A network security risk behavior intention identification method based on controllable perturbation
By injecting low-intrusion, controllable perturbation signals into the terminal system, constructing a dynamic model, and extracting multi-dimensional dynamic features, the problem of existing technologies being unable to identify unknown risk behaviors and highly covert adversarial attacks is solved, achieving deep identification and protection of user behavior.
Patent Information
- Application Number
- CN202610714022.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-22
- Publication Date
- 2026-06-23
Smart Images

Figure CN122268678A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computer network security and terminal behavior analysis technology, specifically to a method for identifying network security risk behavior intent based on controllable perturbation. Background Technology
[0002] With the widespread adoption of terminal devices in government and enterprise offices, industrial control, and personal consumption scenarios, terminals have become a core entry point for cyberattacks. Threats targeting terminals, such as vulnerability injection, privilege theft, data leakage, and evasive violations, continue to evolve and escalate. Terminal security protection technology has become a core research direction in the field of cybersecurity. Currently, existing technologies for identifying terminal user behavior risks and malicious intent can be divided into four main technical systems: terminal threat detection technology based on signature and rule matching; abnormal behavior detection technology based on user behavior baselines; intelligent risk behavior identification technology based on system calls and application layer behavior; and security detection technology based on system dynamics and active probes. However, despite the fact that current mainstream technologies have built a basic system for endpoint security protection, with the rapid iteration of evasion-based malicious violation methods such as encrypted communication, code obfuscation, behavior masquerading, and adversarial sample attacks, existing technologies still have the following shortcomings when facing unknown risk behaviors and highly covert adversarial attacks in complex scenarios: 1. Since signature and rule matching technologies rely on fixed identifiers, it is difficult to obtain effective identifiers when applications are encrypted, obfuscated, or frequently updated, making it impossible to detect unknown risky behaviors; 2. Anomaly detection techniques based on user behavior baselines rely on observable sequences. Violators can disguise their behavior by injecting delays, randomizing rhythms, etc., thus rendering the detection model ineffective. 3. Although intelligent detection technology based on system calls and application layer behavior has extended the detection scope to system calls and process behavior at the kernel layer, it still lacks a comprehensive consideration of the multi-level response characteristics caused by operating system scheduling and resource allocation, and cannot accurately depict the differences in the impact of different behaviors within the system. 4. In cutting-edge technologies based on system dynamics and active probes, the core objective is to determine the system's own operational stability and critical state. They can only identify abnormal loads at the system level and do not involve semantic information that identifies behavioral intentions through external disturbances. Therefore, they are difficult to use directly to distinguish between normal and risky behavior.
[0003] In summary, it can be seen that existing technologies for identifying network security risks of end users have always remained in the technical paradigm of "passive observation and surface feature matching". They either rely on prior knowledge, are easily circumvented, or cannot characterize the essential driving differences of behavior. They cannot effectively deal with unknown risk behaviors and highly covert adversarial attacks in the current complex scenarios. A brand-new technical solution is urgently needed to solve the above technical pain points. Summary of the Invention
[0004] The purpose of this invention is to overcome the problem that existing technologies cannot effectively deal with unknown risk behaviors and highly covert adversarial attacks in current complex scenarios. It provides a method, device and storage medium for identifying network security risk behavior intentions based on controllable perturbations. The invention treats the terminal system as a controllable dynamic system and achieves accurate identification of user behavior risk intentions by actively injecting low-intrusion controllable perturbations, collecting system responses across layers, constructing dynamic models and extracting exclusive features.
[0005] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: This invention provides a method for identifying cybersecurity risk behaviors based on controllable perturbations, specifically including the following steps: S1. Actively inject controllable perturbation signals into the resource layer of the terminal system, wherein the amplitude of the controllable perturbation signals satisfies the user-insensible threshold constraint and the controllable perturbation signal components of each resource layer satisfy statistical orthogonality. S2. During the period of controllable perturbation signal, the operating status of each resource layer of the terminal system is synchronously collected based on a unified time reference, and the operating status of each resource layer is processed for time synchronization to generate a system status time series with time alignment relationship. S3. Based on the system state time series, construct a cross-layer perturbation response dynamic model to describe the mapping relationship between the perturbation signal input and the system state response, and extract multi-dimensional dynamic features from the cross-layer perturbation response dynamic model to characterize the amplitude intensity, nonlinearity and recovery capability of the terminal system to the perturbation response. S4. Input the multi-dimensional dynamic features into the trained risk intent recognition model, evaluate and output the risk intent of user behavior.
[0006] In some specific implementation schemes, the process of generating the controllable perturbation signal is as follows: Construct time-varying controllable perturbation signal components corresponding to each resource layer. Based on the state characteristics of each resource layer, select the corresponding perturbation signal type for each resource layer, generate controllable perturbation signal components for each resource layer, and combine them into a multidimensional initial controllable perturbation signal vector. Composite constraints are configured for each controllable perturbation signal component of the initial controllable perturbation signal vector to generate a perturbation signal that satisfies multiple constraints. For any two controllable perturbation signal components corresponding to different resource layers in the perturbation signal, a statistical orthogonality constraint is applied so that the mathematical expectation product of any two controllable perturbation signal components approaches zero, and finally a controllable perturbation signal is generated for injection into the terminal system.
[0007] In some specific implementations, the composite constraint configuration includes: Amplitude boundary constraint: Based on the device performance and operating status of the terminal system, the threshold that is imperceptible to the user is determined, and an infinite norm constraint is applied to the overall amplitude of the initial controllable perturbation signal vector to limit the maximum amplitude boundary; Load adaptive constraint: Obtain the current normalized load state of the terminal system and dynamically adjust the upper limit of the disturbance amplitude of the controllable perturbation signal component corresponding to each resource layer according to the load state; Discrete random triggering timing constraints: Generate a random triggering time sequence with adjacent triggering time intervals following a uniform distribution within the interval, and configure each controllable perturbation signal component as a discrete perturbation pulse sequence that is triggered sequentially according to the random triggering time sequence.
[0008] In some specific implementation schemes, the process of actively injecting controllable perturbation signals is as follows: Construct a perturbation mapping function that satisfies equivalence constraints and perturbation constraints, and map the controllable perturbation signal components corresponding to each resource layer in the controllable perturbation signal to the small control variable offsets of each resource layer in the terminal system in the scheduling critical path. Obtain a preset unified scheduling clock sequence, and synchronously trigger a disturbance injection operation at each moment of the unified scheduling clock sequence, and synchronously inject the small control variable offsets corresponding to each resource layer into the scheduling critical path corresponding to each resource layer.
[0009] In some specific implementation schemes, the process of actively injecting controllable perturbation signals also includes: During the synchronous execution of the disturbance injection operation, the statistical distribution of the system behavior of the acquisition terminal system under the disturbance is collected. The difference between the statistical distribution of the computing system's behavior and the probability distribution of the terminal system's behavior under undisturbed natural operating conditions; Determine whether the distribution difference meets the preset upper bound constraint of statistical indistinguishability. If it does, the disturbance is determined to be concealed; otherwise, adjust the mapping parameters of the disturbance mapping function to reduce the distribution difference.
[0010] In some specific implementations, the resource layer includes a computing layer, a storage layer, an I / O layer, and a network layer. The specific process of the perturbation injection operation is as follows: For the computing layer, the corresponding small control variable offset is mapped to the time slice offset of the terminal system's central processing unit scheduler. The time slice offset is superimposed with the original time slice of the central processing unit scheduler to generate the perturbed time slice allocation value and write it into the central processing unit scheduler. For the storage layer, the corresponding small control variable offsets are mapped to an ordered access sequence of auxiliary memory. The perturbation access bandwidth is determined based on the ordered access sequence, and controlled cache conflicts are introduced by performing auxiliary memory access constrained by the perturbation access bandwidth. For the I / O layer, the corresponding small control variable offset is mapped to the actual waiting time perturbation. The number of virtual requests to be inserted into the I / O request queue is determined based on the actual waiting time perturbation. The set of virtual requests is inserted into the actual original request set of the I / O layer to generate the perturbed I / O request set. For the network layer, the corresponding small control variable offsets are mapped to delay offsets and transmission time offsets, which are then superimposed on the original round-trip delay value and the original data packet transmission time, respectively, to generate a perturbed round-trip delay to change the timing characteristics of network communication.
[0011] In some specific implementation schemes, the modeling process for the cross-layer disturbance response dynamics model is as follows: When the terminal system is in a steady-state operating point, a dual-window synchronous sampling mechanism is constructed to collect the first system state increment within the undisturbed reference window and the second system state increment within the disturbed detection window at each sampling time. The first system state increment and the second system state increment are calculated based on the system state time series. The difference operation is performed between the second system state increment and the first system state increment to obtain the pure disturbance response increment. The pure perturbation response increments at each sampling time and the controllable perturbation signals actively injected at the corresponding time are stacked to form the output matrix and the input matrix, respectively. The system disturbance response matrix is estimated using the least squares estimation method based on the input and output matrices. The system disturbance response matrix is represented by blocks according to the affected target resource layer and the source resource layer of the disturbance injection, forming a cross-layer response block matrix, which fully describes the disturbance transmission relationship within and between each resource layer, and completes the modeling of the cross-layer disturbance response dynamic model.
[0012] In some specific implementations, the modeling process for the cross-layer disturbance response dynamics model also includes the following steps: Obtain the controllable perturbation signal corresponding to the historical sampling time, introduce the discrete time delay order into the second system state increment, and construct the time delay extension model based on the controllable perturbation signal corresponding to the historical sampling time and the system perturbation response matrix; The tensor product term of the controllable perturbation signal corresponding to the current sampling time is used as the extended input, and together with the first-order linear term, an extended regression model is constructed. The extended regression model is then fitted and solved to obtain the higher-order dynamic parameters. The state increment vector of the second system is obtained by applying time delay expansion and nonlinear compensation to the state increment of the second system using the time delay expansion model and the extended regression model, respectively. The second system state increment vectors processed by the time delay expansion model and the extended regression model at each sampling time are spliced together in time sequence to generate the system dynamic response trajectory. The cross-layer response block matrix, the system dynamic response trajectory, and higher-order dynamic parameters are used together as the output of the cross-layer disturbance response dynamic model.
[0013] In some specific implementation schemes, multi-dimensional dynamic features include response intensity features, nonlinear amplification factor, recovery time features, cross-layer consistency features, frequency domain response features, response directionality features, information entropy features, and stability features. The extraction process of dynamic features is as follows: Obtain the second system state increment vector at each sampling time from the system dynamic response trajectory; calculate the L2 norm of the second system state increment vector at each sampling time, and take the mean of the L2 norms at all sampling times, and use the mean as the response intensity feature; By using sparse constraints to compress higher-order dynamic parameters, the nonlinear amplification coefficient characteristics are obtained. The single recovery time of the terminal system to the steady-state operating point after each injection of a controllable perturbation signal is calculated. The mathematical expectation of the single recovery time after multiple injections of controllable perturbation signals is obtained to obtain the recovery time characteristics. Extract the system state time series corresponding to each resource layer; calculate the inter-layer correlation coefficient between any two system state time series of different resource layers; sum the absolute values of all inter-layer correlation coefficients to obtain the cross-layer consistency characteristics; Perform a discrete Fourier transform on the second system state increment vector at each sampling time to obtain the frequency domain representation of the state increment sequence; calculate the proportion of the sum of the energy spectra of the frequency domain representations of all high-frequency bands to the total sum of the energy spectra of the entire frequency band to obtain the frequency domain response characteristics; Singular value decomposition is performed on the system disturbance response matrix to obtain all singular values; the ratio of the largest singular value to the sum of all singular values is calculated to obtain the response directionality characteristics. Based on the second system state increment vector, the response energy ratio of each state variable is calculated, and the information entropy is calculated based on the response energy ratio to obtain the information entropy feature; The spectral radius of the system's disturbance response matrix is calculated to obtain the stability characteristics.
[0014] In some specific implementation schemes, the specific process of S4 is as follows: The multi-dimensional dynamic features are normalized to obtain the feature vector; The feature vector is mapped to a preset quantization interval by a piecewise nonlinear mapping function to obtain a quantized risk score; The quantitative risk scores are weighted and summed, and a feature coupling compensation term is added to obtain the original risk score. The original risk score is subjected to time smoothing to obtain a smoothed risk score. The smoothed risk score is compared with the preset risk level threshold, and the risk intent determination result is output.
[0015] Compared with the prior art, the present invention has the following beneficial effects: This invention treats the terminal system as a controllable dynamic system. By actively injecting low-intrusion, controllable perturbation signals into the resource layers (computation layer, storage layer, I / O layer, and network layer), it synchronously collects the system's operating status across multiple layers, constructs a perturbation-response dynamic model, and extracts specific dynamic features such as response intensity and nonlinear amplification coefficient. Based on these features, it quantifies and assesses the risk intent of user behavior (e.g., direct user operation, automated program execution, and malicious code-driven behavior). This invention achieves a paradigm shift from passive observation to active detection, and from application-layer semantics to system-level responses, significantly improving the ability to identify unknown and adversarial behaviors. Furthermore, the perturbations do not affect normal user operation, providing a novel technical framework for terminal security protection in complex scenarios.
[0016] By systematically designing the perturbation signal across multiple dimensions, including amplitude, time structure, spectral characteristics, and statistical properties, a controllable perturbation generation mechanism was achieved, combining low perceptibility, high identifiability, and high engineering feasibility. Without altering the functional semantics of the terminal system or the results of user operations, the pre-generated low-amplitude micro-perturbation signal is mapped to tiny control variable offsets in the resource scheduling paths of the operating system, thereby stimulating observable but imperceptible dynamic response changes within the system. Through unified time reference, precise alignment, atomic sampling, and adaptive scheduling, highly consistent observation of multi-resource layer states is achieved, featuring high time accuracy, low system overhead, and strong robustness. This addresses the problem that existing technologies typically focus only on single-layer data (such as system calls or network traffic), neglecting cross-layer coupling relationships within the system.
[0017] This invention achieves deep identification of user behavior risk intent by constructing the complete technical link of "disturbance driving - cross-layer response - dynamic modeling - feature discrimination". It not only breaks through the dependence of traditional methods on prior features and surface behavior, but also achieves significant improvements in anti-avoidance capability, detection accuracy and engineering feasibility, providing a brand-new technical paradigm for terminal security protection in complex adversarial environments. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0019] Figure 1 This is a flowchart of a network security risk behavior intent identification method based on controllable perturbation provided by an embodiment of the present invention; Figure 2 This is a comparison chart of the response trajectories of normal users and simulated risky behaviors provided in an embodiment of the present invention; Figure 3 This is a cross-layer response heatmap corresponding to normal behavior provided in the embodiments of the present invention; Figure 4 This is a heatmap of cross-layer response corresponding to risky behaviors provided in the embodiments of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0021] Example 1 like Figure 1 As shown, this embodiment 1 provides a method for identifying cybersecurity risk behavior intent based on controllable perturbation, specifically including the following steps: S1. Actively inject controllable perturbation signals into the resource layer of the terminal system, wherein the amplitude of the controllable perturbation signals satisfies the user-insensible threshold constraint and the controllable perturbation signal components of each resource layer satisfy statistical orthogonality. To proactively stimulate the potential dynamic response differences of the terminal system at different resource layers, this embodiment constructs a set of multi-dimensional, low-intrusion, and statistically analyzable controllable perturbation signals. The generation process is as follows: S11. Construct time-varying controllable perturbation signal components corresponding to each resource layer. Based on the state characteristics of each resource layer, select the corresponding perturbation signal type for each resource layer, generate controllable perturbation signal components for each resource layer, and combine them into a multidimensional initial controllable perturbation signal vector. S12. Perform composite constraint configuration on each controllable perturbation signal component of the initial controllable perturbation signal vector to generate a perturbation signal that satisfies multiple constraint conditions. Specifically, the composite constraint configuration includes: Amplitude boundary constraint: Based on the device performance and operating status of the terminal system, the threshold that is imperceptible to the user is determined, and an infinite norm constraint is applied to the overall amplitude of the initial controllable perturbation signal vector to limit the maximum amplitude boundary; Load adaptive constraint: Obtain the current normalized load state of the terminal system and dynamically adjust the upper limit of the disturbance amplitude of the controllable perturbation signal component corresponding to each resource layer according to the load state; Discrete random triggering timing constraints: Generate a random triggering time sequence with adjacent triggering time intervals following a uniform distribution within the interval, and configure each controllable perturbation signal component as a discrete perturbation pulse sequence that is triggered sequentially according to the random triggering time sequence; S13. Apply statistical orthogonality constraints to any two controllable perturbation signal components corresponding to different resource layers in the perturbation signal, so that the mathematical expectation product of any two controllable perturbation signal components approaches zero, and finally generate a controllable perturbation signal for injection into the terminal system.
[0022] Specifically, the resource layer includes a computing layer, a storage layer, an I / O layer, and a network layer. In this embodiment, the multi-layer disturbances are uniformly modeled as a time-varying vector signal u( t ) represents the controllable perturbation signal to be injected, u( t The form of ) is shown in formula (1.1): (1.1) in, u c ( t ) represents the controllable perturbation signal component of the computation layer. u m ( t ) represents the controllable perturbation signal component of the storage layer. u io ( t ) represents the controllable perturbation signal component of the I / O layer. u n ( t ) represents the controllable perturbation signal component of the network layer. To ensure that the impact of the perturbation on the user experience is negligible, the overall perturbation amplitude must satisfy the infinite norm constraint, as shown in (1.2): (1.2) in, ϵ This indicates a threshold that is imperceptible to the user and is adaptively determined by the performance and operating status of the terminal device.
[0023] In terms of time structure, the controllable perturbation signal components at each layer are modeled as constrained stochastic processes, as shown in (1.3): u i ( t ) = A i ( t ) ·x i ( t (1.3) in, u i ( t ) represents the first i Layer-controlled perturbation signal components, x i ( tThe system is a random process with zero mean and unit variance, satisfying the characteristics of weak stationarity and rapidly decaying autocorrelation, to avoid interference from long-term memory effects in the analysis of system behavior; while A i ( t The amplitude control function is time-dependent and used to dynamically adjust the disturbance intensity. In practical implementation, the random process can be implemented using Gaussian white noise or by constructing a finite bandwidth signal through the superposition of multiple frequency sine waves, in order to achieve more precise spectrum control in engineering.
[0024] To further ensure the imperceptibility of disturbances, an amplitude adaptive control mechanism based on system load is introduced. Specifically, the upper limit of the disturbance amplitude of each layer of controllable micro-disturbance signal component satisfies the requirement of (1.4).
[0025] (1.4) in Indicates the current system load status. d i ( · ) is the maximum permissible disturbance function for the corresponding resource layer. This function can be expressed in the form (1.5).
[0026] (1.5) in To preset a safety limit, For adjustment coefficients, This represents the normalized system load. This mechanism automatically reduces the disturbance intensity when the system load is high, and appropriately increases the disturbance amplitude when the system is idle, thereby improving the observability of the system response while ensuring a good user experience.
[0027] In terms of time scheduling, the controllable perturbation signal components are generated using a discrete triggering mechanism, that is, through a series of random trigger moments. tk When a perturbation pulse is triggered, the controllable perturbation signal component of each layer is transformed into: (1.6) in, t k For random triggering time, t The time-based variable represents the interval between adjacent trigger times, which follows a uniform distribution within the interval, allowing the disturbance frequency to vary randomly within a preset range, thereby preventing potential risk behaviors from being identified or avoided through periodic detection mechanisms. A i ( k Then it is at the trigger time. t k Discretized sequence k The following time-dependent amplitude control function, The representative is a random process function with unit variance. Represents the time of triggering t k Discretized sequence k The sampled values below; Represents the time of random triggering t k The non-zero disturbance impact generated by the scheduling effectively enhances the system's resilience.
[0028] In addition, to avoid coupling interference between different resource layers, after configuring the above constraints on the controllable micro-perturbation signal components of each layer, a multidimensional perturbation signal is obtained. Statistical orthogonality constraints are applied to the multidimensional perturbation signal to decouple the perturbations, without changing the steady state of user behavior, that is, satisfying the constraint condition (1.7).
[0029] (1.7) in, i and j Represents different resource layer numbers. u i ( t ) represents the first i Layer-controlled perturbation signal components, u j ( t ) represents the first j Layer-controlled perturbation signal components, This represents the mathematical expectation. This constraint is achieved through various means, including generating perturbations for each layer using independent random seeds, performing separation design on the spectrum, and introducing random phase control, thereby ensuring the statistical independence of perturbations in different dimensions and avoiding response aliasing.
[0030] To ensure the identifiability of subsequent system dynamics modeling, the controllable perturbation signal must also satisfy the continuous excitation condition, namely, that the autocorrelation matrix of the perturbation signal is positive definite within any time window, thus ensuring that the system is sufficiently excited in all dimensions. This condition ensures that the perturbation input can cover a sufficiently rich variety of variation modes, so that the system response parameters can be stably estimated in a statistical sense.
[0031] At the engineering implementation level, to maximize the information gain of the system response, a perturbation signal template library can be further constructed. This library predefines and manages different types of controllable micro-perturbations, including white noise, sinusoidal superposition, pulse, and frequency sweep signals. The system can dynamically select the optimal perturbation mode from the template set based on historical response data or preset strategies, thereby improving the effectiveness and efficiency of subsequent analysis. Finally, to prevent the perturbation signal from potentially affecting system stability, a global safety constraint is introduced, requiring that the deviation of the system state from the undisturbed state under perturbation is always limited to a very small range. This constraint ensures, from the perspective of overall system behavior, that the perturbation only causes observable differences at the microscopic scale and does not have a substantial impact on system function or performance.
[0032] In summary, by systematically designing the perturbation signal in multiple dimensions such as amplitude, time structure, spectral characteristics, and statistical properties, a controllable perturbation generation mechanism with low perceptibility, strong identifiability, and high engineering feasibility was achieved, laying a solid foundation for subsequent cross-layer response analysis and behavioral intent recognition.
[0033] The specific process of actively injecting controllable perturbation signals is as follows: 1. Construct a perturbation mapping function that satisfies equivalence constraints and perturbation constraints, and map the controllable perturbation signal components corresponding to each resource layer in the controllable perturbation signal to the small control variable offsets of each resource layer in the terminal system in the scheduling critical path. 2. Obtain the preset unified scheduling clock sequence, and synchronously trigger the disturbance injection operation at each moment of the unified scheduling clock sequence, and synchronously inject the small control variable offsets corresponding to each resource layer into the scheduling critical path corresponding to each resource layer.
[0034] For the computing layer, the corresponding small control variable offset is mapped to the time slice offset of the terminal system's central processing unit scheduler. The time slice offset is superimposed with the original time slice of the central processing unit scheduler to generate the perturbed time slice allocation value and write it into the central processing unit scheduler. For the storage layer, the corresponding small control variable offsets are mapped to an ordered access sequence of auxiliary memory. The perturbation access bandwidth is determined based on the ordered access sequence, and controlled cache conflicts are introduced by performing auxiliary memory access constrained by the perturbation access bandwidth. For the I / O layer, the corresponding small control variable offset is mapped to the actual waiting time perturbation. The number of virtual requests to be inserted into the I / O request queue is determined based on the actual waiting time perturbation. The set of virtual requests is inserted into the actual original request set of the I / O layer to generate the perturbed I / O request set. For the network layer, the corresponding small control variable offsets are mapped to delay offsets and transmission time offsets, which are then superimposed on the original round-trip delay value and the original data packet transmission time, respectively, to generate a perturbed round-trip delay to change the timing characteristics of network communication.
[0035] 3. During the synchronous execution of the disturbance injection operation, collect the statistical distribution of the system behavior of the terminal system under the disturbance. 4. The difference between the statistical distribution of the computing system's behavior and the probability distribution of the terminal system's behavior under undisturbed natural operating conditions; 5. Determine whether the distribution difference meets the preset upper bound constraint of statistical indistinguishability. If it does, the disturbance is determined to be concealed; otherwise, adjust the mapping parameters of the disturbance mapping function to reduce the distribution difference.
[0036] The core objective of the perturbation signal injection mechanism is to map a pre-generated, low-amplitude, controllable micro-perturbation signal into a small offset of control variables in the operating system's resource scheduling paths, without altering the terminal system's functional semantics or user operation results. This induces observable but imperceptible dynamic response changes within the system. In other words, this mechanism does not directly affect application logic or data content, but rather achieves fine-grained perturbation of the system's operating state by adjusting key scheduling variables at the system's underlying level, such as time, sequence, and resource contention relationships.
[0037] From a system modeling perspective, this embodiment abstracts the terminal system into a controlled dynamic system, whose state evolution relationship can be represented as described in (1.8): (1.8) in, x ( t ) indicates that the system at time t t The state vector mainly reflects resource scheduling information such as CPU scheduling, cache status, I / O queue and network status; a ( t ) represents the system's original behavioral input, that is, the natural behavior driven by user operation or program execution; u( t )=[ u c ( t ) ,u m ( t ) ,u io ( t ) ,u n ( t )] represents the controllable perturbation signal introduced in this embodiment; f ( ·) is the system state transition function, used to describe the evolution of the system under the current state and input conditions.
[0038] The essence of perturbation injection can be further represented as a perturbation extension of the original behavior, as shown in (1.9): (1.9) in, This represents the equivalent behavior input after the perturbation. G ( · ) is a perturbation mapping function used to map u( t This is converted into specific small control variable offsets for the system, such as time slice offsets and cache access disturbances. The disturbance mapping function must satisfy the following two core constraints: The first is the equivalence constraint, which states that disturbances should not change the system's functional output, satisfying: (1.10) in This represents the system function output mapping function, such as program execution results or user-visible output.
[0039] The second is the perturbation constraint, which means that the perturbation amplitude is much smaller than the original behavioral input, defined as: (1.11) in The norm of a vector is used to measure signal strength, thereby ensuring that the disturbance is within the range of "weak interference".
[0040] In practical implementation, disturbance injection must follow the principle of "critical path priority," meaning it should prioritize acting on sensitive points in the critical path of the operating system's scheduling, including time scheduling, execution order, and resource contention, while avoiding direct interference with business logic paths. Specifically, the scheduler decision point is selected at the computation layer, the cache contention path at the storage layer, the queue scheduling path at the I / O layer, and the transport scheduling path at the network layer. This ensures that disturbances only change the internal scheduling behavior of the system without affecting the semantics of application functions.
[0041] 1) At the computation layer, the perturbation is mainly achieved by making small offsets to the CPU scheduler's time slice allocation. Let the original time slice be... t slice The time slice after the perturbation will be in the form of (1.12): (1.12) Where, Δ t c = u c ( t) represents the mapping of controllable perturbation signal components in the computational layer, and satisfies |Δ t c | ≤ 10 µ s, meaning the disturbance is controlled within the microsecond range. This method does not change the task set, but only has a slight impact on the task execution timing.
[0042] Furthermore, to improve the precision of the perturbation, the virtual runtime (vruntime) within the scheduler can be fine-tuned. The calculation method is shown in formula (1.13): (1.13) in, d c This represents a small perturbation. This operation does not change the overall fairness of the scheduling policy, but it alters the task scheduling order on a short timescale, thus causing measurable differences in system response.
[0043] 2) In the storage layer, the core objective of the disturbance is not to directly modify the data content, but to artificially introduce controllable cache contention behavior, change the timing and hit structure of the cache access path, and thus induce differences in system response.
[0044] Therefore, this embodiment constructs an ordered access sequence of length N for auxiliary memory. M aux( t ): M aux( t )= 〈addr〈 1 ,addr 2 ,...,addrN〉 (1.14) in, M aux ( t ) represents the moment t Injected ordered access sequence, M aux ( t It is not a set of addresses, but rather it determines the access behavior, and this access behavior determines the perturbation access bandwidth. aux , addrN This represents a sequence of access addresses that partially overlap with the target cache set. The order of these addresses affects cache conflicts, thereby introducing controlled cache conflicts.
[0045] The disturbance intensity is constrained by bandwidth ratio. Only after the constraints are met is it considered a controlled cache conflict. The constraint rules are as follows: (1.15) in, Bandwidth represents the perturbation strength of controlled cache conflicts. aux To disrupt access bandwidth, Bandwidth total This represents the total system bandwidth. This constraint ensures that disturbances will not significantly affect system performance.
[0046] 3) At the I / O layer, perturbations are achieved by inserting virtual requests into the I / O request queue. Let the original request set be... Q real Requests after adding perturbation It can be represented as: (1.16) in, Q aux This is a set of virtual I / O requests. To ensure that the controllable perturbation signal is consistent with the physical dimensions, a reference conversion coefficient for the I / O layer is introduced. (Unit: seconds) is used to map dimensionless, controllable perturbation signal components into actual waiting time perturbations. Determined by storage device performance, it can be adaptively set according to device type or operating status. The disturbance is achieved by altering the request latency, specifically the latency disturbance. for: (1.17) Based on queuing relationship The number of virtual requests can be obtained as follows: (1.18) in, µ Represents service speed. u io ( t () represents a dimensionless, controllable perturbation signal component of the I / O layer, whose value range satisfies u io ( t ) ∈ [ - 1 , 1).
[0047] Number of virtual requests | Q aux | is not directly equal to the controllable perturbation signal, but is determined by the reference transformation coefficient. The mapping yields a result that simultaneously satisfies | Q aux | << | Q real |, meaning the number of virtual requests is much smaller than the number of real requests, thus avoiding a significant impact on throughput. Furthermore, It can dynamically adjust according to the current I / O load status of the system: when an increase in I / O queue length or a decrease in service rate is detected, it adaptively reduces the I / O queue length. This is to control the amplitude of disturbances and ensure the stability of system operation and the user's insensitivity.
[0048] 4) At the network layer, the perturbation is achieved by modulating the network delay. Let the original round-trip time be RTT, and the perturbation-induced round-trip time be RTT. ’ for: RTT ’ =RTT+Δ t n (1.19) Where, Δ t n = u n ( t This represents the controllable perturbation signal component of the network layer. Simultaneously, the packet transmission time is fine-tuned; the adjusted packet transmission time... for: (1.20) in, t send Original sending time This method involves a small time offset and does not affect data integrity; it only alters the timing characteristics of the communication.
[0049] To ensure the coordinated consistency of multi-layered disturbances, a unified scheduling clock is introduced to ensure that the system operates at the same sampling time. By synchronizing the components of the controllable perturbation signal to each resource layer, the comparability of cross-layer responses is ensured.
[0050] (1.21) in, Representing the k A unified scheduling clock for each sampling moment. k Δ is the sampling sequence number. T The sampling period represents a unified time base for system disturbance injection and state sampling, ensuring strict synchronization between disturbance injection and state acquisition. Regarding concealment, disturbances must satisfy statistical indistinguishability, calculated as follows: (1.22) in, This represents the statistical distribution of the overall behavior of the system after the perturbation has been applied. This represents the probability distribution of the terminal system's natural behavior when it operates without any human intervention. DKL This represents the Kullback-Leibler divergence, used to measure the difference in the distribution of system behavior before and after the perturbation. d This represents a pre-defined upper bound constraint. This constraint ensures that the perturbation behavior is statistically close to the natural fluctuations of the system, making it difficult to detect.
[0051] Finally, to ensure system stability and security, an upper bound on the state perturbation is introduced for constraint. This method is a conventional constraint and will not be explained in detail. The final source occupancy constraint is as follows:
[0052] Among them, CPU aux This represents the auxiliary CPU utilization and I / O consumed by the generation and injection of the perturbation itself. aux This refers to the auxiliary I / O utilization resulting from creating perturbations at the I / O layer, BW aux This refers to the secondary memory bandwidth utilization caused by the need to generate controlled cache contention at the storage layer; Meanwhile, all disturbance tasks run at the lowest priority to avoid impacting normal business operations. Under the above resource constraints and scheduling strategies, the system state can be represented as a response function under disturbance-driven conditions. The system state S(t) of each resource layer (such as the compute layer, storage layer, I / O layer, and network layer) can be expressed as: (1.23) Wherein, Φ( · ) represents the state response mapping function determined by the system's internal scheduling and resource contention mechanisms.
[0053] The perturbation injection mechanism in this embodiment achieves the goals of "functional invariance, perturbed structure, and observable response" by performing micro-scale control on the critical scheduling path of the operating system. It features precise path, low intrusion, high concealment, and strong engineering feasibility, providing a reliable foundation for subsequent dynamic modeling.
[0054] S2. During the period of controllable perturbation signal, the operating status of each resource layer of the terminal system is synchronously collected based on a unified time reference, and the operating status of each resource layer is processed for time synchronization to generate a system status time series with time alignment relationship. S3. Based on the system state time series, construct a cross-layer perturbation response dynamic model to describe the mapping relationship between the perturbation signal input and the system state response, and extract multi-dimensional dynamic features from the cross-layer perturbation response dynamic model to characterize the amplitude intensity, nonlinearity and recovery capability of the terminal system to the perturbation response. Multidimensional dynamic characteristics include response intensity characteristics, nonlinear amplification factor, recovery time characteristics, cross-layer consistency characteristics, frequency domain response characteristics, response directionality characteristics, information entropy characteristics, and stability characteristics. Traditional analyses in existing technologies often focus on application-layer and user-layer characteristics, lacking a comprehensive consideration of the multi-layered response characteristics caused by operating system scheduling and resource allocation, and thus failing to accurately characterize the differences in the impact of different behaviors within the system. This embodiment proposes a cross-layer synchronous observation mechanism, the core objective of which is to perform high-precision, low-bias synchronous sampling of the operating status of multiple resource layers in the terminal system based on a unified time reference during the period of disturbance signal action, thereby constructing a multi-dimensional observation data matrix with strict time alignment, providing a reliable data foundation for subsequent analysis.
[0055] In the specific implementation, the system's operating state is first modeled uniformly. The system at time [time] is defined. t The overall operating state is represented by a cross-layer state vector, which is as follows: (1.24) Among them, S( t ) indicates that the system is in time t Overall operational status; superscript T This represents the vector transpose. Each component represents the state of a different resource layer: S c ( t This refers to the operating status of the computing layer (such as CPU-related metrics). S m ( t This represents the operational status of the storage layer (such as cache and memory access status). S io ( t This refers to the operating state of the input / output layer (I / O layer). S n ( t () represents the operating state of the network layer.
[0056] The operational state of each layer is itself a multi-dimensional vector, which can be represented as: (1.25) in, S i ( t ) indicates the first i A state vector for each resource layer. s ik ( t ) indicates that the resource layer is numbered. k Specific status indicators (such as CPU utilization, cache hit rate, etc.). k This represents the number of state variables collected for this layer.
[0057] To ensure data consistency across layers, this embodiment introduces a unified time base mechanism. It requires that the sampling times of all resource layers be synchronously collected based on a unified time base, i.e.: t c = t m = t io = t n = t 基准 (1.26) in, t c , t m , t io , t n These represent the sampling timestamps for the computation layer, storage layer, I / O layer, and network layer, respectively, and are unified to the same time. t 基准 If the time is inconsistent across different layers, it will lead to "spurious correlation" (i.e., asynchronous data is mistakenly identified as related).
[0058] To achieve high-precision time unification, a processor hardware time counter (TSC, Time Stamp Counter) is used as a global time source to unify time. t 基准 Represented as: t 基准 (1.27) Where TSC represents the current CPU time count value, f cpu This represents the CPU clock speed (unit: Hz), used to convert the count value into actual time. Since the TSC of different cores in a multi-core processor may vary, consistency correction is required. The correction method is shown in formula (1.28): (1.28) in, t 基准i Indicates the first i The uniform time measured by each CPU core, Δ t core,i This indicates the time offset of the core relative to the reference core. This is the corrected unified time. This offset can be measured at system startup and periodically corrected for drift during operation. Regarding the sampling triggering mechanism, the unified discrete sampling time sequence defined in (1.21) above is used, where the sampling period Δ... T for: (1.29) in, f s ( t The current sampling frequency range is defined, and an adaptive adjustment mechanism is introduced to adjust the current sampling frequency. f s ( t )= f max · (1- β·L ( t (1.30) in, f max is the maximum sampling frequency. β For adjustment coefficients, L ( t This represents the current load status of the system.
[0059] First, the system obtains the operating status of each resource layer at each sampling time through a unified acquisition function: i ∈{ c,m,io,n}= (1.31) in, This represents a cross-layer acquisition function, used at the sampling time. t k Synchronously obtain the status of all resource layers. Indicates the first i Layer at actual sampling time The acquired original state, at this moment relative to the target sampling time. t k There is a deviation. This sampling process is triggered by a high-precision kernel timer and is executed preferentially in kernel mode to avoid delays caused by user-mode scheduling.
[0060] Then, since time errors are unavoidable in the actual sampling process, the actual sampling error is defined as: (1.32) in, Indicates the first i The actual sampling error of each resource layer This is the actual sampling time for this layer. tk Let be the target sampling time. And the constraints on the actual sampling error must be satisfied: (1.33) in, d t This represents the maximum permissible time error.
[0061] Finally, error correction is performed using linear interpolation, and a snapshot mechanism is introduced to address the issue of asynchronous multi-level sampling. The calculation method is as follows: (1.34) in, Indicates the same logical point in time. t k A snapshot is a collection of state data originally collected from each monitored resource layer. A snapshot represents a consistent reading of the state of each layer at the same logical point in time. · This represents the operation of time alignment and consistency fusion of the original sampled states at each layer, including interpolation correction and time synchronization processing, to obtain the system state time series S under a unified time reference. t k ).
[0062] Through a series of mechanisms, including unified time base correction, high-precision synchronous triggering, sampling error constraints, and snapshot alignment, time offsets and asynchronous deviations between resource layers can be effectively eliminated, ensuring that cross-layer state indicators acquired at each sampling moment have strict time consistency and global comparability. Based on this, the corrected system state time series are sequentially collected according to the sampling time sequence, ultimately forming multi-dimensional system observation data with complete time alignment relationships, which is then structured and expressed as a time series matrix. (1.35) Where X is the observation data matrix, which serves as the system state data used for subsequent disturbance-response dynamics modeling. Rows represent the time dimension (sampling time), and columns represent cross-layer state characteristics.
[0063] In summary, this cross-layer synchronous observation mechanism achieves highly consistent observation of the state of multiple resource layers through unified time reference, precise alignment, atomic sampling, and adaptive scheduling. It features high time accuracy, low system overhead, and strong robustness, providing reliable data support for subsequent dynamic analysis.
[0064] Existing stability analysis methods in control theory, such as Lyapunov's method, focus on the stability of the system itself and do not involve semantic information for identifying behavioral intentions through external disturbances. Therefore, they are difficult to use directly to distinguish between normal and risky behavior. The core of the cross-layer disturbance response dynamic model constructed in this application lies in establishing a mapping relationship between disturbance input and system state changes based on the observation data matrix X obtained from cross-layer synchronous observations. This transforms the differences in user behavior driven by factors that cannot be directly observed into an analyzable dynamic model of the system's internal response structure, thus providing a foundation for subsequent discrimination.
[0065] First, the terminal system is abstracted as a discrete-time nonlinear dynamic system, and its evolution process can be abstracted as follows: (1.36) Among them, S( t ) represents the system at time . t The cross-layer state vector contains the cross-layer operating states of the computation layer (CPU), storage layer (memory), I / O layer, network layer, etc.; S( t +1 represents the next discrete time step. t +1 system state vector; F ( · ): The nonlinear state transition function of the system, describing the state evolution law; u( t ) represents a moment t Injected cross-layer controllable perturbation signal; a( t ) represents the user behavior driving vector, which is a latent variable that cannot be directly observed; w( t ) represents the system measurement noise and environmental interference vector; t Represents a discrete-time index.
[0066] To ensure the effectiveness of disturbance-response identification, this application performs modeling when the system is at its steady-state operating point. The steady-state decision window length is defined as... T Win, within this window, satisfies: (1) CPU / memory / I / O load fluctuation ≤ 5%; (2) The set of active foreground processes and core background processes remains unchanged. Under the above conditions, user behavior drives a( t Within the window, it can be considered a constant; the system's Jacobian matrix... J u ,J a Approximately unchanged.
[0067] Under the perturbation condition (stability of the system process set), the local first-order linearization approximation of the nonlinear system is as follows: (1.37) Wherein, ΔS( t)=S( t +1)-S( t ) represents the system state increment vector; J u ( t ) represents the Jacobian matrix of the disturbance response, which describes the marginal impact of the disturbance on the system state; J a ( t The Jacobian matrix represents the user behavior response, describing the marginal impact of user behavior on the system state; under the same steady-state operating point, a dual-window synchronous sampling mechanism is constructed, including: (1) No-disturbance baseline window: When no disturbance signal is injected, the first system state increment is: ΔS0 t k = J a ( t k )a( t k (1.38) Wherein, ΔS0 t k Represents the sampling time under undisturbed conditions. t k The system state increment at any given time is driven solely by user behavior.
[0068] (2) With a perturbation detection window: Inject a controllable perturbation signal u( t k The second system state increment is: ΔS1 t k = J u ( t k )u( t k )+ J a ( t k )a( t k (1.39) Wherein, ΔS1 t k Represents the sampling time after the perturbation is injected. t k The system state increment at any given time is driven by both disturbances and user behavior. By differencing the two windows and removing user behavior and background trends, the pure disturbance response increment ΔSdiff is obtained. k : ΔSdiff, k=ΔS1 t k -ΔS0 t k = J u ( t k )u( t k (1.40) The reference window and the probe window must meet the following requirements: (1) they are time-continuous and do not overlap; (2) their window lengths are completely consistent; and (3) their sampling frequencies are consistent, in order to ensure the effectiveness and physical interpretability of the differential operation.
[0069] Construct a dataset based on the differencing input and output data: (1.41) in, This represents the dataset used for disturbance-response modeling; k Indicates the sampling sequence number; N This represents the total number of samples. For ease of explanation, the disturbance response Jacobian matrix defined above will be used below. J u ( t ) is denoted as the response matrix ,Right now = J u ( t Construct the system disturbance response matrix to be identified. The optimal estimate of R is obtained by using least squares estimation. : (1.42) Its closed-form solution is: (1.43) in, Represents the known first k The cross-layer perturbation signal vector injected at each time step; The representative model predicted the first k At any given moment, the system state increment caused solely by the disturbance; U This represents the input matrix formed by stacking all controllable perturbation signals row by row; U T Represents the input matrix U The transpose of ΔS diff This represents the output matrix formed by stacking all pure disturbance response increments column-wise; U T U ) -1 Representation matrix The inverse matrix; (1.44) Where ΔS represents the overall state increment matrix formed by stacking the state increments at multiple time steps row by row; ΔS1 t k ( k =1 ,...,N ) indicates the first k The system state increment vector at each time step.
[0070] Considering system time delay and inertia, a dynamic expansion model is introduced. The pure disturbance response increment ΔS obtained earlier using the two-window differencing method... diff This is the static expression considering only the current disturbance input at a single sampling time (see Equation 1.40). In practical systems, the state change after disturbance injection often exhibits inertia and time lag; that is, the response at the current moment depends not only on the current disturbance but also on the cumulative influence of historical disturbance inputs. Therefore, this paper will use ΔS diff Generalized to a time-evolving function form This characterizes the system's dynamic memory effect on disturbance signals. Its time-delay dependency can be modeled as follows: (1.45) in, t It represents the discrete time delay order, characterizing the system's inertia and time delay effects; T 1 indicates the maximum delay order considered; Indicates correspondence t The system disturbance response matrix with step delay; express t-t The historical controllable perturbation signal is injected at each moment. To describe the nonlinear interaction, the system perturbation response matrix R is transformed, and a second-order term is introduced into the dynamic extended model, expressing the pure perturbation response increment as: (1.46) in, R 1 represents the first-order linear response matrix, which describes the linear mapping relationship between the disturbance and the state; R 2 represents the second-order response tensor, which characterizes the nonlinear coupling effect inside the perturbation; ⊗ represents the tensor product (outer product) operation, used to construct second-order nonlinear interaction terms.
[0071] Suppressing slow behavioral tendencies through second-order difference: (1.47) in, The second-order difference, representing the system state increment, is used to suppress slow-varying trends and enhance transient characteristics; : t The system state increment at time +1; : tThe system state increment at time t.
[0072] And utilize statistical orthogonality: (1.48) Where a( t ) T Transpose of latent variables driven by user behavior.
[0073] The core function of this constraint is to limit the coupling between the disturbance signal and user behavior, ensuring that disturbance injection does not cause significant changes in user behavior. This guarantees that the user behavior driver remains consistent between the baseline window and the disturbance window, ensuring that the differential operation only reflects the system response caused by the disturbance. It is important to emphasize that the elimination of the user behavior term does not rely on statistical orthogonality, but is achieved through the aforementioned "dual-window differential mechanism" at the same steady-state operating point. Simultaneously, different disturbance components are required to satisfy the following: (1.49) in, u i ( t ) ,u j ( t ) indicates the first i The and the first j There are 10 components; the different components are statistically approximately orthogonal.
[0074] When the system does not meet the steady-state operating point determination conditions, the disturbance injection is paused, and only the baseline state data is continuously collected; after the system re-enters the steady state, the dual-window disturbance detection and response identification process is resumed.
[0075] Model identifiability requires meeting the continuous excitation condition: (1.50) in, The representation matrix is a symmetric positive definite matrix; the positive definite condition guarantees the response matrix. R There exists a unique least-squares solution; this condition guarantees that the disturbance signal contains sufficient dynamic information, such that the response matrix... R It possesses unique solvability and identifiability. This condition applies to the differencing perturbation input matrix. U , guarantee u( t It has sufficient excitation in all dimensions, thus enabling the 1.40 difference model ∆Sdiff to... k The response matrix in the matrix is uniquely identifiable.
[0076] After completing response modeling, time delay spread, and statistical disturbance suppression, the response matrix characterizing the overall disturbance propagation properties of the system can be obtained. RBased on the previous cross-layer state division of the computation layer, storage layer, I / O layer, network layer, and interaction layer, this global response matrix can be further decomposed according to the inter-layer coupling relationship to clearly reflect the disturbance propagation and mutual influence between different resource layers. Therefore, the cross-layer system disturbance response matrix can be represented as a block structure, fully characterizing the cross-layer disturbance propagation characteristics: (1.51) Among them, matrix elements R xy For the sub-response matrix, the first subscript x Indicates the target resource layer that is affected, the second subscript. y This indicates the source resource layer from which the disturbance is injected. x,y All can be {c,m,io,n,h},c Represents the computing layer, m Represents the storage layer, I / O Represents the I / O layer n Represents the network layer, h Represents the interaction layer; R cc This represents the perturbation response within the computational layer. R c This represents the computation layer's response to disturbances in the storage layer. R cio This represents the computational layer's response to disturbances in the I / O layer. R cn This represents the computational layer's response to perturbations in the network layer. R mc This represents the storage layer's response to disturbances in the computation layer. R mm The first submatrix represents the perturbation response within the storage layer, while the remaining submatrixes correspond to the cross-layer response relationships between each layer.
[0077] In summary, through continuous excitation condition verification, linear / nonlinear fitting, and time delay extension modeling, the estimated value of the system's cross-layer response matrix can be obtained. This estimated matrix is essentially the actual numerical implementation of R, fully characterizing the disturbance transmission relationships within and between each layer.
[0078] After solving for the state increment and estimating the response matrix time-by-time according to the disturbance period, the system state change sequences after time delay correction, nonlinear compensation and second-order difference detrending at each time point are spliced together to form the system dynamic response trajectory. The trajectory, with time as its axis, records the complete evolution of the system's cross-layer state under the continuous action of the disturbance signal. It intuitively reflects the transient response characteristics, inertial delay characteristics, and convergence trend of the system under external excitation, and provides a complete characterization of the disturbance-response dynamics process.
[0079] For the nonlinear second-order model, the tensor product term of the perturbation signal is used as an extended input, which, together with the first-order linear term, constructs an extended regression model. Then, higher-order dynamic parameters, namely the first-order response matrix, are obtained through fitting and solving. R 1 and the second-order response tensor R 2. Provides basic data support for subsequent dynamic feature extraction.
[0080] S4. Input the multi-dimensional dynamic features into the trained risk intent recognition model, evaluate and output the risk intent of user behavior.
[0081] The multi-dimensional dynamic features are normalized to obtain the feature vector; The feature vector is mapped to a preset quantization interval by a piecewise nonlinear mapping function to obtain a quantized risk score; The quantitative risk scores are weighted and summed, and a feature coupling compensation term is added to obtain the original risk score. The original risk score is subjected to time smoothing to obtain a smoothed risk score. The smoothed risk score is compared with the preset risk level threshold, and the risk intent determination result is output.
[0082] Because existing behavior pattern-based methods rely on observable sequences, violators can disguise their behavior by injecting delays, randomizing rhythms, etc., rendering the detection model ineffective. The core of this embodiment's risk intent identification lies in extracting essential dynamic features that reflect differences in user behavior driving mechanisms from the high-dimensional, multi-temporal, and cross-layer coupled system response data obtained from the aforementioned perturbation-response modeling. Furthermore, to ensure that the extracted dynamic features possess risk discrimination capabilities, this embodiment defines the essential difference between risky behavior and normal behavior at the operating system level. This difference does not originate from the surface behavioral form but from its underlying execution mechanism, specifically including: (1) Difference in execution rigidity: Normal user behavior is driven by interaction, and its execution process has scheduling flexibility; risky behavior is driven by code, has strong execution rigidity, and does not have the ability to adaptively adjust to system disturbances. (2) Differences in cross-layer coupling: Normal resource calls exhibit a weakly correlated, ordered chain structure; Risky behaviors are characterized by strong coupling and concurrent calls across multiple resource layers. (3) Differences in the persistence of resource occupation: Normal behavior releases resources after the interaction ends; Risky behavior is characterized by continuous background resource occupation; (4) Abnormality of execution path: Normal behavior follows the operating system scheduling path; risky behavior has abnormal paths such as bypassing scheduling and covert execution.
[0083] Based on the above differences, risky behaviors will exhibit stable and distinguishable dynamic response characteristics under disturbances, thus establishing a causal closed loop of "behavioral essence → response characteristics → risk judgment," and forming a feature vector F' from all dynamic characteristics: F'=[ f 1 ,f 2 ,f 3 ,...,fK (1.52) Where F' represents the final feature set used for behavior discrimination. K The total number of features.
[0084] (1) The input to the risk intent model mainly includes two types of data: The first type is the response matrix obtained during the disturbance-response modeling stage, which has the following form: (1.53) in, This represents the estimated value of the system's response intensity matrix to each state variable under each disturbance dimension; d s Represents the system state dimension. d u Indicates the dimension of the disturbance signal.
[0085] Similarly, from the system response trajectory mentioned above... Therefore, the response trajectory of the system under disturbance-driven conditions in the second category is as follows: (1.54) Wherein, ∆S( t k ) indicates the first k The system state change vector at each sampling time.
[0086] (2) Response intensity characteristics f mag The response strength is used to measure the overall sensitivity of a system to disturbances, and is considered the first dynamic characteristic. It is defined as follows: (1.55) in, The L2 norm, used to represent a vector, characterizes the magnitude of state changes. This feature reflects the overall sensitivity of the system to disturbances, while risky behaviors, due to continuous resource consumption, exhibit significantly stronger responses than normal behaviors.
[0087] (3) Nonlinear amplification factor f nonlin The nonlinear relationship is characterized by a second-order model. The second-order expansion of the pure disturbance response increment has already been given in Equation 1.46; this expression is directly adopted here to define the nonlinear amplification factor: (1.56) in, These are the Frobenius norms of a second-order tensor and a first-order matrix, respectively. This is a very small positive number, used to avoid the denominator being zero. In practical implementation, this invention uses sparse constraints to compress the second-order terms to avoid the dimensionality explosion problem in the second-order model. This feature reflects the nonlinearity of the system response, corresponding to rigid execution. For risky behaviors, its rigid execution leads to a significant amplification of nonlinearity.
[0088] (4) Recovery time characteristics The steady-state condition of the system is: (1.57) in, Indicates the first k The disturbance response increment at each sampling time (consistent with the previous text). The preset steady-state threshold is used to determine when the amplitude of the state change is less than this threshold, at which point the system is considered to have returned to steady state.
[0089] Single recovery time: (1.58) in, Indicates the first k The number of time steps required for the system to recover to steady state after a disturbance; For the first k The next perturbation injection time; d This represents the number of discrete time steps elapsed since the self-perturbation injection. Global recovery time characteristics: (1.59) in, f rec Indicates the characteristics of average recovery time; This is a mathematical expectation operator, representing the average level of system recovery capability under multiple perturbations. This characteristic reflects the system's recovery capability after being disturbed, corresponding to resource consumption persistence; recovery time for risky behaviors will be significantly prolonged.
[0090] (5) Cross-layer consistency characteristics f corr To represent the correlation between different layers, the interlayer correlation coefficient is defined: (1.60) in, Cij Indicates the first i Layer and First j Pearson correlation coefficient of layer state sequence; corr( · ) is the correlation coefficient calculation function; S i , S j These are system state time series for different resource layers.
[0091] Cross-layer consistency characteristics can be represented as follows: (1.61) in, L This represents the total number of system resource layers. This represents the sum of the absolute values of the correlation coefficients between all layers. This feature reflects the coupling strength between different resource layers; for risky behaviors, strong cross-layer coupling leads to a significant increase in correlation.
[0092] (6) Frequency domain response characteristics f freq f freq It is obtained through Fourier transform and is represented as follows: = F u [ΔS( t k (1.62) in, This is the frequency domain representation of the state increment sequence; F u [ · [] is the Discrete Fourier Transform operator; f For frequency variables.
[0093] The frequency domain characteristics of the high-frequency energy proportion are calculated as follows: (1.63) in, It is a set of high-frequency bands; This is the frequency domain energy spectrum. This characteristic reflects the proportion of high-frequency disturbance components in the system response. For risky behaviors, the high-frequency fluctuations introduced by their continued execution will lead to a significant increase in the proportion of high-frequency energy.
[0094] (7) Response directionality characteristics f anisotropy Singular value decomposition of the response matrix: (1.64) in, This is an estimate of the cross-layer response matrix; U , V Σ is an orthogonal matrix; Σ is a singular value diagonal matrix.
[0095] Directional indicators (1.65) in, These are the singular values of the matrix. It is the maximum singular value; The ratio, representing the sum of all singular values, reflects the degree of concentration of response energy. This characteristic reflects the concentration of system response energy across various dimensions; due to the strong directional nature of resource access in risky rows, their energy concentration will be higher.
[0096] (8) Information entropy characteristics f entropy The normalized response distribution is: (1.66) in, For the first i The proportion of response energy for each state variable; Δ S i The first state increment vector i Each component.
[0097] Information entropy: (1.67) Among them, the information entropy feature is used to measure the uniformity and complexity of the system response distribution. This feature reflects the uniformity of the system response distribution. For risky rows, the concentration of their responses will lead to a decrease in entropy value and a more uneven distribution.
[0098] (9) Stability characteristics f stab Stability characteristics based on spectral radius are used to characterize the amplification tendency and potential instability of the system response: (1.68) in, The spectral radius of the response matrix estimate characterizes the divergence or convergence trend of the system's dynamic response. This feature reflects the stability of the system's dynamic response; for risky behaviors, an increase in the spectral radius indicates that the system tends towards an unstable state.
[0099] (10) Feature normalization and combination
[0100] Feature normalization is performed in the following manner: (1.69) in, Represents the normalized features. f i The original dynamic characteristics (corresponding to the previous text) f mag , f nonlin wait), , These are the minimum and maximum values of the feature in the sample set, respectively. ϵ It is a very small positive number, used to avoid the denominator being zero, which is consistent with the nonlinear characteristic calculation mentioned earlier. ϵ The meanings are the same.
[0101] Final eigenvector: F'=[ f mag ,f nonlin ,f rec ,f corr ,f freq ,f anisotropy ,f entropy ,f stab (1.70) Where F' is the final combined feature vector.
[0102] (11) Characteristic stability description: To ensure robustness, the following requirements must be met: (1.71) Among them, Var( · ) represents the variance operator; The characteristic variance under normal behavior; The characteristic variance under abnormal behavior.
[0103] Through the aforementioned feature extraction process, complex system response behaviors are compressed into a set of dynamic features with clear physical meaning, realizing a mapping from the "original system state" to a "discriminable feature space." This feature system simultaneously covers information in the time domain, frequency domain, and structural domain, effectively characterizing the deep dynamic differences caused by different user behaviors within the system. To achieve risk discrimination, it is necessary to construct a feature baseline distribution for normal behavior. Specifically, this includes: 1) Collection scenarios: typical environments such as office terminals, industrial control terminals, and personal terminals; 2) Collection method: continuously collecting system response data under risk-free behavior conditions; 3) Feature processing: normalizing each dynamic feature; 4) Distribution modeling: statistically analyzing the mean, variance, and distribution interval of each feature to form a baseline for the normal behavior feature space.
[0104] Compared to existing deep learning-based attack detection methods, such as those based on graph neural networks or neural network ordinary differential equations, although they can achieve end-to-end micro-perturbation feature learning and risk classification, their internal decision-making process is highly coupled to the latent space state, making it difficult to inversely solve the model output into the specific physical mechanism of the system, and preventing engineers from tracing the perturbation features from the source. This black-box characteristic leads to at least two defects: (1) lack of interpretability of detection results: security analysts cannot know what underlying mechanism triggered the alarm, making it difficult to distinguish between real attacks and occasional system fluctuations; (2) model updates depend on retraining: when facing new types of attacks, the model needs to be retrained based on massive amounts of labeled data, lacking the ability to quickly adapt based on mechanism rules. In this embodiment, a clear perturbation-response dynamic mathematical reasoning model is used to replace the black-box deep learning model. By extracting dynamic features with clear physical meaning, an interpretable causal chain from behavioral mechanism to risk judgment is established.
[0105] The risk intent recognition model used in this embodiment is an interpretable, quantifiable, and structurally stable risk mapping model to accurately determine the risk intent of user behavior. The model's input is the final feature vector F', and the model outputs a risk score. ∈ [0 , 1]: (1.72) in, This represents a risk mapping function used to map feature vectors to quantitative risk scores.
[0106] Basic weighted linear risk model: (1.73) satisfy and w i ≥ 0, where w i For the first i The weights of each feature are used to characterize the degree of influence of that feature on risk assessment. The representative represents the normalized features.
[0107] The piecewise nonlinear mapping function, as shown in equation (1.74), is used to enhance the correlation between features and risks, adapting to the risk-sensitive characteristics of different features. (1.74) in, The first iThe low-risk and high-risk thresholds for each feature were calibrated based on a large amount of sample data. g ( f i ) as a feature f i The nonlinear mapping value normalizes the eigenvalues to [0, 1]. , [1] The interval highlights the differences in characteristics within the risk-sensitive interval. The nonlinear weighted risk score is calculated using formula (1.75), which is used to combine piecewise nonlinear mapping to improve the accuracy of risk assessment. (1.75) A multi-feature coupling compensation term is introduced, and its calculation method is shown in formula (1.76). This term is used to consider the mutual influence between different dynamic features and improve the robustness of the model. (1.76) in, R final For the final risk score, l These are the weighting coefficients of the coupling terms. For the first i The and the first j The coupling coefficients of each feature are used to quantify the impact of interactions between features on risk assessment.
[0108] Final risk score R final Recorded as time-series risk input R t This is used for subsequent time smoothing processing.
[0109] The time smoothing mechanism is mainly used to suppress the fluctuations in risk scores caused by single sampling fluctuations and to ensure the stability of the assessment results. Its processing method is as follows: (1.77) in, For the first t Smoothed risk score at any given time. R t For the first t The original risk score at any given moment. R t-1 For the first t- Smoothed risk score at time 1 β 1 ∈ [0 , [1] is the smoothing coefficient, used to balance real-time performance and stability.
[0110] Based on the smoothed risk score, a graded determination of risk intent is achieved, and the determination criteria are as follows: (1.78) in, Thresholds for risk level classification ( Based on terminal security requirements and sample labeling results, the risk classification is calibrated to ensure its rationality.
[0111] The score cap is used to ensure that the risk score always remains within [0, 1]. , 1] The interval must meet the quantitative evaluation standards: (1.79) Feature contribution is used to quantify the contribution of each dynamic feature to the risk score. Its calculation method is shown in formula (1.80), which can improve the interpretability of the model. (1.80) in, For the first i The risk contribution of each feature, and the feature weight. w i Normalized eigenvalues A positive correlation can intuitively reflect the role of each feature in the current risk assessment.
[0112] The adaptive weight update formula is (1.81), which enables the model to adapt to changes in risk characteristics under different scenarios and improves generalization ability. (1.81) in, For the updated number i Each feature weight, w i For the weights before the update, The learning rate (controls the update step size). This is the weight update amount, which is adaptively adjusted based on the risk assessment error.
[0113] In this application, behavioral intent is not directly defined as a semantic layer concept, but rather as an equivalence class of the dynamic modes of system response under controllable disturbances, with different intents corresponding to different response structural characteristics. Therefore, through the aforementioned risk identification model, the smoothed risk score is... Mapping to the behavioral intent space, thereby achieving the quantitative mapping result of behavioral intent in the secure semantic space.
[0114] In summary, this risk assessment model, through deterministic mapping functions, piecewise nonlinear enhancement, multi-feature coupling modeling, and time smoothing mechanisms, achieves a stable, interpretable, and engineering-applicable method for determining user behavioral risk intent, which can effectively improve terminal security protection capabilities in complex scenarios.
[0115] It is understandable that this application injects a controllable perturbation signal u( t ), and observe the system state response ∆S( t This invention constructs a perturbation-response mapping relationship. This mapping characterizes the system's intrinsic response mechanism to behavior-driven actions, rather than its explicit behavioral patterns. Therefore, even if the surface manifestation of the violation changes, its underlying response characteristics, such as resource scheduling, cache contention, and temporal coupling, are still difficult to completely disguise; different behavior drivers will be mapped to different response matrix structures (such as spectral distribution, nonlinear term strength, etc.). Therefore, this invention can identify unknown behaviors without a prior risk behavior feature library, significantly improving the detection capability of daily user violations and variant violations.
[0116] By actively applying a disturbance, the system is brought into a "controlled stimulus state," where violators cannot predict the disturbance input u( t Therefore, it is impossible to disguise violations as normal daily behavior. Thus, this invention shifts from "behavioral observability" to "response unforgeability," significantly improving the system's ability to resist evasion and disguise. Figure 2 As shown, the normal behavior curve decays rapidly after the initial response, the curve is smooth and without obvious oscillations, and it can quickly enter a steady state, corresponding to a relatively small... f rec The risk behavior curve exhibits a significant response delay, approximately... t≈ 1 . The response only appears after 5 seconds, accompanied by significant oscillations, exhibiting high nonlinear characteristics. f nonlin The system exhibits multiple abnormal peaks triggered by attacks, with slow convergence and prolonged system recovery time. This invention explicitly characterizes the perturbation propagation path by constructing a cross-layer response matrix; extracts cross-layer correlation features to reflect the internal collaborative structure of the system; and utilizes singular value decomposition to extract response directionality, improving discriminative capabilities. Compared to single-layer analysis, this invention can identify deep-level system behavioral pattern differences, thereby significantly improving detection accuracy.
[0117] like Figure 3-Figure 4 As shown, the cross-layer response matrix of normal behavior exhibits diagonal elements (such as perturbations within the computation layer). R cc Internal disturbances of the storage layer R mm The characteristics of elements significantly larger than off-diagonal elements, and cross-layer responses (such as the perturbation response of the computation layer to the storage and network layers). R cm , R cnThe response of the risky behavior is relatively weak, which is consistent with the basic characteristic of "local response dominance" in a stable system. However, the cross-layer response matrix of the risky behavior shows obvious cross-layer enhanced coupling phenomenon (such as Compute → Network). The matrix as a whole presents an asymmetric structure, which reflects the directionality of attack propagation. At the same time, the local response shows abnormal amplification, which reflects abnormal behavior such as resource competition or abnormal scheduling in the system.
[0118] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for identifying cybersecurity risk behaviors and intentions based on controllable perturbations, characterized in that, Specifically, the following steps are included: S1. Actively inject controllable perturbation signals into the resource layer of the terminal system, wherein the amplitude of the controllable perturbation signals satisfies the user-insensible threshold constraint and the controllable perturbation signal components of each resource layer satisfy statistical orthogonality. S2. During the period of controllable perturbation signal, the operating status of each resource layer of the terminal system is synchronously collected based on a unified time reference, and the operating status of each resource layer is processed for time synchronization to generate a system status time series with time alignment relationship. S3. Based on the system state time series, construct a cross-layer perturbation response dynamic model to describe the mapping relationship between the perturbation signal input and the system state response, and extract multi-dimensional dynamic features from the cross-layer perturbation response dynamic model to characterize the amplitude intensity, nonlinearity and recovery capability of the terminal system to the perturbation response. S4. Input the multi-dimensional dynamic features into the trained risk intent recognition model, evaluate and output the risk intent of user behavior.
2. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 1, characterized in that, The process of generating controllable perturbation signals is as follows: Construct time-varying controllable perturbation signal components corresponding to each resource layer. Based on the state characteristics of each resource layer, select the corresponding perturbation signal type for each resource layer, generate controllable perturbation signal components for each resource layer, and combine them into a multidimensional initial controllable perturbation signal vector. Composite constraints are configured for each controllable perturbation signal component of the initial controllable perturbation signal vector to generate a perturbation signal that satisfies multiple constraints. For any two controllable perturbation signal components corresponding to different resource layers in the perturbation signal, a statistical orthogonality constraint is applied so that the mathematical expectation product of any two controllable perturbation signal components approaches zero, and finally a controllable perturbation signal is generated for injection into the terminal system.
3. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 2, characterized in that, Composite constraint configurations include: Amplitude boundary constraint: Based on the device performance and operating status of the terminal system, the threshold that is imperceptible to the user is determined, and an infinite norm constraint is applied to the overall amplitude of the initial controllable perturbation signal vector to limit the maximum amplitude boundary; Load adaptive constraint: Obtain the current normalized load state of the terminal system and dynamically adjust the upper limit of the disturbance amplitude of the controllable perturbation signal component corresponding to each resource layer according to the load state; Discrete random triggering timing constraints: Generate a random triggering time sequence with adjacent triggering time intervals following a uniform distribution within the interval, and configure each controllable perturbation signal component as a discrete perturbation pulse sequence that is triggered sequentially according to the random triggering time sequence.
4. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 2, characterized in that, The specific process of actively injecting controllable perturbation signals is as follows: Construct a perturbation mapping function that satisfies equivalence constraints and perturbation constraints, and map the controllable perturbation signal components corresponding to each resource layer in the controllable perturbation signal to the small control variable offsets of each resource layer in the terminal system in the scheduling critical path. Obtain a preset unified scheduling clock sequence, and synchronously trigger a disturbance injection operation at each moment of the unified scheduling clock sequence, and synchronously inject the small control variable offsets corresponding to each resource layer into the scheduling critical path corresponding to each resource layer.
5. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 4, characterized in that, The process of actively injecting controllable perturbation signals also includes: During the synchronous execution of the disturbance injection operation, the statistical distribution of the system behavior of the acquisition terminal system under the disturbance is collected. The difference between the statistical distribution of the computing system's behavior and the probability distribution of the terminal system's behavior under undisturbed natural operating conditions; Determine whether the distribution difference meets the preset upper bound constraint of statistical indistinguishability. If it does, the disturbance is determined to be concealed; otherwise, adjust the mapping parameters of the disturbance mapping function to reduce the distribution difference.
6. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 4, characterized in that, The resource layer includes the computing layer, storage layer, I / O layer, and network layer. The specific process of the perturbation injection operation is as follows: For the computing layer, the corresponding small control variable offset is mapped to the time slice offset of the terminal system's central processing unit scheduler. The time slice offset is superimposed with the original time slice of the central processing unit scheduler to generate the perturbed time slice allocation value and write it into the central processing unit scheduler. For the storage layer, the corresponding small control variable offsets are mapped to an ordered access sequence of auxiliary memory. The perturbation access bandwidth is determined based on the ordered access sequence, and controlled cache conflicts are introduced by performing auxiliary memory access constrained by the perturbation access bandwidth. For the I / O layer, the corresponding small control variable offset is mapped to the actual waiting time perturbation. The number of virtual requests to be inserted into the I / O request queue is determined based on the actual waiting time perturbation. The set of virtual requests is inserted into the actual original request set of the I / O layer to generate the perturbed I / O request set. For the network layer, the corresponding small control variable offsets are mapped to delay offsets and transmission time offsets, which are then superimposed on the original round-trip delay value and the original data packet transmission time, respectively, to generate a perturbed round-trip delay to change the timing characteristics of network communication.
7. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 1, characterized in that, The modeling process for the cross-layer disturbance response dynamics model is as follows: When the terminal system is in a steady-state operating point, a dual-window synchronous sampling mechanism is constructed to collect the first system state increment within the undisturbed reference window and the second system state increment within the disturbed detection window at each sampling time. The first system state increment and the second system state increment are calculated based on the system state time series. The difference operation is performed between the second system state increment and the first system state increment to obtain the pure disturbance response increment. The pure perturbation response increments at each sampling time and the controllable perturbation signals actively injected at the corresponding time are stacked to form the output matrix and the input matrix, respectively. The system disturbance response matrix is estimated using the least squares estimation method based on the input and output matrices. The system disturbance response matrix is represented by blocks according to the affected target resource layer and the source resource layer of the disturbance injection, forming a cross-layer response block matrix, which fully describes the disturbance transmission relationship within and between each resource layer, and completes the modeling of the cross-layer disturbance response dynamic model.
8. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 7, characterized in that, The modeling process for the cross-layer disturbance response dynamics model also includes the following steps: Obtain the controllable perturbation signal corresponding to the historical sampling time, introduce the discrete time delay order into the second system state increment, and construct the time delay extension model based on the controllable perturbation signal corresponding to the historical sampling time and the system perturbation response matrix; The tensor product term of the controllable perturbation signal corresponding to the current sampling time is used as the extended input, and together with the first-order linear term, an extended regression model is constructed. The extended regression model is then fitted and solved to obtain the higher-order dynamic parameters. The state increment vector of the second system is obtained by applying time delay expansion and nonlinear compensation to the state increment of the second system using the time delay expansion model and the extended regression model, respectively. The second system state increment vectors processed by the time delay expansion model and the extended regression model at each sampling time are spliced together in time sequence to generate the system dynamic response trajectory. The cross-layer response block matrix, the system dynamic response trajectory, and higher-order dynamic parameters are used together as the output of the cross-layer disturbance response dynamic model.
9. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 8, characterized in that, Multidimensional dynamic features include response intensity features, nonlinear amplification factor, recovery time features, cross-layer consistency features, frequency domain response features, response directionality features, information entropy features, and stability features. The extraction process of dynamic features is as follows: Obtain the second system state increment vector at each sampling time from the system dynamic response trajectory; calculate the L2 norm of the second system state increment vector at each sampling time, and take the mean of the L2 norms at all sampling times, and use the mean as the response intensity feature; By using sparse constraints to compress higher-order dynamic parameters, the nonlinear amplification coefficient characteristics are obtained. The single recovery time of the terminal system to the steady-state operating point after each controlled perturbation signal injection is calculated, and the mathematical expectation of the single recovery time after multiple controlled perturbation signal injections is obtained to obtain the recovery time characteristics. Extract the system state time series corresponding to each resource layer; calculate the inter-layer correlation coefficient between any two system state time series of different resource layers; sum the absolute values of all inter-layer correlation coefficients to obtain the cross-layer consistency characteristics; Perform a discrete Fourier transform on the second system state increment vector at each sampling time to obtain the frequency domain representation of the state increment sequence; calculate the proportion of the sum of the energy spectra of the frequency domain representations of all high-frequency bands to the total sum of the energy spectra of the entire frequency band to obtain the frequency domain response characteristics; Singular value decomposition is performed on the system disturbance response matrix to obtain all singular values; the ratio of the largest singular value to the sum of all singular values is calculated to obtain the response directionality characteristics. Based on the second system state increment vector, the response energy ratio of each state variable is calculated, and the information entropy is calculated based on the response energy ratio to obtain the information entropy feature; The spectral radius of the system's disturbance response matrix is calculated to obtain the stability characteristics.
10. The method for identifying network security risk behavior intent based on controllable perturbation according to claim 8, characterized in that, The specific process of S4 is as follows: The multi-dimensional dynamic features are normalized to obtain the feature vector; The feature vector is mapped to a preset quantization interval by a piecewise nonlinear mapping function to obtain a quantized risk score; The quantitative risk scores are weighted and summed, and a feature coupling compensation term is added to obtain the original risk score. The original risk score is subjected to time smoothing to obtain a smoothed risk score. The smoothed risk score is compared with the preset risk level threshold, and the risk intent determination result is output.