Cybersecurity threat alerting method, system, and device

By collecting and analyzing user behavior data in enterprise networks, conducting multi-dimensional risk detection and historical behavior simulation, the problem that static rules in existing technologies are unable to cope with complex threats is solved, and comprehensive assessment and efficient early warning of user behavior are achieved.

CN121012685BActive Publication Date: 2026-04-28ZHEJIANG CHUANGZHI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHEJIANG CHUANGZHI TECH CO LTD
Filing Date
2025-09-17
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing network security protection mechanisms rely on static rules and signature matching, which are insufficient to effectively deal with modern complex security threats such as intranet attacks, account abuse, and social engineering attacks, resulting in inadequate network security protection.

Method used

By collecting user behavior data on multiple target user terminals based on a preset sliding window, multi-dimensional behavioral risk detection is performed, risk types and scores are generated, risk discrimination analysis is conducted, historical behavior data is retrieved for slicing and simulation, user behavior patterns are verified, abnormal terminals are marked, and early warning information is generated.

Benefits of technology

It enables comprehensive assessment of user behavior and accurate identification of high-risk users, improves the ability to identify complex attack patterns, enhances the system's early warning effect, responds to and reports abnormal behavior in a timely manner, and reduces network security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121012685B_ABST
    Figure CN121012685B_ABST
Patent Text Reader

Abstract

The application provides a network security threat early warning method, system and device, relates to the technical field of network security, and comprises the following steps: collecting a plurality of user behavior data sequences, performing local multi-dimensional behavior risk detection, generating a plurality of user behavior risk types and a plurality of user behavior risk scores; performing risk discrimination analysis, positioning a high-risk user terminal, and issuing an examination instruction; obtaining historical user behavior time sequence data; performing data slicing to obtain a plurality of historical user behavior slice data; performing behavior evolution simulation, extracting historical user behavior trajectories, and performing user behavior mode verification; when the verification fails, marking the user terminal as abnormal, and generating network security early warning information. The application solves the technical problem that the network security protection mechanism of the prior art usually relies on static rules and signature matching, is difficult to effectively cope with modern complex security threats, and results in insufficient network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, specifically to network security threat early warning methods, systems, and devices. Background Technology

[0002] With the rapid development of information technology, the complexity and diversity of user behavior in enterprise networks are constantly increasing. User behavior data has become an important source of network security protection. Traditional network security protection mechanisms (such as firewalls and intrusion detection systems) mainly rely on static rules and signature matching, which are difficult to effectively deal with modern complex security threats, such as intranet attacks, account abuse, and social engineering attacks. These threats often manifest as normal user behavior, but in fact, there are abnormal operations. This kind of static network security protection is prone to missing some potential high-risk behaviors, reducing the accuracy and comprehensiveness of detection, resulting in insufficient network security protection. Summary of the Invention

[0003] This application provides a method, system, and device for early warning of cybersecurity threats, which aims to address the technical problem that existing cybersecurity protection mechanisms typically rely on static rules and signature matching, making it difficult to effectively cope with modern complex security threats and resulting in insufficient cybersecurity protection.

[0004] The first aspect disclosed in this application provides a method for early warning of network security threats. The method includes: collecting multiple user behavior data sequences from multiple target user terminals on a target enterprise network based on a preset sliding window; performing local multi-dimensional behavioral risk detection to generate multiple user behavior risk types and multiple user behavior risk scores; performing risk discrimination analysis on the multiple user behavior risk types and multiple user behavior risk scores based on user behavior risk constraints to locate high-risk user terminals and issuing review instructions to the high-risk user terminals; retrieving local historical user behavior data from the high-risk user terminals based on the review instructions to obtain historical user behavior time-series data; slicing the historical user behavior time-series data based on the preset sliding window to obtain multiple historical user behavior slice data; performing behavioral evolution simulation based on the multiple historical user behavior slice data to extract historical user behavior trajectories; verifying the user behavior patterns of the high-risk user terminals based on the historical user behavior trajectories; and when user behavior pattern verification fails, marking the high-risk user terminals as abnormal user terminals and generating network security early warning information.

[0005] The second aspect of this application discloses a network security threat early warning system. This system is used in the aforementioned network security threat early warning method. The system includes: a behavior risk detection module, used to collect multiple user behavior data sequences from multiple target user terminals on a target enterprise network based on a preset sliding window, perform local multi-dimensional behavior risk detection, and generate multiple user behavior risk types and multiple user behavior risk scores; a risk discrimination analysis module, used to perform risk discrimination analysis on the multiple user behavior risk types and multiple user behavior risk scores based on user behavior risk constraints, locate high-risk user terminals, and issue review instructions to the high-risk user terminals; and a local data retrieval module, used for... Upon receiving the review instruction, the system retrieves local historical user behavior data from the high-risk user terminal to obtain historical user behavior time-series data; a data slicing module is used to slice the historical user behavior time-series data based on the preset sliding window to obtain multiple historical user behavior slice data; a pattern verification module is used to perform behavior evolution simulation based on the multiple historical user behavior slice data, extract historical user behavior trajectories, and verify the user behavior pattern of the high-risk user terminal based on the historical user behavior trajectories; and a warning information generation module is used to mark the high-risk user terminal as an abnormal user terminal and generate network security warning information when the user behavior pattern verification fails.

[0006] The third aspect disclosed in this application provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the network security threat early warning method in the first aspect.

[0007] One or more technical solutions provided in this application have at least the following beneficial effects:

[0008] By collecting user behavior data across multiple target user terminals using a pre-defined sliding window, risk assessment can be performed from multiple dimensions. This multi-dimensional detection method can identify potentially high-risk behavior types and assign a risk score to each behavior, ensuring a comprehensive assessment of user behavior. Analyzing user behavior risk types and scores allows for accurate identification of high-risk user terminals, enabling enterprises to quickly pinpoint users who may pose a security threat and promptly send review instructions to these users, thereby reducing the impact of potential security issues. Retrieving local historical behavior data from high-risk user terminals and performing time-series analysis on this data allows for a deeper understanding of user behavior. Behavioral tracing, in this way, not only focuses on current behavior but also analyzes users' long-term behavioral patterns to discover potential behavioral anomalies. By slicing and simulating the evolution of historical user behavior data, user behavior trajectories are extracted, and pattern verification is performed based on these trajectories. This method can accurately determine whether users have abnormal behavioral patterns, improve the ability to identify complex attack patterns, and enhance the system's early warning effect. When user behavior pattern verification fails, the terminal is promptly marked as abnormal, and network security early warning information is generated, enabling rapid response and reporting of abnormal behavior. This helps security personnel take timely protective measures and effectively reduce network security risks.

[0009] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0010] Figure 1 This is a schematic diagram of the network security threat early warning method provided in the embodiments of this application.

[0011] Figure 2 This is a schematic diagram of the network security threat early warning system provided in an embodiment of this application.

[0012] Figure 3 This is a schematic diagram of the structure of an exemplary computer device provided in an embodiment of this application.

[0013] Figure labeling: Behavioral risk detection module 10, risk discrimination and analysis module 20, local data retrieval module 30, data slicing module 40, pattern verification module 50, early warning information generation module 60, bus 300, receiver 301, processor 302, transmitter 303, memory 304, bus interface 305. Detailed Implementation

[0014] This application provides a network security threat early warning method, system, and device, which solves the technical problem that existing network security protection mechanisms usually rely on static rules and signature matching, making it difficult to effectively cope with modern complex security threats and resulting in insufficient network security protection.

[0015] After introducing the basic principles of this application, various non-limiting embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0016] Example 1, as Figure 1 As shown in the figure, this application provides a network security threat early warning method, the method including:

[0017] Multiple user behavior data sequences are collected from multiple target user terminals in the target enterprise network based on a preset sliding window. Local multi-dimensional behavior risk detection is then performed to generate multiple user behavior risk types and multiple user behavior risk scores.

[0018] Target user terminals refer to terminal devices within the target enterprise network, such as computers, mobile phones, and tablets, which perform specific operations. A preset sliding window is used for time-series data processing. By defining a fixed-size time window, such as the past hour, the window slides forward over time to gradually acquire data from different time periods. Through the preset sliding window, a series of behavioral data are collected from multiple target user terminals. This behavioral data includes operation records, login records, and access logs. This behavioral data is arranged in a time series, representing multiple user behavior data sequences and their patterns. Based on the collected user behavior data sequences, multi-dimensional risk detection is performed, including different behavioral dimensions such as operation frequency, access patterns, time characteristics, and device type. During risk detection, user behavior risk types and scores are generated based on the analysis results of each dimension. User behavior risk types include frequent login failures, cross-regional logins, abnormal login times, abnormal file access, and frequent device changes. The user behavior risk score is a specific numerical value representing the degree of risk of the user behavior.

[0019] Based on user behavior risk constraints, risk discrimination analysis is performed on the multiple user behavior risk types and multiple user behavior risk scores to identify high-risk user terminals and issue review instructions to the high-risk user terminals.

[0020] User behavior risk constraints include preset rules or thresholds. For example, when a user's behavior risk score exceeds a preset user behavior risk score standard, the behavior is deemed high-risk. Different user behavior risk types correspond to different preset user behavior risk score standards. Through risk discrimination analysis, user terminals with high risk are identified. These high-risk user terminals exhibit abnormal behavior patterns, such as frequent login failures or access to uncommon resources. For high-risk user terminals, an inspection instruction is issued, requiring further investigation.

[0021] Based on the review instructions, local historical user behavior data is retrieved from the high-risk user terminals to obtain historical user behavior time-series data.

[0022] According to the review instructions, historical user behavior data is retrieved locally from the high-risk user terminals. This data includes past login records, file access records, system operation records, etc. This historical user behavior data is arranged in chronological order, that is, historical user behavior time series data. By analyzing this time series data, the user's long-term behavior pattern can be obtained, and the existence of abnormal behavior can be further assessed.

[0023] Based on the preset sliding window, the historical user behavior time series data is sliced ​​to obtain multiple historical user behavior slice data.

[0024] By applying a preset sliding window to historical user behavior time-series data, the data is divided into time periods. Assuming the preset sliding window size is one hour, each preset sliding window contains all user behavior data from the past hour. As the window slides, the next slice will contain new data, and the old data will be removed from the window. Through this slicing method, multiple small data segments are obtained, namely multiple historical user behavior slices, each slice corresponding to user behavior data for a specific time period.

[0025] Behavioral evolution simulation is performed based on the multiple historical user behavior slice data to extract historical user behavior trajectories, and user behavior patterns of the high-risk user terminals are verified based on the historical user behavior trajectories.

[0026] By simulating the evolution of user behavior across multiple historical user behavior data slices, the process of user behavior change can be simulated. For example, users may exhibit certain regularities in their past behavioral patterns. By simulating these behavioral changes, future user behavior can be predicted. The goal of behavioral evolution simulation is to extract the evolutionary trajectory of user behavior by analyzing historical data. The result of the evolution simulation is a historical user behavior trajectory, which represents the changes in user behavior over a certain period of time, showing how users transition from one behavioral state to another, and helping to identify anomalies in behavioral patterns.

[0027] After obtaining historical user behavior trajectories, the behavior patterns of high-risk user terminals are compared with their actual behavior to verify whether they match the previous historical behavior trajectories. If the current behavior trajectory of a high-risk user terminal deviates significantly from its historical trajectory, such as abnormal behavior frequency or inconsistent behavior sequence, it indicates that the user's behavior pattern is abnormal. In this case, the user behavior pattern verification fails.

[0028] When user behavior pattern verification fails, the high-risk user terminal is marked as an abnormal user terminal, and a network security warning message is generated.

[0029] When a user's current behavior differs from their historical behavior, it indicates abnormal behavior. This could be due to attackers tampering with user actions, the presence of malware, or other security issues. In this case, the high-risk user terminal is marked as an abnormal user terminal. This means that the behavior of this high-risk user terminal has been determined to be abnormal, representing a potential security threat. A network security alert is generated for this abnormal user terminal, informing the enterprise network administrator or security team of the security risk. This network security alert helps to promptly detect and respond to potential network attacks or data breaches.

[0030] Furthermore, the method also includes:

[0031] When there are M abnormal user terminals, perform cross-terminal correlation analysis on the M abnormal user terminals to generate... A number of cross-terminal correlation coefficients, where M is a positive integer greater than 1; based on the cross-terminal correlation coefficient threshold, the following... The association is determined by cross-terminal correlation coefficients, and N groups of abnormally associated user terminals are located, where N is a positive integer less than or equal to M; based on the N groups of abnormally associated user terminals, N cross-terminal network security early warning messages are generated.

[0032] When multiple abnormal user terminals are detected (not just one, but M), further analysis is needed to determine if there are any correlations between them. At this stage, cross-terminal analysis is performed on the M abnormal user terminals to check for correlations. For example, multiple abnormal user terminals might be different identities of the same attacker, or they might be nodes cooperating to execute attacks. By analyzing the behavioral patterns among the M abnormal user terminals, such as accessing the same resources, using the same devices, and similar operation times, a cross-terminal correlation coefficient is calculated for each pair of abnormal user terminals. For the M abnormal user terminals, all terminal combinations are calculated, i.e., all binary combinations of the M abnormal user terminals. The number of these combinations is... A cross-terminal correlation coefficient is generated between each pair of terminals. The higher the cross-terminal correlation coefficient, the stronger the correlation between the two terminals.

[0033] A threshold for the cross-terminal correlation coefficient is set to determine whether the cross-terminal correlation coefficient between two abnormal user terminals is high enough to indicate that there is a significant correlation between them. For example, if the threshold is set to 0.8, if the cross-terminal correlation coefficient of a pair of abnormal user terminals exceeds the threshold, they are considered to be related. If the cross-terminal correlation coefficient is lower than the threshold, they are considered not to be strongly related.

[0034] Association is determined by comparing the cross-terminal correlation coefficient between each pair of terminals with a threshold value. If the cross-terminal correlation coefficient exceeds the threshold, the pair of terminals is considered related, possibly indicating the same attack or different behaviors of the attacker. These terminal pairs are then classified as associated abnormal user terminals, with each group of associated abnormal user terminals showing a significant correlation. N is a positive integer less than or equal to M, representing the number of associated groups.

[0035] N cross-terminal network security alerts are generated for N groups of associated abnormal user terminals. These cross-terminal network security alerts indicate that some terminals may be carrying out some kind of coordinated attack or other malicious activities. Network security personnel can further investigate and prevent potential attacks based on these cross-terminal network security alerts.

[0036] Furthermore, the method includes:

[0037] Based on historical abnormal behavior records, cross-terminal abnormal behavior clustering is performed to generate a cross-terminal abnormal behavior topology map, wherein the cross-terminal abnormal behavior topology map is identified by cooperative node identifiers and jump node identifiers; based on the cross-terminal abnormal behavior topology map, cross-terminal abnormal behavior is identified for the N groups of associated abnormal user terminals.

[0038] Historical abnormal behavior records refer to user behavior data that has been identified as abnormal. They are usually obtained by monitoring and analyzing time-series user behavior data. Historical abnormal behavior records include all abnormal behaviors of users in the past period of time, such as abnormal logins and access to unauthorized resources.

[0039] Historical abnormal behavior records are classified using clustering algorithms. Clustering algorithms group similar abnormal behavior records into one category to find the inherent connections between these abnormal behaviors. For example, if multiple terminals exhibit similar abnormal behaviors, they may be caused by the same attacker or the same attack behavior. Cross-terminal clustering means that clustering is not limited to a single terminal, but spans abnormal behaviors across multiple terminals, looking for abnormal behavior patterns that appear in multiple terminals. Finally, the clustering algorithm groups these abnormal behaviors into abnormal behavior clusters, with each group representing a possible attack pattern.

[0040] The clustering results are represented graphically to obtain a cross-terminal abnormal behavior topology map. This is a graphical structure where nodes represent user terminals and edges represent the relationships between them. The topology map clearly shows which user terminals have strong correlations, possibly different manifestations of the same attack behavior. Collaborative nodes are identified as terminals exhibiting obvious correlations, such as sharing certain abnormal operations or having the same attack behavior characteristics. Collaborative nodes are typically terminals with strong similarities, possibly different terminals cooperating to execute attacks. Jump nodes are prominent nodes in the abnormal behavior topology map. They act as bridge nodes in the clustering, connecting multiple collaborative nodes. Jump nodes are key nodes in the attack path, allowing attackers to cross different terminals to conduct data penetration or remote operations.

[0041] The generated cross-terminal abnormal behavior topology map is used to further identify abnormal behaviors in the previously identified N groups of associated abnormal user terminals. Specifically, by analyzing the cross-terminal abnormal behavior topology map, it is possible to identify which abnormal behaviors are jointly executed by a group of associated terminals. In this way, cross-terminal attack paths can be identified, and potential network security risks can be discovered. The cross-terminal abnormal behavior topology map can also identify which abnormal behaviors within terminal groups are caused by the same attacker or attack behavior. For example, if a terminal has a skip node relationship with multiple other terminals, it indicates that the terminal is a key node in the attack across other terminals. The identification results indicate the attack chain between terminals, showing how the attacker uses different terminals to execute their malicious behavior. This information is used to locate the source of the attack and prevent the attack.

[0042] Furthermore, the method for performing local multi-dimensional behavioral risk detection includes:

[0043] The system locally retrieves preset risk detection dimensions and performs multi-dimensional data decomposition on the multiple user behavior data sequences to obtain multiple multi-dimensional user behavior data blocks. Based on these multi-dimensional user behavior data blocks, it extracts multiple temporal feature data and multiple non-temporal feature data. It then uses a temporal convolutional network to capture local temporal dependencies in the multiple temporal feature data, obtaining multiple multi-scale temporal features. Finally, it uses a graph convolutional network to perform multi-dimensional data association modeling on the multiple non-temporal feature data, obtaining multiple non-temporal structured features. The system then fuses these multiple multi-scale temporal features and multiple non-temporal structured features to obtain multiple fused features. Finally, it performs multi-level feature mapping on these fused features based on a preset behavior risk feature space, outputting multiple user behavior risk types and multiple user behavior risk scores.

[0044] The preset risk detection dimensions are a division of user behavior from different perspectives, aiming to comprehensively assess the risk of user behavior. These dimensions include time, space, device, user behavior, identity and permission, and network traffic. Based on these preset risk detection dimensions, multiple user behavior data sequences are decomposed. This aims to break down a user's behavior data sequence according to different dimensions, forming multiple independent data blocks. These multi-dimensional user behavior data blocks represent the characteristics of different dimensions of user behavior. For example, the time dimension data block contains the specific time and frequency of the behavior, while the device dimension data block records the device information used by the user. Each dimension data block is stored independently for easy subsequent analysis.

[0045] From the decomposed multi-dimensional user behavior data blocks, multiple time-related time-series feature data and multiple time-independent non-time-series feature data are extracted. Time-series feature data refers to behavioral data that depends on the time order, including operation time interval, operation frequency fluctuation, behavior duration, and operation time period distribution. Non-time-series structured features refer to behavioral data that is not related to time, including operation type, operation frequency, and behavior time concentration.

[0046] Temporal convolutional networks (CCNNs) are deep learning models specifically designed for processing time-series data. Unlike traditional convolutional neural networks (CNNs), CCNNs capture temporal features within time-series data. Local temporal dependencies refer to the correlation between behavior at certain points in a time series and behavior at points before and after them. For example, a user's behavior in the past may influence their behavior in the following time period. Through convolution operations, CCNNs can automatically identify and extract these local dependencies. The resulting multi-scale temporal features refer to features captured from different time scales. For instance, some user behaviors exhibit short-term periodic changes, while others show long-term trends. Through CCNNs, different temporal features can be extracted from multiple scales (short-term, medium-term, and long-term), providing a more comprehensive view of the evolution of user behavior.

[0047] Graph Convolutional Networks (GCNNs) are deep learning models that can learn on graph-structured data. By performing convolution operations on the graph structure, they can capture the relationships and dependencies between nodes. Non-temporal feature data usually has multiple dimensions with complex relationships between them. GCNNs model these dimensions, revealing the relationships between them, and pass and fuse information between the various dimensions through graph convolution operations. For example, if two operations have a strong correlation, the GCNN will reflect this correlation in the graph model, thereby better capturing the complex relationships between different operational behaviors.

[0048] Feature fusion is the process of integrating features extracted from different models. In this step, multiple multi-scale temporal features and multiple non-temporal structured features obtained through temporal convolutional networks and graph convolutional networks are fused. After feature fusion, the fused features are mapped to a predefined behavioral risk feature space. Within this space, each fused feature undergoes further hierarchical analysis. Specifically, the predefined behavioral risk feature space defines a space of user baseline behavior. By calculating the deviation between the fused features and the user's baseline behavior, the behavioral risk type and corresponding risk score for each user are output. The risk score reflects the degree of risk of the user's current behavior.

[0049] Furthermore, the preset risk detection dimensions include time dimension, space dimension, device dimension, user behavior dimension, identity and permission dimension, and network traffic dimension.

[0050] The time dimension indicates the temporal characteristics of user behavior, such as the specific time, frequency, and interval of the behavior; the spatial dimension indicates the geographical location information of user behavior, such as the locations, IP addresses, or networks from which the user accessed the site; the device dimension indicates information such as the type of device used by the user, device ID, and operating system version; the user behavior dimension indicates the specific actions of the user, such as logging in, accessing files, and changing permissions; the identity and permission dimension indicates the user's identity and permission information, such as the user's role, access level, and authorized permissions; and the network traffic dimension indicates the user's network activity data, such as the amount of data transmitted, the network ports accessed, and the servers accessed. These dimensions can be expanded or adjusted according to actual needs. Through multi-dimensional evaluation of these dimensions, the risks of user behavior can be analyzed and assessed more comprehensively.

[0051] Furthermore, the method for performing multi-level feature mapping on the multiple fused features based on a preset behavioral risk feature space includes:

[0052] In the time dimension, the first multi-scale temporal features include operation time interval features, operation frequency fluctuation features, behavior duration features, and operation period distribution features; the first non-temporal structured features include operation type features, operation frequency features, and behavior time concentration features. The first multi-scale temporal features and the first non-temporal structured features are fused to obtain a first fused feature. The time dimension feature space of the preset behavior risk feature space is retrieved, wherein the time dimension feature space includes a baseline operation type, a baseline operation frequency, a baseline behavior time concentration, a baseline operation time interval, a baseline operation frequency fluctuation, a baseline behavior duration, and a baseline operation period distribution. The first fused feature is feature-mapped in the time dimension feature space, and a first time dimension behavior risk confidence score is generated based on the feature comprehensive offset. The first time dimension behavior risk confidence score includes a first time dimension behavior risk type and a first time dimension behavior risk score. Similarly, the preset risk detection dimensions are traversed, and the maximum value of the behavior risk confidence score for each dimension is taken to obtain the first user behavior risk type and the first user behavior risk score.

[0053] Analyzing user behavior based on the time dimension extracts multiple time-related features, which help capture changes in user behavior across different time periods. Operation time interval features represent the time interval between consecutive user actions, such as the time difference between two logins or visits. Shorter intervals indicate abnormal user behavior, such as frequent system accesses within a short period. Operation frequency fluctuation features describe the frequency fluctuations of user operations; frequent fluctuations indicate abnormal user behavior, especially without a clear reason. Behavior duration features reflect the duration of a specific user action, such as the time a user spends performing an action. Both excessively long and short durations indicate abnormal behavior. Operation time period distribution features refer to the distribution of user behavior across different time periods, such as nighttime or work hours, which can reveal typical user behavior patterns.

[0054] The first type of non-temporally structured feature is a feature that is unrelated to the time dimension and time sequence. It usually represents behavior at a certain point in time without involving the preceding and following time sequence. The operation type feature describes the specific type of operation performed by the user, such as logging in, viewing files, modifying data, deleting files, etc. Different operation types have different impacts on risk assessment. The operation frequency feature refers to the frequency with which a user performs a specific operation. For example, how many times a user logs in per hour. If the frequency is abnormal, it indicates a potential security threat. The behavior time concentration feature reflects the degree of concentration of user behavior in the time dimension. For example, whether the user concentrates on certain specific times. Too high or too low time concentration may indicate abnormal behavior patterns.

[0055] The first multi-scale temporal features and the first non-temporal structured features are fused together. The purpose of feature fusion is to integrate data from different dimensions into a unified feature set for further analysis. The resulting first fused features include multi-dimensional information about user behavior, including both temporal features and non-temporal features that describe the behavior itself.

[0056] The preset behavioral risk feature space is a multi-dimensional space, where each dimension corresponds to a baseline feature of user behavior. The baseline feature refers to the range of user operations under normal circumstances and is used to assess whether user behavior is abnormal. By comparing it with the current user behavior, the degree of deviation between user behavior and normal behavior can be quantified, thereby assessing its risk.

[0057] The first fused feature is mapped to a time-dimensional feature space. This feature mapping process transforms the current user behavior features into this space, allowing each feature to be compared with a baseline feature in the space. After feature mapping, a comprehensive feature offset is calculated. This offset represents the difference between the current user behavior and normal behavior. The comprehensive feature offset is calculated based on the difference between the mapped feature value and the baseline value. Specifically, the larger the offset, the greater the deviation of the current behavior from normal behavior, and the greater the potential risk. A first-time-dimensional behavioral risk confidence score is generated based on the comprehensive feature offset. This represents the degree of abnormality of the user behavior in the time dimension. The first-time-dimensional behavioral risk type is a risk assessment based on the time dimension, such as frequent login failures or login at abnormal times. The first-time-dimensional behavioral risk score is a specific numerical value representing the degree of risk of the user behavior.

[0058] The process applies not only to the time dimension but also to all preset risk detection dimensions. Specifically, it sequentially processes all dimensions, including spatial, device, and user behavior dimensions, to comprehensively assess the risk of user behavior. For each dimension, the corresponding fused features are mapped into the feature space of that dimension, and a comprehensive offset is calculated to generate the behavioral risk confidence score for that dimension. Finally, the behavioral risk confidence score with the highest confidence score among all dimensions is selected as the final assessment result of the user behavior. In this way, the first user behavior risk type and the first user behavior risk score are obtained, representing the overall behavioral risk assessment result for that user.

[0059] Furthermore, the method for verifying the user behavior patterns of high-risk user terminals based on the historical user behavior trajectories includes:

[0060] The system acquires high-risk user behavior data sequences from the high-risk user terminals, performs behavior evolution simulation, and extracts high-risk user behavior trajectories. Based on preset trajectory features, it performs trajectory feature similarity identification on the historical user behavior trajectories and the high-risk user behavior trajectories to generate behavior trajectory similarity. When the behavior trajectory similarity is lower than the preset behavior trajectory similarity, the user behavior pattern verification is deemed to have failed.

[0061] High-risk user terminals are terminal devices identified as exhibiting abnormal behavior in the aforementioned steps. High-risk user behavior data sequences are behavioral data of high-risk user terminals over a certain period of time. Behavioral evolution simulation is performed on these high-risk user behavior data sequences to reproduce the user's behavioral evolution process. For example, how does the user's behavior change from a normal state to an abnormal state, and are there any specific triggering events? This simulation process helps to understand the user's behavioral patterns and predict future behavior. Through this simulation, the high-risk user behavior trajectory is obtained. The high-risk user behavior trajectory represents the path of behavioral changes of the user over a period of time, including characteristics such as the user's operation sequence, time intervals, and frequency changes.

[0062] Preset trajectory features are key characteristics used to measure and describe behavioral trajectories. These features can include the temporal sequence, duration, frequency, operation type, and relative position between actions. Representative features are extracted from historical user behavior trajectories and high-risk user behavior trajectories to determine their similarity. Similarity identification is performed based on the extracted trajectory features, using methods such as Euclidean distance and cosine similarity to calculate the degree of similarity between the two trajectories. Finally, a behavioral trajectory similarity value is calculated and generated, representing the degree of matching between the high-risk user's current behavioral trajectory and historical behavioral trajectories. A higher similarity value indicates that the high-risk user's behavioral pattern is consistent with their historical behavior, while a lower similarity value indicates a significant difference between the current behavior and the historical pattern.

[0063] The preset behavioral trajectory similarity is a pre-set similarity threshold used to distinguish between normal and abnormal behavior. When the calculated behavioral trajectory similarity is lower than this threshold, it indicates that the current high-risk user's behavior pattern deviates significantly from its historical behavior pattern. At this time, the user's behavior pattern verification is deemed to have failed, which means that the user's behavior has significant abnormalities, such as account theft, malicious software, or external attacks.

[0064] Furthermore, the method also includes:

[0065] When the similarity of the behavior trajectory is higher than the preset similarity of the behavior trajectory, the user behavior pattern verification is deemed successful, a continuous monitoring instruction is generated, and the high-risk user terminal is continuously monitored.

[0066] If the similarity of the behavioral trajectory is higher than a preset threshold, it is considered that the current user's behavior is consistent with its historical behavior pattern and no significant anomalies are found. This indicates that the user's behavior may be normal, but since the user has been marked as high risk, continued monitoring is still required. In this case, a continuous monitoring instruction is generated, requiring long-term behavioral monitoring of the high-risk user terminal. Continuous monitoring helps to discover potential security threats in a timely manner and prevent potential attackers from being detected in time by disguising themselves as normal users.

[0067] Example 2, based on the same inventive concept as the network security threat early warning method in the foregoing examples, such as... Figure 2 As shown in the figure, this application embodiment provides a network security threat early warning system, the system comprising:

[0068] The behavior risk detection module 10 is used to collect multiple user behavior data sequences from multiple target user terminals in the target enterprise network based on a preset sliding window, perform local multi-dimensional behavior risk detection, and generate multiple user behavior risk types and multiple user behavior risk scores. The risk discrimination analysis module 20 is used to perform risk discrimination analysis on the multiple user behavior risk types and multiple user behavior risk scores based on user behavior risk constraints, locate high-risk user terminals, and issue review instructions to the high-risk user terminals. The local data retrieval module 30 is used to retrieve local historical user data from the high-risk user terminals based on the review instructions. The system retrieves historical user behavior time-series data; a data slicing module 40 slices the historical user behavior time-series data based on a preset sliding window to obtain multiple historical user behavior slices; a pattern verification module 50 simulates behavior evolution based on the multiple historical user behavior slices to extract historical user behavior trajectories, and verifies the user behavior patterns of the high-risk user terminal based on the historical user behavior trajectories; and a warning information generation module 60 marks the high-risk user terminal as an abnormal user terminal and generates network security warning information when user behavior pattern verification fails.

[0069] Furthermore, the system also includes a cross-terminal correlation analysis module to perform the following steps:

[0070] When there are M abnormal user terminals, perform cross-terminal correlation analysis on the M abnormal user terminals to generate... A number of cross-terminal correlation coefficients, where M is a positive integer greater than 1; based on the cross-terminal correlation coefficient threshold, the following... The association is determined by cross-terminal correlation coefficients, and N groups of abnormally associated user terminals are located, where N is a positive integer less than or equal to M; based on the N groups of abnormally associated user terminals, N cross-terminal network security early warning messages are generated.

[0071] Furthermore, the cross-terminal association analysis module is used to perform the following operation steps:

[0072] Based on historical abnormal behavior records, cross-terminal abnormal behavior clustering is performed to generate a cross-terminal abnormal behavior topology map, wherein the cross-terminal abnormal behavior topology map is identified by cooperative node identifiers and jump node identifiers; based on the cross-terminal abnormal behavior topology map, cross-terminal abnormal behavior is identified for the N groups of associated abnormal user terminals.

[0073] Furthermore, the behavioral risk detection module 10 is used to perform the following operational steps:

[0074] The system locally retrieves preset risk detection dimensions and performs multi-dimensional data decomposition on the multiple user behavior data sequences to obtain multiple multi-dimensional user behavior data blocks. Based on these multi-dimensional user behavior data blocks, it extracts multiple temporal feature data and multiple non-temporal feature data. It then uses a temporal convolutional network to capture local temporal dependencies in the multiple temporal feature data, obtaining multiple multi-scale temporal features. Finally, it uses a graph convolutional network to perform multi-dimensional data association modeling on the multiple non-temporal feature data, obtaining multiple non-temporal structured features. The system then fuses these multiple multi-scale temporal features and multiple non-temporal structured features to obtain multiple fused features. Finally, it performs multi-level feature mapping on these fused features based on a preset behavior risk feature space, outputting multiple user behavior risk types and multiple user behavior risk scores.

[0075] Furthermore, the preset risk detection dimensions include time dimension, space dimension, device dimension, user behavior dimension, identity and permission dimension, and network traffic dimension.

[0076] Furthermore, the behavioral risk detection module 10 is used to perform the following operational steps:

[0077] In the time dimension, the first multi-scale temporal features include operation time interval features, operation frequency fluctuation features, behavior duration features, and operation period distribution features; the first non-temporal structured features include operation type features, operation frequency features, and behavior time concentration features. The first multi-scale temporal features and the first non-temporal structured features are fused to obtain a first fused feature. The time dimension feature space of the preset behavior risk feature space is retrieved, wherein the time dimension feature space includes a baseline operation type, a baseline operation frequency, a baseline behavior time concentration, a baseline operation time interval, a baseline operation frequency fluctuation, a baseline behavior duration, and a baseline operation period distribution. The first fused feature is feature-mapped in the time dimension feature space, and a first time dimension behavior risk confidence score is generated based on the feature comprehensive offset. The first time dimension behavior risk confidence score includes a first time dimension behavior risk type and a first time dimension behavior risk score. Similarly, the preset risk detection dimensions are traversed, and the maximum value of the behavior risk confidence score for each dimension is taken to obtain the first user behavior risk type and the first user behavior risk score.

[0078] Furthermore, the pattern verification module 50 is used to perform the following operation steps:

[0079] The system acquires high-risk user behavior data sequences from the high-risk user terminals, performs behavior evolution simulation, and extracts high-risk user behavior trajectories. Based on preset trajectory features, it performs trajectory feature similarity identification on the historical user behavior trajectories and the high-risk user behavior trajectories to generate behavior trajectory similarity. When the behavior trajectory similarity is lower than the preset behavior trajectory similarity, the user behavior pattern verification is deemed to have failed.

[0080] Furthermore, the pattern verification module 50 is used to perform the following operation steps:

[0081] When the similarity of the behavior trajectory is higher than the preset similarity of the behavior trajectory, the user behavior pattern verification is deemed successful, a continuous monitoring instruction is generated, and the high-risk user terminal is continuously monitored.

[0082] Through the foregoing detailed description of the network security threat early warning method, those skilled in the art can clearly understand the network security threat early warning system in this embodiment. Since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and relevant parts can be referred to the method section.

[0083] Example 3, as Figure 3 The diagram shown is a structural schematic of an exemplary computer device according to this application. Figure 3In this document, the bus architecture is represented by bus 300. Bus 300 may include any number of interconnected buses and bridges, and bus 300 connects various circuits including one or more processors represented by processor 302 and memory represented by memory 304. Bus 300 may also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. Bus interface 305 provides an interface between bus 300 and receiver 301 and transmitter 303. Receiver 301 and transmitter 303 may be the same element, i.e., a transceiver, providing a unit for communicating with various other devices over a transmission medium. Processor 302 is responsible for managing bus 300 and general processing, while memory 304 can be used to store data used by processor 302 during operation.

[0084] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0085] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for early warning of cybersecurity threats, characterized in that, The method includes: Multiple user behavior data sequences are collected from multiple target user terminals in the target enterprise network based on a preset sliding window, and local multi-dimensional behavior risk detection is performed to generate multiple user behavior risk types and multiple user behavior risk scores. Based on user behavior risk constraints, risk discrimination analysis is performed on the multiple user behavior risk types and multiple user behavior risk scores to identify high-risk user terminals and issue review instructions to the high-risk user terminals. Based on the review instructions, local historical user behavior data of the high-risk user terminal is retrieved to obtain historical user behavior time-series data. Based on the preset sliding window, the historical user behavior time series data is sliced ​​to obtain multiple historical user behavior slice data; Based on the multiple historical user behavior slice data, behavior evolution simulation is performed to extract historical user behavior trajectories, and user behavior patterns of the high-risk user terminals are verified based on the historical user behavior trajectories. When user behavior pattern verification fails, the high-risk user terminal is marked as an abnormal user terminal, and a network security warning message is generated. The method for verifying the user behavior patterns of high-risk user terminals based on the historical user behavior trajectories includes: The high-risk user behavior data sequence of the high-risk user terminal is obtained, the behavior evolution is simulated, and the high-risk user behavior trajectory is extracted. Based on preset trajectory features, the trajectory feature similarity is identified between the historical user behavior trajectory and the high-risk user behavior trajectory to generate a behavior trajectory similarity. When the similarity of the behavior trajectory is lower than the preset similarity of the behavior trajectory, the user behavior pattern verification is deemed to have failed. When the similarity of the behavior trajectory is higher than the preset similarity of the behavior trajectory, the user behavior pattern verification is deemed successful, a continuous monitoring instruction is generated, and the high-risk user terminal is continuously monitored.

2. The network security threat early warning method as described in claim 1, characterized in that, The method further includes: When there are M abnormal user terminals, perform cross-terminal correlation analysis on the M abnormal user terminals to generate... There are 1 cross-terminal correlation coefficients, where M is a positive integer greater than 1; Based on the cross-terminal correlation coefficient threshold, the above The association is determined by cross-terminal association coefficients, and N groups of abnormally associated user terminals are located, where N is a positive integer less than or equal to M. Based on the N groups of associated abnormal user terminals, N cross-terminal network security early warning messages are generated.

3. The network security threat early warning method as described in claim 2, characterized in that, The method includes: Based on historical abnormal behavior records, cross-terminal abnormal behavior clustering is performed to generate a cross-terminal abnormal behavior topology map, wherein the cross-terminal abnormal behavior topology map is identified by cooperative node identifiers and jump node identifiers. Based on the cross-terminal abnormal behavior topology map, cross-terminal abnormal behavior identification is performed on the N groups of associated abnormal user terminals.

4. The network security threat early warning method as described in claim 1, characterized in that, The method for performing local multi-dimensional behavioral risk detection includes: Locally retrieve preset risk detection dimensions and perform multi-dimensional data decomposition on the multiple user behavior data sequences to obtain multiple multi-dimensional user behavior data blocks; Based on the multiple user behavior multi-dimensional data blocks, multiple time-series feature data and multiple non-time-series feature data are extracted; The local temporal dependencies of the multiple temporal feature data are captured by a temporal convolutional network to obtain multiple multi-scale temporal features. Multi-dimensional data association modeling is performed on the multiple non-temporal feature data using graph convolutional networks to obtain multiple non-temporal structured features; Multiple multi-scale temporal features and multiple non-temporal structured features are fused to obtain multiple fused features. Based on a preset behavioral risk feature space, the multiple fused features are subjected to multi-level feature mapping to output multiple user behavior risk types and multiple user behavior risk scores.

5. The network security threat early warning method as described in claim 4, characterized in that, The preset risk detection dimensions include time dimension, space dimension, device dimension, user behavior dimension, identity and permission dimension, and network traffic dimension.

6. The network security threat early warning method as described in claim 5, characterized in that, The method for performing multi-level feature mapping on the multiple fused features based on a preset behavioral risk feature space includes: In the time dimension, the first multi-scale temporal features include operation time interval features, operation frequency fluctuation features, behavior duration features, and operation period distribution features; the first non-temporal structured features include operation type features, operation frequency features, and behavior time concentration features. The first multi-scale temporal feature and the first non-temporal structured feature are fused to obtain the first fused feature; Retrieve the time dimension feature space of the preset behavioral risk feature space, wherein the time dimension feature space includes the baseline operation type, baseline operation frequency, baseline behavior time concentration, baseline operation time interval, baseline operation frequency fluctuation, baseline behavior duration, and baseline operation time period distribution. The first fused feature is mapped in the time dimension feature space, and a first time dimension behavioral risk confidence score is generated based on the feature comprehensive offset. The first time dimension behavioral risk confidence score includes the first time dimension behavioral risk type and the first time dimension behavioral risk score. Similarly, the preset risk detection dimensions are traversed, and the maximum confidence value of behavioral risk in each dimension is taken to obtain the first user behavior risk type and the first user behavior risk score.

7. A network security threat early warning system, characterized in that, The system is used to implement the cybersecurity threat early warning method according to any one of claims 1-6, the system comprising: The behavioral risk detection module is used to collect multiple user behavior data sequences from multiple target user terminals in the target enterprise network based on a preset sliding window, perform local multi-dimensional behavioral risk detection, and generate multiple user behavior risk types and multiple user behavior risk scores. The risk discrimination and analysis module is used to perform risk discrimination and analysis on the multiple user behavior risk types and multiple user behavior risk scores based on user behavior risk constraints, locate high-risk user terminals, and issue review instructions to the high-risk user terminals. The local data retrieval module is used to retrieve local historical user behavior data of the high-risk user terminal based on the review instruction, and obtain historical user behavior time series data. The data slicing module is used to slice the historical user behavior time series data based on the preset sliding window to obtain multiple historical user behavior slice data. The pattern verification module is used to simulate the behavior evolution based on the multiple historical user behavior slice data, extract historical user behavior trajectories, and verify the user behavior patterns of the high-risk user terminals based on the historical user behavior trajectories. The early warning information generation module is used to mark the high-risk user terminal as an abnormal user terminal and generate network security early warning information when the user behavior pattern verification fails.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, The processor executes the computer program to implement the steps of the network security threat early warning method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data monitoring method and device based on server relational network

    CN115422016A

  • Network information security analysis method and system based on big data

    CN118337484A