Threat situation analysis method and device, electronic equipment and storage medium

By combining the target security big model with the preset attack event information set and threat intelligence library, the problems of misjudgment and missed detection of network attack behaviors in network security are solved, high-precision threat situation analysis is achieved, and network security protection capabilities are improved.

CN120658457APending Publication Date: 2025-09-16BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510804851.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing technologies are difficult to detect network attack behaviors with high accuracy in network security, and there are problems of misjudgment and missed detection, which affects network security protection capabilities.

Method used

By using a large target security model combined with a preset attack event information set and a threat intelligence library, we can perform attack event detection and threat situation analysis on the alarm information to be analyzed, achieving threat situation analysis with high accuracy and low misjudgment rate.

Benefits of technology

It improves the network security system's ability to perceive threat situations, reduces misjudgments and missed detections in manual inspections, and enables more accurate and efficient threat situation analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658457A_ABST
    Figure CN120658457A_ABST
Patent Text Reader

Abstract

The invention discloses a threat situation analysis method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring alarm information to be analyzed; inputting the to-be-analyzed alarm information into a target security big model, performing attack event detection on the to-be-analyzed alarm information based on a preset attack event information set, and performing threat situation analysis on the to-be-analyzed alarm information based on a corresponding target attack event detection result and a threat intelligence library, and outputting a target threat situation analysis result corresponding to the to-be-detected alarm information, so that attack event detection can be automatically performed on the to-be-analyzed alarm information with high precision and low misjudgment rate, the problem of misjudgment or missing detection in manual detection is avoided, and the target security big model can be utilized to improve the security of the to-be-detected alarm information. In combination with the target attack event detection result corresponding to the alarm information to be analyzed and the threat intelligence in the threat intelligence library, more accurate and efficient threat situation analysis is realized, and the perceptual ability of the system to the threat situation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a threat situation analysis method, device, electronic device and storage medium. Background Art

[0002] With the rapid development of network technology, network security issues are becoming increasingly prominent, and various cyberattack methods are constantly emerging, posing significant challenges to network security. Network traffic data, as a key threat intelligence carrier that records network behavior, may contain a variety of potential attacks. Therefore, how to effectively detect attacks from this threat intelligence has become a crucial step in improving network security protection capabilities. Summary of the Invention

[0003] The embodiments of the present application provide a threat situation analysis method, device, electronic device, and storage medium that can automatically detect attack events with high accuracy and low false positive rate for the alarm information to be analyzed, avoiding the false positives or missed detections that exist in manual detection. Furthermore, the embodiments of the present application can utilize a large target security model, combining the target attack event detection results corresponding to the alarm information to be analyzed with the threat intelligence in the threat intelligence library, to achieve more accurate and efficient threat situation analysis and improve the system's ability to perceive threat situations. The above technical solutions are as follows:

[0004] In a first aspect, an embodiment of the present application provides a threat situation analysis method, the method comprising:

[0005] Obtain alarm information to be analyzed;

[0006] The above-mentioned alarm information to be analyzed is input into the target security model, and attack event detection is performed on the above-mentioned alarm information to be analyzed based on the preset attack event information set. The threat situation analysis of the above-mentioned alarm information to be analyzed is performed based on the corresponding target attack event detection results and the threat intelligence library, and the target threat situation analysis results corresponding to the above-mentioned alarm information to be detected are output.

[0007] In a possible implementation, the preset attack event information set includes at least one slice information corresponding to each of the plurality of attack events;

[0008] The attack event detection based on the preset attack event information set on the alarm information to be analyzed includes:

[0009] Compare the alarm information to be analyzed with the slice information corresponding to each attack event in the preset attack event information set to obtain a target slice comparison result;

[0010] The target attack event detection result corresponding to the above-mentioned alarm information to be analyzed is determined based on the above-mentioned target slice comparison result.

[0011] In a possible implementation, the target slice comparison result includes a slice overlap degree between each of the plurality of attack events and the alarm information to be analyzed;

[0012] The target attack event detection result corresponding to the alarm information to be analyzed is determined based on the target slice comparison result, including:

[0013] If there is a target attack event among the multiple attack events, and the target attack event has a corresponding slice overlap degree greater than or equal to the target overlap degree, determining that the target attack event detection result corresponding to the alarm information to be analyzed indicates that the target attack event exists in the alarm information to be analyzed;

[0014] When the slice overlap degree between each of the above-mentioned multiple attack events and the above-mentioned alarm information to be analyzed is less than the above-mentioned target overlap degree, it is determined that the target attack event detection result corresponding to the above-mentioned alarm information to be analyzed indicates that there is no attack event in the above-mentioned alarm information to be analyzed.

[0015] In a possible implementation, inputting the alarm information to be analyzed into the target security model, and performing attack event detection on the alarm information to be analyzed based on a preset attack event information set, includes:

[0016] The above-mentioned alarm information to be analyzed is input into the target security big model, and based on the target business scenario information corresponding to the above-mentioned alarm information to be analyzed, the corresponding target attack event special detection rule is retrieved from the preset attack event special detection rule set, and according to the above-mentioned target attack event special detection rule, attack event detection is performed on the above-mentioned alarm information to be analyzed based on the preset attack event information set; the above-mentioned preset attack event special detection rule set includes attack event special detection rules under multiple business scenarios.

[0017] In a possible implementation, when the target attack event detection result indicates that a target attack event exists in the alarm information to be analyzed, the target threat situation analysis result includes target attack details information and target disposal suggestion information corresponding to the target attack event; the target attack details information includes at least one of the following: the target attack stage in which the target attack event is currently located, the target threat level, the target attack status, the target attack impact range, the target attack trend, target attack-related technical points, target attack-related communication information, and the target-related event corresponding to the target attack event;

[0018] When the target attack event detection result indicates that there is no attack event in the alarm information to be analyzed, the target threat situation analysis result includes the target threat situation prediction information corresponding to the alarm information to be analyzed; the target threat situation prediction information includes at least one of the following: target future attack prediction information, target vulnerability repair suggestion information corresponding to the target future attack prediction information; the target future attack prediction information includes target future attack trend information and / or target future attack event information.

[0019] In a possible implementation, the step of obtaining the alarm information to be analyzed includes:

[0020] Obtain the alarm information to be analyzed corresponding to multiple alarm events within the target time period;

[0021] The above-mentioned alarm information to be analyzed is input into the target security model, attack event detection is performed on the above-mentioned alarm information to be analyzed based on the preset attack event information set, and threat situation analysis is performed on the above-mentioned alarm information to be analyzed based on the corresponding target attack event detection results and the threat intelligence library, and the target threat situation analysis results corresponding to the above-mentioned alarm information to be detected are output, including:

[0022] The alarm information to be analyzed corresponding to each of the above-mentioned multiple alarm events is input into the target security model, and attack event detection is performed on each of the above-mentioned alarm information to be analyzed based on the preset attack event information set. The target attack event detection result and target attack trend within the above-mentioned target time period are determined based on the attack event detection result corresponding to each of the above-mentioned alarm information to be analyzed. Finally, based on the above-mentioned target attack event detection result, the above-mentioned target attack trend and the threat intelligence library, a threat situation analysis is performed on the alarm information to be analyzed within the above-mentioned target time period, and the target threat situation analysis result within the above-mentioned target time period is output.

[0023] In a possible implementation, the method further includes:

[0024] Receive a specified query operation input by a user; the specified query operation carries at least one specified query field;

[0025] In response to the above-mentioned specified query operation, displaying corresponding at least one target alarm information based on the above-mentioned at least one specified query field;

[0026] receiving a designated detail viewing operation input by the user based on the at least one target alarm information; the designated detail viewing operation carries a designated alarm identifier corresponding to the designated alarm information selected by the user to be viewed in the at least one target alarm information;

[0027] In response to the specified detail viewing operation, the specified threat situation analysis result corresponding to the specified alarm information is displayed based on the specified alarm identifier.

[0028] In a second aspect, an embodiment of the present application provides a threat situation analysis device, comprising:

[0029] Acquisition module, used to obtain alarm information to be analyzed;

[0030] The threat situation analysis module is used to input the above-mentioned alarm information to be analyzed into the target security model, perform attack event detection on the above-mentioned alarm information to be analyzed based on the preset attack event information set, and perform threat situation analysis on the above-mentioned alarm information to be analyzed based on the corresponding target attack event detection results and the threat intelligence library, and output the target threat situation analysis results corresponding to the above-mentioned alarm information to be detected.

[0031] In a third aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory;

[0032] The processor is connected to the memory;

[0033] The aforementioned memory is used to store executable program code;

[0034] The processor runs the program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method provided by the first aspect of the embodiment of this specification or any possible implementation of the first aspect.

[0035] In a fourth aspect, an embodiment of this specification provides a computer storage medium, which stores multiple instructions, and the instructions are suitable for being loaded by a processor and executing the method provided by the first aspect of the embodiment of this specification or any possible implementation of the first aspect.

[0036] In the embodiments of the present application, on the one hand, by utilizing the target security big model and combining it with a preset attack event information set, it is possible to automatically perform attack event detection with high precision and low misjudgment rate on the alarm information to be analyzed, thereby avoiding the misjudgment or missed detection problems that exist in manual detection; on the other hand, by utilizing the target security big model and combining it with the target attack event detection results corresponding to the alarm information to be analyzed and the threat intelligence in the threat intelligence library, it is possible to achieve more accurate and efficient threat situation analysis and improve the system's ability to perceive the threat situation.

[0037] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0039] Figure 1 A schematic diagram of the architecture of a threat situation analysis system provided by an exemplary embodiment of the present application;

[0040] Figure 2 A flowchart of a threat situation analysis method provided by an exemplary embodiment of the present application;

[0041] Figure 3 A schematic diagram of an implementation flow of attack event detection provided by an exemplary embodiment of the present application;

[0042] Figure 4 A flowchart of another threat situation analysis method provided by an exemplary embodiment of the present application;

[0043] Figure 5 A schematic diagram of an implementation flow of a threat situation query display provided by an exemplary embodiment of the present application;

[0044] Figure 6A-6B A schematic diagram showing a threat situation analysis according to an exemplary embodiment of the present application;

[0045] Figure 7 A schematic diagram of the structure of a threat situation analysis device provided by an exemplary embodiment of the present application;

[0046] Figure 8 A schematic structural diagram of an electronic device provided as an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0047] To make the features and advantages of this application more obvious and easy to understand, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0048] The terms "first," "second," "third," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements, but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.

[0049] Please refer to the following Figure 1 , which is a schematic diagram of the architecture of a threat situation analysis system provided by an exemplary embodiment of this specification. Figure 1 As shown, the threat situation analysis system may include: a terminal 110 and a server 120. Among them:

[0050] The terminal 110 can be a user terminal corresponding to one or more users (network security managers or network security analysts), and specifically can include one or more user terminals. A user version of software (network security related applications) can be installed in the terminal 110 to assist users in threat situation analysis. The terminal 110 can obtain the alarm information to be analyzed, and input the above-mentioned alarm information to be analyzed into the target security model, perform attack event detection on the above-mentioned alarm information to be analyzed based on the preset attack event information set, and perform threat situation analysis on the above-mentioned alarm information to be analyzed based on the corresponding target attack event detection results and the threat intelligence library, and output the target threat situation analysis results corresponding to the above-mentioned alarm information to be detected. Among them, the terminal 110 can be, but is not limited to, a mobile phone, tablet computer, laptop computer and other devices installed with the user version software (network security related applications).

[0051] Optionally, after obtaining the alarm event generated during the network transmission process, the terminal 110 can also, but is not limited to, send the alarm information to be analyzed corresponding to the above alarm event to the server 120 through the network, so that the server 120 can subsequently assist the terminal 110 in performing corresponding threat situation analysis on the alarm information to be analyzed.

[0052] Server 120 can be a server that provides multiple threat situation analysis services. It can obtain the unanalyzed alarm information generated by terminal 110 via the network, input the unanalyzed alarm information into the target security model, perform attack event detection on the unanalyzed alarm information based on a preset attack event information set, perform threat situation analysis on the unanalyzed alarm information based on the corresponding target attack event detection results and the threat intelligence library, and output the target threat situation analysis results corresponding to the unanalyzed alarm information. Server 120 can be, but is not limited to, a hardware server, a virtual server, a cloud server, etc.

[0053] It can be understood that the threat situation analysis method provided in the embodiment of the present application can be executed by the terminal 110 or the server 120 alone, or can be executed by the terminal 110 and the server 120 together, and the embodiment of the present application is not limited to this.

[0054] The network can be a medium that provides a communication link between any terminal 110 and the server 120, or can be the Internet including network devices and transmission media, but is not limited thereto. The transmission medium can be a wired link, such as, but not limited to, coaxial cable, optical fiber, and digital subscriber line (DSL), or a wireless link, such as, but not limited to, wireless fidelity (WIFI), Bluetooth, and mobile device networks.

[0055] Understandably, Figure 1 The number of terminals 110 and servers 120 in the threat situation analysis system shown is for illustrative purposes only. In a specific implementation, the threat situation analysis system may include any number of terminals 110 and servers 120. This specification does not impose any specific limitations on this. For example, but not limited to, the terminals 110 may be a user-end cluster consisting of multiple user terminals, and the servers 120 may be a server cluster consisting of multiple servers.

[0056] Please refer to the following Figure 2 , taking the terminal executing threat situation analysis as an example, a threat situation analysis method provided by an exemplary embodiment of the present application is introduced. Figure 2 As shown in the figure, the threat situation analysis method includes the following steps:

[0057] S201: Obtain alarm information to be analyzed.

[0058] Specifically, alarm information is a structured data record generated when a security system detects a potential threat. The alarm information to be analyzed may include, but is not limited to, basic metadata corresponding to the alarm event to be analyzed, attack behavior description information, contextual information, security analysis auxiliary information, response status tracking information, etc. The basic metadata may include, but is not limited to, the ID of the alarm event to be analyzed (i.e., unique event identifier), generation time, data source type (such as, but not limited to, the log or device type that generated the alarm), original log ID (i.e., the associated underlying log identifier), alarm level, alarm confidence (characterizing the accuracy probability of the system's judgment), etc. The above-mentioned attack behavior description information may include, but is not limited to, the trigger rule name (i.e., the security detection rule matched by the alarm event to be analyzed), the behavior summary (i.e., the abnormal activity corresponding to the alarm event to be analyzed described in natural language), technical feature information (such as, but not limited to, the attack source address, the attacked target address, the communication port, the relevant process information, the relevant file information, such as the malicious file path or hash, the network protocol type, etc.). The above-mentioned context association information may include, but is not limited to, asset ownership information (such as affected device information, user information, etc.), vulnerability association information (such as the associated vulnerability number, risk level, etc.). The above-mentioned security analysis auxiliary information may include, but is not limited to, original data packet capture information, related alarms (such as other alarm information in the same attack chain), etc. The above-mentioned response status tracking information may include, but is not limited to, the processing status corresponding to the alarm event to be analyzed (i.e., the work order lifecycle status, such as, but not limited to, pending status, unreported status, reported status, etc.), response action information (such as, but not limited to, security disposal operation information executed for the alarm event to be analyzed), etc.

[0059] Optionally, the terminal may obtain the alarm information to be analyzed corresponding to each of the multiple alarm events generated within the target time period at a preset time interval, that is, perform threat situation analysis on the alarm events generated by the security system at regular intervals.

[0060] Optionally, when the security system detects a potential threat and generates an alarm event (alarm event to be analyzed), the terminal may retrieve the alarm information to be analyzed corresponding to the alarm event to be analyzed recorded by the security system.

[0061] S202: Input the alarm information to be analyzed into the target security model, perform attack event detection on the alarm information to be analyzed based on the preset attack event information set, and perform threat situation analysis on the alarm information to be analyzed based on the corresponding target attack event detection results and the threat intelligence library, and output the target threat situation analysis results corresponding to the alarm information to be detected.

[0062] Specifically, the aforementioned target security model is a large-scale language model designed specifically for the field of network security. By integrating knowledge such as threat intelligence, attack patterns, and defense strategies, it can implement intelligent threat analysis, automated response, and predictive defense. The aforementioned preset attack event information set is the foundation for the target security model to understand threats, detect attack events, and make accurate judgments. It may, but is not limited to, include at least one attack event information corresponding to each of multiple data sources. The aforementioned attack event information may, but is not limited to, include technical characteristics corresponding to the attack (such as, but not limited to, attack type, attack method, attack payload, attack vector, etc.), behavioral patterns (such as, but not limited to, attack phase, attack frequency, attack target, attack consequences, etc.), associated context information (such as, but not limited to, alarm source, alarm time, associated events, network environment, etc.), attack background knowledge information (such as, but not limited to, attacker information, historical attack patterns, threat intelligence, business context, etc.), attack response recommendation information (such as, but not limited to, attack response disposal recommendations, disposal priority, traceability information, etc.), and other information that specifically describes the attack behavior in multiple dimensions. The aforementioned threat intelligence library contains multiple threat intelligence resources. This refers to analyzed and verified information related to threats. This information helps organizations understand the current threat landscape, attacker motivations and methods, and how to prevent or respond to potential attacks. Threat intelligence typically includes in-depth analysis of the threat, contextual information, and actionable recommendations.

[0063] In the embodiments of the present application, on the one hand, by utilizing the target security big model and combining it with a preset attack event information set, it is possible to automatically perform attack event detection with high precision and low misjudgment rate on the alarm information to be analyzed, thereby avoiding the misjudgment or missed detection problems that exist in manual detection; on the other hand, by utilizing the target security big model and combining it with the target attack event detection results corresponding to the alarm information to be analyzed and the threat intelligence in the threat intelligence library, it is possible to achieve more accurate and efficient threat situation analysis and improve the system's ability to perceive the threat situation.

[0064] In some possible embodiments, the above-mentioned preset attack event information set may include, but is not limited to, at least one slice information corresponding to each of the multiple attack events. The above-mentioned slice information is a structured data fragment formed after fine-grained decomposition of the attack event, which is used to support rapid analysis, tracing and response. In an embodiment of the present application, a known attack event can be first decomposed into data fragments of multiple dimensions (for example, but not limited to time, network, behavior, impact, etc.), and each fragment is called a "slice". Slice information can be analyzed independently or combined to form a complete event portrait. Through the slicing processing of attack events, the efficiency, accuracy and operability of the target security big model for attack event detection can be improved, and the security team can be assisted to quickly locate the root cause of the alarm problem and formulate a response strategy. The slice information corresponding to each attack event may include but is not limited to at least one of the following: time slice information (recording the start time, duration, key time nodes of the attack, such as penetration, lateral movement, data theft, etc.), network slice information (recording the network addresses of the initiator and the attacked party, the protocols and ports used in the attack, etc.), behavior slice information (recording the specific technologies used by the attacker, such as SQL injection, brute force cracking and other attack methods, malware, scripts or tools used in the attack and other attack tools and payloads), impact slice information (recording the affected objects such as the attacked system, application or service, the type and scale of the leaked data, and other data leakage scope), traceability slice information (recording the attacker's intrusion path, related events, etc.), response slice information (recording the response actions taken, such as isolating the host or banning the IP, etc., and providing follow-up suggestions such as fixing vulnerabilities or strengthening monitoring, etc.). Figure 3 As shown, in the above S202, the implementation process of the target large model performing attack event detection on the alarm information to be analyzed based on the preset attack event information set may include but is not limited to:

[0065] S301 : Compare the alarm information to be analyzed with each slice information corresponding to each attack event in the preset attack event information set to obtain a target slice comparison result.

[0066] Specifically, after the alarm information to be analyzed is input into the target security big model, the target security big model can first extract features of the alarm information to be analyzed, such as but not limited to extracting target key features such as source IP, target IP, attack type, attack time, etc. in the alarm information to be analyzed, and then compare them one by one with the slice information of each attack event in the preset attack event information set, calculate the similarity or matching degree or overlap degree, and then obtain the target slice comparison result, so that the target security big model can comprehensively and carefully analyze the correlation between the alarm information and known attack events, and not miss any possible attack feature matches, so as to achieve accurate attack event detection.

[0067] S302: Determine a target attack event detection result corresponding to the alarm information to be analyzed based on the target slice comparison result.

[0068] Optionally, after the target security model obtains the target slice comparison result, it can be based on preset thresholds or rules, for example but not limited to when the similarity exceeds the first threshold, it is determined that the match is successful; when it exceeds the second threshold (the second threshold is greater than the first threshold), it is determined that the alarm information to be analyzed corresponds to a known target attack event; when it exceeds the first threshold but does not exceed the second threshold, it is determined that the alarm information to be analyzed corresponds to an unknown attack event; when it does not exceed the first threshold, it is determined that the alarm information to be analyzed does not have an attack event, which is a false alarm. This can quickly and accurately identify the actual existence of the corresponding attack event of the alarm information to be analyzed and the corresponding attack event type when it exists, providing a clear direction for subsequent threat situation analysis, security response and disposal, and helping to take targeted preventive measures in a timely manner, reduce security risks, and improve the efficiency and effectiveness of network security protection.

[0069] Optionally, the target slice comparison result may include, but is not limited to, a slice overlap degree between each of the multiple attack events and the alarm information to be analyzed. The above-mentioned S302, the implementation process of determining the target attack event detection result corresponding to the alarm information to be analyzed based on the target slice comparison result, may include, but is not limited to: when there is a target attack event among the multiple attack events whose corresponding slice overlap degree is greater than or equal to a target overlap degree (for example, but not limited to 90%, 80%, etc.), determining that the target attack event detection result corresponding to the alarm information to be analyzed indicates that the corresponding target attack event among the multiple known attack events exists in the alarm information to be analyzed; when the slice overlap degrees between each of the multiple attack events and the alarm information to be analyzed are less than the target overlap degree, determining that the target attack event detection result corresponding to the alarm information to be analyzed indicates that there is no attack event in the alarm information to be analyzed.

[0070] In some possible embodiments, the implementation process of inputting the alarm information to be analyzed into the target security big model in the above S202 and performing attack event detection on the alarm information to be analyzed based on the preset attack event information set may include, but is not limited to: inputting the alarm information to be analyzed into the target security big model, retrieving the corresponding target attack event special detection rule from the preset attack event special detection rule set based on the target business scenario information corresponding to the alarm information to be analyzed, and performing attack event detection on the alarm information to be analyzed based on the preset attack event information set according to the target attack event special detection rule. The above-mentioned preset attack event special detection rule set includes attack event special detection rules for multiple business scenarios, and the above-mentioned attack event special detection rules are set by network security analysts based on business demand information in the corresponding business scenario, or are generated by the target rule generation model based on business demand information in the corresponding business scenario and general attack event detection rules (for example, but not limited to, adjusting the general attack event detection rules based on business demand information). This embodiment of the present application does not limit this. The above-mentioned target business scenario information may include, but is not limited to, the identifier and / or type of the target business scenario corresponding to the alarm information to be analyzed.

[0071] It is understandable that different business scenarios will lead to different attack event-specific detection rules being called by the target security model during attack event detection.

[0072] In an embodiment of the present application, special detection rules for attack events under different business scenarios can be pre-built into the target security big model, so that the target big model can achieve high-precision and high-target attack event detection that meets actual business needs by retrieving the target attack event special detection rules corresponding to the target business scenario according to the alarm information to be analyzed during the threat situation analysis.

[0073] In some possible embodiments, when the target attack event detection result indicates that there is a target attack event in the alarm information to be analyzed, the target threat situation analysis result may include, but is not limited to, target attack details information and target disposal recommendation information corresponding to the target attack event. The target attack details information may include, but is not limited to, at least one of the following: the target attack stage in which the target attack event is currently located, the target threat level, the target attack status, the target attack impact range, the target attack trend, target attack-related technical points, target attack-related communication information, and target-related events corresponding to the target attack event. The target-related events may include, but are not limited to, attacker-related events and victim-related events. Optionally, the target threat situation analysis result may also include, but is not limited to, target threat description information corresponding to the alarm information to be analyzed, which is used to inform the target security big model of the reason for providing target disposal recommendation information.

[0074] If the target attack event detection result indicates that no attack events exist in the alarm information to be analyzed, the target threat situation analysis result may include, but is not limited to, target threat situation prediction information corresponding to the alarm information to be analyzed. The target threat situation prediction information may include, but is not limited to, at least one of the following: target future attack prediction information and target vulnerability remediation suggestion information corresponding to the target future attack prediction information. The target future attack prediction information may include, but is not limited to, target future attack trend information and / or target future attack event information.

[0075] Please refer to Figure 4 , which is a flowchart of another threat situation analysis method provided by an exemplary embodiment of this application. Figure 4 As shown, the threat situation analysis method may include the following steps:

[0076] S401: Obtain the alarm information to be analyzed corresponding to each of a plurality of alarm events within a target time period.

[0077] Specifically, the target time period may be, but is not limited to, the past day, the past week, etc. The multiple alarm events may be alarm events in different business scenarios, alarm events in the same business scenario, or alarm events in a specified business scenario, which is not limited in the present embodiment.

[0078] S402, input the alarm information to be analyzed corresponding to each of the multiple alarm events into the target security model, perform attack event detection on each alarm information to be analyzed based on the preset attack event information set, and determine the target attack event detection result and target attack trend within the target time period based on the attack event detection result corresponding to each alarm information to be analyzed. Finally, based on the target attack event detection result, target attack trend and threat intelligence library, perform threat situation analysis on the alarm information to be analyzed within the target time period, and output the target threat situation analysis result within the target time period.

[0079] Specifically, the attack event detection process is consistent with the attack event detection process in S202, and will not be repeated here. The target attack trend may include, but is not limited to, the total number of attacks, the number of successful attacks, the number of failed attacks, the number of attempted attacks, and the attack distribution within the target time period.

[0080] In an embodiment of the present application, the target security big model has multi-event analysis capabilities, and can perform a more comprehensive and accurate threat situation analysis on the alarm information to be analyzed corresponding to multiple alarm events within the target time period based on the target attack event detection results, target attack trends and threat intelligence library, and output the overall target threat situation analysis results within the target time period, thereby giving corresponding threat risk warnings, defense measures and optimization plans through the overall target threat situation analysis results within the target time period, thereby improving the overall security protection capabilities.

[0081] Please refer to Figure 5 , which is a schematic diagram of a threat situation query display implementation flow provided by an exemplary embodiment of the present application. Figure 5 As shown, the implementation process of the threat situation query display may include but is not limited to the following steps:

[0082] S501: Receive a specified query operation input by a user, where the specified query operation carries at least one specified query field.

[0083] Specifically, when a user wants to view certain alarm information, he or she may, but is not limited to, input a specified query condition in the terminal, where the specified query condition is composed of at least one specified query field. The terminal may receive the specified query operation input by the user.

[0084] S502: In response to a specified query operation, display at least one corresponding target alarm information based on at least one specified query field.

[0085] Specifically, after receiving the user's designated query operation, the terminal can respond to the designated query operation, query the alarm information database based on at least one designated query field input or selected by the user to obtain at least one corresponding target alarm information that has been generated, and use it in a manner such as, but not limited to, Figure 6A The information is presented in the form of diagrams and / or text as shown.

[0086] S503: Receive a designated detail viewing operation input by a user based on at least one target alarm information. The designated detail viewing operation carries a designated alarm identifier corresponding to the designated alarm information selected by the user to be viewed in the at least one target alarm information.

[0087] Specifically, when a user wants to view the detailed target threat situation analysis results generated by the target security model corresponding to a certain target alarm information, he can, but is not limited to, enter the corresponding specified detail viewing operation (for example, but not limited to clicking, sliding, etc.) based on the display area corresponding to the selected specified alarm information.

[0088] S504: In response to the designated detail viewing operation, a designated threat situation analysis result corresponding to the designated alarm information is displayed based on the designated alarm identifier.

[0089] Specifically, after receiving the user's designated details viewing operation, the terminal can respond to the designated details viewing operation and query the target security big model based on the designated alarm identifier to obtain the designated threat situation analysis result corresponding to the designated alarm information, or trigger the target security big model to perform threat situation analysis on the designated alarm information according to the process described in S202 above, obtain the corresponding designated threat situation analysis result, and use it in a manner such as, but not limited to, Figure 6B The information is presented in the form of diagrams and / or text as shown.

[0090] Please refer to the following Figure 7 , which is a structural diagram of a threat situation analysis device provided in an embodiment of the present application. Figure 7 As shown, the threat situation analysis device 700 includes:

[0091] An acquisition module 710 is used to acquire alarm information to be analyzed;

[0092] The threat situation analysis module 720 is used to input the above-mentioned alarm information to be analyzed into the target security model, perform attack event detection on the above-mentioned alarm information to be analyzed based on the preset attack event information set, and perform threat situation analysis on the above-mentioned alarm information to be analyzed based on the corresponding target attack event detection results and the threat intelligence library, and output the target threat situation analysis results corresponding to the above-mentioned alarm information to be detected.

[0093] In a possible implementation, the preset attack event information set includes at least one slice information corresponding to each of the plurality of attack events;

[0094] When the threat situation analysis module 720 performs attack event detection on the alarm information to be analyzed based on the preset attack event information set, it is specifically used to: compare the alarm information to be analyzed with the slice information corresponding to each attack event in the preset attack event information set to obtain a target slice comparison result; and determine the target attack event detection result corresponding to the alarm information to be analyzed based on the target slice comparison result.

[0095] In a possible implementation, the target slice comparison result includes a slice overlap degree between each of the plurality of attack events and the alarm information to be analyzed;

[0096] When the threat situation analysis module 720 determines the target attack event detection result corresponding to the alarm information to be analyzed based on the target slice comparison result, it is specifically used to: when there is a target attack event among the multiple attack events whose corresponding slice overlap degree is greater than or equal to the target overlap degree, determine that the target attack event detection result corresponding to the alarm information to be analyzed indicates that the target attack event exists in the alarm information to be analyzed; when the slice overlap degrees between each of the multiple attack events and the alarm information to be analyzed are less than the target overlap degree, determine that the target attack event detection result corresponding to the alarm information to be analyzed indicates that there is no attack event in the alarm information to be analyzed.

[0097] In one possible implementation, when the threat situation analysis module 720 inputs the alarm information to be analyzed into the target security big model and performs attack event detection on the alarm information to be analyzed based on a preset attack event information set, it is specifically used to: input the alarm information to be analyzed into the target security big model, retrieve the corresponding target attack event special detection rule from the preset attack event special detection rule set based on the target business scenario information corresponding to the alarm information to be analyzed, and perform attack event detection on the alarm information to be analyzed based on the preset attack event information set in accordance with the target attack event special detection rule; the preset attack event special detection rule set includes attack event special detection rules under multiple business scenarios.

[0098] In a possible implementation, when the target attack event detection result indicates that a target attack event exists in the alarm information to be analyzed, the target threat situation analysis result includes target attack details information and target disposal suggestion information corresponding to the target attack event; the target attack details information includes at least one of the following: the target attack stage in which the target attack event is currently located, the target threat level, the target attack status, the target attack impact range, the target attack trend, target attack-related technical points, target attack-related communication information, and the target-related event corresponding to the target attack event;

[0099] When the target attack event detection result indicates that there is no attack event in the alarm information to be analyzed, the target threat situation analysis result includes the target threat situation prediction information corresponding to the alarm information to be analyzed; the target threat situation prediction information includes at least one of the following: target future attack prediction information, target vulnerability repair suggestion information corresponding to the target future attack prediction information; the target future attack prediction information includes target future attack trend information and / or target future attack event information.

[0100] In a possible implementation, the acquisition module 710 is specifically configured to: acquire the alarm information to be analyzed corresponding to each of the multiple alarm events within the target time period;

[0101] The above-mentioned threat situation analysis module 720 is specifically used to: input the alarm information to be analyzed corresponding to each of the above-mentioned multiple alarm events into the target security model, perform attack event detection on each of the above-mentioned alarm information to be analyzed based on the preset attack event information set, and determine the target attack event detection result and target attack trend within the above-mentioned target time period based on the attack event detection result corresponding to each of the above-mentioned alarm information to be analyzed; finally, based on the above-mentioned target attack event detection result, the above-mentioned target attack trend and the threat intelligence library, perform threat situation analysis on the alarm information to be analyzed within the above-mentioned target time period, and output the target threat situation analysis result within the above-mentioned target time period.

[0102] In a possible implementation, the threat situation analysis device 700 further includes:

[0103] A first receiving module is configured to receive a specified query operation input by a user; the specified query operation carries at least one specified query field;

[0104] A first display module is configured to display at least one corresponding target alarm information based on the at least one specified query field in response to the specified query operation;

[0105] A second receiving module is configured to receive a designated detail viewing operation input by the user based on the at least one target alarm information; the designated detail viewing operation carries a designated alarm identifier corresponding to the designated alarm information selected by the user to be viewed in the at least one target alarm information;

[0106] The second display module is used to display the specified threat situation analysis result corresponding to the above-mentioned specified alarm information based on the above-mentioned specified alarm identifier in response to the specified detail viewing operation.

[0107] The division of the modules in the threat situation analysis device described above is for illustrative purposes only. In other embodiments, the threat situation analysis device can be divided into different modules as needed to perform all or part of the functions of the threat situation analysis device described above. The various modules in the threat situation analysis device provided in the embodiments of this specification can be implemented in the form of a computer program. This computer program can be executed on a terminal or server. The program modules comprising this computer program can be stored in a memory on the terminal or server. When executed by a processor, this computer program implements all or part of the steps of the threat situation analysis method described in the embodiments of this specification.

[0108] See next Figure 8, which is a structural diagram of an electronic device provided by an exemplary embodiment of this specification. Figure 8 As shown, the electronic device 800 may include: at least one processor 810 , at least one communication bus 820 , a user interface 830 , at least one network interface 840 , and a memory 850 .

[0109] The communication bus 820 may be used to implement connection and communication among the above components.

[0110] The user interface 830 may include a display screen (Display) and a camera (Camera), and the optional user interface 830 may also include a standard wired interface and a wireless interface.

[0111] The network interface 840 may optionally include a Bluetooth module, a Near Field Communication (NFC) module, a Wireless Fidelity (Wi-Fi) module, and the like.

[0112] The processor 810 may include one or more processing cores. The processor 810 utilizes various interfaces and circuits to connect various components within the electronic device 800. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 850, and accessing data stored in the memory 850, the processor 810 performs various functions and processes data for the routing electronic device 800. Optionally, the processor 810 may be implemented using at least one hardware form factor selected from the group consisting of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor 810 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content displayed on the display; and the modem handles wireless communications. It is understood that the modem may not be integrated into the processor 810 and may be implemented as a separate chip.

[0113] Among them, the memory 850 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 850 includes a non-transitory computer-readable medium. The memory 850 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 850 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a receiving function, a threat situation analysis function, an attack event detection function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 850 may also be optionally at least one storage device located away from the aforementioned processor 810. As Figure 8 As shown, the memory 850 as a computer storage medium may include an operating system, a network communication module, a user interface module, and program instructions.

[0114] In some possible embodiments, the electronic device 800 may be the aforementioned Figure 7 The threat situation analysis device 700 shown, the processor 810 can be used to call the program instructions stored in the memory 850, and specifically perform the following operations: obtain the alarm information to be analyzed; input the above-mentioned alarm information to be analyzed into the target security model, perform attack event detection on the above-mentioned alarm information to be analyzed based on the preset attack event information set, and perform threat situation analysis on the above-mentioned alarm information to be analyzed based on the corresponding target attack event detection result and the threat intelligence library, and output the target threat situation analysis result corresponding to the above-mentioned alarm information to be detected.

[0115] In some possible embodiments, the preset attack event information set includes at least one slice information corresponding to each of the plurality of attack events;

[0116] When the processor 810 performs the attack event detection on the alarm information to be analyzed based on the preset attack event information set, it is specifically used to perform: comparing the alarm information to be analyzed with the slice information corresponding to each attack event in the preset attack event information set to obtain a target slice comparison result; and determining a target attack event detection result corresponding to the alarm information to be analyzed based on the target slice comparison result.

[0117] In some possible embodiments, the target slice comparison result includes the slice overlap degree between each of the plurality of attack events and the alarm information to be analyzed;

[0118] When the processor 810 determines the target attack event detection result corresponding to the alarm information to be analyzed based on the target slice comparison result, it is specifically used to execute: when there is a target attack event among the multiple attack events whose corresponding slice overlap degree is greater than or equal to the target overlap degree, determining that the target attack event detection result corresponding to the alarm information to be analyzed indicates that the target attack event exists in the alarm information to be analyzed; when the slice overlap degrees between each of the multiple attack events and the alarm information to be analyzed are less than the target overlap degree, determining that the target attack event detection result corresponding to the alarm information to be analyzed indicates that there is no attack event in the alarm information to be analyzed.

[0119] In some possible embodiments, when the processor 810 executes the above-mentioned inputting of the alarm information to be analyzed into the target security big model and performing attack event detection on the alarm information to be analyzed based on a preset attack event information set, it is specifically used to execute: inputting the alarm information to be analyzed into the target security big model, retrieving the corresponding target attack event special detection rule from the preset attack event special detection rule set based on the target business scenario information corresponding to the alarm information to be analyzed, and performing attack event detection on the alarm information to be analyzed based on the preset attack event information set in accordance with the target attack event special detection rule; the preset attack event special detection rule set includes attack event special detection rules under multiple business scenarios.

[0120] In some possible embodiments, when the target attack event detection result indicates that a target attack event exists in the alarm information to be analyzed, the target threat situation analysis result includes target attack details information and target disposal suggestion information corresponding to the target attack event; the target attack details information includes at least one of the following: the target attack stage currently in which the target attack event is located, the target threat level, the target attack status, the target attack impact range, the target attack trend, target attack-related technical points, target attack-related communication information, and the target-related event corresponding to the target attack event;

[0121] When the target attack event detection result indicates that there is no attack event in the alarm information to be analyzed, the target threat situation analysis result includes the target threat situation prediction information corresponding to the alarm information to be analyzed; the target threat situation prediction information includes at least one of the following: target future attack prediction information, target vulnerability repair suggestion information corresponding to the target future attack prediction information; the target future attack prediction information includes target future attack trend information and / or target future attack event information.

[0122] In some possible embodiments, when the processor 810 executes the step of obtaining the alarm information to be analyzed, the processor 810 is specifically configured to obtain the alarm information to be analyzed corresponding to each of a plurality of alarm events within a target time period.

[0123] The processor 810 executes the steps of inputting the alarm information to be analyzed into the target security model, performing attack event detection on the alarm information to be analyzed based on a preset attack event information set, performing threat situation analysis on the alarm information to be analyzed based on the corresponding target attack event detection result and the threat intelligence library, and outputting the target threat situation analysis result corresponding to the alarm information to be detected. Specifically, the processor 810 is configured to execute:

[0124] The alarm information to be analyzed corresponding to each of the above-mentioned multiple alarm events is input into the target security model, and attack event detection is performed on each of the above-mentioned alarm information to be analyzed based on the preset attack event information set. The target attack event detection result and target attack trend within the above-mentioned target time period are determined based on the attack event detection result corresponding to each of the above-mentioned alarm information to be analyzed. Finally, based on the above-mentioned target attack event detection result, the above-mentioned target attack trend and the threat intelligence library, a threat situation analysis is performed on the alarm information to be analyzed within the above-mentioned target time period, and the target threat situation analysis result within the above-mentioned target time period is output.

[0125] In some possible embodiments, the processor 810 is further configured to execute: receiving a specified query operation input by a user; the specified query operation carries at least one specified query field; in response to the specified query operation, displaying at least one corresponding target alarm information based on the at least one specified query field; receiving a specified detail review operation input by the user based on the at least one target alarm information; the specified detail review operation carries a specified alarm identifier corresponding to the specified alarm information selected by the user to be reviewed in the at least one target alarm information; in response to the specified detail review operation, displaying a specified threat situation analysis result corresponding to the specified alarm information based on the specified alarm identifier.

[0126] Embodiments of the present application also provide a computer storage medium storing instructions that, when executed on a computer or processor, cause the computer or processor to perform one or more steps of any of the aforementioned methods. If the various components of the threat situation analysis device are implemented as software functional units and sold or used as independent products, they may be stored in the aforementioned storage medium.

[0127] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The above-mentioned computer program product includes one or more computer instructions. When the above-mentioned computer program instructions are loaded and executed on a computer, the above-mentioned process or function according to the embodiment of the present application is generated in whole or in part. The above-mentioned computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The above-mentioned computer instructions can be stored in a computer-readable storage medium or transmitted via the above-mentioned computer-readable storage medium. The above-mentioned computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The above-mentioned computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The above-mentioned available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0128] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When executed, the program can include the processes of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks. The technical features of this embodiment and the implementation scheme can be combined in any manner unless they conflict.

[0129] The above embodiments are merely descriptions of preferred embodiments of the present application and do not limit the scope of the present application. Without departing from the design spirit of the present application, various modifications and improvements made to the technical solutions of the present application by ordinary technicians in this field should fall within the scope of protection determined by the claims of the present application.

Claims

1. A threat situation analysis method, characterized in that: The method comprises: Obtain alarm information to be analyzed; The alarm information to be analyzed is input into the target security model, attack event detection is performed on the alarm information to be analyzed based on the preset attack event information set, and threat situation analysis is performed on the alarm information to be analyzed based on the corresponding target attack event detection result and the threat intelligence library, and the target threat situation analysis result corresponding to the alarm information to be detected is output.

2. The method according to claim 1, characterized in that The preset attack event information set includes at least one slice information corresponding to each of the plurality of attack events; The performing attack event detection on the alarm information to be analyzed based on the preset attack event information set includes: Comparing the alarm information to be analyzed with each slice information corresponding to each attack event in the preset attack event information set to obtain a target slice comparison result; The target attack event detection result corresponding to the alarm information to be analyzed is determined based on the target slice comparison result.

3. The method according to claim 2, characterized in that The target slice comparison result includes the slice overlap degree between each of the multiple attack events and the alarm information to be analyzed; The determining, based on the target slice comparison result, a target attack event detection result corresponding to the alarm information to be analyzed includes: If there is a target attack event among the multiple attack events, and the slice overlap degree corresponding to the target attack event is greater than or equal to the target overlap degree, determining that the target attack event detection result corresponding to the alarm information to be analyzed indicates that the target attack event exists in the alarm information to be analyzed; When the slice overlap degrees between each of the multiple attack events and the alarm information to be analyzed are less than the target overlap degree, it is determined that the target attack event detection result corresponding to the alarm information to be analyzed indicates that there is no attack event in the alarm information to be analyzed.

4. The method according to claim 1, wherein The step of inputting the alarm information to be analyzed into a target security model and performing attack event detection on the alarm information to be analyzed based on a preset attack event information set includes: The alarm information to be analyzed is input into the target security big model, and based on the target business scenario information corresponding to the alarm information to be analyzed, the corresponding target attack event special detection rule is retrieved from the preset attack event special detection rule set, and according to the target attack event special detection rule, attack event detection is performed on the alarm information to be analyzed based on the preset attack event information set; the preset attack event special detection rule set includes attack event special detection rules under multiple business scenarios.

5. The method according to claim 1, characterized in that In a case where the target attack event detection result indicates that a target attack event exists in the alarm information to be analyzed, the target threat situation analysis result includes target attack details information and target handling suggestion information corresponding to the target attack event; The target attack details information includes at least one of the following: the target attack stage of the target attack event, the target threat level, the target attack status, the target attack impact range, the target attack trend, target attack related technical points, target attack related communication information, and the target associated event corresponding to the target attack event; In a case where the target attack event detection result indicates that there is no attack event in the alarm information to be analyzed, the target threat situation analysis result includes target threat situation prediction information corresponding to the alarm information to be analyzed; The target threat situation prediction information includes at least one of the following: target future attack prediction information, and target vulnerability repair suggestion information corresponding to the target future attack prediction information; The target future attack prediction information includes target future attack trend information and / or target future attack event information.

6. The method according to claim 1, characterized in that The obtaining of the alarm information to be analyzed includes: Obtain the alarm information to be analyzed corresponding to multiple alarm events within the target time period; The step of inputting the alarm information to be analyzed into the target security model, performing attack event detection on the alarm information to be analyzed based on a preset attack event information set, performing threat situation analysis on the alarm information to be analyzed based on the corresponding target attack event detection result and a threat intelligence library, and outputting a target threat situation analysis result corresponding to the alarm information to be detected includes: The alarm information to be analyzed corresponding to each of the multiple alarm events is input into the target security model, and attack event detection is performed on each of the alarm information to be analyzed based on a preset attack event information set. The target attack event detection result and target attack trend within the target time period are determined based on the attack event detection result corresponding to each of the alarm information to be analyzed. Finally, based on the target attack event detection result, the target attack trend and the threat intelligence library, a threat situation analysis is performed on the alarm information to be analyzed within the target time period, and the target threat situation analysis result within the target time period is output.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Receive a specified query operation input by a user; the specified query operation carries at least one specified query field; In response to the specified query operation, displaying corresponding at least one target warning information based on the at least one specified query field; receiving a designated detail viewing operation input by the user based on the at least one target alarm information; the designated detail viewing operation carries a designated alarm identifier corresponding to the designated alarm information selected by the user to be viewed in the at least one target alarm information; In response to the designated detail viewing operation, a designated threat situation analysis result corresponding to the designated alarm information is displayed based on the designated alarm identifier.

8. A threat situation analysis device, characterized in that: The device comprises: Acquisition module, used to obtain alarm information to be analyzed; The threat situation analysis module is used to input the alarm information to be analyzed into the target security model, perform attack event detection on the alarm information to be analyzed based on a preset attack event information set, and perform threat situation analysis on the alarm information to be analyzed based on the corresponding target attack event detection results and the threat intelligence library, and output the target threat situation analysis result corresponding to the alarm information to be detected.

9. An electronic device, characterized in that: include: processor and memory; wherein, The processor is connected to the memory; the memory is used to store executable program code; The processor reads the executable program code stored in the memory to run a program corresponding to the executable program code, so as to execute the method steps according to any one of claims 1 to 7.

10. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Cloud host security situation awareness system and method, equipment and storage medium

    CN112073389A

  • Network flow detection framework and method, electronic equipment and storage medium

    CN112272186A

  • Multi-source security threat detection method and device

    CN116089940A

  • Attack detection method and device, electronic equipment and nonvolatile storage medium

    CN117201171A

  • Attack detection method and device, terminal equipment and storage medium

    CN117240598A