User risk behavior early warning method and device for operating system, medium and product

By monitoring user behavior and using a multi-layered knowledge base to calculate risk entropy values, the risk problem caused by legitimate user operations in the operating system is solved, and efficient risk warning is achieved.

CN121167697APending Publication Date: 2025-12-19LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511327993.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-12-19

AI Technical Summary

Technical Problem

Existing operating systems cannot prevent legitimate user actions from being blocked by antivirus or hardening software that targets blacklisted users, leading to unexpected system damage.

Method used

By monitoring user behavior, matching user operation information with a pre-set risk warning network and a multi-layered knowledge base, and calculating risk entropy values, it is determined whether to issue a risk behavior warning.

Benefits of technology

It improves the accuracy of risk behavior warnings, avoids accidental damage to the system caused by legitimate user operations, saves system resources, and reduces false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121167697A_ABST
    Figure CN121167697A_ABST
Patent Text Reader

Abstract

The invention discloses a user risk behavior early warning method and device for an operating system, a medium and a product, and relates to the technical field of computers, and the method comprises the steps: monitoring a target user behavior of a target operating system, and inputting the obtained information into a preset risk early warning network, matching the corresponding target monitoring information by sequentially utilizing each locally pre-configured target knowledge base through a preset risk early warning network, and if each piece of target monitoring information is successfully matched in the corresponding target knowledge base, determining a preset weight and a target risk coefficient corresponding to each piece of target monitoring information by utilizing the target knowledge base, and finally, determining a risk entropy value corresponding to the target user behavior according to a preset weight value and the target risk coefficient, and determining whether risk behavior early warning is performed or not based on the risk entropy value. Therefore, risk behavior early warning can be performed according to various operation information of the user, so that the damage of the risk behavior of the user to the operation system is effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, device, medium and product for early warning of user risk behavior in an operating system. Background Technology

[0002] As the foundational software of a computer, the operating system undertakes core functions such as scheduling hardware resources, managing process communication, and ensuring data security. It serves as the basic platform upon which upper-layer business software runs. In critical sectors such as finance, healthcare, and industrial control, if the operating system fails, it can severely impact numerous data centers. Furthermore, the operation and management of operating systems in such environments is highly complex, involving customers, third-party maintenance personnel, and vendor maintenance staff. The different roles involved in operating the system can lead to numerous human error issues.

[0003] Although many operating systems employ security hardening and protection measures for business security, these protections typically target blacklists, such as viruses and malicious attacks. However, outside of antivirus or hardening software protection, when users access operating system configurations or data using legitimate passwords, programs, or software, these methods often consider it legitimate and do not block it. Such human intervention can frequently lead to unexpected system failures or even severe damage. Summary of the Invention

[0004] This application provides a method, device, medium, and product for early warning of user risk behavior in an operating system. It can provide early warning of risk behavior based on various user operation information, thereby effectively preventing user risk behavior from damaging the operating system.

[0005] This application provides a user risk behavior early warning method for an operating system, including:

[0006] The target user behavior of the target operating system is monitored to obtain target monitoring information; each target monitoring information includes user information of the target user who performs the target user behavior, operation information corresponding to the target user behavior, and target process information corresponding to the operation information.

[0007] The monitoring information of each target is input into the preset risk warning network, so that the preset risk warning network can sequentially use the local pre-configured target knowledge base to match the corresponding target monitoring information; wherein, the target knowledge base is a knowledge base constructed based on historical monitoring information of historical user risk behavior, and different target knowledge bases correspond to different types of monitoring information.

[0008] If each target monitoring information is successfully matched in the corresponding target knowledge base, the target knowledge base is used to determine the preset weight and target risk coefficient corresponding to each target monitoring information;

[0009] The risk entropy value corresponding to the target user behavior is determined based on the preset weight and target risk coefficient, and whether to issue a risk behavior warning is determined based on the risk entropy value.

[0010] This application also provides a user risk behavior early warning device for an operating system, including:

[0011] The behavior monitoring module is used to monitor the behavior of target users on the target operating system and obtain various target monitoring information. Each target monitoring information includes user information of the target user who performed the target user behavior, operation information corresponding to the target user behavior, and target process information corresponding to the operation information.

[0012] The information matching module is used to input the monitoring information of each target into the preset risk warning network, so that the preset risk warning network can sequentially use the local pre-configured target knowledge bases to match the corresponding target monitoring information; wherein, the target knowledge base is a knowledge base constructed based on historical monitoring information of historical user risk behavior, and different target knowledge bases correspond to different types of monitoring information.

[0013] The parameter determination module is used to determine the preset weight and target risk coefficient corresponding to each target monitoring information if each target monitoring information is successfully matched in the corresponding target knowledge base.

[0014] The risk behavior early warning module is used to determine the risk entropy value corresponding to the target user's behavior based on the preset weight and target risk coefficient, and to determine whether to issue a risk behavior early warning based on the risk entropy value.

[0015] This application also provides an electronic device, including: a memory for storing a computer program; and a processor for executing the computer program to implement the user risk behavior warning method of any of the above operating systems.

[0016] This application also provides a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, it implements the steps of the user risk behavior warning method of any of the above-mentioned operating systems.

[0017] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of a user risk behavior warning method for any of the above-described operating systems.

[0018] In this application, target user behavior of a target operating system can be monitored to obtain target monitoring information. Each target monitoring information includes user information of the target user performing the target user behavior, operation information corresponding to the target user behavior, and target process information corresponding to the operation information. The target monitoring information is input into a preset risk warning network, which sequentially uses pre-configured local target knowledge bases to match the corresponding target monitoring information. The target knowledge base is constructed based on historical monitoring information of historical user risk behaviors, and different target knowledge bases correspond to different types of monitoring information. If each target monitoring information is successfully matched in its corresponding target knowledge base, the preset weight and target risk coefficient corresponding to each target monitoring information are determined using the target knowledge base. The risk entropy value corresponding to the target user behavior is determined based on the preset weight and target risk coefficient, and a risk behavior warning is issued based on the risk entropy value.

[0019] Therefore, the method of this application can match the monitored information of the target user in the target operating system with a preset risk warning network. The preset risk warning network needs to sequentially use pre-configured local target knowledge bases to match the target monitoring information. If each piece of monitoring information matches successfully in its corresponding target knowledge base, the target knowledge base is used to determine the preset weight and target risk coefficient corresponding to each piece of monitoring information. Based on the preset weight and target risk coefficient, the risk entropy value corresponding to the target user's behavior is determined, and a risk behavior warning is issued based on the risk entropy value. In this way, a comprehensive evaluation can be performed by acquiring information such as the logged-in user, subject, object, operation behavior, and data content during the user's operation process. Through evaluation formulas and high-speed search algorithms, the potential danger of an operation can be quickly identified. Attached Figure Description

[0020] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A flowchart of a user risk behavior early warning method for an operating system provided in this application embodiment;

[0022] Figure 2 A schematic diagram of parameters for a first target knowledge base provided in an embodiment of this application;

[0023] Figure 3 A schematic diagram of parameters for a second target knowledge base provided in an embodiment of this application;

[0024] Figure 4 A schematic diagram illustrating the specific process of a user risk behavior early warning method for an operating system provided in this application embodiment;

[0025] Figure 5 A schematic diagram of multi-layer network matching provided in an embodiment of this application;

[0026] Figure 6 This is a schematic diagram of the structure of a user risk behavior early warning device for an operating system provided in an embodiment of this application. Detailed Implementation

[0027] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0028] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0029] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0030] Currently, while many operating systems have implemented security hardening and protection measures for business security, these protections primarily target blacklists, such as viruses and malicious attacks. However, beyond the protection of antivirus or hardening software, users may engage in risky behaviors when configuring or accessing operating system data using legitimate passwords, programs, or software. These behaviors are often considered legitimate by antivirus and hardening software and are not blocked. However, such human intervention can frequently lead to unexpected system failures or even severe damage.

[0031] To overcome the aforementioned technical problems, this application discloses a method, device, medium, and product for early warning of user risk behavior in an operating system. It can provide early warning of risk behavior based on various user operation information, thereby effectively preventing user risk behavior from damaging the operating system.

[0032] This application provides an embodiment of a user risk behavior warning method for an operating system. The method is described in detail below, in conjunction with the execution flow of the user risk behavior warning method for an operating system. The method includes:

[0033] Step S11: Monitor the target user behavior of the target operating system to obtain target monitoring information; each target monitoring information includes user information of the target user who performs the target user behavior, operation information corresponding to the target user behavior, and target process information corresponding to the operation information.

[0034] In this embodiment, it is necessary to monitor the target user behavior of the target operating system to obtain target monitoring information corresponding to the target user. Specifically, it is necessary to track the target user through a preset monitoring tool and determine the target user identity, the target file information corresponding to the user operation file, the target operation action, and the target operation content based on the user operation log corresponding to the target user behavior. It should be noted that the target user identity represents the identity of the user performing the operation, the target file information represents the target file or resource being operated on, the target operation action represents the specific behavior performed by the target user, such as read / write or delete operations, and the target operation content represents the specific content of the action. For example, for a write operation, the operation content is the specific data written; for a network connection, the operation content is the data packet payload sent; and for command execution, the operation content is the specific command typed in the shell. Furthermore, it is necessary to determine the target process created by the target operating system when executing the target operation content and to determine the target process information corresponding to the target process. It should be noted that when the operating system executes a corresponding command, it needs to create a corresponding process to execute the command. Therefore, it is necessary to determine the target process created by the target operating system when executing the target operation content and to determine the process information of the target process. This allows for the accurate collection of various target monitoring information from target users, thereby indirectly improving the accuracy of early warnings of user risk behaviors.

[0035] Step S12: Input the monitoring information of each target into the preset risk warning network, so that the preset risk warning network can sequentially use the local pre-configured target knowledge base to match the corresponding target monitoring information; wherein, the target knowledge base is a knowledge base constructed based on historical monitoring information of historical user risk behavior, and different target knowledge bases correspond to different types of monitoring information.

[0036] In this embodiment, the detection information of each target needs to be input into a preset risk warning network to match the detection information with the knowledge base in the risk warning network. However, before matching, it is necessary to first create a target knowledge base for the preset risk warning network. Specifically, historical risk behavior cases need to be collected and analyzed to determine the historical monitoring information corresponding to the historical risk behavior cases. The historical monitoring information includes historical user identity, historical file information, historical operation actions, historical operation content, and historical process information. Then, the historical monitoring information needs to be classified to obtain classified historical monitoring information. It should be noted that each type of monitoring information corresponds to a different category. For example, user identity includes administrator, ordinary user, and network user; process information includes user-mode process and kernel-mode process; operation actions include read, write, delete, and update; file information includes configuration files, binary files, and kernel files; operation content includes inserting and deleting a certain type of file. Finally, several risk knowledge bases can be constructed based on the classified historical monitoring information, and these risk knowledge bases can be used as the target knowledge base of the preset risk warning network.

[0037] It should be noted that the target knowledge base is divided into two types: the first type is a four-layer network, and the second type is a network composed of operational content. Specifically, the first target knowledge base in the preset risk warning network needs to be constructed based on the classified historical user identities, classified historical file information, classified historical operation actions, and classified historical process information from the classified historical monitoring information. The first target knowledge base includes a first-layer target knowledge base corresponding to user identities, a second-layer target knowledge base corresponding to process information, a third-layer target knowledge base corresponding to operation actions, and a fourth-layer target knowledge base corresponding to file information. Furthermore, as... Figure 2As shown, the first layer of the target knowledge base corresponds to the user layer, containing different types of user identities, corresponding weights for each user identity, and the judgment principles for different types of user identities. For example, the different types of user identities in the first layer of the target knowledge base include super administrators, ordinary users, and network users; the weight corresponding to a super administrator is 0.9, and the judgment principle is to judge through methods such as Root; the weight corresponding to an ordinary user is 0.8, and the judgment principle is that the user is a non-administrator user, such as an ordinary user named 'test' created during development and testing to test the functions and permissions of ordinary users; among them, the weight corresponding to a network user is 0.7, and the judgment principle is that the user logs in through the business logic. The second layer of the target knowledge base corresponds to the main body layer and contains different types of process information, their corresponding weights, and the judgment principles for different types of process information. For example, the different types of process information in the second layer of the target knowledge base include user-mode processes and kernel-mode processes; the weight corresponding to user-mode processes is 1.1, and the judgment principle is processes that can be manually operated, such as vi, vim, echo, touch, etc.; the weight corresponding to kernel-mode processes is 1.2, and the judgment principle is some commands that can run in kernel mode but cannot run in user mode, such as insod, rmmod, probe, etc. The third layer of the target knowledge base corresponds to the action layer and contains different types of operation actions, their corresponding weights, and the judgment principles for different types of operation actions, such as Delete, Write, Update, Read, etc., where the weight of Delete is 2, the weight of Write is 1.9, the weight of Update is 1.7, and the weight of Read is 1. The fourth layer, the target knowledge base, corresponds to the object layer and contains information on different types of files, their corresponding weights, and the judgment principles for different types of files, such as configuration files, binary files, and kernel files. Configuration files have a weight of 1.1, and the judgment principle is files with the .conf extension. Binary files have a weight of 1.3, and the judgment principle is binary files stored in the / usr / sbin directory. Kernel files have a weight of 1.5, and the judgment principle is files stored in the / kernel directory.

[0038] Furthermore, based on the categorized historical operations from the categorized historical monitoring information, a second target knowledge base needs to be constructed within the pre-defined risk warning network. Specifically, risk coefficients and risk entropy values ​​need to be assigned to the categorized historical operations from the categorized historical monitoring information according to pre-defined assignment rules to obtain several risk coefficients and several risk entropy values ​​corresponding to the categorized historical operations. Then, the second target knowledge base within the pre-defined risk warning network is constructed based on the categorized historical operations, several risk coefficients, and several risk entropy values. It should be noted that the pre-defined assignment rules are derived from a summary of historical cases where problems were caused by human error, and risk coefficients and risk entropy values ​​are assigned based on these historical cases. Furthermore, as... Figure 3 The example shown illustrates a second target knowledge base. This base includes actions and content corresponding to different file types, network risk coefficients, and risk entropy values ​​for each file type. For configuration files, the actions are write, modify, and delete. It's necessary to determine if the file content after writing, modifying, or deleting conforms to the configuration file format. The network risk coefficient for configuration files corresponding to these actions and content is 10, with a risk entropy value range of 0 to 50. For binary files, the actions are insert and delete. It's necessary to determine whether the insertion and deletion positions and content will affect the binary file. For example, inserting a few characters into the middle of a binary file has a high risk factor. The network risk coefficient for binary files corresponding to these actions and content is 50, with a risk entropy value range of 50 to 100. For kernel configuration files, the action is modification. It's necessary to determine if the modified content matches the original content. Examples include modifying the boot file, the grub file, and files in the / etc / fstab directory. The network risk coefficient for kernel configuration files corresponding to these actions and content is 100, with a risk entropy value range of 100 to 200. This allows risk coefficients and risk entropy values ​​to be stored in a structured form, facilitating rapid querying and matching by the risk warning network, thereby improving the efficiency of risk warning.

[0039] In this embodiment, target monitoring information needs to be matched using a first target knowledge base and a second target knowledge base. Specifically, it is necessary to determine whether the target user identity matches the historical user identity in the first-layer target knowledge base to obtain a first matching result. If the first matching result indicates a successful match, it is then determined whether the target process information matches the historical process information in the second-layer target knowledge base to obtain a second matching result. If the second matching result indicates a successful match, it is then determined whether the target operation action in the operation information matches the historical operation action in the third-layer target knowledge base to obtain a third matching result. If the third matching result indicates a successful match, it is then determined whether the target file information in the operation information matches the historical file information in the fourth-layer target knowledge base to obtain a fourth matching result. If the fourth matching result indicates a successful match, the target operation content is matched with the historical operation content in the second target knowledge base to determine the target historical operation content corresponding to the target operation content in the historical operation content. Therefore, it can be seen that the target monitoring information first needs to be matched through the four-layer network of the first target knowledge base. Only if all four layers match, the second target knowledge base is used for matching. In this way, the matching efficiency is effectively optimized. Information matching continues only when there is a complete match, and processing resources are saved.

[0040] Step S13: If each target monitoring information is successfully matched in the corresponding target knowledge base, then the preset weight and target risk coefficient corresponding to each target monitoring information are determined using the target knowledge base.

[0041] In this embodiment, before obtaining the preset weights and risk coefficients, if any of the first, second, third, and fourth matching results indicates a matching failure, the risk behavior warning is exited. It should be noted that since the four-layer network in the first target knowledge base is progressive, a matching failure occurs in any layer of the knowledge base, indicating that the current user's operation does not pose a risk to the operating system. Therefore, the risk warning needs to be exited to save system resources.

[0042] Furthermore, if the first, second, third, and fourth matching results all indicate a successful match, then the preset weights corresponding to each target monitoring information are obtained from the first target knowledge base. Specifically, if all four layers of the first target knowledge base are successfully matched, it indicates that the current user's operation on the operating system is risky, and it is necessary to first obtain the preset weights corresponding to the target monitoring information and the information that matches in the first to fourth layers of the target knowledge base. Then, it is necessary to obtain the target risk coefficient corresponding to the operation content in the target monitoring information from the second target knowledge base.

[0043] It should be noted that when retrieving the preset weights corresponding to the monitoring information of each target from the first target knowledge base, if the first matching result indicates a successful match, the target user's identity type is determined, and the first preset weight corresponding to the target identity type is retrieved from the first-level target knowledge base. For example, if the target user's identity is a regular user, its first preset weight is 0.8. If the second matching result indicates a successful match, the process command corresponding to the target process information is determined, and the process information type of the target process information is determined based on the process command. The second preset weight corresponding to the process information type is retrieved from the second-level target knowledge base. For example... If the process information type of the target process information is a user-mode process, then its second preset weight is 1.1; if the third matching result indicates a successful match, then the action instruction corresponding to the target operation is determined, and the third preset weight corresponding to the action instruction is obtained from the third-level target knowledge base. For example, if the target operation is Write, then its third preset weight is 1.9; if the fourth matching result indicates a successful match, then the file type corresponding to the target file information is determined, and the fourth preset weight corresponding to the file type is obtained from the fourth-level target knowledge base. For example, if the target file information is a configuration file, then its fourth preset weight is 1.1.

[0044] Furthermore, when obtaining the target risk coefficient from the second target knowledge base, it is necessary to match the target operation content with the historical operation content in the second target knowledge base to identify the target historical operation content that corresponds to the target operation content. Then, based on the operation type and file type corresponding to the target historical operation content, the target risk coefficient corresponding to the target operation content is determined. For example, if the target file information is a configuration file and the operation content is to write certain content into the configuration file, then a match can be determined, and its network risk coefficient is 10. In this way, the traditional neural network optimization concept can be reconstructed into a knowledge base based on multi-layer filtering. After multi-layer filtering processing, the final result is extracted to improve the accuracy of the early warning.

[0045] Step S14: Determine the risk entropy value corresponding to the target user behavior based on the preset weight and target risk coefficient, and determine whether to issue a risk behavior warning based on the risk entropy value.

[0046] In this embodiment, it is necessary to calculate the product of the first preset weight, the second preset weight, the third preset weight, the fourth preset weight, and the target risk coefficient, and use the value of the product as the risk entropy value corresponding to the target user behavior. Specifically, it is necessary to first calculate the target weight corresponding to the target user behavior according to the preset weight calculation formula, and then calculate the risk entropy value corresponding to the target user behavior based on the risk entropy value calculation formula.

[0047] The formula for calculating the weights is as follows:

[0048] ;

[0049] in, The target weight is handle(user), the first preset weight is handle(host), the second preset weight is handle(op), the third preset weight is handle(obj), and the fourth preset weight is handle(obj).

[0050] The formula for calculating the risk entropy value is as follows:

[0051] ;

[0052] Where Value(n) is the risk entropy value corresponding to the target user's behavior. The target weight is denoted as 'value(type)', and the target risk coefficient is denoted as 'value(type)'.

[0053] Furthermore, it is necessary to determine whether the risk entropy value falls within a preset risk entropy value range. If the risk entropy value falls within the preset risk entropy value range, a user risk behavior warning is issued. Figure 3 As shown, if the target file information is a configuration file and the risk entropy value is in the range (0, 50), a risk warning is required. This improves the accuracy of risk warnings. A risk warning is only issued when the target monitoring information completely matches the knowledge base in the risk warning network and the risk entropy value is within the preset risk entropy value range, effectively avoiding false alarms.

[0054] In this embodiment, target user behavior of the target operating system can be monitored to obtain target monitoring information. Each target monitoring information includes user information of the target user who performed the target user behavior, operation information corresponding to the target user behavior, and target process information corresponding to the operation information. Each target monitoring information is input into a preset risk warning network, which uses pre-configured target knowledge bases to match the corresponding target monitoring information. The target knowledge base is constructed based on historical monitoring information of historical user risk behaviors, and different target knowledge bases correspond to different types of monitoring information. If each target monitoring information is successfully matched in the corresponding target knowledge base, the preset weight and target risk coefficient corresponding to each target monitoring information are determined using the target knowledge base. The risk entropy value corresponding to the target user behavior is determined based on the preset weight and target risk coefficient, and whether to issue a risk behavior warning is determined based on the risk entropy value. Therefore, the method in this embodiment can match the monitored information of the target user in the target operating system with a preset risk warning network. The preset risk warning network needs to sequentially use pre-configured target knowledge bases to match the target monitoring information. If each monitoring information matches successfully in its corresponding target knowledge base, the target knowledge base is used to determine the preset weight and target risk coefficient corresponding to each monitoring information. Based on the preset weight and target risk coefficient, the risk entropy value corresponding to the target user's behavior is determined, and a risk behavior warning is issued based on the risk entropy value. In this way, on the one hand, the traditional neural network optimization concept can be reconstructed into a knowledge base based on multi-layer filtering. The final result is extracted after multi-layer filtering to improve the accuracy of the warning. On the other hand, by constructing a multi-layer network filtering knowledge base with independent intellectual property rights, common human error scenarios can be summarized and quantified. These factors are incorporated into the knowledge base through quantitative analysis, risk coefficients are set according to the content, and the risk entropy value is calculated by combining the weights of the network filtering to determine whether the operation is risky, thereby improving the accuracy of risk behavior warnings.

[0055] As a preferred embodiment, such as Figure 4 The diagram illustrates the specific process for user risk behavior early warning. First, the preset risk warning network needs to be initialized, including the four-layer knowledge base within it. Then, layer-by-layer matching is performed on the target monitoring information. A schematic diagram of the layer-by-layer matching is shown below. Figure 5 As shown, by Figure 5The content indicates that layer matching is mainly divided into four layers, corresponding to the four-layer knowledge base in the aforementioned preset risk warning network. The first layer, the target knowledge base, corresponds to the user layer and can match different types of user identities, such as super administrators and ordinary users. The second layer corresponds to the subject layer and can match different types of process information, such as user-mode processes, kernel-mode processes, and viruses. The third layer corresponds to the action layer and can match different types of actions, such as creating, deleting, modifying, and reading. The fourth layer corresponds to the object layer and can match different types of file information, such as regular configuration files, binary files, and kernel-mode configuration files. If a match is successful, the weight corresponding to that layer needs to be determined before proceeding to the next layer. If a match fails, it indicates that the target user's behavior is risk-free, and the warning can be exited directly. After matching is completed at all layers, the risk entropy value can be calculated, and corresponding behavioral warnings can be issued based on the risk entropy value.

[0056] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0057] Embodiments of this application also provide a user risk behavior early warning device for an operating system, comprising:

[0058] The behavior monitoring module 11 is used to monitor the behavior of the target user on the target operating system and obtain various target monitoring information. The target monitoring information includes the user information of the target user who performs the target user behavior, the operation information corresponding to the target user behavior, and the target process information corresponding to the operation information.

[0059] The information matching module 12 is used to input the monitoring information of each target into the preset risk warning network, so that the corresponding target monitoring information can be matched by using the local pre-configured target knowledge base in sequence through the preset risk warning network; wherein, the target knowledge base is a knowledge base constructed based on historical monitoring information of historical user risk behavior, and different target knowledge bases correspond to different types of monitoring information.

[0060] The parameter determination module 13 is used to determine the preset weight and target risk coefficient corresponding to each target monitoring information by using the target knowledge base if each target monitoring information is successfully matched in the corresponding target knowledge base.

[0061] The risk behavior early warning module 14 is used to determine the risk entropy value corresponding to the target user's behavior based on the preset weight and the target risk coefficient, and to determine whether to issue a risk behavior early warning based on the risk entropy value.

[0062] In some embodiments, the behavior monitoring module 11 may specifically include:

[0063] The operation information determination unit is used to track target users through preset monitoring tools and determine the target user's identity, target file information, target operation actions, and target operation content based on the user operation logs corresponding to the target user's behavior.

[0064] The process information determination unit is used to determine the target process created when the target operating system executes the target operation content, and to determine the target process information corresponding to the target process.

[0065] In some embodiments, the user risk behavior warning device of the operating system may further include:

[0066] The historical data collection submodule is used to collect historical risk behavior cases and analyze them to determine the corresponding historical monitoring information. The historical monitoring information includes historical user identity, historical file information, historical operation actions, historical operation content, and historical process information.

[0067] The historical data classification submodule is used to classify historical user identities, historical file information, historical operation actions, historical operation content, and historical process information to obtain classified historical monitoring information.

[0068] The knowledge base construction submodule is used to build several risk knowledge bases based on classified historical monitoring information, and to use these risk knowledge bases as the target knowledge bases of the preset risk early warning network.

[0069] In some embodiments, the knowledge base construction submodule may specifically include:

[0070] The first knowledge base construction unit is used to construct the first target knowledge base in the preset risk warning network based on the classified historical user identity, classified historical file information, classified historical operation actions, and classified historical process information in the classified historical monitoring information. The first target knowledge base includes a first-layer target knowledge base corresponding to user identity, a second-layer target knowledge base corresponding to process information, a third-layer target knowledge base corresponding to operation actions, and a fourth-layer target knowledge base corresponding to file information.

[0071] The second knowledge base construction unit is used to construct the second target knowledge base in the preset risk warning network based on the classified historical operation content in the classified historical monitoring information.

[0072] In some embodiments, the information matching module 12 may specifically include:

[0073] The first matching unit is used to determine whether the target user's identity matches the historical user identities in the first-layer target knowledge base, so as to obtain the first matching result;

[0074] The second matching unit is used to determine whether the target process information matches the historical process information in the second-layer target knowledge base if the first matching result indicates a successful match, so as to obtain the second matching result.

[0075] The third matching unit is used to determine whether the target operation action in the operation information matches the historical operation action in the third-layer target knowledge base if the second matching result indicates a successful match, so as to obtain the third matching result.

[0076] The fourth matching unit is used to determine whether the target file information in the operation information matches the historical file information in the fourth-level target knowledge base if the third matching result indicates a successful match, so as to obtain the fourth matching result.

[0077] The fifth matching unit is used to match the target operation content with the historical operation content in the second target knowledge base if the fourth matching result indicates a successful match, so as to determine the target historical operation content corresponding to the target operation content in the historical operation content.

[0078] In some embodiments, the user risk behavior warning device of the operating system may further include:

[0079] The warning exit unit is used to exit the risk behavior warning if any of the first, second, third, and fourth matching results indicate a matching failure.

[0080] In some embodiments, the parameter determination module 13 may specifically include:

[0081] The first parameter acquisition submodule is used to obtain the preset weights corresponding to the monitoring information of each target from the first target knowledge base if the first matching result, the second matching result, the third matching result, and the fourth matching result all indicate successful matching.

[0082] The second parameter acquisition submodule is used to obtain the target risk coefficient corresponding to the monitoring information of each target from the second target knowledge base.

[0083] In some embodiments, the first parameter acquisition submodule may specifically include:

[0084] The first weight acquisition unit is used to determine the target identity type of the target user identity if the first matching result indicates a successful match, and to obtain the first preset weight corresponding to the target identity type from the first layer target knowledge base;

[0085] The second weight acquisition unit is used to determine the process command corresponding to the target process information if the second matching result indicates a successful match, and to determine the process information type of the target process information based on the process command, and to obtain the second preset weight corresponding to the process information type from the second layer target knowledge base;

[0086] The third weight acquisition unit is used to determine the action instruction corresponding to the target operation action if the third matching result indicates a successful match, and to obtain the third preset weight corresponding to the action instruction from the third layer target knowledge base;

[0087] The fourth weight acquisition unit is used to determine the file type corresponding to the target file information if the fourth matching result indicates a successful match, and to obtain the fourth preset weight corresponding to the file type from the fourth layer target knowledge base.

[0088] In some embodiments, the second parameter acquisition submodule may specifically include:

[0089] The operation content matching unit is used to match the target operation content with the historical operation content in the second target knowledge base to determine the target historical operation content that corresponds to the target operation content in the historical operation content.

[0090] The risk coefficient determination unit is used to determine the target risk coefficient corresponding to the target operation content based on the operation type and file type corresponding to the target historical operation content.

[0091] In some embodiments, the risk behavior warning module 14 may specifically include:

[0092] The risk entropy calculation unit is used to calculate the product of the first preset weight, the second preset weight, the third preset weight, the fourth preset weight, and the target risk coefficient, and uses the value of the product as the risk entropy value corresponding to the target user behavior.

[0093] In some embodiments, the risk behavior warning module 14 may specifically include:

[0094] The risk behavior warning unit is used to determine whether the risk entropy value is within the preset risk entropy value range. If the risk entropy value is within the preset risk entropy value range, a user risk behavior warning is issued.

[0095] For a description of the features in the embodiment corresponding to the user risk behavior warning device of the operating system, please refer to the relevant description of the embodiment corresponding to the user risk behavior warning method of the operating system, which will not be repeated here.

[0096] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in the user risk behavior warning method embodiments of any of the above operating systems.

[0097] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in the user risk behavior warning method embodiments of any of the above operating systems when running.

[0098] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0099] The embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in the user risk behavior warning method embodiments of any of the above operating systems.

[0100] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in the user risk behavior warning method embodiments of any of the above operating systems.

[0101] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0102] The foregoing has provided a detailed description of a user risk behavior early warning method, device, medium, and product for an operating system provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only intended to help understand the method and core ideas of this application. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A user risk behavior early warning method for an operating system, characterized in that, include: Monitor the behavior of target users on the target operating system to obtain monitoring information for each target; Each of the target monitoring information includes user information of the target user who performed the target user behavior, operation information corresponding to the target user behavior, and target process information corresponding to the operation information; The target monitoring information is input into a preset risk warning network, and the preset risk warning network sequentially uses the locally pre-configured target knowledge bases to match the corresponding target monitoring information; wherein, the target knowledge base is a knowledge base constructed based on historical monitoring information of historical user risk behavior, and different target knowledge bases correspond to different types of monitoring information; If each of the target monitoring information is successfully matched in the corresponding target knowledge base, then the preset weight and target risk coefficient corresponding to each of the target monitoring information are determined using the target knowledge base; The risk entropy value corresponding to the target user behavior is determined based on the preset weight and the target risk coefficient, and whether to issue a risk behavior warning is determined based on the risk entropy value.

2. The user risk behavior early warning method for an operating system according to claim 1, characterized in that, The monitoring of target user behavior on the target operating system yields target monitoring information, including: The target user is tracked by a preset monitoring tool, and the target user identity, target file information, target operation action, and target operation content are determined based on the user operation log corresponding to the target user's behavior. Determine the target process created when the target operating system executes the target operation content, and determine the target process information corresponding to the target process.

3. The user risk behavior early warning method for an operating system according to claim 2, characterized in that, Before inputting the target monitoring information into a preset risk warning network, and then using the preset risk warning network to sequentially match the corresponding target monitoring information using pre-configured local target knowledge bases, the method further includes: Collect historical risk behavior cases and analyze them to determine the historical monitoring information corresponding to the historical risk behavior cases; the historical monitoring information includes historical user identity, historical file information, historical operation actions, historical operation content, and historical process information; The historical user identity, historical file information, historical operation actions, historical operation content, and historical process information are classified respectively to obtain classified historical monitoring information; Several risk knowledge bases are constructed based on the classified historical monitoring information, and these risk knowledge bases are used as the target knowledge bases of the preset risk early warning network.

4. The user risk behavior early warning method for an operating system according to claim 3, characterized in that, The construction of several risk knowledge bases based on the classified historical monitoring information, and the use of these risk knowledge bases as the target knowledge base of the preset risk early warning network, includes: Based on the classified historical user identity, classified historical file information, classified historical operation actions, and classified historical process information in the classified historical monitoring information, a first target knowledge base in the preset risk warning network is constructed; the first target knowledge base includes a first-layer target knowledge base corresponding to user identity, a second-layer target knowledge base corresponding to process information, a third-layer target knowledge base corresponding to operation actions, and a fourth-layer target knowledge base corresponding to file information. Based on the classified historical operation content in the classified historical monitoring information, a second target knowledge base is constructed in the preset risk warning network.

5. The user risk behavior early warning method for an operating system according to claim 4, characterized in that, The step of constructing the second target knowledge base in the preset risk warning network based on the classified historical operation content in the classified historical monitoring information includes: According to the preset assignment rules, risk coefficients and risk entropy values ​​are assigned to the classified historical operation content in the classified historical monitoring information to obtain several risk coefficients and several risk entropy values ​​corresponding to the classified historical operation content. The second target knowledge base in the preset risk warning network is constructed based on the classified historical operation content, the several risk coefficients, and the several risk entropy values.

6. The user risk behavior early warning method for an operating system according to claim 4, characterized in that, The step of sequentially matching the corresponding target monitoring information using pre-configured local target knowledge bases through the preset risk warning network includes: Determine whether the target user's identity matches the historical user identities in the first-layer target knowledge base to obtain a first matching result; If the first matching result indicates a successful match, then it is determined whether the target process information matches the historical process information in the second-layer target knowledge base to obtain the second matching result; If the second matching result indicates a successful match, then it is determined whether the target operation action in the operation information matches the historical operation action in the third-layer target knowledge base, so as to obtain the third matching result; If the third matching result indicates a successful match, then it is determined whether the target file information in the operation information matches the historical file information in the fourth layer target knowledge base, so as to obtain the fourth matching result; If the fourth matching result indicates a successful match, then the target operation content is matched with the historical operation content in the second target knowledge base to determine the target historical operation content corresponding to the historical operation content.

7. The user risk behavior early warning method for an operating system according to claim 6, characterized in that, If each of the target monitoring information is successfully matched in the corresponding target knowledge base, before determining the preset weight and target risk coefficient corresponding to each of the target monitoring information using the target knowledge base, the method further includes: If any of the first matching result, the second matching result, the third matching result, and the fourth matching result indicate a matching failure, then the risk behavior warning will be exited.

8. The user risk behavior early warning method for an operating system according to claim 6, characterized in that, If each of the target monitoring information is successfully matched in the corresponding target knowledge base, then the preset weight and target risk coefficient corresponding to each of the target monitoring information are determined using the target knowledge base, including: If the first matching result, the second matching result, the third matching result, and the fourth matching result all indicate a successful match, then the preset weight corresponding to each target monitoring information is obtained from the first target knowledge base; Obtain the target risk coefficient corresponding to each target monitoring information from the second target knowledge base.

9. The user risk behavior early warning method for an operating system according to claim 8, characterized in that, If the first matching result, the second matching result, the third matching result, and the fourth matching result all indicate a successful match, then the preset weight corresponding to each target monitoring information is obtained from the first target knowledge base, including: If the first matching result indicates a successful match, then the target identity type of the target user is determined, and a first preset weight corresponding to the target identity type is obtained from the first layer target knowledge base; If the second matching result indicates a successful match, then the process command corresponding to the target process information is determined, and the process information type of the target process information is determined based on the process command. The second preset weight corresponding to the process information type is obtained from the second layer target knowledge base. If the third matching result indicates a successful match, then the action instruction corresponding to the target operation action is determined, and the third preset weight corresponding to the action instruction is obtained from the third-layer target knowledge base; If the fourth matching result indicates a successful match, then the file type corresponding to the target file information is determined, and the fourth preset weight corresponding to the file type is obtained from the fourth-layer target knowledge base.

10. The user risk behavior early warning method for an operating system according to claim 9, characterized in that, The step of obtaining the target risk coefficient corresponding to each target monitoring information in the second target knowledge base includes: The target operation content is matched with the historical operation content in the second target knowledge base to determine the target historical operation content that corresponds to the target operation content in the historical operation content; Based on the operation type corresponding to the target historical operation content and the file type, the target risk coefficient corresponding to the target operation content is determined.

11. The user risk behavior early warning method for an operating system according to claim 9, characterized in that, The step of determining the risk entropy value corresponding to the target user behavior based on the preset weight and the target risk coefficient includes: Calculate the product of the first preset weight, the second preset weight, the third preset weight, the fourth preset weight, and the target risk coefficient, and use the value of the product as the risk entropy value corresponding to the target user behavior.

12. The user risk behavior early warning method for an operating system according to any one of claims 1 to 11, characterized in that, The process of determining whether to issue a risk behavior warning based on the risk entropy value includes: Determine whether the risk entropy value is within a preset risk entropy value range. If the risk entropy value is within the preset risk entropy value range, then issue a user risk behavior warning.

13. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the user risk behavior warning method of the operating system as described in any one of claims 1 to 12 when executing the computer program.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the steps of the user risk behavior warning method of the operating system as described in any one of claims 1 to 12.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the user risk behavior warning method of the operating system as described in any one of claims 1 to 12.