Network security event notification and early warning method and system
Through the dual confirmation mechanism between the notifying end and the notified end, the efficiency problem of network security tools in reporting and warning during event data processing is solved, ensuring that the party responsible for the incident is consistent with the party handling the incident, and achieving efficient and accurate incident processing and tracing.
Patent Information
- Application Number
- CN202510242743.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-10-14
AI Technical Summary
Existing network security tools have difficulty in efficiently reporting and warning when processing large amounts of event data, which can easily lead to omissions or failure to handle them in a timely manner, thereby causing the threat to spread.
By establishing a double confirmation mechanism between the notifying and notified ends, we ensure that the responsible party for the security incident is consistent with the actual handling party. We use the event detection engine to match conditions, and through multiple confirmations and reviews by the notifying and notified ends, we ensure the accuracy and timeliness of event handling.
It achieves efficient notification and early warning of security incidents, ensures that the party responsible for the incident is consistent with the party handling the incident, provides a post-event tracing mechanism, and improves the execution effect of incident early warning.
Smart Images

Figure CN120785564A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of network security event processing, and particularly relates to a network security event reporting and early warning method and a system applying the method. BACKGROUND
[0002] With the development of the Internet, attack events increase year by year, and network security problems gradually become the focus of society. Network security events refer to situations in which information systems are potentially harmed or even affected in normal service provision due to human factors and defects or faults of hardware and software. Network security events usually have negative impacts on society, and certain alarm and disposal measures need to be taken after confirmation.
[0003] The security linkage of network security tools such as firewalls, intrusion prevention, terminal security and other products can achieve effective disposal of threats and abnormal behaviors. However, due to different sources of logs corresponding to different alarm configurations, the types of alarm events are numerous, and in particular, the amount of event data after data correlation analysis and processing is huge. If efficient reporting and early warning cannot be performed, it is easy to cause omission or untimely processing, and thus lead to threat diffusion. SUMMARY
[0004] In view of the above background, the present application aims to provide an efficient network security event reporting and early warning method and system, and the specific technical solutions are as follows.
[0005] On the one hand, the present application first provides a network security event reporting and early warning method, comprising: network security events meeting preset conditions are sequentially added to a to-be-reported event list according to time sequence, and the to-be-reported events include reporting end and reported end information; each to-be-reported event is transferred to a corresponding reporting end, and if the reporting end determines that the to-be-reported event needs to be reported, the event is converted into a to-be-claimed event and is issued to a corresponding reported end; the reported end determines whether the received to-be-claimed event is a false positive, and if it is a false positive, the event is returned to the reporting end, and if it is not a false positive, the event is claimed and a handled mark is returned after offline processing.
[0006] Preferably, the reporting and early warning method further comprises: the reporting end audits the handled event returned by the reported end, reissues a to-be-handled event to the reported end if the audit fails, archives the security event and adds a passed audit mark if the audit passes, and the handled event and the passed audit event both have responsibility information and a marking time.
[0007] Preferably, the reporting and early warning method further comprises: periodically determining whether the claimed event has been handled, and urging if it has not been handled.
[0008] Preferably, the judging whether the network security event meets the preset condition comprises: acquiring the aggregated and merged log data at a time, and performing condition matching by the event detection engine according to a preset strategy, and if the matching is successful, adding the event as a to-be-reported event.
[0009] Further, the to-be-reported event further comprises an event reported by a subordinate organization and a manually added event.
[0010] Preferably, the information of the to-be-reported event, the to-be-claimed event, the to-be-handled event and the handled event comprises event source, event type, threat level, handling state, IP, asset organization name or responsible person keyword, and time range; further, the to-be-claimed event, the to-be-handled event and the handled event further comprise event description, event harm, asset organization to which the event belongs, event level, reporting source and reporting state.
[0011] On the other hand, the application further provides a network security event reporting and warning system, which comprises: An event handling module, which sequentially adds network security events meeting preset conditions into a to-be-reported event list according to time sequence; A reporting module, which converts the to-be-reported event into a to-be-claimed event if it is determined that the to-be-reported event needs to be reported, and then sends the to-be-claimed event to a corresponding reported end and receives information returned by the reported end.
[0012] Preferably, the event handling module judges whether the network security event meets the preset condition by acquiring the aggregated and merged log data at a time, and performing condition matching by the event detection engine according to a preset strategy, and if the matching is successful, adding the event as a to-be-reported event.
[0013] Preferably, the reporting module audits the handled event returned by the reported end, and if the handled event does not pass the audit, re-sends the to-be-handled event to the reported end, and if the handled event passes the audit, archives the security event and adds an audit passing mark; the reporting module periodically judges whether the claimed event has been handled, and if not, sends a reminder.
[0014] The application has at least the following beneficial effects: the security events that pass the condition screening are used as the data basis of the reporting and warning, and are pushed to the corresponding reported end according to the event related information by the reporting end, and in this process, the to-be-reported event is confirmed by the reporting end and the reported end twice, which can ensure the consistency of the event responsibility party and the actual handling party, and is beneficial to the after-tracing; meanwhile, there are handling marks and state audit mechanisms, which can ensure the execution effect of the event reporting and warning. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1The whole flowchart of the event notification of the network security event notification and early warning method and system. DETAILED DESCRIPTION
[0016] The application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related content of the application, but not to limit the application. In addition, it should be noted that, for the convenience of description, only the parts related to the application are shown in the drawings. EMBODIMENT
[0017] The network security event notification and early warning method embodiment includes the following steps: From a security event to a to-be-notified event: the network security events meeting the preset conditions are sequentially added to the to-be-notified event list according to the time sequence, and the information of the to-be-notified event, the to-be-claimed event, the to-be-handled event, and the handled event includes the event source, the event type, the threat level, the handling state, the IP, the asset organization name or the key of the person in charge, and the time range; further, the to-be-claimed event, the to-be-handled event, and the handled event also include the event description, the event harm, the asset organization to which the event belongs, the event level, the notification source, and the notification state.
[0018] From the notification end to the notified end: each to-be-notified event is transferred to the corresponding notification end, if the notification end judges that the to-be-notified event needs to be notified, the event is converted into a to-be-claimed event and is issued to the corresponding notified end. In addition, it is judged whether the claimed event has been handled or not, and if not, a single is urged.
[0019] As a preferred embodiment, the notification includes the notification and issuance of the selected asset group responsible person of the event, the asset responsible person, the notification mode, and the required handling days and other dimension information.
[0020] The event handling process of the notified end: the notified end judges whether the received to-be-claimed event is a misjudgment or not, if it is a misjudgment, it is returned to the notification end, if it is not a misjudgment, the event is claimed and is returned with a handled mark after offline processing.
[0021] As a preferred embodiment, the security event source includes: the aggregated and merged log data is acquired at regular intervals, and the event detection engine matches the conditions according to the preset strategy, if the matching is successful, the to-be-notified event is added.
[0022] As a preferred embodiment, the above-mentioned notification and early warning method further includes: the notification end audits the handled event returned by the notified end, if it does not pass, the to-be-handled event is reissued to the notified end, if it passes, the security event is archived and a pass mark is added. In addition, the handled event and the pass event both have the information of the person in charge and the marking time.
[0023] Further, the above-mentioned event to be reported also includes events reported by subordinate organizations and manually added events. Embodiments
[0024] A network security event reporting and warning system embodiment includes: An event processing module adds network security events meeting preset conditions to a list of events to be reported in sequence according to time of occurrence. A reporting module converts the event to an event to be claimed if the event to be reported needs to be reported, and sends the event to a corresponding reported end and receives information returned by the reported end.
[0025] Preferably, the event processing module determines whether the network security event meets the preset conditions by: regularly obtaining aggregated and merged log data, and performing condition matching by an event detection engine according to a preset strategy, and adding the event to the list of events to be reported if the matching is successful.
[0026] Preferably, the reporting module audits the processed event returned by the reported end, re-sends the event to be processed to the reported end if the audit fails, archives the security event and adds an audit pass mark if the audit passes, and determines whether the claimed event has been processed and urges the processing if the processing has not been completed.
[0027] As a preferred implementation, the reporting module can include functions of reporting overview, events to be reported, events in reporting, archived events, and events not needing to be reported.
[0028] Specifically, the reporting overview: an administrator can uniformly view reported events and reporting processing, mainly including reporting event statistics, reporting asset organization statistics, and reporting event filtering and viewing. The events to be reported: after automatic identification of security events needing to be reported by configuration, an administrator can view the events to be reported, mainly including event description, event harm, asset organization, reporting source, and event level. Meanwhile, filtering is supported by time range, reporting source (automatic research and judgment, manual creation, upper or lower reporting), event category, and threat level. The events in reporting: after an event is reported, the event is transferred to the events in reporting, and an administrator can view, filter, and operate the events in reporting. The archived events: when a security event has been disposed. The events not needing to be reported: in the stages of “events to be reported” and “events in reporting”, when an administrator judges that an event does not need to be reported and marks the event, the event is transferred to the events not needing to be reported.
[0029] As a preferred embodiment, the information of the event to be reported, the event to be claimed, the event to be processed, and the processed event includes the event source, the event type, the threat level, the processing state, the IP, the asset organization name or the key word of the person in charge, the time range and other information; further, the event to be claimed, the event to be processed, and the processed event also includes the event description, the event damage, the asset organization, the event level, the reporting source and the reporting state and other information.
[0030] The technical solution of the embodiment of the application as described above takes the security events screened by conditions as the data basis of the reporting and warning, and pushes the events to the corresponding notified end according to the event related information by the reporting end, in the process, the notified event is double-confirmed by the reporting end and the notified end, which can ensure the consistency of the event responsibility party and the actual processing party, and is beneficial to the after-tracing; meanwhile, there are processing marks and state auditing mechanisms, which can ensure the execution effect of the event reporting and warning.
[0031] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiment methods can be completed by programs instructing the related hardware, and the programs can be stored in a computer readable storage medium, such as ROM / RAM, magnetic disc, optical disc and the like.
[0032] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles disclosed herein.
Claims
1. A method for notifying and warning of network security incidents, characterized in that: include: Network security events that meet the preset conditions are added to the list of events to be reported in order of occurrence time. The events to be reported include information about the reporting end and the notified end. Each event to be reported is forwarded to the corresponding reporting terminal. If the reporting terminal determines that the event to be reported needs to be reported, it will be converted into a pending claim event and sent to the corresponding notified terminal; The notified end determines whether the received unclaimed event is a misjudgment. If it is a misjudgment, it returns it to the notifying end. If it is not a misjudgment, it claims the event, processes it offline, and returns a processed mark.
2. The notification and warning method according to claim 1, characterized in that: Also includes: The notifying end reviews the processed events returned by the notified end. If the event fails, the notified end will resend the pending event to the notified end. If the event passes the review, the security event will be archived and a review pass mark will be added.
3. The notification and warning method according to claim 2, characterized in that: The processed events and approved events all have responsible person information and marking time.
4. The notification and warning method according to claim 1, characterized in that: Also includes: Regularly check whether the claimed event has been processed, and if not, urge the order.
5. The notification and warning method according to claim 1, characterized in that: The determination of whether a network security event meets preset conditions includes: regularly obtaining aggregated and merged log data, and having an event detection engine perform condition matching according to a preset strategy. If the match is successful, the event is added as an event to be reported.
6. The notification and warning method according to claim 1, characterized in that: The events to be reported also include events reported by lower-level organizations and manually added events.
7. The notification and warning method according to any one of claims 1 to 5, characterized in that: Information on pending notification events, pending claim events, pending processing events, and processed events, including event source, event type, threat level, processing status, IP address, asset organization name or responsible person keyword, and timeframe; The pending events, pending events, and processed events also include event description, event hazard, affiliated asset organization, event level, notification source, and notification status.
8. A notification and early warning system for network security incidents, characterized in that: The system comprises: The event processing module adds network security events that meet the preset conditions to the list of events to be reported in order of occurrence time; If the notification module determines that the event to be notified needs to be notified, it will convert the event into a pending event, send it to the corresponding notified end, and receive the information returned by the notified end.
9. The network security incident notification and warning system according to claim 8, characterized in that: The event processing module determines whether the network security event meets the preset conditions, including: regularly obtaining aggregated and merged log data, and the event detection engine matches the conditions according to the preset strategy. If the match is successful, it is added as an event to be reported.
10. The network security incident notification and warning system according to claim 8, characterized in that: The notification module reviews the processed events returned by the notified end. If they fail, the pending events will be re-sent to the notified end. If the review passes, the security event will be archived and a review pass mark will be added; it will regularly determine whether the claimed events have been processed. If not, the order will be urged.