首页 | 本学科首页   官方微博 | 高级检索  
     检索      

用户异常行为分析方法研究与应用
引用本文:赖建华,唐 敏.用户异常行为分析方法研究与应用[J].教育技术导刊,2019,18(8):181-185.
作者姓名:赖建华  唐 敏
作者单位:1. 福建省科学技术信息研究所;2. 福建省信息网络重点实验室;3. 福建省海峡信息技术有限公司,福建 福州 350003
基金项目:福建省科技计划项目(2017R1008-1,2018R1008-9)
摘    要:为了应对高级持续性威胁(APT)攻击造成的威胁,解决传统基于规则的分析方法对用户异常行为检测的误报与漏报问题,提高用户异常行为检测效果,通过采集用户行为日志生成用户操作行为矩阵,并通过模型定义方式对用户行为进行相似度分析。采用容忍度测算、突变测算、差值测算与峰值测算方法,分析与发现用户异常访问。基于用户画像的异常行为分析方法结合了用户操作行为特征及角色定义,利用用户行为日志历史信息勾勒出用户行为画像,使系统能准确、实时地判断用户行为异常,提高了对异常行为的实时检测与快速响应能力。

关 键 词:异常行为分析  高级持续性威胁攻击  行为矩阵  用户画像  
收稿时间:2018-10-11

Research and Application of User Abnormal Behavior Analysis Method
LAI JIAN-hua,TANG Min.Research and Application of User Abnormal Behavior Analysis Method[J].Introduction of Educational Technology,2019,18(8):181-185.
Authors:LAI JIAN-hua  TANG Min
Institution:1. Fujian Institute of Science and Technology Information;2. Fujian Key Laboratory of Information Network;3. Fujian Straits Information Co. Ltd,Fuzhou 350003, China
Abstract:In order to deal with the threat caused by high-level persistent threat attack, the traditional rule-based analysis method is used to solve the false alarm and missed alarm of user abnormal behavior detection, and improve the detection effect of user abnormal behavior. User behavior matrix is generated by collecting user behavior log, and similarity analysis of user behavior is done by model definition. Tolerance measure method, mutation measure method, difference measure method and peak value measure method are collected. Users' abnormal access is analyzed and found by common use. The abnormal behavior analysis method based on user portrait is combined with user operation behavior characteristics and role definition, and the user behavior portrait is outlined by using user behavior log history information. The system can judge user behavior abnormality in real-time and improve the ability of real-time detection and rapid response to abnormal behavior.
Keywords:abnormal behavior analysis  high-level persistent threat attack  behavior matrix  user portrait  
点击此处可从《教育技术导刊》浏览原始摘要信息
点击此处可从《教育技术导刊》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号