Alarm linkage method, device and system, computer equipment and storage medium
A technology of linkage and alarm information, applied in the field of communication, can solve the problems of single security protection strategy, insufficient flexibility, lack of emergency response, etc., and achieve the effect of optimal attack response results
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0038] Such as figure 2 As shown, in one embodiment, an alarm linkage method is proposed, and this embodiment is mainly applied to the above-mentioned figure 1 The alarm linkage device 130 in the system is used as an example, which may specifically include the following steps:
[0039] Step S201, receiving the alarm information sent by the alarm source, and identifying the type of network attack;
[0040] Step S202, obtaining a set of candidate linkage strategies according to the network attack type;
[0041] Step S203, calculating the network risk value of each linkage strategy in the candidate linkage strategy set, and using the linkage strategy corresponding to the minimum network risk value as the target linkage strategy;
[0042] Step S204, execute the corresponding alarm linkage action according to the target linkage strategy.
[0043] In the embodiment of the present invention, the type of network attack refers to the threat to the network system, such as brute forc...
Embodiment 2
[0078] Such as Figure 5 As shown, in one embodiment, an alarm linkage device is provided, which can be integrated into the above-mentioned alarm linkage device 130, and specifically can include:
[0079] The attack type identification module 501 is used to receive the alarm information sent by the alarm source and identify the network attack type;
[0080] A linkage strategy query module 502, configured to obtain a set of candidate linkage strategies according to the type of network attack;
[0081] A linkage strategy decision module 503, configured to calculate the network risk value of each linkage strategy in the candidate linkage strategy set, and use the linkage strategy corresponding to the minimum network risk value as the target linkage strategy;
[0082] A linkage strategy execution module 504, configured to execute corresponding alarm linkage actions according to the target linkage strategy.
[0083] In the embodiment of the present invention, the type of network ...
Embodiment 3
[0111] Such as Figure 8 As shown, in one embodiment, an alarm linkage system 801 is provided. The alarm linkage system 801 provided in the embodiment of the present invention includes:
[0112] An alarm information collection device 802, configured to collect alarm information and send the alarm information to the alarm linkage device;
[0113] The alarm linkage device 803 is configured to receive the alarm information, and execute the alarm linkage method, so as to perform a corresponding alarm linkage action.
[0114] In the alarm linkage system in the embodiment of the present invention, when receiving an alarm, by querying all matching strategies, and then selecting the optimal strategy through evaluation and selection steps, the overall optimal effect can be achieved; at the same time, the defense Combining the evaluation of the strategy with the change of the attack effect after the strategy is implemented, the evaluation of the attack effect provides feedback informat...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


