Detection of Abnormal Behavior of Network Users
K. S. Geethu, Anchare V. Babu · Journal of Science and Engineering Research · 2022
Users' access to information has increased quickly along with the quick development of technologies like big data and the Internet of Things.However, while enjoying huge technological dividends, all sectors of society are also faced with problems brought about by information security.Anomaly detection and analysis of user access log data are one of the research hotspots in academic circles.However, the traditional anomaly detection methods for large-scale distributed data have some shortcomings.First, the collected web log data sets are time-effective, but little attention is paid to them in traditional anomaly detection algorithms.Secondly, training existing historical normal users to access data requires a lot of costs, and the anomaly detection efficiency is low.Thirdly, in the era of big data, network traffic is characterized by large data volume, high dimensions of characteristic attributes, and a large correlation between attributes.Using traditional anomaly detection methods, there will be problems of low detection efficiency and long detection time.Therefore, how to quickly and efficiently detect the anomaly of large-scale network user behavior data collected by big data platforms has become a huge challenge.Aiming at the above problems, this paper analyzes the advantages and disadvantages of various anomaly detection methods and puts forward two anomaly detection methods based on data mining, which realize high-efficiency anomaly detection.Aiming at the characteristics of a large amount of network traffic data and high data dimension, this paper proposes an improved GRU anomaly detection method.Firstly, principal component analysis is used to reduce the dimension of large-scale network traffic data sets and extract effective attributes.Then, the processed training data set is used to train the GRU-SVDD classifier model.Finally, the actual traffic to be detected is input into the GRU-SVDD comparator, and the anomaly in the traffic is detected.Aiming at the data set of network user behavior collected on the big data platform, a multi-layer protection model from the application layer and network layer is constructed.It can effectively protect the security of the big data platform, and the corresponding algorithm is designed and implemented in this project system.