A user behavior portrait-based access security protection method and system
By constructing dynamic network graphs and neural network models to analyze user collaboration networks, and identifying abnormal behaviors in multi-level connection paths, the problem of detecting hidden collaboration risks in dynamic environments is solved, and efficient security protection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-04-10
AI Technical Summary
Existing technologies struggle to accurately capture abnormal behavior in multi-user collaboration scenarios, especially in dynamic environments where they cannot effectively identify hidden collaboration risks among users or abnormal access to cold data, leading to increased data security risks.
By constructing a dynamic network graph of the user collaboration network, we use a neural network model to analyze the connection strength and evolution sequence between nodes, extract multi-level connection paths, combine behavioral analysis algorithms to identify potential risk paths, and isolate abnormal behaviors through access control mechanisms.
It enables efficient detection and protection against hidden threats in user collaborative networks, improves the accuracy and response speed of abnormal behavior identification, reduces the false positive rate, and provides a fully automated security management solution.
Smart Images

Figure CN121396653B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information technology, and particularly relates to a user behavior portrait-based access security protection method and system. BACKGROUND
[0002] In the information age, data security has become a top priority for enterprise operations and personal privacy protection, especially in complex scenarios involving multi-user collaboration and data interaction, preventing data leaks is particularly critical.
[0003] Whether it's an internal system or a cross-organizational collaboration platform, the stealth and diversity of data flow make risk identification an urgent task.
[0004] How to accurately capture abnormal behavior in a dynamic environment and effectively prevent potential threats is a field problem that needs to be solved urgently.
[0005] However, some existing protection methods are often limited to surface monitoring of data access behavior, ignoring the deep relevance of user interaction.
[0006] This approach can easily lead to missed judgments of hidden risks in complex collaboration scenarios, especially in data transfer processes involving multiple levels and multiple accounts. Traditional detection mechanisms are difficult to detect abnormal motives and behavior patterns hidden behind.
[0007] This limitation makes some carefully designed evasion behaviors difficult to be discovered in time, increasing the risk of data security.
[0008] The deeper technical challenge lies in the dynamic and stealth nature of user collaboration.
[0009] First, the collaboration network between users often evolves over time and with changes in tasks, and normal collaboration patterns may show diverse characteristics in a short period of time, making it difficult to form stable judgment basis.
[0010] This dynamic further increases the difficulty of identifying abnormal collaboration behavior, especially when interacting with cross-level or unfamiliar users, it is difficult for the system to accurately distinguish between normal business needs and potential risks.
[0011] Second, this dynamic also leads to misjudgments of data access intentions, such as when some cold data, i.e., long-term unaccessed data, is suddenly accessed by multiple unfamiliar accounts in succession, the system may not be able to quickly distinguish whether this is a normal business requirement or intentional leakage behavior.
[0012] Therefore, how to accurately depict the normal interaction mode between users in a dynamic collaboration network, and combine the characteristics of data access to conduct correlation analysis on abnormal access of cold data and collaboration behavior of strangers, has become a key problem in the field of data security protection.
[0013] This problem is particularly prominent in actual business, for example, a certain account indirectly accesses sensitive data through multiple intermediate accounts, each step of operation appears to be compliant on the surface, but the overall path hides the intention of evading monitoring, and technical means are urgently needed to identify and respond. SUMMARY
[0014] The application provides an access security protection method based on user behavior portrait, mainly comprising:
[0015] Obtain the interaction records and data access logs of all accounts in the user collaboration network, construct a dynamic network graph through a neural network model, obtain the connection strength and evolution sequence between each node, and use it for subsequent interaction correlation extraction;
[0016] Extract the multi-level connection path between nodes from the dynamic network graph, analyze the collaboration hidden features hidden in the path using a behavior analysis algorithm, and determine the abnormal behavior sequence, wherein if the path length exceeds the preset threshold and the proportion of strangers involved is higher than the threshold, it is marked as a potential risk path;
[0017] For the marked risk path, obtain the cold data access events involved in the path, judge the access burst characteristics, if the event time interval is less than the preset interval and the access frequency is higher than the threshold, obtain the access burst indicator sequence;
[0018] According to the access burst indicator sequence, analyze the collaboration hidden mode of the stranger in the path, update the node embedding vector through the neural network model, and determine the quantification score of the collaboration hidden degree;
[0019] Extract the stranger node with a high score from the quantification score, compare its behavior with the deviation of normal interaction correlation using the behavior analysis algorithm, and determine if the deviation value is greater than the preset threshold to obtain an abnormal behavior confirmation list;
[0020] For the abnormal behavior confirmation list, build a correlation analysis model of path intention, integrate the event sequence in the list and the access burst indicator to determine the evading monitoring intention score of the overall path;
[0021] According to the evading monitoring intention score, generate a protection response sequence, if the score is higher than the alert threshold, isolate the related nodes and data path through the access control mechanism, and obtain the final security protection log.
[0022] The application provides an access security protection system based on user behavior portrait, mainly comprising:
[0023] A data acquisition and atlas construction module is configured to acquire interaction records and data access logs of all accounts in a user collaboration network, construct a dynamic network atlas through a neural network model, obtain connection strength and evolution sequence between each node, and extract subsequent interaction correlation.
[0024] A multi-level path analysis and risk marking module is configured to extract multi-level connection paths between nodes from the dynamic network atlas, analyze hidden collaboration hidden features in the paths through a behavior analysis algorithm, determine abnormal behavior sequence, and mark a potential risk path if the path length exceeds a preset threshold and the proportion of unknown users involved is higher than a threshold.
[0025] A cold data access event analysis module is configured to acquire cold data access events involved in the marked risk path, judge access burst characteristics, and obtain an access burst index sequence if the event time interval is less than a preset interval and the access frequency is higher than a threshold.
[0026] A collaboration hidden mode quantification module is configured to analyze collaboration hidden modes of unknown users in the path according to the access burst index sequence, update node embedding vectors through the neural network model, and determine a quantification score of the collaboration hidden degree.
[0027] An abnormal behavior confirmation module is configured to extract high-score unknown user nodes from the quantification score, compare the behavior of the nodes with the deviation of normal interaction correlation through the behavior analysis algorithm, and judge whether the deviation value is greater than a preset threshold to obtain an abnormal behavior confirmation list.
[0028] A path intention correlation analysis module is configured to construct a correlation analysis model of path intention for the abnormal behavior confirmation list, integrate event sequences in the list and the access burst index, and determine an avoidance monitoring intention score of the overall path.
[0029] A protection response generation module is configured to generate a protection response sequence according to the avoidance monitoring intention score, isolate related nodes and data paths through an access control mechanism if the score is higher than an alarm threshold, and obtain a final security protection log.
[0030] The technical scheme provided by the application embodiment can have the following beneficial effects:
[0031] The application discloses a user cooperation network security protection method based on a dynamic network graph and behavior analysis, and proposes an integrated solution for potential hidden cooperation risks and abnormal behavior detection in a user cooperation network. BRIEF DESCRIPTION OF DRAWINGS
[0032] Figure 1 A flowchart of a user behavior portrait-based access security protection method of the application.
[0033] Figure 2 A schematic diagram of a user behavior portrait-based access security protection method of the application.
[0034] Figure 3 Still another schematic diagram of a user behavior portrait-based access security protection method of the application.
[0035] Figure 4 A structural schematic diagram of a user behavior portrait-based access security protection system of the application.
[0036] Figure 5 A dynamic network graph construction process schematic diagram of the application.
[0037] Figure 6 A node embedding vector updating algorithm schematic diagram of the application.
[0038] Figure 7 An access burst index sequence calculation flowchart of the application.
[0039] Figure 8 An abnormal behavior detection performance comparison diagram of the application.
[0040] Figure 9 A circumvention monitoring intention score calculation schematic diagram of the application.
[0041] Figure 10 An enterprise cooperation network server deployment topology diagram of the application.
[0042] Figure 11 A user collaboration network visualization interface diagram of the present application.
[0043] Figure 12 A connection diagram of the access control isolation device of the present application.
[0044] Figure 13 A multi-level connection path three-dimensional space relationship diagram of the present application. DETAILED DESCRIPTION
[0045] In order for those skilled in the art to better understand the technical solutions in the specification, the technical solutions in the specification will be clearly and completely described below in combination with the drawings in the specification. Obviously, the described embodiments are only some of the embodiments of the specification, not all. Based on the embodiments in the specification, all other embodiments obtained by those of ordinary skill in the art without creative labor should be within the scope of protection of the specification.
[0046] As Figure 1 , the access security protection method and system based on user behavior portrait of the embodiment can specifically include:
[0047] S101, obtain the interaction records and data access logs of all accounts in the user collaboration network, construct a dynamic network graph through a neural network model, and obtain the connection strength and evolution sequence between each node, which is used for subsequent interaction correlation extraction.
[0048] As Figure 2 indicated, the present application realizes access security protection by constructing a user collaboration network. Figure 2 The left side shows the overall structure of the user collaboration network, including a plurality of user nodes (user A to user K) and the collaboration relationship connections therebetween. The connections in the network are divided into two types of strong connections and weak connections according to the collaboration strength, the strong connections are represented by thick solid lines, indicating that the users have frequent and stable collaboration relationship; the weak connections are represented by thin solid lines, indicating that the collaboration relationship between the users is relatively loose.
[0049] Specifically, the interaction records and data access logs of accounts in a user collaboration network are obtained by a log collection tool, the interaction records and the data access logs are formatted, the records are sorted by timestamps, and an interaction dataset arranged in chronological order is obtained. According to the interaction dataset, a dynamic network graph is constructed by a graph database tool, connection relationship mapping is performed on account nodes and interaction events in the dataset, if the interaction frequency between the nodes exceeds a preset threshold, it is determined as a strong connection, and a connection strength distribution between the nodes is obtained. For the connection strength distribution, a time series analysis tool is used to segment the interaction records, the change trend of the connection strength between the nodes is extracted from the segmented data, and an evolution sequence of the dynamic network graph is determined. The evolution sequence is graphically displayed by a data visualization tool, the key nodes and strong connections are labeled, the interaction correlation features between the nodes are extracted, and structured correlation data is obtained. In the access security protection method, the evolution sequence refers to the dynamic change trajectory and law of the connection relationship between the account nodes in the user collaboration network over time, which is sequence data obtained by modeling the connection relationship between the nodes (accounts) in time sequence based on the historical interaction records and data access logs of all accounts by a neural network model, which contains not only the chronological order of the connection relationship, but also the dynamic change trend of the connection strength. For example: the interaction frequency between account A and account B from Monday to Friday decreases from 5 times a day to 1 time a day, account C suddenly establishes a high-privilege data access connection with account A on Wednesday, the connection topology between the nodes in a collaboration group changes from “star-shaped” to “net-shaped”, and the like. These change processes arranged in chronological order are integrated into the evolution sequence.
[0050] As Figure 11As shown, the user collaboration network visualization interface includes four main functional areas. At the top is the title bar of the collaboration network visualization analysis platform. On the left is the control panel 300, which includes a time slider 302 for selecting the time period to view, a filter 303 for filtering by user type, risk level, and activity, and zoom controls 304 containing zoom in and out buttons for adjusting the display scale of the view. In the middle is the dynamic network map 305 of the main view area, which graphically displays the structure of the user collaboration network, with the central square node representing the key user node and the surrounding circular nodes representing the ordinary user nodes, and the connection lines between the nodes representing the collaboration relationship between users, with the thickness of the connection lines representing the size of the connection strength. In the dynamic network map 305, the detected risk path 306 is highlighted by labeling, which facilitates the rapid identification of abnormal collaboration behavior by security personnel. On the right is the information panel 307, which displays detailed information of the selected node, including node information (user ID, type, activity), connection strength value (current value and average value), and risk score (abnormality value and risk level visualization bar chart), providing accurate data support for users. At the bottom is the abnormal behavior alert list 308, which lists the detected abnormal behavior records in table form, with columns including time, user ID, abnormal type, risk level, and status, and each alert record clearly displays the key information of the abnormal behavior, facilitating security management personnel to respond and handle security incidents in a timely manner. Through this multi-dimensional visualization interface design, the system can present complex network evolution data in an intuitive and easy-to-understand manner, effectively improving security monitoring and decision-making efficiency.
[0051] For example, in an enterprise collaboration platform such as Microsoft Teams, the interaction records and data access logs of accounts are obtained from the user collaboration network through a log collection tool such as ELKStack.
[0052] Specifically, these logs include chat message records between user A and user B, file sharing events, and data viewing logs, and the tool captures these data in real time to ensure completeness.
[0053] In one possible implementation, assuming a project team has 10 members, the log collection tool records that user A sent a message to user B at 10:00 on October 1, 2023, user B replied and shared a document at 10:05, and user A accessed the document at 10:10, etc. The tool pulls these raw log data from the network through an API interface, providing a basis for subsequent analysis.
[0054] In one possible implementation, the interaction records and data access logs are formatted, e.g., converting the original logs from JSON format to a unified standard CSV format, extracting key fields such as account ID, event type, timestamp, etc., and then sorting the records by timestamp.
[0055] Specifically, the sorting process arranges all events in chronological order using the timestamp field, e.g., "timestamp", to obtain a time-ordered interaction dataset. For example, in the above team, the sorted dataset shows that user A initiates the interaction first, user B responds, and then user C joins the discussion, forming a continuous timeline, which helps reveal the timing logic of the interaction.
[0056] For example, a dynamic network graph is constructed using a graph database tool such as Neo4j, and the connection relationship between account nodes and interaction events in the dataset is mapped.
[0057] In one possible implementation, each account is treated as a node, e.g., users A, B, and C are nodes, and interaction events such as message sending are edges. If the interaction frequency between nodes exceeds a preset threshold, e.g., 5 times per week, it is determined to be a strong connection, and the connection strength distribution between nodes is obtained.
[0058] Specifically, in the team collaboration scenario, the interaction frequency between users A and B is 3 times per day, which exceeds the threshold of 2 times, so it is marked as a strong connection, while the frequency between users A and C is 1 time per week, which is a weak connection. This mapping can intuitively display the network structure and dynamically update the graph through a query language such as Cypher to analyze the collaboration pattern, which can technically improve team efficiency monitoring.
[0059] Specifically, for the connection strength distribution, a time series analysis tool such as Prometheus is used to segment the interaction records, e.g., segmenting the dataset by week, extracting the trend of connection strength between nodes from the segmented data, and determining the evolution sequence of the dynamic network graph.
[0060] In one possible implementation, the connection strength between users A and B is high in the first week, drops to medium in the second week, and rises in the third week. Through a trend extraction algorithm such as moving average, it is observed that the strength evolves from stable to fluctuating and then strengthens, which reflects the changes in the project phase, such as the transition from planning to execution, helping to identify potential collaboration bottlenecks.
[0061] For example, the evolution sequence is graphically displayed using a data visualization tool such as Tableau, and key nodes such as high-activity user A and strong connections are labeled to extract the interaction association features between nodes, obtaining structured association data.
[0062] In one possible implementation, strong connections are highlighted in red and key nodes in blue. Association features include interaction type, frequency, and duration statistics, forming structured data in JSON format, such as {"nodeA-nodeB":{"frequency":10,"type":"message"}}. This not only makes it easier for managers to review network dynamics but also reveals implicit collaboration patterns through visualization, improving the accuracy of decision-making.
[0063] like Figure 5 As shown, the construction process of the dynamic network graph includes six main stages. First, in the data acquisition stage (S1), log collection tools (such as ELK Stack) are used to obtain account interaction records and data access logs from the user collaboration network. This raw data is typically stored in JSON format. Second, in the formatting stage (S2), the raw logs are converted from JSON format to a unified standard CSV format, and key fields (such as account ID, event type, timestamp, etc.) are extracted. Third, in the timestamp sorting stage (S3), the records are sorted using timestamps to obtain an interaction dataset arranged in chronological order, laying the foundation for subsequent time series analysis. Fourth, in the graph database construction stage (S4), a dynamic network graph is constructed using graph database tools (such as Neo4j), representing accounts as nodes and interaction relationships as edges. Fifth, in the connection strength calculation stage (S5), strong connections are determined based on the interaction frequency between nodes. If the interaction frequency between nodes exceeds a preset threshold, it is considered a strong connection, thus obtaining the connection strength distribution between nodes. Finally, in the evolution sequence extraction stage (S6), time series analysis tools are used to segment the interaction records, determine the evolution sequence of the dynamic network graph in different time periods, and ultimately output the complete dynamic network graph data structure. The entire construction process ensures that the graph can accurately reflect the dynamic evolution characteristics of the user collaboration network, providing a reliable data foundation for subsequent anomaly detection.
[0064] S102. Extract multi-level connection paths between nodes from the dynamic network graph, analyze the hidden collaborative features in the path using a behavior analysis algorithm, and determine abnormal behavior sequences. If the path length exceeds a preset threshold and the proportion of unfamiliar users involved is higher than the threshold, it is marked as a potential risk path.
[0065] Figure 2The right side shows the risk path analysis process, taking the access path of user D to user F (D→E→G→H→F) as an example, which has a path length of 4 and passes through 5 nodes. The system conducts identity determination on each node in the path, identifies the stranger nodes (user E, user G, and user H) among them, and marks them with a dashed box, and the stranger nodes are filled with gray to distinguish them. By calculating the path length and the proportion of stranger nodes (3 / 5), the system determines that this access path is a high-risk path.
[0066] Specifically, the multi-level connection paths between nodes are extracted from the dynamic network graph by a graph database tool, and the path length data and user identity information are obtained for each path to obtain complete path distribution records. According to the path distribution records, the user identity information in each path is analyzed using a data comparison tool, the proportion of stranger users is calculated, and if the proportion is higher than a preset threshold and the path length exceeds a preset range, it is marked as a to-be-inspected path to determine a list of potential risk paths. For the list of potential risk paths, the interaction frequency distribution between nodes is extracted using a time series comparison tool, and the hidden collaboration behavior characteristics are analyzed in combination with historical data to determine whether there is an abnormal behavior sequence. The abnormal behavior sequence is stored by a behavior log recording tool, and for each type of sequence, the potential risk path is associated to obtain detailed path analysis depth data and obtain a structured risk profile.
[0067] As shown in Figure 13 The distribution relationship of multi-level connection paths in the collaboration network in three-dimensional space is shown. In the figure, the risk path instance D→E→G→H→F is taken as an example to illustrate the spatial structure characteristics of abnormal collaboration mode. Among them, node D is the source node, representing a normal user; nodes E, G, and H are intermediate nodes, representing stranger users, with a proportion of 3 / 5=60%, exceeding the preset proportion threshold; node F is the target node, representing a sensitive data access point. The total length of the path is 4, which exceeds the preset length threshold of 3, triggering the abnormal determination condition. In the three-dimensional space representation, the Z-axis represents the level depth, and the nodes at different levels are distributed on different height planes. Layer 1 represents the direct collaboration relationship layer, including the connection between nodes D and E; Layer 2 represents the indirect collaboration relationship layer, including the connection between nodes E and G; Layer 3 represents the further indirect relationship layer, including the connection between nodes G and H; Layer 4 and Layer 5 represent the final access relationship layer, including the connection between nodes H and F. Through this spatial representation, the hierarchical progression characteristics of the abnormal path and the distribution position of the stranger nodes (identified by hollow circles with diagonal lines) in the path can be observed intuitively. The visualization of this multi-level path structure helps to understand the formation mechanism of abnormal collaboration mode and provides spatial positioning basis for subsequent risk assessment and intervention measures.
[0068] For example, in an enterprise internal collaboration environment, the specific implementation method for extracting multi-level connection paths between nodes from a dynamic network graph and analyzing potential risk paths is as follows. Assuming a project collaboration network containing 50 users, graph analysis tools such as GraphX are used to perform path mining on the graph, automatically identifying all possible paths from user D to user F, calculating the path length and the number of nodes involved, and finding a path that passes through 5 nodes (DEGHF) with a path length of 4. Next, behavioral analysis algorithms such as the Isolation Forest algorithm are used to analyze the collaborative behavioral characteristics in the path, extracting hidden collaboration patterns. The specific analysis process includes calculating the behavioral vector of each node (such as interaction frequency and event type percentage). It is found that the interaction patterns of users G and H deviate from the team average; for example, their file sharing percentage is only 5%, far lower than the team average of 20%, and are marked as potential hidden features. Subsequently, the system automatically calculates whether the path length exceeds a preset threshold of 3 and counts the proportion of unfamiliar users (i.e., non-core team members) in the path. It is found that users G and H are unfamiliar users, accounting for 40%, which is higher than the preset threshold of 30%, therefore this path is marked as a potential risk path. Furthermore, the system analyzes abnormal behavior sequences using association rule mining algorithms (such as the Apriori algorithm). It extracts that user G's interactions with H over the past 7 days were concentrated in the late-night hours (11:00 PM - 1:00 AM), and the interaction content involved non-project-related keywords, appearing with a frequency as high as 60%, forming an abnormal behavior sequence record. To ensure logical rigor, the system integrates this risk path with access control in the business scenario, automatically checking the permission levels of users G and H, and discovering that their permissions exceeded the normal scope (such as accessing unnecessary sensitive data). This forms a complete analysis chain from path extraction to risk labeling, assisting in subsequent security policy adjustments.
[0069] S103. For the marked risk path, obtain the cold data access events involved in the path, determine the access burst characteristics, and if the event time interval is less than the preset interval and the access frequency is higher than the threshold, then obtain the access burst index sequence.
[0070] like Figure 3 As shown, this invention performs in-depth analysis of cold data access events and quantifies the degree of collaboration concealment. Figure 3 The upper part shows the timeline of cold data access events. Users A, B, C, D, E, and F accessed cold data that had not been accessed for a long time in sequence from time T1 to T6 (00:00:05 to 00:01:02). The time intervals between adjacent access events were 10 seconds, 5 seconds, 12 seconds, 16 seconds, and 14 seconds, respectively. Most intervals were less than the preset 30-second threshold, and the access frequency reached more than 5 times per minute, which is consistent with the characteristics of sudden access. Figure 3The middle part shows the statistical results of the access burst indicator sequence, and the time window is set to 1 minute. The number of burst events obtained by statistics is [0, 0, 8, 3, 0], among which 8 burst events are detected in the 2-3 minute time window, and more than 5 times of the preset threshold, indicating that there is obvious cooperative access behavior in this period.
[0071] As shown in Figure 7 The calculation process of the access burst indicator sequence is as follows: first, obtain cold data access events (S710), sort them by timestamp (S720), and calculate the time interval between adjacent events (S730). Then judge whether the time interval is less than 30 seconds, if yes, mark it as a burst event (S750), otherwise mark it as a normal event (S760). Then set a 1-minute time window (S770), count the number of burst events in the window (S780), generate a burst indicator sequence (S790), and finally calculate a comprehensive risk score (S800). This process can effectively identify abnormal burst patterns in user access behavior through time window statistics, providing a quantitative basis for access security protection.
[0072] Specifically, the cold data access event records in the risk path are obtained, the relevant access behavior monitoring data is extracted through the pre-established log database, the timestamps of the data access events are sorted, and the event time interval distribution is determined. According to the event time interval distribution, the access frequency is counted using a time window sliding tool. If the access frequency is higher than the preset threshold, it is judged as frequency anomaly, and the frequency anomaly judgment result is obtained. Through the frequency anomaly judgment result, combined with the path risk assessment rules, the correlation data of the cold data access and risk path marking is obtained, the burst characteristic analysis is performed on the correlation data, and the preliminary form of the burst indicator sequence is determined. According to the preliminary form of the burst indicator sequence, the data comparison tool is used to cross-verify the access behavior monitoring and data storage state. If the verification result meets the preset burst characteristic analysis standard, the complete data set of the access burst indicator sequence is obtained.
[0073] For example, for the marked risk path, the system first extracts events related to cold data access from the storage log through the data analysis tool, assuming that the risk path is "Path A", and its log record contains 1000 access records, of which 200 are cold data access events, involving access timestamps and access object IDs. Next, the system calculates the time interval of the 200 cold data access events, using the algorithm: after sorting the events by timestamp, calculate the time difference between adjacent events to get 199 time interval values in seconds, assuming an average interval of 50 seconds. Then, the system judges the access burst characteristics, with a preset time interval threshold of 30 seconds and an access frequency threshold of 5 times per minute. By statistics, it is found that there is a continuous 10-event time interval less than 30 seconds, with an average of 10 seconds, and the access frequency in this section is 8 times per minute, higher than the threshold of 5 times, meeting the burst characteristic condition. Based on this, the system generates an access burst indicator sequence, with an algorithm: taking a 1-minute time window, calculate the number of events that meet the burst condition in each window to get the sequence value, for example [0, 0, 8, 3, 0], indicating the distribution of burst event numbers in 5 consecutive time windows, where the 3rd window value is 8, indicating a burst peak. The analysis process shows that this sequence reflects the abnormal concentration of cold data access of path A in a certain time period, providing data support for subsequent risk assessment. To form a logical chain, the system performs correlation analysis on the indicator sequence and other risk indicators of path A (such as access permission anomalies), assuming that the permission anomaly indicator is 3 (normal range 1-2), combined with the burst indicator peak value 8, the comprehensive risk score algorithm is: risk score = burst indicator peak value * 0.6 + permission anomaly indicator * 0.4, the result is 8*0.6+3*0.4=6.0 (full score 10), indicating that path A is at high risk and needs further monitoring. Through the above automatic process, the system realizes the whole-link processing from data extraction to risk assessment.
[0074] S104、According to the access burst indicator sequence, analyze the collaboration concealment mode of the stranger user in the path, update the node embedding vector through the neural network model, and determine the quantification score of the collaboration concealment degree.
[0075] Figure 3The lower part shows the quantitative calculation process of the collaboration concealment degree. First, the node embedding vector is updated through the GNN graph neural network, for example, V1=[0.82, 0.15, 0.93,...], then the cosine similarity S=cos(V1, V2)=0.87 between nodes is calculated, and the concealment index H=f(interval, frequency)=0.92 is calculated according to the access interval and frequency characteristics. Finally, the collaboration concealment degree score is obtained through the weighted formula Score=0.6*S+0.4*H=0.6*0.87+0.4*0.92=0.890. The score close to 1 indicates that there is a highly concealed collaboration access mode between multiple accounts, and the system determines it as a high-risk level, triggering the corresponding security protection measures.
[0076] As shown in Figure 6 The node embedding vector updating algorithm realizes the deep extraction of enterprise node association characteristics through the graph neural network. In the node network, there is an association relationship between the target node and its neighbor nodes, and each node initializes an embedding vector, for example, [0.1, 0.2, 0.3]. The initial vector is input into the first layer of GNN convolution, and the information of neighbor nodes is aggregated through the weight matrix W1 to capture the association characteristics between nodes. Then, the output of the first layer enters the second layer of GNN convolution, and the weight matrix W2 is used to further extract high-order features to generate an updated embedding vector, for example, [0.23, 0.31, 0.28]. After obtaining the updated embedding vector, the system calculates the collaboration concealment degree. First, the cosine similarity between the target node and the collaboration group nodes is calculated, for example, 0.85, which reflects the similarity in the vector space; second, the concealment index is calculated, for example, 0.97, which evaluates the concealment characteristics of the behavior pattern. Finally, the comprehensive score 0.892 is calculated through the weighted formula 0.6*0.85+0.4*0.97, and the higher the score, the stronger the collaboration concealment between enterprises. The whole algorithm process includes three main stages of input node network, GNN processing, output embedding vector and score calculation, which realizes the quantitative evaluation of the concealment of enterprise collaboration behavior.
[0077] Specifically, according to the access burst index sequence, the behavior characteristic data of the stranger user in the path is extracted, the behavior characteristic data is preliminarily grouped through a pre-established classification rule, and a preliminary collaboration mode classification result is obtained. For the preliminary collaboration mode classification result, a clustering tool is used to perform deep feature mining on the grouped data, to obtain potential collaboration hidden mode characteristics, and to determine the distribution rule of the hidden mode. If the number of the potential collaboration hidden mode characteristics exceeds a preset threshold, a neural network tool is used to update a node embedding vector, to obtain updated vector data, which is used for subsequent quantitative evaluation. According to the updated vector data, a scoring calculation tool is used to quantitatively process the collaboration hidden degree, and a final collaboration hidden degree quantitative score is determined in combination with a preset weight parameter.
[0078] For example, in the process of analyzing the collaboration concealment pattern of the stranger user in the analysis path and updating the node embedding vector to determine the quantification score of the collaboration concealment degree, firstly, for the analysis of the access burst indicator sequence, the user access data can be processed by the time series analysis algorithm. Assuming that the access data collected in a certain path is the per-minute access frequency sequence [10, 15, 50, 20, 12], by calculating the mean value 18.0 and the standard deviation 16.2 of the sequence, it is identified that the access frequency 50 is an abnormal peak value, indicating that there may be a burst collaboration behavior. Then, the local volatility rate is calculated by using the sliding window algorithm (window size is 3), and the volatility sequence [18.3, 28.4, 27.3] is obtained, further confirming that the high volatility near the peak point is related to potential collaboration. Subsequently, for the analysis of the collaboration concealment pattern of the stranger user, a clustering algorithm such as K-means (K=2) is used to group user behavior features, assuming that the feature vector includes access frequency and time interval, and the data points are [(15, 2.5), (50, 1.0), (12, 3.0)], the clustering result shows that the user with high access frequency and short time interval is classified into the potential collaboration group, and the analysis of the path context shows that the concealment performance is the high consistency of access time, and the quantification concealment indicator is 0.85 (range 0-1). Then, the node embedding vector is updated by the neural network model, the graph neural network (GNN) is used to model the node relationship in the path, the initial embedding vector is [0.1, 0.2, 0.3], and the updated embedding vector is [0.23, 0.31, 0.28] after two-layer convolution operation (weight matrix W1=[0.5, 0.3; 0.2, 0.4]), reflecting the collaboration correlation strength between nodes. Finally, based on the updated embedding vector, the quantification score of the collaboration concealment degree is calculated, the cosine similarity algorithm is used to compare the embedding vectors of the target node and the collaboration group node, assuming that the similarity value is 0.92, and the final score is 0.892 by the weighted formula (0.6*similarity+0.4*concealment) combined with the concealment indicator 0.85, indicating that the collaboration concealment degree is high. The above process forms a complete logical chain through algorithm and numerical analysis, the abnormal detection of the access burst indicator provides the basis for the collaboration pattern analysis, the pattern analysis result drives the embedding vector update, and the updated vector directly affects the calculation of the final quantification score, ensuring the traceability and consistency of the technical implementation.
[0079] S105, extract the stranger user node with a high score from the quantification score, compare its behavior with the deviation of normal interaction correlation by using the behavior analysis algorithm, and determine whether the deviation value is greater than a preset threshold value to obtain an abnormal behavior confirmation list.
[0080] As shown in Figure 8 The method of the present application has a significant performance advantage in abnormal behavior detection. Figure 8The performance differences between the method and the traditional detection method are comprehensively evaluated by using four-dimensional comparative analysis. In terms of detection accuracy, the method achieves an accuracy of 92% by using dynamic network graph combined with behavior analysis, which is significantly improved compared with the rule matching method of 75% and the static threshold method of 68%. In terms of false positive rate control, the method is only 5%, which is significantly lower than the rule matching method of 18% and the static threshold method of 25%, effectively reducing the interference of false judgment on normal business. In terms of detection response time dimension, the average response time of the method is 120 milliseconds, although the rule matching method and the static threshold method are 350 milliseconds and 180 milliseconds respectively, but the method realizes faster response speed while ensuring high accuracy. In terms of hidden behavior recognition rate, the method achieves 88%, which is much higher than the rule matching method of 45% and the static threshold method of 30%, indicating that the dynamic analysis mechanism of the method can effectively identify hidden abnormal behaviors that are difficult to be found by traditional methods. The above multi-dimensional performance comparison verifies the technical superiority of the method in the field of abnormal behavior detection.
[0081] Specifically, the node data of the stranger user with a higher score is extracted from the quantitative score database, the behavior data of the node is compared with the benchmark data of normal interaction behavior by using a pre-established behavior comparison tool, the deviation value of each node is calculated, and a preliminary deviation result list is obtained. For each node data in the preliminary deviation result list, the comparison between the deviation value and the preset threshold value is obtained, if the deviation value is greater than the preset threshold value, the node is marked as a potential abnormal node, and a potential abnormal node set is determined. According to the data in the potential abnormal node set, the detailed interaction record of the node is extracted by using a behavior log tracking tool, the time distribution and frequency characteristics of the behavior mode are analyzed, whether there is an abnormal behavior mode is judged, and a preliminary confirmation list of abnormal behaviors is obtained. For the node data in the preliminary confirmation list of abnormal behaviors, a data cross-validation tool is used to combine the historical behavior database for secondary comparison, if the secondary comparison result still shows behavior abnormality, it is listed in the final abnormal behavior confirmation list, and a final abnormal behavior node set is determined.
[0082] For example, when processing user behavior data, first, high-score stranger nodes are extracted from the quantitative scores. Assuming that we set a score threshold of 85 points, the system will automatically filter out all user nodes with a quantitative score of more than 85 points, for example, user A scores 88 points and user B scores 90 points. These users will be marked as high-risk nodes and enter the next step of analysis. Next, the behavior analysis algorithm is used to compare the deviations of the behaviors of these high-score users. Specifically, a time series-based anomaly detection algorithm is used, such as calculating the Euclidean distance between the user operation frequency and interaction mode and the normal user group. Assuming that the average operation frequency of normal users is 5 times per hour, and the frequency of user A is 15 times per hour, the deviation value is calculated to be 10, which is significantly higher than the preset deviation threshold of 6. At this time, the system will mark the behavior of user A as abnormal. Further, if the deviation value of user B is 5, which is lower than the threshold, it will not be marked. Finally, the system generates an abnormal behavior confirmation list based on users with a deviation value greater than the threshold, for example, user A is listed, while user B is excluded. The list also records the specific deviation value 10 and related behavior logs, such as the number of frequent login attempts is 20 times, which is 3 times higher than the normal range. At the same time, the system automatically associates the IP address change record of user A and finds that it has switched 5 different IPs within 24 hours, which is much higher than the average of 1.2 times for normal users, further supporting the judgment of abnormal behavior. Through this series of automated processes, the system can accurately identify potential risk users and provide data support for subsequent security strategies to ensure the stability of the platform interaction environment.
[0083] S106, for the abnormal behavior confirmation list, build an associated analysis model of path intention, determine the overall path avoidance monitoring intention score by integrating the event sequence in the list and the access burst indicator.
[0084] As Figure 9As shown, the calculation process of the circumvention monitoring intention score includes the following steps: first, the system receives the abnormal behavior confirmation list (containing the event sequence) and the access burst indicator sequence as input data. Then, the distribution feature data of each event is extracted in step S1, and the abnormal fluctuation of the path segment is analyzed. Next, the high-frequency behavior segment proportion is calculated in step S2, for example, if 6 high-frequency behavior segments are detected, and the total number of events is 10, then the proportion is 6 / 10=0.6. The burst index is calculated in step S3, for example, the total burst is 50, and the time window is 10, then the burst index is 50 / 10=5. Step S4 performs weighted calculation of the path intention score, using the formula: path intention score=high-frequency proportion x 0.4+burst index x 0.6, according to the above example, 0.6x 0.4+5x 0.6=3.24 is calculated. Then, the score is checked by the judgment node to determine whether it is greater than the threshold value 2.5, if yes, it is determined that there is a circumvention monitoring intention, otherwise it is marked as not reaching the threshold value. In step S5, the intention scores of all paths are summarized and the average score is calculated. Finally, it is determined whether to trigger an alarm by judging whether the average score is greater than 2.0, if the average score exceeds 2.0, an alarm is triggered, otherwise it is considered to be normal. Through the multi-dimensional weighted scoring mechanism, the algorithm can effectively identify whether the user has the intention to circumvent the security monitoring.
[0085] Specifically, by processing the event sequence data in the abnormal behavior confirmation list, the distribution feature data of each event in the list is obtained. According to the distribution feature data combined with the fluctuation value of the access burst indicator, the abnormal fluctuation score of the path segment is determined. For the high-risk path segment whose abnormal fluctuation score exceeds the preset threshold value, the context event record is obtained from the list to obtain the event association mode in the path segment. By integrating the event association mode and the abnormal fluctuation score, a comprehensive evaluation logic is constructed, and if the mode in the logic matches the preset feature, the circumvention monitoring intention score of the overall path is determined.
[0086] For example, the process of building a path intention association analysis model for abnormal behavior confirmation list and determining the overall path evasion monitoring intention score by integrating event sequences and access burst indicators can be implemented through the following specific implementation method. First, assuming that we have an abnormal behavior confirmation list containing 10 user behavior events, each event records the timestamp, access path, and behavior type (such as login, file download, etc.). We extract the event sequence, calculate the time interval between adjacent events, set the threshold to 5 minutes, and mark it as high-frequency behavior if the interval is less than 5 minutes. The statistical results show that there are 6 high-frequency behavior segments. Second, combined with the access burst indicator, assuming that the normal access frequency of a certain path is 10 times per day, and a user accesses 50 times in 1 hour, the burst index is calculated as 50 / 10=5, which exceeds the preset threshold of 3, and is determined as an abnormal burst. Next, build an association analysis model, use a weighted scoring algorithm, assign a weight of 0.4 to the high-frequency behavior segment ratio (6 / 10=0.6), and a weight of 0.6 to the burst index (5), calculate the path intention score as 0.6*0.4+5*0.6=3.24, the score is higher than the threshold of 2.5, indicating that there is an evasion monitoring intention. Finally, integrate the overall path analysis, aggregate all user path intention scores, assuming there are 5 paths, the scores are 3.24, 1.8, 2.9, 1.5, and 2.1, the average score is 2.28, combined with the business rules, if the average score exceeds 2.0, trigger the system to automatically alarm, notify the background monitoring module for in-depth analysis. Through the above method, from event sequence extraction to intention score calculation, to overall path evaluation, a complete logical chain is formed, ensuring that the system can automatically identify potential evasion behavior and improve monitoring efficiency.
[0087] S107、According to the evasion monitoring intention score, generate a protection response sequence, if the score is higher than the warning threshold, isolate the related nodes and data paths through the access control mechanism, and get the final security protection log.
[0088] As Figure 12As shown, the device connection status of the access control isolation mechanism is displayed. The figure contains four main device nodes: the abnormal node 12101 (IP address 192.168.1.100) is marked as a high-risk state and placed in the isolated area, which is clearly identified by the dotted boundary line; the firewall device 12201 is located in the network center position, responsible for updating and implementing the isolation rules; the core database server 12301 (IP address 10.0.0.5) is in a protected state; the normal client 102 (IP address 192.168.1.50) maintains normal access rights. Different line types are used to distinguish connection states in the figure: solid arrows represent normal connections, and dashed arrows with X symbols represent blocked connections. The connection from the abnormal node to the firewall is cut off, preventing high-risk nodes from accessing the core database; while the connections from the normal client to the firewall and from the firewall to the database remain unblocked. The bottom of the figure indicates the monitoring state, and the system re-evaluates the threat index every 30 minutes to dynamically adjust the isolation strategy. The figure clearly shows how the access control mechanism achieves precise isolation when detecting evasion monitoring intentions, protecting the safety of core resources while not affecting normal business access.
[0089] Specifically, according to the evasion monitoring intention score, the activity records and data path information of the relevant nodes are obtained from the pre-established database, and the score is compared with the preset alert threshold to obtain a comparison result. If the comparison result shows that the score is higher than the alert threshold, the relevant nodes are temporarily isolated through the access control mechanism to obtain a preliminary protection response record. By analyzing the preliminary protection response record, the historical behavior data of the isolated nodes is obtained, and a log analysis tool is used for classification to determine whether there is a persistent threat feature. According to the determination result of the threat feature, a traffic monitoring tool is used to track subsequent activity data for high-risk nodes to obtain the final security protection log.
[0090] For example, in the process of implementing the protection response sequence, assume that the system receives an evaluation result with an evasion monitoring intention score of 85.6, and the preset alert threshold is 70.0. First, the system judges by the built-in score comparison algorithm that 85.6 is greater than 70.0, triggering the high-risk warning mechanism. Then, the system automatically calls the access control mechanism to isolate the relevant nodes and data paths.
[0091] For example, if an abnormal traffic source is detected from a node with IP address 192.168.1.100, the system immediately updates the firewall rules to limit the inbound and outbound traffic of this IP to 0, and cuts off its connection with the core database server at address 10.0.0.5, ensuring data path interruption, with an isolation time set to 24 hours. During this period, the system re-evaluates the threat index of the node every 30 minutes through a traffic analysis algorithm (such as K-means clustering-based anomaly detection, with 5 cluster centers and 10 iterations), and considers releasing the isolation if the index is below 50.0. Subsequently, the system generates detailed security protection logs, recording the isolation start time as 2023-10-15 14:30:25, the IP of the isolated node, data path interruption details, and the threat index evaluation results every 30 minutes (such as the first evaluation of 78.3 and the second evaluation of 65.2), and stores the logs in the security audit database with the file name log_20231015_1430.txt and the storage path / var / log / security / . To form a rigorous logic chain, the system also associates the business monitoring module to combine the isolation event with business impact analysis, calculates the business interruption rate during isolation at about 3.5%, and predicts the recovery time to be within 2 hours, verifies the reasonableness of the prediction by analyzing historical data (the average recovery time of similar events in the past 30 days is 1.8 hours), and ensures the balance between protection measures and business continuity. Finally, the system synchronizes the logs and business impact report to the management platform through an automated script for subsequent analysis and optimization of protection strategies.
[0092] The application provides an access security protection system based on user behavior portrait, mainly comprising:
[0093] A data collection and graph construction module is used to obtain interaction records and data access logs of all accounts in a user collaboration network, construct a dynamic network graph through a neural network model, obtain connection strength and evolution sequence between each node, and extract interaction correlation for subsequent use;
[0094] A multi-level path analysis and risk marking module is used to extract multi-level connection paths between nodes from the dynamic network graph, analyze hidden collaboration hidden features in the paths using a behavior analysis algorithm, determine abnormal behavior sequences, and mark potential risk paths if the path length exceeds a preset threshold and the proportion of unknown users involved is higher than a threshold;
[0095] A cold data access event analysis module is used to obtain cold data access events involved in the marked risk paths, judge access burst characteristics, and obtain access burst indicators if the event time interval is less than a preset interval and the access frequency is higher than a threshold;
[0096] The cooperative concealment mode quantification module is configured to analyze a cooperative concealment mode of a stranger user in the path according to the access burst indicator sequence, update a node embedding vector through the neural network model, and determine a quantification score of the cooperative concealment degree.
[0097] The abnormal behavior confirmation module is configured to extract a high-score stranger user node from the quantification score, compare a deviation of the behavior of the stranger user node from a normal interaction through the behavior analysis algorithm, and determine an abnormal behavior confirmation list if the deviation value is greater than a preset threshold.
[0098] The path intention correlation analysis module is configured to construct a correlation analysis model of a path intention for the abnormal behavior confirmation list, determine an evading monitoring intention score of the whole path by integrating the event sequence in the list and the access burst indicator, and determine an evading monitoring intention score of the whole path by integrating the event sequence in the list and the access burst indicator.
[0099] The protection response generation module is configured to generate an protection response sequence according to the evading monitoring intention score, isolate related nodes and data paths through an access control mechanism if the score is higher than an alert threshold, and obtain a final security protection log.
[0100] As shown in Figure 4 The user behavior portrait-based access security protection system provided by the application comprises three functional levels. The data input layer comprises a data acquisition and graph construction module 101, which receives interaction records and data access logs as raw data input, constructs a dynamic network graph by analyzing the interaction relationship between users and the data access behavior, and outputs to the analysis processing layer. The analysis processing layer comprises five core modules: a multi-level path analysis and risk marking module 201 receives the network graph, extracts a multi-level connection path, and marks a potential risk path; a cold data access event analysis module 202 analyzes the risk path, obtains a cold data access event, and obtains an access burst indicator sequence; a cooperative concealment mode quantification module 203 analyzes the cooperative concealment mode between stranger users, and determines a quantification score; an abnormal behavior confirmation module 204 extracts a high-score node, and obtains an abnormal behavior confirmation list; and a path intention correlation analysis module 205 constructs a correlation analysis model, and determines an evading monitoring intention score. The response output layer comprises a protection response generation module 301, which generates a protection response sequence according to the intention score, and finally outputs a security protection log. The whole system realizes the whole-process security protection from raw data to protection response through layer-by-layer processing of data flow.
[0101] As shown in Figure 10As shown, the enterprise collaboration network server deployment topology of the present application includes a three-layer architecture of a user layer, a network layer and a service layer. The user layer includes a plurality of user terminals 601, 602, 603 and an alarm terminal 604; the network layer includes a firewall device 12201 and a core switch 402; and the service layer includes a log collection server 10101, a graph database server 10201, an analysis computing server 10301 and a core database server 12301.
[0102] It is apparent that a person skilled in the art can implement the present application in other concrete forms without departing from the spirit or essential characteristics thereof, and therefore the above exemplary embodiments are not limitative of the present application. Consequently, the scope of the present application is not to be construed as being limited to the above exemplary embodiments but is to be determined solely on the basis of the following claims. Any drawing reference in the claims is to be construed as being illustrative only and not to be construed as limiting the claims.
Claims
1. An access security protection method based on user behavior profiling, characterized in that, The method includes: The interaction records and data access logs of all accounts in the user collaboration network are obtained, and a dynamic network graph is constructed through a graph neural network (GNN) to obtain the connection strength and evolution sequence between each node. Multi-level connection paths between nodes are extracted from the dynamic network graph. The hidden collaborative features in the paths are analyzed using the isolated forest algorithm / K-means clustering algorithm to determine abnormal behavior sequences. If the path length exceeds a preset threshold and the proportion of unfamiliar users involved is higher than the threshold, it is marked as a potential risk path. For the marked risk path, obtain the cold data access events involved in the path, determine the access burst characteristics, and if the event time interval is less than the preset interval and the access frequency is higher than the threshold, then obtain the access burst index sequence. Based on the access burst index sequence, the collaborative concealment pattern of unfamiliar users in the path is analyzed, and the node embedding vector is updated through the graph neural network (GNN) to determine the quantitative score of the degree of collaborative concealment. Extract unfamiliar user nodes with high scores from the quantified scores, and use the isolated forest algorithm / K-means clustering algorithm to compare the deviation of their behavior from normal interaction. If the deviation value is greater than a preset threshold, an abnormal behavior confirmation list is obtained. For the abnormal behavior confirmation list, a path intent correlation analysis model is constructed. By integrating the event sequence in the list and the access burst index, the overall path avoidance monitoring intent score is determined. Based on the monitoring avoidance intent score, a protection response sequence is generated. If the score is higher than the warning threshold, the relevant nodes and data paths are isolated through the access control mechanism to obtain the final security protection log. Specifically, for the abnormal behavior confirmation list, a path intent correlation analysis model is constructed. By integrating the event sequences in the list and the access burst indicators, the overall path avoidance monitoring intent score is determined, including: By processing the event sequence data in the abnormal behavior confirmation list, the distribution characteristic data of each event in the list is obtained; Based on the distribution feature data and the fluctuation value of the access burst index, the abnormal fluctuation score of the path segment is determined, wherein the path segment is an event sequence fragment in the abnormal behavior confirmation list. For high-risk path segments where the abnormal fluctuation score exceeds a preset threshold, context event records are retrieved from the list to obtain the event association pattern within the path segment. By integrating the event association patterns and the abnormal fluctuation scores, a comprehensive evaluation logic is constructed. If the patterns in the logic match preset features, the overall path's intention to evade monitoring is determined.
2. The method according to claim 1, characterized in that, The process involves obtaining interaction records and data access logs from all accounts in the user collaboration network, constructing a dynamic network graph using a graph neural network (GNN), and obtaining the connection strength and evolution sequence between each node for subsequent interaction association extraction. This includes: The original logs are formatted and denoised, and sorted according to timestamps to form a time-series interactive dataset; Based on this dataset, we used graph modeling to establish account nodes and their interaction edges, and used interaction frequency or data flow as weights to calculate the connection strength between nodes. Furthermore, the evolution trend of connection strength is analyzed by time window slices to generate an evolution sequence that reflects the dynamic changes in cooperative relationships.
3. The method according to claim 1, characterized in that, The process involves extracting multi-level connection paths between nodes from the dynamic network graph, analyzing the hidden collaborative features within these paths using the Isolation Forest / K-means clustering algorithm, and identifying abnormal behavior sequences. If the path length exceeds a preset threshold and the proportion of unfamiliar users involved is higher than the threshold, it is marked as a potentially risky path, including: Traverse the path structure in the dynamic network graph to obtain the hop count and user identity information of each path; By comparing users' historical collaboration relationships, we can identify unfamiliar user nodes in the path and calculate their proportion. When the path length exceeds the first preset threshold and the proportion of unfamiliar users is higher than the second preset threshold, the path will be included in the inspection list. By further combining historical behavior baselines, we can analyze whether the interaction frequency and timing patterns in the path deviate from the normal pattern, thereby determining whether there are abnormal behavior sequences.
4. The method according to claim 1, characterized in that, For the marked risk path, cold data access events involved in the path are obtained, and access burst characteristics are determined. If the event time interval is less than a preset interval and the access frequency is higher than a threshold, an access burst indicator sequence is obtained, including: Filter out operation records on cold data from the logs associated with risk paths; The time interval between adjacent visits is calculated based on the event timestamp, and the frequency of visits per unit time is counted using a sliding time window. If the time interval is less than the third preset interval and the access frequency is higher than the fourth preset threshold, the event is determined to be sudden, and a structured access suddenness index sequence is generated accordingly.
5. The method according to claim 1, characterized in that, The step of analyzing the collaborative concealment pattern of unfamiliar users in the path based on the access burst index sequence, and determining the quantitative score of the degree of collaborative concealment by updating the node embedding vector through the graph neural network (GNN), includes: Based on the access burst indicator sequence, the behavioral characteristics of unfamiliar users in the path are extracted, including the distribution of access objects, the combination of operation types and the timing rhythm. Clustering algorithms are used to identify potential patterns of coordinated covert behavior. When the number of identified pattern features exceeds the fifth preset threshold, the graph neural network (GNN) is triggered to incrementally update the embedding vectors of the relevant nodes. Finally, based on the updated vector and combined with the preset weighting rules, a quantitative score representing the degree of collaborative concealment is calculated.
6. The method according to claim 1, characterized in that, The process involves extracting high-scoring unfamiliar user nodes from the quantified scores, comparing their behavior against normal interactions using the isolated forest / K-means clustering algorithm, and determining if the deviation exceeds a preset threshold. If so, an abnormal behavior confirmation list is obtained, including: Filter out unfamiliar user nodes whose scores are higher than the sixth preset threshold from the quantitative score results; The current behavioral characteristics of these nodes are compared with the historical interaction benchmarks of normal users in multiple dimensions, and the comprehensive deviation value is calculated. If the deviation value exceeds the seventh preset threshold, it will be initially marked as abnormal; Further cross-validation of its behavioral consistency across multiple time windows or different data dimensions eliminates occasional interference and generates a confirmed list of abnormal behaviors.
7. The method according to claim 1, characterized in that, The process involves generating a protection response sequence based on the monitoring evasion intent score. If the score exceeds a warning threshold, relevant nodes and data paths are isolated using an access control mechanism to obtain the final security protection log, which includes: The score for the intent to evade monitoring is compared with the eighth preset warning threshold; If the score exceeds the limit, the access control policy will be activated immediately to temporarily isolate or downgrade the permissions of the relevant user nodes and their data access paths. Simultaneously, the historical activity trajectories of the controlled nodes are collected to analyze whether there are persistent or spreading threats; Enhanced monitoring is enabled for nodes identified as high-risk to track their subsequent behavior, and the entire process of operation and decision-making is written into a structured security protection log.
8. An access security protection system based on user behavior profiles, characterized in that, The system includes: Module 1 is used to obtain the interaction records and data access logs of all accounts in the user collaboration network, and to construct a dynamic network graph through a graph neural network (GNN) to obtain the connection strength and evolution sequence between each node; Module 2 is used to extract multi-level connection paths between nodes from the dynamic network graph, and to analyze the hidden collaborative features in the paths using the isolated forest algorithm / K-means clustering algorithm to determine abnormal behavior sequences. If the path length exceeds a preset threshold and the proportion of unfamiliar users involved is higher than the threshold, it is marked as a potential risk path. Module 3 is used to obtain cold data access events involved in the marked risk path, determine access burst characteristics, and obtain an access burst index sequence if the event time interval is less than a preset interval and the access frequency is higher than a threshold. Module 4 is used to analyze the collaborative concealment pattern of unfamiliar users in the path based on the access burst index sequence, and to determine the quantitative score of the degree of collaborative concealment by updating the node embedding vector through the graph neural network (GNN). Module 5 is used to extract unfamiliar user nodes with high scores from the quantified scores, and compare their behavior with the deviation of normal interaction using the isolated forest algorithm / K-means clustering algorithm. If the deviation value is greater than a preset threshold, an abnormal behavior confirmation list is obtained. Module 6 is used to construct a path intent correlation analysis model for the abnormal behavior confirmation list, and to determine the overall path avoidance monitoring intent score by integrating the event sequence in the list and the access burst index. Module 7 is used to generate a protection response sequence based on the monitoring avoidance intention score. If the score is higher than the warning threshold, the relevant nodes and data paths are isolated through the access control mechanism to obtain the final security protection log. Specifically, for the abnormal behavior confirmation list, a path intent correlation analysis model is constructed. By integrating the event sequences in the list and the access burst indicators, the overall path avoidance monitoring intent score is determined, including: By processing the event sequence data in the abnormal behavior confirmation list, the distribution characteristic data of each event in the list is obtained; Based on the distribution feature data and the fluctuation value of the access burst index, the abnormal fluctuation score of the path segment is determined, wherein the path segment is an event sequence fragment in the abnormal behavior confirmation list. For high-risk path segments where the abnormal fluctuation score exceeds a preset threshold, context event records are retrieved from the list to obtain the event association pattern within the path segment. By integrating the event association patterns and the abnormal fluctuation scores, a comprehensive evaluation logic is constructed. If the patterns in the logic match preset features, the overall path's intention to evade monitoring is determined.
Citation Information
Patent Citations
Abnormal access behavior analysis method, electronic equipment, medium and program product
CN119066574A
Network attack tracing method, system and equipment based on user portrait, and medium
CN120238369A