An access agent identification system and method based on interaction behavior analysis

CN122414210BActive Publication Date: 2026-09-25BEIJING TRUSFORT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610864815.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-06-16
Publication Date
2026-09-25
Estimated Expiration
2046-06-16

AI Technical Summary

Technical Problem

然而,随着自动化技术的进步,高级脚本能够模拟人类的表层交互行为,使得基于简单规则或孤立操作统计的检测方法准确率大幅下降

Benefits of technology

1.传统方法通常依赖大量已标记操作实体类型的历史数据来训练监督模型,数据获取与标注成本高昂。本发明无需对历史会话进行任何人工标记,直接利用未区分操作实体的历史事件序列构建历史行为特征向量群,并通过计算当前行为特征向量在其中的离群深度来判定操作实体类型,实现了无监督的实时识别,从而显著降低了前期数据准备的开销。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122414210B_ABST
    Figure CN122414210B_ABST
Patent Text Reader

Abstract

The application discloses an access agent identification system and method based on interactive behavior analysis, and relates to the technical field of Internet security; the method comprises the following steps: obtaining a historical event sequence of a historical session of an operation entity which is not distinguished, extracting a historical event category label sequence and a historical event timestamp sequence; constructing a directed transition graph based on the historical event category label sequence, and extracting a historical structure channel feature; calculating a historical event time interval sequence and a historical event rate density signal based on the historical event timestamp sequence, and extracting a historical rhythm channel feature; synthesizing a historical behavior fingerprint vector and forming a historical vector group; extracting a current behavior fingerprint vector for a current session; calculating an outlier depth by using Mahalanobis distance based on a median vector and a median absolute deviation of the historical vector group, and determining whether the operation entity is a human or an automated intelligent agent; the application does not depend on operation content and identity information, and solves the human-computer discrimination problem of unannotated data under the premise of protecting privacy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet security technology, specifically to an access agent identification system and method based on interactive behavior analysis. Background Technology

[0002] Traditional methods for identifying operational entities typically rely on CAPTCHAs, frequency statistics, or single behavioral features to distinguish between humans and automated agents. However, with advancements in automation technology, advanced scripts can simulate surface-level human interactions, significantly reducing the accuracy of detection methods based on simple rules or isolated operational statistics. Existing technologies generally ignore the deep structural patterns inherent in operational sequences, such as the distribution of dwell times in different interface states and the transition patterns between states, leading to high false negatives and false positives in the identification of automated agents.

[0003] To address these issues, some solutions attempt to introduce supervised learning or user behavior profiling. However, these methods typically require large amounts of historical data with labeled operation entity types, which is costly to obtain in practical applications. Furthermore, these methods often treat operation events in isolation, lacking a contextual semantic understanding of the attributes of the interface elements where the operation is focused and the interactive effects triggered by the operation. This limits the model's ability to discriminate when dealing with automated programs that simulate human behavior.

[0004] Therefore, a method is needed that does not require pre-labeling of operation entity types, can classify the original operation into a finite state with semantic meaning based on the page meta-attributes and interaction meta-attributes at the time of the operation, and extract multi-dimensional features reflecting dwell distribution, state transition orderliness and local pattern complexity from the operation sequence, and then identify automated intelligent agents whose behavior patterns deviate significantly from the normal distribution of humans through unsupervised outlier detection. Summary of the Invention

[0005] The purpose of this invention is to provide an access agent recognition system and method based on interactive behavior analysis to solve the problems raised in the prior art.

[0006] To achieve the above objectives, the present invention provides the following technical solution: an access agent recognition system and method based on interactive behavior analysis. The methods include: Step S1: Obtain historical event sequences of several historical sessions without distinguishing operation entities, and extract event category tag sequences from each event sequence; the event category tags are obtained by classifying the original operation types in each historical event sequence based on the page meta attributes of the interface where the operation entity is located and the interaction meta attributes of the operation behavior. Step S2: For each historical event category label sequence, calculate the historical residence morphology entropy, historical transition orderliness, and historical local transfer mode entropy respectively, and combine them into a historical behavior feature vector; gather the historical behavior feature vectors corresponding to all historical event category label sequences to form a historical behavior feature vector group; Step S3: Obtain the current event sequence generated by the operation entity in the current session, extract the current event category label sequence from the current event sequence, calculate the current dwell mode entropy, current transition orderliness and current local transition mode entropy in the same way as in step S2, and combine them into the current behavior feature vector; Step S4: Calculate the outlier depth of the current behavior feature vector in the historical behavior feature vector group described in step S2; when the outlier depth is greater than or equal to a preset judgment threshold, determine that the current operating entity is an automated intelligent agent and trigger risk handling operation; when the outlier depth is less than the preset judgment threshold, determine that the current operating entity is a human and process it as normal business interaction.

[0007] Furthermore, step S1 includes: Step S1-1: Obtain the historical event sequence of several historical sessions without distinguishing the operation entities, denoted as E={E1,E2,…,E...} i ,…,E I}, where E1, E2, ..., E i ,…,E I Let E represent the 1st, 2nd, ..., i-th, ..., 1st historical event sequences, respectively. For the i-th historical event sequence E... i E i ={e i,1 ,e i,2 ,…,e i,j ,…,e i,J}, where e i,1 ,e i,2 ,…,e i,j ,…,e i,J Let represent the 1st, 2nd, ..., jth, ..., Jth historical event records in the i-th historical event sequence, respectively; where e is the j-th historical event record in the i-th historical event sequence. i,j Includes historical primitive operation type a i,j ; Step S1-2: Record e for the j-th historical event in the i-th historical event sequence. i,j Extract the j-th historical event record e from the i-th historical event sequence. i,j The set of interface meta-attributes A in the i-th historical event sequence when the operation occurs. i,j and the j-th interactive meta-attribute set B in the i-th historical event sequence i,jThe set of interface meta-attributes A in the i-th historical event sequence. i,j This includes the input control type identifier and the non-input content display area identifier in the area where the focus is located; wherein, the focus refers to the area where the cursor of the operating entity is located in the current interface; and the j-th interactive meta-attribute set B in the i-th historical event sequence. i,j This includes a first flag indicating whether an operation triggers a keystroke event, a second flag indicating whether an operation triggers a page jump, and a third flag indicating whether an operation triggers a content deletion or replacement operation. Step S1-3: Record the j-th historical event in the i-th historical event sequence as e. i,j primitive operation type a i,j With the j-th interface meta-attribute set A in the i-th historical event sequence i,j The set of interactive meta-attributes B in the i-th historical event sequence. i,j By matching and classifying, the j-th historical event record e in the i-th historical event sequence is obtained. i,j Corresponding category tag c i,j All categories are marked with c i The historical event category label sequence is formed by arranging historical events in chronological order; the matching determines the j-th historical event record e in the i-th historical event sequence in the following manner. i,j Corresponding category tag c i,j : When the first flag indicates no keystroke event, the second flag indicates no page jump, and the j-th interface meta-attribute set A in the i-th historical event sequence... i,j When the focus area in the c is a non-input content display area, i,j Mark the browsing status; When the first flag indicates the existence of a keystroke event, and the j-th interface meta-attribute set A in the i-th historical event sequence... i,j When the focus area is within the input control, c i,j Input status flag; When the third flag indicates that a content deletion or replacement operation has been triggered, and the j-th interface meta-attribute set A is in the i-th historical event sequence... i,j When the focus area in the c is within an input control that already contains content, i,j To modify the status flag; When the second flag indicates a page redirect or the third flag indicates a transaction termination operation, c i,j For the submission status flag; Step S1-4: Denote the historical event category label sequence of the i-th historical event sequence obtained by classification as C. i,hist ={c i,1 ,c i,2 ,…,ci,j ,…,c i,J}, where c i,1 ,c i,2 ,…,c i,j ,…,c i,J Represent the category labels corresponding to the 1st, 2nd, ..., jth, ..., Jth historical event records in the i-th historical event sequence, respectively; output C i,hist .

[0008] Furthermore, step S2 includes: Step S2-1: For the historical event category label sequence C of the i-th historical event sequence i,hist The historical event category label sequence C of the i-th historical event sequence is... i,hist The system is segmented based on consecutive identical markers to obtain several historical residency segments. Each historical residency segment contains a marker category and the number of consecutive occurrences of that marker category, which serves as the segment length. The lengths of all historical residency segments corresponding to the browsing, input, modification, and submit status markers are counted separately to obtain the set of historical residency segment lengths for each marker category, L. i ={L i,browse ,L i,input ,L i,modify ,L i,submit}, where L i,browse ,L i,input ,L i,modify ,L i,submit These represent the length values ​​of each historical segment under the browsing status flag, input status flag, modified status flag, and submitted status flag, respectively. Step S2-2: For the historical event category label sequence C of the i-th historical event sequence i,hist For any given tag category, discretize the elements in the historical dwell segment length set of that tag category according to a preset length interval division method, and statistically analyze the proportion of dwell segments within each length interval to form a probability distribution of the dwell segment length for any tag category, denoted as P. i,cat (r), where cat∈{browse,input,modify,submit}, and r is the length interval index; calculate the Shannon entropy of the probability distribution as the resident distribution entropy for any labeled category, denoted as . The historical residence morphology entropy of the historical event category label sequence for the i-th historical event sequence is obtained by weighting the residence distribution entropy of any label category according to the proportion of the number of residence segments of any label category to the total number of residence segments. This entropy is denoted as H. i,dwell =(N i,browse ×H i,browse +N i,input ×H i,input +Ni,modify ×H i,modify +N i,submit ×H i,submit ) / (N browse + N input +N modify +N submit ), where N i,browse N i,input N i,modify N i,submit These represent the total number of segments residing in the browsing tag category, input tag category, modification tag category, and submission tag category of the historical event category tag sequence for the i-th historical event sequence, respectively. Step S2-3: Arrange the browse status marker, input status marker, modification status marker, and submit status marker in a preset cyclical order, specifically browse, input, modify, submit, browse. The forward adjacent category marker for each category marker refers to the next category marker in the positive direction of the cyclical order, and the backward adjacent category marker refers to the next category marker in the negative direction. To achieve quantitative determination of the transition direction, these four markers are mapped to four points in a two-dimensional plane, and these four points are connected in a counter-clockwise direction to form a convex quadrilateral. This determines the next marker in the counter-clockwise and clockwise directions on the convex quadrilateral for each marker. Traverse the historical event category marker sequence C of the i-th historical event sequence. i,hist The position pairs of all adjacent historical event records in the set, the position pairs of the j-th and j+1-th historical event records are denoted as (c j ,c j+1 If c j ≠c j+1 Then, a transition is recorded, with the starting marker being c. j The termination marker is c j+1 The transition sequence is obtained sequentially and denoted as T. i =[(b1,d1),(b2,d2),…,(b z ,d z ),...,(b Z ,d Z ]], where (b1,d1), (b2,d2), ..., (b z ,d z ),...,(b Z ,d Z ) represent the start and end markers of the 1st, 2nd, ..., zth, ..., Zth transitions, respectively; for the zth transition, the coordinates (f) of the start marker are obtained according to the preset two-dimensional coordinate mapping rule. z,x ,f z,y ) and the coordinates of the termination marker (h) z,x ,hz,y ), calculate the coordinate difference Δx z =h z,x -f z,x Δy z =h z,y -f z,y If |Δx z |+|Δy z |=1, and Δx z with Δy z If one is 0 and the other is ±1, then further determination is needed if Δx z =1 or Δy z =1, then the z-th transition is determined to be a forward transition; if Δx z =-1 or Δy z =-1, then the z-th transition is determined to be a backward transition; if |Δx z |+|Δy z If |≠1, then the z-th transition is determined to be a jump transition; count the number of forward transitions F, the number of backward transitions R, and the number of jump transitions Q for all transitions, and F+R+Q=Z; define the order of historical transitions in the i-th historical event sequence as: Order i =(FR) / Z, where Z>0, and when Z=0, Order i =0; Step S2-4: From the historical event category label sequence C of the i-th historical event sequence i,hist Extract all triplet subsequences consisting of three consecutive labels, denoted as G. i,q =(c q ,c q+1 ,c q+2 ), where q=1,2,…,J-2, and J is the historical event category label sequence C of the i-th historical event sequence. i,hist The length of the triplet pattern; the frequency of occurrence of all different triplet patterns is counted to obtain the probability distribution P(g); the triplet pattern entropy is calculated. Normalize the triplet pattern entropy to obtain the historical local transition pattern entropy of the historical event category label sequence of the i-th historical event sequence. ; Step S2-5: Assign the historical event category label sequence to the historical resident morphological entropy H of the i-th historical event sequence obtained in step S2-2. i,dwell The order of historical transitions in the historical event category label sequence of the i-th historical event sequence obtained in steps S2-3. i The historical local transition mode entropy M of the historical event category label sequence of the i-th historical event sequence obtained in steps S2-4 i Together they form a historical behavior feature vector, denoted as X. i =(Hi,dwell Order i M i The historical behavior feature vectors corresponding to all I historical event sequences are aggregated to form a historical behavior feature vector group X. i,hist ={X1,X2,…,X i ,…,X I}, where X1, X2, ..., X i ,…,X I These represent the historical behavioral feature vectors of the 1st, 2nd, ..., ith, ..., 1st historical event sequences, respectively.

[0009] Furthermore, step S3 includes: Step S3-1: Obtain the current event sequence generated by the operation entity in the current session, denoted as E. cur ={e cur,1 ,e cur,2 ,…,e cur,s ,…,e cur,S}, where e cur,1 ,e cur,2 ,…,e cur,s ,…,e cur,S These represent the 1st, 2nd, ..., sth, ..., Sth current event records in the current event sequence, arranged chronologically; the sth current event record e cur,s Includes the current primitive operation type a cur,s ; Step S3-2: Following the methods of steps S1-2 to S1-4, process the current event sequence E. cur Processing yields the current event category label sequence C. cur ={c cur,1 ,c cur,2 ,…,c cur,s ,…,c cur,S}, where c cur,1 ,c cur,2 ,…,c cur,s ,…,c cur,S These represent the category labels corresponding to the 1st, 2nd, ..., sth, ..., Sth current event records in the current event sequence, respectively. Step S3-3: Calculate the current resident morphological entropy of the current event category label sequence according to the methods of steps S2-1 to S2-2, denoted as H. cur,dwell Calculate the current transition order of the current event category label sequence according to the method in steps S2-3, denoted as Order. cur Calculate the current transition mode entropy of the current event category label sequence according to the method in steps S2-4, denoted as M. cur ; Step S3-4: Assign the current resident morphological entropy H of the current event category label sequence. cur,dwell The current transition order of the current event category label sequence. cur The current transition mode entropy M of the current event category label sequence cur The combination forms the current behavior feature vector, denoted as X. cur =(H cur,dwell Order cur M cur ).

[0010] Furthermore, step S4 includes: Step S4-1: For the historical behavior feature vector group X obtained in step S2-5 i,hist ={X1,X2,…,X i ,…,X I}, where the historical behavior feature vector X of the i-th historical event sequence. i =(H i,dwell Order i M i () is a three-dimensional vector, whose three components correspond to the historical residence morphology entropy, historical transition orderliness, and historical local transfer mode entropy of the i-th historical event sequence, respectively; calculate the historical behavior feature vector X of the i-th historical event sequence. i The historical behavior feature vector X of the j-th historical event sequence j The Euclidean distance between them For the historical behavior feature vector of the i-th historical event sequence, calculate the Euclidean distance between the historical behavior feature vector of the i-th historical event sequence and the historical behavior feature vectors of the other I-1 historical event sequences. Sort the calculated Euclidean distances from smallest to largest, and select the distance value at the k-th position after sorting as the k-nearest neighbor distance of the vector, denoted as d. k (X i ), where k is a preset neighborhood parameter; the nearest neighbor distances of the historical behavior feature vectors of all historical event sequences are calculated to form the nearest neighbor distance set D. hist ={d k (X1),d k (X2),…,d k (X i ),…,d k (X I )}, where d k (X1),d k (X2),…,d k (X i ),…,d k (X I) represent the k-nearest neighbor distances of the historical behavior feature vectors of the 1st, 2nd, ..., ith, ..., ith historical event sequences, respectively; Step S4-2: Set the nearest neighbor distances D hist Sort the elements in ascending order and take the first one. The number of elements is used as the distance threshold T, where α is the preset quantile ratio. Indicates rounding up; Step S4-3: For the current behavior feature vector X of the current event category label sequence obtained in step S3-4 cur =(H cur,dwell Order cur M cur ), calculate the current behavior feature vector X of the current event category label sequence. cur The Euclidean distance between the historical behavior feature vector and the historical behavior feature vector of the i-th historical event sequence in the historical behavior feature vector group: The minimum value among them is taken as the outlier depth of the current behavior feature vector, denoted as . ; Step S4-4: d min Compared with the threshold T, if d min If the value is >T, the current operating entity is determined to be an automated intelligent agent, and a risk handling operation is triggered; otherwise, it is determined to be a human and processed as a normal business interaction.

[0011] The system includes: a data acquisition module, a historical feature construction module, a current feature extraction module, and an outlier detection and judgment module; The data acquisition module is used to acquire historical session event sequences that do not distinguish between operational entities and extract event category tag sequences from them; The historical feature construction module is used to calculate the resident morphology entropy, transition orderliness, and local transition mode entropy of the label sequence of each historical event category, and combine them into a group of historical behavior feature vectors. The current feature extraction module is used to obtain the current event sequence and calculate the current resident morphology entropy, current transition orderliness and current local transition mode entropy in the same way as the historical feature construction module, and combine them into the current behavior feature vector; The outlier detection and determination module is used to calculate the outlier depth of the current behavior feature vector in the historical behavior feature vector group and compare it with a threshold to determine the type of the operation entity.

[0012] The data acquisition module includes: The event sequence acquisition unit is used to acquire the event sequence and original operation type of each historical session; The meta-attribute extraction unit is used to extract the set of interface meta-attributes and the set of interaction meta-attributes for each event record; The classification and matching unit is used to classify the original operation type into four tags: browse, input, modify, and submit according to preset rules; The sequence output unit is used to output the historical event category tag sequence for each historical event sequence.

[0013] The historical features building module includes: The residence segment segmentation unit is used to divide the sequence into residence segments according to consecutive identical labels and to count the residence segment length for each label category; The dwell morphology entropy calculation unit is used to discretize the dwell length and calculate the historical dwell morphology entropy by weighting. The jump order calculation unit is used to calculate the historical jump order based on coordinate mapping and jump direction. The local transition pattern entropy calculation unit is used to statistically analyze triplet patterns and calculate the normalized historical local transition pattern entropy. The historical vector synthesis unit is used to combine three-dimensional feature vectors and aggregate them into a group of historical behavior feature vectors.

[0014] The current feature extraction module includes: The current data acquisition unit is used to acquire the current event sequence of the current session; The current classification processing unit is used to classify the current event sequence to obtain the current event category label sequence; The current feature calculation unit is used to calculate the current residence morphology entropy, the current transition order, and the current local transition mode entropy. The current vector synthesis unit is used to combine the three current features into the current behavior feature vector.

[0015] The outlier detection and judgment module includes: The nearest neighbor distance calculation unit is used to calculate the Euclidean distance between each historical vector and other vectors. It takes the distances in a specified order according to the preset neighborhood parameters as the nearest neighbor distances of the vector, and forms a nearest neighbor distance set. The threshold calculation unit is used to sort the nearest neighbor distance set from smallest to largest and take the element at the sorting position corresponding to the preset quantile ratio as the distance threshold. The minimum distance calculation unit is used to calculate the minimum distance from the current vector to the historical vectors as the outlier depth; The comparison and determination unit is used to compare the outlier depth with a threshold and determine whether it is an automated intelligent agent or a human.

[0016] Compared with the prior art, the beneficial effects of the present invention are: 1. Traditional methods typically rely on large amounts of historical data with labeled operation entity types to train supervised models, resulting in high costs for data acquisition and labeling. This invention eliminates the need for any manual labeling of historical sessions. It directly utilizes historical event sequences without distinguishing operation entities to construct a group of historical behavioral feature vectors, and determines the operation entity type by calculating the outlier depth of the current behavioral feature vector within it. This achieves unsupervised real-time recognition, significantly reducing the overhead of preliminary data preparation.

[0017] 2. Traditional methods often analyze the original operation type in isolation, ignoring the interface context and interaction results, leading to the loss of semantic information. This invention, based on the interface meta-attributes and interaction meta-attributes of the focal area, classifies the original operation into four types of event-labeled sequences with clear semantics: browsing, input, modification, and submission. This allows the subsequently extracted dwell morphology entropy, transition orderliness, and local transition mode entropy to truly reflect the intention and behavior pattern of the operation entity within the interface, thereby improving the accuracy of the behavioral feature vector representation.

[0018] 3. Traditional methods rely on single-dimensional behavioral statistics, making it difficult to distinguish automated scripts that simulate surface-level human interactions. This invention constructs behavioral feature vectors from three orthogonal dimensions: residence distribution entropy, transition orderliness, and local transition pattern entropy. This simultaneously captures the residence fluctuations, natural transition patterns, and local sequence pattern complexity unique to human operations. Because the distribution of automated agents in these dimensions differs significantly from that of humans, the outlier depth of their current behavioral feature vector within the historical behavioral feature vector group will be significantly greater than a preset threshold. This enables high-precision identification of automated agents without the need for labeled data and timely triggering of risk management actions. Attached Figure Description

[0019] Figure 1 This is a flowchart illustrating an access agent identification method based on interactive behavior analysis according to the present invention. Figure 2 This is a schematic diagram of the structure of an access agent recognition system based on interactive behavior analysis according to the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Example: Figures 1-2 As shown, the present invention provides a technical solution: an access agent recognition system and method based on interactive behavior analysis. The methods include: Step S1: Obtain historical event sequences of several historical sessions without distinguishing operation entities, and extract event category tag sequences from each event sequence; the event category tags are obtained by classifying the original operation types in each historical event sequence based on the page meta attributes of the interface where the operation entity is located and the interaction meta attributes of the operation behavior. Step S1-1: Obtain the historical event sequences of 6 historical sessions without distinguishing operation entities, denoted as E={E1,E2,E3,E4,E5,E6}, I=6; for the first historical event sequence E1, E1={e 1,1 ,e 1,2 ,e 1,3 ,e 1,4 ,e 1,5 ,e 1,6 ,e 1,7}, J=7, each historical event record contains the historical original operation type; e 1,1 Includes the historical original operation type "Browse product list"; e 1,2 Includes the original historical operation type "Enter keywords in the search box"; e 1,3 Includes the historical original operation type "Browse search results"; e 1,4 Includes the original historical operation type "Click on product details"; e 1,5 Includes the historical original operation type "Return Search Results"; e 1,6 Includes the historical original operation type "Modify search keywords"; e 1,7 Includes the original historical operation type "Click to submit order"; Step S1-2: Extract the interface meta-attribute set and the interaction meta-attribute set for each event record in the first historical event sequence; the interface meta-attribute set includes the input control type identifier of the focus and the non-input content display area identifier, where the focus refers to the area where the cursor or touch point of the operation entity is located in the current interface. The interaction meta-attribute set includes a first flag indicating whether the operation triggers a keystroke event, a second flag indicating whether the operation triggers a page jump, and a third flag indicating whether the operation triggers a content deletion or replacement operation; For e 1,1 The original operation type was "Browse Product List", and the interface meta-attribute set A 1,1 The central focus is the "non-input content display area"; the interactive meta-attribute set B. 1,1 The first flag indicates no keystroke event, the second flag indicates no page redirection, and the third flag indicates no content deletion or replacement operation. For e 1,2 The original operation type in the history is "Enter keywords in the search box", and the interface meta-attribute set A is...1,2 The focus is "within the input control"; the interactive meta-attribute set B 1,2 The first flag indicates that a keystroke event has occurred; the second flag indicates that no page redirection has occurred; and the third flag indicates that no content deletion or replacement operation has occurred. For e 1,3 The original historical operation type was "Browse search results," and the interface meta-attribute set A was used. 1,3 The central focus is the "non-input content display area"; the interactive meta-attribute set B. 1,3 The first flag indicates no keystroke event, the second flag indicates no page redirection, and the third flag indicates no content deletion or replacement operation. For e 1,4 The original historical operation type was "Click on product details," and the interface meta-attribute set A was used. 1,4 The central focus is the "non-input content display area"; the interactive meta-attribute set B. 1,4 The first flag indicates that a keystroke event has occurred, the second flag indicates that a page redirect has been triggered, and the third flag indicates that no content has been deleted or replaced. For e 1,5 The original historical operation type is "Return to search results", and the interface meta-attribute set A is... 1,5 The central focus is the "non-input content display area"; the interactive meta-attribute set B. 1,5 The first flag indicates that a keystroke event has occurred, the second flag indicates that a page redirect has been triggered, and the third flag indicates that no content has been deleted or replaced. For e 1,6 The original operation type was "Modify search keywords", and the interface meta-attribute set A was used. 1,6 The focus is "within an input control that already contains content"; the interactive meta-attribute set B 1,6 The first flag indicates that a keystroke event has occurred, the second flag indicates that no page redirection has occurred, and the third flag indicates that a content deletion or replacement operation has been triggered. For e 1,7 The original historical operation type was "Click to submit order," and the interface meta-attribute set A is... 1,7 The central focus is the "Submit button area"; the interactive meta-attribute set B. 1,7 The first flag indicates the presence of a keystroke event, the second flag indicates that a page redirect has been triggered, and the third flag indicates that a transaction has been terminated. Steps S1-3: Match the original operation type of each event record with the set of interface meta-attributes and the set of interaction meta-attributes to obtain category labels: c 1,1 The first indicator indicates no keystrokes, the second indicates no navigation, and the third indicates no deletion / replacement. Furthermore, the focus is on an area where the input content is not displayed. Based on the matching rules, this is determined to be a browsing status marker. c 1,2The first indicator is that a key has been pressed and the focus is within the input control. According to the matching rules, this is determined to be an input status marker. c 1,3 No keystrokes, no navigation, no deletion / replacement, and the focus is on an area where no input content is displayed; this is considered a browsing status indicator. c 1,4 If there are keystrokes, navigation, but no deletion / replacement, and the focus is on an area where no input content is displayed, it is considered a browsing status marker. c 1,5 If there are keystrokes, navigation, but no deletion / replacement, and the focus is on an area where no input content is displayed, it is considered a browsing status marker. c 1,6 If there are keystrokes, no jump, deletion / replacement, and the focus is on an input control with existing content, it is determined to be a modified status. c 1,7 If there are keystrokes, jumps, or transaction termination operations, it is determined to be a committed status. Similarly, the same extraction, matching, and classification are performed on the 2nd to 6th historical event sequences; Step S1-4: Obtain the category label sequence for each historical event sequence; The first historical event sequence: C 1,hist ={c 1,1 ,c 1,2 ,c 1,3 ,c 1,4 ,c 1,5 ,c 1,6 ,c 1,7 = {Browse, Input, Browse, Browse, Browse, Modify, Submit}; Similarly, the category label sequence for the second historical event sequence is obtained; C 2,hist ={c 2,1 ,c 2,2 ,c 2,3 ,c 2,4 ,c 2,5 ,c 2,6 ,c 2,7 ,c 2,8 = {Browse, Input, Browse, Modify, Browse, Input, Browse, Submit}; Similarly, the category label sequence for the third historical event sequence is obtained; C 3,hist ={c 3,1 ,c 3,2 ,c 3,3 ,c 3,4 ,c 3,5 ,c 3,6 ,c 3,7= {Browse, Browse, Input, Browse, Modify, Browse, Submit}; Similarly, the category label sequence for the fourth historical event sequence is obtained; C 4,hist ={c 4,1 ,c 4,2 ,c 4,3 ,c 4,4 ,c 4,5 ,c 4,6 ,c 4,7 = {Browse, Browse, Input, Browse, Browse, Modify, Submit}; Similarly, the category label sequence for the 5th historical event sequence is obtained; C 5,hist ={c 5,1 ,c 5,2 ,c 5,3 ,c 5,4 ,c 5,5 ,c 5,6 ,c 5,7 = {Browse, Input, Browse, Browse, Input, Modify, Browse, Submit}; Similarly, the category label sequence for the 6th historical event sequence is obtained; C 6,hist ={c 6,1 ,c 6,2 ,c 6,3 ,c 6,4 ,c 6,5 ,c 6,6 = {Browse, Input, Modify, Browse, Browse, Submit}.

[0022] Step S2: For each historical event category label sequence, calculate the historical residence morphology entropy, historical transition orderliness, and historical local transfer mode entropy respectively, and combine them into a historical behavior feature vector; gather the historical behavior feature vectors corresponding to all historical event category label sequences to form a historical behavior feature vector group; Step S2-1: Label sequence C with the historical event category of the first historical event sequence. 1,hist , will C 1,hist The segmentation is performed based on consecutive identical markers, and the segmentation results are as follows: The first resident segment is the browsing status marker at position 1, and this segment has a length of 1; The second dwell segment is the input status flag at position 2, and this segment has a length of 1. The third dwell segment is the browsing status marker at positions 3 to 5, and this segment is 3 units long; The fourth stationary segment is the modified status marker at position 6, and this segment has a length of 1. The fifth stationary segment is the commit status flag at position 7, and this segment has a length of 1. Calculate the length of all dwell segments under each marker category: The dwell time lengths under the browsing status markers are 1 and 3; The dwell segment length under the input status flag is: 1; The length of the resident segment under the status flag can be modified as follows: 1; The length of the segment remaining under the commit status flag is: 1; Step S2-2: The preset length intervals are: interval 1 corresponds to length 1, interval 2 corresponds to length 2, interval 3 corresponds to length 3, and interval 4 corresponds to length greater than or equal to 4. Calculate the dwell length probability distribution for each tag category: For browsing status markers: length 1 accounts for 1 / 2, length 3 accounts for 1 / 2, and the remaining intervals account for 0%; its dwell distribution entropy is... ; For the input state label: only length 1, probability 1, entropy ; For modifying the state flag: only length 1, entropy H 1,modify =0; For the commit status flag: only length 1, entropy H 1,submit =0; The total number of segments residing in each marker category is as follows: N 1,browse =2, N 1,input =1, N 1,modify =1, N 1,submit =1, the total number of residence segments is 5; the weighted average yields the historical residence morphological entropy: H 1,dwell =(2×1+1×0+1×0+1×0) / 5=0.4; Step S2-3: Map browse, input, modify, and submit to four points in a two-dimensional plane, and connect these four points in a counter-clockwise direction to form a convex quadrilateral; specifically, browse corresponds to coordinates (0,0), input to (1,0), modify to (1,1), and submit to (0,1); thus determine the next counter-clockwise and clockwise markers on the convex quadrilateral for each marker. The next counter-clockwise marker for browse is input, and the next clockwise marker is submit; iterate through C... 1,hist For each pair of adjacent positions, if the labels are different, record a transition; the resulting transition sequence contains 4 transitions. First jump: Start marker is browse, end marker is input; start coordinates (0,0), end coordinates (1,0), calculate Δx1=1, Δy1=0; because |Δx1|+|Δy1|=1 and Δx1=1, the first jump is determined to be a forward jump; Second transition: Start marker is input, end marker is browsing; start (1,0), end (0,0), Δx2=-1, Δy2=0, |Δx2|+|Δy2|=1 and Δx2=-1, the second transition is determined to be a back transition; The third jump: the starting marker is browsing, and the ending marker is modification; the starting point is (0,0), the ending point is (1,1), Δx3=1, Δy3=1, |Δx3|+|Δy3|=2≠1, so the third jump is determined to be a jump jump; 4th jump: The start marker is modified, and the end marker is committed; the start is (1,1), the end is (0,1), Δx4=-1, Δy4=0, which is determined to be a back jump; The number of forward transitions is F=1, the number of backward transitions is R=2, the number of jump transitions is Q=1, and the total number of transitions is Z=4; the order of historical transitions is Order1=(FR) / Z=(1-2) / 4=-0.25; Step S2-4: From C 1,hist Extract all triplet subsequences consisting of three consecutive tags; C 1,hist The length J=7, and there are 5 triples in total; The first triplet: (browse, input, browse); The second triplet: (input, browse, browse); The third triplet: (browse, browse, browse); The fourth triplet: (browse, browse, modify); The 5th triplet: (Browse, Modify, Submit); Count the frequency of each triplet pattern: each pattern occurs once, with a probability of 1 / 5; triplet pattern entropy: Normalized and divided by 6, the historical local transfer pattern entropy is: M1 = 2.3219 / 6 ≈ 0.387; Step S2-5: Combine historical behavior feature vectors. Obtain the historical behavior feature vector of the first historical event sequence; X1=(H 1,dwell ,Order1,M1)=(0.4,-0.25,0.387); Similarly, the historical behavior feature vector of the second historical event sequence is obtained; X2=(H 2,dwell Order2, M2) = (0.8, 0.6, 0.7); Similarly, the historical behavior feature vector of the third historical event sequence is obtained; X3=(H 3,dwell Order3, M3) = (0.1, 0.05, 0.2); Similarly, the historical behavior feature vector of the fourth historical event sequence is obtained; X4=(H 4,dwell ,Order4,M4)=(0.75,0.7,0.65); Similarly, the historical behavior feature vector of the 5th historical event sequence is obtained; X5=(H 5,dwell ,Order5,M5)=(0.85,0.3,0.55); Similarly, the historical behavior feature vector of the 6th historical event sequence is obtained; X6=(H 6,dwell ,Order6,M6)=(0.05,0.9,0.15); Obtain the historical behavior feature vector group; X hist ={X1,X2,X3,X4,X5,X6}={(0.4,-0.25,0.387),(0.8,0.6,0.7),(0.1,0.05,0.2), (0.75,0.7,0.65),(0.85,0.3,0.55),(0.05,0.9,0.15)}; Step S3: Obtain the current event sequence generated by the operation entity in the current session, extract the current event category label sequence from the current event sequence, calculate the current dwell mode entropy, current transition orderliness and current local transition mode entropy in the same way as in step S2, and combine them into the current behavior feature vector; Step S3-1: Obtain the current event sequence E generated by the operation entity in the current session. cur E cur ={e cur,1 ,e cur,2 ,e cur,3 ,e cur,4 ,e cur,5 ,e cur,6}, containing 6 event records, e cur,1 For "browsing products", e cur,2 For "Enter keywords", e cur,3 To "modify keywords", e cur,4 For "Submit Order", e cur,5 For "Return to Browse", e cur,6 To "resubmit"; Step S3-2: Following the methods in steps S1-2 to S1-4, classify and obtain the current event category label sequence. After the same extraction and matching of interface meta-attributes and interaction meta-attributes, obtain C. cur ={c cur,1,c cur,2 ,c cur,3 ,c cur,4 ,c cur,5 ,c cur,6 = {Browse, Input, Modify, Submit, Browse, Submit}; Step S3-3: Calculate the current dwell morphology entropy using the methods from steps S2-1 to S2-2, and obtain H. cur,dwell =0; Calculate the current transition order degree according to the method in steps S2-3 to obtain the Order. cur =0.2; Calculate the current local transfer mode entropy according to the method in steps S2-4, and obtain M. cur =0.3333; Step S3-4: Combine the current behavior feature vector: X cur =(H cur,dwell Order cur M cur =(0,0.2,0.3333).

[0023] Step S4: Calculate the outlier depth of the current behavior feature vector in the historical behavior feature vector group described in step S2; when the outlier depth is greater than or equal to a preset judgment threshold, determine that the current operating entity is an automated intelligent agent and trigger risk handling operation; when the outlier depth is less than the preset judgment threshold, determine that the current operating entity is a human and process it as normal business interaction. Step S4-1: Take the preset neighborhood parameter k=2; with X1=(H 1,dwell Given the vector (Order1, M1) = (0.4, -0.25, 0.387), calculate its Euclidean distance to the other vectors: With X2=(H 2,dwell Order2, M2) = (0.8, 0.6, 0.7), ; Similarly, we can conclude that ; ; ; ; ; Sorted from smallest to largest: 0.464, 0.729, 0.99, 1.046, 1.225. The distance of the second smallest is 0.729, so d2(X1) = 0.729. Similarly, calculate the k-nearest neighbor distances for the remaining vectors: d2(X2)≈0.812; d2(X3)≈0.515; d2(X4)≈0.794; d2(X5)≈0.768; d2(X6)≈0.901; Construct a set of nearest neighbor distances: D hist ={d2(X1),d2(X2),d2(X3),d2(X4),d2(X5),d2(X6)}={0.729,0.812,0.515,0.794,0.768,0.901}; Step S4-2: Place D hist The values ​​are sorted from smallest to largest as follows: [0.515, 0.729, 0.768, 0.794, 0.812, 0.901]. Taking the quantile ratio α = 0.9 and I = 6, The 6th element is taken as the distance threshold T=0.901; Step S4-3: Calculate X cur =(H cur,dwell Order cur M cur The Euclidean distance from (0, 0.2, 0.3333) to each historical vector, with X1, ; Similarly, we can conclude that ; ; ; ; The minimum value is taken as the outlier depth d of the current behavior feature vector. min =0.224; Step S4-4: Compare d min =0.224 and threshold T=0.901. Since 0.224<0.901, the current operating entity is determined to be a human and processed as a normal business interaction.

[0024] The system includes: a data acquisition module, a historical feature construction module, a current feature extraction module, and an outlier detection and judgment module; The data acquisition module is used to acquire historical session event sequences that do not distinguish between operational entities and extract event category tag sequences from them; The historical feature construction module is used to calculate the resident morphology entropy, transition orderliness, and local transition mode entropy of the label sequence of each historical event category, and combine them into a group of historical behavior feature vectors. The current feature extraction module is used to obtain the current event sequence and calculate the current resident morphology entropy, current transition orderliness and current local transition mode entropy in the same way as the historical feature construction module, and combine them into the current behavior feature vector; The outlier detection and determination module is used to calculate the outlier depth of the current behavior feature vector in the historical behavior feature vector group and compare it with a threshold to determine the type of the operation entity.

[0025] The data acquisition module includes: The event sequence acquisition unit is used to acquire the event sequence and original operation type of each historical session; The meta-attribute extraction unit is used to extract the set of interface meta-attributes and the set of interaction meta-attributes for each event record; The classification and matching unit is used to classify the original operation type into four tags: browse, input, modify, and submit according to preset rules; The sequence output unit is used to output the historical event category tag sequence for each historical event sequence.

[0026] The historical features building module includes: The residence segment segmentation unit is used to divide the sequence into residence segments according to consecutive identical labels and to count the residence segment length for each label category; The dwell morphology entropy calculation unit is used to discretize the dwell length and calculate the historical dwell morphology entropy by weighting. The jump order calculation unit is used to calculate the historical jump order based on coordinate mapping and jump direction. The local transition pattern entropy calculation unit is used to statistically analyze triplet patterns and calculate the normalized historical local transition pattern entropy. The historical vector synthesis unit is used to combine three-dimensional feature vectors and aggregate them into a group of historical behavior feature vectors.

[0027] The current feature extraction module includes: The current data acquisition unit is used to acquire the current event sequence of the current session; The current classification processing unit is used to classify the current event sequence to obtain the current event category label sequence; The current feature calculation unit is used to calculate the current residence morphology entropy, the current transition order, and the current local transition mode entropy. The current vector synthesis unit is used to combine the three current features into the current behavior feature vector.

[0028] The outlier detection and judgment module includes: The nearest neighbor distance calculation unit is used to calculate the Euclidean distance between each historical vector and other vectors. It takes the distances in a specified order according to the preset neighborhood parameters as the nearest neighbor distances of the vector, and forms a nearest neighbor distance set. The threshold calculation unit is used to sort the nearest neighbor distance set from smallest to largest and take the element at the sorting position corresponding to the preset quantile ratio as the distance threshold. The minimum distance calculation unit is used to calculate the minimum distance from the current vector to the historical vectors as the outlier depth; The comparison and determination unit is used to compare the outlier depth with a threshold and determine whether it is an automated intelligent agent or a human.

[0029] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A method for identifying access agents based on interaction behavior analysis, characterized in that: Includes the following steps: The system acquires historical event sequences from several historical sessions without distinguishing operation entities, and extracts historical event category tag sequences from each historical event sequence. Based on the interface meta-attributes of the operation focus area and the interaction meta-attributes triggered by the operation, the original operation type of each event in the historical event sequence is classified into browsing status tag, input status tag, modification status tag, or submit status tag, and a historical event category tag sequence is constructed according to the event order. For each historical event category tag sequence, it is divided into dwell segments according to consecutive identical category tags, and the probability distribution of the dwell segment length under each category tag is calculated to obtain the historical dwell morphology entropy. Based on the difference in mapping coordinates between the starting and ending category markers during transitions between adjacent different category markers, the number of forward and backward transitions is counted, and the historical transition orderliness is calculated. All triplet subsequences composed of three consecutive category markers are extracted, and the frequency of occurrence of all different triplet patterns is counted to obtain a probability distribution, and the historical local transition pattern entropy is calculated. The historical dwelling morphology entropy, historical transition orderliness, and historical local transition pattern entropy are combined into a historical behavior feature vector. The historical behavior feature vectors of all historical event category marker sequences are aggregated to form a historical behavior feature vector group. The current event sequence generated by the operation entity in the current session is obtained, and the current event category marker sequence is extracted from the current event sequence. The current dwelling morphology entropy, current transition orderliness, and current local transition pattern entropy are calculated and combined into a current behavior feature vector. The outlier depth of the current behavior feature vector in the historical behavior feature vector group is calculated. When the outlier depth is less than a preset judgment threshold, it is judged as normal; otherwise, it is judged as abnormal. The historical residency morphological entropy of the historical event category label sequence of the i-th historical event sequence is H. i,dwell =(N i,browse ×H i,browse +N i,input ×H i,input +N i,modify ×H i,modify +N i,submit ×H i,submit ) / (N browse + N input +N modify +N submit ); where N i,browse N i,input N i,modify N i,submit These represent the total number of segments residing in the browsing tag category, input tag category, modification tag category, and submission tag category of the historical event category tag sequence for the i-th historical event sequence, respectively. H i,browse H i,input H i,modify H i,submit The residence distribution entropy of the browsing tag category, input tag category, modification tag category, and submission tag category of the historical event category tag sequence of the i-th historical event sequence is respectively, and the residence distribution entropy is the Shannon entropy of the probability distribution of the residence segment length; The order of the historical transitions in the i-th historical event sequence is Order. i =(FR) / Z; where F is the number of forward transitions, R is the number of backward transitions, Z is the total number of transitions and Z=F+R+Q, Q is the number of jump transitions; when Z=0, Order i =0; The entropy of the historical local transition pattern of the i-th historical event sequence is: Among them, PE i,triple Represents the pattern entropy of triples, and ; where P(g) is the probability distribution of the frequency of occurrence of all different triplet patterns; Calculate the Euclidean distance between the current behavior feature vector of the current event category label sequence and the historical behavior feature vector of the i-th historical event sequence in the historical behavior feature vector group, and take the minimum value as the outlier depth of the current behavior feature vector.

2. The method for identifying access agents based on interactive behavior analysis according to claim 1, characterized in that: The extraction of historical event category label sequences from each historical event sequence includes: When there are no keystroke events, no page jumps, and the focused area is not an input content display area, it is classified as a browsing status flag; when there are keystroke events and the focused area is within an input control, it is classified as an input status flag; when a content deletion or replacement operation is triggered and the focused area is within an input control with existing content, it is classified as a modification status flag; when a page jump or transaction termination operation is triggered, it is classified as a commit status flag.

3. The method for identifying access agents based on interactive behavior analysis according to claim 1, characterized in that: The calculated historical residence morphology entropy includes: The historical event category tag sequence is divided into several dwell segments according to consecutive identical category tags. Each dwell segment corresponds to a category tag, and the number of consecutive occurrences is recorded as the dwell segment length. For the four categories of browsing, input, modification, and submission, all dwell segment length values ​​corresponding to each category tag are collected to form a dwell segment length set for each category tag. The elements in the dwell segment length set of each category tag are discretized according to a preset length interval, and the proportion of dwell segments in each length interval to the total number of dwell segments for each category tag is calculated to obtain the probability distribution of dwell segment length for each category tag. Shannon entropy is calculated based on the probability distribution as the dwell distribution entropy for each category tag. The dwell distribution entropy of each category tag is weighted and averaged according to the proportion of dwell segments contained in each category tag to the total number of dwell segments to obtain the historical dwell morphology entropy.

4. The method for identifying access agents based on interactive behavior analysis according to claim 1, characterized in that: The calculation yields the following historical transition order: The process involves cyclically arranging the browsing, inputting, modifying, and submitting category tags, and determining the forward and backward adjacent category tags for each category tag in the cyclical order. It then iterates through all adjacent pairs of different category tags in the historical event category tag sequence, forming a transition sequence in cyclical order. For each transition, the positional relationship between the starting and ending category tags in the cyclical order is determined. If the ending category tag is the forward adjacent category tag of the starting category tag, it is considered a forward transition; if the ending category tag is the backward adjacent category tag of the starting category tag, it is considered a backward transition; if the ending category tag is neither forward nor backward adjacent, it is considered a jump transition. The number of forward and backward transitions in all transitions is counted, and the ratio of the difference between the number of forward and backward transitions to the total number of transitions is used as the historical transition order. The order is zero when the total number of transitions is zero.

5. The method for identifying access agents based on interactive behavior analysis according to claim 1, characterized in that: The calculated entropy of the historical local transfer pattern includes: Extract all triplet subsequences consisting of three consecutive category labels from the historical event category label sequence; count the occurrence frequency of all different triplet patterns to obtain the probability distribution; calculate the triplet pattern entropy based on the probability distribution; normalize the triplet pattern entropy to obtain the historical local transition pattern entropy.

6. The method for identifying access agents based on interactive behavior analysis according to claim 1, characterized in that: The calculation of the outlier depth of the current behavior feature vector in the group of historical behavior feature vectors includes: For each historical behavior feature vector in the historical behavior feature vector group, calculate the Euclidean distance between any historical behavior feature vector and other historical vectors. After sorting them in ascending order of Euclidean distance, take the Euclidean distance that is at the first preset parameter after sorting as the nearest neighbor distance of any historical behavior feature vector. Collect the nearest neighbor distances of all historical behavior feature vectors to form a nearest neighbor distance set. Sort the nearest neighbor distances in the nearest neighbor distance set in ascending order, and take the nearest neighbor distance that is at the second preset parameter after sorting as the preset judgment threshold. Calculate the Euclidean distance between the current behavior feature vector and each historical behavior feature vector in the historical behavior feature vector group, and take the minimum value as the outlier depth.

7. An access agent recognition system based on interaction behavior analysis, used to execute the access agent recognition method based on interaction behavior analysis as described in any one of claims 1-6, characterized in that: The system includes: The module includes a data acquisition module, a historical feature construction module, a current feature extraction module, and an outlier detection and judgment module. The data acquisition module is used to acquire historical session event sequences that do not distinguish between operational entities and extract event category tag sequences from them; The historical feature construction module is used to calculate the resident morphology entropy, transition orderliness, and local transition mode entropy of the label sequence of each historical event category, and combine them into a group of historical behavior feature vectors. The current feature extraction module is used to obtain the current event sequence and calculate the current resident morphology entropy, current transition orderliness and current local transition mode entropy in the same way as the historical feature construction module, and combine them into the current behavior feature vector; The outlier detection and determination module is used to calculate the outlier depth of the current behavior feature vector in the historical behavior feature vector group and compare it with a threshold to determine the type of the operation entity.

8. The access agent recognition system based on interactive behavior analysis according to claim 7, characterized in that: The data acquisition module includes: The event sequence acquisition unit is used to acquire the event sequence and original operation type of each historical session; The meta-attribute extraction unit is used to extract the set of interface meta-attributes and the set of interaction meta-attributes for each event record; The classification and matching unit is used to classify the original operation type into four tags: browse, input, modify, and submit according to preset rules; The sequence output unit is used to output the historical event category label sequence for each historical event sequence. The historical feature construction module includes: The residence segment segmentation unit is used to divide the sequence into residence segments according to consecutive identical labels and to count the residence segment length for each label category; The residence morphology entropy calculation unit is used to discretize the residence segment length and calculate the historical residence morphology entropy by weighting. The jump order calculation unit is used to calculate the historical jump order based on coordinate mapping and jump direction. The local transition pattern entropy calculation unit is used to statistically analyze triplet patterns and calculate the normalized historical local transition pattern entropy. The historical vector synthesis unit is used to combine three-dimensional feature vectors and aggregate them into a group of historical behavior feature vectors.

9. The access agent recognition system based on interactive behavior analysis according to claim 7, characterized in that: The current feature extraction module includes: The current data acquisition unit is used to acquire the current event sequence of the current session; The current classification processing unit is used to classify the current event sequence to obtain the current event category label sequence; The current feature calculation unit is used to calculate the current residence morphology entropy, the current transition order, and the current local transition mode entropy. The current vector synthesis unit is used to combine the three current features into the current behavior feature vector.

10. The access agent recognition system based on interactive behavior analysis according to claim 7, characterized in that: The outlier detection and determination module includes: The nearest neighbor distance calculation unit is used to calculate the Euclidean distance between each historical vector and other vectors. It takes the distances in a specified order according to the preset neighborhood parameters as the nearest neighbor distances of the vector, and forms a nearest neighbor distance set. The threshold calculation unit is used to sort the nearest neighbor distance set from smallest to largest and take the element at the sorting position corresponding to the preset quantile ratio as the distance threshold. The minimum distance calculation unit is used to calculate the minimum distance from the current vector to the historical vectors as the outlier depth; The comparison and determination unit is used to compare the outlier depth with a threshold and determine whether it is an automated intelligent agent or a human.

Citation Information

Patent Citations

  • Abnormal operation behavior analysis method and system based on service behavior distribution

    CN120654233A

  • Abnormal behavior detection method and device, nonvolatile storage medium and electronic equipment

    CN121256526A