Resource protection method and device based on user behavior analysis, equipment and medium

By deploying multi-layered protection mechanisms at the network, host, and application layers, and combining machine learning for intelligent log analysis and dynamic permission management, the weaknesses in business data protection in existing technologies are addressed, achieving efficient and accurate resource protection.

CN122437705APending Publication Date: 2026-07-21CHINA PING AN LIFE INSURANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA PING AN LIFE INSURANCE CO LTD
Filing Date
2026-05-09
Publication Date
2026-07-21

Smart Images

  • Figure CN122437705A_ABST
    Figure CN122437705A_ABST
Patent Text Reader

Abstract

The application discloses a resource protection method and device based on user behavior analysis, equipment and storage medium, through the history behavior characteristic vector and the access resource level sequence, the behavior abnormality of the user and the importance of the resource to be accessed are quantified, and the dynamic risk of the target user is quantified through the two-dimensional features, the behavior abnormality level is obtained, the permission granularity is adjusted according to the user history behavior and the importance of the data to be accessed, the initial permission table is dynamically adjusted, the permission of the target user in the current session is trimmed to the minimum permission table, and decision delay is avoided. Based on the preset decision rule, the permission check is refined from the entrance level to the single action corresponding to each resource operation instruction, which prevents excessive authorization and avoids misblocking. The method can be applied to the resource protection function of the system in the financial business field or the medical field, so as to improve the protection efficiency of the business resource and improve the business protection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent decision-making technology, and in particular to a resource protection method, device, computer equipment, and computer-readable storage medium based on user behavior analysis. Background Technology

[0002] Current business data protection primarily relies on bastion hosts deployed at the host layer for entry-level permissions or authentication. However, this solution suffers from weak single-point protection, and its permission table remains unchanged over time, making it prone to over-authorization or false blocking. Furthermore, static permission matching is only performed upon receiving a single instruction, increasing decision-making delays and resulting in low accuracy and efficiency in business data protection. Therefore, improving the accuracy and efficiency of current business resource protection has become a pressing issue. Summary of the Invention

[0003] This application provides a resource protection method, apparatus, computer equipment, and computer-readable storage medium based on user behavior analysis to improve the accuracy and efficiency of current business resource protection.

[0004] Firstly, this application provides a resource protection method based on user behavior analysis, the resource protection method comprising: Upon receiving a resource operation instruction from a target user, the system acquires the target user's historical behavior feature vector and access resource level sequence. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. The abnormal behavior level of the target user is calculated based on the preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. Obtain the initial permission table of the target user, and dynamically adjust the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session; The system obtains the resource level and operation action corresponding to the resource operation instruction, and determines whether the target user has permission to perform the operation action on the resource to be accessed based on preset decision rules, the resource level to be accessed, and the minimum permission table.

[0005] Secondly, this application also provides a resource protection device based on user behavior analysis, comprising: The dual-dimensional feature acquisition module is used to acquire the historical behavior feature vector and access resource level sequence of the target user when receiving a resource operation instruction sent by the target user. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. An anomaly level calculation module is used to calculate the anomaly level of the target user's behavior based on a preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. The permission dynamic control module is used to obtain the initial permission table of the target user, and dynamically control the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session. The resource permission determination module is used to obtain the level of the resource to be accessed and the action to be performed corresponding to the resource operation instruction, and determine whether the target user has the permission to perform the action to be performed on the resource to be accessed based on preset decision rules, the level of the resource to be accessed and the minimum permission table.

[0006] Thirdly, this application also provides a computer device, the computer device including a memory and a processor; the memory is used to store a computer program; the processor is used to execute the computer program and, when executing the computer program, to implement the resource protection based on user behavior analysis as described above.

[0007] Fourthly, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement the resource protection based on user behavior analysis as described above.

[0008] This application discloses a resource protection method, apparatus, computer device, and storage medium based on user behavior analysis. Upon receiving a resource operation instruction from a target user, the method acquires the target user's historical behavior feature vector and access resource level sequence. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitive data within the preset time window. Based on preset weight coefficients, the historical behavior feature vector, and the access resource level sequence, the method calculates the target user's behavior anomaly level. It then acquires the target user's initial permission table and dynamically adjusts it based on the behavior anomaly level to generate a minimum permission table for the target user in the current session. Finally, it acquires the resource level to be accessed and the action to be performed corresponding to the resource operation instruction, and determines whether the target user has permission to perform the action on the resource to be accessed based on preset decision rules, the resource level to be accessed, and the minimum permission table. By employing the methods described above, this application quantifies abnormal user behavior and the importance of the resources to be accessed through historical behavior feature vectors representing the target user's historical behavior and access resource level sequences representing the importance of the resources accessed by the target user. Furthermore, it quantifies the dynamic risk of the target user using these two-dimensional features to obtain an abnormal behavior level. This allows for dynamic adjustment of permissions in the initial permission table, reducing the target user's permissions within the current session to the minimum permission level. This granularity of permissions is adjusted based on the user's historical behavior and the importance of the data to be accessed, avoiding decision-making delays. Based on preset decision rules, the access resource levels, and the minimum permission table, permission verification is refined from the entry level to the single action corresponding to each resource operation instruction. This prevents both over-authorization and false blocking, thereby improving both the efficiency and accuracy of business resource protection. Attached Figure Description

[0009] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 This is a schematic flowchart of a resource protection method based on user behavior analysis provided in an embodiment of this application; Figure 2 A schematic block diagram of a resource protection device based on user behavior analysis provided for embodiments of this application; Figure 3 A schematic block diagram of the structure of a computer device provided for an embodiment of this application. Detailed Implementation

[0011] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0012] The flowchart shown in the attached diagram is for illustrative purposes only and does not necessarily include all content and operations / steps, nor does it necessarily have to be performed in the order described. For example, some operations / steps can be broken down, combined, or partially merged, so the actual execution order may change depending on the actual situation.

[0013] It should be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of the application. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0014] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0015] This application provides a resource protection method, apparatus, computer device, and storage medium based on user behavior analysis. The user behavior analysis-based resource protection method can be applied to a server, achieving resource protection through a resource protection program deployed on the server. The server can be a standalone server or a server cluster.

[0016] The following detailed description of some embodiments of this application is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0017] Please see Figure 1 , Figure 1 This is a schematic flowchart of a resource protection method based on user behavior analysis provided in an embodiment of this application.

[0018] like Figure 1 As shown, the resource protection method based on user behavior analysis specifically includes steps S101 to S104.

[0019] Step S101: Upon receiving a resource operation instruction sent by the target user, obtain the target user's historical behavior feature vector and access resource level sequence; The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. In this embodiment, traditional business data protection mainly relies on bastion hosts deployed at the host layer for basic access control and authentication, which cannot meet complex network security needs and has the following main problems: 1. Insufficient single-point protection: Traditional bastion hosts are just a simple entry point and do not have the means or ability to provide multi-layered protection, making them easy to bypass and break through.

[0020] 2. Limited log auditing capabilities: Bastion hosts can record user operation logs, but because they cannot analyze these logs or provide real-time alerts, they cannot promptly detect any abnormal user behavior.

[0021] 3. Coarse-grained permission management: In the past, bastion host permission management was implemented through roles or groups, which did not achieve fine-grained permission management, thus posing a great security risk.

[0022] 4. Lack of automated response capabilities: Once a threat is detected, traditional bastion hosts do not have an automatic response method and rely entirely on manual intervention, which is very inefficient.

[0023] To address the aforementioned issues, this embodiment provides a resource protection method based on user behavior, comprising: 1. Construct a multi-layered protection system: For system security issues, security is improved through multiple layers, including the network layer, host layer, and application layer.

[0024] At the network layer, firewalls and intrusion detection systems (IDS) are deployed to filter illegal traffic. At the host layer, a bastion host is deployed as the sole entry point for user login, performing identity authentication and access control. At the application layer, intrusion prevention systems (IPS) and application firewalls are deployed to protect critical business systems.

[0025] 2. Intelligent Log Analysis and Alerts: Utilizes machine learning technology to analyze the bastion host's log information and proactively handles abnormal user behavior based on the analysis results.

[0026] This involves collecting comprehensive log data across the network, host, and application layers, including information such as user logins, user actions, and system status. Machine learning algorithms are then used to perform in-depth analysis of the log data to identify abnormal behavior patterns. Real-time alerts are triggered to notify security administrators for appropriate action.

[0027] 3. Fine-grained permission management: Assign user permissions based on user behavior and implement dynamic permission granting for fine-grained permission management.

[0028] This means dynamically adjusting a user's permission scope based on their historical behavior data. Multi-factor authentication (MFA) and behavioral authentication technologies further enhance the granularity and security of permission management.

[0029] 4. Automated response mechanism: When a security threat is detected, the system will determine whether to take isolation or blocking actions to reduce security risks based on the scenario.

[0030] When a security threat is detected, the system automatically triggers an isolation policy to isolate abnormal users or devices in a secure area. For serious threats, the system blocks related traffic or shuts down affected services.

[0031] 5. Continuous optimization and feedback The system security should be assessed and protective measures and handling procedures should be revised in a timely manner according to the prescribed cycle.

[0032] The system's protection capabilities are continuously improved based on security incidents reported in the feedback information.

[0033] Therefore, through the above method, this embodiment uses the bastion host as the sole identity anchor point, upgrading the traditional single-point entry point to a four-layer closed loop. First, multi-layer probes are used to label all log data across the network layer, host layer, and application layer with identity tags (i.e., source layer tags). Then, machine learning is used to create user behavior profiles over a period of time, calculating a minimum privilege policy in real time. Automatic responses are then used to immediately tighten or allow permissions, and the results are fed back into the model, forming a continuously iterating adaptive protection system. This results in more complete and intelligent network security protection capabilities, and is more suitable for the multi-layered security requirements of the domestic IT innovation environment.

[0034] Specifically, the resource protection method provided in this implementation detects abnormal behavior of user operation commands / data reading commands within a certain time window (such as 5 min, 30 min, 1 h), and dynamically tightens the permissions of users who are judged to be abnormal.

[0035] The original multi-source logs collected from the entire domain are pre-cleaned, aggregated, and modeled to output a structured feature vector that tells "who, at what time, on what resource, and what series of actions were performed".

[0036] Specifically, network layer, host layer, and application layer probes can capture raw data in real time and unify the logs of the three layers into the bastion host log center; then, historical behavioral features (login frequency, command sequence, resource access pattern) are extracted through machine learning models and recorded as a structured feature vector table (each record contains user ID, behavioral features, and layer source).

[0037] In a specific embodiment, during the raw log aggregation, resource importance is further tagged, i.e., a "data importance tag" field is added (such as four levels of tags: public / internal / confidential / top secret). This can be written in real-time at the file, table, or API level by a DLP or data classification engine. This results in a raw log stream carrying a triple tag: "source layer tag + user ID + data importance tag".

[0038] Upon receiving a resource operation instruction from the target user, extract two-dimensional features from the original log stream: a historical behavior feature vector and a resource access level sequence (used to count the target user's access frequency, cumulative downloads, and number of times they accessed higher-level data within a certain period of time). Store these features in a feature vector table (user ID, historical behavior features, hierarchical source, and resource access level sequence).

[0039] The feature vector table is used to perform strategy calculations at two different granularities: Dynamic least privileges for "accounts / sessions" (coarse-grained, focusing on identity-behavioral risk). Real-time access control for each read operation (fine-grained, with added data sensitivity).

[0040] This involves providing a behavioral profile of the target user based on historical behavioral characteristics, and then reallocating the legal activity scope of the target user's corresponding account based on the behavioral profile. In other words, by combining the minimum permission table of the current session with the behavioral profile and resource importance tags, a single action decision is made for each resource operation command of the user, thereby realizing a two-layer dynamic permission system that achieves long-term convergence of coarse-grained permissions and real-time decision-making of fine-grained permissions.

[0041] Business resources include various types of business data (such as files, tables, etc.) and interfaces.

[0042] Step S102: Calculate the abnormal behavior level of the target user based on the preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. In this embodiment, after obtaining the historical behavioral feature vectors of users within a quantified preset time window, including login frequency, command sequence TF-IDF vector, and abnormal command ratio, as well as the access resource level sequence of the distribution vector of user access frequency to four levels of sensitive resources (public, internal, confidential, and top secret) within the same window, the abnormal behavior level of the target user is calculated by further combining the preset weight coefficients of the two features.

[0043] Two sets of preset weight coefficients can be obtained through offline training, namely the behavior weight w1 and the resource importance weight w2.

[0044] Vector normalization is performed on the historical behavior feature vector and the access resource level sequence respectively: The historical behavior feature vector is normalized to [0,1] using Min-Max. The access resource level sequence is L2 normalized to [0,1].

[0045] Then, a weighted sum is performed on the two normalized features: Abnormal behavior level = w1 × normalized behavioral feature vector score + w2 × normalized resource sensitivity score.

[0046] in: Behavioral Feature Vector Score = Login Anomaly Score + Command Anomaly Score + Statistical Anomaly Score Resource sensitivity score = 1 × number of times it was made public + 0.8 × number of times it was made internal + 0.5 × number of times it was classified as confidential + 0.2 × number of times it was classified as top secret.

[0047] Then the scores are mapped to levels, that is, the final score is mapped to a level four anomaly level: 0–0.25: Low risk; 0.25–0.50: Medium risk; 0.50–0.75: High risk; 0.75–1.00: Extremely high risk.

[0048] The risk levels derived from the score range can be used for subsequent dynamic permission pruning, taking into account both user and data risks, thereby reducing false positive and false negative rates.

[0049] Step S103: Obtain the initial permission table of the target user, and dynamically adjust the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session; In this embodiment, to address the problem of over-granting and false blocking caused by the traditional static permission table, the permissions table is dynamically reduced based on real-time user anomaly risks, thus avoiding over-granting or false blocking.

[0050] In one embodiment, the step of dynamically adjusting the initial permission table based on the abnormal risk level to generate the minimum permission table for the target user in the current session includes: The abnormal risk level is quantified, and a first coefficient of the quantified abnormal risk level is obtained based on the first weight mapping rule. Obtain the resource level corresponding to each resource record in the initial permission table, and obtain the second coefficient corresponding to the resource importance level based on the data classification engine and the second weight mapping rule; Based on the first coefficient and the second coefficient, the target weight corresponding to each resource record is calculated; Obtain the permission actions corresponding to each resource record, and based on the comparison results of the target weight of each resource record and the preset threshold, perform permission pruning on the initial permissions corresponding to each resource record to obtain the minimum permission table.

[0051] Specifically, it includes the following steps: a) Quantitative tightening coefficient k=1 – abnormal behavior level, k maps to [0,1], the higher the risk, the smaller k becomes.

[0052] b) Resource importance weight mapping Public = 1, Internal = 0.8, Confidential = 0.5, Top Secret = 0.2.

[0053] c) Target weight calculation For each resource record: target_weight=k×sensitivity_weight d) Permission pruning rules If target_weight ≥ 0.5, then retain the resource and linearly degrade the action: If the weight is 0.5–0.7, only read access to the resource is retained. If the weight is 0.7–0.9, then read and write permissions for the resource are retained (read + write). If the weight is ≥0.9, then read, write and modify permissions for the resource are retained (read+write+exec).

[0054] If target_weight < 0.5, then remove all permissions for that resource.

[0055] e) Aggregated output Aggregate the remaining records by user_id + session_id to generate a JSON file with minimum permissions: {user_id, session_id, min_resources:[{resource_id, actions}],timestamp} f) Cache effective Write Redis key min_perm:<user_id> :<session_id> TTL = Session Lifetime; synchronous push to bastion host IAM, WAF, and DB Proxy.

[0056] By using the above method, the granularity of permissions is refined from host / directory to permission verification for a single action, realizing dynamic means and avoiding false blocking rates and over-authorization caused by long-term permission tables.

[0057] Step S104: Obtain the resource level to be accessed and the operation to be performed corresponding to the resource operation instruction, and determine whether the target user has the permission to perform the operation to be performed on the resource to be accessed based on the preset decision rules, the resource level to be accessed and the minimum permission table.

[0058] In this embodiment, after receiving a resource operation instruction, the traditional solution can only verify once according to the static whitelist, and cannot combine the "sensitivity of the resource to be accessed" with the "current minimum permission" in real time, resulting in excessively lenient access or false blocking.

[0059] In one embodiment, the step of obtaining the resource level to be accessed and the action to be performed corresponding to the resource operation instruction, and determining whether the target user has permission to perform the action to be performed on the resource to be accessed based on preset decision rules, the resource level to be accessed, and the minimum permission table, includes: The resource operation instruction is parsed to obtain the resource field and operation action field, which serve as the resource ID to be accessed and the operation action to be performed. Based on a preset level dictionary and the ID of the resource to be accessed, the resource level corresponding to the resource to be accessed is queried and used as the resource level to be accessed. If the resource level to be accessed exists in the minimum permission table, retrieve the set of allowed operation action fields corresponding to the resource level to be accessed from the minimum permission table. The action to be performed is matched with the set of allowed action fields to obtain a matching result. Based on the weight corresponding to the level of the resource to be accessed and the quantification coefficient of the abnormal risk level, the decision risk value is calculated. Based on the matching result and the decision risk value, an permission result is obtained to determine whether the target user has the permission to perform the operation to be performed on the resource to be accessed.

[0060] Specifically, based on resource operation commands: {user_id, session_id, resource_id, action_type}, and the minimum permission table Redis key min_perm:<user_id> :<session_id> The JSON object and level dictionary Redis key level_dict:<resource_id> The output importance labels (public / internal / confidential / top secret) and the preset decision rule matrix 4×4 table (resource level × abnormal risk level → risk value threshold) are used to make decisions on single resource operation instructions.

[0061] Specifically, the following steps are included: a) Instruction parsing Extract resource_id and action_type from resource operation instructions using regular expressions.

[0062] b) Level query The resource level to be accessed can be obtained by looking up the resource_id in the level dictionary.

[0063] c) Permission matching Look up resource_id in the minimum privilege table: If the action_type does not exist or is not in allowed_actions, then the match failed.

[0064] If it exists and action_type is allowed, then the match is successful.

[0065] d) Decision risk calculation Risk value = Resource level weight × k in: Resource level weights = {public = 1, internal = 0.8, confidential = 0.5, top secret = 0.2}, where k is the tightening coefficient from step 4.4-1.

[0066] e) Rule mapping Based on the risk value and matching results, look up the preset matrix: If a match is successful and the risk value is less than or equal to the threshold, then the action of the resource operation command is allowed. If a match is successful and the risk value is greater than the threshold, a secondary identity verification (MFA) is performed on the target user, and a decision is made based on the verification result. If a match fails, the resource operation command will be blocked.

[0067] f) Output of Results Generate permission confirmation results {allow / mfa / block, action_id, latency_ms} and write them back to the log center synchronously.

[0068] This embodiment discloses a resource protection method, apparatus, computer device, and storage medium based on user behavior analysis. Upon receiving a resource operation command from a target user, the method acquires the target user's historical behavior feature vector and access resource level sequence. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitive data within the preset time window. Based on preset weight coefficients, the historical behavior feature vector, and the access resource level sequence, the target user's behavior anomaly level is calculated. An initial permission table for the target user is acquired, and the initial permission table is dynamically adjusted based on the behavior anomaly level to generate a minimum permission table for the target user in the current session. The method acquires the resource level to be accessed and the action to be performed corresponding to the resource operation command, and based on preset decision rules, the resource level to be accessed, and the minimum permission table, determines whether the target user has permission to perform the action to be performed on the resource to be accessed. By employing the methods described above, this application quantifies abnormal user behavior and the importance of the resources to be accessed through historical behavior feature vectors representing the target user's historical behavior and access resource level sequences representing the importance of the resources accessed by the target user. Furthermore, it quantifies the dynamic risk of the target user using these two-dimensional features to obtain an abnormal behavior level. This allows for dynamic adjustment of permissions in the initial permission table, reducing the target user's permissions within the current session to the minimum permission level. This granularity of permissions is adjusted based on the user's historical behavior and the importance of the data to be accessed, avoiding decision-making delays. Based on preset decision rules, the access resource levels, and the minimum permission table, permission verification is refined from the entry level to the single action corresponding to each resource operation instruction. This prevents both over-authorization and false blocking, thereby improving both the efficiency and accuracy of business resource protection.

[0069] In one embodiment, before obtaining the target user's historical behavior feature vector and access resource level sequence upon receiving a resource operation instruction sent by the target user, the method further includes: Obtain raw security multi-source logs collected from the entire domain, wherein the raw security multi-source logs carry dual tags consisting of source layer tags and resource importance tags; Based on the user ID and session ID, the behavioral events in the original security multi-source logs carrying the dual tags are grouped, and a session behavior list including user, session and time window is generated according to the grouped logs. Extract the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user, as the historical behavior feature vector and the access resource level sequence.

[0070] To address the shortcomings of traditional logs, such as fragmented data and inconsistent fields, which hinder the rapid generation of computable behavioral features and resource sensitivity distributions for each user / session and result in a lack of high-quality input for subsequent anomaly detection and dynamic permission decisions, this embodiment achieves format and time-based consistency through comprehensive data collection and dual labeling, log streaming grouping, behavioral feature extraction, and resource importance level distribution, ensuring complete feature alignment.

[0071] Specifically, full-domain data collection and dual labeling include: The network layer IDS, host layer bastion host / EDR, and application layer WAF / Gateway simultaneously capture raw events; each event is tagged with a source layer label (network / host / application) and a resource importance label (public / internal / confidential / top secret) during the collection phase, generating raw, secure, multi-source logs with dual labels.

[0072] Log streaming packetization specifically includes: Use Kafka-Connect to aggregate sessions by preset time windows (such as Spark Streaming's 5-minute sliding window) and by grouping by user_id + session_id, generating a list of session behaviors. The list fields include: user_id, session_id, start_time, end_time, and raw_events (i.e., commands, logins, downloads, API calls, etc.).

[0073] Behavioral feature extraction specifically includes: Command sequence features: Perform TF-IDF + 2 / 3-gram on the command field in raw_events to output a 5000-dimensional command sequence feature vector.

[0074] Statistical features: Count login times, failure times, number of bytes downloaded, number of times sensitive data was accessed, and proportion of abnormal commands by window, and output a 16-dimensional statistical feature vector.

[0075] Concatenation and normalization: The above two vectors are normalized by Z-Score to form the historical behavior feature vector.

[0076] Resource sensitivity distribution specifically includes: Based on the resource importance tag in the dual tagging, the number of occurrences of the four levels (public / internal / confidential / top secret) of all accessed resources within the session is counted to generate a 4-dimensional access resource level sequence.

[0077] Through the above methods, this embodiment achieves complementary distribution of behavioral characteristics and resource importance levels, thereby improving the accuracy of anomaly level calculation and reducing the false alarm rate.

[0078] In one embodiment, extracting the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user as the historical behavior feature vector and the access resource level sequence includes: The target command list corresponding to the target user is determined from the session-level behavior list, and the command sequence feature vector in the target command list is extracted through the feature engineering module. The statistical feature calculator aggregates the statistical dimension feature vectors in the target command list according to the time window. The statistical dimensions include the number of logins, the number of failures, the number of bytes downloaded, the number of times sensitive data is accessed, and / or the proportion of abnormal commands. The historical behavior feature vector is obtained by concatenating the command sequence feature vector and the statistical dimension feature vector.

[0079] In this embodiment, the command text and statistical dimensions in the session-level behavior list are isolated and cannot form a unified and computable user behavior profile, resulting in insufficient anomaly detection accuracy.

[0080] Historical behavior feature vectors are obtained by extracting feature vectors from the target command list, command sequence feature vectors, statistical dimension feature vectors, and concatenating vectors.

[0081] The target command list extraction is used to filter the session behavior list by user_id + session_id + time window and extract the cmd_list field (a list of all shell command strings entered by the target user in this window).

[0082] The command sequence feature vector is used to generate 2-gram / 3-gram based on cmd_list using CountVectorizer, and then the weights are calculated using TF-IDF to output a 5000-dimensional dense vector.

[0083] The statistical dimension feature vector is used to aggregate login counts, failure counts, download bytes, access to sensitive data counts, and abnormal command ratios based on the original events of the same session window using Pandas UDF, generating a 5-dimensional statistical vector and performing Z-Score normalization.

[0084] Vector concatenation is used to concatenate a 5000-dimensional command sequence vector and a 5-dimensional statistical vector column by column, and then perform L2 normalization on the whole to output a 5005-dimensional historical behavior feature vector.

[0085] Through the above methods, this embodiment achieves complementarity between behavioral semantics and statistical anomalies, thereby improving the accuracy of anomaly detection.

[0086] In one embodiment, extracting the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user as the historical behavior feature vector and the access resource level sequence includes: The statistical feature calculator is used to count the number of times all resources accessed by the target user in the session-level behavior list are ranked according to importance level, and the access resource level sequence is generated based on the statistical distribution of the number of times each importance level is counted.

[0087] In this embodiment, in order to perform risk weighting by multiplying with the abnormal behavior score, it is necessary to quantify the "how much sensitive data the user has touched" in the session window into a computable vector.

[0088] Specifically, the session-level behavior list (user_id, session_id, start_time, end_time, raw_events), where each event already has a resource_id and resource_importance_tag (public / internal / confidential / top secret), is processed as follows: a) Unfolding events b) Use Spark UDF to split raw_events into individual records, retaining resource_id and tag.

[0089] c) b) Mapping level weights d) Public = 1, Internal = 0.8, Confidential = 0.5, Top Secret = 0.2.

[0090] e) c) Window aggregation Count the occurrences of level 4 by user_id + session_id + time window groupBy to obtain a four-dimensional counting vector [cnt_public, cnt_internal, cnt_confidential, cnt_topsecret].

[0091] d) Normalization Perform L2 normalization on the four-dimensional count to generate a sequence of access resource levels.

[0092] By using the above method, the data importance exposure surface is transformed into a 4-dimensional numerical vector, which can be directly concatenated with behavioral features; risk weighting is performed from two dimensions to improve accuracy and reduce false positive rate.

[0093] In one embodiment, the step of acquiring the raw security multi-source logs collected across the entire domain, wherein before the raw security multi-source logs carry a dual tag consisting of a source layer tag and a resource importance tag, further includes: By capturing and processing network packets at the network layer, network events can be obtained. Through the host layer, the host session stream is captured to obtain host command events, and the system state snapshot is periodically collected to obtain integrity events; Based on the application layer, application requests are collected, application access events are generated, and the call sequence corresponding to the application requests is collected to output API call events. Add source layer tags to the network events, host command events, integrity events, application access events, and API call events respectively. The source layer tags include network layer tags, host layer tags, and application layer tags. The data classification engine maps the access resources of each event to the corresponding importance level, and adds resource importance tags to each event based on the importance level of the access resources of each event. The resource importance tags include public tags, internal tags, confidential tags and top secret tags. The original security multi-source log is generated based on the network events, host command events, integrity events, application access events, and API call events carrying the dual tags.

[0094] In this embodiment, in order to address the problem that isolated log sources and inconsistent fields make it difficult to directly use them for cross-layer correlation and sensitivity weighting, resulting in a lack of structured, labeled, high-quality input for subsequent anomaly detection.

[0095] Through the network layer, perform IDS deep packet inspection on the raw Ethernet frames of the switch's mirror port, parse the 5-tuple, payload, and attack characteristics, and output network events.

[0096] Through the host layer, the bastion host agent captures and records the commands of the SSH / RDP session character stream and the real-time system status. EDR / OSQuery periodically snapshots processes, files, and the registry and calculates hash differences to obtain host command events and integrity events.

[0097] At the application layer, HTTP / HTTPS requests and call sequences are decrypted using WAF / Gateway rule matching. The API Gateway plugin records REST / GraphQL calls, obtaining application access events and API call events.

[0098] Based on the five types of events mentioned above, a unified Logstash pipeline is used to write a source layer tag (network / host / application) for each event. This also includes the resource fields (file_path, table_name, API_URI) within the event.

[0099] The DLP classification engine maps four levels of sensitivity (public / internal / confidential / top secret) in real time, and adds resource importance tags.

[0100] For all events carrying dual tags, the original secure multi-source log stream (including source layer tags + resource importance tags) is obtained by merging the logs according to the unified JSON format of Kafka-Connect, time zone, deduplication and log merging.

[0101] This achieves a unified log format and timestamp across layers, allowing the unified logs and timestamps to be directly used for subsequent session-level feature extraction. Furthermore, by leveraging the source and sensitivity dual labels inherent in each log entry, the training accuracy of the anomaly detection model is improved.

[0102] Specifically, network traffic is collected through L2-L7 firewalls and IDS (such as Suricata and Snort) deployed at the network layer to detect network layer attacks such as lateral movement, C&C communication, abnormal port scanning, and DDoS attacks; host logs are collected through bastion hosts and host agents (OSQuery / Auditd) deployed at the host layer to audit who executed which commands on the host, process startup / termination, file changes, privilege escalation, and other events. Application access records are collected through application-layer deployed WAF, application firewall, reverse proxy, and API Gateway to identify high-frequency or unauthorized access, SQL injection, API abuse, and other events targeting business systems. By deploying bastion hosts, bastion host command auditing modules, screen recording, and keyboard and mouse hooks at the host layer, user operation behaviors are collected to characterize user session-level behavior baselines (login time, command sequence, file operation mode). System state snapshots are collected by host agents, EDR, and file integrity monitors deployed at the host layer to capture system integrity (processes, services, file hashes, registry, kernel modules) to detect tampering or persistence.

[0103] Specifically, the system employs a network layer firewall for first-layer filtering based on 5-tuples / application protocols, outputting "allow / deny" logs. Deep packet inspection is performed via IDS, outputting network layer alerts (attack type, payload fragments). Attacks are blocked online via IPS / WAF, generating application layer alerts. A bastion host provides unified authentication and command-level auditing, outputting structured logs in "user-command-result-timestamp" format. Host agents continuously collect OS-level events and state snapshots.

[0104] Please see Figure 2 , Figure 2 This application provides a schematic block diagram of a resource protection device based on user behavior analysis, which is used to perform the aforementioned resource protection based on user behavior analysis. The resource protection device based on user behavior analysis can be configured on a server.

[0105] like Figure 2 As shown, the resource protection device 200 based on user behavior analysis includes:

[0106] The dual-dimensional feature acquisition module 210 is used to acquire the historical behavior feature vector and access resource level sequence of the target user when receiving a resource operation instruction sent by the target user; The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. The anomaly level calculation module 220 is used to calculate the anomaly level of the target user's behavior based on the preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. The permission dynamic control module 230 is used to obtain the initial permission table of the target user, and dynamically control the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session. The resource permission determination module 240 is used to obtain the level of the resource to be accessed and the action to be performed corresponding to the resource operation instruction, and determine whether the target user has the permission to perform the action to be performed on the resource to be accessed based on the preset decision rules, the level of the resource to be accessed and the minimum permission table. Furthermore, the resource prevention device 200 also includes a two-dimensional feature extraction module, used for: Obtain raw security multi-source logs collected from the entire domain, wherein the raw security multi-source logs carry dual tags consisting of source layer tags and resource importance tags; Based on the user ID and session ID, the behavioral events in the original security multi-source logs carrying the dual tags are grouped, and a session behavior list including user, session and time window is generated according to the grouped logs. Extract the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user, as the historical behavior feature vector and the access resource level sequence.

[0107] Furthermore, the two-dimensional feature extraction module is also used for: The target command list corresponding to the target user is determined from the session-level behavior list, and the command sequence feature vector in the target command list is extracted through the feature engineering module. The statistical feature calculator aggregates the statistical dimension feature vectors in the target command list according to the time window. The statistical dimensions include the number of logins, the number of failures, the number of bytes downloaded, the number of times sensitive data is accessed, and / or the proportion of abnormal commands. The historical behavior feature vector is obtained by concatenating the command sequence feature vector and the statistical dimension feature vector.

[0108] Furthermore, the two-dimensional feature extraction module is also used for: The statistical feature calculator is used to count the number of times all resources accessed by the target user in the session-level behavior list are ranked according to importance level, and the access resource level sequence is generated based on the statistical distribution of the number of times each importance level is counted.

[0109] Furthermore, the resource prevention device 200 also includes a log global collection module, used for: By capturing and processing network packets at the network layer, network events can be obtained. Through the host layer, the host session stream is captured to obtain host command events, and the system state snapshot is periodically collected to obtain integrity events; Based on the application layer, application requests are collected, application access events are generated, and the call sequence corresponding to the application requests is collected to output API call events. Add source layer tags to the network events, host command events, integrity events, application access events, and API call events respectively. The source layer tags include network layer tags, host layer tags, and application layer tags. The data classification engine maps the access resources of each event to the corresponding importance level, and adds resource importance tags to each event based on the importance level of the access resources of each event. The resource importance tags include public tags, internal tags, confidential tags and top secret tags. The original security multi-source log is generated based on the network events, host command events, integrity events, application access events, and API call events carrying the dual tags.

[0110] Furthermore, the resource permission determination module includes: An operation instruction parsing unit is used to parse the resource operation instruction to obtain a resource field and an operation action field, which serve as the resource ID to be accessed and the operation action to be performed. The resource level query unit is used to query the resource level corresponding to the resource to be accessed based on a preset level dictionary and the ID of the resource to be accessed, and use it as the resource level to be accessed. An operation action authorization unit is used to obtain the set of allowed operation action fields corresponding to the resource level to be accessed from the minimum permission table when the resource level to be accessed exists in the minimum permission table. The decision risk calculation unit is used to match the action to be operated with the set of allowed action fields to obtain the matching result, and calculate the decision risk value based on the weight corresponding to the level of the resource to be accessed and the quantification coefficient of the abnormal risk level. The permission result determination unit is used to obtain a permission result based on the matching result and the decision risk value to determine whether the target user has the permission to perform the operation to be performed on the resource to be accessed.

[0111] Furthermore, the dynamic permission control module includes: The first weight mapping unit is used to quantify the abnormal risk level and obtain the first coefficient of the quantified abnormal risk level based on the first weight mapping rule. The second weight mapping unit is used to obtain the resource level corresponding to each resource record in the initial permission table, and to obtain the second coefficient corresponding to the resource importance level based on the data classification engine and the second weight mapping rule. The target weight calculation unit is used to calculate the target weight corresponding to each resource record based on the first coefficient and the second coefficient. The permission action pruning unit is used to obtain the permission action corresponding to each resource record, and based on the comparison result of the target weight of each resource record and the preset threshold, to prune the initial permissions corresponding to each resource record to obtain the minimum permission table.

[0112] It should be noted that those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the above-described apparatus and modules can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0113] The aforementioned device can be implemented as a computer program, which can be used in, for example... Figure 3 It runs on the computer device shown.

[0114] Please see Figure 3 , Figure 3 This is a schematic block diagram illustrating the structure of a computer device according to an embodiment of this application. The computer device may be a server.

[0115] See Figure 3 The computer device includes a processor, memory, and network interface connected via a system bus, wherein the memory may include non-volatile storage media and internal memory.

[0116] Non-volatile storage media can store operating systems and computer programs. These computer programs include program instructions that, when executed, cause the processor to perform any type of resource protection based on user behavior analysis.

[0117] The processor provides computing and control capabilities, supporting the operation of the entire computer device.

[0118] Internal memory provides an environment for the execution of computer programs on non-volatile storage media. When these computer programs are executed by the processor, the processor can perform any kind of resource protection based on user behavior analysis.

[0119] This network interface is used for network communication, such as sending assigned tasks. Those skilled in the art will understand that... Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0120] It should be understood that the processor can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among these, a general-purpose processor can be a microprocessor or any conventional processor.

[0121] In one embodiment, the processor is configured to run a computer program stored in memory to perform the following steps: Upon receiving a resource operation instruction from a target user, the system acquires the target user's historical behavior feature vector and access resource level sequence. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. The abnormal behavior level of the target user is calculated based on the preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. Obtain the initial permission table of the target user, and dynamically adjust the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session; The system obtains the resource level and operation action corresponding to the resource operation instruction, and determines whether the target user has permission to perform the operation action on the resource to be accessed based on preset decision rules, the resource level to be accessed, and the minimum permission table.

[0122] In one embodiment, the processor is configured to run a computer program stored in memory for implementing: Obtain raw security multi-source logs collected from the entire domain, wherein the raw security multi-source logs carry dual tags consisting of source layer tags and resource importance tags; Based on the user ID and session ID, the behavioral events in the original security multi-source logs carrying the dual tags are grouped, and a session behavior list including user, session and time window is generated according to the grouped logs. Extract the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user, as the historical behavior feature vector and the access resource level sequence.

[0123] In one embodiment, the processor is configured to run a computer program stored in memory for implementing: The target command list corresponding to the target user is determined from the session-level behavior list, and the command sequence feature vector in the target command list is extracted through the feature engineering module. The statistical feature calculator aggregates the statistical dimension feature vectors in the target command list according to the time window. The statistical dimensions include the number of logins, the number of failures, the number of bytes downloaded, the number of times sensitive data is accessed, and / or the proportion of abnormal commands. The historical behavior feature vector is obtained by concatenating the command sequence feature vector and the statistical dimension feature vector.

[0124] In one embodiment, the processor is configured to run a computer program stored in memory for implementing: The statistical feature calculator is used to count the number of times all resources accessed by the target user in the session-level behavior list are ranked according to importance level, and the access resource level sequence is generated based on the statistical distribution of the number of times each importance level is counted.

[0125] In one embodiment, the processor is configured to run a computer program stored in memory for implementing: By capturing and processing network packets at the network layer, network events can be obtained. Through the host layer, the host session stream is captured to obtain host command events, and the system state snapshot is periodically collected to obtain integrity events; Based on the application layer, application requests are collected, application access events are generated, and the call sequence corresponding to the application requests is collected to output API call events. Add source layer tags to the network events, host command events, integrity events, application access events, and API call events respectively. The source layer tags include network layer tags, host layer tags, and application layer tags. The data classification engine maps the access resources of each event to the corresponding importance level, and adds resource importance tags to each event based on the importance level of the access resources of each event. The resource importance tags include public tags, internal tags, confidential tags and top secret tags. The original security multi-source log is generated based on the network events, host command events, integrity events, application access events, and API call events carrying the dual tags.

[0126] In one embodiment, the processor is configured to run a computer program stored in memory for implementing: The resource operation instruction is parsed to obtain the resource field and operation action field, which serve as the resource ID to be accessed and the operation action to be performed. Based on a preset level dictionary and the ID of the resource to be accessed, the resource level corresponding to the resource to be accessed is queried and used as the resource level to be accessed. If the resource level to be accessed exists in the minimum permission table, retrieve the set of allowed operation action fields corresponding to the resource level to be accessed from the minimum permission table. The action to be performed is matched with the set of allowed action fields to obtain a matching result. Based on the weight corresponding to the level of the resource to be accessed and the quantification coefficient of the abnormal risk level, the decision risk value is calculated. Based on the matching result and the decision risk value, an permission result is obtained to determine whether the target user has the permission to perform the operation to be performed on the resource to be accessed.

[0127] In one embodiment, the processor is configured to run a computer program stored in memory for implementing: The abnormal risk level is quantified, and a first coefficient of the quantified abnormal risk level is obtained based on the first weight mapping rule. Obtain the resource level corresponding to each resource record in the initial permission table, and obtain the second coefficient corresponding to the resource importance level based on the data classification engine and the second weight mapping rule; Based on the first coefficient and the second coefficient, the target weight corresponding to each resource record is calculated; Obtain the permission actions corresponding to each resource record, and based on the comparison results of the target weight of each resource record and the preset threshold, perform permission pruning on the initial permissions corresponding to each resource record to obtain the minimum permission table.

[0128] The embodiments of this application also provide a computer-readable storage medium storing a computer program, the computer program including program instructions, and the processor executing the program instructions to implement any of the user behavior analysis-based resource protection provided in the embodiments of this application.

[0129] The computer-readable storage medium may be an internal storage unit of the computer device described in the foregoing embodiments, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the computer device.

[0130] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A resource protection method based on user behavior analysis, characterized in that, The resource protection method includes: Upon receiving a resource operation instruction from a target user, the system acquires the target user's historical behavior feature vector and access resource level sequence. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. The abnormal behavior level of the target user is calculated based on the preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. Obtain the initial permission table of the target user, and dynamically adjust the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session; The system obtains the resource level and operation action corresponding to the resource operation instruction, and determines whether the target user has permission to perform the operation action on the resource to be accessed based on preset decision rules, the resource level to be accessed, and the minimum permission table.

2. The resource protection method according to claim 1, characterized in that, Before obtaining the target user's historical behavior feature vector and access resource level sequence upon receiving a resource operation instruction from the target user, the process further includes: Obtain raw security multi-source logs collected from the entire domain, wherein the raw security multi-source logs carry dual tags consisting of source layer tags and resource importance tags; Based on the user ID and session ID, the behavioral events in the original security multi-source logs carrying the dual tags are grouped, and a session behavior list including user, session and time window is generated according to the grouped logs. Extract the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user, as the historical behavior feature vector and the access resource level sequence.

3. The business resource protection method according to claim 2, characterized in that, The step of extracting the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user, as the historical behavioral feature vector and the access resource level sequence, includes: The target command list corresponding to the target user is determined from the session-level behavior list, and the command sequence feature vector in the target command list is extracted through the feature engineering module. The statistical feature calculator aggregates the statistical dimension feature vectors in the target command list according to the time window. The statistical dimensions include the number of logins, the number of failures, the number of bytes downloaded, the number of times sensitive data is accessed, and / or the proportion of abnormal commands. The historical behavior feature vector is obtained by concatenating the command sequence feature vector and the statistical dimension feature vector.

4. The business resource protection method according to claim 2, characterized in that, The step of extracting the behavioral features of the target user from the session behavior list and the distribution features of the importance level of all resources accessed by the target user, as the historical behavioral feature vector and the access resource level sequence, includes: The statistical feature calculator is used to count the number of times all resources accessed by the target user in the session-level behavior list are ranked according to importance level, and the access resource level sequence is generated based on the statistical distribution of the number of times each importance level is counted.

5. The business resource protection method according to claim 2, characterized in that, The process of acquiring raw security multi-source logs collected across the entire domain, wherein the raw security multi-source logs, before carrying a dual tag consisting of a source layer tag and a resource importance tag, further include: By capturing and processing network packets at the network layer, network events can be obtained. Through the host layer, the host session stream is captured to obtain host command events, and the system state snapshot is periodically collected to obtain integrity events; Based on the application layer, application requests are collected, application access events are generated, and the call sequence corresponding to the application requests is collected to output API call events. Add source layer tags to the network events, host command events, integrity events, application access events, and API call events respectively. The source layer tags include network layer tags, host layer tags, and application layer tags. The data classification engine maps the access resources of each event to the corresponding importance level, and adds resource importance tags to each event based on the importance level of the access resources of each event. The resource importance tags include public tags, internal tags, confidential tags and top secret tags. The original security multi-source log is generated based on the network events, host command events, integrity events, application access events, and API call events carrying the dual tags.

6. The resource protection method according to claim 1, characterized in that, The step of obtaining the resource level and operation to be performed corresponding to the resource operation instruction, and determining whether the target user has permission to perform the operation to be performed on the resource to be accessed based on preset decision rules, the resource level to be accessed, and the minimum permission table, includes: The resource operation instruction is parsed to obtain the resource field and operation action field, which serve as the resource ID to be accessed and the operation action to be performed. Based on a preset level dictionary and the ID of the resource to be accessed, the resource level corresponding to the resource to be accessed is queried and used as the resource level to be accessed. If the resource level to be accessed exists in the minimum permission table, retrieve the set of allowed operation action fields corresponding to the resource level to be accessed from the minimum permission table. The action to be performed is matched with the set of allowed action fields to obtain a matching result. Based on the weight corresponding to the level of the resource to be accessed and the quantification coefficient of the abnormal risk level, the decision risk value is calculated. Based on the matching result and the decision risk value, an permission result is obtained to determine whether the target user has the permission to perform the operation to be performed on the resource to be accessed.

7. The resource protection method according to any one of claims 1-6, characterized in that, The step of dynamically adjusting the initial permission table based on the abnormal risk level to generate the minimum permission table for the target user in the current session includes: The abnormal risk level is quantified, and a first coefficient of the quantified abnormal risk level is obtained based on the first weight mapping rule. Obtain the resource level corresponding to each resource record in the initial permission table, and obtain the second coefficient corresponding to the resource importance level based on the data classification engine and the second weight mapping rule; Based on the first coefficient and the second coefficient, the target weight corresponding to each resource record is calculated; Obtain the permission actions corresponding to each resource record, and based on the comparison results of the target weight of each resource record and the preset threshold, perform permission pruning on the initial permissions corresponding to each resource record to obtain the minimum permission table.

8. A resource protection device based on user behavior analysis, characterized in that, include: The dual-dimensional feature acquisition module is used to acquire the historical behavior feature vector and access resource level sequence of the target user when receiving a resource operation instruction sent by the target user. The historical behavior feature vector represents the target user's historical operation behavior within a preset time window, and the access resource level sequence represents the target user's access to various sensitivity data within the preset time window. An anomaly level calculation module is used to calculate the anomaly level of the target user's behavior based on a preset weight coefficient, the historical behavior feature vector, and the access resource level sequence. The permission dynamic control module is used to obtain the initial permission table of the target user, and dynamically control the initial permission table based on the abnormal behavior level to generate the minimum permission table of the target user in the current session. The resource permission determination module is used to obtain the level of the resource to be accessed and the action to be performed corresponding to the resource operation instruction, and determine whether the target user has the permission to perform the action to be performed on the resource to be accessed based on the preset decision rules, the level of the resource to be accessed and the minimum permission table.

9. A computer device, characterized in that, The computer device includes a memory and a processor; The memory is used to store computer programs; The processor is configured to execute the computer program and, in executing the computer program, implement the resource protection method based on user behavior analysis as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, causes the processor to implement the resource protection method based on user behavior analysis as described in any one of claims 1 to 7.