CN111538614B - 一种操作系统的时序异常操作行为检测方法 - Google Patents
一种操作系统的时序异常操作行为检测方法 Download PDFInfo
- Publication number
- CN111538614B CN111538614B CN202010353357.3A CN202010353357A CN111538614B CN 111538614 B CN111538614 B CN 111538614B CN 202010353357 A CN202010353357 A CN 202010353357A CN 111538614 B CN111538614 B CN 111538614B
- Authority
- CN
- China
- Prior art keywords
- data
- encoder
- abnormal
- layer
- matrix
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 230000002159 abnormal effect Effects 0.000 title claims abstract description 26
- 238000001514 detection method Methods 0.000 title description 4
- 230000006399 behavior Effects 0.000 claims abstract description 29
- 238000013528 artificial neural network Methods 0.000 claims abstract description 14
- 238000000034 method Methods 0.000 claims abstract description 14
- 206010000117 Abnormal behaviour Diseases 0.000 claims abstract description 9
- 239000011159 matrix material Substances 0.000 claims description 23
- 238000012549 training Methods 0.000 claims description 6
- 230000006870 function Effects 0.000 claims description 4
- ORILYTVJVMAKLC-UHFFFAOYSA-N Adamantane Natural products C1C(C2)CC3CC1CC2C3 ORILYTVJVMAKLC-UHFFFAOYSA-N 0.000 claims description 3
- 235000004257 Cordia myxa Nutrition 0.000 claims description 3
- 244000157795 Cordia myxa Species 0.000 claims description 3
- 230000004913 activation Effects 0.000 claims description 3
- 230000007246 mechanism Effects 0.000 claims description 3
- 238000011176 pooling Methods 0.000 claims description 3
- 238000012545 processing Methods 0.000 claims description 3
- 238000005457 optimization Methods 0.000 claims description 2
- 230000006835 compression Effects 0.000 abstract description 2
- 238000007906 compression Methods 0.000 abstract description 2
- 238000012423 maintenance Methods 0.000 abstract description 2
- 230000007547 defect Effects 0.000 description 2
- 238000000605 extraction Methods 0.000 description 2
- 238000013179 statistical model Methods 0.000 description 2
- 238000006467 substitution reaction Methods 0.000 description 2
- 230000004075 alteration Effects 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000002372 labelling Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000008569 process Effects 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/0706—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/0766—Error or fault reporting or storing
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/04—Architecture, e.g. interconnection topology
- G06N3/045—Combinations of networks
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/08—Learning methods
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Computational Linguistics (AREA)
- Data Mining & Analysis (AREA)
- Evolutionary Computation (AREA)
- Biomedical Technology (AREA)
- Molecular Biology (AREA)
- Biophysics (AREA)
- Artificial Intelligence (AREA)
- Life Sciences & Earth Sciences (AREA)
- Mathematical Physics (AREA)
- Software Systems (AREA)
- Health & Medical Sciences (AREA)
- Quality & Reliability (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Error Detection And Correction (AREA)
Abstract
Description
Claims (1)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202010353357.3A CN111538614B (zh) | 2020-04-29 | 2020-04-29 | 一种操作系统的时序异常操作行为检测方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202010353357.3A CN111538614B (zh) | 2020-04-29 | 2020-04-29 | 一种操作系统的时序异常操作行为检测方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN111538614A CN111538614A (zh) | 2020-08-14 |
CN111538614B true CN111538614B (zh) | 2024-04-05 |
Family
ID=71978934
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202010353357.3A Active CN111538614B (zh) | 2020-04-29 | 2020-04-29 | 一种操作系统的时序异常操作行为检测方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN111538614B (zh) |
Families Citing this family (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN112445957A (zh) * | 2020-11-05 | 2021-03-05 | 西安电子科技大学 | 社交网络异常用户检测方法、系统、介质、设备、终端 |
CN113934616B (zh) * | 2021-12-16 | 2022-03-18 | 深圳市活力天汇科技股份有限公司 | 一种基于用户操作时序判断异常用户的方法 |
Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109188502A (zh) * | 2018-07-05 | 2019-01-11 | 中国科学技术大学 | 一种基于自编码器的束流位置监测器异常检测方法及装置 |
CN109241946A (zh) * | 2018-10-11 | 2019-01-18 | 平安科技(深圳)有限公司 | 异常行为监控方法、装置、计算机设备及存储介质 |
CN109492767A (zh) * | 2018-11-09 | 2019-03-19 | 济南浪潮高新科技投资发展有限公司 | 一种应用于无监督领域基于自编码器的异常检测方法 |
CN110177108A (zh) * | 2019-06-02 | 2019-08-27 | 四川虹微技术有限公司 | 一种异常行为检测方法、装置及验证系统 |
CN110263807A (zh) * | 2019-05-13 | 2019-09-20 | 杭州安恒信息技术股份有限公司 | 基于auto-encoder的异常行为检测方法 |
CN110502895A (zh) * | 2019-08-27 | 2019-11-26 | 中国工商银行股份有限公司 | 接口异常调用确定方法及装置 |
CN110533752A (zh) * | 2019-07-23 | 2019-12-03 | 深圳大学 | 一种人体动作编辑模型的生成方法、存储介质及电子设备 |
CN111050170A (zh) * | 2019-12-06 | 2020-04-21 | 山东浪潮人工智能研究院有限公司 | 基于gan的图片压缩系统构建方法、压缩系统及方法 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US11204602B2 (en) * | 2018-06-25 | 2021-12-21 | Nec Corporation | Early anomaly prediction on multi-variate time series data |
-
2020
- 2020-04-29 CN CN202010353357.3A patent/CN111538614B/zh active Active
Patent Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109188502A (zh) * | 2018-07-05 | 2019-01-11 | 中国科学技术大学 | 一种基于自编码器的束流位置监测器异常检测方法及装置 |
CN109241946A (zh) * | 2018-10-11 | 2019-01-18 | 平安科技(深圳)有限公司 | 异常行为监控方法、装置、计算机设备及存储介质 |
CN109492767A (zh) * | 2018-11-09 | 2019-03-19 | 济南浪潮高新科技投资发展有限公司 | 一种应用于无监督领域基于自编码器的异常检测方法 |
CN110263807A (zh) * | 2019-05-13 | 2019-09-20 | 杭州安恒信息技术股份有限公司 | 基于auto-encoder的异常行为检测方法 |
CN110177108A (zh) * | 2019-06-02 | 2019-08-27 | 四川虹微技术有限公司 | 一种异常行为检测方法、装置及验证系统 |
CN110533752A (zh) * | 2019-07-23 | 2019-12-03 | 深圳大学 | 一种人体动作编辑模型的生成方法、存储介质及电子设备 |
CN110502895A (zh) * | 2019-08-27 | 2019-11-26 | 中国工商银行股份有限公司 | 接口异常调用确定方法及装置 |
CN111050170A (zh) * | 2019-12-06 | 2020-04-21 | 山东浪潮人工智能研究院有限公司 | 基于gan的图片压缩系统构建方法、压缩系统及方法 |
Non-Patent Citations (2)
Title |
---|
prediction based deep autoencoding model for anomaly detection;zhanzhong pang etl al.;《Asion conference on computer vision ACCV 2018》;第1-10页 * |
基于长短时记忆―自编码神经网络的风电机组性能评估及异常检测;柳青秀;马红占;褚学宁;马斌彬;王峥;;计算机集成制造系统(第12期);第233-243页 * |
Also Published As
Publication number | Publication date |
---|---|
CN111538614A (zh) | 2020-08-14 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
EP3910571A1 (en) | Methods and systems for server failure prediction using server logs | |
CN111652290B (zh) | 一种对抗样本的检测方法及装置 | |
CN111600919B (zh) | 智能网络应用防护系统模型的构建方法和装置 | |
CN111538614B (zh) | 一种操作系统的时序异常操作行为检测方法 | |
Chang et al. | Anomaly detection for industrial control systems using k-means and convolutional autoencoder | |
US10785243B1 (en) | Identifying evidence of attacks by analyzing log text | |
CN112306982B (zh) | 异常用户检测方法、装置、计算设备及存储介质 | |
Gao | Network intrusion detection method combining CNN and BiLSTM in cloud computing environment | |
CN112738014A (zh) | 一种基于卷积时序网络的工控流量异常检测方法及系统 | |
CN110113368B (zh) | 一种基于子轨迹模式的网络行为异常检测方法 | |
Zhang et al. | {HDDse}: Enabling {High-Dimensional} Disk State Embedding for Generic Failure Detection System of Heterogeneous Disks in Large Data Centers | |
CN112951311A (zh) | 一种基于变权重随机森林的硬盘故障预测方法及系统 | |
CN114528547A (zh) | 基于社区特征选择的icps无监督在线攻击检测方法和设备 | |
Tomer et al. | Hard disk drive failure prediction using SMART attribute | |
You et al. | sBiLSAN: Stacked bidirectional self-attention lstm network for anomaly detection and diagnosis from system logs | |
Liang et al. | Disk Failure Prediction Based on SW-Disk Feature Engineering | |
CN115344563A (zh) | 数据去重方法及装置、存储介质、电子设备 | |
KR102472850B1 (ko) | 하이브리드 인공지능 기반의 악성코드 탐지 장치 및 방법 | |
CN111797732B (zh) | 一种对采样不敏感的视频动作识别对抗攻击方法 | |
Ganesh et al. | Autoencoder Based Network Anomaly Detection | |
CN114330500A (zh) | 基于storm平台的电网电力设备在线并行诊断方法及系统 | |
Inoue et al. | Early Stuck Detection Using Supervised and Unsupervised Machine Learning Approaches | |
CN113935023A (zh) | 一种数据库异常行为检测方法及装置 | |
Xu et al. | STEAMCODER: Spatial and Temporal Adaptive Dynamic Convolution Autoencoder for Anomaly Detection | |
Wu et al. | Tree-based model with advanced data preprocessing for large scale hard disk failure prediction |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20240306 Address after: 250100 building S02, No. 1036, Langchao Road, high tech Zone, Jinan City, Shandong Province Applicant after: Shandong Inspur Scientific Research Institute Co.,Ltd. Country or region after: Zhong Guo Address before: 250100 First Floor of R&D Building 2877 Kehang Road, Sun Village Town, Jinan High-tech Zone, Shandong Province Applicant before: JINAN INSPUR HIGH-TECH TECHNOLOGY DEVELOPMENT Co.,Ltd. Country or region before: Zhong Guo |
|
TA01 | Transfer of patent application right | ||
GR01 | Patent grant | ||
GR01 | Patent grant |