An unsupervised host anomaly detection method and system based on login behavior characterization

By constructing a global login graph and combining computational semantics and structural semantics features, an unsupervised host anomaly detection method is developed, which solves the problems of detection accuracy and false alarm control in existing technologies. This method achieves efficient and interpretable detection of covert penetration attacks and reduces system costs.

CN122419956APending Publication Date: 2026-07-17INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610766873.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing host anomaly detection methods struggle to balance detection accuracy, false alarm control, and applicability to large-scale networks. They are particularly ineffective in identifying covert penetration attacks and rely on manual labeling, which is costly.

Method used

An unsupervised host anomaly detection method based on login behavior representation is adopted. By constructing a global login graph, the computational semantic features and structural semantic features of nodes are jointly learned to generate node embedding vectors. Anomaly discrimination and alarm filtering are performed by combining low-frequency sparsity and topological clustering features.

Benefits of technology

It achieves high-accuracy detection of covert penetration attacks in large-scale complex network environments, reduces system deployment and maintenance costs, and improves computational efficiency and the interpretability of alarm results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419956A_ABST
    Figure CN122419956A_ABST
Patent Text Reader

Abstract

本发明公开了一种基于登录行为表征的无监督主机异常检测方法及系统,属于网络安全技术领域。本发明为解决现有检测方法在检测精度、误报控制与大规模网络适用性之间难以取得平衡技术问题,通过获取用户登录事件数据并构建全局登录图;联合学习节点的计算语义特征与结构语义特征得到节点嵌入向量;根据节点嵌入向量对待检测登录行为进行异常判别得到初始异常结果;根据初始异常结果在全局登录图中的低频稀疏性特征和拓扑聚集性特征进行过滤,输出告警结果。本发明能够实现无需人工标注的高准确率和高效率主机检测,增强对隐蔽渗透攻击的检测能力。
Need to check novelty before this filing date? Find Prior Art