Intrusion login behavior identification method, computer equipment, readable storage medium and program product
By comparing real-time and historical login information from the login platform, the suspiciousness of intrusive login behavior can be identified, solving the problem of relying on professional experience in existing technologies and achieving higher identification accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SF TECH CO LTD
- Filing Date
- 2024-10-25
- Publication Date
- 2026-04-28
AI Technical Summary
In existing technologies, the accuracy of identifying intrusion login behavior depends on the expertise and experience of professionals, which cannot effectively identify unexpected intrusion methods, resulting in low accuracy.
By acquiring real-time login behavior and login information from historical login logs of the target login platform, and comparing dimensions such as login location, time, access content, and frequency, the suspiciousness of intrusive login behavior can be identified, eliminating the reliance on the experience of professional personnel.
It improves the accuracy of identifying intrusion login behavior, enabling accurate identification of intrusion behavior in the face of diverse intrusion methods and reducing false positives.
Smart Images

Figure CN121940144A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of big data technology, and in particular to a method for identifying intrusion login behavior, a computer device, a computer-readable storage medium, and a computer program product. Background Technology
[0002] With the development of technology, the application of login platform technology is becoming more and more widespread. Login platforms are usually set up for specific users, and users can access and process important data by logging into the login platform. Therefore, hackers may use various methods to intrude into the login platform in order to access and process important data in the platform. In order to prevent hackers from maliciously manipulating the important data in the platform, there is an urgent need for a way to identify intrusion login behavior.
[0003] In traditional technologies, professionals typically develop identification rules based on their past experience with intrusion methods. These rules are then used to identify suspicious login behavior. However, hackers employ a wide variety of intrusion methods, such as identity spoofing, session hijacking, CSRF (Cross-site request forgery), password guessing, and registration fraud. Therefore, the accuracy of identifying suspicious login behavior depends on the expertise and experience of the professionals in identifying intrusive login behavior. If the hacker uses an intrusion method on the login platform that the professionals did not anticipate, the identification rules will fail to detect the intrusive login behavior, resulting in low accuracy in identifying intrusive login behavior. Summary of the Invention
[0004] Therefore, it is necessary to provide an intrusion login behavior identification method, apparatus, computer equipment, computer-readable storage medium, and computer program product that can improve the accuracy of intrusion login behavior identification in response to the above-mentioned technical problems.
[0005] Firstly, this application provides a method for identifying intrusion login behavior, including:
[0006] Obtain first login information for real-time login behavior of a target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior;
[0007] Filter out second login information belonging to suspicious login behavior from the historical login logs of the target login platform, wherein the second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior;
[0008] Each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain the comparison result;
[0009] Based on the comparison results, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained.
[0010] Secondly, this application also provides an intrusion login behavior identification device, comprising:
[0011] The acquisition module is used to acquire first login information for real-time login behavior of the target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior;
[0012] The filtering module is used to filter second login information belonging to suspicious login behavior from the historical login logs of the target login platform, wherein the second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior;
[0013] The comparison module is used to compare each login dimension information in the first login information with the login dimension information corresponding to the second login information to obtain the comparison result;
[0014] The identification module is used to identify the item name based on the characteristics of the item name, and obtain the identification result of the intrusion login behavior.
[0015] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0016] Obtain first login information for real-time login behavior of a target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior;
[0017] Filter out second login information belonging to suspicious login behavior from the historical login logs of the target login platform, wherein the second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior;
[0018] Each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain the comparison result;
[0019] Based on the comparison results, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained.
[0020] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0021] Obtain first login information for real-time login behavior of a target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior;
[0022] Filter out second login information belonging to suspicious login behavior from the historical login logs of the target login platform, wherein the second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior;
[0023] Each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain the comparison result;
[0024] Based on the comparison results, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained.
[0025] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0026] Obtain first login information for real-time login behavior of a target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior;
[0027] Filter out second login information belonging to suspicious login behavior from the historical login logs of the target login platform, wherein the second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior;
[0028] Each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain the comparison result;
[0029] Based on the comparison results, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained.
[0030] The aforementioned method, apparatus, computer equipment, computer-readable storage medium, and computer program product for identifying intrusion login behavior acquire first login information representing real-time login behavior against a target login platform. This first login information characterizes at least one of the following: login location, login time, login access content, and login count. Then, it filters second login information belonging to suspicious login behavior from the historical login logs of the target login platform. This second login information characterizes at least one of the following: login location, login time, login access content, and login count. Finally, it compares each login dimension information in the first login information with the corresponding login dimension information in the second login information to obtain... The comparison results are obtained; based on the comparison results, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained. By comparing the login information of the real-time login behavior with the login information of the suspicious login behavior, the intrusion login suspicion of the real-time login behavior is identified. The essence of the identification of intrusion login suspicion lies in the information level of login information that can characterize the login location, login time, login access content or login frequency, rather than the information level of intrusion method. Therefore, it eliminates the dependence on the professional level of professionals and the experience of intrusion login behavior identification. Even if the intrusion methods are diverse, the intrusion login behavior can still be identified through the login information, thus improving the accuracy of intrusion login behavior identification. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is an application environment diagram of an intrusion login behavior identification method in one embodiment;
[0033] Figure 2 This is a flowchart illustrating an intrusion login behavior identification method in one embodiment;
[0034] Figure 3 This is a flowchart illustrating the second login information step of filtering suspicious login behavior from the historical login logs of a target login platform in one embodiment.
[0035] Figure 4 This is a flowchart illustrating the steps of identifying the suspicious intrusion login behavior of real-time login behavior based on the comparison results in one embodiment.
[0036] Figure 5 This is a structural block diagram of an intrusion login behavior identification device in one embodiment;
[0037] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0038] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0039] It should be noted that the information (including but not limited to first login information and second login information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the acquisition, transmission, storage, use, and processing of the relevant data comply with the relevant provisions of national laws and regulations. Users can refuse or easily refuse content pushed to them (e.g., login behavior identification results). In the embodiments of this application, certain existing solutions in the industry, such as software, components, and models, may be mentioned. These should be considered exemplary, and their purpose is merely to illustrate the feasibility of implementing the technical solution of this application, but does not mean that the applicant has or necessarily used such a solution.
[0040] When hackers use identity spoofing, they typically send phishing websites or malware to legitimate users of the login platform. When using session hijacking, they typically intercept the credentials of legitimate users sent to the login platform's server. When using CSRF, they typically construct web pages or links tailored to the login platform to induce legitimate users to send malicious requests. When using password guessing, they typically use brute-force or dictionary attacks to guess legitimate users' passwords and obtain their credentials. When using registration-based hacking, they typically register a large number of new accounts to abuse the login platform and attempt malicious attacks; once they obtain legitimate user credentials, hackers can use those credentials to access the login platform.
[0041] As illustrated by the examples above, hackers can currently use various channels to attempt to intrude into login platforms and perform malicious operations. When hackers fail to penetrate using the above methods, they will also optimize their intrusion methods. Therefore, relying solely on the intrusion methods used by hackers as the basis for identifying intrusion login behavior cannot fundamentally achieve the identification of intrusion login behavior. Thus, there is an urgent need for a way to accurately identify intrusion login behavior.
[0042] The intrusion login behavior identification method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on a cloud or other network server. Server 104 obtains first login information representing real-time login behavior against a target login platform, and second login information representing suspicious login behavior. The first login information represents at least one of the following: login location, login time, login access content, and login count of the real-time login behavior. The second login information represents at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior. Each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain a comparison result. Based on the comparison result, server 104 identifies the intrusion login suspicion of the real-time login behavior, obtains the login behavior identification result, and pushes and displays the login behavior identification result on terminal 102. The terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle systems, and projection devices. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted displays. Head-mounted displays can be virtual reality (VR) devices, augmented reality (AR) devices, and smart glasses. The server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0043] In one exemplary embodiment, such as Figure 2 As shown, a method for identifying intrusion login behavior is provided, which can be applied to... Figure 1 Taking server 104 as an example, the explanation includes the following steps 202 to 208. Wherein:
[0044] Step 202: Obtain first login information for real-time login behavior of the target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior.
[0045] In step 202, the target login platform is the login platform waiting to be identified for intrusion login behavior. The target login platform can be a CAS (Central Authentication Service) login platform or other login platforms, and there are no restrictions here.
[0046] Thus, because the CAS login platform can access multiple portal systems, it contains more data than other login platforms, and therefore has more avenues for malicious operations. Consequently, the CAS login platform is at higher risk of being attacked by hackers. Therefore, providing a method for identifying intrusive login behaviors for the CAS login platform ensures its security.
[0047] The real-time login behavior refers to the login behavior performed within a first preset time period. The first preset time period can be the most recent day or the most recent week, and there is no restriction on it.
[0048] As an example, step 202 includes: obtaining first login information of real-time login behavior sent by the target login platform.
[0049] As another embodiment, step 202 includes: querying the first login information of real-time login behavior from the historical login logs of the target login platform, wherein the historical login logs include login information of each login behavior at each time point.
[0050] Step 204: Filter the second login information belonging to suspicious login behavior from the historical login logs of the target login platform. The second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior.
[0051] Suspicious login behavior is defined as login behavior suspected of being hacked. Login information (including but not limited to the first and second login information mentioned above, and the third and fourth login information described below) includes at least one of the following: login location information, login device information, login access information, login time information, and login count information; login location information includes at least one of the following: login province information, login city information, login country information, login address information, login longitude information, and login latitude information; login device information is used to identify the login device, and the login device identifier is unique; different login devices have different login device identifiers; login access information includes at least one of the following: login access system and login access data; login count information is used to indicate the number of login failures in a single login attempt.
[0052] As one embodiment, step 204 includes: obtaining at least one intrusion method, wherein the intrusion method includes, but is not limited to, identity spoofing, session hijacking, CSRF, password guessing, registration flight, etc.; and filtering second login information belonging to suspicious login behavior from the historical login logs of the target login platform according to at least one intrusion method.
[0053] In this way, second login information that matches multiple intrusion methods and belongs to suspicious login behavior can be filtered from historical login logs.
[0054] As one embodiment, according to at least one intrusion method, filtering second login information belonging to suspicious login behavior from the historical login logs of the target login platform includes: if the intrusion method includes password guessing, then filtering second login information belonging to suspicious login behavior from the historical login logs whose number of login failures is greater than a preset threshold.
[0055] Therefore, since password guessing is an intrusion method that uses brute force or dictionary attacks to guess the password of legitimate users, using the number of failed login attempts as a filtering criterion can accurately filter out suspicious login behavior that belongs to the password guessing intrusion method.
[0056] As another embodiment, according to at least one intrusion method, filtering second login information belonging to suspicious login behavior from the historical login logs of the target login platform includes: if the intrusion method includes the registration flight method, then according to the registration time of each login behavior in the historical login logs, filtering second login information belonging to suspicious login behavior from the historical login logs. Specifically, filtering second login information belonging to suspicious login behavior from the historical login logs whose registration time interval between other login behaviors does not exceed a preset interval threshold, and whose number of other login behaviors not exceeding the preset interval threshold is greater than a preset number threshold.
[0057] Therefore, since registering for flights is a method of intrusion that involves registering a large number of new accounts, using the registration time as a filtering criterion can accurately filter out the second login information of suspicious login behaviors belonging to this intrusion method.
[0058] It is understandable that since the methods of intrusion into a target login platform are not necessarily fixed, only the two methods mentioned above are more likely to find the corresponding second login information that belongs to suspicious login behavior by means of registration time or number of login failures. However, when using other intrusion methods such as identity spoofing and CSRF, their characteristics are usually no different from legitimate login behavior. Therefore, using the above methods may result in the inability to completely filter out the second login information that belongs to suspicious login behavior.
[0059] As another embodiment, step 204 includes: filtering second login information belonging to suspicious login behavior from each login information in the historical login log based on the deviation between each login information in the historical login log. Specifically, if there is a target login information group with a deviation greater than a preset deviation threshold, then the target login information group is used to filter second login information belonging to suspicious login behavior.
[0060] In this way, secondary login information that constitutes suspicious login behavior when using other intrusion methods such as identity spoofing and CSRF can be extracted, thus improving the completeness of the screening of secondary login information.
[0061] Step 206: Compare each login dimension information in the first login information with the corresponding login dimension information in the second login information to obtain the comparison results.
[0062] For example, step 206 includes: comparing each login dimension information in the first login information with the login dimension information corresponding to the second login information to obtain the similarity between each login dimension information in the first login information and the login dimension information corresponding to the second login information, and determining the similarity between all login dimension information in the first login information as the comparison result.
[0063] Among them, the first login information and the second login information to be compared belong to the same login type. Specifically, login information belonging to the same account can be determined to belong to the same login type, or login information belonging to the same job type can be determined to belong to the same login type.
[0064] It is understandable that there may be significant discrepancies between login information from different accounts. For example, the login location information for account A's second login might be located in region A, while the login location information for account B's second login might be located in region B. If the login location information for account B's first login is compared with that of account A's second login, and account B's first login location is located in region B, it's easy to misjudge the login activity corresponding to account B's first login as a legitimate login activity (when it should actually be an intrusion). Conversely, if account B's first login location is located in region A, it's easy to misjudge the login activity corresponding to account B's first login as an intrusion activity (when it should actually be a legitimate login), leading to low accuracy in identifying intrusion activities. Therefore, the above settings allow for comparison of first and second login information belonging to the same account, ensuring the accuracy of intrusion activity identification.
[0065] It is understandable that there may be significant differences in login information between different job types. For example, the second login information for job type A might show access to content A, while the second login information for job type B might show access to content B. If the login behavior corresponding to the first login information for job type B is misjudged as a legitimate login behavior (in reality, the login location information should be compared with the login location information of the second login information for job type A, but if the login location information of the first login information for job type B is distributed in access content B, then the login behavior belonging to job type B is easily misjudged), or if the login location information of the first login information for job type B is distributed in access content A, then the login behavior corresponding to the first login information for job type B is easily misjudged as an intrusion login behavior (when it should actually be a legitimate login behavior), resulting in low accuracy in identifying intrusion login behavior. Therefore, the above settings allow for the comparison of first and second login information belonging to the same job type, ensuring the accuracy of intrusion login behavior identification.
[0066] As one embodiment, each login dimension information in the first login information is compared with the login dimension information corresponding to the second login information to obtain the similarity between each login dimension information in the first login information and the login dimension information corresponding to the second login information. This includes: if the login dimension information includes login location information, then the login location information in the first login information is compared with the login location information corresponding to the second login information to obtain the distance between the login location information in the first login information and the login location information corresponding to the second login information; based on the distance between the login location information in the first login information and the login location information corresponding to the second login information, a similarity between the login location information in the first login information and the login location information corresponding to the second login information is generated, wherein the shorter the distance between the login location information in the first login information and the login location information corresponding to the second login information, the higher the similarity between the login location information in the first login information and the login location information corresponding to the second login information.
[0067] In another embodiment, each login dimension information in the first login information is compared with the login dimension information corresponding to the second login information to obtain the similarity between each login dimension information in the first login information and the login dimension information corresponding to the second login information. This includes: if the login dimension information includes login device information, then when the login device information in the first login information and the login device information corresponding to the second login information belong to the same device, the similarity between the login device information in the first login information and the login device information corresponding to the second login information is determined as a first similarity; if the login device information in the first login information and the login device information corresponding to the second login information do not belong to the same device, the similarity between the login device information in the first login information and the login device information corresponding to the second login information is determined as a second similarity, wherein the first similarity is greater than the second similarity.
[0068] As another embodiment, each login dimension information in the first login information is compared with the login dimension information corresponding to the second login information to obtain the similarity between each login dimension information in the first login information and the login dimension information corresponding to the second login information. This includes: if the login dimension information includes login access content, then the login access content in the first login information is compared with the login access content corresponding to the second login information to obtain overlapping login access content. The ratio between the size of the overlapping login access content and the size of the login access content in the first login information is determined as the similarity between the login access content in the first login information and the login access content corresponding to the second login information.
[0069] As another embodiment, each login dimension information in the first login information is compared with the login dimension information corresponding to the second login information to obtain the similarity between each login dimension information in the first login information and the login dimension information corresponding to the second login information. This includes: if the login dimension information includes the number of login failures, then the number of login failures in the first login information is compared with the number of login failures corresponding to the second login information to obtain the difference in the number of login failures. Based on the difference in the number of login failures, the similarity between the number of login failures in the first login information and the number of login failures corresponding to the second login information is generated. The larger the difference in the number of login failures, the higher the similarity between the number of login failures in the first login information and the number of login failures corresponding to the second login information.
[0070] Step 208: Based on the comparison results, identify the suspiciousness of intrusion login in real-time login behavior and obtain the login behavior identification result.
[0071] In step 208, the login behavior identification result is used to characterize the intrusion login identification type of real-time login behavior. At this time, the login behavior identification result includes intrusion login behavior result or legitimate login behavior result. The login behavior identification result can also be used to characterize the degree of intrusion login suspicion of real-time login behavior. At this time, the login behavior identification result includes the degree of intrusion login suspicion value, which is not restricted here.
[0072] As an example, step 208 includes: determining login dimension information whose similarity to the first login information meets the preset similarity conditions based on the comparison results; identifying the intrusion login suspicion of real-time login behavior based on the login dimension information whose similarity to the first login information meets the preset similarity conditions; and obtaining login behavior identification results.
[0073] The preset similarity condition can be a preset similarity range, for example, a similarity range consisting of values greater than a preset similarity threshold.
[0074] Further, step 208 includes: if the number of login dimensions corresponding to the third target information represented by the comparison result is greater than a preset number threshold, then the login behavior identification result is determined to be an intrusive login behavior result; if the number of login dimensions corresponding to the third target information represented by the comparison result is not greater than the preset number threshold, then the login behavior identification result is determined to be a legitimate login behavior result; the third target information is the login dimension information in the first login information whose similarity to the login dimension information corresponding to the second login information is greater than a preset similarity threshold, wherein the preset number threshold can be set by the user as needed or based on experience.
[0075] The preset similarity thresholds for different login dimensions can be the same or different. However, considering that the similarity generation rules for different login dimensions (login dimension information) are different, the preset similarity thresholds are usually set according to the corresponding login dimension.
[0076] As another embodiment, step 208 includes: generating dimension suspicious identification information corresponding to each login dimension of the first login information based on the comparison results; identifying the intrusion login suspiciousness of real-time login behavior based on the dimension suspicious identification information corresponding to all login dimensions of the first login information, and obtaining login behavior identification results.
[0077] In the aforementioned method for identifying intrusion login behavior, the following steps are taken: First login information is obtained based on real-time login behavior against the target login platform. This first login information represents at least one of the following: login location, login time, accessed content, and number of login attempts. Second login information, representing suspicious login behavior, is filtered from the target login platform's historical login logs. This second login information represents at least one of the following: login location, login time, accessed content, and number of login attempts. Each login dimension in the first login information is compared with the corresponding login dimension in the second login information to obtain a comparison result. Based on the comparison result, the real-time login behavior is identified. The system identifies suspicious login behaviors and obtains login behavior identification results by comparing real-time login information with suspicious login information. The identification of suspicious login behaviors essentially lies in the information level that can characterize the login location, login time, login access content, or login frequency, rather than the information level of the intrusion method. Therefore, it eliminates the reliance on the professional level of personnel and experience in identifying intrusion login behaviors. Even if the intrusion methods are diverse, intrusion login behaviors can still be identified through login information, thus improving the accuracy of intrusion login behavior identification.
[0078] Understandably, when filtering second login information based on intrusion methods, only login information obtained through password guessing or registration fraud can be identified. However, it cannot identify login information obtained through other intrusion methods such as identity spoofing or CSRF, resulting in low completeness of the second login information filtering. However, when filtering second login information directly based on the deviation between different login information, it is impossible to filter out second login information that has a small deviation from legitimate login behavior and is considered suspicious. This also results in low completeness of the second login information filtering. Therefore, there is an urgent need for a more accurate method for filtering second login information.
[0079] In one exemplary embodiment, such as Figure 3 As shown, in Figure 2 Step 204 includes steps 302 to 304. Wherein:
[0080] Step 302: Filter out third login information that belongs to legitimate login behavior from the login information in the historical login logs of the target login platform.
[0081] For example, step 302 includes: obtaining information features of each login information in the historical login logs of the target login platform, wherein the information features include the frequency of information occurrence and the correlation between information, and filtering out third login information belonging to legitimate login behavior from each login information in the historical login logs based on the information features of each login information in the historical login logs of the target login platform.
[0082] As an embodiment, step 302 includes: obtaining the frequency of occurrence of each login information in the historical login logs of the target login platform; filtering first target information whose frequency of occurrence is greater than a preset frequency threshold from each login information in the historical login logs, wherein the preset frequency threshold can be set by the user as needed or by experience, specifically determined by the frequency distribution of the frequency of occurrence of each login information; filtering second target information whose correlation with the first target information is greater than a preset correlation threshold from each login information in the historical login logs, wherein the preset correlation threshold can be set by the user as needed or by experience, and is not limited here; and determining the first target information and the second target information as third login information belonging to legitimate login behavior.
[0083] Furthermore, the correlation between the job type corresponding to the login information in the historical login logs and the job type corresponding to the first target information is determined as the correlation between the login information in the historical login logs and the first target information.
[0084] In this way, login information that appears frequently is identified as third-party login information belonging to legitimate login behavior, ensuring the credibility of login information judged as legitimate login behavior; login information that appears less frequently but has a high correlation with login information that appears more frequently is also identified as third-party login information belonging to legitimate login behavior, ensuring the completeness of the identification of login information for legitimate login behavior.
[0085] Step 304: Based on the discrepancy between the fourth login information and the third login information, filter out the second login information that belongs to suspicious login behavior from the fourth login information. The fourth login information is the login information other than the third login information in the historical login log.
[0086] For example, step 304 includes: for each login dimension information in the fourth login information, identifying the degree of suspicion of the login dimension corresponding to the fourth login information based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, and obtaining the dimension suspicion identification information of the login dimension corresponding to the fourth login information; and filtering out the second login information belonging to suspicious login behavior from the fourth login information based on the dimension suspicion identification information of all login dimensions corresponding to the fourth login information.
[0087] Further, as an embodiment, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the degree of suspicion of the login dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login dimension corresponding to the fourth login information. This includes: if the login dimension information includes login location information, then based on the positional deviation between the login location information in the fourth login information and the login location information in the third login information, the degree of suspicion of the login location dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login location dimension corresponding to the fourth login information. The larger the positional deviation, the higher the degree of suspicion represented by the dimension suspicion identification information of the login location dimension corresponding to the fourth login information.
[0088] Specifically, as an embodiment, based on the positional deviation between the login location information in the fourth login information and the login location information in the third login information, the degree of suspicion of the login location dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login location dimension corresponding to the fourth login information is obtained. If the login location information includes at least one of login province information, login city information, login country information, login address information, login longitude information, and login latitude information, based on the positional deviation between at least one of the login province information, login city information, login country information, login address information, login longitude information, and login latitude information in the fourth login information and the corresponding login location information in the third login information, the degree of suspicion of the location dimension corresponding to the login location information included in the fourth login information (including but not limited to login province dimension, login city dimension, login country dimension, login address dimension, login longitude dimension, and login latitude dimension) is identified, and location dimension identification information of the location dimension corresponding to the login location information included in the fourth login information is obtained. The location dimension identification information of the location dimension corresponding to the login location information included in the fourth login information is fused to obtain dimension suspicion identification information of the login location dimension corresponding to the fourth login information.
[0089] Furthermore, the location dimension identification information corresponding to the location dimension of the login location information included in the fourth login information is fused to obtain the dimension suspicious identification information of the login location dimension corresponding to the fourth login information. This includes: fusing the location dimension identification information corresponding to the location dimension of the login location information included in the fourth login information according to the correction coefficient of the location dimension of the login location information included in the fourth login information to obtain the dimension suspicious identification information of the login location dimension corresponding to the fourth login information. The correction coefficient relationship is usually: login country dimension > login province dimension > login city dimension > login address dimension > login longitude dimension equal to login latitude dimension.
[0090] Thus, the correction coefficients for the location dimension are set according to the granularity of the location description. Specifically, the larger the granularity of the location description, the larger the correction coefficient. That is, the greater the influence of the dimension suspicious identification information corresponding to the login location dimension of the fourth login information that participates in the final whole, the more accurately it can characterize the location deviation between the login location information in the fourth login information and the login location information in the third login information.
[0091] As another embodiment, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the degree of suspicion of the login dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login dimension corresponding to the fourth login information. This includes: if the login dimension information includes login device information, then based on the deviation between the login device information in the fourth login information and the login device information in the third login information, the degree of suspicion of the login device dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login device dimension corresponding to the fourth login information.
[0092] Among them, the deviation between the login device information in the fourth login information and the login device information in the third login information represents the degree of suspicion represented by the dimension suspicion identification information of the login device dimension of the fourth login information when the fourth login information and the third login information belong to the same login device. The deviation between the login device information in the fourth login information and the login device information in the third login information represents the degree of suspicion represented by the fourth login information and the third login information not belonging to the same login device.
[0093] As another embodiment, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the degree of suspicion of the login dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login dimension corresponding to the fourth login information. This includes: if the login dimension information includes login access information, then based on the deviation between the login access information in the fourth login information and the login access information in the third login information, the degree of suspicion of the login system dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login access dimension corresponding to the fourth login information. The greater the deviation between the login access information in the fourth login information and the login access information in the third login information, the higher the degree of suspicion represented by the dimension suspicion identification information of the login access dimension corresponding to the fourth login information.
[0094] As another embodiment, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the degree of suspicion of the login dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login dimension corresponding to the fourth login information. This includes: if the login dimension information includes login time information, then based on the time deviation between the login time information in the fourth login information and the login time information in the third login information, the degree of suspicion of the login time dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login time dimension corresponding to the fourth login information. The larger the time deviation, the higher the degree of suspicion represented by the dimension suspicion identification information of the login time dimension corresponding to the fourth login information.
[0095] As another embodiment, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the degree of suspicion of the login dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login dimension corresponding to the fourth login information. This includes: if the login dimension information includes the number of login failures, then based on the difference between the number of login failures in the fourth login information and the number of login failures in the third login information, the degree of suspicion of the login failure count dimension corresponding to the fourth login information is identified to obtain dimension suspicion identification information of the login failure count dimension corresponding to the fourth login information. The larger the difference in the number of login failures, the higher the degree of suspicion represented by the dimension suspicion identification information of the login failure count dimension corresponding to the fourth login information.
[0096] As one embodiment, the dimension suspicious identification information includes dimension suspicious values; based on the dimension suspicious identification information of all login dimensions corresponding to the fourth login information, the second login information belonging to suspicious login behavior is filtered from the fourth login information, including: generating a weight for each login dimension corresponding to the fourth login information according to the importance of each login dimension to the identification of intrusive login behavior; fusing the dimension suspicious values of all login dimensions corresponding to the fourth login information according to the weight of each login dimension corresponding to the fourth login information to obtain the login suspicious value of the fourth login information; filtering the second login information whose corresponding login suspicious value meets the preset suspicious value condition from the fourth login information, wherein the fusion method can be weight addition fusion or weight multiplication fusion, which is not limited here.
[0097] Thus, by taking into account the impact of login location, login device, login access, login time, and number of login failures on the login suspiciousness of the fourth login information, the accuracy of login suspiciousness values is improved.
[0098] Among all login failure dimensions, the weight of the login failure count dimension is set to the highest.
[0099] Therefore, considering that hackers may attempt to intrude into the login platform by trying multiple methods before succeeding, the more login failures there are, the higher the likelihood that it is an intrusive login attempt. Thus, the greater the impact of the login failure count dimension on the decision-making of the login suspicion value of the fourth login information, the more accurate the generation of the login suspicion value of the fourth login information is improved.
[0100] In this embodiment, third login information belonging to legitimate login behavior is filtered from the login information in the historical login logs of the target login platform; second login information belonging to suspicious login behavior is filtered from the fourth login information based on the deviation between the fourth login information and the third login information. The fourth login information is the login information other than the third login information in the historical login logs. On the one hand, since the source of the second login information is the historical login logs of the target login platform, the authenticity of the second login information is guaranteed. On the other hand, the second login information is obtained by filtering the fourth login information based on the deviation between the corresponding and the third login information belonging to legitimate login behavior, so it is also guaranteed that the second login information accurately belongs to suspicious login behavior, that is, the accuracy of the second login information is guaranteed.
[0101] It is understandable that different login dimensions have different impacts on the identification of suspicious intrusion logins. If this impact is not considered when identifying suspicious intrusion logins in real-time based on comparison results, the accuracy of identifying intrusion login behavior is likely to be low. Therefore, there is an urgent need for a way to accurately identify suspicious intrusion logins in real-time based on comparison results.
[0102] In one exemplary embodiment, such as Figure 4 As shown, in Figure 2 Step 208 includes steps 402 to 406. Wherein:
[0103] Step 402: Based on the comparison results, generate dimension suspicious identification information for each login dimension corresponding to the first login information.
[0104] As an example, step 402 includes: if the login dimension includes the login location dimension, then based on the comparison result, dimension suspicious identification information corresponding to the login location dimension of the first login information is generated, wherein the greater the similarity between the login location information of the first login information and the login location information of the second login information, the higher the degree of intrusion login suspiciousness represented by the dimension suspicious identification information corresponding to the login location dimension of the first login information.
[0105] As another embodiment, step 402 includes: if the login dimension includes the login device dimension, then based on the comparison result, dimension suspicious identification information of the login device dimension corresponding to the first login information is generated, wherein the comparison result indicates that when the first login information and the second login information belong to the same login device, the degree of intrusion login suspiciousness represented by the dimension suspicious identification information of the login device dimension corresponding to the first login information is higher than the degree of intrusion login suspiciousness represented by the dimension suspicious identification information of the login device dimension corresponding to the first login information is generated when the comparison result indicates that the first login information and the second login information do not belong to the same login device.
[0106] As another embodiment, step 402 includes: if the login dimension includes login access information, then based on the comparison result, dimension suspicious identification information corresponding to the login access dimension of the first login information is generated, wherein the greater the similarity between the login access information of the first login information and the login access information of the second login information, the higher the degree of intrusion login suspicion represented by the dimension suspicious identification information corresponding to the login access dimension of the first login information.
[0107] As another embodiment, step 402 includes: if the login dimension includes login time information, then based on the comparison result, dimension suspicious identification information corresponding to the login time dimension of the first login information is generated, wherein the greater the similarity between the login time information of the first login information and the login time information of the second login information, the higher the degree of intrusion login suspiciousness represented by the dimension suspicious identification information corresponding to the login time dimension of the first login information.
[0108] As another embodiment, step 402 includes: if the login dimension includes the number of login failures, then based on the comparison result, dimension suspicious identification information corresponding to the number of login failures of the first login information is generated. The comparison result indicates that the greater the similarity between the number of login failures of the first login information and the number of login failures of the second login information, the higher the degree of intrusion login suspicion represented by the dimension suspicious identification information corresponding to the number of login failures of the first login information.
[0109] Step 404: Based on the weight of each login dimension corresponding to the first login information, the dimension suspicious identification information of all login dimensions corresponding to the first login information is fused to obtain the login suspicious value of the first login information.
[0110] The weight of each login dimension corresponding to the first login information can be referred to the weight settings described in the above embodiments, and will not be repeated here.
[0111] For example, step 404 includes: the dimension suspicious identification information includes dimension suspicious values; according to the weight of each login dimension corresponding to the first login information, the dimension suspicious values of all login dimensions corresponding to the first login information are weighted and fused to obtain the login suspicious value of the first login information. The weighted fusion method can be weighted addition fusion or weighted multiplication fusion.
[0112] Step 406: Based on the login suspicion value of the first login information, identify the intrusion login suspicion of the real-time login behavior and obtain the login behavior identification result.
[0113] As an example, step 406 includes: when the login suspicion value of the first login information is greater than a preset suspicion threshold, the login behavior identification result is determined as an intrusion login behavior result; when the login suspicion value of the first login information is not greater than the preset suspicion threshold, the login behavior identification result is determined as a legitimate login behavior result. The preset suspicion threshold can be set by the user as needed or by experience, and is not limited here.
[0114] As another embodiment, step 406 includes: identifying the degree of intrusion login suspicion of real-time login behavior based on the login suspicion value of the first login information, and obtaining the login behavior identification result, wherein the larger the login suspicion value of the first login information, the higher the degree of intrusion login suspicion represented by the login behavior identification result.
[0115] Thus, by providing the corresponding recognition method for each of the various forms of login behavior recognition results, the possibility of recognizing multiple forms of login behavior recognition results is guaranteed.
[0116] In this embodiment, based on the comparison results, dimension suspicious identification information corresponding to each login dimension of the first login information is generated; based on the weight of each login dimension corresponding to the first login information, the dimension suspicious identification information corresponding to all login dimensions of the first login information is fused to obtain the login suspicious value of the first login information; based on the login suspicious value of the first login information, the intrusion login suspiciousness of real-time login behavior is identified to obtain the login behavior identification result. The dimension suspicious identification information of all login dimensions is used together as the basis for generating the login suspicious value of the first login information, ensuring that all login dimensions can participate in the decision-making for the intrusion login suspiciousness of real-time login behavior, thereby improving the accuracy of intrusion login behavior identification.
[0117] As a detailed embodiment, first login information is obtained for real-time login behavior targeting a target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior; the frequency of occurrence of each login information in the historical login logs of the target login platform is obtained; first target information with a frequency greater than a preset frequency threshold is filtered from each login information in the historical login logs; second target information with a correlation greater than a preset correlation threshold is filtered from each login information in the historical login logs; the first target information and the second target information are determined as third login information belonging to legitimate login behavior; and for each of the fourth login information... First, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the suspiciousness of the corresponding login dimension in the fourth login information is identified, resulting in the dimension suspiciousness identification information of the corresponding login dimension in the fourth login information. Second, based on the importance of each login dimension in the fourth login information for identifying intrusive login behavior, a weight is generated for each login dimension in the fourth login information. Third, based on the weight of each login dimension in the fourth login information, the dimension suspiciousness values of all login dimensions in the fourth login information are fused to obtain the login suspiciousness value of the fourth login information. Finally, second login information that meets the preset suspiciousness value conditions is selected from the fourth login information.
[0118] Furthermore, each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain a comparison result. If the comparison result indicates that the number of login dimensions corresponding to the third target information is greater than a preset threshold, then the login behavior identification result is determined to be an intrusive login behavior result. If the comparison result indicates that the number of login dimensions corresponding to the third target information is not greater than the preset threshold, then the login behavior identification result is determined to be a legitimate login behavior result. The third target information is the login dimension information in the first login information whose similarity to the login dimension information corresponding to the second login information is greater than a preset similarity threshold.
[0119] In this way, by comparing the login information of real-time login behavior with the login information of suspicious login behavior, the suspicion of intrusion login in real-time login behavior can be identified. The essence of identifying the suspicion of intrusion login lies in the information level of login information that can characterize the login location, login time, login access content or login frequency, rather than the information level of intrusion method. Therefore, it eliminates the dependence on the professional level of professionals and the experience of intrusion login behavior identification. Even if there are diverse intrusion methods, intrusion login behavior can still be identified through login information, thus improving the accuracy of intrusion login behavior identification.
[0120] Furthermore, on the one hand, since the source of the second login information is the historical login logs of the target login platform, the authenticity of the second login information is guaranteed. On the other hand, the second login information is obtained by filtering the fourth login information based on the deviation between it and the third login information that corresponds to legitimate login behavior. Therefore, it is also guaranteed that the second login information accurately belongs to suspicious login behavior, that is, the accuracy of the second login information is guaranteed. In addition, by using the suspicious identification information of all login dimensions as the basis for generating the login suspicious value of the first login information, it is guaranteed that all login dimensions can participate in the decision-making of the intrusion login suspiciousness of real-time login behavior, thereby improving the accuracy of intrusion login behavior identification.
[0121] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0122] Based on the same inventive concept, this application also provides an intrusion login behavior identification device for implementing the aforementioned intrusion login behavior identification method. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more embodiments of the intrusion login behavior identification device provided below can be found in the limitations of the intrusion login behavior identification method described above, and will not be repeated here.
[0123] In one exemplary embodiment, such as Figure 5 As shown, an intrusion login behavior identification device 500 is provided, including: an acquisition module 502, a filtering module 504, a comparison module 506, and an identification module 508, wherein:
[0124] The acquisition module 502 is used to acquire first login information for real-time login behavior of the target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior;
[0125] The filtering module 504 is used to filter second login information belonging to suspicious login behavior from the historical login logs of the target login platform. The second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior.
[0126] The comparison module 506 is used to compare each login dimension information in the first login information with the login dimension information corresponding to the second login information to obtain the comparison result;
[0127] The identification module 508 is used to identify the item name based on the item name characteristics to obtain the identification result of the intrusion login behavior.
[0128] In one embodiment, the filtering module 504 is further configured to filter third login information belonging to legitimate login behavior from the login information in the historical login logs of the target login platform; and to filter second login information belonging to suspicious login behavior from the fourth login information based on the deviation between the fourth login information and the third login information, wherein the fourth login information is the login information other than the third login information in the historical login logs.
[0129] In one embodiment, the filtering module 504 is further configured to obtain the frequency of occurrence of each login information in the historical login logs of the target login platform; filter out first target information whose frequency of occurrence is greater than a preset frequency threshold from each login information in the historical login logs; filter out second target information whose correlation with the first target information is greater than a preset correlation threshold from each login information in the historical login logs; and determine the first target information and the second target information as third login information belonging to legitimate login behavior.
[0130] In one embodiment, the filtering module 504 is further configured to, for each login dimension information in the fourth login information, identify the degree of suspicion of the login dimension corresponding to the fourth login information based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, and obtain the dimension suspicion identification information of the login dimension corresponding to the fourth login information; and filter the second login information belonging to suspicious login behavior from the fourth login information based on the dimension suspicion identification information of all login dimensions corresponding to the fourth login information.
[0131] In one embodiment, the dimension suspicious identification information includes dimension suspicious values; the filtering module 504 is further configured to generate a weight for each login dimension corresponding to the fourth login information based on the importance of each login dimension to the identification of intrusion login behavior; to fuse the dimension suspicious values of all login dimensions corresponding to the fourth login information according to the weight of each login dimension corresponding to the fourth login information to obtain the login suspicious value of the fourth login information; and to filter the second login information whose corresponding login suspicious value meets the preset suspicious value condition from the fourth login information.
[0132] In one embodiment, the filtering module 504 is further configured to, if the login dimension information includes login location information, identify the degree of suspicion of the login location dimension corresponding to the fourth login information based on the positional deviation between the login location information in the fourth login information and the login location information in the third login information, and obtain dimension suspicion identification information of the login location dimension corresponding to the fourth login information. The larger the positional deviation, the higher the degree of suspicion represented by the dimension suspicion identification information of the login location dimension corresponding to the fourth login information.
[0133] If the login dimension information includes login device information, then based on the deviation between the login device information in the fourth login information and the login device information in the third login information, the degree of suspicion of the login device dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login device dimension corresponding to the fourth login information is obtained.
[0134] If the login dimension information includes login access information, then the degree of suspicion of the login system dimension corresponding to the fourth login information is identified based on the deviation between the login access information in the fourth login information and the login access information in the third login information, thus obtaining dimension suspicion identification information for the login access dimension corresponding to the fourth login information. If the login dimension information includes login time information, then the degree of suspicion of the login time dimension corresponding to the fourth login information is identified based on the time deviation between the login time information in the fourth login information and the login time information in the third login information, thus obtaining dimension suspicion identification information for the login time dimension corresponding to the fourth login information. The larger the time deviation, the higher the degree of suspicion represented by the dimension suspicion identification information for the login time dimension corresponding to the fourth login information. If the login dimension information includes the number of login failures, then the degree of suspicion of the number of login failures dimension corresponding to the fourth login information is identified based on the difference in the number of login failures between the number of login failures in the fourth login information and the number of login failures in the third login information, thus obtaining dimension suspicion identification information for the number of login failures dimension corresponding to the fourth login information. The larger the difference in the number of failures, the higher the degree of suspicion represented by the dimension suspicion identification information for the number of login failures dimension corresponding to the fourth login information.
[0135] In one embodiment, the identification module 508 is further configured to determine that the login behavior identification result is an intrusive login behavior result if the number of login dimensions corresponding to the third target information represented by the comparison result is greater than a preset number threshold; and to determine that the login behavior identification result is a legitimate login behavior result if the number of login dimensions corresponding to the third target information represented by the comparison result is not greater than the preset number threshold. The third target information is the login dimension information in the first login information whose similarity to the login dimension information corresponding to the second login information is greater than a preset similarity threshold.
[0136] In one embodiment, the identification module 508 is further configured to generate dimension suspicious identification information corresponding to each login dimension of the first login information based on the comparison result; to fuse the dimension suspicious identification information corresponding to all login dimensions of the first login information according to the weight of each login dimension of the first login information to obtain the login suspicious value of the first login information; and to identify the intrusion login suspiciousness of the real-time login behavior based on the login suspicious value of the first login information to obtain the login behavior identification result.
[0137] Each module in the aforementioned intrusion login behavior identification device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0138] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 6As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When executed by the processor, the computer program implements an intrusion login behavior identification method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.
[0139] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0140] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0141] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.
[0142] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0143] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0144] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0145] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for identifying intrusion login behavior, characterized in that, The method includes: Obtain first login information for real-time login behavior of a target login platform, wherein the first login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the real-time login behavior; Filter out second login information belonging to suspicious login behavior from the historical login logs of the target login platform, wherein the second login information is used to characterize at least one of the following: login location, login time, login access content, and login count of the suspicious login behavior; Each login dimension information in the first login information is compared with the corresponding login dimension information in the second login information to obtain the comparison result; Based on the comparison results, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained.
2. The method according to claim 1, characterized in that, The step of filtering second login information belonging to suspicious login behavior from the historical login logs of the target login platform includes: Filter out third login information that belongs to legitimate login behavior from the historical login logs of the target login platform; Based on the deviation between the fourth login information and the third login information, second login information belonging to the suspicious login behavior is filtered from the fourth login information, wherein the fourth login information is the login information other than the third login information in the historical login log.
3. The method according to claim 2, characterized in that, The step of filtering third login information belonging to legitimate login behavior from the historical login logs of the target login platform includes: Obtain the frequency of occurrence of each login information in the historical login logs of the target login platform; Filter out first target information whose frequency of occurrence is greater than a preset frequency threshold from each login information in the historical login log; Filter out second target information from the login information in the historical login logs whose correlation with the first target information is greater than a preset correlation threshold; The first target information and the second target information are identified as the third login information belonging to legitimate login behavior.
4. The method according to claim 2, characterized in that, The step of filtering second login information belonging to the suspicious login behavior from the fourth login information based on the deviation between the fourth login information and the third login information includes: For each login dimension information in the fourth login information, based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, the degree of suspicion of the login dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login dimension corresponding to the fourth login information is obtained. Based on the suspicious identification information of all login dimensions corresponding to the fourth login information, the second login information belonging to the suspicious login behavior is filtered out from the fourth login information.
5. The method according to claim 4, characterized in that, The dimension suspicious identification information includes dimension suspicious values; the step of filtering second login information belonging to the suspicious login behavior from the fourth login information based on the dimension suspicious identification information of all login dimensions corresponding to the fourth login information includes: Based on the importance of each login dimension corresponding to the fourth login information for the identification of intrusion login behavior, a weight is generated for each login dimension corresponding to the fourth login information. Based on the weight of each login dimension corresponding to the fourth login information, the dimension suspicion values of all login dimensions corresponding to the fourth login information are fused to obtain the login suspicion value of the fourth login information. The second login information that corresponds to the login suspicious value and meets the preset suspicious value conditions is filtered from the fourth login information.
6. The method according to claim 4, characterized in that, The step of identifying the degree of suspicion of the login dimension corresponding to the fourth login information based on the deviation between the login dimension information in the fourth login information and the login dimension information in the third login information, and obtaining the dimension suspicion identification information of the login dimension corresponding to the fourth login information, includes at least one of the following: If the login dimension information includes login location information, then based on the positional deviation between the login location information in the fourth login information and the login location information in the third login information, the degree of suspicion of the login location dimension corresponding to the fourth login information is identified to obtain the dimension suspicion identification information of the login location dimension corresponding to the fourth login information. The larger the positional deviation, the higher the degree of suspicion represented by the dimension suspicion identification information of the login location dimension corresponding to the fourth login information. If the login dimension information includes login device information, then based on the deviation between the login device information in the fourth login information and the login device information in the third login information, the degree of suspicion of the login device dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login device dimension corresponding to the fourth login information is obtained. If the login dimension information includes login access information, then based on the deviation between the login access information in the fourth login information and the login access information in the third login information, the degree of suspicion of the login system dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login access dimension corresponding to the fourth login information is obtained. If the login dimension information includes login time information, then based on the time deviation between the login time information in the fourth login information and the login time information in the third login information, the degree of suspicion of the login time dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login time dimension corresponding to the fourth login information is obtained. The larger the time deviation, the higher the degree of suspicion represented by the dimension suspicion identification information of the login time dimension corresponding to the fourth login information. If the login dimension information includes the number of login failures, then based on the difference between the number of login failures in the fourth login information and the number of login failures in the third login information, the degree of suspicion of the login failure count dimension corresponding to the fourth login information is identified, and dimension suspicion identification information of the login failure count dimension corresponding to the fourth login information is obtained. The larger the difference, the higher the degree of suspicion represented by the dimension suspicion identification information of the login failure count dimension corresponding to the fourth login information.
7. The method according to any one of claims 1 to 6, characterized in that, The step of identifying the intrusion login suspicion of the real-time login behavior based on the comparison result, and obtaining the login behavior identification result, includes: If the number of login dimensions corresponding to the third target information represented by the comparison result is greater than a preset number threshold, then the login behavior identification result is determined to be an intrusion login behavior result; If the number of login dimensions corresponding to the third target information represented by the comparison result is not greater than a preset number threshold, then the login behavior identification result is determined to be a legitimate login behavior result. The third target information is the login dimension information in the first login information that has a similarity greater than a preset similarity threshold with the login dimension information corresponding to the second login information.
8. The method according to any one of claims 1 to 6, characterized in that, The step of identifying the intrusion login suspicion of the real-time login behavior based on the comparison result, and obtaining the login behavior identification result, includes: Based on the comparison results, dimension suspicious identification information is generated for each login dimension corresponding to the first login information; Based on the weight of each login dimension corresponding to the first login information, the dimension suspicious identification information of all login dimensions corresponding to the first login information is fused to obtain the login suspicious value of the first login information. Based on the login suspicion value of the first login information, the intrusion login suspicion of the real-time login behavior is identified, and the login behavior identification result is obtained.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.