A user behavior supervision and guidance method based on double-mode mutual authentication

CN122195787BActive Publication Date: 2026-09-29CHINESE PEOPLES LIBERATION ARMY UNIT 91977
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511111263.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-08
Publication Date
2026-09-29
Estimated Expiration
2045-08-08

AI Technical Summary

Technical Problem

[0003]当前办公信息系统在系统安全方面主要依赖于对传统日志进行事后分析,无法及时识别异常操作达到预警目的,同时对异常行为进行终止后,缺乏引导其智能恢复的操作指引,导致用户操作路径中断

Benefits of technology

[0062]本发明提供了一种基于双模互鉴的用户行为监督及引导方法,实现了当前行为模式偏差分析与后续高风险操作的预测,同时通过蚁群算法和马尔科夫链的协同处理,解决了单一模型漏检与误报的问题,实现了用户行为监管从“事后追溯”到“事前干预”的转化,为办公系统安全性提升提供技术支撑。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122195787B_ABST
    Figure CN122195787B_ABST
Patent Text Reader

Abstract

The application discloses a user behavior supervision and guidance method based on double-mode mutual authentication, which comprises the following steps: obtaining a user historical behavior mode; based on the user historical behavior mode, using a user behavior chain construction and abnormality detection method based on an ant colony algorithm to monitor the abnormality of a current behavior chain in real time to obtain a first user behavior prediction result; using a behavior risk prediction method based on a Markov chain to process the state transition law of the user historical behavior mode to obtain a second user behavior prediction result; performing consistency judgment on the first user behavior prediction result and the second user behavior prediction result to obtain a consistency judgment result; when the consistency judgment result is no, performing secondary detection to obtain a third user behavior prediction result; using a preset user behavior knowledge graph to perform behavior reasoning on the first user behavior prediction result or the third user behavior prediction result to realize supervision and guidance on the system user behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security management technology for office automation systems, and in particular to a method for monitoring and guiding user behavior based on dual-mode mutual learning. Background Technology

[0002] In the use of office and other information systems, user behavior is a significant factor affecting system security. Anomaly detection mechanisms for user behavior in office systems can effectively identify abnormal operations and improve system security. A key step in such mechanisms is establishing user behavior chains, generating user behavior graphs, matching current operation steps, and using graph reasoning techniques to identify and guide user actions.

[0003] Current office information systems primarily rely on post-event analysis of traditional logs for system security, which fails to promptly identify abnormal operations for early warning. Furthermore, after terminating abnormal behavior, there is a lack of guidance for intelligent recovery, leading to interruptions in the user's operational path. Therefore, identifying user behavior chains and constructing user behavior graphs to achieve the supervision, prediction, and guidance of user behavior has become an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0004] The technical problem this invention aims to solve is to provide a user behavior supervision and guidance method based on dual-mode mutual learning. "Dual-mode mutual learning" refers to first using an ant colony algorithm model for abnormal behavior identification to achieve abnormal behavior chain detection, and then using a Markov prediction model for future risk prediction. By combining ant colony abnormal behavior identification and Markov prediction to achieve complementary modeling and cross-validation, this method jointly addresses the problems of "missed detection" and "false alarms" in user behavior supervision in office systems. When a user's operation is found to have potential risks, behavioral reasoning is performed based on the user behavior knowledge graph to generate a guidance strategy, thereby intervening and guiding the user's operation.

[0005] To address the aforementioned technical problems, this invention discloses a user behavior monitoring and guidance method based on dual-mode mutual authentication, the method comprising:

[0006] S1, obtain the user's historical behavior patterns;

[0007] S2, Based on the user's historical behavior pattern, the user behavior chain construction and anomaly detection method based on ant colony algorithm is used to monitor the anomaly of the current behavior chain in real time and obtain the first user behavior prediction result.

[0008] S3, using a Markov chain-based behavioral risk prediction method, the state transition patterns of the user's historical behavior patterns are processed to obtain a second user behavior prediction result.

[0009] S4, perform a consistency judgment on the first user behavior prediction result and the second user behavior prediction result to obtain a consistency judgment result;

[0010] S5, when the consistency judgment result is yes, execute S6; when the consistency judgment result is no, perform a second detection to obtain a third user behavior prediction result, and execute S6.

[0011] S6. Using a preset user behavior knowledge graph, perform behavioral reasoning on the first user behavior prediction result or the third user behavior prediction result to achieve supervision and guidance of system user behavior.

[0012] As an optional implementation, in this embodiment of the invention, the step of using an ant colony algorithm-based user behavior chain construction and anomaly detection method to monitor the anomalies of the current behavior chain in real time based on the user's historical behavior pattern and obtain a first user behavior prediction result includes:

[0013] S21, Based on the user's historical behavior pattern, each operation is abstracted into different behavior nodes according to the user's operation method;

[0014] S22, generate a behavior path from the user's operation sequence;

[0015] S23, by simulating the pheromone mechanism of ant colony foraging, dynamically updates the pheromone concentration of behavioral paths;

[0016] S24. Using the user behavior chain construction and anomaly detection method based on ant colony algorithm, the anomaly of the current behavior chain is monitored in real time to obtain the first user behavior prediction result.

[0017] As an optional implementation, in this embodiment of the invention, the method for constructing and detecting user behavior chains based on ant colony algorithms, which monitors the anomalies of the current behavior chain in real time to obtain a first user behavior prediction result, includes:

[0018] S241, Initialize pheromone concentration, set the initial pheromone concentration to τ0(i,j) for each path (i→j) between behavior node i and subsequent node j, and determine the initial default value of the historical baseline;

[0019] S242, when the user executes the path (i→j), the pheromone is dynamically adjusted according to the timestamp t of the operation, the operation type and the environmental attributes to obtain the pheromone concentration τ(t+1)(i,j);

[0020] S243, when the growth rate of pheromone concentration τ(t+1)(i,j) of path (i→j) exceeds a preset threshold per unit time, a first user behavior prediction result is obtained; the first user behavior prediction result is that path (i→j) is an abnormal behavior chain.

[0021] As an optional implementation, in this embodiment of the invention, the expression for the pheromone concentration τ(t+1)(i,j) is:

[0022] τ(t+1)(i,j)=(1-ρ)·(i,j)+Δτ(i,j)

[0023] Δτ(i,j)=Q / [1+|t-tb|]·wr·we

[0024] Where: ρ is the pheromone decay factor, 0<ρ<1, mainly used to control the forgetting rate of historical behavior; Q is the pheromone intensity constant, which is positively correlated with the operation risk level. The higher the risk, the larger the Q value, and vice versa; |t-tb| is the deviation between the current time and the average execution time of the operation, i.e., the baseline time; wr is the operation risk weight, and we is the environmental risk weight.

[0025] As an optional implementation, in this embodiment of the invention, the step of processing the state transition patterns of the user's historical behavior patterns using a Markov chain-based behavioral risk prediction method to obtain a second user behavior prediction result includes:

[0026] S31, Process the user's historical behavior pattern to obtain a finite state set; the expression of the finite state set is:

[0027] S = {s1, s2, ..., s} n}

[0028] Where s1 = file query, s2 = data download, s3 = permission modification, and s4 = external operation;

[0029] S32, Based on the user's historical behavior data, the finite set of states is processed to obtain the state transition matrix P;

[0030] S33, Perform dynamic risk prediction on the state transition matrix P to obtain the second user behavior prediction result.

[0031] As an optional implementation, in this embodiment of the invention, the state transition matrix P is expressed as:

[0032]

[0033] The state transition probability P(s_t+1|s_t) is calculated through maximum likelihood estimation and optimized by combining it with the time decay factor.

[0034] As an optional implementation, in this embodiment of the invention, the step of performing dynamic risk prediction on the state transition matrix P to obtain a second user behavior prediction result includes:

[0035] Based on the current behavior sequence s_t={s1,s 2, …,s_t}, process the state transition matrix P to obtain the second user behavior prediction result;

[0036] The expression for the second user behavior prediction result is:

[0037] P(S_t+k∈High-risk set)=max{P(s_{t+1}|s_t),

[0038] P(s {t+2} |s t ,s {t+1} 0,…,

[0039] P(s_{t+k}|s_t,…,

[0040] s_{t+k-1})}

[0041] Where P(S_t+k∈high-risk set) is the second user behavior prediction result, and max represents finding the maximum value.

[0042] As an optional implementation, in this embodiment of the invention, the consistency judgment result includes:

[0043] If the ant colony algorithm detects abnormal behavior and the Markov chain predicts it as low risk, or if the Markov chain predicts it as high risk and the ant colony algorithm detects it as normal behavior, or if the score of the ant colony algorithm detecting abnormal behavior is close to a preset threshold and the probability of the Markov chain predicting it as high risk is close to a preset threshold.

[0044] As an optional implementation, in this embodiment of the invention, the secondary detection includes:

[0045] S51, Collect user behavior dataset, which includes operation object data, user permission data and environment data;

[0046] S52, Process the user behavior dataset to obtain an evaluation index system;

[0047] S53, Process the aforementioned evaluation index system to obtain a comprehensive risk assessment result;

[0048] S54, using the comprehensive risk assessment results, update the ant colony algorithm information weights to obtain updated information weights;

[0049] S55, based on the updated information weight, update the ant colony algorithm pheromone concentration information, optimize the ant colony algorithm parameters, and obtain the optimized ant colony algorithm;

[0050] S56, using the optimized ant colony algorithm, the user's historical behavior pattern is processed to obtain the third user behavior prediction result.

[0051] As an optional implementation, in this embodiment of the invention, the step of using a preset user behavior knowledge graph to perform behavioral reasoning on the first user behavior prediction result or the third user behavior prediction result to achieve supervision and guidance of system user behavior includes:

[0052] S61, Construct a user behavior knowledge graph; the expression of the user behavior knowledge graph is:

[0053] G = (U, O, R, C)

[0054] in:

[0055] U: User node, including job title and permission level attribute information;

[0056] O: The node to be operated on, including file type and sensitivity level attribute information;

[0057] R: Operation relationship, including access, download, and modification operation steps;

[0058] C: Context node, including time, terminal location, and network type attribute information;

[0059] S62, when abnormal behavior is detected or high-risk operation is predicted, link matching is performed on the user behavior knowledge graph to obtain the historical behavior chain;

[0060] S63, perform operation reasoning matching on the historical behavior chain to generate personalized guidance suggestions, thereby realizing the supervision and guidance of system user behavior.

[0061] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0062] This invention provides a user behavior supervision and guidance method based on dual-mode mutual learning, which realizes the analysis of current behavior pattern deviation and the prediction of subsequent high-risk operations. At the same time, through the collaborative processing of ant colony algorithm and Markov chain, it solves the problems of missed detection and false alarm of single model, realizes the transformation of user behavior supervision from "post-event traceability" to "pre-event intervention", and provides technical support for improving the security of office systems. Attached Figure Description

[0063] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0064] Figure 1 This is a flowchart illustrating a user behavior monitoring and guidance method based on dual-mode mutual authentication disclosed in an embodiment of the present invention.

[0065] Figure 2 This is an overall technical framework diagram disclosed in the embodiments of the present invention;

[0066] Figure 3 This is a schematic diagram of the risk assessment algorithm mechanism based on dual-mode mutual authentication disclosed in an embodiment of the present invention. Detailed Implementation

[0067] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0068] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.

[0069] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0070] This invention discloses a user behavior supervision and guidance method based on dual-mode mutual learning. The method includes: acquiring user historical behavior patterns; based on these patterns, using an ant colony algorithm-based user behavior chain construction and anomaly detection method, real-time monitoring of the anomalies in the current behavior chain to obtain a first user behavior prediction result; using a Markov chain-based behavior risk prediction method to process the state transition patterns of the user historical behavior patterns to obtain a second user behavior prediction result; performing a consistency judgment on the first and second user behavior prediction results to obtain a consistency judgment result; if the consistency judgment result is negative, performing a second detection to obtain a third user behavior prediction result; and using a pre-set user behavior knowledge graph to perform behavioral reasoning on either the first or third user behavior prediction result, thereby achieving supervision and guidance of user behavior in the system. These are described in detail below.

[0071] User behavior refers to user actions and is a significant factor affecting system security. Anomaly detection mechanisms for user behavior in office systems can effectively identify abnormal operations and improve information system security. User behavior in office systems encompasses a series of operations and interactions performed by users when using various office software, platforms, or tools, covering core workflows and functional usage scenarios in daily office work.

[0072] Example 1

[0073] Please see Figure 1 , Figure 1 This is a flowchart illustrating a user behavior monitoring and guidance method based on dual-mode mutual authentication disclosed in an embodiment of the present invention. Figure 1 The described user behavior supervision and guidance method based on dual-mode mutual authentication is applied in the field of office automation system security management technology, and is applicable to office and business information systems. This invention does not limit the scope of the embodiments. Figure 1 As shown, the user behavior supervision and guidance method based on dual-mode mutual authentication can include the following operations:

[0074] S1, obtain the user's historical behavior patterns;

[0075] S2, Based on the user's historical behavior pattern, the user behavior chain construction and anomaly detection method based on ant colony algorithm is used to monitor the anomaly of the current behavior chain in real time and obtain the first user behavior prediction result.

[0076] The first user behavior prediction result is the anomaly of the current behavior chain, including abnormal behavior and normal behavior.

[0077] S3, using a Markov chain-based behavioral risk prediction method, the state transition patterns of the user's historical behavior patterns are processed to obtain a second user behavior prediction result.

[0078] The second user behavior prediction result is the high-risk actions that users may take in the future, including both high-risk and low-risk actions;

[0079] S4, perform a consistency judgment on the first user behavior prediction result and the second user behavior prediction result to obtain a consistency judgment result;

[0080] S5, when the consistency judgment result is yes, execute S6; when the consistency judgment result is no, perform a second detection to obtain a third user behavior prediction result, and execute S6.

[0081] S6. Using a preset user behavior knowledge graph, perform behavioral reasoning on the first user behavior prediction result or the third user behavior prediction result to achieve supervision and guidance of system user behavior.

[0082] Optionally, the step of using the user's historical behavior pattern and an anomaly detection method based on ant colony algorithm to monitor the anomaly of the current behavior chain in real time and obtain the first user behavior prediction result includes:

[0083] S21, based on the user's historical behavior pattern, each operation is abstracted into different behavior nodes according to the user's operation method; such as file access, data download, permission request;

[0084] S22, generate a behavior path from the user's operation sequence;

[0085] S23, by simulating the pheromone mechanism of ant colony foraging, dynamically updates the pheromone concentration of behavioral paths;

[0086] S24. Using the user behavior chain construction and anomaly detection method based on ant colony algorithm, the anomaly of the current behavior chain is monitored in real time to obtain the first user behavior prediction result.

[0087] Optionally, the method for constructing and detecting user behavior chains based on ant colony algorithms, which monitors the anomalies of the current behavior chain in real time to obtain a first user behavior prediction result, includes:

[0088] S241, Initialize pheromone concentration, set the initial pheromone concentration to τ0(i,j) for each path (i→j) between behavior node i and subsequent node j, and determine the initial default value of the historical baseline;

[0089] S242, when the user executes the path (i→j), the pheromone is dynamically adjusted according to the timestamp t of the operation, the operation type and the environmental attributes to obtain the pheromone concentration τ(t+1)(i,j);

[0090] S243, when the growth rate of the pheromone concentration τ(t+1)(i,j) of the path (i→j) exceeds a preset threshold per unit time, a first user behavior prediction result is obtained; the first user behavior prediction result indicates that the path (i→j) is an abnormal behavior chain. For example, if the threshold is set to 0.8, i.e. Δτ / Δt>0.8, then the first user behavior prediction result is determined to be an abnormal behavior chain, triggering an early warning.

[0091] If the ant colony algorithm has marked a behavioral chain as anomalous, the Markov chain will prioritize high-risk operations that follow that path during prediction, rather than calculating the probability of all possible transitions. The anomalous behavioral chains detected by the ant colony algorithm can serve as key input features for the Markov chain, constraining the prediction range of subsequent state transition matrices.

[0092] Optionally, the expression for the pheromone concentration τ(t+1)(i,j) is:

[0093] τ(t+1)(i,j)=(1-ρ)·(i,j)+Δτ(i,j)

[0094] Δτ(i,j)=Q / [1+|t-tb|]·wr·we

[0095] Where: ρ is the pheromone decay factor, 0<ρ<1, mainly used to control the forgetting rate of historical behavior; Q is the pheromone intensity constant, which is positively correlated with the operation risk level. The higher the risk, the larger the Q value, and vice versa; |t-tb| is the deviation between the current time and the average execution time of the operation, i.e., the baseline time; wr is the operation risk weight, and we is the environmental risk weight.

[0096] Optionally, the step of using a Markov chain-based behavioral risk prediction method to process the state transition patterns of the user's historical behavior to obtain a second user behavior prediction result includes:

[0097] S31, Process the user's historical behavior pattern to obtain a finite state set; the expression of the finite state set is:

[0098] S = {s1, s2, ..., s} n}

[0099] Where s1 = file query, s2 = data download, s3 = permission modification, and s4 = external operation;

[0100] S32, Based on the user's historical behavior data, the finite set of states is processed to obtain the state transition matrix P;

[0101] S33, Perform dynamic risk prediction on the state transition matrix P to obtain the second user behavior prediction result.

[0102] Optionally, the state transition matrix P is expressed as:

[0103]

[0104] The state transition probability P(s_t+1|s_t) is calculated through maximum likelihood estimation and optimized by combining it with the time decay factor.

[0105] Optionally, the step of performing dynamic risk prediction on the state transition matrix P to obtain the second user behavior prediction result includes:

[0106] Based on the current behavior sequence s_t=Ps1,s 2, …,s_t}, process the state transition matrix P to obtain the second user behavior prediction result;

[0107] The expression for the second user behavior prediction result is:

[0108] P(S_t+k∈High-risk set)=max{P(s_{t+1}|s_t),

[0109] P(s Pt+2} |s t ,s {t+1} ),…,

[0110] P(s_{t+k}|s_t,…,

[0111] s_{t+k-1})}

[0112] Where P(S_t+k∈high-risk set) is the second user behavior prediction result, and max represents finding the maximum value.

[0113] When the prediction probability of the Markov chain exceeds a threshold, active intervention is triggered.

[0114] The Markov chain prediction model can provide confidence verification for ant colony anomaly detection results. When the ant colony algorithm is marked as abnormal behavior due to short-term noise, if the Markov chain predicts that there will be no high-risk operation in the next 3 steps, the system can determine that the anomaly is a "false alarm" and lower the interception threshold. When the ant colony algorithm does not mark the abnormal behavior chain, but the Markov chain predicts that the next step is a high-risk operation, the system can trigger a secondary detection to avoid missing new anomalies.

[0115] Optionally, the consistency judgment result includes:

[0116] If the ant colony algorithm detects abnormal behavior and the Markov chain predicts it as low risk, or if the Markov chain predicts it as high risk and the ant colony algorithm detects it as normal behavior, or if the score of the ant colony algorithm detecting abnormal behavior is close to a preset threshold and the probability of the Markov chain predicting it as high risk is close to a preset threshold.

[0117] Optionally, the secondary detection includes:

[0118] S51, Collect user behavior dataset, which includes operation object data, user permission data and environment data;

[0119] S52, Process the user behavior dataset to obtain an evaluation index system;

[0120] S53, Process the aforementioned evaluation index system to obtain a comprehensive risk assessment result;

[0121] S54, using the comprehensive risk assessment results, update the ant colony algorithm information weights to obtain updated information weights;

[0122] S55, based on the updated information weight, update the ant colony algorithm pheromone concentration information, optimize the ant colony algorithm parameters, and obtain the optimized ant colony algorithm;

[0123] S56, using the optimized ant colony algorithm, the user's historical behavior pattern is processed to obtain the third user behavior prediction result.

[0124] Optionally, the step of using a preset user behavior knowledge graph to perform behavioral reasoning on the first user behavior prediction result or the third user behavior prediction result to achieve supervision and guidance of system user behavior includes:

[0125] S61, Construct a user behavior knowledge graph; the expression of the user behavior knowledge graph is:

[0126] G = (U, O, R, C)

[0127] in:

[0128] U: User node, including job title and permission level attribute information;

[0129] O: The node to be operated on, including file type and sensitivity level attribute information;

[0130] R: Operation relationship, including access, download, and modification operation steps;

[0131] C: Context node, including time, terminal location, and network type attribute information;

[0132] S62, when abnormal behavior is detected or high-risk operation is predicted, link matching is performed on the user behavior knowledge graph to obtain the historical behavior chain;

[0133] S63, perform operation reasoning matching on the historical behavior chain to generate personalized guidance suggestions, thereby realizing the supervision and guidance of system user behavior.

[0134] As can be seen, this invention provides a user behavior supervision and guidance method based on dual-mode mutual learning, which realizes the analysis of current behavior pattern deviations and the prediction of subsequent high-risk operations. At the same time, through the collaborative processing of ant colony algorithm and Markov chain, it solves the problems of missed detection and false alarms of single model, realizes the transformation of user behavior supervision from "post-event traceability" to "pre-event intervention", and provides technical support for improving the security of office systems.

[0135] Example 2

[0136] This embodiment of a user behavior supervision and guidance method based on dual-mode mutual learning includes: a user behavior chain construction and anomaly detection method based on ant colony algorithm to monitor behavior chain anomalies in real time; a behavior risk prediction method based on Markov chain to predict potential risky operations in the future; secondary detection to confirm the authenticity of abnormal behavior; and user behavior knowledge graph reasoning to generate operation guidance strategies, thereby realizing the supervision and guidance of system user behavior. The technical solution provided by this invention realizes the analysis of current behavior pattern deviations and the prediction of subsequent high-risk operations. Simultaneously, through the collaborative processing of ant colony algorithm and Markov chain, it solves the problems of missed detections and false alarms with a single model, realizing the transformation of user behavior supervision from "post-event traceability" to "pre-event intervention," and providing technical support for improving the security of office systems.

[0137] The main application of ant colony optimization (ACO) in user behavior monitoring is to monitor the anomalies of the current behavior chain in real time based on users' historical behavior patterns. Specifically, this includes:

[0138] Based on the user's operation methods, each step is abstracted into different behavioral nodes, such as file access, data download, and permission request. The user's operation sequence is generated into a behavioral path. By simulating the pheromone mechanism of ant colony foraging, the "pheromone concentration" of the behavioral path is dynamically updated to obtain the user's long-term / short-term behavioral patterns.

[0139] Initialize pheromone concentration. Set the initial pheromone concentration to τ0(i,j) for each behavior node (i) and its subsequent node (j) path (i→j), and determine the initial default value of the historical baseline.

[0140] Update pheromone rule settings. When a user executes the path (i→j), dynamically adjust pheromones based on the operation's timestamp (t), operation type, and environmental attributes:

[0141] τ(t+1)(i,j)=(1-ρ)·(i,j)+Δτ(i,j)

[0142] Δτ{i,j)=Q / [1+|t-tb|]·wr·we

[0143] in:

[0144] ρ is the pheromone decay factor, 0 < ρ < 1, which is mainly used to control the rate of forgetting historical behavior;

[0145] Q is the pheromone intensity constant, which is positively correlated with the operational risk level. The greater the risk, the larger the Q value, and vice versa.

[0146] |t-tb| represents the degree of deviation between the current time and the average execution time of this operation, i.e., the baseline time;

[0147] wr is the operational risk weight, for example, high risk is wr=2, medium risk is wr=1, and low risk is wr=0.5;

[0148] 'we' represents the environmental risk weight, for example, we = 1.5 for non-working hours, we = 1 for online access during working hours, and we = 2 for external network access.

[0149] Identifying abnormal paths: When the pheromone concentration of a certain path (i→j) increases at a rate exceeding a threshold per unit time, for example, if the threshold is 0.8, then Δτ / Δt>0.8, it is identified as an abnormal behavior chain and an alert is triggered.

[0150] If the ant colony algorithm has marked a behavioral chain as anomalous, the Markov chain will prioritize high-risk operations that follow that path during prediction, rather than calculating the probability of all possible transitions. The anomalous behavioral chains detected by the ant colony algorithm can serve as key input features for the Markov chain, constraining the prediction range of subsequent state transition matrices.

[0151] Ant colony optimization excels at detecting chains of abnormal behavior that have already occurred, but it cannot directly predict whether such a chain will evolve into a higher-risk operation. Markov chains, on the other hand, can construct a state transition matrix based on a user's historical behavior chains, calculate the probability of entering a high-risk state in the future, and provide a basis for predicting potential high-risk operations by the user, thus achieving early risk warning. Specifically, this includes the following steps:

[0152] Define user states. Divide user behavior into a finite set of states S = {s1, s2, ..., s...} n} Specific operations include s1 = file query, s2 = data download, s3 = permission modification, and S4 = external operation.

[0153] Construct the transition matrix. Based on the statistical state transition probability P(s_t+1|s_t) from historical behavioral data, form an n×n state transition matrix P:

[0154]

[0155] P(s_t+1|s_t) is calculated through maximum likelihood estimation and optimized by combining the time decay factor.

[0156] Dynamic risk prediction. Given the current behavior sequence s_t={s1,s... 2, …,s_t}, calculate the probability of entering a high-risk state, such as “s4 = external operation”, within the next k steps:

[0157] P(S_t+k∈High-risk set)=max{P(s_{t+1}|s_t),

[0158] P(s {t+2} |s t ,s {t+1} ),…,

[0159] P(s_{t+k}|s_t,…,

[0160] s_{t+k-1})}

[0161] Set a threshold to trigger active intervention.

[0162] The Markov chain prediction model can provide confidence verification for ant colony anomaly detection results. When the ant colony algorithm is marked as abnormal behavior due to short-term noise, if the Markov chain predicts that there will be no high-risk operation in the next 3 steps, the system can determine that the anomaly is a "false alarm" and lower the interception threshold. When the ant colony algorithm does not mark the abnormal behavior chain, but the Markov chain predicts that the next step is a high-risk operation, the system can trigger a secondary detection to avoid missing new anomalies.

[0163] This application provides a secondary detection mechanism for high-risk behaviors. When the identified abnormal behavior of the ant colony conflicts with or approaches a threshold value, the system triggers a "deep verification mechanism" to avoid false alarms or missed detections. Through cross-verification of multi-dimensional information, the authenticity of the abnormal behavior or the necessity of the high-risk operation is confirmed, ultimately outputting a more accurate decision.

[0164] The conditions for triggering secondary detection are as follows, based on the "uncertainty" or "conflict" of the dual-model results:

[0165] ① If the ant colony algorithm detects abnormal behavior, but the Markov prediction result is low risk, a secondary detection is triggered.

[0166] ② When the Markov prediction result is high risk, but the ant colony algorithm detects it as normal behavior, a secondary detection is triggered.

[0167] ③ When the score of the abnormal behavior detected by the ant colony algorithm is close to the set threshold, and the Markov prediction probability is close to the threshold, a secondary detection is triggered.

[0168] Behavioral data collection and analysis. This mainly involves collecting data on the objects being operated on, user permissions, and environmental data, including data sensitivity levels, relevant historical risk events, user roles, permission levels, historical compliance records, device status, network status, and other information.

[0169] Assess the risk level of the behavior. Construct an assessment indicator system, determine the assessment dimensions and risk conditions, and assign scores to different dimensions based on their actual weight.

[0170] A comprehensive risk assessment is obtained by summing the risk scores from each dimension.

[0171] Update the ant colony algorithm information weights. When the ant colony algorithm detects a non-abnormal behavior, but the Markov chain predicts it as a high-risk behavior, and after a second detection, the behavior is ultimately determined to be high-risk, then the ant colony algorithm pheromone concentration information is updated, and the ant colony algorithm parameters are optimized.

[0172] Secondary detection quantifies the actual risk of abnormal behavior by using key information such as the sensitivity of the target object, the matching degree of user permissions, and the credibility of the environment, providing a basis for subsequent decision-making and providing important support for improving system security and intelligence.

[0173] Fourthly, this application provides a knowledge graph-based method for generating behavior guidance strategies, mainly used to construct a user behavior knowledge graph, integrate user attribute information, operation object type, environmental context, and historical guidance cases, and generate an operation guidance path that meets user needs:

[0174] Knowledge graph structure definition. A knowledge graph is defined as a quadruple structure G = (U, O, R, C), where:

[0175] U: User node, which includes attribute information such as job title and permission level;

[0176] O: The operation object node, which contains attribute information such as file type and sensitivity level;

[0177] R: Operation relationship, including operation steps such as access, download, and modification;

[0178] C: Context node, containing attribute information such as time, terminal location, and network type.

[0179] Generate guidance strategies. When abnormal behavior is detected or high-risk operations are predicted, personalized guidance suggestions are generated by matching historical successful guidance cases through knowledge graph reasoning. Taking "frequent querying of sensitive data" as a specific example, the specific steps are as follows:

[0180] If a user is alerted for "frequently querying sensitive data", and the knowledge graph finds that similar users often complete the operation by "applying for temporary access permission", then it will push a closed-loop approval example of "click here to submit temporary access permission application";

[0181] If it is predicted that a user may attempt to "send confidential files", then a message will be displayed: "The file you are currently working on is classified as confidential. Sending it requires approval. Do you need assistance in initiating the approval process?" and a shortcut to the corresponding application will be provided.

[0182] Example 3

[0183] This embodiment presents a user behavior monitoring and guidance method based on dual-mode mutual authentication. Figure 2 This is an overall technical framework diagram disclosed in the embodiments of the present invention; Figure 3 This is a schematic diagram of the risk assessment algorithm mechanism based on dual-mode mutual authentication disclosed in an embodiment of the present invention.

[0184] A user behavior chain construction and anomaly detection method based on ant colony algorithm is adopted, which monitors the anomalies of the current behavior chain in real time based on the user's historical behavior patterns.

[0185] Then, based on the Markov chain-based behavioral risk prediction method, the state transition patterns of historical behaviors are analyzed to predict high-risk operations that users may perform in the future.

[0186] Next, it is determined whether the ant colony algorithm and the Markov prediction results are consistent. If they are inconsistent, a second detection is performed.

[0187] By conducting secondary testing to achieve cross-validation of multi-dimensional information, the authenticity of abnormal behavior can be confirmed, providing a more accurate basis for judging high-risk operations.

[0188] Finally, a user behavior knowledge graph is used to complete behavioral reasoning, generate operation guidance strategies, and realize the supervision and guidance of user behavior in the system.

[0189] Example 4

[0190] A method for constructing user behavior chains and detecting anomalies based on the ant colony algorithm. The main application of the ant colony algorithm in user behavior monitoring is to monitor the anomalies of the current behavior chain in real time based on users' historical behavior patterns. Specifically, it includes:

[0191] Based on the user's operation methods, each step is abstracted into different behavioral nodes, such as file access, data download, and permission request. The user's operation sequence is generated into a behavioral path. By simulating the pheromone mechanism of ant colony foraging, the "pheromone concentration" of the behavioral path is dynamically updated to obtain the user's long-term / short-term behavioral patterns.

[0192] Initialize pheromone concentration. Set the initial pheromone concentration to τ0(i,j) for each behavior node (i) and its subsequent node (j) path (i→j), and determine the initial default value of the historical baseline.

[0193] Update pheromone rule settings. When a user executes the path (i→j), dynamically adjust pheromones based on the operation's timestamp (t), operation type, and environmental attributes:

[0194] τ(t+1)(i,j)=(1-ρ)·(i,j)+Δτ(i,j)

[0195] Δτ(i,j)=Q / [1+|t-tb|]·wr·we

[0196] in:

[0197] ρ is the pheromone decay factor, 0 < ρ < 1, which is mainly used to control the rate of forgetting historical behavior;

[0198] Q is the pheromone intensity constant, which is positively correlated with the operational risk level. The greater the risk, the larger the Q value, and vice versa.

[0199] |t-tb| represents the degree of deviation between the current time and the average execution time of this operation, i.e., the baseline time;

[0200] wr is the operational risk weight, for example, high risk is wr=2, medium risk is wr=1, and low risk is wr=0.5;

[0201] 'we' represents the environmental risk weight, for example, we = 1.5 for non-working hours, we = 1 for online access during working hours, and we = 2 for external network access.

[0202] Identifying abnormal paths: When the pheromone concentration of a certain path (i→j) increases at a rate exceeding a threshold per unit time, for example, if the threshold is 0.8, then Δτ / Δt>0.8, it is identified as an abnormal behavior chain and an alert is triggered.

[0203] If the ant colony algorithm has marked a behavioral chain as anomalous, the Markov chain will prioritize high-risk operations that follow that path during prediction, rather than calculating the probability of all possible transitions. The anomalous behavioral chains detected by the ant colony algorithm can serve as key input features for the Markov chain, constraining the prediction range of subsequent state transition matrices.

[0204] Example 5

[0205] A behavioral risk prediction method based on Markov chains is proposed. Ant colony optimization excels at detecting existing abnormal behavior chains, but it cannot directly predict whether the chain will evolve into a higher-risk operation. Markov chains can construct a state transition matrix based on a user's historical behavior chains, calculate the probability of entering a high-risk state in the future, and provide a basis for predicting potential high-risk operations by the user, thus achieving early risk warning. Specifically, the method includes the following steps:

[0206] Define user states. Divide user behavior into a finite set of states S = {s1, s2, ..., s...} n} Specific operations include s1 = file query, s2 = data download, s3 = permission modification, and s4 = external operation.

[0207] Construct the transition matrix. Based on the statistical state transition probability P(s_t+1|s_t) from historical behavioral data, form an n×n state transition matrix P:

[0208]

[0209] P(s_t+1|s_t) is calculated through maximum likelihood estimation and optimized by combining the time decay factor.

[0210] Dynamic risk prediction. Given the current behavior sequence s_t={s1,s... 2, …,s_t}, calculate the probability of entering a high-risk state, such as “s4 = external operation”, within the next k steps:

[0211] P(S_t+k∈High-risk set)=max{P(s_{t+1}|s_t),

[0212] P(s {t+2} |s t ,s {t+1} ),…,

[0213] P(s_{t+k}|s_t,…,

[0214] s_{t+k-1})}

[0215] Set a threshold to trigger active intervention.

[0216] The Markov chain prediction model can provide confidence verification for ant colony anomaly detection results. When the ant colony algorithm is marked as abnormal behavior due to short-term noise, if the Markov chain predicts that there will be no high-risk operation in the next 3 steps, the system can determine that the anomaly is a "false alarm" and lower the interception threshold. When the ant colony algorithm does not mark the abnormal behavior chain, but the Markov chain predicts that the next step is a high-risk operation, the system can trigger a secondary detection to avoid missing new anomalies.

[0217] Example 6

[0218] A high-risk behavior secondary detection mechanism is proposed. When the identified abnormal behavior of the ant colony conflicts with or approaches a threshold value, the system triggers a "deep verification mechanism" to avoid false alarms or missed detections. Through cross-verification of multi-dimensional information, the authenticity of the abnormal behavior or the necessity of the high-risk operation is confirmed, ultimately outputting a more accurate decision.

[0219] The conditions for triggering secondary detection are as follows, based on the "uncertainty" or "conflict" of the dual-model results:

[0220] ① If the ant colony algorithm detects abnormal behavior, but the Markov prediction result is low risk, a secondary detection is triggered.

[0221] ② When the Markov prediction result is high risk, but the ant colony algorithm detects it as normal behavior, a secondary detection is triggered.

[0222] ③ When the score of the abnormal behavior detected by the ant colony algorithm is close to the set threshold, and the Markov prediction probability is close to the threshold, a secondary detection is triggered.

[0223] Behavioral data collection and analysis. This mainly involves collecting data on the objects being operated on, user permissions, and environmental data, including data sensitivity levels, relevant historical risk events, user roles, permission levels, historical compliance records, device status, network status, and other information.

[0224] Assess the risk level of the behavior. Construct an assessment indicator system, determine the assessment dimensions and risk conditions, and assign scores to different dimensions based on their actual weight.

[0225] A comprehensive risk assessment is obtained by summing the risk scores from each dimension.

[0226] Update the ant colony algorithm information weights. When the ant colony algorithm detects a non-abnormal behavior, but the Markov chain predicts it as a high-risk behavior, and after a second detection, the behavior is ultimately determined to be high-risk, then the ant colony algorithm pheromone concentration information is updated, and the ant colony algorithm parameters are optimized.

[0227] Secondary detection quantifies the actual risk of abnormal behavior by using key information such as the sensitivity of the target object, the matching degree of user permissions, and the credibility of the environment, providing a basis for subsequent decision-making and providing important support for improving system security and intelligence.

[0228] Example 7

[0229] A knowledge graph-based method for generating behavior guidance strategies is mainly used to construct a user behavior knowledge graph, integrate user attribute information, operation object type, environmental context, and historical guidance cases, and generate operation guidance paths that meet user needs.

[0230] Knowledge graph structure definition. A knowledge graph is defined as a quadruple structure G = (U, O, R, C), where:

[0231] U: User node, which includes attribute information such as job title and permission level;

[0232] O: The operation object node, which contains attribute information such as file type and sensitivity level;

[0233] R: Operation relationship, including operation steps such as access, download, and modification;

[0234] C: Context node, containing attribute information such as time, terminal location, and network type.

[0235] Generate guidance strategies. When abnormal behavior is detected or high-risk operations are predicted, personalized guidance suggestions are generated by matching historical successful guidance cases through knowledge graph reasoning. Taking "frequent querying of sensitive data" as a specific example, the specific steps are as follows:

[0236] If a user is alerted for "frequently querying sensitive data", and the knowledge graph finds that similar users often complete the operation by "applying for temporary access permission", then it will push a closed-loop approval example of "click here to submit temporary access permission application";

[0237] If it is predicted that a user may attempt to "send confidential files", then a message will be displayed: "The file you are currently working on is classified as confidential. Sending it requires approval. Do you need assistance in initiating the approval process?" and a shortcut to the corresponding application will be provided.

[0238] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0239] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.

[0240] Finally, it should be noted that the user behavior supervision and guidance method based on dual-mode mutual learning disclosed in the embodiments of the present invention is only a preferred embodiment of the present invention and is only used to illustrate the technical solution of the present invention, not to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A user behavior monitoring and guidance method based on dual-mode mutual learning, characterized in that, The method includes: S1, obtain the user's historical behavior patterns; S2, Based on the user's historical behavior pattern, the user behavior chain construction and anomaly detection method based on ant colony algorithm is used to monitor the anomaly of the current behavior chain in real time and obtain the first user behavior prediction result. S3, using a Markov chain-based behavioral risk prediction method, the state transition patterns of the user's historical behavior patterns are processed to obtain a second user behavior prediction result. S4, perform a consistency judgment on the first user behavior prediction result and the second user behavior prediction result to obtain a consistency judgment result; S5, when the consistency judgment result is yes, execute S6; when the consistency judgment result is no, perform a second detection to obtain a third user behavior prediction result, and execute S6. The secondary detection includes: S51, Collect user behavior dataset, which includes operation object data, user permission data and environment data; S52, Process the user behavior dataset to obtain an evaluation index system; S53, Process the aforementioned evaluation index system to obtain a comprehensive risk assessment result; S54, using the comprehensive risk assessment results, update the ant colony algorithm information weights to obtain updated information weights; S55, based on the updated information weight, update the ant colony algorithm pheromone concentration information, optimize the ant colony algorithm parameters, and obtain the optimized ant colony algorithm; S56, Using the optimized ant colony algorithm, the user's historical behavior pattern is processed to obtain a third user behavior prediction result; S6, when the consistency judgment result is yes, the system uses a preset user behavior knowledge graph to perform behavioral reasoning on the first user behavior prediction result; when the consistency judgment result is no, the system uses a preset user behavior knowledge graph to perform behavioral reasoning on the third user behavior prediction result, thereby achieving supervision and guidance of system user behavior, including: S61, Construct a user behavior knowledge graph; the expression of the user behavior knowledge graph is: in: User nodes include job title and permission level attribute information; The node to be operated on includes file type and sensitivity level attribute information; Operational relationships, including access, download, and modification steps; Context node, including time, terminal location, and network type attribute information; S62, when abnormal behavior is detected or high-risk operation is predicted, link matching is performed on the user behavior knowledge graph to obtain the historical behavior chain; S63, perform operation reasoning matching on the historical behavior chain to generate personalized guidance suggestions, thereby realizing the supervision and guidance of system user behavior.

2. The user behavior monitoring and guidance method based on dual-mode mutual authentication according to claim 1, characterized in that, The method for constructing and detecting user behavior chains based on ant colony algorithms, using the user's historical behavior patterns, monitors the anomalies of the current behavior chain in real time to obtain a first user behavior prediction result, including: S21, Based on the user's historical behavior pattern, each operation is abstracted into different behavior nodes according to the user's operation method; S22, generate a behavior path from the user's operation sequence; S23, by simulating the pheromone mechanism of ant colony foraging, dynamically updates the pheromone concentration of behavioral paths; S24. Using the user behavior chain construction and anomaly detection method based on ant colony algorithm, the anomaly of the current behavior chain is monitored in real time to obtain the first user behavior prediction result.

3. The user behavior supervision and guidance method based on dual-mode mutual authentication according to claim 2, characterized in that, The method for constructing and detecting user behavior chains based on ant colony algorithms monitors the anomalies of the current behavior chain in real time to obtain a first user behavior prediction result, including: S241, Initialize pheromone concentration for each behavior node. With subsequent nodes path Set the initial pheromone concentration to Determine the initial default value for the historical baseline; S242, when the user executes the path At that time, based on the timestamp of the operation Based on the operation type and environmental attributes, pheromones are dynamically adjusted to obtain pheromone concentration. ; S243, when the path pheromone concentration When the growth rate per unit time exceeds a preset threshold, a first user behavior prediction result is obtained; the first user behavior prediction result is a path. This is a chain of abnormal behavior.

4. The user behavior monitoring and guidance method based on dual-mode mutual authentication according to claim 3, characterized in that, The pheromone concentration The expression is: in: For pheromone decay factor, It is mainly used to control the rate at which historical behavior is forgotten; This is the pheromone intensity constant, which is positively correlated with the operational risk level; the greater the risk, the higher the pheromone intensity. The larger the value, the smaller it is; This represents the degree of deviation between the current time and the average execution time of the operation, i.e., the baseline time. To operate risk weights, Environmental risk weights.

5. The user behavior monitoring and guidance method based on dual-mode mutual authentication according to claim 3, characterized in that, The method of using Markov chain-based behavioral risk prediction to process the state transition patterns of the user's historical behavior to obtain a second user behavior prediction result includes: S31, Process the user's historical behavior pattern to obtain a finite state set; the expression of the finite state set is: in, =File search, Data download, Permission modification, =Outsourced operation; S32, Based on the user's historical behavior data, the finite set of states is processed to obtain the state transition matrix. ; S33, regarding the state transition matrix Dynamic risk prediction is performed to obtain the second user behavior prediction result.

6. The user behavior supervision and guidance method based on dual-mode mutual authentication according to claim 5, characterized in that, The state transition matrix The expression is: Among them, the state transition probability The result is calculated using maximum likelihood estimation and optimized by incorporating a time decay factor.

7. The user behavior supervision and guidance method based on dual-mode mutual authentication according to claim 5, characterized in that, The state transition matrix Dynamic risk prediction is performed to obtain the second user behavior prediction results, including: Based on the current behavior sequence , For the state transition matrix The process is performed to obtain the second user behavior prediction result; The expression for the second user behavior prediction result is: in, The second user behavior prediction result is given, and max represents finding the maximum value.

Citation Information

Patent Citations

  • Network security situation early warning method and system based on knowledge graph

    CN119603058A

  • Unmanned aerial vehicle group collaboration method based on combination of fuzzy ant colony algorithm and near-end strategy optimization

    CN119937592A