![基于用户访问序列的异常行为检测方法](/CN/2017/1/22/images/201710110615.jpg)
基本信息:
- 专利标题: 基于用户访问序列的异常行为检测方法
- 专利标题(英):Detection method for abnormal behaviors based on user access sequence
- 申请号:CN201710110615.3 申请日:2017-02-28
- 公开(公告)号:CN106657410A 公开(公告)日:2017-05-10
- 发明人: 廖鹏 , 夏元轶 , 郭靓 , 于晓文 , 金倩倩 , 蒋甜 , 张骞 , 李炜键 , 赵俊峰
- 申请人: 国家电网公司 , 南京南瑞集团公司 , 南京南瑞信息通信科技有限公司 , 国网江苏省电力公司信息通信分公司
- 申请人地址: 北京市西城区西长安街86号; ; ;
- 专利权人: 国家电网公司,南京南瑞集团公司,南京南瑞信息通信科技有限公司,国网江苏省电力公司信息通信分公司
- 当前专利权人: 国家电网公司,南瑞集团有限公司南京南瑞信息通信科技有限公司国网江苏省电力公司信息通信分公司
- 当前专利权人地址: 北京市西城区西长安街86号; ; ;
- 代理机构: 南京纵横知识产权代理有限公司
- 代理人: 董建林; 王丹
- 主分类号: H04L29/08
- IPC分类号: H04L29/08 ; H04L12/26
The invention discloses a detection method for abnormal behaviors based on a user access sequence. The detection method comprises the following steps: 1) capturing data from a local network, preprocessing the data, and performing serializing treatment on the acquired data; 2) storing a sequence formed in the step 1 into a sequence database, and generating a behavior sequence of each user on the basis of time; and 3) calculating the behavior similarity and the correlation coefficient between users according to the behavior sequence of each user, comparing the correlation coefficient for detecting the abnormal behaviors, and searching for the abnormal behaviors of the user. According to the method, on the basis of sequence pattern excavation, factors, such as, time and user behavior characteristics, are fully considered, an improved more accurate user behavior similarity algorithm is utilized to calculate, and the sequence rule of the user access is effectively extracted, so that an analysis result is more accurate and the defects of other analysis methods are overcome. Besides, on the basis of the user behavior similarity algorithm, the method has obvious advantages in noise interference, the used resources are few, and the running efficiency is high.
公开/授权文献:
- CN106657410B 基于用户访问序列的异常行为检测方法 公开/授权日:2018-04-03
IPC结构图谱:
H | 电学 |
--H04 | 电通信技术 |
----H04L | 数字信息的传输,例如电报通信 |
------H04L27/00 | 调制载波系统 |
--------H04L27/02 | .调幅载波系统,例如应用通/断键控的;单边带或残留边带调制 |
----------H04L29/06 | ..以协议为特征的 |
------------H04L29/08 | ...传输控制规程,例如数据链级控制规程 |