A behavior sequence processing method, device and equipment
By compressing the target behavior sequence and querying the baseline event time sequence flow model, a detection and analysis report is generated, which solves the problem of low efficiency in large-scale log data processing and realizes efficient API call sequence pattern extraction and business analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ALIPAY COM CO LTD
- Filing Date
- 2026-04-13
- Publication Date
- 2026-07-21
AI Technical Summary
In systems with hundreds of millions of daily active users and tens or hundreds of billions of API calls, the raw log data is enormous. Directly performing complex sequence pattern mining or graph analysis would incur astronomical computational and storage overhead, making it extremely inefficient or even infeasible. Furthermore, existing methods struggle to extract API call sequence processing patterns that are universal and business-relevant.
By receiving a detection request for a target behavior sequence, compressing it to generate a target sequence fingerprint, querying the benchmark event time sequence process model in the event time sequence process database based on the sequence fingerprint, and generating a detection analysis report using a pre-set intelligent agent; if no matching fingerprint is found, obtaining the semantically matching benchmark event time sequence process model from the database and generating a report.
It enables the rapid and accurate extraction of API call sequence processing patterns with universality and business significance, allowing for the analysis of security risks, the location of business system faults, and the optimization of product processes, thereby improving the accuracy and efficiency of detection and analysis reports.
Smart Images

Figure CN122432213A_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of computer technology, and in particular to a method, apparatus and device for processing behavioral sequences. Background Technology
[0002] In systems with hundreds of millions of daily active users and tens or hundreds of billions of API (Application Programming Interface) calls, the raw log data is enormous. Directly performing complex sequence pattern mining or graph analysis incurs astronomical computational and storage costs, making it extremely inefficient or even infeasible. Therefore, there is a need to provide a stable API call sequence processing method that can extract universal and business-meaning patterns. Summary of the Invention
[0003] The purpose of the embodiments in this specification is to provide a stable API call sequence processing pattern that can extract universal and business-significant features.
[0004] To achieve the above technical solution, the embodiments in this specification are implemented as follows: This specification provides an embodiment of a method for processing a behavior sequence. The method includes: receiving a detection request for a target behavior sequence; compressing the target behavior sequence to generate a target sequence fingerprint; querying a benchmark event time-series process model corresponding to the target sequence fingerprint from an event time-series process database based on the target sequence fingerprint, and generating a detection analysis report corresponding to the detection request through a preset intelligent agent based on the queried benchmark event time-series process model; if the target sequence fingerprint does not exist in the event time-series process database, obtaining a benchmark event time-series process model semantically matching the target behavior sequence from the benchmark event time-series process models included in the event time-series process database, and generating a detection analysis report corresponding to the detection request through a preset intelligent agent based on the obtained benchmark event time-series process model semantically matching the target behavior sequence.
[0005] This specification provides an embodiment of a method for processing behavior sequences. The method includes: collecting information from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period, the key information including entity identifier, behavior information, and timestamp; based on the key information corresponding to each log data, grouping behavior information belonging to the same entity identifier within the key information of the log data within the preset time period into a group, and arranging the behavior information within the same group in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences; performing clustering processing on the obtained behavior sequences, and constructing a benchmark event time sequence flow model based on the clustered behavior sequences; creating an event time sequence flow database based on the constructed benchmark event time sequence flow model, the event time sequence flow database providing a retrieval database for the target behavior sequences to be detected, and triggering the generation of a corresponding detection analysis report based on the retrieval of the benchmark event time sequence flow model.
[0006] This specification provides an embodiment of a behavior sequence processing apparatus, comprising: a detection request module for receiving a detection request for a target behavior sequence; a compression module for compressing the target behavior sequence to generate a target sequence fingerprint; a first report generation module for querying a benchmark event time sequence model corresponding to the target sequence fingerprint from an event time sequence process database, and generating a detection analysis report corresponding to the detection request based on the queried benchmark event time sequence process model through a preset intelligent agent; and a second report generation module for obtaining a benchmark event time sequence process model semantically matching the target behavior sequence from the benchmark event time sequence process models included in the event time sequence process database if the target sequence fingerprint does not exist, and generating a detection analysis report corresponding to the detection request based on the obtained benchmark event time sequence process model semantically matching the target behavior sequence through a preset intelligent agent.
[0007] This specification provides an embodiment of a behavior sequence processing device, comprising: an information acquisition module, which acquires information from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period, the key information including entity identifier, behavior information, and timestamp; a sorting module, which, based on the key information corresponding to each log data, groups behavior information belonging to the same entity identifier within the key information of the log data within the preset time period into a group, and sorts the behavior information within the same group in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences; a clustering module, which performs clustering processing on the obtained behavior sequences and constructs a benchmark event time sequence flow model based on the clustered behavior sequences; and a database construction module, which creates an event time sequence flow database based on the constructed benchmark event time sequence flow model, the event time sequence flow database providing a retrieval database for target behavior sequences to be detected, and triggering the generation of a corresponding detection analysis report based on the retrieved benchmark event time sequence flow model.
[0008] This specification provides an embodiment of a behavior sequence processing device, comprising: a processor; and a memory arranged to store computer-executable instructions, wherein the executable instructions, when executed, cause the processor to: receive a detection request for a target behavior sequence; compress the target behavior sequence to generate a target sequence fingerprint corresponding to the target behavior sequence; based on the target sequence fingerprint, query a benchmark event time-series process database corresponding to the target sequence fingerprint, and based on the queried benchmark event time-series process model, generate a detection analysis report corresponding to the detection request through a preset intelligent agent; if the target sequence fingerprint does not exist in the event time-series process database, obtain a benchmark event time-series process model semantically matching the target behavior sequence from the benchmark event time-series process models contained in the event time-series process database, and based on the obtained benchmark event time-series process model semantically matching the target behavior sequence, generate a detection analysis report corresponding to the detection request through a preset intelligent agent.
[0009] This specification provides an embodiment of a behavior sequence processing device, comprising: a processor; and a memory arranged to store computer-executable instructions. When executed, the executable instructions cause the processor to: collect information from log data stored in a preset log database within a preset time period, obtaining key information corresponding to each log data within the preset time period, the key information including entity identifier, behavior information, and timestamp; based on the key information corresponding to each log data, grouping behavior information belonging to the same entity identifier within the key information corresponding to the log data within the preset time period into a group, and arranging the behavior information within the same group in ascending order according to the corresponding timestamp, obtaining one or more different behavior sequences; performing clustering processing on the obtained behavior sequences, and constructing a benchmark event time sequence flow model based on the clustered behavior sequences; creating an event time sequence flow database based on the constructed benchmark event time sequence flow model, the event time sequence flow database providing a retrieval database for target behavior sequences to be detected, and triggering the generation of a corresponding detection analysis report based on the retrieved benchmark event time sequence flow model.
[0010] This specification also provides a storage medium for storing computer-executable instructions. When executed by a processor, the executable instructions implement the following process: receiving a detection request for a target behavior sequence; compressing the target behavior sequence to generate a target sequence fingerprint; based on the target sequence fingerprint, querying a benchmark event time-series process model corresponding to the target sequence fingerprint from an event time-series process database, and generating a detection analysis report corresponding to the detection request through a preset intelligent agent based on the queried benchmark event time-series process model; if the target sequence fingerprint does not exist in the event time-series process database, obtaining a benchmark event time-series process model semantically matching the target behavior sequence from the benchmark event time-series process models contained in the event time-series process database, and generating a detection analysis report corresponding to the detection request through a preset intelligent agent based on the obtained benchmark event time-series process model semantically matching the target behavior sequence.
[0011] This specification also provides a storage medium for storing computer-executable instructions. When executed by a processor, these instructions implement the following process: Information is collected from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifiers, behavioral information, and timestamps. Based on the key information corresponding to each log data, behavioral information belonging to the same entity identifier within the key information of the log data within the preset time period is grouped together, and the behavioral information within the same group is arranged in ascending order according to the corresponding timestamps to obtain one or more different behavioral sequences. The obtained behavioral sequences are clustered, and a baseline event time-series process model is constructed based on the clustered behavioral sequences. An event time-series process database is created based on the constructed baseline event time-series process model. The event time-series process database provides a retrieval database for the target behavioral sequences to be detected and triggers the generation of corresponding detection and analysis reports based on the retrieved baseline event time-series process model.
[0012] This specification also provides a computer program product, including a computer program that, when executed by a processor, implements the following process: receiving a detection request for a target behavior sequence; compressing the target behavior sequence to generate a target sequence fingerprint corresponding to the target behavior sequence; based on the target sequence fingerprint, querying a benchmark event time-series process model corresponding to the target sequence fingerprint from an event time-series process database, and generating a detection analysis report corresponding to the detection request through a preset intelligent agent based on the queried benchmark event time-series process model; if the target sequence fingerprint does not exist in the event time-series process database, obtaining a benchmark event time-series process model semantically matching the target behavior sequence from the benchmark event time-series process models contained in the event time-series process database, and generating a detection analysis report corresponding to the detection request through a preset intelligent agent based on the obtained benchmark event time-series process model semantically matching the target behavior sequence.
[0013] This specification also provides a computer program product, including a computer program that, when executed by a processor, implements the following process: collecting information from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period, the key information including entity identifier, behavior information, and timestamp; based on the key information corresponding to each log data, grouping behavior information belonging to the same entity identifier within the key information of the log data within the preset time period into a group, and arranging the behavior information within the same group in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences; performing clustering processing on the obtained behavior sequences, and constructing a benchmark event time-series process model based on the clustered behavior sequences; creating an event time-series process database based on the constructed benchmark event time-series process model, the event time-series process database providing a retrieval database for the target behavior sequences to be detected, and triggering the generation of a corresponding detection analysis report based on the retrieval of the benchmark event time-series process model. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 This is a schematic diagram of the structure of a behavior sequence processing system described in this specification; Figure 2 This is a schematic diagram of the processing procedure for a behavior sequence in this specification; Figure 3 This is a schematic diagram illustrating the processing procedure for another behavioral sequence in this specification; Figure 4 This is a schematic diagram illustrating the processing procedure for yet another behavioral sequence described in this specification. Figure 5 This is a schematic diagram illustrating the processing procedure for yet another behavioral sequence described in this specification. Figure 6 This is a schematic diagram of a behavior sequence processing device according to this specification; Figure 7 This is a schematic diagram of a processing device for another behavior sequence as described in this specification; Figure 8 This is a schematic diagram of a device for processing behavioral sequences as described in this specification. Detailed Implementation
[0015] This specification provides a method, apparatus, and device for processing behavioral sequences through its embodiments.
[0016] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0017] This specification provides an intelligent modeling mechanism for API time series data at the level of hundreds of millions. In systems with hundreds of millions of daily active users and tens or hundreds of billions of API (Application Programming Interface) calls, the raw log data is enormous. Directly performing complex sequence pattern mining or graph analysis incurs astronomical computational and storage costs, making it extremely inefficient or even infeasible. Typically, high-order sequence mining algorithms can be directly applied to mine and analyze time series sequences in log data. Specifically, each user's API call record is treated as a sequence, and algorithms such as PrefixSpan and GSP are directly input for frequent sequence pattern mining. However, this method generates a huge sequence space for hundreds of millions of events. The time complexity of the algorithm is exponential or polynomial with the sequence length, number, and pattern complexity. Consequently, due to combinatorial explosion, it cannot process tens of billions of event data within an acceptable timeframe. Moreover, it produces a massive amount of trivial patterns containing low-frequency APIs and no business significance. Furthermore, a pattern used by 100 users may be equivalent to one user's use, failing to reflect popularity. In addition, time-series sequences in log data can be mined and analyzed based on statistical aggregation of time windows. This involves dividing log data into fixed time windows (e.g., 5 minutes), statistically analyzing the co-occurrence frequency of APIs within the window, and constructing an API association graph. However, this method only yields results such as "A and B frequently appear in the same time window," rather than "A is always followed by B." Furthermore, it's difficult to choose a time window that suits all business rhythms; too short a window can lead to fragmentation, while too long a window can introduce irrelevant noise. Alternatively, time-series sequences in log data can be mined and analyzed based on dimensionality reduction processing using sampling. This involves randomly sampling hundreds of millions of log data points and performing modeling and analysis on the sampled subset. However, this method may fail to detect low-frequency but critical attack patterns or business paths because they are not sampled. Sampling cannot guarantee uniform coverage of various user groups and behaviors, leading to model bias. This specification provides an embodiment that can extract a stable API call sequence processing pattern with universality and business significance. Specific processing details can be found in the following embodiments.
[0018] The method for processing behavior sequences provided in one or more embodiments of this specification is applicable to the implementation environment of behavior sequence processing. (Refer to...) Figure 1 The implementation environment includes at least: Client 100 and server 200. Furthermore, server 200 may include various algorithms and specified intelligent agents, etc., wherein: Client 100 can run on terminal devices, which can be mobile phones, personal computers, tablets, e-book readers, wearable devices, devices that interact with information based on AR (Augmented Reality) and VR (Virtual Reality), and laptop computers, etc. Client 100 can be installed on terminal devices. Client 100 can be an application, a browser, or a subroutine embedded in an application, etc.
[0019] Server 200 can run on a server, which can be one or more servers, a server cluster consisting of several servers, or a cloud server on a cloud computing platform. Server 200 can be installed on the server. Server 200 can be an application or a subroutine embedded in an application. Various algorithms and intelligent agents can be integrated into server 200, or server 200 can call any one or more of various algorithms and intelligent agents to perform corresponding operations.
[0020] In addition, it may include a database 300, which may be set in the server on which the server 200 runs or outside the server on which the server 200 runs. The database 300 may store behavioral sequences, detection and analysis reports, and may also include relevant information such as benchmark event time sequence flow models.
[0021] In this implementation environment, client 100 can generate a detection request for a target behavior sequence and send the detection request to server 200. After receiving the request, server 200 can compress the target behavior sequence to generate a target sequence fingerprint. Then, based on the target sequence fingerprint, it can query the event time sequence flow database for a benchmark event time sequence flow model corresponding to the target sequence fingerprint. Based on the queried benchmark event time sequence flow model, it generates a detection analysis report for the above detection request through a preset intelligent agent. If the target sequence fingerprint does not exist in the event time sequence flow database, it obtains a benchmark event time sequence flow model that semantically matches the target behavior sequence from the benchmark event time sequence flow models contained in the event time sequence flow database. Based on the obtained benchmark event time sequence flow model that semantically matches the target behavior sequence, it generates a detection analysis report for the above detection request through a preset intelligent agent.
[0022] like Figure 2 As shown in the embodiments of this specification, a method for processing behavioral sequences is provided. The execution subject of this method can be a terminal device or a server, etc. The terminal device can be a mobile terminal device such as a mobile phone or tablet computer, a computer device such as a laptop or desktop computer, or an IoT device (specifically, a smartwatch, an in-vehicle device, etc.). The server can be a single server or a server cluster composed of multiple servers. The server can be a backend server in fields such as finance or online shopping, or a backend server of an application. This embodiment uses a server as the execution subject for detailed description. For the case where the execution subject is a terminal device, please refer to the following server-side processing, which will not be repeated here. The method may specifically include the following steps: In step S202, a detection request for the target behavior sequence is received.
[0023] The target behavior sequence can be a sequence of user behaviors for any event or business. This sequence can be a chain of API call events ordered by the user over a period of time. For example, for the process of a user setting up facial recognition payment in a specific application, the target behavior sequence could be: "When the user enters the biometric settings page, the system first calls the xxx function to detect the device's biometric capabilities. If the returned content includes facial recognition, the process continues; then, the xxx function is called consecutively to obtain anonymized names, used for display in the page header and for identity verification before key operations; next, the facial recognition settings page is initialized through the xxx function, passing in the user ID and device metadata to obtain the facial recognition payment's activation status and task ID; when the user clicks the online payment switch, the activation status is queried in real time according to specified parameters; finally, when the user clicks the 'Try Facial Recognition' button, the xxx function triggers face detection, reusing the task ID to complete the verification task creation. If any step in the process returns usable=false or passed=false, subsequent operations are terminated and the error reason is displayed."
[0024] In implementation, for a specific event or business process, a chain of API call events from the user, sorted by occurrence time over a period of time, can be obtained. Based on this information, a target behavior sequence can be determined. When it is necessary to detect or query the target behavior sequence, a detection request can be generated. This detection request can be sent to the server through the user's terminal device.
[0025] In practical applications, besides setting the target behavior sequence in the detection request, to reduce the amount of content carried by the detection request, the target behavior sequence can also be compressed or mapped, thus reducing its content. For example, a hash value corresponding to the target behavior sequence can be generated using a specified hash algorithm, and the detection request can be generated based on this hash value. Alternatively, the target behavior sequence can be mapped to a specified character or string. Or, a lossless compression algorithm can be pre-defined, and the target behavior sequence can be losslessly compressed using this algorithm to obtain the compressed target behavior sequence. Under these methods, after receiving a detection request, the compressed target behavior sequence or the specified character or string mapped to the target behavior sequence can be obtained from the detection request. The corresponding target behavior sequence can then be obtained based on the compressed target behavior sequence or the specified character or string mapped to the target behavior sequence.
[0026] In step S204, the target behavior sequence is compressed to generate the target sequence fingerprint corresponding to the target behavior sequence.
[0027] The target sequence fingerprint can be information that uniquely represents a certain behavior sequence. The target sequence fingerprint can be identification information, or it can be the result obtained by calculating the behavior sequence through a specified lossless compression algorithm (such as Huffman coding algorithm or run-length encoding algorithm), or it can be the result obtained by mapping the behavior sequence through a specified mapping rule (such as mapping a certain behavior sequence to a specified string (such as a string consisting of 10 characters) or a matrix or vector, etc.). The specific settings can be set according to the actual situation.
[0028] In implementation, for example, the behavior sequence can be losslessly compressed using the Huffman coding algorithm to obtain the corresponding calculation result, which can then be used as the target sequence fingerprint corresponding to the target behavior sequence. Alternatively, the behavior sequence can be mapped to a string of a preset length using a specified mapping rule, and this string can then be used as the target sequence fingerprint corresponding to the target behavior sequence.
[0029] In step S206, based on the target sequence fingerprint, a benchmark event time sequence process model corresponding to the target sequence fingerprint is queried from the event time sequence process database, and based on the queried benchmark event time sequence process model, a detection analysis report corresponding to the above detection request is generated by a preset intelligent agent.
[0030] The event time-series process database can be used to store benchmark event time-series process models, or it can store benchmark event time-series process models and their corresponding benchmark sequence fingerprints. The benchmark event time-series process model can be a time series of a benchmark or standard process executed for any event or business operation. It can be a time-series process of API call patterns with specific business semantics or statistical significance, mined from a large number of user behavior sequences through unsupervised learning or statistical analysis. The benchmark event time-series process model can include information describing the temporal dependencies, transformation relationships, and context parameter flow between APIs. The benchmark sequence fingerprint can be a corresponding sequence fingerprint generated by compressing the benchmark event time-series process model. The detection and analysis report can be generated based on a specific detection request and the retrieved baseline event time sequence flow model. The aforementioned detection request can also include other specific detection requirement information. For example, whether the target behavior sequence has any preset risks, such as whether the target behavior sequence is a commonly used behavior sequence with fraud or attack risks, the detection and analysis report can include relevant information on whether the target behavior sequence has fraud or attack risks. Or, whether the target behavior sequence has any specified vulnerabilities or defects, the detection and analysis report can include relevant information on the specified vulnerabilities or defects in the target behavior sequence. For another example, the report can detect the location of the failure point of the corresponding business system, and the detection and analysis report can include relevant information on the location of the failure point of the business system. The specific details can be set according to the actual situation. An intelligent agent can be an entity capable of performing one or more different functions. An intelligent agent may include one or more different processing rules (such as data query rules, feature extraction rules, etc.), one or more network models (such as convolutional neural network models, recurrent neural network models, etc.), and one or more different large models (such as large language models (e.g., large language models for text modality, or large language models for speech modality, etc.), multimodal large models (e.g., large models for text and image modality, or large models for speech and image modality), full-modality large models, or discriminative large models, etc.). Furthermore, the intelligent agent can run on a server, which can be one or more servers, a server cluster consisting of several servers, or a cloud server on a cloud computing platform, etc. In this embodiment, the intelligent agent can be used to generate a detection analysis report that meets the detection request based on a benchmark event time-series process model.
[0031] In implementation, for a specific event or business, with user consent and authorization, user behavior data and timestamps of each user's behavior data can be collected during the execution of the event or business by different users. Then, the user behavior data can be arranged according to the chronological order of the timestamps to obtain the event timeline or time-series behavior sequence for each user's execution of the event or business. The event timeline or time-series behavior sequences of multiple different users can be summarized and statistically analyzed to obtain a baseline event timeline model for the execution of the event or business. Multiple baseline event timeline models can be obtained through the above method, thereby constructing an event timeline database. Alternatively, the event timeline or time-series behavior sequences of multiple different users executing the event or business can be obtained from a specified database or crawled using web crawlers. Then, the event timeline or time-series behavior sequences of multiple different users executing the event or business can be summarized and statistically analyzed to obtain a baseline event timeline model for the execution of the event or business, thereby constructing an event timeline database. Alternatively, a baseline event sequence flow model for a specific event or business can be executed directly from a specified database, thereby enabling the construction of an event sequence flow database, etc. The specific settings can be configured according to the actual situation.
[0032] The event time-series process database can contain baseline event time-series process models. To facilitate querying, each baseline event time-series process model in the database can be compressed to generate a baseline sequence fingerprint corresponding to each model. Alternatively, the database can contain baseline event time-series process models and their corresponding baseline sequence fingerprints. Then, based on the target sequence fingerprint, a baseline sequence fingerprint identical to the target sequence fingerprint can be searched for in the database. If found, the corresponding baseline event time-series process model can be retrieved.
[0033] The architecture of the agent can be pre-constructed using specified algorithms and / or models, and the agent can be trained using a large amount of sample data to obtain the trained agent. Then, the benchmark event time-series flow model and the aforementioned detection request (or the specified data in the detection request) can be input into the agent. The agent can then combine the benchmark event time-series flow model and the aforementioned detection request (or the specified data in the detection request) to generate a detection analysis report that satisfies the detection request, such as a detection analysis report on whether the target behavior sequence has fraud or attack risks.
[0034] In step S208, if the target sequence fingerprint does not exist in the event time sequence process database, a benchmark event time sequence process model that semantically matches the target behavior sequence is obtained from the benchmark event time sequence process models contained in the event time sequence process database. Based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence, a detection analysis report corresponding to the above detection request is generated by a preset intelligent agent.
[0035] In implementation, if no corresponding benchmark event time-series process model is found in the event time-series process database using the target sequence fingerprint, a benchmark event time-series process model matching the target behavior sequence can be obtained from the event time-series process database through other methods (such as semantic matching). Specifically, if the target sequence fingerprint does not exist in the event time-series process database, the corresponding benchmark event time-series process model can be determined based on the content of the benchmark event time-series process model. Specifically, the content of each benchmark event time-series process model contained in the event time-series process database can be compared with the content of the target behavior sequence. The benchmark event time-series process model with the smallest difference between its content and the target behavior sequence can be used as the benchmark event time-series process model that semantically matches the target behavior sequence. Alternatively, the similarity between each benchmark event time-series process model contained in the event time-series process database and the target behavior sequence can be calculated. The benchmark event time-series process model with a similarity greater than a preset similarity threshold can be used as the benchmark event time-series process model that semantically matches the target behavior sequence. It should be noted that calculating the similarity between each benchmark event time-series process model in the event time-series process database and the target behavior sequence can be either calculating the similarity between the entirety of each benchmark event time-series process model in the event time-series process database and the entirety of the target behavior sequence, and / or, the similarity between each user behavior data in each benchmark event time-series process model in the event time-series process database and each user behavior data in the target behavior sequence. For example, if the benchmark event time-series process models include ABCD and the target behavior sequence includes MNKL, then the similarity between A and M, B and N, C and K, and D and L can be calculated. The specific processing procedure for generating the detection analysis report corresponding to the above detection request through a preset intelligent agent based on the obtained benchmark event time-series process models that semantically match the target behavior sequence can be found in the aforementioned related content and will not be repeated here.
[0036] This specification provides a method for processing behavior sequences. It involves receiving a detection request for a target behavior sequence, compressing the target behavior sequence to generate a target sequence fingerprint, and then querying an event time-series flow database for a corresponding benchmark event time-series flow model based on the fingerprint. Based on the retrieved benchmark event time-series flow model, a pre-set intelligent agent generates a detection analysis report for the detection request. If the target sequence fingerprint is not found in the event time-series flow database, a benchmark event time-series flow model semantically matching the target behavior sequence is obtained from the database. Based on this obtained benchmark event time-series flow model, a pre-set intelligent agent generates a detection analysis report for the target behavior sequence. The detection and analysis report corresponding to the detection request is generated by querying the corresponding benchmark event time sequence model in the pre-built event time sequence process database based on the target behavior sequence to be detected. This allows for the analysis of security risks in financial business, rapid location of faults and performance bottlenecks in business systems, and timely discovery of mainstream user interaction paths and drop-off points within the product, providing data support for product process optimization. This provides a stable API call sequence processing mechanism with universality and business significance. Furthermore, by clustering similar behavior sequences and checking low-frequency hashes or new hashes to discover unknown behavior sequences, new or abnormal behavior sequences can be quickly discovered, thereby improving the accuracy and generation efficiency of the detection and analysis report.
[0037] In practical applications, if the above detection request is a detection request for risk prevention and control of a preset financial business, and the target behavior sequence is an event behavior sequence related to resource transfer events in the preset financial business, then the generated detection analysis report corresponding to the detection request is an analysis report used to indicate whether there is a preset risk in the target behavior sequence.
[0038] Resource transfer events can be varied, including payments, transfers, and loans. Pre-defined risks can be diverse, such as fraud risk and illegal financial activity risk.
[0039] In practice, in response to security risks in the financial sector, when a detection request for risk prevention and control of a pre-defined financial business is received, the event behavior sequence related to resource transfer events in the pre-defined financial business in the detection request can be analyzed. Through the above-mentioned processing, abnormal or attack sequences can be identified, and a detection analysis report corresponding to the detection request can be generated. The detection analysis report may include relevant information such as whether the target behavior sequence has a pre-defined risk, the resource transfer path after the resource is stolen, and the risk path probing of illegal financial activities.
[0040] If the above detection request is a detection request for the performance of a preset business system, and the target behavior sequence is a behavior sequence of business execution events in the preset business system, then the generated detection analysis report corresponding to the detection request includes fault information and / or performance defect information.
[0041] The fault information can include various types, such as the location and time of the fault. The performance defect information can also include various types, such as the propagation path and scope of impact within complex business processes.
[0042] In implementation, regarding business link monitoring and root cause analysis, when a detection request for the performance of a preset business system is received, the behavioral sequence of business execution events in the preset business system in the detection request can be analyzed. Through the above-mentioned processing, the propagation path and impact range of business system faults or performance bottlenecks in complex business links can be quickly located, thereby generating a detection analysis report corresponding to the detection request. This detection analysis report may include relevant information such as fault information and / or performance defect information.
[0043] If the above detection request is a detection request to optimize the business execution process of a preset business, and the target behavior sequence is the behavior sequence corresponding to the business execution process of the preset business, then the generated detection analysis report corresponding to the detection request includes the optimization strategy for the business execution process of the preset business.
[0044] The preset services can be any service, and can be set according to the actual situation.
[0045] In implementation, regarding user experience optimization and product design, when a detection request is received to optimize the business execution process of a preset business, the behavioral sequence corresponding to the business execution process of the preset business in the detection request can be analyzed. Through the above-mentioned processing, the mainstream interaction paths and drop-off points of users in the product can be discovered, providing data support for product process optimization, and then generating a detection analysis report corresponding to the detection request. This detection analysis report may include relevant information such as optimization strategies for the business execution process of the preset business.
[0046] In practical applications, the specific processing method of the above step S204 can be varied. The following is another optional processing method, which may include the following: based on a preset hash algorithm, calculate the hash value of the target behavior sequence, and use the hash value of the target behavior sequence as the target sequence fingerprint corresponding to the target behavior sequence.
[0047] The hash algorithm can include a variety of algorithms, such as SHA-512 and MD5, or Locality Sensitive Hash (LSH) algorithms such as SimHash and MinHash. The specific algorithm can be set according to the actual situation.
[0048] In practical applications, the specific processing method for obtaining the benchmark event time sequence flow model that semantically matches the target behavior sequence from the benchmark event time sequence flow model contained in the event time sequence flow database in step S208 can be varied. The following provides another optional processing method, which may specifically include the processing steps S2082 and S2084. Based on this, in the above... Figure 2 Based on this, the specific steps included in this method can be as follows: Figure 3 As shown.
[0049] In step S2082, the similarity between the target behavior sequence and each benchmark event time sequence model contained in the event time sequence process database is calculated.
[0050] In implementation, the target behavior sequence can be converted into a representation vector. In addition, each benchmark event time series process model contained in the event time series process database can be converted into a corresponding representation vector. Then, the similarity between the representation vector corresponding to the target behavior sequence and the representation vector corresponding to each benchmark event time series process model contained in the event time series process database can be calculated using similarity algorithms such as cosine similarity algorithm or Euclidean distance.
[0051] In step S2084, a baseline event time-series flow model that semantically matches the target behavior sequence is determined based on the calculated similarity.
[0052] In implementation, a benchmark event time-series process model that semantically matches the target behavior sequence can be selected from the event time-series process database based on the similarity calculated above. Specifically, the benchmark event time-series process model corresponding to the maximum value of the calculated similarity can be used as the benchmark event time-series process model that semantically matches the target behavior sequence. Alternatively, the benchmark event time-series process model corresponding to the similarity greater than a preset threshold can be used as the benchmark event time-series process model that semantically matches the target behavior sequence.
[0053] In practical applications, event sequence flow databases can be constructed in various ways. The following provides an achievable processing procedure, which may include the following steps A2 to A8.
[0054] In step A2, information is collected from the log data stored in the preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information and timestamp.
[0055] The log database can be any database storing log data, such as a distributed log database in a distributed log system or a log database in a specific business system, depending on the actual situation. Log data can include slow query log data, general query log data, error log data, transaction log data, binary log data, etc., depending on the actual situation. Entity identifiers can include various types, such as user identifiers and terminal device identifiers (specifically, the terminal device's name, MAC address, or IP address). Behavioral information can be information related to user behavior or user operations. Behavioral information can have one or more different types of fields in the log data. The information in these fields can constitute the main content of the behavioral information, such as login field information or information related to transfer behavior. In addition, behavioral information can also be represented by event identifiers (such as API names), depending on the actual situation. Preset time periods can include various types, such as daily, hourly, or 7-day periods, depending on the actual situation.
[0056] In implementation, log data within a preset time period can be collected in real time or in batches from the log database set in a distributed log system or a specified business system. Each log data within the preset time period can be collected as a triplet (i.e., key information), namely <entity identifier, behavior information, timestamp>. In this way, unstructured massive log data can be transformed into structured time-series points (i.e., the key information of the above triplet data).
[0057] In step A4, based on the key information corresponding to each log data, the behavior information belonging to the same entity identifier in the key information corresponding to the log data within a preset time period is grouped together, and the behavior information within the same group is arranged in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences.
[0058] In implementation, based on the key information <entity identifier, behavior information, timestamp> corresponding to each log data, the behavior information belonging to the same entity identifier in the key information of the log data within a preset time period can be grouped together. Within the same group, for each unique entity identifier, all its behavior information is arranged in strict ascending order according to the timestamp, thus forming an ordered list (i.e., behavior sequence). In this way, if there are multiple groups, multiple different behavior sequences can be obtained.
[0059] In step A6, the obtained behavior sequences are clustered, and a baseline event time sequence flow model is constructed based on the clustered behavior sequences.
[0060] In implementation, clustering algorithms can be pre-defined, such as DBSCAN or PrefixSpan. Alternatively, other methods can be used to cluster the obtained behavioral sequences. For example, a corresponding clustering model can be built using machine learning networks, specifically a convolutional neural network. This model can cluster the obtained behavioral sequences, and the specific model can be set according to the actual situation. Using the above clustering algorithms or models, behavioral sequences belonging to the same event or business can be clustered to obtain clustered behavioral sequences. These clustered behavioral sequences can be directly used as the baseline event time-series flow model for the event or business. Alternatively, the clustered behavioral sequences can be further processed. For example, preprocessing such as removing redundant information and completing missing information can be performed. Furthermore, semantically similar behavioral sequences can be merged (e.g., merging behavioral sequences with different parameters but the same processing flow (or process)). Ultimately, a baseline event time-series flow model can be obtained.
[0061] In step A8, an event timing process database is created based on the constructed baseline event timing process model.
[0062] In practical applications, there are various ways to perform clustering on the obtained behavioral sequences in step A6 above. Here is another optional processing method, which may include the following steps A602 to A608.
[0063] In step A602, each obtained behavior sequence is compressed to generate a sequence fingerprint corresponding to each behavior sequence.
[0064] The specific processing method of step A602 above can be found in the specific processing procedure of step S204 above, and will not be repeated here.
[0065] In practical applications, the specific processing method of step A602 above can also be to calculate the hash value of each behavior sequence based on a preset hash algorithm, and use the hash value of each behavior sequence as the sequence fingerprint corresponding to each behavior sequence. For the specific processing process, please refer to the relevant content mentioned above, which will not be repeated here.
[0066] In step A604, based on the sequence fingerprint corresponding to each behavior sequence, the number of occurrences of each behavior sequence and the number of independent users that triggered each behavior sequence are determined.
[0067] In implementation, the sequence fingerprints of a massive number of users can be grouped and aggregated to calculate the PV (Page Views, total occurrences) and UV (Unique Users, unique users) corresponding to the sequence fingerprint of each behavior sequence. PV represents the number of occurrences of each behavior sequence, and UV represents the number of unique users who trigger each behavior sequence. The number of unique users can be the number of non-repeating users who trigger a certain behavior sequence within a preset time period. If the same user triggers a certain behavior sequence multiple times, it is only counted as 1 time.
[0068] In step A606, based on the number of occurrences of each behavior sequence and / or the number of independent users who triggered each behavior sequence, a first sequence fingerprint that meets preset conditions is obtained from the generated sequence fingerprint. The preset conditions are constructed based on the number of occurrences of each behavior sequence and / or the number of independent users who triggered each behavior sequence.
[0069] In implementation, preset conditions can be set according to actual conditions. For example, a threshold for the number of occurrences can be set, where the number of occurrences exceeds the threshold. Alternatively, a threshold for the number of independent users can be set, where the number of independent users triggering the behavior sequence exceeds the threshold. Or, both the number of occurrences and the number of independent users can be set, where the number of occurrences exceeds the threshold and the number of independent users triggering the behavior sequence exceeds the threshold. The specific conditions can be set according to actual conditions. Based on the number of occurrences of each behavior sequence and / or the number of independent users triggering each behavior sequence, it can be determined whether a sequence fingerprint satisfying the preset conditions exists in the generated sequence fingerprint. If so, the sequence fingerprint satisfying the preset conditions can be obtained from the generated sequence fingerprint and used as the first sequence fingerprint.
[0070] In step A608, the behavior sequence corresponding to the first sequence fingerprint is clustered to determine the clustered behavior sequence.
[0071] In implementation, clustering algorithms can be pre-defined, such as DBSCAN or PrefixSpan. These algorithms can be used to cluster behavioral sequences belonging to the same event or business within the behavioral sequences corresponding to the first sequence fingerprint, resulting in clustered behavioral sequences.
[0072] In practical applications, the specific processing method of step A608 above can be varied. The following provides another optional processing method, which may include the processing of steps A6082 and A6084.
[0073] In step A6082, the behavior sequences corresponding to the first sequence fingerprint are clustered to obtain multiple clusters.
[0074] In practice, clustering algorithms such as DBSCAN or PrefixSpan can be used to cluster the behavioral sequences corresponding to the first sequence fingerprint to obtain multiple clusters.
[0075] In step A6084, multiple behavioral sequences with a similarity greater than a preset similarity threshold are identified in each cluster, and the multiple behavioral sequences identified in each cluster are merged, and the merged clusters are used as the clustered behavioral sequences.
[0076] In implementation, considering that there may be semantically similar behavioral sequences within clusters (such as behavioral sequences with different parameters but the same processing flow (or process), these semantically similar behavioral sequences can be further merged. Specifically, a similarity algorithm, such as cosine similarity or Euclidean distance, can be pre-defined, depending on the actual situation. Then, the similarity between different behavioral sequences in each cluster can be calculated using the aforementioned similarity algorithm. This allows us to obtain multiple behavioral sequences in each cluster with a similarity greater than a preset similarity threshold. These multiple behavioral sequences in each cluster can then be merged to obtain multiple merged clusters, which can then be used as the clustered behavioral sequences.
[0077] In practical applications, there are various ways to perform clustering on the obtained behavioral sequences in step A6 above. Here is another optional processing method, which may include the following steps A610 to A614.
[0078] In step A610, graph structure data corresponding to each behavior sequence is constructed based on each obtained behavior sequence.
[0079] In implementation, each obtained behavior sequence can be converted into graph structure data corresponding to each behavior sequence. The graph structure data can include nodes and edges. Nodes can be constructed from relevant information of each user behavior or user operation behavior in the behavior sequence, and edges can be temporal paths.
[0080] In step A612, the graph structure data corresponding to each behavior sequence is input into the graph neural network model to obtain the graph representation information corresponding to each behavior sequence.
[0081] In implementation, the graph structure data corresponding to each behavior sequence can be input into a graph neural network model. The graph neural network model learns the representations of nodes and edges in the graph structure data, ultimately obtaining the graph representation information corresponding to each behavior sequence, which can include node representation information and edge representation information. The graph neural network model can be obtained through supervised training with a large amount of labeled sample data, and can be used to generate the graph representation information corresponding to a certain behavior sequence.
[0082] In step A614, the obtained behavior sequences are clustered based on the graph representation information corresponding to each behavior sequence.
[0083] In practice, after obtaining the graph representation information corresponding to each behavior sequence through the above method, the obtained graph representation information can be clustered based on the graph representation information corresponding to each behavior sequence using the clustering algorithm or clustering model set above, thereby realizing the clustering of the obtained behavior sequences and obtaining the corresponding results.
[0084] In practical applications, after the above-mentioned event time sequence process database is constructed, semantic injection can be performed on relevant information in the benchmark event time sequence process model in the event time sequence process database to enhance the benchmark event time sequence process model. The following is a specific processing method, which may include the following: Based on the API information contained in the preset application programming interface (API) knowledge base, business semantic injection processing is performed on the API node corresponding to each benchmark event time sequence process model in the event time sequence process database to obtain an event time sequence process database containing the enhanced benchmark event time sequence process model.
[0085] The API knowledge base can include business description information, parameter structure, and other related data for preset services.
[0086] In implementation, the API nodes corresponding to each baseline event time sequence process model in the event time sequence process database can be associated with the API information (such as business description information, parameter structure, etc.) contained in the preset API knowledge base. This allows the API nodes in the event time sequence process database to be supplemented with relevant data such as business description information and parameter structure, thereby realizing the injection of business semantics into the API nodes in the event time sequence process database. This results in an enhanced baseline event time sequence process model of "behavioral sequence + business semantics", and finally, an event time sequence process database containing the enhanced baseline event time sequence process model is obtained.
[0087] Based on the event time-series process database containing the enhanced benchmark event time-series process model, the processing of step S206 can be as follows: based on the target sequence fingerprint, query the event time-series process database for the enhanced benchmark event time-series process model corresponding to the target sequence fingerprint, and based on the queried enhanced benchmark event time-series process model, generate a detection analysis report corresponding to the detection request through a preset intelligent agent; the processing of step S208 can be as follows: if the target sequence fingerprint does not exist in the event time-series process database, obtain the enhanced benchmark event time-series process model that semantically matches the target behavior sequence from the enhanced benchmark event time-series process models contained in the event time-series process database, and based on the obtained enhanced benchmark event time-series process model that semantically matches the target behavior sequence, generate a detection analysis report corresponding to the detection request through a preset intelligent agent.
[0088] It should be noted that during the process of obtaining an enhanced benchmark event time sequence flow model that semantically matches the target behavior sequence from the enhanced benchmark event time sequence flow model contained in the event time sequence flow database, it is possible to obtain partial behavior information of the enhanced benchmark event time sequence flow model that matches some behavior information in the target behavior sequence. The remaining behavior information cannot be matched with the enhanced benchmark event time sequence flow model. At this time, based on the partial behavior information of the matched enhanced benchmark event time sequence flow model and its corresponding business semantic information (such as business description information, parameter structure, etc.), as well as the remaining behavior information in the target behavior sequence that cannot be matched, a detection analysis report corresponding to the above detection request can be generated by a preset intelligent agent.
[0089] In another embodiment of this specification, the processes of steps A2 to A8 can be performed independently without being dependent on the processes of steps S202 to S208. For details, please refer to [link to relevant documentation]. Figure 5 The following steps S502 to S508 are also processed.
[0090] In step S502, information is collected from the log data stored in the preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information, and timestamp.
[0091] In step S504, based on the key information corresponding to each log data, the behavior information belonging to the same entity identifier in the key information corresponding to the log data within a preset time period is grouped together, and the behavior information within the same group is arranged in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences.
[0092] In step S506, the obtained behavior sequence is clustered, and a baseline event time sequence flow model is constructed based on the clustered behavior sequence.
[0093] In step S508, an event time series process database is created based on the constructed benchmark event time series process model. The event time series process database can provide a retrieval database for the target behavior sequence that needs to be detected, and trigger the benchmark event time series process model based on the retrieval to generate a corresponding detection analysis report.
[0094] Based on the processing of steps S502 to S508 above, the processing of steps S202 to S208 above may also be included (that is, the processing of steps S502 to S508 is executed first, and then the processing of steps S202 to S208 is executed again based on steps S502 to S508). The specific processing process can be referred to the relevant content mentioned above, and will not be repeated here.
[0095] This specification provides a method for processing behavior sequences. It involves receiving a detection request for a target behavior sequence, compressing the target behavior sequence to generate a target sequence fingerprint, and then querying an event time-series flow database for a corresponding benchmark event time-series flow model based on the fingerprint. Based on the retrieved benchmark event time-series flow model, a pre-set intelligent agent generates a detection analysis report for the detection request. If the target sequence fingerprint is not found in the event time-series flow database, a benchmark event time-series flow model semantically matching the target behavior sequence is obtained from the database. Based on this obtained benchmark event time-series flow model, a pre-set intelligent agent generates a detection analysis report for the target behavior sequence. The detection and analysis report corresponding to the detection request is generated by querying the corresponding benchmark event time sequence model in the pre-built event time sequence process database based on the target behavior sequence to be detected. This allows for the analysis of security risks in financial business, rapid location of faults and performance bottlenecks in business systems, and timely discovery of mainstream user interaction paths and drop-off points within the product, providing data support for product process optimization. This provides a stable API call sequence processing mechanism with universality and business significance. Furthermore, by clustering similar behavior sequences and checking low-frequency hashes or new hashes to discover unknown behavior sequences, new or abnormal behavior sequences can be quickly discovered, thereby improving the accuracy and generation efficiency of the detection and analysis report.
[0096] Furthermore, the introduction of hash aggregation of behavioral sequences reduces the dimensionality of the analysis object from billions of events to tens of thousands of sequence fingerprints, thereby avoiding data explosion and improving computational efficiency. Moreover, pre-screening is performed through PV and / or UV statistics, allowing in-depth analysis only on high-frequency, high-coverage behavioral sequences, thereby reducing noise in the data and improving data processing speed and accuracy. In addition, a "business semantic enhancement" step is designed to combine API behavioral sequences with a static API knowledge base, thereby improving business interpretability.
[0097] The above describes the method for processing behavioral sequences provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a device for processing behavioral sequences, such as... Figure 6 As shown.
[0098] The processing device for this behavior sequence includes: a detection request module 601, a compression module 602, a first report generation module 603, and a second report generation module 604, wherein: The detection request module 601 receives detection requests for the target behavior sequence; Compression module 602 compresses the target behavior sequence to generate a target sequence fingerprint corresponding to the target behavior sequence; The first report generation module 603, based on the target sequence fingerprint, queries the event time sequence process database for the benchmark event time sequence process model corresponding to the target sequence fingerprint, and generates a detection analysis report corresponding to the detection request through a preset intelligent agent based on the queried benchmark event time sequence process model. The second report generation module 604, if the target sequence fingerprint does not exist in the event time sequence process database, obtains a benchmark event time sequence process model that semantically matches the target behavior sequence from the benchmark event time sequence process models contained in the event time sequence process database, and generates a detection analysis report corresponding to the detection request through a preset intelligent agent based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence.
[0099] In the embodiments of this specification, if the detection request is a detection request for risk prevention and control of a preset financial business, and the target behavior sequence is an event behavior sequence related to resource transfer events in the preset financial business, then the generated detection analysis report corresponding to the detection request is used to indicate whether a preset risk exists in the target behavior sequence; or, If the detection request is a detection request for the performance of a preset business system, and the target behavior sequence is a behavior sequence of business execution events in the preset business system, then the generated detection analysis report corresponding to the detection request includes fault information and / or performance defect information; or, If the detection request is a detection request to optimize the business execution process of a preset service, and the target behavior sequence is a behavior sequence corresponding to the business execution process of the preset service, then the generated detection analysis report corresponding to the detection request includes the optimization strategy for the business execution process of the preset service.
[0100] In this embodiment of the specification, the compression module 602 calculates the hash value of the target behavior sequence based on a preset hash algorithm, and uses the hash value of the target behavior sequence as the target sequence fingerprint corresponding to the target behavior sequence.
[0101] In this embodiment of the specification, the second report generation module 604 includes: The similarity calculation unit calculates the similarity between the target behavior sequence and each benchmark event time sequence process model contained in the event time sequence process database; The process model determination unit determines a baseline event time-series process model that semantically matches the target behavior sequence based on calculated similarity.
[0102] In the embodiments described in this specification, the device further includes: The information collection module collects information from log data stored in a preset log database within a preset time period, and obtains key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information and timestamp. The sorting module, based on the key information corresponding to each log data, divides the behavioral information belonging to the same entity identifier in the key information of the log data within a preset time period into a group, and sorts the behavioral information within the same group in ascending order according to the corresponding timestamp, to obtain one or more different behavioral sequences. The clustering module performs clustering processing on the obtained behavior sequences and constructs a baseline event time sequence flow model based on the clustered behavior sequences; The database construction module creates the event time sequence process database based on the constructed baseline event time sequence process model.
[0103] In the embodiments of this specification, the clustering module includes: The compression unit compresses each obtained behavior sequence to generate a sequence fingerprint corresponding to each behavior sequence. The statistics unit determines the frequency of occurrence of each behavior sequence and the number of independent users who triggered each behavior sequence based on the sequence fingerprint corresponding to each behavior sequence. The data extraction unit extracts a first sequence fingerprint that meets preset conditions from the generated sequence fingerprints, based on the number of occurrences of each behavior sequence and / or the number of independent users that trigger each behavior sequence. The preset conditions are constructed based on the number of occurrences of each behavior sequence and / or the number of independent users that trigger each behavior sequence. The first clustering unit performs clustering processing on the behavior sequence corresponding to the first sequence fingerprint to determine the clustered behavior sequence.
[0104] In this embodiment of the specification, the first clustering unit performs clustering processing on the behavior sequence corresponding to the first sequence fingerprint to obtain multiple clusters; determines multiple behavior sequences contained in each cluster with a similarity greater than a preset similarity threshold, and merges the multiple behavior sequences determined in each cluster, and uses the merged multiple clusters as the clustered behavior sequences.
[0105] In the embodiments of this specification, the clustering module includes: The graph construction unit constructs graph structure data corresponding to each behavior sequence based on the obtained behavior sequence. The graph data processing unit inputs the graph structure data corresponding to each behavior sequence into the graph neural network model to obtain the graph representation information corresponding to each behavior sequence. The second clustering unit performs clustering processing on the obtained behavior sequences based on the graph representation information corresponding to each behavior sequence.
[0106] In the embodiments described in this specification, the device further includes: The semantic injection module performs business semantic injection processing on the API nodes corresponding to each benchmark event time sequence process model in the event time sequence process database based on the API information contained in the preset application programming interface (API) knowledge base, thereby obtaining an event time sequence process database containing enhanced benchmark event time sequence process models.
[0107] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more embodiments of this specification, the functions of each module or unit can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative; the division of each module and unit is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or modules can be combined or integrated into another system, or some features can be ignored or not executed, etc.
[0108] This specification provides a behavior sequence processing apparatus. It receives a detection request for a target behavior sequence, compresses the target behavior sequence to generate a target sequence fingerprint, and then queries an event time sequence database for a corresponding benchmark event time sequence model based on the fingerprint. Based on the retrieved benchmark event time sequence model, a preset intelligent agent generates a detection analysis report for the detection request. If the target sequence fingerprint is not found in the event time sequence database, a benchmark event time sequence model semantically matching the target behavior sequence is obtained from the database. Based on this obtained benchmark event time sequence model, a preset intelligent agent generates a detection analysis report for the target behavior sequence. The detection and analysis report corresponding to the detection request is generated by querying the corresponding benchmark event time sequence model in the pre-built event time sequence process database based on the target behavior sequence to be detected. This allows for the analysis of security risks in financial business, rapid location of faults and performance bottlenecks in business systems, and timely discovery of mainstream user interaction paths and drop-off points within the product, providing data support for product process optimization. This provides a stable API call sequence processing mechanism with universality and business significance. Furthermore, by clustering similar behavior sequences and checking low-frequency hashes or new hashes to discover unknown behavior sequences, new or abnormal behavior sequences can be quickly discovered, thereby improving the accuracy and generation efficiency of the detection and analysis report.
[0109] Furthermore, the introduction of hash aggregation of behavioral sequences reduces the dimensionality of the analysis object from billions of events to tens of thousands of sequence fingerprints, thereby avoiding data explosion and improving computational efficiency. Moreover, pre-screening is performed through PV and / or UV statistics, allowing in-depth analysis only on high-frequency, high-coverage behavioral sequences, thereby reducing noise in the data and improving data processing speed and accuracy. In addition, a "business semantic enhancement" step is designed to combine API behavioral sequences with a static API knowledge base, thereby improving business interpretability.
[0110] Following the same line of thought, embodiments of this specification also provide a device for processing behavioral sequences, such as... Figure 7 As shown.
[0111] The processing device for this behavior sequence includes: an information acquisition module 701, a sorting module 702, a clustering module 703, and a database construction module 704, wherein: The information collection module 701 collects information from log data stored in a preset log database within a preset time period, and obtains key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information and timestamp. The sorting module 702, based on the key information corresponding to each log data, divides the behavior information belonging to the same entity identifier in the key information corresponding to the log data within a preset time period into a group, and sorts the behavior information within the same group in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences. Clustering module 703 performs clustering processing on the obtained behavior sequences and constructs a baseline event time sequence flow model based on the clustered behavior sequences; The database construction module 704 creates the event time sequence process database based on the constructed benchmark event time sequence process model. The event time sequence process database provides a retrieval database for the target behavior sequence to be detected and triggers the generation of corresponding detection and analysis reports based on the retrieval benchmark event time sequence process model.
[0112] In the embodiments described in this specification, the device further includes: The detection request module receives detection requests for the target behavior sequence; The compression module compresses the target behavior sequence to generate a target sequence fingerprint corresponding to the target behavior sequence. The first report generation module, based on the target sequence fingerprint, queries the event time sequence process database for the benchmark event time sequence process model corresponding to the target sequence fingerprint, and generates a detection analysis report corresponding to the detection request through a preset intelligent agent based on the queried benchmark event time sequence process model. If the target sequence fingerprint does not exist in the event time sequence process database, the second report generation module obtains a benchmark event time sequence process model that semantically matches the target behavior sequence from the benchmark event time sequence process models contained in the event time sequence process database, and generates a detection analysis report corresponding to the detection request through a preset intelligent agent based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence.
[0113] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more embodiments of this specification, the functions of each module or unit can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative; the division of each module and unit is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or modules can be combined or integrated into another system, or some features can be ignored or not executed, etc.
[0114] This specification provides a behavior sequence processing device. It collects information from log data stored in a preset log database within a preset time period, obtaining key information corresponding to each log data within that time period. The key information includes entity identifiers, behavior information, and timestamps. Based on the key information corresponding to each log data, behavior information belonging to the same entity identifier within the key information of the log data within the preset time period is grouped together. The behavior information within the same group is then arranged in ascending order according to its corresponding timestamp, resulting in one or more different behavior sequences. These behavior sequences are then clustered, and a baseline event time-series is constructed based on the clustered behavior sequences. The process model creates an event time-series process database based on the constructed benchmark event time-series process model. This database provides a retrieval database for the target behavior sequences to be detected and triggers the generation of corresponding detection and analysis reports based on the retrieval of the benchmark event time-series process model. By introducing hash aggregation of behavior sequences, the dimensionality of the analysis object is reduced from billions of events to tens of thousands of sequence fingerprints, thus avoiding data explosion and improving computational efficiency. Furthermore, pre-screening through PV and / or UV statistics allows for in-depth analysis only of high-frequency, high-coverage behavior sequences, reducing noise in the data and improving data processing speed and accuracy. Additionally, a "business semantic enhancement" step is designed, combining API behavior sequences with a static API knowledge base to improve business interpretability. Moreover, clustering similar behavior sequences and checking low-frequency hashes or new hashes to discover unknown behavior sequences allows for the rapid discovery of new or abnormal behavior sequences, thereby improving the accuracy and generation efficiency of the detection and analysis reports.
[0115] The above describes the behavior sequence processing apparatus provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a behavior sequence processing device, such as... Figure 8 As shown.
[0116] The device for processing the behavior sequence can be a terminal device or a server, as described in the above embodiments.
[0117] The behavior sequence processing device can vary considerably depending on its configuration or performance, and may include a communication interface 802, a user interface 804, a processor 806, and a data storage 808. These components are interconnected and communicate with each other via a system bus, network, or other connection mechanism 810. The communication interface 802 enables the behavior sequence processing device 800 to communicate with other devices, access networks, and transmission networks via analog or digital modulation. For example, the communication interface 802 may include a chipset and antenna for wireless communication with a radio access network or access point. Furthermore, the communication interface 802 can be a wired interface such as Ethernet, Token Ring, or a USB port, or a wireless interface such as Wi-Fi, Bluetooth, Global Positioning System (GPS), or a wide-area wireless interface (e.g., WiMAX or LTE). Of course, the communication interface 802 may also support other forms of physical layer interfaces and standard or proprietary communication protocols. The communication interface 802 may also include multiple physical communication interfaces, such as Wi-Fi, Bluetooth, and wide-area wireless interfaces.
[0118] User interface 804 includes receiving user input and providing output to the user. Therefore, user interface 804 may include input components such as a keypad, keyboard, touch-sensitive or presence-sensitive panel, computer mouse, trackball, joystick, microphone, still camera, and video camera, and output components such as a display screen (which may be combined with a touch-sensitive panel), CRT, LCD, LED, display using DLP technology, printer, and other similar devices known or developed in the future. User interface 804 may also generate auditory output via speakers, speaker jacks, audio output ports, audio output devices, headphones, and other similar devices known or developed in the future. In some embodiments, user interface 804 may include software, circuitry, or other forms of logic capable of transmitting and receiving data from external user input / output devices. Additionally or alternatively, the behavior sequence processing device 800 may support remote access from other devices via communication interface 802 or another physical interface (not shown). User interface 804 may be configured to receive user input, the position and movement of which may be indicated by an indicator or cursor described herein. User interface 804 may also be configured as a display device for rendering or displaying text fragments.
[0119] The processor 806 may contain one or more general-purpose processors and / or special-purpose processors.
[0120] Data storage 808 may include one or more volatile and / or non-volatile storage components and may be integrated wholly or partially with processor 806. Data storage 808 may include removable and non-removable components.
[0121] Processor 806 is capable of executing program instructions 818 (e.g., compiled or uncompiled program logic and / or machine code) stored in data storage 808 to perform the various functions described herein. Data storage 808 may contain a non-transitory computer-readable medium on which program instructions are stored, which, when executed by processing device 800 of a sequence of actions, enable processing device 800 of a sequence of actions to perform any methods, processes, or functions disclosed in this specification and / or the accompanying drawings. Execution of program instructions 818 by processor 806 may result in processor 806 using data 812.
[0122] For example, program instructions 818 may include an operating system 822 (e.g., an operating system kernel, device drivers, and / or other modules) and one or more applications 820 (e.g., a browser, social application, or game application) installed on the processing device 800 of the behavior sequence. Similarly, data 812 may include operating system data 816 and application data 814. Operating system data 816 is primarily accessible to the operating system 822, while application data 814 is primarily accessible to one or more applications 820. Application data 814 may reside in a file system that is visible or hidden from the user of the processing device 800 of the behavior sequence.
[0123] Application 820 can communicate with operating system 812 through one or more application programming interfaces (APIs). These APIs help application 820 read and / or write application data 814, transmit or receive information via communication interface 802, receive or display information on user interface 804, etc.
[0124] In some terminology, application 820 may be simply referred to as "app". Furthermore, application 820 can be downloaded to the behavior sequence processing device 800 through one or more online app stores or app markets. However, the application can also be installed on the behavior sequence processing device 800 in other ways, such as through a web browser or a physical interface on the behavior sequence processing device 800 (e.g., a USB port).
[0125] Specifically, in this embodiment, the behavior sequence processing device 800 includes a data storage 808 and one or more program instructions 818, wherein one or more program instructions 818 are stored in the data storage 808, and one or more program instructions 818 are configured to be executed by one or more processors. The one or more program instructions include computer-executable instructions for performing the following: Receive detection requests for target behavior sequences; The target behavior sequence is compressed to generate a target sequence fingerprint corresponding to the target behavior sequence; Based on the target sequence fingerprint, a benchmark event time sequence process model corresponding to the target sequence fingerprint is queried from the event time sequence process database, and based on the queried benchmark event time sequence process model, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent. If the target sequence fingerprint does not exist in the event time sequence process database, a benchmark event time sequence process model that semantically matches the target behavior sequence is obtained from the benchmark event time sequence process models contained in the event time sequence process database. Based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent.
[0126] Furthermore, specifically in this embodiment, the behavior sequence processing device 800 includes a data storage 808 and one or more program instructions 818, wherein one or more program instructions 818 are stored in the data storage 808, and one or more program instructions 818 are configured to be executed by one or more processors. The one or more program instructions include computer-executable instructions for performing the following: Information is collected from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information and timestamp. Based on the key information corresponding to each log data, the behavior information belonging to the same entity identifier in the key information of the log data within a preset time period is grouped together, and the behavior information within the same group is sorted in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences. The obtained behavior sequences are clustered, and a baseline event time-series flow model is constructed based on the clustered behavior sequences. An event time series process database is created based on the constructed benchmark event time series process model. The event time series process database provides a retrieval database for the target behavior sequences that need to be detected, and triggers the benchmark event time series process model based on the retrieval to generate corresponding detection and analysis reports.
[0127] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device embodiment for processing behavioral sequences is described simply because it is fundamentally similar to the method embodiment; relevant parts can be referred to the descriptions in the method embodiment.
[0128] This specification provides a behavior sequence processing device. It receives a detection request for a target behavior sequence, compresses the target behavior sequence to generate a target sequence fingerprint, and then queries an event time sequence database for a corresponding benchmark event time sequence model based on the fingerprint. Based on the retrieved benchmark event time sequence model, a preset intelligent agent generates a detection analysis report for the detection request. If the target sequence fingerprint is not found in the event time sequence database, a benchmark event time sequence model semantically matching the target behavior sequence is obtained from the database. Based on this model, a preset intelligent agent generates a detection analysis report for the target behavior sequence. The detection and analysis report corresponding to the detection request is generated by querying the corresponding benchmark event time sequence model in the pre-built event time sequence process database based on the target behavior sequence to be detected. This allows for the analysis of security risks in financial business, rapid location of faults and performance bottlenecks in business systems, and timely discovery of mainstream user interaction paths and drop-off points within the product, providing data support for product process optimization. This provides a stable API call sequence processing mechanism with universality and business significance. Furthermore, by clustering similar behavior sequences and checking low-frequency hashes or new hashes to discover unknown behavior sequences, new or abnormal behavior sequences can be quickly discovered, thereby improving the accuracy and generation efficiency of the detection and analysis report.
[0129] Furthermore, based on the above Figures 1 to 5 This specification also provides a storage medium for storing computer-executable instruction information in one or more embodiments. In one specific embodiment, the storage medium may be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, it can realize the following process: Receive detection requests for target behavior sequences; The target behavior sequence is compressed to generate a target sequence fingerprint corresponding to the target behavior sequence; Based on the target sequence fingerprint, a benchmark event time sequence process model corresponding to the target sequence fingerprint is queried from the event time sequence process database, and based on the queried benchmark event time sequence process model, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent. If the target sequence fingerprint does not exist in the event time sequence process database, a benchmark event time sequence process model that semantically matches the target behavior sequence is obtained from the benchmark event time sequence process models contained in the event time sequence process database. Based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent.
[0130] In another specific embodiment, the storage medium can be a USB flash drive, optical disc, hard disk, etc., and the computer-executable instruction information stored in the storage medium can achieve the following process when executed by the processor: Information is collected from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information and timestamp. Based on the key information corresponding to each log data, the behavior information belonging to the same entity identifier in the key information of the log data within a preset time period is grouped together, and the behavior information within the same group is sorted in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences. The obtained behavior sequences are clustered, and a baseline event time-series flow model is constructed based on the clustered behavior sequences. An event time series process database is created based on the constructed benchmark event time series process model. The event time series process database provides a retrieval database for the target behavior sequences that need to be detected, and triggers the benchmark event time series process model based on the retrieval to generate corresponding detection and analysis reports.
[0131] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described storage medium embodiment is basically similar to the method embodiment, so the description is relatively simple; relevant parts can be referred to the description of the method embodiment.
[0132] This specification provides a storage medium that receives a detection request for a target behavior sequence, compresses the target behavior sequence to generate a target sequence fingerprint, and then queries an event time sequence database for a corresponding benchmark event time sequence model based on the target sequence fingerprint. Based on the retrieved benchmark event time sequence model, a preset intelligent agent generates a detection analysis report for the detection request. If the target sequence fingerprint is not found in the event time sequence database, a benchmark event time sequence model semantically matching the target behavior sequence is obtained from the database. Based on this obtained benchmark event time sequence model, a preset intelligent agent generates a report for the detection request. The system generates corresponding detection and analysis reports. By querying a pre-built event sequence database with the target behavior sequence to be detected, a corresponding baseline event sequence model is retrieved, generating a detection and analysis report for the target behavior sequence. This allows for the analysis of security risks in financial businesses, rapid identification of system failures and performance bottlenecks, and timely discovery of mainstream user interaction paths and churn points within the product, providing data support for product process optimization. It offers a stable API call sequence processing mechanism with universality and business significance. Furthermore, by clustering similar behavior sequences and examining low-frequency hashes or new hashes to discover unknown behavior sequences, it can quickly identify new or abnormal behavior sequences, thereby improving the accuracy and efficiency of the detection and analysis report generation.
[0133] Furthermore, based on the above Figures 1 to 5 This specification also provides one or more embodiments of a computer program product, including a computer program, which, when executed by a processor, can perform the following processes: Receive detection requests for target behavior sequences; The target behavior sequence is compressed to generate a target sequence fingerprint corresponding to the target behavior sequence; Based on the target sequence fingerprint, a benchmark event time sequence process model corresponding to the target sequence fingerprint is queried from the event time sequence process database, and based on the queried benchmark event time sequence process model, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent. If the target sequence fingerprint does not exist in the event time sequence process database, a benchmark event time sequence process model that semantically matches the target behavior sequence is obtained from the benchmark event time sequence process models contained in the event time sequence process database. Based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent.
[0134] Furthermore, in another specific embodiment, the computer program product includes a computer program that, when executed by a processor, performs the following process: Information is collected from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information and timestamp. Based on the key information corresponding to each log data, the behavior information belonging to the same entity identifier in the key information of the log data within a preset time period is grouped together, and the behavior information within the same group is sorted in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences. The obtained behavior sequences are clustered, and a baseline event time-series flow model is constructed based on the clustered behavior sequences. An event time series process database is created based on the constructed benchmark event time series process model. The event time series process database provides a retrieval database for the target behavior sequences that need to be detected, and triggers the benchmark event time series process model based on the retrieval to generate corresponding detection and analysis reports.
[0135] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described embodiment of a computer program product is relatively simple in description because it is fundamentally similar to the method embodiment; relevant parts can be referred to the description of the method embodiment.
[0136] This specification provides a computer program product that receives a detection request for a target behavior sequence, compresses the target behavior sequence to generate a target sequence fingerprint, and then queries an event time sequence database for a corresponding benchmark event time sequence model based on the target sequence fingerprint. Based on the retrieved benchmark event time sequence model, a preset intelligent agent generates a detection analysis report for the detection request. If the target sequence fingerprint is not found in the event time sequence database, a benchmark event time sequence model semantically matching the target behavior sequence is obtained from the database. Based on this obtained benchmark event time sequence model, a preset intelligent agent generates a detection analysis report for the request. The system generates a detection and analysis report corresponding to the test request. This involves querying a pre-built event sequence database to retrieve the corresponding baseline event sequence model based on the target behavior sequence, thereby generating a detection and analysis report for the target behavior sequence. This allows for the analysis of security risks in financial businesses, rapid identification of system failures and performance bottlenecks, and timely discovery of mainstream user interaction paths and churn points within the product, providing data support for product process optimization. It offers a stable API call sequence processing mechanism with universality and business significance. Furthermore, by clustering similar behavior sequences and checking low-frequency hashes or new hashes to discover unknown behavior sequences, it can quickly identify new or abnormal behavior sequences, thereby improving the accuracy and efficiency of the detection and analysis report generation.
[0137] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims may be performed in a different order than those shown in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are possible or may be advantageous. Moreover, although one or more embodiments of this specification provide method steps as described in the embodiments or flowcharts, it is understood that the order of steps listed in the embodiments or flowcharts is merely one possible execution order among many steps and does not represent the only execution order. Therefore, when method steps are involved in the claims, adjustments to the order of those steps, or parallelism between steps, are also within the scope of protection of the claims.
[0138] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0139] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0140] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0141] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0142] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0143] The embodiments described herein are illustrated with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0144] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0145] These computer program instructions may also be loaded onto a computer or other programmable device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0146] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0147] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0148] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0149] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical or equivalent elements in the process, method, article, or apparatus that includes said element. Furthermore, "a," "an," and "the" are not specifically singular and may include plural forms. Ordinal numbers such as "first," "second," etc., do not necessarily indicate order; they are often used to distinguish objects. For example, "first server" and "second server" usually refer to two servers, described as "first server" and "second server" to differentiate them; however, sometimes these two servers may be the same server. Moreover, in this specification, unless explicitly stated otherwise, "receiving and sending data" does not necessarily mean direct receiving and sending; it can be indirect receiving and sending (i.e., receiving and sending indirectly through one or more entities). Similarly, in this specification, unless otherwise stated, the relationships between structures can be direct or indirect.
[0150] Furthermore, the specific terms used in this specification to describe embodiments, such as "an embodiment," "one embodiment," or "some embodiments," refer to a particular feature, structure, or characteristic related to at least one embodiment of this specification. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. Moreover, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples, without contradiction.
[0151] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0152] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0153] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0154] The above description is merely an embodiment of this specification and is not intended to limit this document. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims in this document.
Claims
1. A method for processing behavioral sequences, the method comprising: Receive detection requests for target behavior sequences; The target behavior sequence is compressed to generate a target sequence fingerprint corresponding to the target behavior sequence; Based on the target sequence fingerprint, a benchmark event time sequence process model corresponding to the target sequence fingerprint is queried from the event time sequence process database, and based on the queried benchmark event time sequence process model, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent. If the target sequence fingerprint does not exist in the event time sequence process database, a benchmark event time sequence process model that semantically matches the target behavior sequence is obtained from the benchmark event time sequence process models contained in the event time sequence process database. Based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent.
2. The method according to claim 1, wherein if the detection request is a detection request for risk prevention and control of a preset financial business, and the target behavior sequence is an event behavior sequence related to resource transfer events in the preset financial business, then the generated detection analysis report corresponding to the detection request is used to indicate whether the target behavior sequence has a preset risk; or, If the detection request is a detection request for the performance of a preset business system, and the target behavior sequence is a behavior sequence of business execution events in the preset business system, then the generated detection analysis report corresponding to the detection request includes fault information and / or performance defect information. or, If the detection request is a detection request to optimize the business execution process of a preset service, and the target behavior sequence is a behavior sequence corresponding to the business execution process of the preset service, then the generated detection analysis report corresponding to the detection request includes the optimization strategy for the business execution process of the preset service.
3. The method according to claim 1, wherein compressing the target behavior sequence to generate a target sequence fingerprint corresponding to the target behavior sequence comprises: Based on a preset hash algorithm, the hash value of the target behavior sequence is calculated, and the hash value of the target behavior sequence is used as the target sequence fingerprint corresponding to the target behavior sequence.
4. The method according to claim 1, wherein obtaining a benchmark event time-series flow model semantically matching the target behavior sequence from the benchmark event time-series flow models contained in the event time-series flow database comprises: Calculate the similarity between the target behavior sequence and each benchmark event timeline model contained in the event timeline database; Based on the calculated similarity, a baseline event time-series flow model that semantically matches the target behavior sequence is determined.
5. The method according to claim 1, further comprising: Information is collected from log data stored in a preset log database within a preset time period to obtain key information corresponding to each log data within the preset time period. The key information includes entity identifier, behavior information, and timestamp. Based on the key information corresponding to each log data, the behavior information belonging to the same entity identifier in the key information of the log data within a preset time period is grouped together, and the behavior information within the same group is sorted in ascending order according to the corresponding timestamp to obtain one or more different behavior sequences. The obtained behavior sequences are clustered, and a baseline event time-series flow model is constructed based on the clustered behavior sequences. The event timing process database is created based on the constructed baseline event timing process model.
6. The method according to claim 5, wherein clustering the obtained behavioral sequences comprises: Each obtained behavior sequence is compressed to generate a sequence fingerprint corresponding to each behavior sequence; Based on the sequence fingerprint corresponding to each behavior sequence, determine the number of occurrences of each behavior sequence and the number of independent users that triggered each behavior sequence; Based on the occurrence count of each behavior sequence and / or the number of independent users triggering each behavior sequence, a first sequence fingerprint that meets preset conditions is obtained from the generated sequence fingerprints. The preset conditions are constructed based on the occurrence count of each behavior sequence and / or the number of independent users triggering each behavior sequence. Clustering is performed on the behavioral sequences corresponding to the first sequence fingerprint to determine the clustered behavioral sequences.
7. The method according to claim 6, wherein clustering the behavior sequence corresponding to the first sequence fingerprint to determine the clustered behavior sequence comprises: The behavior sequences corresponding to the first sequence fingerprint are clustered to obtain multiple clusters. Identify multiple behavioral sequences in each cluster that have a similarity greater than a preset similarity threshold, merge the identified multiple behavioral sequences in each cluster, and use the merged multiple clusters as the clustered behavioral sequences.
8. The method according to claim 5, wherein clustering the obtained behavioral sequences comprises: Construct graph structure data corresponding to each behavior sequence based on the obtained behavior sequence; The graph structure data corresponding to each behavior sequence is input into the graph neural network model to obtain the graph representation information corresponding to each behavior sequence; Based on the graph representation information corresponding to each behavior sequence, the obtained behavior sequences are clustered.
9. The method according to claim 5, further comprising: Based on the API information contained in the preset application programming interface (API) knowledge base, business semantic injection processing is performed on the API nodes corresponding to each benchmark event time sequence process model in the event time sequence process database to obtain an event time sequence process database containing enhanced benchmark event time sequence process models.
10. A processing apparatus for a sequence of actions, the apparatus comprising: The detection request module receives detection requests for the target behavior sequence; The compression module compresses the target behavior sequence to generate a target sequence fingerprint corresponding to the target behavior sequence. The first report generation module, based on the target sequence fingerprint, queries the event time sequence process database for the benchmark event time sequence process model corresponding to the target sequence fingerprint, and generates a detection analysis report corresponding to the detection request through a preset intelligent agent based on the queried benchmark event time sequence process model. If the target sequence fingerprint does not exist in the event time sequence process database, the second report generation module obtains a benchmark event time sequence process model that semantically matches the target behavior sequence from the benchmark event time sequence process models contained in the event time sequence process database, and generates a detection analysis report corresponding to the detection request through a preset intelligent agent based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence.
11. A device for processing behavioral sequences, the device comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Receive detection requests for target behavior sequences; The target behavior sequence is compressed to generate a target sequence fingerprint corresponding to the target behavior sequence; Based on the target sequence fingerprint, a benchmark event time sequence process model corresponding to the target sequence fingerprint is queried from the event time sequence process database, and based on the queried benchmark event time sequence process model, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent. If the target sequence fingerprint does not exist in the event time sequence process database, a benchmark event time sequence process model that semantically matches the target behavior sequence is obtained from the benchmark event time sequence process models contained in the event time sequence process database. Based on the obtained benchmark event time sequence process model that semantically matches the target behavior sequence, a detection analysis report corresponding to the detection request is generated by a preset intelligent agent.