtain the reference value of the original information entropy as the original reference entropy value; Based on the original reference entropy value and the preset standard deviation, the reference entropy value corresponding to the user role type is determined; The user role type and the corresponding reference entropy value are associated to obtain the preset relationship.

5. The client anomaly detection method of claim 4, wherein, Further comprising: Obtain the number of normal clients corresponding to the user role type as the number of normal clients; According to the size of the number of normal clients and the preset number, the reference entropy value is updated.

6. The client anomaly detection method of claim 5, wherein, The reference entropy value is updated according to the size of the number of normal clients and the preset number, which comprises: In the case that the preset number is less than the number of normal clients, the information entropy value corresponding to the client to be detected is added to the original information entropy value set to obtain the updated original information entropy value set as the first updated original information entropy value set; The preset number is changed to the updated number; Based on the updated number, the first updated original information entropy value set is averaged to obtain the reference value of the updated original information entropy as the first updated original reference entropy value; Determine a first updated reference entropy value corresponding to the user role type based on the first updated reference entropy value and a preset standard deviation.

7. The client anomaly detection method of claim 6, wherein, Further comprising: In a case where the preset quantity is not less than the normal client quantity, remove an original information entropy value in the original information entropy value set that meets a preset condition in collection time; Add the information entropy value corresponding to the to-be-detected client to the original information entropy value set to obtain an updated original information entropy value set as a second updated original information entropy value set; Obtain an updated original information entropy reference value based on averaging the second updated original information entropy value set based on the preset quantity; Determine a second updated reference entropy value corresponding to the user role type based on the second updated reference entropy value and a preset standard deviation.

8. The client anomaly detection method of claim 2, wherein, The determination of the information entropy value corresponding to the to-be-detected client abnormal invocation of the server sensitive data interface comprises: Obtain the name and corresponding number of the to-be-detected client abnormal invocation of the server sensitive data interface; Determine the information entropy value corresponding to the to-be-detected client abnormal invocation of the server sensitive data interface based on the name and corresponding number of the to-be-detected client abnormal invocation of the server sensitive data interface.

9. The client anomaly detection method of claim 3, wherein, The receiving of the information entropy value corresponding to the to-be-detected client abnormal invocation of the mobile device sensitive permission sent by the to-be-detected client comprises: Receive the information entropy value corresponding to the to-be-detected client abnormal invocation of the mobile device sensitive permission number sent by the to-be-detected client, wherein the to-be-detected client abnormal invocation of the mobile device sensitive permission number is collected by the to-be-detected client.

10. A client anomaly detection apparatus, characterized by, The device comprises: A first determination module configured to determine a target user role type corresponding to the to-be-detected client in response to user identity information logged in the to-be-detected client; A second determination module configured to determine a target reference entropy value corresponding to the target user role type from a preset relationship based on the target user role type, wherein the preset relationship is a correspondence between a user role type and a reference entropy value; A third determination module configured to determine an information entropy value corresponding to an abnormal invocation behavior based on the abnormal invocation behavior performed by the to-be-detected client within a preset time window of the user logged in the to-be-detected client in the target user role type; A determination module configured to determine that the to-be-detected client is abnormal in a case where the information entropy value is greater than the target reference entropy value.

11. A client anomaly detection device, characterized by, The device comprises a processor and a memory storing computer program instructions; the processor executes the computer program instructions to implement the client anomaly detection method of any one of claims 1-9.

12. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer program instructions, and the computer program instructions are executed by the processor to implement the client anomaly detection method of any one of claims 1-9.

13. A computer program product, characterised in that, The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device can execute the client anomaly detection method of any one of claims 1-9.