Safety alarm method, device and equipment based on chain analysis and medium
By constructing target context objects through chain-based analysis, data filtering and attack analysis are performed, solving the flexibility and scalability issues of existing security alert systems. This achieves end-to-end traffic control, ensures the continuity and accuracy of data processing, and improves system efficiency.
Patent Information
- Application Number
- CN202511889130.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-02-10
AI Technical Summary
Existing security alarm analysis systems lack flexibility, struggle to adapt to the processing needs of different types of alarms, have poor scalability, are prone to losing contextual information during data processing, and suffer from serious resource waste.
By employing a chain-based analysis approach, target context objects are constructed to perform data filtering and attack analysis. A pre-defined analysis model is used for secondary attack analysis, and the processing results are pushed to the corresponding processing platform to achieve end-to-end traffic control.
Ensure that data from different types of processing nodes is processed in a timely manner, guarantee the continuity and integrity of data processing through a context passing mechanism, improve data processing efficiency and accuracy, reduce invalid data processing, and improve system efficiency.
Smart Images

Figure CN121509074A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a security alerting method, apparatus, device, and medium based on chain analysis. Background Technology
[0002] With the increasing number of cybersecurity threats, security devices are generating alarm data characterized by large volume, diverse types, and complex correlations. Existing security alarm analysis systems typically employ a single processing flow, directly inputting alarm data into the analysis model for processing. This approach lacks flexibility, struggles to adapt to the processing needs of different alarm types, has poor scalability, and suffers from a rigid processing flow that makes it difficult to differentiate processing based on different alarm types. Furthermore, contextual information is easily lost during data processing, and the lack of effective data filtering mechanisms leads to resource waste. Summary of the Invention
[0003] In view of this, the purpose of this invention is to provide a security alarm method, device, equipment, and medium based on chain analysis, which can realize end-to-end traffic control from data source to model invocation, ensuring that data from different types of processing nodes can be processed in a timely manner. The specific solution is as follows:
[0004] Firstly, this application discloses a security alerting method based on chain analysis, applied to a security alerting system, including:
[0005] A target context object is constructed based on the target data corresponding to the preset data source, and the target context object is transmitted to the filtering node in the analysis link so that the target context object is filtered by the filtering node to obtain the filtered object.
[0006] The data characteristics corresponding to the filtered object are determined, and the filtered object is sent to the target analysis node in the analysis link that corresponds to the data characteristics, so that the target analysis node can perform attack analysis on the filtered object to obtain the corresponding attack analysis results.
[0007] The attack analysis results are subjected to secondary attack analysis based on the preset analysis model, and the obtained target processing results are sent to the output node in the analysis link.
[0008] The target processing result is pushed to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alarms or push information based on the target processing result.
[0009] Optionally, before constructing a target context object based on target data corresponding to a preset data source and transmitting the target context object to a filtering node in the analysis chain, so as to filter the target context object through the filtering node to obtain the filtered object, the method further includes:
[0010] The original data stream in the preset data source is sliced based on the preset time interval and preset data threshold to obtain several discrete data segments.
[0011] The discrete data segments are deduplicated and standardized to obtain the target data.
[0012] Optionally, the step of constructing a target context object based on target data corresponding to a preset data source, and transmitting the target context object to a filtering node in the analysis chain, so as to filter the target context object through the filtering node to obtain a filtered object, includes:
[0013] Determine the environmental information, historical status, associated data, and configuration parameters of the target data corresponding to the preset data source, and construct a target context object corresponding to the target data based on the environmental information, historical status, associated data, configuration parameters, and target data;
[0014] The target context object is transmitted to a filtering node in the analysis link so that the filtering node can remove the internal data in the target context object to obtain a filtered object; the internal data is the data generated by the security alarm system.
[0015] Optionally, determining the data features corresponding to the filtered object and sending the filtered object to the target analysis node in the analysis chain corresponding to the data features, so as to perform attack analysis on the filtered object through the target analysis node to obtain the corresponding attack analysis results, includes:
[0016] Determine the data features corresponding to the filtered object and determine the feature type of the data features, so as to send the filtered object to the target analysis node in the analysis link that corresponds to the feature type based on the feature type;
[0017] The filtered object is subjected to attack analysis by the target analysis node. If the filtered object has an attack behavior corresponding to the feature type, a first attack analysis result is generated. If it is not determined whether there is an attack behavior corresponding to the feature type in the filtered object, a second attack analysis result is generated.
[0018] Optionally, the step of performing secondary attack analysis on the attack analysis results based on a preset analysis model and sending the obtained target processing results to the output node in the analysis link includes:
[0019] If the attack analysis result is the first attack analysis result, then the first attack analysis result is sent as the target processing result to the output node in the analysis link;
[0020] If the attack analysis result is the second attack analysis result, then a second attack analysis is performed on the second analysis result using a preset analysis model and dedicated model analysis resources, and the attack intent of the target context object is determined. Based on the attack intent, a target processing result is generated, and then the target processing result is sent to the output node in the analysis link. The dedicated model analysis resources are pre-allocated model resources.
[0021] Optionally, before pushing the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alarms or push information based on the target processing result, the method further includes:
[0022] If the dedicated model analysis resources are exhausted and the target processing result is not obtained, then the second analysis result is subjected to a secondary attack analysis by sharing the model analysis resources in order to obtain the target processing result.
[0023] If the shared model analysis resources are exhausted and the target processing result is not obtained, the analysis will be retried based on the shared model analysis resources within a preset waiting time threshold. If the target processing result is not obtained, the target context object will be discarded.
[0024] Optionally, the step of pushing the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alerts or push information based on the target processing result, includes:
[0025] The target processing result is pushed to the first processing platform through the output node, so that the first processing platform can visualize the target processing result;
[0026] The target processing result is pushed to the second processing platform through the output node, so that the second processing platform saves the target processing result to a preset database;
[0027] The target processing result is pushed to the third processing platform through the output node, so that the third processing platform can issue a security alarm based on the target processing result.
[0028] Secondly, this application discloses a security alarm device based on chain analysis, applied to a security alarm system, comprising:
[0029] The data filtering module is used to construct a target context object based on the target data corresponding to a preset data source, and transmit the target context object to the filtering node in the analysis link, so as to filter the target context object through the filtering node to obtain the filtered object;
[0030] The first attack analysis module is used to determine the data characteristics corresponding to the filtered object and send the filtered object to the target analysis node in the analysis link that corresponds to the data characteristics, so as to perform attack analysis on the filtered object through the target analysis node and obtain the corresponding attack analysis results.
[0031] The second attack analysis module is used to perform secondary attack analysis on the attack analysis results based on a preset analysis model, and send the obtained target processing results to the output node in the analysis link.
[0032] The security alarm module is used to push the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alarms or push information based on the target processing result.
[0033] Thirdly, this application discloses an electronic device, including:
[0034] Memory, used to store computer programs;
[0035] A processor is used to execute the computer program to implement the security alerting method based on chain analysis as described above.
[0036] Fourthly, this application discloses a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned security alarm method based on chain analysis.
[0037] In this application, a target context object can be constructed based on target data corresponding to a preset data source, and the target context object can be transmitted to a filtering node in the analysis link to filter the target context object and obtain a filtered object. The data characteristics corresponding to the filtered object are determined, and the filtered object is sent to a target analysis node in the analysis link corresponding to the data characteristics to perform attack analysis on the filtered object and obtain corresponding attack analysis results. A secondary attack analysis is performed on the attack analysis results based on a preset analysis model, and the obtained target processing results are sent to an output node in the analysis link. The output node pushes the target processing results to a corresponding processing platform so that the processing platform can issue corresponding security alerts or push information based on the target processing results. Therefore, the method of this application can construct a target context object based on target data from a preset data source, transmit the target context object to a filtering node in the analysis chain for data filtering, and obtain a filtered object; determine the data characteristics of the filtered object, and send the filtered object to the target analysis node in the analysis chain corresponding to the data characteristics for attack analysis to obtain the attack analysis result; perform secondary attack analysis on the attack analysis result based on a preset analysis model, and push the obtained target processing result to the corresponding processing platform through the output node in the analysis chain, so that the processing platform can issue corresponding security alerts or push information based on the target processing result. In this way, end-to-end traffic control from data source to model call can be realized, ensuring that data from different types of processing nodes can be processed in a timely manner, and the continuity and integrity of data processing are guaranteed by the context passing mechanism, while the chained processing mechanism improves the efficiency and accuracy of data processing, and the intelligent filtering mechanism reduces the processing of invalid data and improves system efficiency. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0039] Figure 1 This is a flowchart of a security alerting method based on chain analysis disclosed in this application;
[0040] Figure 2 This is a schematic diagram illustrating the processing sequence of a security alarm method based on chain analysis disclosed in this application.
[0041] Figure 3This is a schematic diagram of a security alarm device based on chain analysis disclosed in this application;
[0042] Figure 4 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0044] Existing security alarm analysis systems typically employ a single processing flow, directly inputting alarm data into the analysis model for processing. This approach lacks flexibility, struggles to adapt to the processing needs of different alarm types, has poor scalability, and suffers from a rigid processing flow that makes it difficult to differentiate processing based on different alarm types. Furthermore, contextual information is easily lost during data processing, and the lack of an effective data filtering mechanism leads to wasted resources.
[0045] To overcome the aforementioned technical problems, this application discloses a security alarm method, device, equipment, and medium based on chain analysis, which can realize end-to-end traffic control from data source to model call, ensuring that data from different types of processing nodes can be processed in a timely manner. Furthermore, the context passing mechanism ensures the continuity and integrity of data processing, and the chain processing mechanism improves the efficiency and accuracy of data processing, while the intelligent filtering mechanism reduces the processing of invalid data and improves system efficiency.
[0046] See Figure 1 As shown, this embodiment of the invention discloses a security alarm method based on chain analysis, applied to a security alarm system, including:
[0047] Step S11: Construct a target context object based on the target data corresponding to the preset data source, and transmit the target context object to the filtering node in the analysis link so that the target context object can be filtered by the filtering node to obtain the filtered object.
[0048] In this embodiment, before constructing the target context object based on the target data corresponding to the preset data source, the data in the preset data source needs to be preprocessed. Specifically, as shown in Figure 2, the original data stream in the preset data source needs to be sliced based on a preset time interval and a preset data threshold to obtain several discrete data segments. Then, data deduplication and standardization operations are performed on these discrete data segments to obtain the target data. It should be noted that the preset data source is a Kafka data source, and to ensure smooth processing, time window-level rate control is required. A time window-based data sharding strategy can be adopted, dividing the continuous data stream into discrete time windows with a preset time interval of minutes. Then, a quota restriction mechanism is implemented within each time window, allowing only a preset data threshold number of data to enter subsequent processing, thereby achieving source flow control. Furthermore, data deduplication and standardization operations are performed on the obtained discrete data segments to obtain the target data corresponding to the preset data source, thereby improving the efficiency of subsequent processing.
[0049] Furthermore, after receiving the target data corresponding to the preset data source, the security alarm system needs to create a context object corresponding to the target data. Specifically, such as... Figure 2 As shown, it is necessary to determine the environmental information, historical status, associated data, and configuration parameters of the target data corresponding to the preset data source, and construct a target context object corresponding to the target data based on the environmental information, historical status, associated data, configuration parameters, and target data. It should be noted that the data acquisition process uses the LinkAnalysisNode abstract base class to construct the analysis link, and defines a unified processing specification through the AnalysisNode interface. To facilitate data transfer between nodes, an AnalysisContext is designed to manage the context object. The context flows between different nodes, realizing the transfer and sharing of data in the processing link, as well as the transfer of processing status between different nodes, enabling the tracking and control of the processing status.
[0050] Another step, such as Figure 2As shown, the target context object needs to be transmitted to the filter node in the analysis chain so that the filter node can remove the internal data in the target context object to obtain the filtered object. The internal data is generated by the security alarm system. It should be noted that if the target context object fails the filter, it should be discarded. Furthermore, the analysis chain needs to be divided into three layers: filter node, processing node, and output node. This layered decoupling avoids coupling in the processing process. Each link is connected through a standard interface, allowing for dynamic addition of processing nodes without excessive development. During node execution, the `safeProcess` method is used to process data from different nodes. Exceptions are handled uniformly to ensure that an exception in a single node does not affect the overall process. This chained processing mechanism improves the efficiency and accuracy of data processing.
[0051] Step S12: Determine the data features corresponding to the filtered object, and send the filtered object to the target analysis node in the analysis link that corresponds to the data features, so as to perform attack analysis on the filtered object through the target analysis node and obtain the corresponding attack analysis results.
[0052] In this embodiment, it is necessary to determine the data characteristics corresponding to the filtered object and send the filtered object to the target analysis node in the analysis chain corresponding to the data characteristics. Specifically, it is necessary to determine the data characteristics corresponding to the filtered object and identify the feature type of the data characteristics, so as to send the filtered object to the target analysis node in the analysis chain corresponding to the feature type based on the feature type. It should be noted that it is necessary to determine the attack type corresponding to the filtered object based on the data characteristics, such as active attack, web attack, etc. Different attack types correspond to different analysis nodes, therefore, it is necessary to send the filtered object to the corresponding target analysis node based on the data characteristics corresponding to the filtered object.
[0053] Furthermore, the filtered objects need to be analyzed for attacks by the target analysis node. If the filtered objects exhibit attack behaviors corresponding to the feature type, a first attack analysis result is generated. For example, if the target analysis node is a Web attack analysis node, after receiving the filtered objects, it needs to determine whether they contain filtered Web attack behaviors. If Web attack behaviors exist, a first attack analysis result is generated. On the other hand, if it is not determined whether the filtered objects contain attack behaviors corresponding to the feature type, a second attack analysis result is generated. For example, if the Web attack analysis node is unsure whether the filtered objects contain Web attack behaviors after performing attack analysis, a second attack analysis is needed using a pre-defined analysis model. Therefore, a second attack analysis result representing the uncertainty of whether corresponding attack behaviors exist needs to be generated.
[0054] Step S13: Perform secondary attack analysis on the attack analysis results based on the preset analysis model, and send the obtained target processing results to the output node in the analysis link.
[0055] In this embodiment, as Figure 2 As shown, a pre-set analysis model is needed to perform secondary attack analysis on the attack analysis results, and the resulting target processing result is sent to the output node in the analysis chain. Specifically, on the one hand, if the attack analysis result is the first attack analysis result, then the first attack analysis result is sent as the target processing result to the output node in the analysis chain; on the other hand, if the attack analysis result is the second attack analysis result, then a secondary attack analysis is performed on the second analysis result using the pre-set analysis model and dedicated model analysis resources, and the attack intent of the target context object is determined. Based on the attack intent, a target processing result is generated, and then the target processing result is sent to the output node in the analysis chain. The dedicated model analysis resources are pre-allocated model resources. It should be noted that, to ensure processing efficiency, load balancing is required based on the aforementioned time window strategy and the node concurrent resource allocation strategy. Specifically, if dedicated model analysis resources are exhausted and no target processing result is obtained, secondary attack analysis is performed on the second analysis result using shared model analysis resources to obtain the target processing result. If shared model analysis resources are exhausted and no target processing result is obtained, analysis is retried based on shared model analysis resources within a preset waiting time threshold. If the target processing result is not obtained, the target context object is discarded. A fine-grained concurrent resource management strategy based on processing node type needs to be implemented in the pre-call stage of the large model. The system divides the total concurrent capacity of the large model into two types of resource pools: a dedicated concurrent pool and a shared concurrent pool. The dedicated concurrent pool pre-allocates exclusive concurrent resources for each processing node type, while the shared concurrent pool serves as a globally shared resource, dynamically available for each node to request when dedicated resources are exhausted. When the dedicated concurrent resources of a specific node are exhausted, the system automatically switches to the shared concurrent pool for resource scheduling. If all concurrent resources are occupied, the system activates a timeout protection mechanism, discarding timed-out data to ensure system stability. This approach ensures fairness in data processing across all processing nodes while maximizing the utilization of concurrent resources in large models.
[0056] Step S14: Push the target processing result to the corresponding processing platform through the output node, so that the processing platform can make corresponding security alarms or push information based on the target processing result.
[0057] In this embodiment, the target processing result needs to be pushed to the corresponding processing platform through the output node so that the processing platform can issue corresponding security alerts or push information based on the target processing result. Specifically, for example... Figure 2As shown, the target processing results need to be pushed to the first processing platform via the output node so that the first processing platform can visualize the target processing results, i.e., push the activity list, and push the target processing results to the real-time alarm panel and activity monitoring dashboard. The target processing results also need to be pushed to the second processing platform via the output node so that the second processing platform can save the target processing results to a preset database, i.e., store them in a database or data lake for subsequent auditing and report generation. Furthermore, the target processing results need to be pushed to the third processing platform via the output node so that the third processing platform can generate security alerts based on the target processing results, and can also perform security operations such as blocking IPs (Internet Protocol Addresses) and issuing WAF (Web Application Firewall) rules.
[0058] In this embodiment, a target context object can be constructed based on target data corresponding to a preset data source, and the target context object is transmitted to a filtering node in the analysis link. The filtering node filters the target context object to obtain a filtered object. The data characteristics corresponding to the filtered object are determined, and the filtered object is sent to a target analysis node in the analysis link corresponding to the data characteristics. The target analysis node performs attack analysis on the filtered object to obtain corresponding attack analysis results. A secondary attack analysis is performed on the attack analysis results based on a preset analysis model, and the obtained target processing results are sent to an output node in the analysis link. The output node pushes the target processing results to a corresponding processing platform so that the processing platform can issue corresponding security alerts or push information based on the target processing results. Therefore, the method of this application can construct a target context object based on target data from a preset data source, transmit the target context object to a filtering node in the analysis chain for data filtering, and obtain a filtered object; determine the data characteristics of the filtered object, and send the filtered object to the target analysis node in the analysis chain corresponding to the data characteristics for attack analysis to obtain the attack analysis result; perform secondary attack analysis on the attack analysis result based on a preset analysis model, and push the obtained target processing result to the corresponding processing platform through the output node in the analysis chain, so that the processing platform can issue corresponding security alerts or push information based on the target processing result. In this way, end-to-end traffic control from data source to model call can be realized, ensuring that data from different types of processing nodes can be processed in a timely manner, and the continuity and integrity of data processing are guaranteed by the context passing mechanism, while the chained processing mechanism improves the efficiency and accuracy of data processing, and the intelligent filtering mechanism reduces the processing of invalid data and improves system efficiency.
[0059] See Figure 3 As shown, this embodiment of the invention discloses a security alarm device based on chain analysis, applied to a security alarm system, comprising:
[0060] Data filtering module 11 is used to construct a target context object based on the target data corresponding to a preset data source, and transmit the target context object to the filtering node in the analysis link, so as to filter the target context object through the filtering node to obtain the filtered object;
[0061] The first attack analysis module 12 is used to determine the data characteristics corresponding to the filtered object and send the filtered object to the target analysis node in the analysis link corresponding to the data characteristics, so as to perform attack analysis on the filtered object through the target analysis node to obtain the corresponding attack analysis results.
[0062] The second attack analysis module 13 is used to perform secondary attack analysis on the attack analysis results based on a preset analysis model, and send the obtained target processing results to the output node in the analysis link.
[0063] The security alarm module 14 is used to push the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alarms or push information based on the target processing result.
[0064] In this embodiment, a target context object can be constructed based on target data corresponding to a preset data source, and the target context object is transmitted to a filtering node in the analysis link. The filtering node filters the target context object to obtain a filtered object. The data characteristics corresponding to the filtered object are determined, and the filtered object is sent to a target analysis node in the analysis link corresponding to the data characteristics. The target analysis node performs attack analysis on the filtered object to obtain corresponding attack analysis results. A secondary attack analysis is performed on the attack analysis results based on a preset analysis model, and the obtained target processing results are sent to an output node in the analysis link. The output node pushes the target processing results to a corresponding processing platform so that the processing platform can issue corresponding security alerts or push information based on the target processing results. Therefore, the method of this application can construct a target context object based on target data from a preset data source, transmit the target context object to a filtering node in the analysis chain for data filtering, and obtain a filtered object; determine the data characteristics of the filtered object, and send the filtered object to the target analysis node in the analysis chain corresponding to the data characteristics for attack analysis to obtain the attack analysis result; perform secondary attack analysis on the attack analysis result based on a preset analysis model, and push the obtained target processing result to the corresponding processing platform through the output node in the analysis chain, so that the processing platform can issue corresponding security alerts or push information based on the target processing result. In this way, end-to-end traffic control from data source to model call can be realized, ensuring that data from different types of processing nodes can be processed in a timely manner, and the continuity and integrity of data processing are guaranteed by the context passing mechanism, while the chained processing mechanism improves the efficiency and accuracy of data processing, and the intelligent filtering mechanism reduces the processing of invalid data and improves system efficiency.
[0065] In some embodiments, the security alarm device based on chain analysis may further include:
[0066] The data slicing unit is used to slice the original data stream in the preset data source based on a preset time interval and a preset data threshold to obtain several discrete data segments.
[0067] The data preprocessing unit is used to perform data deduplication and standardization operations on the plurality of discrete data segments to obtain the target data.
[0068] In some embodiments, the data filtering module 11 may specifically include:
[0069] An object construction unit is used to determine the environmental information, historical state, associated data and configuration parameters of the target data corresponding to the preset data source, and to construct a target context object corresponding to the target data based on the environmental information, the historical state, the associated data, the configuration parameters and the target data.
[0070] The data filtering unit is used to transmit the target context object to the filtering node in the analysis link, so that the filtering node can remove the internal data in the target context object to obtain the filtered object; the internal data is the data generated by the security alarm system.
[0071] In some embodiments, the first attack analysis module 12 may specifically include:
[0072] The first data transmission unit is used to determine the data features corresponding to the filtered object and to determine the feature type of the data features, so as to send the filtered object to the target analysis node in the analysis link corresponding to the feature type based on the feature type;
[0073] The first attack analysis unit is used to perform attack analysis on the filtered object through the target analysis node. If the filtered object has an attack behavior corresponding to the feature type, a corresponding first attack analysis result is generated. If it is not determined whether there is an attack behavior corresponding to the feature type in the filtered object, a corresponding second attack analysis result is generated.
[0074] In some embodiments, the second attack analysis module 13 may specifically include:
[0075] The second data transmission unit is used to send the first attack analysis result as the target processing result to the output node in the analysis link if the attack analysis result is the first attack analysis result.
[0076] The second attack analysis unit is used to perform a second attack analysis on the second analysis result by means of a preset analysis model and a dedicated model analysis resource if the attack analysis result is the second attack analysis result, and to determine the attack intent of the target context object, so as to generate a target processing result according to the attack intent, and then send the target processing result to the output node in the analysis link; the dedicated model analysis resource is a pre-allocated model resource.
[0077] In some embodiments, the security alarm device based on chain analysis may further include:
[0078] The third attack analysis unit is used to perform a second attack analysis on the second analysis result by sharing the model analysis resources if the dedicated model analysis resources are exhausted and the target processing result is not obtained, so as to obtain the target processing result.
[0079] The analysis retry unit is used to retry the analysis based on the shared model analysis resources within a preset waiting time threshold if the shared model analysis resources are exhausted and the target processing result is not obtained. If the target processing result is not obtained, the target context object is discarded.
[0080] In some embodiments, the security alarm module 14 may specifically include:
[0081] A visualization unit is used to push the target processing result to the first processing platform through the output node, so that the first processing platform can visualize the target processing result.
[0082] A data storage unit is used to push the target processing result to the second processing platform through the output node, so that the second processing platform can save the target processing result to a preset database;
[0083] The security alarm unit is used to push the target processing result to the third processing platform through the output node, so that the third processing platform can issue a security alarm based on the target processing result.
[0084] Furthermore, embodiments of this application also disclose an electronic device, Figure 4 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0085] Figure 4 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the chain-analysis-based security alarm method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be a computer.
[0086] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0087] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0088] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the chain-analysis-based security alerting method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.
[0089] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned security alerting method based on chain analysis. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0090] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0091] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0092] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0093] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0094] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A security alerting method based on chain analysis, characterized in that, Applications in security alarm systems include: A target context object is constructed based on the target data corresponding to the preset data source, and the target context object is transmitted to the filtering node in the analysis link so that the target context object is filtered by the filtering node to obtain the filtered object. The data characteristics corresponding to the filtered object are determined, and the filtered object is sent to the target analysis node in the analysis link that corresponds to the data characteristics, so that the target analysis node can perform attack analysis on the filtered object to obtain the corresponding attack analysis results. The attack analysis results are subjected to secondary attack analysis based on the preset analysis model, and the obtained target processing results are sent to the output node in the analysis link. The target processing result is pushed to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alarms or push information based on the target processing result.
2. The security alarm method based on chain analysis according to claim 1, characterized in that, Before constructing a target context object based on target data corresponding to a preset data source, and transmitting the target context object to a filtering node in the analysis chain so as to filter the target context object through the filtering node to obtain the filtered object, the process further includes: The original data stream in the preset data source is sliced based on the preset time interval and preset data threshold to obtain several discrete data segments. The discrete data segments are deduplicated and standardized to obtain the target data.
3. The security alarm method based on chain analysis according to claim 1, characterized in that, The step of constructing a target context object based on target data corresponding to a preset data source and transmitting the target context object to a filtering node in the analysis chain, so as to filter the target context object through the filtering node to obtain a filtered object, includes: Determine the environmental information, historical status, associated data, and configuration parameters of the target data corresponding to the preset data source, and construct a target context object corresponding to the target data based on the environmental information, historical status, associated data, configuration parameters, and target data; The target context object is transmitted to a filtering node in the analysis link so that the filtering node can remove the internal data in the target context object to obtain a filtered object; the internal data is the data generated by the security alarm system.
4. The security alarm method based on chain analysis according to claim 1, characterized in that, The process of determining the data features corresponding to the filtered object and sending the filtered object to the target analysis node corresponding to the data features in the analysis chain, so as to perform attack analysis on the filtered object through the target analysis node to obtain the corresponding attack analysis results, includes: Determine the data features corresponding to the filtered object and determine the feature type of the data features, so as to send the filtered object to the target analysis node in the analysis link that corresponds to the feature type based on the feature type; The filtered object is subjected to attack analysis by the target analysis node. If the filtered object has an attack behavior corresponding to the feature type, a first attack analysis result is generated. If it is not determined whether there is an attack behavior corresponding to the feature type in the filtered object, a second attack analysis result is generated.
5. The security alarm method based on chain analysis according to claim 4, characterized in that, The process of performing secondary attack analysis on the attack analysis results based on a preset analysis model and sending the resulting target processing results to the output node in the analysis link includes: If the attack analysis result is the first attack analysis result, then the first attack analysis result is sent as the target processing result to the output node in the analysis link; If the attack analysis result is the second attack analysis result, then a second attack analysis is performed on the second analysis result using a preset analysis model and dedicated model analysis resources, and the attack intent of the target context object is determined. Based on the attack intent, a target processing result is generated, and then the target processing result is sent to the output node in the analysis link. The dedicated model analysis resources are pre-allocated model resources.
6. The security alarm method based on chain analysis according to claim 5, characterized in that, Before the step of pushing the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alerts or push information based on the target processing result, the method further includes: If the dedicated model analysis resources are exhausted and the target processing result is not obtained, then the second analysis result is subjected to a secondary attack analysis by sharing the model analysis resources in order to obtain the target processing result. If the shared model analysis resources are exhausted and the target processing result is not obtained, the analysis will be retried based on the shared model analysis resources within a preset waiting time threshold. If the target processing result is not obtained, the target context object will be discarded.
7. The security alarm method based on chain analysis according to any one of claims 1 to 6, characterized in that, The step of pushing the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alerts or push information based on the target processing result, includes: The target processing result is pushed to the first processing platform through the output node, so that the first processing platform can visualize the target processing result; The target processing result is pushed to the second processing platform through the output node, so that the second processing platform saves the target processing result to a preset database; The target processing result is pushed to the third processing platform through the output node, so that the third processing platform can issue a security alarm based on the target processing result.
8. A security alarm device based on chain analysis, characterized in that, Applications in security alarm systems include: The data filtering module is used to construct a target context object based on the target data corresponding to a preset data source, and transmit the target context object to the filtering node in the analysis link, so as to filter the target context object through the filtering node to obtain the filtered object; The first attack analysis module is used to determine the data characteristics corresponding to the filtered object and send the filtered object to the target analysis node in the analysis link that corresponds to the data characteristics, so as to perform attack analysis on the filtered object through the target analysis node and obtain the corresponding attack analysis results. The second attack analysis module is used to perform secondary attack analysis on the attack analysis results based on a preset analysis model, and send the obtained target processing results to the output node in the analysis link. The security alarm module is used to push the target processing result to the corresponding processing platform through the output node, so that the processing platform can issue corresponding security alarms or push information based on the target processing result.
9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the security alerting method based on chain analysis as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store computer programs, wherein the computer programs, when executed by a processor, implement the security alerting method based on chain analysis as described in any one of claims 1 to 7.
Citation Information
Patent Citations
WEB attack detection method, equipment, website application layer firewall and medium
CN113194058A
Police cloud security data fusion method, system and device and storage medium
CN115277177A
Network threat monitoring analysis method and system based on artificial intelligence
CN116846633A
Network security alarm method and device, electronic equipment and storage medium
CN120979765A
Method and system for backbone network flow anomaly detection
TW202017337A