Patent
Method, apparatus and system for detecting abnormal user behavior
Zhao Linong,Lu Yanjun,Chen Lang,Yang Xiang,Deng Mimi,Huang Guoqiang,Liao Tianyu +6 more
- 13 Nov 2018
8
TL;DR: In this article, a clustering centroid of the user behavior feature values related to each type of user behaviors according to the clustering characteristics of user behaviour feature values is used to detect abnormal user behavior.
read more
Abstract: The invention provides a method, apparatus and system for detecting an abnormal user behavior. The method for detecting the abnormal user behavior comprises the following steps: obtaining user behavior information; extracting user behavior feature values related to user behaviors from the user behavior information; calculating a clustering centroid of the user behavior feature values related to each type of user behaviors according to the clustering characteristics of the user behavior feature values; determining a standard baseline of a normal user behavior by using the clustering centroid as the center; calculating the distance between the user behavior feature values of the user behavior information and the clustering centroid; and comparing the calculated distances with the standard baseline to judge whether the user behavior information belongs to abnormal behavior information. According to the method provided by the invention, by collecting the user behavior information, extracting the feature values from the user behavior information, and performing clustering analysis on the extracted feature values in combination with the normal behavior standard baseline to judge the abnormal situation of the user behaviors, thereby simplifying the judgment process of the abnormal user behavior and realizing fast and accurate detection of the abnormal user behavior.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Patent
Abnormal user detection method and system based on ensemble learning
TL;DR: In this article, an abnormal user detection method and system based on ensemble learning is proposed, which relates to the technical field of network security, and the method comprises the steps: collecting to-be-detected behavior information of a user, wherein the behavior information comprises at least one piece of behavior feature information; comparing the behavior characteristic information with a preset characteristic baseline corresponding to the behaviour characteristic information to obtain a comparison result; extracting abnormal behavior information from the behaviour information to be detected according to a comparison results; and finally, scoring the suspected abnormal users by utilizing a preset ensemble learning
1
Patent
Abnormal behavior analysis method and device based on operator situation awareness portrait
Wang Xingliang,Jiang Miao,Wang Jiayue +2 more
- 16 Jul 2019
TL;DR: In this paper, an abnormal behavior analysis method and device based on an operator situation awareness portrait is presented, and the method comprises the steps: dividing operator data into a group data set and a personal data set, adding a behavior mark to the operator data in the group data sets and the personal data sets, wherein the behavior mark at least comprises an abnormal behaviour mark, and generating a situation aware portrait of the operator according to the abnormal behaviour analysis model.
1
Patent
Operation and maintenance violation operation identification method and device and storage medium
Fang Jiansheng
- 23 Jul 2019
TL;DR: In this paper, an operation and maintenance violation operation identification method and device and a storage medium are described, and the method comprises steps of clustering the plurality of collected sessions according to the session feature vector information of the sessions to obtain a plurality of clusters, identifying the session in the cluster with the session number smaller than the number threshold value of the cluster as the abnormal session.
1
Patent
Method, device, and computer storage medium for detecting abnormal account
Hou Mingyuan
- 28 Jan 2021
TL;DR: In this article, the authors present a method, device, and computer storage medium for detecting an abnormal account, used for the technical field of computers, which comprises: obtaining N sets of access data for N accounts to access a target URL within a preset time, each of the N groups of accessdata being M-dimensional data, N and M both being positive integers; using a Gaussian kernel function to map the data of the access data in each dimension to the interval [0,1]; determining to be an abnormally accessed account an account corresponding to abnormally distributed access data
Patent
Abnormal telecommunication service scene determination method and device, and computer equipment
Luo Bing,Zhao Congbiao,Pan Xiaolei +2 more
- 27 Nov 2020
TL;DR: In this paper, the authors proposed an abnormal telecommunication service scene determination method and device, computer equipment and a storage medium, which comprises: acquiring initial telecommunicationservice index data; selecting telecommunication services index data matched with the telecommunication scene from the initial telecommunicationservice index data, and performing clustering calculation on the matchedtelecommunication service index data and determining clustered telecommunication Service index data contained in each group corresponding to the target grouping number.
References
Patent
Methods and systems for automatically generating semantic/concept searches
Venkat Rangan
- 16 Feb 2011
TL;DR: In various embodiments, a semantic space associated with a corpus of electronically stored information (ESI) may be created and used for concept searches as discussed by the authors, where documents and any other objects in the ESI, in general, may be represented as vectors in the semantic space.
45
Patent
Method and apparatus for confirming user behavior
Zhiguang Qin,Xuan Liu,Juan Wang,Xinggao He,Fengli Zhang,Chong Fu,Dunquan Wang +6 more
- 28 Jan 2009
TL;DR: In this article, a method for determining user behaviors, comprising the following steps that a user behavior database is established according to the network flow data and the security event journal data, and various users in the user behaviour database are clustered and the network behavioral pattern of the various users is determined according to clustering result.
41
Patent
Method and system for identifying abnormal microblog users
Wang Peng,Zhang Peng,Liu Tienan,Sun Liang +3 more
- 12 Jun 2013
TL;DR: Wang et al. as mentioned in this paper proposed a method for identifying abnormal microblog users by taking statistical distribution of time intervals of user behaviors as behavior time characteristics of the users according to the microblog data.
27
Patent
Intrusion detection method based on integral correlation analysis and hierarchical clustering
Jiang Zhang,Jianhuai Qi +1 more
- 04 May 2011
TL;DR: Wang et al. as discussed by the authors proposed an intrusion detection method based on integral correlation analysis and hierarchical clustering, belonging to the technical field of information security, where the maximal correlation coefficient between each feature data vector and the other feature data vectors in a user behavior data vector set on a computer network is less than a correlation coefficient threshold.
12
Patent
Method, system and client terminal for detecting working efficiency of user
Chen Zhide,Wu Jiyun,Huang Xinyi,Wu Wei +3 more
- 15 Jul 2015
TL;DR: In this paper, a method, a system and a client terminal for detecting the working efficiency of a user is presented, which includes the steps that behavior data of the user in the working process within multiple unit intervals are collected and recorded; behavior characteristics of the behavior data in the work process within the multiple unit interval are extracted, and a behavior characteristic vector is built; normative processing is carried out on the behavior characteristic vectors of the work within the unit interval, and authentication results are recorded; the work efficiency is calculated according to the authentication results, and feature extraction, analysis and authentication
10
Related Papers (5)
Zhang Jiachao
- 17 Aug 2016
Yan Shaohua,Yang Yahui,Sun Yaping,Yang Jun,Li Zhenbo +4 more
- 05 Jun 2018
He Xian,Yin Weidong,Meng Xiaonan +2 more
- 24 Dec 2014