Data processing method, device, equipment and medium
By receiving and processing threat event information in the critical information infrastructure system and using pre-generated event processing maps to determine security measures, the problems of low efficiency and low accuracy in the implementation of security measures in the existing technology are solved, and more efficient and accurate security measure determination is achieved.
Patent Information
- Application Number
- CN202211209749.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2042-09-30
AI Technical Summary
In the existing technology, due to excessive reliance on manual judgment, the implementation efficiency and accuracy of security measures in critical information infrastructure systems when security incidents occur are low.
By receiving information carrying target threat events, if the preset number of times is reached, the node corresponding to the target threat event is searched in the pre-generated event processing map, and the node related to the security measures connected to the node is obtained. The electronic device obtains and sends relevant information to determine the security measures.
It improves the accuracy of determining safety measures, avoids reliance on manual judgment, and improves implementation efficiency.
Smart Images

Figure CN115499240B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a data processing method, apparatus, device and medium. Background Art
[0002] Critical information infrastructure systems provide network information services to the public and support the operations of important industries such as energy, communications, finance, transportation, and public utilities. These systems are used to deliver essential goods and services or form the foundational platform for other critical infrastructure. Therefore, the security of these systems is paramount. Disruption or destruction of these systems can severely impact vital societal functions. Cybersecurity incidents in these systems can disrupt the normal operation of key industries and cause significant losses.
[0003] In the existing technology, maintenance of critical information infrastructure systems involves using detection equipment to detect security incidents. Based on this information and their own experience, personnel then determine corresponding security measures to facilitate maintenance of critical information infrastructure systems. However, these security measures, determined by personnel based on their own experience, are inaccurate and waste human resources. Summary of the Invention
[0004] The embodiments of the present application provide a data processing method, apparatus, device, and medium to address the problems in the prior art of low efficiency in implementing security measures due to over-reliance on manual judgment when a security incident occurs, and low accuracy in determining security measures based on manual experience.
[0005] In a first aspect, an embodiment of the present application provides a data processing method, the method comprising:
[0006] receiving information carrying target threat events;
[0007] If the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, searching for a node corresponding to the target threat event in a pre-generated event processing graph and obtaining a node related to a security measure connected to the node;
[0008] Obtain and send the information recorded in the node related to the security measure.
[0009] In a second aspect, an embodiment of the present application further provides a data processing device, the device comprising:
[0010] A receiving module, configured to receive information carrying target threat events;
[0011] a processing module configured to, if the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, search for a node corresponding to the target threat event in a pre-generated event processing graph, and obtain a node related to a security measure connected to the node;
[0012] The acquisition and sending module is used to acquire and send the information recorded in the nodes related to the security measures.
[0013] In a third aspect, an embodiment of the present application further provides an electronic device, which includes at least a processor and a memory, and the processor is configured to execute the steps of any of the above-mentioned data processing methods when executing a computer program stored in the memory.
[0014] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which performs the steps of any of the above-mentioned data processing methods when executed by a processor.
[0015] In an embodiment of the present application, an electronic device receives information carrying a target threat event. If the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, the electronic device searches for a node corresponding to the target threat event in a pre-generated event processing graph and obtains a node related to a security measure connected to the node. The electronic device obtains and sends information recorded in the node related to the security measure. In an embodiment of the present application, after determining that the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, the electronic device determines the node corresponding to the target threat event in the event processing graph and determines the node related to the security measure connected to the node. Thus, when the target threat event affects a critical information infrastructure system, that is, when a security event occurs, the corresponding security measure can be determined, thereby improving the accuracy of the security measure determination. The electronic device searches for the node corresponding to the target threat event according to the event processing graph and obtains information recorded in the node related to the security measure connected to the node. The node related to the security measure records specific security measures, thereby avoiding the problem of over-reliance on human judgment leading to low efficiency in the implementation of security measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0017] Figure 1 A schematic diagram of a data processing process provided in an embodiment of the present application;
[0018] Figure 2 A schematic diagram of the structure of the atlas template provided in the embodiment of the present application;
[0019] Figure 3 A schematic diagram of the structure of the event processing diagram provided in the embodiment of the present application;
[0020] Figure 4 A schematic diagram of some nodes included in the graph template provided in the embodiment of the present application;
[0021] Figure 5 A schematic diagram of a detailed process for obtaining security measures provided in an embodiment of the present application;
[0022] Figure 6 A schematic diagram of a data processing process provided in an embodiment of the present application;
[0023] Figure 7 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application;
[0024] Figure 8 A schematic diagram of the structure of another data processing device provided in an embodiment of the present application;
[0025] Figure 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0026] The present application will be further described in detail below with reference to the accompanying drawings. It is apparent that the embodiments described are only a portion of the embodiments of the present application, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present application without creative effort are intended to fall within the scope of protection of the present application.
[0027] In an embodiment of the present application, an electronic device receives information carrying a target threat event. If the target threat event is a preset event and the number of times the information carrying the target threat event is received reaches a preset number, the electronic device searches for a node corresponding to the target threat event in a pre-generated event processing graph and obtains a node related to a security measure connected to the node. The electronic device obtains and sends the information recorded in the node related to the security measure.
[0028] In order to improve the accuracy of determining security measures, embodiments of the present application provide a data processing method, apparatus, device, and medium.
[0029] Example 1:
[0030] Figure 1 A data processing process diagram provided in an embodiment of the present application includes the following steps:
[0031] S101: Receive information carrying a target threat event.
[0032] The data processing method provided in the embodiment of the present application is applied to an electronic device, which may be a PC, a server or other device.
[0033] In an embodiment of the present application, when the detection device detects that a security incident is currently occurring against a critical information infrastructure system, it will detect a target threat event that caused the security incident, wherein the target threat event may be an "EternalBlue vulnerability attack." The detection device will send information carrying the target threat event to the electronic device, and the electronic device can receive the information carrying the target threat event.
[0034] S102: If the target threat event is a preset event and the number of times the information carrying the target threat event is received reaches a preset number, then search for a node corresponding to the target threat event in a pre-generated event processing graph, and obtain a node related to the security measure connected to the node.
[0035] In order to accurately determine the security measures corresponding to the target threat event, in an embodiment of the present application, a pre-generated event processing graph is stored in the electronic device, and the electronic device can search for the node corresponding to the target threat event in the pre-generated event processing graph. After finding the node corresponding to the target threat event, the electronic device can obtain the security measure-related node connected to the node. The security measure-related node is a node of a security measure-related type.
[0036] Since certain threat events will not cause losses to critical information infrastructure systems in actual application scenarios, if a threat event will not cause losses to critical information infrastructure systems, there is no need to determine corresponding security measures when the threat event occurs. Therefore, in an embodiment of the present application, a baseline set by business personnel is pre-saved in the electronic device, and the baseline includes preset events that will cause losses to the critical information infrastructure system, and a corresponding preset number of times is saved for each preset event. After receiving information carrying the target threat event, the electronic device determines whether the target threat event is a preset event. If the target threat event is not a preset event, it means that the target threat event will not cause losses to the critical information infrastructure system, and there is no need to determine corresponding security measures.
[0037] If the target threat event carried in the information received by the electronic device is a preset event, the electronic device determines whether the number of times the information carrying the target threat event has been received has reached a preset number. Specifically, when the electronic device receives the information carrying the target threat event, it can update the number of times the information carrying the target threat event has been received based on the stored number of times the information carrying the target threat event has been received, and determine whether the updated number has reached the preset number, wherein the preset number is the number stored for the target threat event, and the preset number can be any non-zero number such as 2, 10, etc. In the embodiment of the present application, the preset number corresponding to different threat events may be different, so different correspondences between threat events and times can be stored in the electronic device.
[0038] If the number of times the information carrying the target threat event is received does not reach the preset number, it indicates that the target threat event has a minor impact on the critical information infrastructure system and no corresponding security measures need to be determined. If the number of times the information carrying the target threat event is received reaches the preset number, it indicates that the target threat event has a certain impact on the critical information infrastructure system. The electronic device then searches for the node corresponding to the target threat event in a pre-generated event processing graph. Specifically, the electronic device searches for the node that records the target threat event. After finding the node, the electronic device obtains the node related to the security measures connected to the node. The electronic device also resets the number of times the information carrying the target threat event is received to zero.
[0039] For example, the preset event includes "Eternal Blue Vulnerability Attack", and the preset number of times saved for the preset event is 10. If the information received by the electronic device carries "Eternal Blue Vulnerability Attack", and the number of times the electronic device receives the information carrying the "Eternal Blue Vulnerability Attack" reaches 10 times, the electronic device obtains the node that records the "Eternal Blue Vulnerability Attack" and obtains the node related to the security measures connected to the node.
[0040] In the embodiments of the present application, there may be one or more nodes related to security measures. For example, the nodes related to security measures may include nodes that record specific security technologies and nodes that record specific security devices. Security technologies refer to specific operating methods, such as "access control devices," and security devices refer to specific protection objects, such as "network boundaries." Both specific security technologies and security devices are security measures.
[0041] S103: Obtain and send the information recorded in the node related to the security measure.
[0042] In an embodiment of the present application, after obtaining a node related to a security measure, the electronic device can obtain the information recorded in the node related to the security measure, wherein the information recorded in the node related to the security measure is a specific security measure. The obtained information can be an "access control device" or a "target asset." The target asset exposes an object that is attacked by a target threat event, wherein the object attacked by the target threat event is a service port or a device in a critical information infrastructure system.
[0043] After obtaining the information recorded in the nodes related to security measures, the electronic device can transmit the obtained information, which can be sent to the device used by business personnel to facilitate business personnel to maintain the critical information infrastructure system based on the information. If the information transmitted is the specific security technology "access control device", the business personnel can use the "access control device" security technology to maintain the critical information infrastructure system. Specifically, how business personnel maintain the critical information infrastructure system based on the information sent by the electronic device is not restricted here.
[0044] In the embodiment of the present application, the electronic device determines the security event based on the event processing map, without relying on manual judgment. After the security measures are determined, the business can directly maintain the key information infrastructure system based on the security measures without having to judge whether the security measures are accurate. This can improve the efficiency of the implementation of security measures and effectively avoid the problem of low efficiency of security measures implementation caused by over-reliance on manual judgment in the existing technology.
[0045] Because in the embodiment of the present application, after the electronic device determines that the target threat event is a preset event and the number of times it receives the target threat event reaches the preset number, it determines the node corresponding to the target threat event in the event processing map and determines the node related to the security measures connected to the node. Therefore, when the target threat event affects the critical information infrastructure system, that is, when a security event occurs, the corresponding security measures can be determined to improve the accuracy of the security measures. The electronic device searches for the node corresponding to the target threat event according to the event processing map and obtains the information recorded in the node related to the security measures connected to the node. The node related to the security measures records specific security measures, thereby avoiding determining security measures based solely on manual experience, improving the accuracy of security measures, and avoiding the problem of low efficiency in implementing security measures due to over-reliance on manual judgment.
[0046] Example 2:
[0047] In order to generate an event processing graph, based on the above embodiment, in the embodiment of the present application, the event processing graph is generated by the following method:
[0048] Receive each text used to generate an event processing graph;
[0049] For each text, extract each keyword contained in the text. For each keyword, if the graph template does not contain a node recording the keyword, create a target node in the graph template, record the keyword in the target node, obtain the type saved corresponding to the keyword, save the correspondence between the target node and the type, and determine the target type of each other node connected to the node of the type in the graph template based on the connection relationship between the nodes in the graph template, determine other nodes of other keywords of the target type in the text, and connect the target node and the other nodes.
[0050] To accurately generate an event processing map, in an embodiment of the present application, the electronic device can receive each text used to generate the event processing map, wherein the text contains various keywords. Each text can be sent to the electronic device by a business person operating the device they use, and each text can be obtained by the business person from documents such as compliance standards, management systems, personnel records, asset lists, operating procedures, security event logs, sandbox analysis, vulnerability scanning, and configuration verification.
[0051] For each text received, the electronic device extracts each keyword contained in the text. The text received by the electronic device can be called unstructured data. When obtaining keywords from the text, the electronic device can use entity extraction technology to extract each keyword in the text. The specific electronic device can pre-store a keyword library, which stores multiple keywords. If there is a keyword in the text that is the same as any keyword in the keyword library, the electronic device extracts the keyword. In this way, the electronic device can obtain each keyword in the text. For example, the keywords extracted by the electronic device from "Unnecessary system services, default sharing, and high-risk ports should be closed" are "Unnecessary system services", "Default sharing", and "High-risk ports".
[0052] After obtaining each keyword contained in the text, the electronic device determines whether the graph template contains a node recording the keyword. If the graph template does not contain a node recording the keyword, the electronic device can create a target node in the graph template and record the keyword in the target node. If the graph template contains a node recording the keyword, the electronic device does not need to create a target node in the graph template. In this way, the electronic device can include a node recording each keyword in the text in the graph template. In an embodiment of the present application, the graph template can be called a security and compliance knowledge graph ontology.
[0053] After the electronic device has created a node corresponding to each keyword in the text, for each keyword, it determines the type saved in advance for the keyword. For example, the type saved for the keyword "Eternal Blue Vulnerability Attack" is "Threat Event". After obtaining the type corresponding to the keyword, the electronic device saves the correspondence between the target node and the type. The electronic device also obtains the target type of each other node connected to the node of this type in the graph template, and connects the target node of the keyword with other nodes of the target type. For example, the target type of each other node connected to the node of type "Threat Event" includes "Object". In an embodiment of the present application, the types of nodes included in the graph template include threat events, vulnerable events, objects, key information infrastructure systems, inspection items, compliance standards, standard regulations, organizational personnel, security incidents and security measures related types.
[0054] Among them, the node of threat event type records specific threat events, that is, specific attack methods, the node of vulnerable event type records specific vulnerable events, the node of object type records open ports or devices attacked by threat events, the node of inspection item type records specific inspection methods, the node of compliance standard type records standards that need to be followed to maintain critical information infrastructure systems, the node of standard regulations type records specific regulations under the compliance standards, the node of organizational personnel type records specific business personnel in charge, the node of security event type records specific security events to which the threat event belongs, and the node of security measure-related type records information related to security measures.
[0055] In the embodiment of the present application, a module with management and adjustment functions in the electronic device may be responsible for generating the event processing graph.
[0056] Specifically, since in an embodiment of the present application, there are multiple keywords corresponding to the same type, not all keywords recorded in other nodes of each target type have an associated relationship with the keyword. Therefore, when the electronic device connects the target node with other nodes of the target type, it can obtain the node of the target type and the recorded keyword is the keyword in the text, and connect the target node with the obtained node.
[0057] For example, a keyword is "EternalBlue vulnerability attack", and the type saved for the keyword is "threat event", and the target type of the node connected to this type in the graph template is "object". The graph template includes two nodes with a target type of "object", and they respectively record "SMB service port 445" and "SMB service port 442". The text only contains "SMB service port 445", then the electronic device connects the node recording the keyword with other nodes recording "SMB service port 445".
[0058] In an embodiment of the present application, for each keyword, after connecting and recording the target node of the keyword and other nodes, the electronic device can obtain the relationship between the node of the corresponding type of the keyword in the graph template and the node of the corresponding type of the other node, and record the obtained relationship between the target node and the other node.
[0059] For example, the electronic device extracts the keywords "network boundary", "access control device" and "access control function" from the text "Access control devices should be deployed at the network boundary and the access control function should be enabled", and based on the connection relationship between different types of nodes saved in the graph template, determines that the node of the type corresponding to "network boundary" is connected to the node of the type corresponding to "access control device". Therefore, the electronic device connects the node with the record of "network boundary" and the node with the record of "access control device", and the connection relationship between the node of the type corresponding to "network boundary" and the node of the type corresponding to "access control device" in the graph template is "deployment", so the connection relationship between the "network boundary" and the "access control device" can be recorded as "deployment".
[0060] Figure 2 Schematic diagram of the atlas template structure provided in the embodiment of this application.
[0061] in, Figure 2 For some map templates, Figure 2 The information recorded in the graph template is the type corresponding to each node. Figure 2 It can be seen that the types corresponding to the nodes include: "Critical Information Infrastructure System", "Compliance Standards", "Standard Regulations", "Inspection Items", "Organization Personnel", "Objects", "Security Measures", "Vulnerable Events", "Threat Events" and "Security Events", among which "Security Measures" is a security measures-related type.
[0062] Depend on Figure 2It can be seen that the node of type "security event" has a connection relationship with the node of type "threat event", and the security event contains the threat event; the node of type "threat event" has a connection relationship with the node of type "security measure" and the node of type "vulnerable event", and the relationship between the node of type "threat event" and the node of type "security measure" is mitigation, and the relationship between the node of type "threat event" and the node of type "vulnerable event" is exploitation; the node of type "vulnerable event" has a connection relationship with the node of type "object" and the node of type "security measure". The relationship between the node of type "Vulnerable Event" and the node of type "Safety Measures" is Mitigation, and the relationship between the node of type "Vulnerable Event" and the node of type "Object" is Existence; the node of type "Object" has a connection relationship with the node of type "Safety Measures", the node of type "Inspection Item" and the node of type "Critical Information Infrastructure System", and the relationship between the node of type "Safety Measures" and the node of type "Inspection Item" and the node of type "Object" is Protection, and the relationship between the node of type "Critical Information Infrastructure System" and the node of type "Object" is Possession. Yes; the node of type "Safety Measures" has a connection relationship with the node of type "Organization Personnel" and the node of type "Inspection Item", and the relationship between the node of type "Safety Measures" and the node of type "Organization Personnel" is execution, and the relationship between the node of type "Safety Measures" and the node of type "Inspection Item" is use; the node of type "Inspection Item" has a connection relationship with the node of type "Organization Personnel" and the node of type "Standard Regulations", and the relationship between the node of type "Inspection Item" and the node of type "Organization Personnel" is requirement and responsibility, and the node of type "Standard Regulations" The relationship between the node of type "Inspection Item" and the node of type "Organization Personnel" is to guide implementation; the node of type "Organization Personnel" has a connection relationship with the node of type "Key Information Basic System", and the relationship between the node of type "Key Information Basic System" and the node of type "Organization Personnel" is to own; the node of type "Key Information Basic System" has a connection relationship with the node of type "Compliance Standards", and the relationship between the node of type "Key Information Basic System" and the node of type "Compliance Standards" is to follow; the node of type "Compliance Standards" has a connection relationship with the node of type "Safety Regulations".
[0063] In an embodiment of the present application, keywords expressing the same content stored in different texts may be different. For example, in text A, "attack A" is used to represent "Eternal Blue vulnerability attack", and in text B, "attack B" is used to represent "Eternal Blue vulnerability attack". Therefore, in an embodiment of the present application, the electronic device pre-stores the relationship between different keywords and the standard keywords represented. After obtaining each keyword in the text, the electronic device needs to normalize each keyword obtained and standardize the keywords expressing the same content. Specifically, the electronic device mainly performs normalization processing through field mapping, that is, the electronic device determines the standard keyword pre-stored for each keyword, and performs the subsequent specific steps of generating an event processing map for the standard keyword. In an embodiment of the present application, the corresponding types of keywords are usually required to be normalized: attack source, attack target, attack technical means, vulnerable event, etc.
[0064] Figure 3 A schematic diagram of the structure of the event processing map provided in the embodiment of the present application.
[0065] in, Figure 3 Only part of the event processing graph is included in Figure 3 It can be seen that the event processing graph contains multiple nodes, each of which records "Level 4 Security Protection", "Network Security", "Access Control", "Access control devices should be deployed at the network boundary and the access control function should be enabled", "Access Control Device", "Network Boundary", "Access Control Function", "Intrusion Detection System", "Firewall", "Target Assets", "SMB Service (Port 445)", "CVE-2017-0144", "Eternal Blue Vulnerability Attack", "Attack Source A" and "A Unit Intrusion Event".
[0066] Depend on Figure 3It can be seen that the node with the record of "A unit intrusion event" has a connection relationship with the node with the record of "Eternal Blue vulnerability attack", the node with the record of "attack source A" and the node with the record of "target asset". Specifically, the relationship between "A unit intrusion event" and "target asset" is target, the relationship between "A unit intrusion event" and "Eternal Blue vulnerability attack" is attack means, and the relationship between "A unit intrusion event" and "attack source A" is attack source; the node with the record of "attack source A" has a connection relationship with the node with the record of "Eternal Blue vulnerability attack", and specifically the relationship between "attack source A" and "Eternal Blue vulnerability attack" is initiation; the node with the record of "Eternal Blue vulnerability attack" has a connection relationship with the node with the record of "CVE-2017-0144", and specifically the relationship between "Eternal Blue vulnerability attack" and "CVE-2017-0144" is targeting; the node with the record of "CVE-2017-0144" has a connection relationship with the node with the record of "SMB service (445 The nodes with "Target Assets" recorded, the node with "Access Control Function" recorded, and the node with "Network Boundary" recorded are connected. Specifically, the relationship between "Target Assets" and "SMB Service (445 Port)" is Development, the relationship between "Access Control Function" and "SMB Service (445 Port)" is Open, and the relationship between "Network Boundary" and "SMB Service (445 Port)" is Belong.
[0067] Depend on Figure 3It can be seen that the node with "target assets" recorded has a connection relationship with the node with "intrusion detection system" and the node with "firewall" recorded, and the specific relationship between "intrusion detection system" and "firewall" and "target assets" is protection; the node with "intrusion detection system" and the node with "firewall" recorded have a connection relationship with the node with "access control device" recorded, and the specific relationship between "intrusion detection system" and "firewall" and "access control device" is belonging; among them, the node with "access control function" recorded has a connection relationship with the node with "access control device" recorded, and the specific relationship between "access control device" and "access control function" is functional composition; the node with "access control device should be deployed at the network boundary and access control function should be enabled" recorded has a connection relationship with the node with "access control function". The nodes are connected to the nodes with "access control device" and the nodes with "network boundary" respectively. Specifically, the relationship between "access control device should be deployed at the network boundary and the access control function should be enabled" and "access control device" is a security measure, and the relationship between "access control device" and "network boundary" is a protection object; the nodes with "access control" are connected to the nodes with "access control device should be deployed at the network boundary and the access control function should be enabled". Specifically, the relationship between "access control" and "access control device should be deployed at the network boundary and the access control function should be enabled" is an inspection requirement; the nodes with "network security" are connected to the nodes with "access control"; the nodes with "Level 4 Security Protection" are connected to the nodes with "network security".
[0068] In an embodiment of the present application, the electronic device can realize the association between information related to security measures of specific threat events through the connection relationship between different types of nodes in the graph template. For example, the electronic device can connect the node recording the "target asset" with the node recording the "SMB service (port 445)", and can connect the node recording the "Eternal Blue vulnerability attack" with the node recording the "SMB service (port 445)". That is to say, there is a connection relationship between the node recording the "Eternal Blue vulnerability attack" and the node recording the "target asset", and the node recording the "target asset" is a node related to the security measures. Therefore, when obtaining the node related to the security measures connected to the node recording the "Eternal Blue vulnerability attack", the "target asset" connected to it can be obtained, and thus the specific security measures can be obtained.
[0069] In the embodiment of the present application, the keywords extracted from the text by the electronic device include: threat keywords, vulnerable keywords, and management keywords. Among them, threat keywords refer to specific threat events, vulnerable keywords refer to specific vulnerable events, and management keywords refer to certain keywords related to the management of critical information infrastructure systems. Management keywords include specific security measures. In the embodiment of the present application, management keywords are mainly recorded in texts such as compliance standards, management systems, and operating procedures. Threat keywords are mainly recorded in texts such as security event logs and sandbox analysis. Threat keywords are mainly recorded in texts such as vulnerability scans and configuration verification.
[0070] Table 1 is an explanation of some types corresponding to keywords in the embodiment of the present application.
[0071] type illustrate Compliance Standards Management documents for knowledge ownership Standard Regulations Security category Inspection items Safe implementation of operational requirements Object Security implementation objects, including devices, systems, services, and components Safety measures Management and technical means used for protection Organization personnel Executing and responsible units, organizations or personnel fragile events Vulnerabilities targeted by the attack, etc.
[0072] Table 1
[0073] Among them, the first column in Table 1 refers to the type corresponding to the keyword, and the second column in Table 1 is an explanation of the different types. It can be seen from Table 1 that the type of "compliance standards" refers to "management documents to which management knowledge belongs"; the type of "standard regulations" refers to "security implementation operation requirements"; the type of "inspection items" refers to "security implementation operation requirements"; the type of "objects" refers to "security implementation objects, including equipment, systems, services, and components"; the type of "security measures" refers to "management and technical means used for protection"; the type of "organizational personnel" refers to "executing and responsible units, institutions, or personnel in positions"; the type of "vulnerability events" refers to "vulnerabilities targeted by attacks, etc."
[0074] Depend on Figure 2 and Figure 3 It can be seen that the event processing map generated in the embodiment of the present application contains four levels, and the specific standard regulations in the four levels, and each inspection item information under the standard regulations, that is, it contains the top-level standard policy. In other words, the event processing map uses the top-level standard policy as a security governance guide. Among them, the business personnel in the pre-generated map template build the connection between the top-level standard and other nodes through the research and design of the compliance standard structure. Secondly, the other nodes include the connection relationship between the nodes at the monitoring level and the nodes at the management level. Therefore, the deficiencies at the management level can be reflected through threat events and guidance can be provided for adjustment.
[0075] Example 3:
[0076] In order to accurately determine security measures, based on the above embodiments, in an embodiment of the present application, searching for a node corresponding to the target threat event in a pre-generated event processing graph includes:
[0077] If the information also carries a target vulnerability event, then searching for a first node whose recorded keyword is the target threat event and a second node whose recorded keyword is the target vulnerability event in a pre-generated event processing map;
[0078] If the information does not carry the target vulnerability event, a node whose keyword recorded in a pre-generated event processing map is the target threat event is searched.
[0079] In actual application scenarios, the detection device may also detect a target vulnerable event, where the target vulnerable event can be a vulnerability exploited during a target threat event attack, such as "CVE-2017-0144". If the detection device detects a target vulnerable event, when the detection device sends information carrying the target threat event, the information also carries the detected target vulnerable event. If the information also carries the target vulnerable event, when determining security measures, the electronic device can search for the first node whose recorded keyword is the target threat event in the pre-generated event processing graph, and search for the second node whose recorded keyword is the target vulnerable event in the pre-generated event processing graph.
[0080] If the information received by the electronic device does not carry the target vulnerability event but only carries the target threat event, the electronic device can search for the node whose recorded keyword is the target threat event in the pre-generated event processing map when determining the security measures.
[0081] In an embodiment of the present application, in order to further determine security measures, if the received information carrying the target threat event does not include the target vulnerable event, the electronic device can also complete the target vulnerable event based on the connection relationship between the node of type "threat event" and the node of type "vulnerable event" in the event processing graph, that is, determine the node that records the target threat event, and determine the node of type vulnerable event connected to the node.
[0082] In an embodiment of the present application, a target vulnerability event is used to describe the hidden dangers and related business information of the attack target. In addition to the vulnerability exploited during the target threat event attack, the target vulnerability event also includes a specific target type, specific version information, specific network information, specific improper configuration, etc.
[0083] Table 2 is a detailed description of the target vulnerability events in the embodiment of the present application.
[0084] type illustrate Target Type Hosts, network equipment, applications, software systems, platforms, etc. Version Information Version number Network Information Network address, domain name Vulnerabilities Exploitable flaws with CVE, CNNVD, and other numbers Improper configuration Insufficient password strength, etc.
[0085] Table 2
[0086] The first column in Table 2 indicates the type of the target vulnerability event, and the second column in Table 2 is a description of the type. As shown in Table 2, the type of the target vulnerability event can be a target type, where the target type refers to a host, network device, application, software system, platform, etc., which means that the target vulnerability event can be a specific target type of the attack target. As shown in Table 2, the type of the target vulnerability event can be version information, where the version information refers to a specific version number, which means that the target vulnerability event can be the version information of the attack target. As shown in Table 2, the type of the target vulnerability event can be network information, where the network information refers to a specific network address, domain name, etc., which means that the target vulnerability event can be the network information of the attack target. As shown in Table 2, the type of the target vulnerability event can be a vulnerability, where a vulnerability refers to an exploitable defect with a number such as CVE or CNNVD, which means that the target vulnerability event can be a vulnerability exploited by the target threat event. As shown in Table 2, the type of the target vulnerability event can be improper configuration, where improper configuration includes insufficient password strength, etc., which means that the target vulnerability event can be a hidden danger of the attack target.
[0087] In order to accurately determine the security measures, based on the above embodiments, in an embodiment of the present application, if the information also carries a target vulnerability event, obtaining the node related to the security measures connected to the node includes:
[0088] A node of a security measure related type connected to the first node is acquired, and a node of a security measure related type connected to the second node is acquired.
[0089] In an embodiment of the present application, if the information received by the electronic device also carries a target vulnerability event, the electronic device can obtain a node of a security measure-related type connected to the first node and a node of a security measure-related type connected to the second node after finding a first node recording the target threat event and finding a second node recording the target vulnerability event.
[0090] In an embodiment of the present application, the node of type "object" in the event processing graph is connected to the node of type "vulnerable event", the node of type "threat event" is connected to the node of type "vulnerable event", and the node of type "security measure" is connected to the node of type "vulnerable event" and the node of type "threat event". Therefore, the electronic device can determine the node of the security measure-related type connected to the first node recording the target threat event, and determine the node of the security measure-related type connected to the second node recording the target vulnerable event, thereby determining the security measures according to the nodes of the security measure-related type connected to the first node and the second node respectively.
[0091] In an embodiment of the present application, the node of the security measure-related type connected to the first node and the node of the security measure-related type connected to the second node may be the same node. Therefore, in an embodiment of the present application, after the electronic device obtains each node of the security measure-related type this time, it determines whether there is a node with the same recorded keyword in each of the obtained nodes. If there is a node with the same recorded keyword, one of them is retained in each node with the same recorded keyword.
[0092] In order to accurately maintain critical information infrastructure systems, based on the above embodiments, in the embodiments of the present application, the security measure-related types include: assets, objects, security resources, security technologies, security equipment and security measures.
[0093] In the embodiment of the present application, the acquired security measure-related types are assets, objects, security resources, security technologies, security equipment and security measures.
[0094] Taking the target threat event received as "EternalBlue vulnerability attack" as an example, the electronic device Figure 3 Each node connected in the event processing graph shown is obtained by Figure 3 It can be seen that the node recording "SMB service (445 port)" can be obtained, the type of this node is "object", and the electronic device obtains the node recording "target asset" connected to the node recording "SMB service (445 port)", the corresponding type of this node is "asset", the electronic device can send "target asset" and "SMB service (445 port)" to enable business personnel to protect the target asset, and specific business personnel can close the SMB service (445 port) of the target asset.
[0095] In a possible implementation, the electronic device can obtain the node that records the "target threat event", the node of the type "asset", and determine whether the node of the type "asset" is connected to a node of the type "security resource". If so, the electronic device sends the information recorded in the node of the type "security resource". Figure 3 For example, electronic equipment can obtain the "detection system" and "firewall", which makes it easier for business personnel to adjust the "detection system" and "firewall" to protect the "SMB service (445 port)".
[0096] Specifically, in embodiments of the present application, when determining security measures, electronic devices typically utilize the connection relationship between nodes recording "target vulnerability events" and nodes of type "object" to determine security measures. In one possible implementation, business personnel can maintain critical information infrastructure systems by severing the logical association between information recorded in nodes of type "object" and information recorded in nodes of type "attack techniques."
[0097] In an embodiment of the present application, when an electronic device obtains a node of a security measure type connected to a node that records a target threat event, it can first determine a node of type "object" connected to the node that records the target threat event. After obtaining the node of type "object", the electronic device can determine nodes of a relationship such as "protection", "patch", "upgrade", etc. connected to the node, and determine that these nodes are nodes of the security measure type. After obtaining the information sent by the electronic device, the business personnel can retain the information recorded in the "object" type node by providing external protection measures; they can also remove the information recorded in the "object" type node from the logical association.
[0098] by Figure 3 For example, in the "EternalBlue Vulnerability Attack" target threat event, the "SMB Service (Port 445)" is recorded in the node with the connection type "Object." The electronic device acquires nodes connected to this node with the relationships "Protection," "Patch," and "Upgrade," including "Access Control Device." Therefore, business personnel can use the "Access Control Device" as a security measure or disable the SMB Service (Port 445) to remove the object entity from the logical association. Business personnel can choose the appropriate handling method based on their business requirements.
[0099] In an embodiment of the present application, the key to obtaining information recorded in nodes of a type related to security measures lies in nodes of type "object". In an embodiment of the present application, when determining nodes related to security measures, from the attacker's perspective, the object is a carrier of vulnerable events, so the node of type "object" is connected to the node of type "vulnerable event", and the object is the target of the threat event, so the node of type "object" is connected to the node of type "threat event". In addition, from the protector's perspective, the object is the protection object of the inspection item and the implementation target of the security measures, so the node of type "object" is respectively connected to the node of type "inspection item" and the node of type "security measures". Therefore, the electronic device can determine the security measures through the connection relationship between the node of type object and other nodes.
[0100] Example 4:
[0101] In order to ensure the security of the critical information infrastructure system, based on the above embodiments, in the embodiment of the present application, the method further includes:
[0102] If the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than the preset number, searching for a node corresponding to the target threat event in a pre-generated event processing graph and obtaining a node of the check item type connected to the node;
[0103] The inspection item information recorded in the node of the inspection item type is obtained. If the number of times the inspection item information is obtained exceeds a target number, the inspection item information is sent and the number of times the inspection item information is obtained is cleared.
[0104] In an embodiment of the present application, if the target threat event carried in the information received by the electronic device is a preset event, and the number of times the target threat event is received is less than the preset number, the electronic device can search for a node whose recorded keyword is the target threat event in a pre-generated event processing graph, and after finding the node whose recorded keyword is the target threat event, obtain a node of type inspection item connected to the node.
[0105] Take the target threat event as "Eternal Blue Vulnerability Attack", which is a preset event, and the number of times the information carrying the target threat event is received does not reach the preset number as an example. Figure 3 It can be seen that when searching for inspection item information, the electronic device can determine that the node recording "Eternal Blue Vulnerability Attack" is connected to the node recording "CVE-2017-0144", and the node recording "CVE-2017-0144" is connected to the node recording "SMB Service (Port 445)", and the node recording "Access Control Device" and the node recording "Network Boundary" are respectively connected to the node recording "SMB Service (Port 445)", and the node recording the inspection item "Access control devices should be deployed at the network boundary, and the access control function should be enabled" is connected to the node recording "Access Control Device" and the node recording "Network Boundary". Therefore, the electronic device determines that the node of the inspection item type records "Access control devices should be deployed at the network boundary, and the access control function should be enabled". Therefore, after receiving information carrying "Eternal Blue Vulnerability Attack", it can obtain the node of the inspection item type connected to the node recording the target threat event, which records "Access control devices should be deployed at the network boundary, and the access control function should be enabled".
[0106] In an embodiment of the present application, after the electronic device obtains a node of the type of inspection item connected to the node, it obtains the inspection item information recorded in the node of the type of inspection item, wherein the inspection item information may be "access control devices should be deployed at the network boundary and the access control function should be enabled". After obtaining the inspection item information, the electronic device determines the number of times the inspection item information is obtained. If the number of times the inspection item information is obtained exceeds the target number, it means that the inspection item information has not been implemented in place, and the inspection item information is sent, wherein the target number can be any number such as 10 or 15. Specifically, the inspection item information can be sent to the device used by the business personnel so that the business personnel can check the inspection item, thereby realizing the maintenance of the key information infrastructure system. In an embodiment of the present application, if the electronic device sends the inspection item information, the electronic device clears the inspection item information obtained.
[0107] Among them, in an embodiment of the present application, when the electronic device determines whether to send inspection item information, it can save the corresponding score for each inspection item information locally. After obtaining a certain inspection item information, it obtains the score corresponding to the inspection item information, and subtracts a preset value from the score to obtain the target score after subtracting the preset score, and uses the target score to update the score corresponding to the inspection item information saved locally. After obtaining the target score, the electronic device can determine whether the target score is lower than the threshold score. If the target score is lower than the threshold score, the electronic device sends the inspection item information.
[0108] Figure 4 A schematic diagram of some nodes included in the graph template provided in the embodiment of this application.
[0109] Depend on Figure 4 It can be seen that the graph template includes nodes that record "four levels", and the four levels include ten requirements, namely "network security", "host security", "application security", ... and "data security and backup recovery". Among them, "network security" includes seven specific requirements, namely "access control", ... and "security audit". The inspection item information corresponding to "access control" is "access control devices should be deployed at the network boundary and access control functions should be enabled", ... and "data with general protocols should not be allowed to pass". The inspection item information corresponding to "security review" is "network equipment operation status, network traffic, user behavior, etc. in the network system should be logged", ... and "should be able to analyze based on the recorded data and generate audit reports."
[0110] In the embodiment of the present application, taking the inspection item information as "access control devices should be deployed at the network boundary and access control functions should be enabled" as an example, the preset score corresponding to the inspection item information is determined in the following way: Figure 4It can be seen that the inspection item information "Access control devices should be deployed at the network boundary and the access control function should be enabled" is one of the five inspection items under "Access Control", "Access Control" is one of the seven requirements under "Network Security", and "Network Security" is one of the ten requirements under "Level 4 Security Protection". Therefore, when determining the preset score corresponding to the inspection item information, each corresponding value is 5, 7, and 10 respectively. The electronic device can determine the product of each value and determine the ratio of the preset total score to the product, which is the preset score corresponding to the inspection item information. If the total score is 100, the preset score corresponding to the inspection item information is 100 / (5*7*10)≈0.29.
[0111] Depend on Figure 4 It can be seen that the atlas template contains nodes that record compliance standards in a tree-like hierarchical structure. In an embodiment of the present application, when determining the preset score corresponding to each inspection item information, the electronic device can save a corresponding weight value for each inspection item information and each requirement. The weight value can be any numerical value. The electronic device can determine the preset score corresponding to each inspection item information and each requirement to which the inspection item information belongs based on the weight value. Specifically, for each inspection item information, the electronic device can use the above method to determine the preset score corresponding to the inspection item information, and determine the product of the preset score and the weight value corresponding to each requirement to which the inspection item information belongs, and use the product to update the preset score corresponding to the inspection item information. And when the score is lower than the threshold score, send the inspection item information. It is convenient for business personnel to maintain the key information infrastructure system based on the inspection item information. When sending the inspection item information, the electronic device adjusts the score saved for the inspection item information to the preset highest score.
[0112] For example, if the detection device discovers that the border device of unit A has been attacked by the EternalBlue vulnerability, the electronic device will receive information carrying the "EternalBlue vulnerability attack". Since the target threat event is a preset event and the number of times it has received events carrying the target threat event has not reached the preset number, the electronic device will obtain the corresponding inspection item information. If the inspection item information obtained is "Access control devices should be deployed at the network boundary and the access control function should be enabled", it means that the inspection item information does not meet the standard and the corresponding points will be deducted. The inspection item information will be sent when the score reaches the first threshold after the deduction. This makes it easier for business personnel to maintain the key information infrastructure system based on the inspection item information.
[0113] Traditional security measures determination schemes are mainly based on the business personnel's own experience to determine security measures. They lack the guidance of top-level compliance standards, resulting in the determined security measures being not accurate and not comprehensive enough, and unable to meet the compliance requirements of critical information infrastructure systems. In the embodiment of the present application, nodes that record compliance standards are introduced into the graph template, and a connection relationship between the nodes and the nodes that record threat events is established, so that the inspection item information can be accurately determined, facilitating the repair of security risks.
[0114] In the embodiment of the present application, when business personnel pre-build the atlas template, they divide the compliance standards that the key information infrastructure system needs to follow into a tree structure hierarchy, that is, into Figure 4 The structure shown in the figure decomposes the inspection item information at the bottom level of the compliance standard into nodes of types such as "inspection item" and "object" related to security measures, so that when determining the security measures corresponding to the target threat event, the security measures can be accurately determined while meeting the compliance standards.
[0115] Example 5:
[0116] In order to accurately maintain the key information infrastructure system, based on the above embodiments, in the embodiment of the present application, the method further includes:
[0117] If no node related to the security measure connected to the node is obtained, a preset reminder message is sent.
[0118] In an embodiment of the present application, after a node corresponding to a target threat event is obtained, if a node related to a security measure connected to the node is not obtained, a preset reminder message is sent.
[0119] Specifically, if the received information only carries a target threat event, the electronic device obtains a node that records the target threat event, and obtains a node that is connected to the node and is of a type related to security measures. If a node that is connected to the node and is of a type related to security measures is not obtained, a preset reminder message is sent.
[0120] If the received information carries a target threat event and a target vulnerability event, the electronic device obtains a first node that records the target threat event, and a second node that records the target vulnerability event, and obtains a node that is connected to the first node and is of a type related to security measures, and a node that is connected to the second node and is of a type related to security measures. If no node that is connected to the first node and the second node and is of a type related to security measures is obtained, the electronic device outputs a preset reminder message.
[0121] Figure 5A detailed process diagram of obtaining security measures provided in an embodiment of the present application includes the following steps:
[0122] S501: Receive information carrying a target threat event.
[0123] S502: Determine whether the received information carries the target vulnerability event. If so, execute S503; if not, execute S505.
[0124] S503: Search the event processing graph for a first node recording a target threat event and a second node recording a target vulnerability event, and execute S504.
[0125] S504: Search for a node of a type related to security measures connected to the first node and a node of a type related to security measures connected to the second node, and execute S507.
[0126] S505: Search the event processing graph for a node that records the target threat event, and execute S506.
[0127] S506: Search for nodes of a type related to security measures connected to the node, and execute S507.
[0128] S507: Determine whether a node related to the security measure is found. If so, execute S508; if not, execute S509.
[0129] S508: Obtain the information recorded in the found node, send it, and execute S510.
[0130] S509: Send the preset reminder information and execute S510.
[0131] S510: End.
[0132] Figure 6 A schematic diagram of a data processing process provided in an embodiment of the present application.
[0133] Depend on Figure 6It can be seen that the text from which electronic devices extract keywords includes management systems, personnel records, asset lists, vulnerability scans, configuration checks, security logs, sandbox logs, etc., and keywords are proposed in the text, among which the extracted keywords include management keywords, vulnerable keywords, threat keywords, and electronic devices realize the connection between nodes that record "keywords" according to the connection relationship between different types of nodes in the graph template, generate an event processing graph, and after receiving an event carrying a target threat, according to the pre-configured baseline, that is, the pre-configured preset event and the preset number of times, if the target threat event is a preset event and the number of times the event carrying the target threat is received reaches the preset number, then the node that records the target threat event is obtained, and the node related to the security measures connected to the node is obtained, and the information recorded in the node related to the security measures is obtained and sent.
[0134] The event processing map in the embodiment of the present application preliminarily establishes a security protection system. Business personnel can improve the event processing map in combination with daily security operations and maintenance. Compared with the traditional security measure determination method, it has real-time dynamic adjustment capabilities, and after receiving information carrying target threat events, it can quickly trace risks and respond quickly, and determine the information in the corresponding security measure-related nodes. It is mainly used to solve the problem of determining security measures for critical information infrastructure systems that have high requirements for business security and continuity.
[0135] For example, in a case of an "SMB remote code execution vulnerability attack" that exploited the Eternal Blue vulnerability, the electronic device received information carrying the "Eternal Blue vulnerability attack" and Figure 3 The event processing diagram shows that Unit A needs to comply with the Level 4 protection standard. The tree structure of the basic protection requirements is divided into "network security, access control, deployment of access control devices at the network boundary, and enabling access control functions." This check item uses the "port access control function" and the protection target is the "network boundary." The attacker exploited the "EternalBlue vulnerability attack" technique and operated at the network boundary of the open SMB service.
[0136] Therefore, the SMB service can be associated with the network boundary and security measures, thereby establishing a relationship between management knowledge and monitoring event knowledge, such as Figure 4 When an incident related to the "EternalBlue vulnerability attack" occurs, the event processing graph can provide feedback on the inadequacy of the access control management implementation process.
[0137] Since critical information infrastructure systems have extremely high requirements for business continuity, data integrity, and confidentiality, the traditional long-term risk assessment model cannot ensure that critical information infrastructure can timely and effectively discover long-term potential security risks and respond to sudden network security incidents; secondly, due to industry differences, critical information infrastructure needs to comply with the requirements of network compliance standards in different countries. The current security assessment process lacks top-level standard guidance, resulting in incomplete assessments. At the same time, the implementation of compliance standards mainly relies on on-site manual surveys and interviews for data collection. The system cannot effectively process management data, and standard compliance is decoupled from actual monitoring and threat monitoring. The solution of this application can quickly and accurately determine security measures.
[0138] The embodiments of this application mainly solve the problems of comprehensiveness and timeliness of security status assessment of critical information infrastructure, while building a connection between compliance standards and regulations and actual monitoring data, realizing automated compliance assessment, and guiding the implementation of compliance standards.
[0139] Example 6:
[0140] Figure 7 This is a structural diagram of a data processing device provided in an embodiment of the present application. Based on the above embodiments, an embodiment of the present application further provides a data processing device, the device comprising:
[0141] Receiving module 701, configured to receive information carrying target threat events;
[0142] Processing module 702 is configured to, if the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, search for a node corresponding to the target threat event in a pre-generated event processing graph, and obtain a node related to a security measure connected to the node;
[0143] The acquisition and sending module 703 is used to acquire and send the information recorded in the node related to the security measure.
[0144] Furthermore, the processing module 702 is also used to receive each text used to generate an event processing graph; for each text, each keyword contained in the text is extracted, and for each keyword, if the graph template does not contain a node recording the keyword, a target node is created in the graph template, the keyword is recorded in the target node, the type saved corresponding to the keyword is obtained, the correspondence between the target node and the type is saved, and according to the connection relationship between the nodes in the graph template, the target type of each other node connected to the node of the type in the graph template is determined, other nodes of other keywords of the target type in the text are determined, and the target node and the other nodes are connected.
[0145] Furthermore, the processing module 702 is specifically used to search for the first node whose keyword recorded in the pre-generated event processing map is the target threat event, and the second node whose keyword recorded is the target vulnerable event, if the information also carries the target vulnerable event; if the information does not carry the target vulnerable event, search for the node whose keyword recorded in the pre-generated event processing map is the target threat event.
[0146] Furthermore, the processing module 702 is specifically configured to obtain a node of a security measure-related type connected to the first node and obtain a node of a security measure-related type connected to the second node if the information also carries a target vulnerability event.
[0147] Furthermore, the processing module 702 is also used to search for the node corresponding to the target threat event in the pre-generated event processing map if the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than the preset number, and obtain the node of the type of inspection item connected to the node; obtain the inspection item information recorded in the node of the type of inspection item; if the number of times the inspection item information is obtained exceeds the target number, send the inspection item information and clear the number of times the inspection item information is obtained.
[0148] In the embodiments of this application, Figure 8 A structural diagram of another data processing device provided in an embodiment of the present application is shown in FIG. Figure 8 As shown:
[0149] The device includes: a data acquisition module 801, a management and monitoring association module 802 and a security management module 803.
[0150] Among them, the management monitoring association module 802 and the security governance module 803 are used to receive information carrying target threat events; if the target threat event is a preset event and the number of times the information carrying the target threat event is received reaches the preset number, then find the node corresponding to the target threat event in the pre-generated event processing map and obtain the node related to the security measure connected to the node; this part of the function is the same as Figure 7 The corresponding functions of the receiving module 701 and the processing module 702 are consistent.
[0151] The security management module 803 is used to obtain and send the information recorded in the nodes related to the security measures. Figure 7 The corresponding function of the acquisition and sending module 703 is consistent.
[0152] Furthermore, the data acquisition module 801 and the management monitoring association module 802 are used to receive each text used to generate an event processing map; for each text, extract each keyword contained in the text, and for each keyword, if the map template does not contain a node recording the keyword, create a target node in the map template, record the keyword in the target node, obtain the type saved corresponding to the keyword, save the correspondence between the target node and the type, and determine the target type of each other node connected to the node of the type in the map template based on the connection relationship between the nodes in the map template, determine other nodes of other keywords of the target type in the text, and connect the target node and the other nodes. This part of the function is the same as Figure 7 The corresponding functions of the processing module 702 in are consistent.
[0153] Furthermore, the management monitoring association module 802 is used to search for the first node whose keyword is the target threat event and the second node whose keyword is the target vulnerability event in the pre-generated event processing map if the information also carries the target vulnerability event; if the information does not carry the target vulnerability event, search for the node whose keyword is the target threat event in the pre-generated event processing map. This part of the function is similar to Figure 7 The corresponding functions of the processing module 702 in are consistent.
[0154] Furthermore, the management monitoring association module 802 is used to obtain a node of a security measure related type connected to the first node and a node of a security measure related type connected to the second node if the information also carries a target vulnerability event. This part of the function is similar to Figure 7 The corresponding functions of the processing module 702 in are consistent.
[0155] Furthermore, the security governance module 803 is used to search for the node corresponding to the target threat event in the pre-generated event processing map if the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than the preset number, and obtain the node of the type of inspection item connected to the node; obtain the inspection item information recorded in the node of the type of inspection item, and if the number of times the inspection item information is obtained exceeds the target number, send the inspection item information and clear the number of times the inspection item information is obtained. This part of the function is similar to Figure 7 The corresponding functions of the processing module 702 in are consistent.
[0156] Furthermore, the management monitoring association module 802 is used to send a preset reminder message if no node related to the security measure connected to the node is obtained. Figure 7The corresponding functions of the processing module 702 in are consistent.
[0157] Example 7:
[0158] Figure 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown in FIG. Figure 9 As shown, it includes: a processor 901 , a communication interface 902 , a memory 903 and a communication bus 904 , wherein the processor 901 , the communication interface 902 and the memory 903 communicate with each other via the communication bus 904 .
[0159] The memory 903 stores a computer program. When the program is executed by the processor 901, the processor 901 performs the following steps:
[0160] receiving information carrying target threat events;
[0161] If the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, searching for a node corresponding to the target threat event in a pre-generated event processing graph and obtaining a node related to a security measure connected to the node;
[0162] Obtain and send the information recorded in the node related to the security measure.
[0163] Furthermore, the processor 901 is further configured to receive each text used to generate an event processing graph;
[0164] For each text, extract each keyword contained in the text. For each keyword, if the graph template does not contain a node recording the keyword, create a target node in the graph template, record the keyword in the target node, obtain the type saved corresponding to the keyword, save the correspondence between the target node and the type, and determine the target type of each other node connected to the node of the type in the graph template based on the connection relationship between the nodes in the graph template, determine other nodes of other keywords of the target type in the text, and connect the target node and the other nodes.
[0165] Furthermore, the processor 901 is specifically configured to, if the information also carries a target vulnerability event, search a pre-generated event processing graph for a first node whose recorded keyword is the target threat event and a second node whose recorded keyword is the target vulnerability event;
[0166] If the information does not carry the target vulnerability event, a node whose keyword recorded in a pre-generated event processing map is the target threat event is searched.
[0167] Furthermore, the processor 901 is specifically configured to, if the information also carries a target vulnerability event, obtain a node of a security measure-related type connected to the first node, and obtain a node of a security measure-related type connected to the second node.
[0168] Furthermore, the processor 901 is further configured to, if the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than a preset number, search for a node corresponding to the target threat event in a pre-generated event processing graph, and obtain a node of the check item type connected to the node;
[0169] The inspection item information recorded in the node of the inspection item type is obtained. If the number of times the inspection item information is obtained exceeds a target number, the inspection item information is sent and the number of times the inspection item information is obtained is cleared.
[0170] Furthermore, the processor 901 is further configured to send a preset reminder message if no node related to the security measure connected to the node is obtained.
[0171] The communication bus mentioned in the server above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into address buses, data buses, control buses, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0172] The communication interface 902 is used for communication between the electronic device and other devices.
[0173] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. Alternatively, the memory may be at least one storage device located away from the processor.
[0174] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processing processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.
[0175] Example 8:
[0176] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program executable by an electronic device. When the program is executed on the electronic device, the electronic device implements the following steps:
[0177] The memory stores a computer program, which, when executed by the processor, causes the processor to perform the following steps:
[0178] receiving information carrying target threat events;
[0179] If the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, searching for a node corresponding to the target threat event in a pre-generated event processing graph and obtaining a node related to a security measure connected to the node;
[0180] Obtain and send the information recorded in the node related to the security measure.
[0181] In one possible implementation, the event processing graph is generated in the following manner:
[0182] Receive each text used to generate an event processing graph;
[0183] For each text, extract each keyword contained in the text. For each keyword, if the graph template does not contain a node recording the keyword, create a target node in the graph template, record the keyword in the target node, obtain the type saved corresponding to the keyword, save the correspondence between the target node and the type, and determine the target type of each other node connected to the node of the type in the graph template based on the connection relationship between the nodes in the graph template, determine other nodes of other keywords of the target type in the text, and connect the target node and the other nodes.
[0184] In a possible implementation, searching for a node corresponding to the target threat event in a pre-generated event processing graph includes:
[0185] If the information also carries a target vulnerability event, then searching for a first node whose recorded keyword is the target threat event and a second node whose recorded keyword is the target vulnerability event in a pre-generated event processing map;
[0186] If the information does not carry the target vulnerability event, a node whose keyword recorded in a pre-generated event processing map is the target threat event is searched.
[0187] In a possible implementation manner, if the information also carries a target vulnerability event, obtaining a node related to a security measure connected to the node includes:
[0188] A node of a security measure related type connected to the first node is acquired, and a node of a security measure related type connected to the second node is acquired.
[0189] In one possible implementation, the method further includes:
[0190] If the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than the preset number, searching for a node corresponding to the target threat event in a pre-generated event processing graph and obtaining a node of the check item type connected to the node;
[0191] The inspection item information recorded in the node of the inspection item type is obtained. If the number of times the inspection item information is obtained exceeds a target number, the inspection item information is sent and the number of times the inspection item information is obtained is cleared.
[0192] In one possible implementation, the method further includes:
[0193] If no node related to the security measure connected to the node is obtained, a preset reminder message is sent.
[0194] In a possible implementation manner, the security measure-related types include: assets, objects, security resources, security technologies, security equipment, and security measures.
[0195] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0196] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0197] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0198] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0199] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A data processing method, characterized in that: The method comprises: receiving information carrying target threat events; If the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, then the node corresponding to the target threat event in the pre-generated event processing map is searched, and nodes related to security measures connected to the node are obtained; wherein the nodes related to security measures are nodes that record specific security technologies and nodes that record specific security devices; Obtaining and sending information recorded in nodes related to the security measures; The method further comprises: If the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than the preset number, searching for a node corresponding to the target threat event in a pre-generated event processing graph and obtaining a node of the check item type connected to the node; Acquire the inspection item information recorded in the node of the inspection item type, and if the number of times the inspection item information is acquired exceeds a target number, send the inspection item information and reset the number of times the inspection item information is acquired; The step of searching for a node corresponding to the target threat event in a pre-generated event processing graph includes: If the information also carries a target vulnerability event, then searching for a first node whose recorded keyword is the target threat event and a second node whose recorded keyword is the target vulnerability event in a pre-generated event processing map; If the information does not carry the target vulnerability event, a node whose keyword recorded in a pre-generated event processing map is the target threat event is searched.
2. The method according to claim 1, characterized in that The event processing graph is generated in the following way: Receive each text used to generate an event processing graph; For each text, extract each keyword contained in the text. For each keyword, if the graph template does not contain a node recording the keyword, create a target node in the graph template, record the keyword in the target node, obtain the type saved corresponding to the keyword, save the correspondence between the target node and the type, and determine the target type of each other node connected to the node of the type in the graph template based on the connection relationship between the nodes in the graph template, determine other nodes of other keywords of the target type in the text, and connect the target node and the other nodes.
3. The method according to claim 1, characterized in that If the information also carries a target vulnerability event, obtaining nodes related to security measures connected to the node includes: A node of a security measure related type connected to the first node is acquired, and a node of a security measure related type connected to the second node is acquired.
4. The method according to claim 1, wherein The method further comprises: If no node related to the security measure connected to the node is obtained, a preset reminder message is sent.
5. A data processing device, characterized in that: The device comprises: A receiving module, configured to receive information carrying target threat events; a processing module configured to, if the target threat event is a preset event and the number of times the information carrying the target threat event has been received reaches a preset number, search for a node corresponding to the target threat event in a pre-generated event processing graph, and obtain a node related to a security measure connected to the node; wherein the node related to the security measure is a node that records a specific security technology and a node that records a specific security device; An acquisition and sending module, configured to acquire and send information recorded in nodes related to the security measures; The processing module is further configured to, if the target threat event is a preset event and the number of times the information carrying the target threat event is received is less than a preset number, search for a node corresponding to the target threat event in a pre-generated event processing map, and obtain a node of the inspection item type connected to the node; obtain inspection item information recorded in the node of the inspection item type; and if the number of times the inspection item information has been obtained exceeds a target number, send the inspection item information and reset the number of times the inspection item information has been obtained to zero; The processing module is specifically used to search for the first node whose keyword recorded in the pre-generated event processing map is the target threat event, and the second node whose keyword recorded in the pre-generated event processing map is the target vulnerable event, if the information also carries the target vulnerable event; if the information does not carry the target vulnerable event, search for the node whose keyword recorded in the pre-generated event processing map is the target threat event.
6. An electronic device, characterized in that: The electronic device comprises at least a processor and a memory, and the processor is configured to execute the steps of the data processing method according to any one of claims 1 to 4 when executing a computer program stored in the memory.
7. A computer-readable storage medium, characterized in that The computer program is stored therein, and when the computer program is executed by a processor, the steps of the data processing method according to any one of claims 1 to 4 are executed.
Citation Information
Patent Citations
Network security event response method, device and equipment
CN113709147A