Trusted terminal network security protection method and system

By analyzing the anomalies in user attribute habits and operating habits, and combining time intervals and strong correlations, the problem of inaccurate user behavior identification in terminal network security was solved, thereby improving the security of terminal networks and user experience.

CN121262002APending Publication Date: 2026-01-02QINGDAO YONGTAIYUAN THERMAL POWER CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511686388.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-18
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Existing endpoint security protection methods are insufficient to cope with dynamic threats in OT and IT converged environments, especially when users are operating with legitimate identities. Traditional security boundaries are blurred, and existing user behavior recognition methods are not accurate enough, leading to frequent abnormal alarms and affecting user experience.

Method used

By collecting user history and current login attributes and operation habits, a judgment window is set up to analyze abnormal user attributes, strong correlations in operation habits, and abnormal time intervals. Based on this comprehensive judgment, abnormal user behavior is identified, and anomaly thresholds are set for security protection.

Benefits of technology

It improves the accuracy of user behavior recognition, enhances the security of the terminal network, reduces abnormal alarms, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121262002A_ABST
    Figure CN121262002A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of terminal security, in particular to a trusted terminal network security protection method and system. The method comprises the following steps: collecting user attribute habits, user operation habits and login duration of user history and current login; the preset judgment window sets a target moment, and user attribute abnormity is obtained based on the attribute value difference in the login and the history; obtaining strong correlation of user operation habits based on historical data, and combining the user operation habits of the login with the strong correlation to calculate operation correlation abnormity; obtaining time anomaly based on time interval difference between the history and the operation habits of the user logging in this time; obtaining user operation abnormity based on the two; obtaining an abnormal value according to the user operation abnormity and the user attribute abnormity; and completing safety protection based on comparison between the abnormal value and the judgment threshold. According to the invention, the identification capability of the terminal user is improved, and the security of the terminal network is greatly guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of terminal security, in particular to a trusted terminal network security protection method and system. BACKGROUND

[0002] Traditional security protection systems based on border firewalls and static rules are difficult to cope with dynamic threats in OT and IT fusion environments, and industrial terminal devices have limited resources and cannot deploy complex security software. Especially when attackers use the identity of legitimate users to operate, the traditional security boundary becomes blurred. In order to effectively prevent these advanced persistent threats, behavior recognition technology, as a new security protection method, is gradually becoming an important part of the network security field. As part of the trusted terminal network security protection, behavior recognition brings new ideas and technical means to solve modern information security problems. It not only detects and prevents external attacks, but more importantly, it enhances the internal risk prevention and control capability, enabling organizations to maintain effective control over their assets in complex network environments. By monitoring terminal user behavior, the user can be identified, and the terminal network security can be protected.

[0003] However, the existing terminal security performance is not good, and may be subject to leakage, but user behavior is not reproducible, so the user identity can be identified again by combining user behavior, and the terminal network security can be protected. The existing method, such as the method of identifying the user according to the similarity between the user behavior and the user historical behavior by using the SAD method and the Euclidean distance, only identifies and analyzes a part of the parameters, without more detailed analysis of the operation, which may lead to inaccurate matching and abnormal alarms, thereby affecting the user's use of the terminal and reducing the user experience. SUMMARY

[0004] In order to solve the technical problem of inaccurate secondary identification of users, the application provides a trusted terminal network security protection method and system, and the technical scheme adopted is as follows: In the first aspect, the application provides a trusted terminal network security protection method, which comprises the following steps: For industrial terminals, collect user historical and this time login user attribute habits and user operation habits, and login duration; A preset judgment window is set, a target time is set based on the judgment window, and a user attribute anomaly of the target time is obtained based on the difference between the mean value of the attribute value before the target time and the mean value of the attribute value in the history; The number of times that any two user operation habits appear together before the target moment in the statistical history and the total number of times that the two user operation habits appear are counted, a strong correlation of the user operation habits is obtained based on the difference between the number of times and the total number of times, operation-related abnormality is calculated based on whether any two user operation habits appear at the same time before the target moment of the current login and the strong correlation of the two user operation habits, the time interval of each user operation habit is taken as the time length of the user operation habit appearing from the login time, time abnormality of the target moment is obtained based on the difference between the time interval of all user operation habits before the target moment and the time interval of the user operation habit in the history, and user operation abnormality is obtained based on the time abnormality and the operation-related abnormality. An abnormal value of each target moment is obtained based on the user operation abnormality and the user attribute abnormality of each target moment, and security protection is completed based on comparison of the abnormal value in the judgment window and a preset judgment threshold.

[0005] In the above scheme, the user behavior habits are divided into two categories, the user is analyzed for basic similarity based on the user attribute habits to confirm abnormality, the relationship between the user operation habits and the time abnormality of the operation behavior habits after the user logs in are analyzed based on the user operation habit analysis, and finally a comprehensive analysis result is obtained. The present application continuously monitors different moments through multiple judgment windows, analyzes the attribute characteristics through the difference between the history and the present user attribute habits, and then determines the abnormality of the user operation habits based on the strong correlation of the operation habits and the user operation habits in the history. The interval time of the user operation habits is then reacted based on the user operation habits, the user personal operation behavior habits are fully analyzed, the user behavior habit detection accuracy is greatly improved, the user attribute habits and the user operation habits are combined to obtain an abnormal value, and finally a reliable user behavior habit detection result is obtained. The identification ability of the terminal user is improved, and the security of the terminal network is greatly ensured.

[0006] In one embodiment, the user attribute habits include the browsing time length of a single page and the number of clicks on a single page, and the user operation habits are the operations of the user on the system. If the operation exists, the user operation habit is recorded as 1, and if the operation does not exist, the user operation habit is recorded as 0.

[0007] In one embodiment, the target moment is the last moment of a plurality of small windows divided by the judgment window.

[0008] In one embodiment, the user attribute abnormality and the difference between the average value of the attribute value before the target moment and the average value of the attribute value in the history are in a positive correlation relationship.

[0009] In one embodiment, the method for obtaining the strong correlation of the user operation habits based on the difference between the number of times and the total number of times is as follows: The number of times that the two user operation habits appear together before the target time is recorded as a first number, and the total number of times that the two user operation habits appear is counted as a second number. The ratio of the first number to the second number is taken as the strong correlation of the two user operation habits.

[0010] In one embodiment, the method for calculating the operation-related abnormality based on whether any two user operation habits appear simultaneously before the target time of the current login and the strong correlation of the two user operation habits is as follows: If the two user operation habits appear simultaneously or do not appear simultaneously before the target time of the current login, the asynchronization is recorded as 0, and if only one of the two user operation habits appears before the target time of the current login, the asynchronization is recorded as 1. The operation-related abnormality before the target time of the current login is obtained by weighting the asynchronization with the strong correlation of the user operation habits as a weight.

[0011] In one embodiment, the method for obtaining the time abnormality of the target time based on the difference between the time interval of all user operation habits before the target time and the time interval of the user operation habits in the history is as follows: , represents the time interval of the a-th user operation habit in the current login, represents the mean of the time interval of the a-th user operation habit in the history, represents the number of all user operation habits before the target time T, represents a linear normalization function, represents the time abnormality of the target time T.

[0012] In one embodiment, the user operation abnormality is positively correlated with the time abnormality and the operation-related abnormality, respectively.

[0013] In one embodiment, the method for obtaining the abnormal value of each target time based on the user operation abnormality and the user attribute abnormality of each target time and completing security protection based on the comparison between the abnormal value and the judgment threshold in the judgment window is as follows: The abnormal value is positively correlated with the user attribute abnormality and the user operation abnormality; In the judgment window, if there is any abnormal value greater than the judgment threshold, the user is abnormal, at which time an alarm is given, the software function is stopped, the higher level authentication method is jumped to, and the user information is further verified; if there is no abnormal value greater than the judgment threshold, the user is not abnormal, and the detection is passed.

[0014] In a second aspect, the embodiments of the present application further provide a trusted terminal network security protection system, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, and the processor implements the steps of the speech enhancement system in the dynamic noise environment according to the computer program.

[0015] The present application has the following beneficial effects: The present application divides the user behavior habits into two categories, confirms the anomaly based on the basic similarity analysis of the user attribute habits, analyzes the relationship between the user operation habits based on the user operation habit analysis, and analyzes the abnormality of the operation behavior habits in the use time after the user logs in, finally obtains the comprehensive analysis result, fully analyzes the user personal operation behavior habits, greatly strengthens the user behavior habit detection accuracy, and finally obtains the reliable user behavior habit detection result. The identification ability of the terminal user is improved, and the security of the terminal network is greatly guaranteed. BRIEF DESCRIPTION OF DRAWINGS

[0016] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.

[0017] Figure 1 A flow chart of a trusted terminal network security protection method provided by an embodiment of the present application. DETAILED DESCRIPTION

[0018] In order to further illustrate the technical means and effects adopted by the present application to achieve the predetermined invention purpose, the specific implementation, structure, features and effects of the trusted terminal network security protection method and system according to the present application are described in detail as follows by combining with the drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs.

[0020] Embodiments of a trusted terminal network security protection method and system: The specific scheme of the trusted terminal network security protection method and system provided by the present application will be specifically described below in combination with the drawings.

[0021] Please refer toFigure 1 It shows a trusted terminal network security protection method flowchart provided by one embodiment of the application, which comprises the following steps: Step S001, collect the attribute habits and user operation habits of the user history and this time login and the login duration.

[0022] The behavior habits of the terminal user are collected, and the behavior habits of the user in the application are divided into two kinds, one is the user attribute habits, and the other is the user operation habits.

[0023] The user attribute habits are some content attribute habits viewed by the user after login, and the user operation habits are some user operation habits of the user for controlling the terminal after logging into the terminal.

[0024] In this embodiment, the user attribute habits include the browsing duration of a single page and the click times of a single page.

[0025] In this embodiment, the user operation habits are the operations of the user on the terminal, for example, whether to open a certain subsystem in the terminal, whether to view the data in a certain subsystem; if the operation exists, the user operation habit is recorded as 1, and if the operation does not exist, the user operation habit is recorded as 0; and the time of each user operation habit is recorded.

[0026] And for the user attribute habits and the user operation habits, the login duration is counted.

[0027] At this point, the user attribute habits and the user operation habits and the login duration are obtained.

[0028] Step S002, preset a judgment window to set a target time, and obtain the user attribute anomaly based on the attribute value difference between this time login and history.

[0029] When the user is identified, the user is continuously and progressively identified, that is, after the user logs in, the operation time is short, and the short-time operation content may be the relevant behavior habits of most people just opening the device, so the user is progressively identified, that is, after the user logs in, the user behavior is continuously monitored, and the user behavior habits are analyzed multiple times within a certain time period, so as to judge the user identity.

[0030] According to the user login account, the user historical login information is obtained, the average login duration is obtained, the preset duration before the login duration is selected as the user behavior judgment window, the user identity is judged based on the judgment window, the judgment window is divided into a plurality of small windows, after each small window, all the data before it is identified, and after each small window, the last time of the small window is taken as the target time. In this embodiment, the judgment window is composed of 1 / 10 of the duration before the login duration, and each judgment window is divided into 3 small windows.

[0031] First, whether the user is abnormal in this aspect after login is analyzed according to the user attribute habit, and the attribute value mean of any user attribute habit in the history of the user is obtained, and the user attribute anomaly is obtained based on the difference between the attribute value mean before the target time and the attribute value mean in the history. The attribute value is the normalized value corresponding to each user attribute habit, and the normalization is linear normalization of the attribute value of all the user attribute habits in the history.

[0032] The user attribute anomaly and the difference between the attribute value mean before the target time and the attribute value mean in the history are positively correlated.

[0033] It should be noted that positive correlation means that when one variable increases, the other variable also increases, and the two variables change in the same direction. When one variable changes from large to small or from small to large, the other variable also changes from large to small or from small to large. The specific relationship is determined by actual application, and the present application does not make special limitation.

[0034] Preferably, the expression of the embodiment is: , represents the attribute value of the oth user attribute habit before the target time, represents the attribute value mean of the oth user attribute habit in the history data, represents the type of user attribute habit, represents a linear normalization function, represents the user attribute anomaly at the target time T.

[0035] When the difference between the user attribute habit obtained by real-time detection of the user and the attribute value of the historical user attribute habit is larger, the user attribute anomaly value is larger.

[0036] At this point, the user attribute anomaly of the user at the target time is obtained.

[0037] Step S003, based on the strong correlation of the user operation habit obtained from the history data, the operation related anomaly of the user operation habit of this login is calculated by combining the strong correlation; the time anomaly is obtained based on the time interval difference between the history and the user operation habit of this login; and the user operation anomaly is obtained based on the two.

[0038] Since it is impossible for a terminal user to perform all the historical behavior habits acquired each time he logs in, the user will perform different operations according to different conditions, but there is a certain correlation between different operations, for example, the copy and paste operations on production data, which generally require operations after copying the data, so there is a strong correlation between copying and pasting. Different people have different habits, some users are used to opening a subsystem for viewing immediately after opening a system, and some users do not open a subsystem for viewing after opening a system. Therefore, the correlation is different for different users.

[0039] The behavior habits appearing together in the historical data are recorded as strong correlation behaviors, that is, in the user historical data, as long as one of the user operation habits appears, the other user operation habit also appears in most cases. In the historical data, the number of times that the two user operation habits appear together before the target time is recorded as the first number, and the total number of times that the two user operation habits appear is recorded as the second number. The second number is the difference between the sum of the number of times that the two user operation habits appear and the first number. For example, one user operation habit appears 100 times, another user operation habit appears 90 times, and both appear 60 times, so the second number is 130 times. That is, the first number is the intersection of the two numbers, and the second number is the union of the two numbers.

[0040] The ratio of the first number and the second number is taken as the strong correlation of the two user operation habits. If the two user operation habits have a strong correlation in the history, if one of the user operation habits appears and the other does not appear, it means that the correlation is abnormal. Therefore, if the two user operation habits appear or do not appear at the same time before the target time of this login, the asynchronization is recorded as 0, and if only one of the two user operation habits appears before the target time of this login, the asynchronization is recorded as 1.

[0041] Based on the above analysis, the strong correlation between the user operation habits is taken as the weight to obtain the operation correlation abnormality before the target time of this login.

[0042] Preferably, in the embodiment, the expression of the operation correlation abnormality is: , represents the strong correlation between the user operation habit A and the user operation habit B, represents the asynchronization between the user operation habit A and the user operation habit B, represents the number of all user operation habit categories before the target time T, represents a linear normalization function, represents the operation correlation abnormality at the target time T.

[0043] When two users' operating habits are highly correlated, if their operating habits frequently fail to synchronize, it indicates an operational anomaly, and the correlation between the two anomalies is significant.

[0044] For any given user action habit, the time elapsed since login is recorded as the time interval for that user action habit. This time interval is then compared to the historical time intervals for that user action habit to determine if the user's action habit during the current login is abnormal. If the time interval for the current login differs significantly from the historical time intervals for that user action habit, it indicates that the current login is abnormal.

[0045] Therefore, the mean of the time intervals of all user operation habits over a certain number of days in history is calculated, and the time anomaly is obtained based on the difference between the time interval of the user's operation habits at the time of this login and the mean of the time intervals of all user operation habits. In this embodiment, data from the 30 days prior to this login is selected for calculation.

[0046] Preferably, in this embodiment, the expression for temporal anomaly is: , This indicates the time interval for the user's operational habits during the current login session (the 'a'th timer). This represents the average time interval of the a-th user's operating habits in history. This represents the number of all user operation habit types before the target time T. Represents a linear normalization function. This indicates the temporal anomaly of the target time T.

[0047] Therefore, after a user logs in, the closer the time when the user's corresponding user operation habit appears before the target time T is to the time when the user's operation habit appears in the past, the less abnormal the user's operation habit is.

[0048] Based on the above steps, the analysis of user operation habits was completed, and user operation anomalies were obtained based on the temporal anomalies and operation-related anomalies at the target time T.

[0049] User operation anomalies are positively correlated with time anomalies and operation-related anomalies.

[0050] Preferably, in this embodiment, the expression for user operation anomaly is: , This indicates the operation-related anomalies at the target time T. Indicates the temporal anomaly of the target time T. Represents a linear normalization function. This indicates an abnormal user operation at the target time T.

[0051] At this point, the user's abnormal operation at the target time has been obtained.

[0052] Step S004: Obtain abnormal values ​​based on abnormal user operations and abnormal user attributes; complete security protection based on the comparison of abnormal values ​​with judgment thresholds.

[0053] Based on the above analysis, abnormal user attributes and abnormal user operations are used to calculate abnormal behavior values.

[0054] This application performs the above analysis on all data before the last moment of each small window, i.e., the target time T is the last moment of each small window.

[0055] For each target time T, calculate and obtain user attribute anomalies and user operation anomalies, and calculate anomaly values ​​based on user attribute anomalies and user operation anomalies.

[0056] The outliers are positively correlated with user attribute anomalies and user operation anomalies.

[0057] Preferably, in this embodiment, the expression for outliers is: , This indicates that the user attributes at the target time T are abnormal. This indicates that the user operation at the target time T was abnormal. Represents a linear normalization function. This represents an outlier at the target time T.

[0058] The outliers at each target time T are obtained using the above method. Within the judgment window, if any outlier exceeds the judgment threshold, it indicates a user anomaly. An alarm is triggered, software functionality is halted, and the system proceeds to a higher-level authentication method for further verification of user information. If no outlier exceeds the judgment threshold, the user is considered normal, and the detection passes. In this embodiment, the judgment threshold is 0.8.

[0059] Based on the same inventive concept as the above method, this embodiment of the invention also provides a trusted terminal network security protection system, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the above-described trusted terminal network security protection methods.

[0060] It should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

[0061] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

Claims

1. A trusted terminal network security protection method, characterized in that, The method includes the following steps: For industrial terminals, collect user history and current login user attributes, habits, operation habits, and login duration; A preset judgment window is set, and a target time is set based on the judgment window; user attribute anomalies at the target time are obtained based on the difference between the average attribute value before the target time and the average attribute value in history; The system calculates the strong correlation between user operation habits by statistically analyzing the number of times any two user operation habits occurred together before the target time in the past and the total number of occurrences. It then calculates operation-related anomalies by combining the strong correlation between any two user operation habits occurring simultaneously before the target login time with the occurrence of those habits. The time interval between the occurrence of a user operation habit and the login time is used as the time interval for each user operation habit. Finally, it calculates the temporal anomalies at the target time by comparing the time intervals of all user operation habits before the target time with the historical time intervals of that user operation habit. Finally, it identifies user operation anomalies based on both temporal and operation-related anomalies. The abnormal values ​​at each target time are obtained based on user operation anomalies and user attribute anomalies; security protection is completed by comparing the abnormal values ​​in the judgment window with the preset judgment threshold.

2. The trusted terminal network security protection method as described in claim 1, characterized in that, The user attribute habits include the browsing time of a single page and the number of clicks on a single page. User operation habits are the user's operations on the terminal. If the operation exists, the user operation habit is recorded as 1; if the operation does not exist, the user operation habit is recorded as 0.

3. The trusted terminal network security protection method as described in claim 1, characterized in that, The target time is the last moment of the several small windows divided by the judgment window.

4. The trusted terminal network security protection method as described in claim 1, characterized in that, The abnormal user attributes are positively correlated with the difference between the average attribute value before the target time and the average attribute value in history.

5. A trusted terminal network security protection method as described in claim 1, characterized in that, The method for obtaining a strong correlation between user operation habits based on the difference between the number of times and the total number of times is as follows: The first count is recorded as the number of times two user operation habits occur together before the target time, and the second count is recorded as the total number of times the two user operation habits occur. The ratio of the first count to the second count is used as a strong correlation between two user operating habits.

6. A trusted terminal network security protection method as described in claim 1, characterized in that, The method for calculating operation-related anomalies based on whether any two user operation habits appear simultaneously before the target login time and combining the strong correlation between the two user operation habits is as follows: If two user operation habits appear simultaneously or not at the same time before the target login time, the asynchrony is recorded as 0; if only one of the two user operation habits appears before the target login time, the asynchrony is recorded as 1. Using the strong correlation between user operation habits as weights, the asynchronous anomalies are weighted to obtain the operation-related anomalies before the target login time.

7. A trusted terminal network security protection method as described in claim 1, characterized in that, The method for obtaining the temporal anomaly of the target time based on the difference between the time interval of all user operation habits before the target time and the time interval of the user operation habits in history is as follows: , This indicates the time interval for the user's operational habits during the current login session (the 'a'th timer). This represents the average time interval of the a-th user's operating habits in history. This represents the number of all user operation habits before the target time T. Represents a linear normalization function. This indicates the temporal anomaly of the target time T.

8. A trusted terminal network security protection method as described in claim 1, characterized in that, The user operation anomalies are positively correlated with both time-related anomalies and operation-related anomalies.

9. A trusted terminal network security protection method as described in claim 1, characterized in that, The method for obtaining abnormal values ​​at each target time based on user operation anomalies and user attribute anomalies, and completing security protection by comparing the abnormal values ​​within the judgment window with the judgment threshold is as follows: The outliers are positively correlated with abnormal user attributes and abnormal user operations. In the judgment window, if any outlier exceeds the judgment threshold, the user is considered abnormal. At this time, an alarm is triggered, the software function is stopped, and the process is redirected to a higher-level authentication method to further verify the user information. If no outlier exceeds the judgment threshold, the user is considered normal, and the detection passes.

10. A trusted terminal network security protection system, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the trusted terminal network security protection method as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Internet of Things terminal equipment safety monitoring and protection method

    CN118174887A

  • Network security protection method for cloud service system

    CN119299194A

  • Big data network security protection method and system

    CN119420546A

  • User abnormal behavior detection method and device, equipment and storage medium

    CN119830166A

  • Block chain-based geological data secure storage method and system, and storage medium

    CN119989404A