Abnormal behavior detection method and device, equipment and medium
By constructing a feature baseline set and combining it with a Bayesian probabilistic algorithm for anomaly assessment, the problem of insufficient robustness and accuracy in existing technologies for anomaly behavior detection is solved, and more comprehensive anomaly behavior detection and assessment is achieved.
Patent Information
- Application Number
- CN202511443268.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2025-11-28
AI Technical Summary
Existing abnormal behavior detection methods have poor robustness and comprehensiveness, low detection efficiency and accuracy, difficulty in conducting correlation analysis of user behavior across different times, locations and systems, and lack consideration for contextual information.
By acquiring real-time behavioral data and historical datasets of target users, a feature baseline set is constructed. Anomaly assessment results are calculated using feature algorithms and Bayesian probability algorithms, and anomaly assessment is performed by combining time, source of occurrence, device, and behavioral interval features.
It improves the robustness and comprehensiveness of abnormal behavior detection, enhances the accuracy of abnormal assessment results, and enables more precise detection of abnormal behavior.
Smart Images

Figure CN121037101A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of security detection, and in particular to a method and device for detecting abnormal behavior, equipment and medium. BACKGROUND
[0002] In the context of increasing digitalization, network security is of paramount importance, and accurate detection of abnormal behavior is a key link.
[0003] Currently, network authentication security mechanisms rely on static rule thresholds or simple baseline statistical methods, which have significant shortcomings in abnormal behavior detection. First, the comprehensiveness and robustness of existing technologies in detection are poor, and the single dimensionality of time and space limits abnormal behavior detection. Traditional methods usually only focus on a single event point, which makes it difficult for them to correlate and analyze isolated behaviors of users at different times, different places, and different systems. Second, the lack of context correlation leads to inaccurate abnormal behavior judgment, and thus poor accuracy of detection results. Simple detection methods often ignore the context information of user behavior, for example, whether a successful system access is followed by multiple failed authentication attempts, or whether abnormal application operations are associated with unconventional login location changes. Due to the lack of overall correlation analysis, it is difficult to accurately distinguish between subtle changes in normal behavior sequences and malicious attack behaviors, and thus it is difficult to accurately detect abnormal behavior. For example, the simple statistical method of existing technologies, in the face of low and slow abnormal attack scenarios such as attempting to crack a library every few hours or slowly accessing a small number of sensitive files, the deviation of single event and historical mean is difficult to exceed the fixed threshold, even if these cumulative behaviors have constituted a serious threat, the method is also difficult to detect abnormal behavior and issue an alarm in a timely manner.
[0004] In summary, the existing abnormal behavior detection method has the problems of poor robustness and comprehensiveness of abnormal behavior detection work, and poor detection efficiency and accuracy of abnormal behavior evaluation results. SUMMARY
[0005] The present application provides an abnormal behavior detection method, device, equipment and medium, which can solve the problem of poor robustness and comprehensiveness of abnormal behavior detection work, and poor detection efficiency and accuracy of abnormal behavior evaluation results of the existing abnormal behavior detection method.
[0006] In a first aspect, the present application provides an abnormal behavior detection method, which comprises:
[0007] In response to the authentication behavior of the target user, the real-time behavior data of the target user and the historical data set of the target user are obtained;
[0008] The historical data set is processed to obtain a feature baseline set matched with the target user;
[0009] The abnormality evaluation result matched with the authentication behavior is calculated according to the feature baseline set and the real-time behavior data.
[0010] In a second aspect, an embodiment of the present application provides an abnormal behavior detection device, which comprises:
[0011] A data acquisition module is configured to acquire real-time behavior data of a target user and a historical data set of the target user in response to an authentication behavior of the target user.
[0012] A baseline generation module is configured to process the historical data set to obtain a feature baseline set matched with the target user.
[0013] A result generation module is configured to calculate an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, which comprises:
[0015] at least one processor; and
[0016] a memory connected with the at least one processor in communication; wherein
[0017] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the abnormal behavior detection method according to any one of the embodiments of the present application.
[0018] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, which stores computer instructions for enabling a processor to execute the abnormal behavior detection method according to any one of the embodiments of the present application.
[0019] The technical scheme of the embodiments of the present application acquires real-time behavior data of a target user and a historical data set of the target user in response to an authentication behavior of the target user, processes the historical data set to obtain a feature baseline set matched with the target user, and calculates an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data, thereby solving the problems of poor robustness and comprehensiveness of abnormal behavior detection, and poor detection efficiency and accuracy of abnormal behavior in the existing abnormal behavior detection methods, and achieving the detection of abnormal behavior of a user, the generation of an abnormality evaluation result, the improvement of robustness and comprehensiveness of abnormal behavior detection, and the improvement of detection efficiency and accuracy of abnormal behavior.
[0020] It is to be understood that the details set forth herein do not limit the scope of the embodiments of the application to the specific embodiments described. Rather, the scope of the embodiments of the application is to be defined by the appended claims. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0022] Figure 1 is a flow chart of an abnormal behavior detection method according to an embodiment of the present application;
[0023] Figure 2 is a flow chart of an abnormal behavior detection method according to an embodiment of the present application;
[0024] Figure 3 is a structural schematic diagram of an abnormal behavior detection device according to an embodiment of the present application;
[0025] Figure 4 is a structural schematic diagram of an electronic device for implementing an abnormal behavior detection method according to an embodiment of the present application. DETAILED DESCRIPTION
[0026] In order to make the technical personnel in the art better understand the present application scheme, the following will combine the drawings in the embodiments of the present application, and the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only some embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present application.
[0027] It should be noted that the terms first, second, etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the term includes and has any variation, which is intended to cover non-exclusive inclusion, for example, the process, method, system, product or device including a series of steps or units does not necessarily limit to the clearly listed steps or units, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0028] Embodiment One
[0029] Figure 1 A flowchart of an abnormal behavior detection method provided by Embodiment One of the present application. This embodiment can be applied to the detection of abnormal behavior of a user. The method can be executed by an abnormal behavior detection device, which can be implemented in the form of hardware and / or software, and can be configured in a terminal or a server having an abnormal behavior detection function.
[0030] As shown in Figure 1 , the method comprises:
[0031] S110, in response to the authentication behavior of the target user, obtaining real-time behavior data of the target user and a historical data set of the target user.
[0032] The real-time behavior data includes time information of the authentication behavior, source information of occurrence, behavior device information, time interval information, and post-authentication behavior.
[0033] Further, the authentication behavior is an identity verification operation triggered by the user to obtain system access permission. The time information is the occurrence time of the authentication behavior. The source information of occurrence includes the source IP address of initiating authentication. The behavior device information is the device identification of the device that occurs the authentication behavior. The time interval information is the time difference between the current successful authentication and the last successful authentication of the target user. The post-authentication behavior refers to the operation behavior of the user on the system resources after authentication, including the accessed application system, the operation type, the operation data volume, etc.
[0034] S120, processing the historical data set to obtain a feature baseline set matched with the target user.
[0035] S130, calculating an abnormal evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data.
[0036] The feature baseline set is a behavior benchmark set constructed for the target user.
[0037] The abnormality evaluation result matched with the authentication behavior is calculated according to the feature baseline set and real-time behavior data, including: the real-time behavior data is processed based on a pre-configured feature algorithm to obtain time features, source features, behavior device features, time interval features and post-authentication features matched with the authentication behavior; an abnormality score matched with the authentication behavior is calculated according to the feature baseline set, the time features, the source features, the behavior device features, the time interval features and the post-authentication features; a pre-set abnormality threshold is obtained, and the abnormality threshold and the abnormality score are used to generate the abnormality evaluation result matched with the authentication behavior.
[0038] In the embodiment, the pre-configured feature algorithm is used to convert the real-time original data related to the target user authentication behavior into real-time feature values that can be used for difference calculation with corresponding baseline feature values in the feature baseline set. In the embodiment, the feature algorithm can be a normalization algorithm, a feature extraction algorithm, etc.
[0039] Further, the time feature is a numerical value obtained by converting and calculating the time information of the current authentication (such as 19:30 on a certain day) through a feature algorithm (such as mapping 24 hours to a numerical interval of 0-1, 19:30 corresponding to 0.8125); the source feature is a numerical value obtained by converting and calculating the source information through a feature algorithm (such as mapping a common IP segment to 0.8-1.0, and a strange IP segment to 0.1-0.3); the behavior device feature is a numerical value obtained by converting and calculating the device information of the current authentication through a feature algorithm (such as mapping a common device to 0.9, and a new device to 0.2); the time interval feature is a numerical value obtained by converting and calculating the time difference between the current authentication and the last authentication (such as 8 hours) through an algorithm (normal interval of 24 hours mapped to 0.9, and 8-hour interval mapped to 0.4); and the post-authentication feature is a numerical value obtained by converting and calculating the first operation after the current authentication through a feature algorithm.
[0040] Further, the abnormality score matched with the authentication behavior is calculated according to the feature baseline set, the time features, the source features, the behavior device features, the time interval features and the post-authentication features, including: a first difference value between the time features and the time feature baseline is calculated, a second difference value between the source features and the source feature baseline is calculated, a third difference value between the behavior device features and the device feature baseline is calculated, a fourth difference value between the time interval features and the interval feature baseline is calculated, and a fifth difference value between the post-authentication features and the post-authentication feature baseline is calculated; the first difference value, the second difference value, the third difference value, the fourth difference value and the fifth difference value are normalized respectively; and the normalized results of the first difference value, the second difference value, the third difference value, the fourth difference value and the fifth difference value are added to obtain the abnormality score matched with the authentication behavior.
[0041] On the basis of the above steps, first find the baseline feature value corresponding to the real-time feature from the feature baseline set, for example, the time information of the authentication behavior is 22:45, and the corresponding time feature is 0.2, locate the baseline time feature value corresponding to the time point 22:45 on the time feature baseline (for example, according to the historical curve, the baseline feature value of 22:45 is 0.15), calculate the difference value as the real-time time feature value 0.2-baseline time feature value 0.15=0.05; find the baseline source feature value corresponding to the IP type on the source feature baseline according to the source information of the authentication behavior (for example, the baseline feature value of the uncommon IP is 0.2), the difference value is 0.3-0.2=0.1; the behavior equipment information of the authentication behavior is a stranger device, and the corresponding behavior equipment feature is 0.25, find the baseline device feature value corresponding to the stranger device on the behavior equipment feature baseline (for example, the baseline feature value of the stranger device is 0.18), the difference value is 0.25-0.18=0.07; the time interval information of the authentication behavior is 18 hours, and the corresponding time interval feature is 0.4, find the baseline interval feature value corresponding to the 18-hour interval on the time interval feature baseline (for example, the baseline feature value of the 18-hour interval is 0.32), the difference value is 0.4-0.32=0.08; if the post-authentication behavior of the authentication behavior is a non-routine operation, and the corresponding post-authentication feature is calculated as 0.35, find the baseline post-authentication feature value corresponding to the non-routine operation (for example, the baseline feature value of the non-routine operation is 0.28), the difference value is 0.35-0.28=0.07. Then directly add the five difference values, that is, 0.05+0.1+0.07+0.08+0.07=0.37, and this accumulated result is the abnormal score of the authentication behavior.
[0042] Optionally, a pre-set abnormal threshold is obtained, and an abnormal evaluation result matched with the authentication behavior is generated based on the abnormal threshold and the abnormal score, including: if the abnormal threshold is less than the abnormal behavior score, an abnormal evaluation result of no abnormal behavior is generated; if the abnormal threshold is not less than the abnormal behavior score, an abnormal warning information is generated and sent to the user, and the abnormal warning information includes the time information, the source information and the behavior equipment information of the current authentication behavior.
[0043] The technical scheme of the embodiment of the present application, by responding to the authentication behavior of the target user, obtains the real-time behavior data of the target user and the historical data set of the target user, then processes the historical data set to obtain a feature baseline set matched with the target user, and finally calculates an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data, which can detect the abnormal behavior of the user, generate the abnormality evaluation result, improve the robustness and comprehensiveness of the abnormal behavior detection work, and also improve the detection efficiency of the abnormal behavior and the accuracy of the abnormality evaluation result.
[0044] Embodiment two
[0045] Figure 2 The flowchart of the abnormal behavior detection method provided by the second embodiment of the present application is based on the above-mentioned embodiment and is refined in this embodiment. In this embodiment, the method of processing the historical data set to obtain a feature baseline set matched with the target user is refined.
[0046] As shown in Figure 2 , the method comprises:
[0047] S210, in response to the authentication behavior of the target user, obtaining the real-time behavior data of the target user and the historical data set of the target user.
[0048] S220, processing the historical data set to obtain a historical behavior chain matched with the target user.
[0049] Among them, processing the historical data set to obtain a historical behavior chain matched with the target user comprises: performing an ascending order sorting operation on each historical data in the historical data set based on the historical authentication time of each historical data to obtain a historical data sequence; using a sequence mining algorithm to extract a frequent behavior pattern from the historical data sequence to obtain a historical behavior chain matched with the target user.
[0050] The historical authentication time refers to the specific time when the user initiates the identity verification operation corresponding to each piece of historical data. The ascending order sorting operation is an operation of rearranging all data entries in the historical data set in the order from early to late according to time. For example, if a target user's historical data set contains 5 pieces of historical data, the corresponding historical authentication times are April 5, 2024, 10:20, April 3, 2024, 9:15:40, April 4, 2024, 8:30, April 3, 2024, 14:50, after the ascending order sorting operation, the obtained historical data sequence is [data corresponding to April 3, 2024, 9:15, data corresponding to April 3, 2024, 14:50, data corresponding to April 4, 2024, 8:30, data corresponding to April 5, 2024, 10:20, and data corresponding to April 5, 2024, 15:40].
[0051] Further, the sequence mining algorithm is a data analysis technology for discovering frequently occurring and regular behavior combinations from a data sequence arranged in time or logical order. In the present embodiment, the sequence mining algorithm can be specifically AprioriAll algorithm, GSP generalized sequence pattern algorithm, etc. The frequent behavior pattern is a behavior combination that repeatedly appears in the historical data sequence and can reflect the user's stable behavior habit. For example, a target user has 70% of authentication behaviors in the historical data sequence that meet the characteristics of using the company intranet IP and logging into the system through the office computer during 8:30-9:00 on weekdays, and first accessing the OA system to check work emails after logging in. This high-frequency behavior combination is the frequent behavior pattern of the user. Further, the historical behavior chain is an ordered behavior set formed by concatenating the extracted multiple frequent behavior patterns according to their time association relationship in the historical data sequence. For example, two frequent behavior patterns of logging in in the morning on weekdays (8:30-9:00, company IP, office computer) - accessing OA system - processing documents, and logging in in the afternoon on weekdays (13:30-14:00, company IP, office computer) - accessing CRM system - checking customer data are extracted from a user's historical data sequence by the sequence mining algorithm. The two patterns are concatenated in the time order of the user's daily behavior to form the user's historical behavior chain.
[0052] Those skilled in the art should understand that the method of using the sequence mining algorithm to obtain a historical behavior chain matching the historical data sequence in the case of known historical data sequence is a mature existing technology, and the principles and specific calculation steps thereof will not be described here.
[0053] S230, using a Bayesian probability algorithm to process the historical behavior chain to obtain a feature baseline set matching the target user.
[0054] The Bayesian probability algorithm is a probability calculation method based on Bayes theorem, which is used to mine the exclusive behavior probability distribution of the target user based on the historical behavior chain of the target user, so as to construct a feature baseline that fits the individual habits.
[0055] The Bayesian probability algorithm is used to process the historical behavior chain to obtain a feature baseline set matched with the target user, including: screening historical authentication time data corresponding to each historical data from the historical behavior chain, calculating each historical authentication time data by the Bayesian probability algorithm to obtain a time historical baseline; screening historical occurrence source information corresponding to each historical data from the historical behavior chain, and calculating each historical occurrence source information by the Bayesian probability algorithm to obtain an occurrence source historical baseline; screening historical device information corresponding to each historical data from the historical behavior chain, and calculating each historical device information by the Bayesian probability algorithm to obtain a device historical baseline; screening historical interval information corresponding to each historical data from the historical behavior chain, and calculating each historical interval information by the Bayesian probability algorithm to obtain an interval historical baseline; screening historical post-authentication behavior corresponding to each historical data from the historical behavior chain, and calculating each historical post-authentication behavior by the Bayesian probability algorithm to obtain a post-authentication behavior historical baseline; and performing feature processing on the time historical baseline, the occurrence source historical baseline, the device historical baseline, the interval historical baseline, and the post-authentication behavior historical baseline to obtain a feature baseline set, which includes a time feature baseline, an occurrence source feature baseline, a device feature baseline, an interval feature baseline, and a post-authentication feature baseline.
[0056] The historical event data is specific time information of a user initiating an identity verification operation corresponding to each behavior record in the historical behavior chain; the historical occurrence source information is source-related information of initiating an authentication request corresponding to each behavior record in the historical behavior chain; the historical device information is unique identification information of a device used by a user to initiate authentication corresponding to each behavior record in the historical behavior chain; the historical interval information is a time difference between two adjacent successful authentication records in the historical behavior chain; and the historical post-authentication behavior is an operation behavior of a user on a system resource after successfully passing authentication corresponding to each authentication record in the historical behavior chain.
[0057] Exemplarily, the historical authentication time data corresponding to each historical data is screened out from the historical behavior chain, and the historical authentication time data is calculated by using a Bayesian probability algorithm to obtain a time historical baseline. Specifically, when the Bayesian probability algorithm is used for calculation, the time is first divided into a plurality of continuous intervals, and then the number of authentications in a certain time period is used as prior data, and the posterior probability of the user's authentication behavior in each time period is calculated by using the Bayesian theorem. For example, 100 pieces of historical authentication time data are screened out from the historical behavior chain of a target user, among which 35 pieces fall in the morning 8:00-9:00, 25 pieces fall in the afternoon 13:30-14:30, and the remaining 40 pieces are scattered in other time periods. Through the Bayesian algorithm calculation, it can be obtained that the authentication probability of the user in 8:00-9:00 is 35%, and the authentication probability in 13:30-14:30 is 25%. The authentication probability distribution in different time periods jointly constitutes the time historical baseline.
[0058] Those skilled in the art should understand that the method of using the Bayesian probability algorithm to obtain the baseline under the premise of the known historical behavior chain is a mature prior art. The above examples only exemplify the method of obtaining the time historical baseline. The historical occurrence source information, historical device information, historical interval information, and historical post-authentication behavior are screened out from the historical behavior chain, and the occurrence source historical baseline, the device historical baseline, the interval historical baseline, and the post-authentication behavior historical baseline are obtained by using the Bayesian probability algorithm. The core logic of the above four types of baselines is consistent with the method of obtaining the time historical baseline. Therefore, to avoid redundancy, the above examples will not be described in detail.
[0059] S240, calculating an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data.
[0060] The technical scheme of the embodiment of the application can obtain the real-time behavior data of the target user and the historical data set of the target user in response to the authentication behavior of the target user, then process the historical data set to obtain a historical behavior chain matched with the target user, process the historical behavior chain by using a Bayesian probability algorithm to obtain a feature baseline set matched with the target user, and finally calculate an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data. The abnormality behavior of the user can be detected, the abnormality evaluation result is generated, the robustness and comprehensiveness of the abnormality behavior detection work are improved, and the detection efficiency of the abnormality behavior and the accuracy of the abnormality evaluation result are also improved.
[0061] Embodiment three
[0062] Figure 3 Figure 1 is a schematic structural diagram of an abnormal behavior detection device according to an embodiment of the present application. Figure 3 As shown in the figure, the device comprises:
[0063] a data acquisition module 310 configured to acquire real-time behavior data of a target user and a historical data set of the target user in response to an authentication behavior of the target user;
[0064] a baseline generation module 320 configured to process the historical data set to obtain a feature baseline set matched with the target user;
[0065] a result generation module 330 configured to calculate an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data.
[0066] The technical scheme of the embodiment of the present application can acquire real-time behavior data of a target user and a historical data set of the target user in response to an authentication behavior of the target user, then process the historical data set to obtain a feature baseline set matched with the target user, and finally calculate an abnormality evaluation result matched with the authentication behavior according to the feature baseline set and the real-time behavior data, thereby detecting abnormal behavior of a user, generating an abnormality evaluation result, improving the robustness and comprehensiveness of abnormal behavior detection work, and improving the detection efficiency of abnormal behavior and the accuracy of the abnormality evaluation result.
[0067] On the basis of the above embodiment, the baseline generation module 320 comprises:
[0068] a behavior chain generation unit configured to process the historical data set to obtain a historical behavior chain matched with the target user;
[0069] a feature baseline generation unit configured to process the historical behavior chain using a Bayesian probability algorithm to obtain the feature baseline set matched with the target user.
[0070] On the basis of the above embodiment, the behavior chain generation unit comprises:
[0071] a data sorting unit configured to sort each historical data in the historical data set in ascending order based on a historical authentication time of each historical data to obtain a historical data sequence;
[0072] a sequence mining unit configured to extract a frequent behavior pattern from the historical data sequence using a sequence mining algorithm to obtain the historical behavior chain matched with the target user.
[0073] On the basis of the above embodiment, the feature baseline generation unit comprises:
[0074] a time history baseline generation unit configured to filter historical authentication time data corresponding to each historical data from the historical behavior chain, and calculate each historical authentication time data by using a Bayesian probability algorithm to obtain a time history baseline;
[0075] a source history baseline generation unit configured to filter historical source information corresponding to each historical data from the historical behavior chain, and calculate each historical source information by using a Bayesian probability algorithm to obtain a source history baseline;
[0076] a device history baseline generation unit configured to filter historical device information corresponding to each historical data from the historical behavior chain, and calculate each historical device information by using a Bayesian probability algorithm to obtain a device history baseline;
[0077] an interval history baseline generation unit configured to filter historical interval information corresponding to each historical data from the historical behavior chain, and calculate each historical interval information by using a Bayesian probability algorithm to obtain an interval history baseline;
[0078] a post-authentication behavior history baseline generation unit configured to filter historical post-authentication behavior corresponding to each historical data from the historical behavior chain, and calculate each historical post-authentication behavior by using a Bayesian probability algorithm to obtain a post-authentication behavior history baseline;
[0079] a feature baseline set generation unit configured to perform feature processing on the time history baseline, the source history baseline, the device history baseline, the interval history baseline, and the post-authentication behavior history baseline to obtain a feature baseline set, wherein the feature baseline set includes a time feature baseline, a source feature baseline, a device feature baseline, an interval feature baseline, and a post-authentication feature baseline.
[0080] In the above embodiment, the result generation module 330 includes:
[0081] a feature processing unit configured to process the real-time behavior data based on a preconfigured feature algorithm to obtain a time feature, a source feature, a behavior device feature, a time interval feature, and a post-authentication feature matched with the authentication behavior;
[0082] an anomaly score calculation unit configured to calculate an anomaly score matched with the authentication behavior according to the feature baseline set, the time feature, the source feature, the behavior device feature, the time interval feature, and the post-authentication feature;
[0083] a result generation unit configured to obtain a preconfigured anomaly threshold, and generate an anomaly evaluation result matched with the authentication behavior based on the anomaly threshold and the anomaly score.
[0084] In the above embodiment, the anomaly score calculation unit includes:
[0085] a difference calculation unit configured to calculate a first difference between the time feature and a time feature baseline, calculate a second difference between the source feature and a source feature baseline, calculate a third difference between the behavior device feature and a device feature baseline, calculate a fourth difference between the time interval feature and an interval feature baseline, and calculate a fifth difference between the post-authentication feature and a post-authentication feature baseline;
[0086] a normalization unit configured to normalize the first difference, the second difference, the third difference, the fourth difference, and the fifth difference, respectively;
[0087] an accumulation unit configured to accumulate the normalized results of the first difference, the second difference, the third difference, the fourth difference, and the fifth difference to obtain an anomaly score matched with the authentication behavior.
[0088] The anomaly behavior detection device provided by the embodiment of the present application can execute the anomaly behavior detection method provided by any embodiment of the present application, and has the corresponding function modules and beneficial effects of the execution method.
[0089] Embodiment Four
[0090] Figure 4 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the present application described and / or claimed in this document to the embodiments presented herein.
[0091] As Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11, wherein the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0092] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0093] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as an abnormal behavior detection method.
[0094] Correspondingly, the method includes:
[0095] In response to the authentication behavior of the target user, obtaining real-time behavior data of the target user and a historical data set of the target user;
[0096] Processing the historical data set to obtain a feature baseline set matched with the target user;
[0097] According to the feature baseline set and the real-time behavior data, calculating an abnormality evaluation result matched with the authentication behavior.
[0098] In some embodiments, a method of detecting abnormal behavior can be implemented as a computer program tangibly embodied in a computer readable storage medium, e.g., storage unit 18. In some embodiments, portions or all of the computer program can be loaded and / or installed onto electronic device 10 via, e.g., ROM 12 and / or communication unit 19. When the computer program is loaded onto RAM 13 and executed by processor 11, one or more steps of a method of detecting abnormal behavior as described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform a method of detecting abnormal behavior by other means, e.g., with the aid of firmware.
[0099] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, specially designed application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0100] Computer programs implementing methods of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0101] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0102] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0103] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), blockchain network, and the Internet.
[0104] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0105] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, each step described in the present application can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, which is not limited herein.
Claims
1. A method for detecting abnormal behavior, characterized in that, include: In response to the authentication behavior of the target user, acquire the target user's real-time behavioral data and historical dataset; The historical dataset is processed to obtain a feature baseline set that matches the target user; An anomaly assessment result matching the authentication behavior is calculated based on the feature baseline set and real-time behavior data.
2. The method according to claim 1, characterized in that, The real-time behavioral data includes: the time information, source information, device information, time interval information, and post-authentication behavior of the authentication behavior.
3. The method according to claim 1, characterized in that, The historical dataset is processed to obtain a feature baseline set matching the target user, including: The historical dataset is processed to obtain a historical behavior chain that matches the target user; The historical behavior chain is processed using a Bayesian probabilistic algorithm to obtain a feature baseline set that matches the target user.
4. The method according to claim 3, characterized in that, The historical dataset is processed to obtain a historical behavior chain matching the target user, including: Based on the historical authentication time of each historical data in the historical dataset, the historical data are sorted in ascending order to obtain a historical data sequence. The historical data sequence is used to extract frequent behavior patterns, and the historical behavior chain matching the target user is obtained.
5. The method according to claim 3, characterized in that, The historical behavior chain is processed using a Bayesian probabilistic algorithm to obtain a feature baseline set matching the target user, including: Historical authentication time data corresponding to each historical data is selected from the historical behavior chain, and the historical authentication time data is calculated using a Bayesian probability algorithm to obtain the historical time baseline. Historical source information corresponding to each historical data is selected from the historical behavior chain, and the historical source information is calculated using a Bayesian probability algorithm to obtain the historical baseline of the source. Historical device information corresponding to each historical data is selected from the historical behavior chain, and the historical device information is calculated using a Bayesian probability algorithm to obtain the device historical baseline. Historical interval information corresponding to each historical data is selected from the historical behavior chain, and the historical interval information is calculated by Bayesian probability algorithm to obtain the historical interval baseline. The historical post-authentication behaviors corresponding to each historical data are selected from the historical behavior chain, and the historical post-authentication behaviors are calculated using a Bayesian probability algorithm to obtain the historical baseline of post-authentication behaviors. The time history baseline, the occurrence source history baseline, the device history baseline, the interval history baseline, and the post-authentication behavior history baseline are characterized to obtain a feature baseline set, which includes: time feature baseline, occurrence source feature baseline, device feature baseline, interval feature baseline, and post-authentication feature baseline.
6. The method according to any one of claims 1-2, characterized in that, Based on the feature baseline set and real-time behavior data, an anomaly assessment result matching the authentication behavior is calculated, including: The real-time behavior data is processed based on a pre-configured feature algorithm to obtain time features, occurrence source features, behavior device features, time interval features, and post-authentication features that match the authentication behavior. An anomaly score matching the authentication behavior is calculated based on the feature baseline set, time features, occurrence source features, behavior device features, time interval features, and post-authentication features. Obtain a pre-set anomaly threshold, and generate an anomaly assessment result matching the authentication behavior based on the anomaly threshold and the anomaly score.
7. The method according to claim 6, characterized in that, An anomaly score matching the authentication behavior is calculated based on the aforementioned feature baseline set, time features, source features, behavioral device features, time interval features, and post-authentication features, including: Calculate the first difference between the time feature and the time feature baseline, calculate the second difference between the occurrence source feature and the occurrence source feature baseline, calculate the third difference between the behavior device feature and the device feature baseline, calculate the fourth difference between the time interval feature and the interval feature baseline, and calculate the fifth difference between the post-authentication feature and the post-authentication feature baseline. Normalize the first difference, the second difference, the third difference, the fourth difference, and the fifth difference respectively; The normalized results of the first, second, third, fourth, and fifth differences are summed to obtain the anomaly score that matches the authentication behavior.
8. A device for detecting abnormal behavior, characterized in that, include: The data acquisition module is used to respond to the authentication behavior of the target user and acquire the target user's real-time behavioral data and historical dataset. The baseline generation module is used to process the historical dataset to obtain a feature baseline set that matches the target user; The result generation module is used to calculate an anomaly evaluation result that matches the authentication behavior based on the feature baseline set and real-time behavior data.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform a method for detecting abnormal behavior according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement a method for detecting abnormal behavior according to any one of claims 1-7.