An unsupervised host anomaly detection method and system based on login behavior characterization
By constructing a global login graph and combining computational semantics and structural semantics features, an unsupervised host anomaly detection method is developed, which solves the problems of detection accuracy and false alarm control in existing technologies. This method achieves efficient and interpretable detection of covert penetration attacks and reduces system costs.
Patent Information
- Application Number
- CN202610766873.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-29
- Publication Date
- 2026-07-17
AI Technical Summary
Existing host anomaly detection methods struggle to balance detection accuracy, false alarm control, and applicability to large-scale networks. They are particularly ineffective in identifying covert penetration attacks and rely on manual labeling, which is costly.
An unsupervised host anomaly detection method based on login behavior representation is adopted. By constructing a global login graph, the computational semantic features and structural semantic features of nodes are jointly learned to generate node embedding vectors. Anomaly discrimination and alarm filtering are performed by combining low-frequency sparsity and topological clustering features.
It achieves high-accuracy detection of covert penetration attacks in large-scale complex network environments, reduces system deployment and maintenance costs, and improves computational efficiency and the interpretability of alarm results.
Smart Images

Figure CN122419956A_ABST