User behavior anomaly detection method and device based on multi-feature learning
By using a neural network model enhanced with multi-feature learning and self-attention mechanism, the problems of noise interference and poor adaptability in complex scenarios in existing technologies for user behavior anomaly detection are solved, and high-precision anomaly detection and detailed report generation are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHONGKE JIASU (BEIJING) INFORMATION TECH CO LTD
- Filing Date
- 2025-12-15
- Publication Date
- 2026-05-19
AI Technical Summary
Existing methods for detecting abnormal user behavior suffer from low accuracy due to limited data and high noise levels, poor adaptability, and difficulty in handling complex and subtle detection scenarios.
By acquiring various log data, we identify multiple statistical features, temporal features, semantic features, and deep learning features. After fusing these features, we input them into a pre-trained neural network model for anomaly detection. We also combine a self-attention mechanism to enhance feature learning and improve detection accuracy.
In complex and covert detection scenarios, it significantly improves the accuracy and robustness of abnormal user behavior detection, and can promptly identify and classify abnormal behaviors, generating detailed abnormal profile reports.
Smart Images

Figure CN122065199A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data detection technology, specifically to a method and apparatus for detecting abnormal user behavior based on multi-feature learning. Background Technology
[0002] With the widespread adoption of the internet, the Internet of Things (IoT), and mobile devices, user interactions with various systems and applications generate massive amounts of behavioral data. This data contains user operating habits, preferences, and potential intentions. Identifying and detecting abnormal user behavior within this complex data stream is crucial, directly impacting system security, business stability, and the quality of user experience.
[0003] In related technologies, anomaly detection of user behavior data is generally performed in three ways. The first method sets a fixed threshold for a single indicator, triggering an alarm when the threshold is exceeded. This method is susceptible to noise interference, has limited ability to detect complex and subtle anomalies, and is prone to numerous false positives and false negatives. The second method uses statistical models to analyze the distribution of single or a few statistical features. This method struggles to capture nonlinear and multi-dimensional correlation anomaly patterns. The third method is based on trigger rules to detect abnormal user behavior. However, this method involves costly rule base construction, struggles to cover all potential anomalies, and lacks adaptability to new and mutated attack behaviors. Therefore, these user behavior anomaly detection methods, due to their limited data sets, are susceptible to noise interference and have poor adaptability when facing complex and subtle detection scenarios, resulting in low detection accuracy. Summary of the Invention
[0004] This invention provides a user behavior anomaly detection method and apparatus based on multi-feature learning to solve the problem that user behavior anomaly detection methods in related technologies suffer from low detection accuracy due to the limited detection data and high noise interference when facing complex and hidden detection scenarios.
[0005] In a first aspect, the present invention provides a user behavior anomaly detection method based on multi-feature learning, the method comprising: Obtain various types of log data; Based on various log data, we identified multiple statistical features, multiple time-series features, multiple semantic features, and multiple deep learning features. By integrating multiple statistical features, multiple temporal features, multiple semantic features, and multiple deep learning features, the target fusion feature is obtained; The target fusion features are input into the abnormal behavior detection model to obtain an anomaly detection score. The abnormal behavior detection model is a pre-trained neural network model.
[0006] This embodiment acquires various log data; based on the various log data, it determines various statistical features, various temporal features, various semantic features, and various deep learning features; it fuses these features to obtain target fusion features; and it inputs the target fusion features into an abnormal behavior detection model to obtain an anomaly detection score. The abnormal behavior detection model is a pre-trained neural network model. Because this embodiment acquires a wide variety of log data and utilizes the abnormal behavior detection model for feature learning, it can improve the accuracy of abnormal user behavior detection even in complex and concealed detection scenarios.
[0007] In some optional embodiments, the user behavior anomaly detection method based on multi-feature learning of the present invention further includes: Based on the anomaly detection score, obtain the target user's target abnormal behavior within a preset time period; Extract the abnormal behavior features corresponding to the target's abnormal behavior; The abnormal behavior features are input into the abnormal behavior classification model for classification, and the classification result of the target abnormal behavior is obtained. Based on the classification results of the target abnormal behavior, determine the abnormal behavior risk assessment parameters corresponding to the target abnormal behavior; Based on the abnormal behavior risk assessment parameters, determine the target risk level corresponding to the target abnormal behavior.
[0008] Through the above-described embodiments, this invention further classifies the target abnormal behavior of the target user within a preset time period by combining the abnormal detection score, then determines the abnormal behavior risk assessment parameters corresponding to the target abnormal behavior based on the classification results of the target abnormal behavior, and finally obtains the target risk level corresponding to the target abnormal behavior, so as to promptly inform the target user of the risk level of the target abnormal behavior.
[0009] In some optional implementations, the user behavior anomaly detection method based on multi-feature learning in this invention obtains target profile information of the target user; Obtain the target operation anomaly information corresponding to the target abnormal behavior, including: operation time anomaly information, operation equipment anomaly information, operation behavior anomaly information, and operation content anomaly information; Based on the target profile information, target risk level, and target operational anomaly information, generate an anomaly profile report for the target user. Through the above-described embodiments, this invention combines target profile information, target risk level, and target operation anomaly information to generate an anomaly profile report for the target user, facilitating timely notification of the detailed anomaly of the target user's abnormal behavior.
[0010] In some optional embodiments, the user behavior anomaly detection method based on multi-feature learning of the present invention further includes: Based on the abnormal user profile report, determine the abnormal event chain of the target user.
[0011] In some optional embodiments, the user behavior anomaly detection method based on multi-feature learning of the present invention further includes: When the anomaly detection score exceeds a preset threshold, an anomaly alarm is triggered based on the target user's anomaly profile report.
[0012] In some optional implementations, the user behavior anomaly detection method based on multi-feature learning in this invention acquires various log data, including: Obtain raw log data from various sources, including: process audit data, service audit data, internet activity data, operation audit data, and login authentication data. Define log event types; Based on the log event type, raw log data of various log data types are classified; Perform data preprocessing on the categorized raw log data; User feature data is added to the preprocessed raw log data to obtain various types of log data.
[0013] Secondly, the present invention provides a user behavior anomaly detection device based on multi-feature learning, the device comprising: The log data acquisition module is used to acquire various types of log data; The log feature determination module is used to determine various statistical features, time-series features, semantic features, and deep learning features based on various log data. The log feature fusion module is used to fuse multiple statistical features, multiple temporal features, multiple semantic features, and multiple deep learning features to obtain the target fused features; The abnormal behavior detection module is used to input the target fused features into the abnormal behavior detection model for detection and obtain an anomaly detection score. The abnormal behavior detection model is a pre-trained neural network model.
[0014] Thirdly, the present invention provides an electronic device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the user behavior anomaly detection method based on multi-feature learning described in the first aspect or any corresponding embodiment.
[0015] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the user behavior anomaly detection method based on multi-feature learning described in the first aspect or any corresponding embodiment thereof.
[0016] Fifthly, the present invention provides a computer program product, including computer instructions for causing a computer to execute the user behavior anomaly detection method based on multi-feature learning described in the first aspect or any corresponding embodiment. Attached Figure Description
[0017] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0018] Figure 1 This is a flowchart illustrating a user behavior anomaly detection method based on multi-feature learning according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the second process of the user behavior anomaly detection method based on multi-feature learning according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the second process of the user behavior anomaly detection method based on multi-feature learning according to an embodiment of the present invention; Figure 4 This is a structural block diagram of a user behavior anomaly detection device based on multi-feature learning according to an embodiment of the present invention; Figure 5 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] It is understood that before using the technical solutions disclosed in the various embodiments of the present invention, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in the present invention and their authorization should be obtained in accordance with relevant laws and regulations through appropriate means.
[0021] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0022] With the widespread adoption of the internet, the Internet of Things (IoT), and mobile devices, user interactions with various systems and applications generate massive amounts of behavioral data. This data contains user operating habits, preferences, and potential intentions. Identifying and detecting abnormal user behavior within this complex data stream is crucial, directly impacting system security, business stability, and the quality of user experience.
[0023] In related technologies, anomaly detection of user behavior data is generally carried out in the following three ways.
[0024] The first approach involves setting a fixed threshold for a single metric, triggering an alarm when that threshold is exceeded. However, user behavior data comes from diverse sources, including heterogeneous information such as time, location, device, operation type, and content. Simple features are insufficient to fully describe the complex patterns of user behavior, ultimately affecting the accuracy of anomaly detection. Therefore, while simple and efficient, this method lacks flexibility, is susceptible to noise interference, has limited ability to detect complex and subtle anomalies, and is prone to generating numerous false alarms or missed alarms.
[0025] The second approach involves using statistical models to analyze the distribution of single or a few statistical features for anomaly detection. However, malicious users or attackers often employ sophisticated and evolving methods to evade detection, making their abnormal behavior more covert, which makes it difficult to detect abnormal behavior using single-dimensional data. Therefore, this method struggles to capture non-linear and multi-dimensionally correlated anomaly patterns.
[0026] The third approach is to detect abnormal user behavior based on trigger rules. However, this approach has a high cost of building a rule base and is difficult to cover all potential anomalies. It also lacks adaptability to new and mutated attack behaviors.
[0027] Therefore, user behavior anomaly detection methods in related technologies suffer from significant noise interference and poor adaptability when facing complex and covert detection scenarios due to their limited detection features.
[0028] Therefore, this embodiment provides a user behavior anomaly detection method based on multi-feature learning, which can be used in computer devices such as mobile phones, tablets, desktop computers, laptops, servers, etc. Figure 1This is a flowchart of a user behavior anomaly detection method based on multi-feature learning according to an embodiment of the present invention, such as... Figure 1 As shown, the process includes the following steps: Step S101: Obtain various log data.
[0029] Specifically, customized data collection software is deployed in the computer device of this embodiment. This software can collect fine-grained behavioral data of the target user at the operating system and network levels in real time and comprehensively. The collected data includes various types of raw log data. Raw log data includes, but is not limited to: process audit data, service audit data, internet access behavior data, file operation audit data, login authentication data, etc.
[0030] Among them, process audit data records information on process startup, termination, creation of child processes, resource usage, file access, network connection, and other behaviors.
[0031] Service audit data records the startup, shutdown, configuration modification, permission change, and access to specific system resources of system services.
[0032] Internet access behavior data records the URLs (Uniform Resource Locator) accessed by users, domain names, protocols, ports, data traffic, etc.
[0033] File operation audit data records operations such as file creation, reading, writing, deletion, modification, and permission changes.
[0034] Login authentication data records the user's login time, URL source, login method, success or failure status, etc.
[0035] In some specific implementations, step S101 above, obtaining various log data, includes: Step a1: Obtain raw log data for various types of log data, including: process audit data, service audit data, internet access behavior data, operation audit data, and login authentication data.
[0036] Specifically, the raw log data for various log types has already been explained above and will not be repeated here.
[0037] Step a2: Define the log event type.
[0038] Step a3: Classify the raw log data of various log data according to the log event type.
[0039] Specifically, based on different original data sources and business needs, we define unified and structured standard log types and field specifications to ensure the comparability and interoperability of different types of log events.
[0040] Step a4: Perform data preprocessing on the categorized raw log data.
[0041] Specifically, the preprocessing methods include data cleaning and data standardization. Data cleaning includes, but is not limited to, deduplication, noise reduction, format correction, and filtering. This embodiment preprocesses the raw log data to improve data quality. Data standardization parses and structures the cleaned raw log data according to predefined standard log types, ensuring consistency in field naming, data types, and units.
[0042] Step a5: Add user feature data to the preprocessed raw log data to obtain various types of log data.
[0043] Specifically, for the preprocessed raw log data, combined with the enterprise's internal user authentication system, host and other information, the preprocessed raw log data is supplemented with related basic user characteristic data such as department, position, and permission level, thereby enriching the contextual information of user behavior.
[0044] Step S102: Based on various log data, determine various statistical features, various time-series features, various semantic features, and various deep learning features.
[0045] Step S103: In this embodiment, multiple statistical features, multiple temporal features, multiple semantic features and multiple deep learning features are fused to obtain the target fusion feature.
[0046] This embodiment performs aggregated statistics on various log data to identify multiple statistical features, multiple time-series features, multiple semantic features, and multiple deep learning features.
[0047] For example, various statistical characteristics include, but are not limited to: high load state, low load state, rate of change of (Central Processing Unit, CPU) usage, number of URL accesses, number of times a specific process is started, count of abnormal operations (such as the number of times file modification failed), access permissions, and other basic statistical characteristics.
[0048] For example, various time-series features include, but are not limited to, time-series related features such as behavioral intervals, sequence patterns, and periodicity. Among these, behavioral intervals calculate the time interval between consecutive operations (such as the interval between two logins or two file accesses), identifying unusually high-frequency behaviors or long periods of inactivity within a short period. Sequence pattern identifiers are typical user operation sequences (such as "login -> open confidential document A -> copy to USB drive"). Periodic time-series features refer to analyzing the periodicity of target user behavior on a weekly, monthly, or quarterly basis, identifying abnormal activity during holidays or non-working hours.
[0049] For example, multiple semantic features include textual semantic features in various logs. Specifically, word embedding techniques or pre-trained language models can be used to extract their semantic vector features to capture the semantic relevance of target user behavior.
[0050] For example, various deep learning features include, but are not limited to: input features, convolutional features, pooling features, combined features, and attention mechanism features.
[0051] The various deep learning features mentioned above are specifically processed using deep neural networks, one-dimensional convolutional neural networks (CNNs), and attention enhancement networks to process behavioral sequences, automatically learning and extracting high-level, abstract feature information from raw or pre-processed sequential behavioral data.
[0052] For details on the extraction process of various deep learning features, please refer to the following content.
[0053] Assume that there is a sequence of file behavior events or a sequence of file paths in this embodiment.
[0054] The input features are extracted through a convolutional neural network, and the input features represent the feature information of event / path element embedding.
[0055] File behavior events (such as creation, deletion, read, and write events) and each component of a file path are discrete symbols. We transform them into a dense real-number vector representation, denoted by the following vocabulary. It contains all possible discrete event types or path components.
[0056] For the first in the sequence Events / components In this embodiment, it is mapped to a single layer through an embedding layer. dimensional vector .
[0057]
[0058] in: yes One-hot encoded vector It is an embedding matrix, where each column corresponds to the embedding vector of an element in the vocabulary.
[0059] For a sequence of length L After embedding, an embedding sequence is obtained. This can be seen as a The matrix.
[0060] Convolutional features are extracted through the convolutional layers in a convolutional neural network.
[0061] Convolutional layers extract local features by applying multiple filters (convolutional kernels).
[0062] Suppose this embodiment has K filters (convolution kernels), each filter , where k is the size of the filter (i.e., the window size, indicating the number of consecutive events / components to be considered).
[0063] For the j-th filter It performs a sliding window operation on the embedded sequence E to generate a feature map. .
[0064] Each eigenvalue It is a filter With the sequence from t to t+k The convolution result of a single embedded vector segment:
[0065] in: It is a submatrix (of size k) consisting of k consecutive embedding vectors extracted from the embedding sequence E. ).
[0066] This represents the operation of dot product or element-wise multiplication and summation (depending on the specific implementation of convolution, it can be understood here as the tensor product and summation of the filter and the local input).
[0067] It is the bias term of the j-th filter.
[0068] It is a modified linear unit activation function.
[0069] For local features in "abnormal file behavior", such as: A process performing "create-write-delete" operations in quick succession (this may indicate malicious behavior).
[0070] A "download-execute" sequence for a specific file type (such as .exe).
[0071] Perform continuous "read-copy-upload" operations in a sensitive directory.
[0072] For local features in the "file access path pattern", such as: / etc / passwd (path to specific sensitive files) / temp / or / tmp / (temporary directory access) C: / Users / Public / (Public directory access) .. / or .. / .. / (attempt to traverse the directory) Multiple filters: Multiple filters of different sizes (e.g., k=2,3,4) are typically used to capture local patterns of different lengths.
[0073] Pooling layers are extracted from pooling layers in convolutional neural networks.
[0074] Pooling layers are used to extract the most salient features from each feature map and reduce dimensionality, increasing the translation invariance of the network (i.e., slight changes in the position of features in the sequence do not lead to drastic changes in the final output).
[0075] The most commonly used is max pooling. For each filter j, a feature map is generated... In this embodiment, the maximum value is taken as the most important local feature captured by the filter.
[0076]
[0077] After pooling all K filters, this embodiment will yield a K-dimensional vector. This vector is the local feature representation extracted by the CNN from the input sequence.
[0078] Combined features are obtained by combining multiple filters of different sizes in a convolutional neural network.
[0079] If this embodiment uses multiple filters of different sizes (e.g.) Each filter size will generate a set of pooled features. These features are then concatenated to form the final feature vector.
[0080]
[0081] in This refers to the local feature representation extracted from file behavior sequences or file path sequences using a CNN. This vector can then be further fed into fully connected layers, classifiers, or used as input to other modules.
[0082] The attention mechanism features were extracted using an attention mechanism enhancement network.
[0083] In the aforementioned feature fusion or deep learning feature extraction process, a self-attention mechanism is dynamically introduced. This mechanism can automatically assign weights to different feature dimensions or time steps based on the context and importance of the behavioral event. This allows the abnormal behavior attention mechanism enhancement network to focus on the feature information that is more critical to identifying abnormal behavior, while effectively reducing the influence of noisy data and irrelevant features. This strengthens the weight of key abnormal information and improves the accuracy and robustness of anomaly detection.
[0084] Regarding abnormal file behavior: Context awareness: assumptions This is a local feature vector representing "execution of a suspicious file". Through self-attention, the network detection can simultaneously consider other local features before and after the event (e.g., "downloading a file", "connecting to an external network") and dynamically determine the impact of these related contextual events on the anomalousness of the "execution of a suspicious file" behavior. If there is a preceding feature such as "downloaded from an unknown website", self-attention will give these related contextual features higher weights, thereby strengthening the anomalous signal of "execution of a suspicious file".
[0085] Reinforcing specific patterns: If a file contains consecutive local features of "create-hide-delete", the self-attention mechanism can capture the strong correlation between these three features and reinforce the anomalous signal of this specific sequence pattern, even if they are not in strictly adjacent positions.
[0086] For document subject auditing: Topic Relevance: Assumption This is a document access feature related to "Project A". The self-attention mechanism can help the attention mechanism enhance the network to consider other recently accessed documents related to "Project A" or creation / modification operations performed in the "Project A" folder when evaluating this access, thereby more accurately identifying the user's overall behavior pattern for "Project A" and auditing whether it conforms to the specifications.
[0087] Critical path element enhancement: For the file access path / home / user / project_A / sensitive_data / report.pdf, although CNN can extract local features of "sensitive_data", self-attention can give it higher importance throughout the path because it indicates the sensitivity of the data.
[0088] Assuming this embodiment has a sequence of file behavior events, after CNN or other feature extraction, this embodiment obtains a local feature representation of the sequence. ,in It is the i-th event / pattern in the sequence A feature vector of dimension L, where L is the sequence length.
[0089] Objective: To use a self-attention mechanism to provide attention to each element in the sequence. Generate a new enhanced representation that includes contextual information. .
[0090] 1. Linear transformation: Generate Q, K, V vectors For each feature vector in the input sequence This embodiment transforms it into a query, key, and value vector through three different linear transformations (matrix multiplication):
[0091]
[0092]
[0093] in: , , It is a learnable weight matrix. Typically, the dimensions are those of the query and the key. Equality, dimension of value Can be with They are different, but for simplicity, we assume here...
[0094] Stack the Q, K, and V vectors of the entire sequence to form a matrix:
[0095]
[0096]
[0097] 2. Calculate attention scores. Attention scores measure the similarity between the query vector and all key vectors. A commonly used method is dot-product attention.
[0098] in: It is an attention score matrix, where the elements are... This represents the i-th query (the element currently being viewed). ) and the j-th key (all elements in the sequence) The correlation between them.
[0099] The specific element calculation is as follows .
[0100] 3. Scaling and Normalization (Softmax) To avoid the Softmax function saturating (gradient vanishing) due to an excessively large inner product, the attention score is scaled and then converted into a probability distribution (attention weights) using the Softmax function.
[0101]
[0102] in: It is a scaling factor, usually the square root of the key vector dimension.
[0103] It is the attention weight matrix, where the elements are... This represents the weight assigned to the j-th element when processing the i-th element.
[0104] For each i.
[0105] 4. Weighted summation: Generates a context vector By using the attention weight matrix A to perform a weighted summation on the value matrix V, a new, context-aware sequence representation is obtained. .
[0106]
[0107] in: .
[0108] For each element in the sequence Its corresponding augmented representation The calculation method is as follows:
[0109] this It contains information about all other elements in the sequence, and their importance is determined by... Decide.
[0110] Step S104: Input the target fusion features into the abnormal behavior detection model to obtain an anomaly detection score. The abnormal behavior detection model is a pre-trained neural network model.
[0111] The target fusion features are input into the abnormal behavior detection model, and an abnormal detection score is output based on the target fusion features.
[0112] Specifically, the feature vectors, after multi-dimensional extraction, fusion, and attention mechanism enhancement, are used as input data. One or more unsupervised or semi-supervised anomaly detection algorithms are employed to calculate the anomaly score for each user behavior event or aggregated behavior within a specific time window. The anomaly detection algorithms used include, but are not limited to: Assuming this embodiment has already used the Isolation Forest algorithm to enhance the feature vectors with self-attention mechanism Its anomaly score was calculated. And a threshold was set. ,when At that time, the judgment This is an outlier.
[0113] For example, for a sample that is judged as abnormal. If we want to know which feature dimensions contribute the most to its anomalies.
[0114] 1. Path Contribution For an outlier This embodiment focuses on the path from the root node to an isolated tree t in an isolated forest. Path of the leaf node This path consists of a series of feature selections and segmentation points.
[0115] For path Each split node on It divides the data into two parts by selecting feature j and split point p. If this split makes If further isolated, then feature j represents the path length of that point in tree t. It has made contributions.
[0116] A more refined feature contribution metric would consider: Split depth: The closer a split is to the root node (the shallower the split), the more critical the selected features are usually to isolate that point.
[0117] Splitting effect: The size of the subset containing the outliers after the split.
[0118] 2. Feature Contribution per Tree For isolating outliers in tree t path Each split node m on: make Select the feature dimension for splitting this node.
[0119] make This represents the depth at which the node is located.
[0120] make This is the size of the subset of samples contained in this node.
[0121] This embodiment can define feature j in tree t. Contribution weight The features are weighted based on their frequency and depth of occurrence in the path:
[0122] in: It is a very small positive number to prevent the denominator from being zero.
[0123] If feature j appears multiple times in the path, its contribution is accumulated. This reflects the idea that the earlier (shallower) the split, the greater its contribution to the characteristics.
[0124] 3. Overall Feature Importance of Isolated Forests To obtain all tree pairs in an isolated forest for a specific outlier. The overall feature contribution is calculated by averaging the contribution weights of all trees in this embodiment:
[0125] in: T is the total number of trees in an isolated forest.
[0126] Representing feature dimension j for outliers Average contribution of anomalies.
[0127] 4. Filtering for abnormal features Once the outlier for each feature dimension is calculated... Contribution In this embodiment, abnormal features can be "filtered" in the following way: Sorting: For all feature dimensions According to its Sort the values in descending order.
[0128] Threshold filtering: Select the set of feature dimensions whose contribution exceeds a preset threshold γ. :
[0129] This set Isolated forests are considered anomalies. The set of abnormal features selected through "screening".
[0130] "Abnormal characteristics" applied to abnormal file behavior and file subject auditing behavior. File Abnormal Behavior: If a sequence of file behaviors is determined to be abnormal (e.g., Create-Write-Delete a sensitive file), then It may highlight: Process-related characteristics: process name (svchost.exe disguised), command-line parameters (cmd.exe / c del).
[0131] File operation type characteristics: Frequent write and delete operations.
[0132] File path characteristics: sensitive directories being operated on, and the temp directory.
[0133] Time characteristics: The time period in which the operation occurred (late at night).
[0134] Network characteristics: Anomalous external connections. These are features enhanced by self-attention.
[0135] File topic auditing behavior: If a user's behavior regarding a file topic (such as "Top Secret Project X Document") is deemed abnormal (e.g., abnormal copying of a large number of related documents within a short period of time), then... It may highlight: Document content / semantic characteristics: Documents containing specific sensitive keywords.
[0136] Operation frequency characteristics: Abnormally high frequency of access to documents on this topic.
[0137] Target device characteristics: copied to USB flash drive, uploaded to unauthorized cloud storage.
[0138] User context characteristics: Does the user have permission to access this type of document but exhibit abnormal behavior patterns?
[0139] This embodiment acquires various log data; based on the various log data, it determines various statistical features, various temporal features, various semantic features, and various deep learning features; it fuses these features to obtain target fusion features; and it inputs the target fusion features into an abnormal behavior detection model to obtain an anomaly detection score. The abnormal behavior detection model is a pre-trained neural network model. Because this embodiment acquires a wide variety of log data and utilizes the abnormal behavior detection model for feature learning, it can improve the accuracy of abnormal user behavior detection even in complex and concealed detection scenarios.
[0140] This embodiment provides a user behavior anomaly detection method based on multi-feature learning, which can be used in computer devices such as mobile phones, tablets, desktop computers, laptops, servers, etc. Figure 2 This is a flowchart of a user behavior anomaly detection method based on multi-feature learning according to an embodiment of the present invention, such as... Figure 2 As shown, the process includes the following steps: Step S201: Based on the anomaly detection score, obtain the target user's target abnormal behavior within a preset time period.
[0141] Obtain the target user's abnormal behavior within a preset time period. Such abnormal behavior includes, but is not limited to: abnormal startup of high-risk processes, abnormal login from different locations, and abnormal high-frequency file operations.
[0142] Step S202: Extract the abnormal behavior features corresponding to the target abnormal behavior.
[0143] Abnormal behavior characteristics are the key features that characterize the abnormal behavior of a target.
[0144] Step S203: Input the abnormal behavior features into the abnormal behavior classification model for classification to obtain the classification result of the target abnormal behavior.
[0145] For example, various abnormal behavior classification results include, but are not limited to: "account theft", "malicious file operation", "internal personnel data leakage", and "privilege abuse".
[0146] Step S204: Based on the classification results of the target abnormal behavior, determine the abnormal behavior risk assessment parameters corresponding to the target abnormal behavior.
[0147] For example, if the target abnormal behavior is classified as account theft, the corresponding abnormal behavior risk assessment parameters are determined based on this account theft type. These risk assessment parameters include, but are not limited to, parameters such as the number of abnormal events, abnormal scores, and duration.
[0148] Step S205: Determine the target risk level corresponding to the target abnormal behavior based on the abnormal behavior risk assessment parameters.
[0149] For example, the abnormal behavior risk assessment parameter is the number of abnormal events, which is 3. By combining this risk assessment parameter with a preset threshold, the target risk level corresponding to the target abnormal behavior is determined. Typically, in this embodiment, the target risk levels corresponding to the target abnormal behavior include: low, medium, and high.
[0150] Figure 2 For details of steps S101-S104, please refer to the above embodiment, and they will not be repeated here.
[0151] This embodiment, through the above implementation method, further classifies the target abnormal behavior of the target user within a preset time by combining the abnormal detection score, then determines the abnormal behavior risk assessment parameters corresponding to the target abnormal behavior based on the classification results of the target abnormal behavior, and finally obtains the target risk level corresponding to the target abnormal behavior, so as to promptly inform the target user of the risk level of the target abnormal behavior.
[0152] This embodiment provides a user behavior anomaly detection method based on multi-feature learning, which can be used in computer devices such as mobile phones, tablets, desktop computers, laptops, servers, etc. Figure 3 This is a flowchart of a user behavior anomaly detection method based on multi-feature learning according to an embodiment of the present invention, such as... Figure 3 As shown, the process includes the following steps: Step S301: Obtain the target user's target profile information.
[0153] Specifically, the target user profile information includes the target user's basic information and prominent features of abnormal behavior. For example, the target profile information represents the degree of abnormal deviation in terms of abnormal login events and active time periods in the "time dimension," access to different URLs and unconventional locations in the spatial dimension, abnormal command execution and access to high-risk files in the operational dimension, and abnormal high-frequency operations in the frequency dimension.
[0154] Step S302: Obtain the target operation anomaly information corresponding to the target abnormal behavior, wherein the target operation anomaly information includes: operation time anomaly information, operation equipment anomaly information, operation behavior anomaly information, and operation content anomaly information.
[0155] Step S303: Generate an abnormal profile report for the target user based on the target profile information, target risk level, and target operation anomaly information. The target user's anomaly profile report displays detailed anomaly information about the target user, making it easy for the target user to know the anomaly status corresponding to the target's abnormal behavior in a timely manner.
[0156] Figure 3 For details of steps S101-S104 and steps S201-S205, please refer to the above implementation method, and they will not be repeated here.
[0157] This embodiment, through the above implementation method, combines target profile information, target risk level, and target operation anomaly information to generate an anomaly profile report for the target user, which facilitates timely notification of the detailed anomaly of the target user's abnormal behavior.
[0158] In some specific implementations, the user behavior anomaly detection method based on multi-feature learning in this embodiment further includes: Based on the abnormal user profile report, determine the abnormal event chain of the target user.
[0159] For example, this embodiment delves into the contextual information when abnormal behavior occurs, including the sequence of behaviors before and after the abnormality, related device information, and operation objects, in order to construct a complete chain of abnormal events and assist analysts in understanding the full picture of the abnormality.
[0160] In some specific implementations, the user behavior anomaly detection method based on multi-feature learning also includes: When the anomaly detection score exceeds a preset threshold, an anomaly alarm is triggered based on the target user's anomaly profile report.
[0161] Specifically, one or more preset thresholds are set for anomaly detection scores obtained based on experience or learning. When the anomaly score of a user behavior data point or a certain aggregated behavior exceeds the preset threshold, the system immediately determines that the behavior is abnormal. At the same time, the system will trigger an alarm mechanism to send an alarm notification to security operations personnel or relevant management personnel. The alarm information will integrate user anomaly behavior profiles and risk assessment results from the object characterization module, providing anomaly type, confidence level, correlation characteristics, risk level, and specific characterization details of the anomaly behavior, assisting analysts in quickly understanding the nature of the anomaly, conducting root cause analysis, and making subsequent decision-making.
[0162] This embodiment also provides a user behavior anomaly detection device based on multi-feature learning. This device is used to implement the above embodiments and preferred embodiments, and details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0163] This embodiment provides a user behavior anomaly detection device based on multi-feature learning, such as... Figure 4 As shown, it includes: Log data acquisition module 401 is used to acquire various types of log data; The log feature determination module 402 is used to determine multiple statistical features, multiple time series features, multiple semantic features and multiple deep learning features based on the multiple log data. The log feature fusion module 403 is used to fuse multiple statistical features, multiple temporal features, multiple semantic features and multiple deep learning features to obtain the target fusion feature; An abnormal behavior detection module 404 is used to input the target fusion features into an abnormal behavior detection model for detection and obtain an abnormal detection score, wherein the abnormal behavior detection model is a pre-trained neural network model.
[0164] In some optional embodiments, the user behavior anomaly detection device based on multi-feature learning of the present invention further includes: The abnormal behavior acquisition module is used to acquire the target abnormal behavior of the target user within a preset time period based on the abnormal detection score. The abnormal feature extraction module is used to extract the abnormal behavior features corresponding to the target abnormal behavior; The abnormal information classification module is used to input abnormal behavior features into the abnormal behavior classification model for classification, and obtain the classification result of the target abnormal behavior; The risk assessment determination module is used to determine the abnormal behavior risk assessment parameters corresponding to the abnormal behavior of the target based on the classification results of the abnormal behavior of the target. The risk level determination module is used to determine the target risk level corresponding to the target abnormal behavior based on the abnormal behavior risk assessment parameters.
[0165] In some optional embodiments, the user behavior anomaly detection device based on multi-feature learning of the present invention further includes: The profile information acquisition module is used to acquire the target profile information of the target user; The abnormal information acquisition module is used to acquire the target operation abnormal information corresponding to the target abnormal behavior. The target operation abnormal information includes: operation time abnormal information, operation equipment abnormal information, operation behavior abnormal information, and operation content abnormal information. The profile report generation module is used to generate an abnormal profile report of the target user based on the target profile information, target risk level, and target operation anomaly information. In some optional embodiments, the user behavior anomaly detection device based on multi-feature learning of the present invention further includes: The abnormal event chain generation module is used to determine the abnormal event chain of the target user based on the target user's abnormal profile report.
[0166] In some optional embodiments, the user behavior anomaly detection method based on multi-feature learning of the present invention further includes: The alarm information triggering module is used to trigger an anomaly alarm information when the anomaly detection score exceeds a preset threshold, combined with the target user's anomaly profile report.
[0167] In some optional implementations, the log data acquisition module 401 of the user behavior anomaly detection method based on multi-feature learning in this invention is specifically used for: Obtain raw log data from various sources, including: process audit data, service audit data, internet activity data, operation audit data, and login authentication data. Define log event types; Based on the log event type, raw log data of various log data types are classified; Perform data preprocessing on the categorized raw log data; User feature data is added to the preprocessed raw log data to obtain various types of log data.
[0168] The user behavior anomaly detection device based on multi-feature learning provided in this embodiment of the invention can execute the user behavior anomaly detection method based on multi-feature learning provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method. Further functional descriptions of the above modules and units are the same as in the corresponding embodiments described above, and will not be repeated here.
[0169] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.
[0170] The following is a detailed reference. Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.
[0171] The following is a detailed reference. Figure 5 This diagram illustrates a suitable structural schematic for implementing an electronic device according to embodiments of the present invention. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 501, which can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) 502 or a program loaded from memory 508 into random access random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device. The processor 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0172] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.
[0173] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a memory 508, or installed from a ROM 502. When the computer program is executed by the processor 501, it performs the functions defined in the user behavior anomaly detection method based on multi-feature learning according to embodiments of the present invention.
[0174] Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.
[0175] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0176] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0177] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A user behavior anomaly detection method based on multi-feature learning, characterized in that, The method includes: Obtain various types of log data; Based on the various log data, multiple statistical features, multiple temporal features, multiple semantic features, and multiple deep learning features are determined; By integrating the aforementioned statistical features, temporal features, semantic features, and deep learning features, the target fusion feature is obtained. The target fusion features are input into the abnormal behavior detection model to obtain an anomaly detection score, wherein the abnormal behavior detection model is a pre-trained neural network model.
2. The method according to claim 1, characterized in that, The method further includes: Based on the anomaly detection score, the target user's target abnormal behavior within a preset time period is obtained; Extract the abnormal behavior features corresponding to the target abnormal behavior; The abnormal behavior features are input into the abnormal behavior classification model for classification to obtain the classification result of the target abnormal behavior; Based on the classification results of the target abnormal behavior, determine the abnormal behavior risk assessment parameters corresponding to the target abnormal behavior; Based on the abnormal behavior risk assessment parameters, the target risk level corresponding to the target abnormal behavior is determined.
3. The method according to claim 2, characterized in that, The method further includes: Obtain the target profile information of the target user; Obtain the target operation anomaly information corresponding to the target abnormal behavior, wherein the target operation anomaly information includes: operation time anomaly information, operation equipment anomaly information, operation behavior anomaly information, and operation content anomaly information; Based on the target profile information, target risk level, and target operation anomaly information, an anomaly profile report of the target user is generated.
4. The method according to claim 3, characterized in that, The method further includes: Based on the abnormal profile report of the target user, the abnormal event chain of the target user is determined.
5. The method according to claim 3, characterized in that, The method further includes: When the anomaly detection score exceeds a preset threshold, an anomaly alarm is triggered in conjunction with the target user anomaly profile report.
6. The method according to claim 1, characterized in that, Obtaining the various log data includes: Obtain the raw log data of the various log data, including: process audit data, service audit data, internet access behavior data, operation audit data, and login authentication data; Define log event types; The raw log data of the various log data types are classified according to the log event type; Perform data preprocessing on the categorized raw log data; User feature data is added to the preprocessed raw log data to obtain the various types of log data.
7. A user behavior anomaly detection device based on multi-feature learning, characterized in that, The device includes: The log data acquisition module is used to acquire various types of log data; The log feature determination module is used to determine various statistical features, time-series features, semantic features, and deep learning features based on the various log data. The log feature fusion module is used to fuse multiple statistical features, multiple temporal features, multiple semantic features, and multiple deep learning features to obtain the target fused features; An abnormal behavior detection module is used to input the target fused features into an abnormal behavior detection model for detection and obtain an abnormality detection score, wherein the abnormal behavior detection model is a pre-trained neural network model.
8. An electronic device, characterized in that, include: The system includes a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the user behavior anomaly detection method based on multi-feature learning as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the user behavior anomaly detection method based on multi-feature learning as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, Includes computer instructions for causing a computer to execute the user behavior anomaly detection method based on multi-feature learning as described in any one of claims 1 to 6.