This application relates to a method, apparatus, electronic device, and storage medium for detecting abnormal
server behavior, applied in the field of
network security technology. The method includes: real-time acquisition of
system call sequences during
server process execution; dividing the
system call sequence into N runtime phase subsequences, and further dividing the runtime phase subsequences corresponding to the target process's runtime phases into process activity subsequences; segmenting the
system call sequence into multiple unidentified subsequences; inputting each unidentified subsequence into a process semantic abstraction model to obtain the
named entity recognition result corresponding to each
system call in the unidentified subsequence; aggregating and overwriting the
named entity recognition results of multiple unidentified subsequences to obtain the
named entity recognition result corresponding to each
system call in the
system call sequence; if unidentified named entities are included, determining that the system call sequence is abnormal, and sending an
alarm message. This application can extract
process behavior, facilitating
expert analysis of abnormal events.