Data alarm system, processing method, electronic device and storage medium

CN121984795BActive Publication Date: 2026-08-18BOE TECHNOLOGY GROUP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610458842.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-08
Publication Date
2026-08-18
Estimated Expiration
2046-04-08

AI Technical Summary

Technical Problem

[0004]然而,现有技术在多源威胁情报融合与冗余告警削减方面仍存在局限,关键威胁情报容易被重复告警淹没或被误聚合抑制,并且告警聚合与处置资源分配无法随威胁形态与处置压力自适应调整,进而会引发告警信噪比失衡、响应滞后和研判负担增加等问题,影响安全运营效率与防护精准性

Benefits of technology

本申请实施例提供的数据告警系统中,模式识别模块用于根据不同来源的告警信息生成具备时空关联关系的动态情报序列,并基于所述动态情报序列的动态关联度序列,识别当前攻击的主导交互模式。阻塞概率确定模块用于基于所述动态情报序列确定告警关联链路,并根据所述告警关联链路中相邻情报帧之间的信息连贯性以及所述主导交互模式的变化频率,确定局部信息阻塞概率。补偿因子确定模块用于基于告警事件处置回执中的告警处置通道信息以及基于网络交互特征,生成补偿因子。调配处理模块用于在每一预设调配周期内,根据所述补偿因子调整所述告警处置通道的资源配额和告警聚合判定阈值。基于此,可以构建多源威胁数据采集、关联链路阻塞评估和资源配额及聚合规则闭环优化的调节机制,使得处置通道的资源配置和对应的告警聚合规则能够随威胁形态和处置压力自适应调整,从而可以避免关键威胁情报被重复告警淹没或被误聚合抑制。可以实现网络威胁情报在多源异构条件下的高关联性融合以及冗余告警的自适应削减,在不丢失关键告警信息的前提下,提升告警信噪比与处置吞吐能力,降低误抑制与漏检风险,缩短关键威胁的平均响应时间,有利于提高安全运营效率与防护精准性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121984795B_ABST
    Figure CN121984795B_ABST
Patent Text Reader

Abstract

The embodiment of the specification provides a data alarm system, a processing method, electronic equipment and a storage medium, and relates to the technical field of network security data processing. The system comprises: a pattern recognition module, configured to generate dynamic intelligence sequences with a space-time correlation relationship according to alarm information of different sources, and recognize a dominant interaction mode of a current attack; a blocking probability determination module, configured to determine an alarm correlation link, and determine a local information blocking probability according to information continuity between adjacent intelligence frames in the alarm correlation link and a change frequency of the dominant interaction mode; a compensation factor determination module, configured to generate a compensation factor based on alarm handling channel information and based on network interaction characteristics; and a deployment processing module, configured to adjust a resource quota of an alarm handling channel and an alarm aggregation determination threshold according to the compensation factor in each preset deployment period. Based on this, adaptive reduction of redundant alarms can be realized, and security operation efficiency and protection accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of network security data processing technology, and in particular to a data alarm system, processing method, electronic device and storage medium. Background Technology

[0002] In the field of cybersecurity operations, the collection, correlation, and alert handling of cyber threat intelligence have become routine tasks for enterprises and critical infrastructure. Typically, security operations centers need to simultaneously access data from multiple sources, including intrusion detection devices, endpoint detection and response systems, perimeter protection devices, domain name resolution, proxy access, and security orchestration platforms, to support continuous monitoring and rapid response to attacks such as intrusions, external downloads, brute-force attacks, and lateral movement.

[0003] Related technologies typically revolve around rule-based matching and single-source feature filtering and aggregation for alarm management. They mitigate alarm flooding and avoid redundancy by using alarm deduplication, alarm tiering, or fixed-window merging methods. The technical implementation involves the processing of digital data from multi-source logs and alarm events, as well as correlation analysis of security events.

[0004] However, existing technologies still have limitations in multi-source threat intelligence fusion and redundant alarm reduction. Critical threat intelligence is easily overwhelmed by duplicate alarms or suppressed by mis-aggregation. Furthermore, alarm aggregation and resource allocation for handling cannot be adaptively adjusted according to threat patterns and handling pressures, which can lead to problems such as alarm signal-to-noise ratio imbalance, response delays, and increased analysis burden, affecting security operation efficiency and protection accuracy. Summary of the Invention

[0005] To overcome the problems existing in related technologies and improve the efficiency and accuracy of safe operation, this specification provides a data alarm system, processing method, electronic device and storage medium.

[0006] According to a first aspect of the embodiments of this application, a data alarm system is provided, comprising: The pattern recognition module is used to generate dynamic intelligence sequences with spatiotemporal correlation based on alarm information from different sources, and to identify the dominant interaction pattern of the current attack based on the dynamic correlation sequence of the dynamic intelligence sequences. The blocking probability determination module is used to determine the alarm association link based on the dynamic intelligence sequence, and to determine the local information blocking probability based on the information coherence between adjacent intelligence frames in the alarm association link and the change frequency of the dominant interaction mode. The compensation factor determination module is used to generate compensation factors based on alarm handling channel information in alarm event handling receipts and network interaction characteristics. The allocation processing module is used to adjust the resource quota and alarm aggregation judgment threshold of the alarm handling channel according to the compensation factor within each preset allocation cycle.

[0007] In some possible implementations, the dynamic intelligence sequence includes multiple intelligence frames arranged in chronological order, each intelligence frame including a structured alarm event in the same time slice and the context associated with the alarm event; The system also includes a data preprocessing module, which is used to acquire the alarm events and the context based on different observation sources, and merge the alarm events and the context of the same time slice to form the intelligence frame.

[0008] In some possible implementations, the pattern recognition module is further configured to determine the dynamic correlation sequence, specifically for: The association level is determined by candidate pairings based on the alarm events of the current intelligence frame and the context of adjacent intelligence frames; The association levels corresponding to multiple intelligence frames are arranged in chronological order to determine the dynamic association degree sequence.

[0009] In some possible implementations, the candidate pairing includes the event feature vector corresponding to the alarm event and the context semantic embedding vector corresponding to the context; The pattern recognition module is also used for: Based on preset structured rules, the event feature vector corresponding to the alarm event is obtained; Based on a preset semantic encoding model, obtain the context semantic embedding vector corresponding to the context.

[0010] In some possible implementations, the pattern recognition module, when used to determine the association level, is specifically used for: Based on the source entity identifier, destination entity identifier, and key object entity identifier, the candidate pairings are judged for entity consistency. If the entity consistency determination result meets the first preset condition, the candidate pairing is semantically consistent based on entity semantic similarity. If the semantic consistency determination result meets the second preset condition, the candidate pairing is determined by temporal proximity. The association level is determined based on the entity consistency determination result, the semantic consistency determination result, and the temporal proximity determination result.

[0011] In some possible implementations, the pattern recognition module, when used to identify the dominant interaction pattern of the current attack, is specifically used for: Based on the intelligence frames within the time range corresponding to the first preset sliding time window, a transfer sequence for the corresponding association level is determined. The transfer sequence is used to indicate the change in the association level of adjacent intelligence frames. Based on the transition sequence, multiple corresponding interaction modes are determined by querying a preset pattern dictionary; The dominant interaction mode is determined based on the frequency of occurrence and continuous duration of the multiple interaction modes.

[0012] In some possible implementations, the blocking probability determination module is further configured to detect the information coherence between adjacent intelligence frames in the alarm association link, specifically for: Based on the source entity identifier, destination entity identifier, and key object entity identifier corresponding to adjacent intelligence frames, entity continuity detection is performed on adjacent intelligence frames. Based on the attack phase markers corresponding to adjacent intelligence frames, the attack phase consistency of adjacent intelligence frames is checked by querying a preset attack phase progression rule table. By querying a pre-defined semantic embedding similarity interval mapping table, semantic drift detection is performed on the context of adjacent intelligence frames.

[0013] In some possible implementations, the system further includes an alarm efficiency determination module for determining intent response sparse regions based on the network interaction characteristics; The compensation factor determination module is further configured to generate a corresponding compensation factor based on the combination relationship between the response sparsity region and the processing channel.

[0014] In some possible implementations, the alarm efficiency determination module, when used to determine the sparse region of intent response, is specifically used for: An interaction graph is constructed based on the aforementioned network interaction features; Based on the preset security domain configuration table, network address planning table, and business asset grouping table, the interaction graph is divided into multiple partitions; The interaction frequency of each partition is determined based on the window length parameter and step parameter of the second preset sliding time window; the interaction frequency includes the increment of the number of edges within the partition, the number of times the cross-partition edge is triggered, and the number of times the path is traversed; Based on the preset threshold configuration, determine whether the partition is an intention response sparse region.

[0015] In some possible implementations, the alarm efficiency determination module is further used for: Based on the window length parameter and step parameter of the second preset sliding time window, the alarm repetition triggering characteristics of each partition are determined; the alarm repetition triggering characteristics include repetition triggering density, repetition triggering duration and the number of assets covered by repetition triggering; Based on a preset fluctuation range mapping table, the corresponding alarm efficiency fluctuation coefficient is determined according to the alarm repetitive triggering characteristics and the dynamic correlation sequence of the corresponding time. The compensation factor determination module is further configured to determine the compensation factor based on the alarm efficiency fluctuation coefficient.

[0016] In some possible implementations, the compensation factor determination module, when used to generate the compensation factor, is specifically used for: Based on the alarm event handling receipt, a response delay sample table is constructed with the combination of the intent response sparse region and the handling channel as the index key; Based on the response delay sample, the predicted response delay level and delay sensitivity level corresponding to the index key are determined by querying the preset response delay level range table and sensitivity level range table mapping. Based on the alarm efficiency fluctuation coefficient, the predicted response delay level, and the delay sensitivity level, the compensation factor corresponding to the index key is determined by querying a preset adjustment rule table. Each rule in the adjustment rule table includes the scope of application for sparse area identifiers and the scope of application for disposal channel identifiers.

[0017] In some possible implementations, the dispensing processing module is further configured to: Based on the compensation factor, adjust the resource quota parameters and aggregation threshold parameters corresponding to the alarm handling channel; Within each preset allocation cycle, the dynamic correlation sequence and the local information blocking probability are re-determined based on the adjusted parameters; If the dynamic correlation sequence indicates that the dynamic correlation of the intelligence frame sequence remains valid within the current allocation cycle, and the local information blocking probability is within a preset controlled range, the current parameter is archived as an effective configuration and enters the next allocation cycle; otherwise, the current parameter is rolled back until the parameter is archived as an effective configuration.

[0018] In some possible implementations, the dynamic correlation sequence includes multiple dynamic correlation validity markers arranged in chronological order; The dynamic correlation degree remains effective, including: within the current allocation cycle, the proportion of the dynamic correlation degree marked as effective is greater than or equal to a preset proportion threshold.

[0019] In some possible implementations, the aggregation threshold parameter includes a time window threshold parameter and a suppression threshold parameter; When the allocation processing module is used to roll back the current parameters, it is specifically used for: According to the preset rollback rules, and in accordance with the preset single-cycle adjustment step size upper limit, the time window threshold parameter and the suppression threshold parameter are adjusted from the current value to the value of the previous adjustment cycle.

[0020] According to a second aspect of the embodiments of this application, a data alarm processing method is also provided, comprising: Based on alarm information from different sources, a dynamic intelligence sequence with spatiotemporal correlation is generated, and based on the dynamic correlation sequence of the dynamic intelligence sequence, the dominant interaction mode of the current attack is identified. Based on the dynamic intelligence sequence, an alarm association link is determined, and based on the information coherence between adjacent intelligence frames in the alarm association link and the change frequency of the dominant interaction mode, the probability of local information blocking is determined. Compensation factors are generated based on alarm handling channel information in alarm event handling receipts and network interaction characteristics. Within each preset allocation cycle, the resource quota and alarm aggregation judgment threshold of the alarm handling channel are adjusted according to the compensation factor.

[0021] According to a third aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods described in the above embodiments.

[0022] According to a fourth aspect of the embodiments of this application, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the methods described in the above embodiments.

[0023] According to a fifth aspect of the embodiments of this application, a computer-readable storage medium is also provided, on which a computer program is stored, wherein the program, when executed by a processor, implements the methods described in the above embodiments.

[0024] The technical solutions provided by the embodiments of this application may include the following beneficial effects: In the data alarm system provided in this application embodiment, a pattern recognition module generates a dynamic intelligence sequence with spatiotemporal correlation based on alarm information from different sources, and identifies the dominant interaction pattern of the current attack based on the dynamic correlation sequence of the dynamic intelligence sequence. A blocking probability determination module determines alarm association links based on the dynamic intelligence sequence, and determines the local information blocking probability based on the information coherence between adjacent intelligence frames in the alarm association links and the frequency of change of the dominant interaction pattern. A compensation factor determination module generates a compensation factor based on alarm handling channel information in the alarm event handling receipt and based on network interaction characteristics. A allocation processing module adjusts the resource quota and alarm aggregation judgment threshold of the alarm handling channel according to the compensation factor within each preset allocation cycle. Based on this, a closed-loop optimization mechanism for multi-source threat data collection, association link blocking assessment, and resource quota and aggregation rule optimization can be constructed, enabling the resource configuration of the handling channel and the corresponding alarm aggregation rules to adaptively adjust with the threat form and handling pressure, thereby preventing critical threat intelligence from being overwhelmed by repeated alarms or suppressed by false aggregation. It can achieve highly correlated fusion of network threat intelligence under multi-source heterogeneous conditions and adaptive reduction of redundant alarms. Without losing key alarm information, it can improve the alarm signal-to-noise ratio and processing throughput, reduce the risk of false suppression and missed detection, shorten the average response time of key threats, and help improve security operation efficiency and protection accuracy.

[0025] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0026] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0027] Figure 1 This is a schematic diagram of the structure of a data alarm system provided in an embodiment of this application; Figure 2 This is a schematic diagram of another data alarm system provided in an embodiment of this application; Figure 3 This is a flowchart illustrating the steps for identifying a dominant interaction mode according to an embodiment of this application; Figure 4 This is a schematic diagram of the structure of another data alarm system provided in the embodiments of this application; Figure 5 This is a schematic diagram of an interaction graph topology provided in an embodiment of this application; Figure 6 This is a flowchart of a data block encryption management method provided in an embodiment of this application; Figure 7This is a flowchart of another data alarm processing method provided in the embodiments of this application; Figure 8 This is a hardware schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0028] In the field of cybersecurity operations, it is often necessary to fuse multi-source threat intelligence and reduce redundant alerts to avoid alert flooding. However, alert events and contextual information from different sources vary in timestamp caliber, field specifications, and data quality, and the acquisition time can be out of order and delayed. This causes the same attack chain to be broken into fragmented events, making it difficult to form a traceable link under a unified spatiotemporal benchmark. Consequently, critical threats are easily overwhelmed by duplicate alerts or suppressed by mis-aggregation. On the other hand, redundant alert reduction relies heavily on rules and experience, lacking a dynamic allocation mechanism that combines semantic correlation, attack stage progression, and response delays in the handling channel. This results in alert aggregation and handling resource allocation failing to adapt to threat forms and handling pressures, leading to problems such as an imbalance in the alert signal-to-noise ratio, delayed response, and increased analysis burden, affecting security operation efficiency and protection accuracy.

[0029] In view of this, embodiments of this application provide a data alarm system. For example... Figure 1 As shown, Figure 1 This is a schematic diagram of the structure of a data alarm system provided in an embodiment of this application.

[0030] The data alarm system includes a pattern recognition module 10, a blocking probability determination module 20, a compensation factor determination module 30, and a scheduling and processing module 40.

[0031] The pattern recognition module 10 is used to generate a dynamic intelligence sequence with spatiotemporal correlation based on alarm information from different sources, and to identify the dominant interaction mode of the current attack based on the dynamic correlation sequence of the dynamic intelligence sequence.

[0032] The source here refers to the data observation source, such as intrusion detection equipment, endpoint detection and response, perimeter protection equipment, domain name resolution, proxy access and security orchestration platforms, etc. The alarm information includes the identification information corresponding to the observation source. The dynamic intelligence sequence is a collection of alarm information arranged in chronological order; that is, the dynamic intelligence sequence includes the temporal and spatial relationships of the alarm information.

[0033] Dynamic correlation is a metric used to measure the strength of the correlation between two or more threat event records. It reflects the likelihood of association between different alert messages in an attack behavior chain, indicating whether two alert events belong to the same attack behavior chain. A dynamic correlation sequence is a record of the correlation changes of alert messages over time, used to indicate the correlation between adjacent alert messages.

[0034] The dominant interaction pattern refers to the main activity mode of attack behavior in the network. It is used to describe the dominant structural characteristics of various network interaction behaviors of attackers during the attack process and to reflect the behavioral stage or attack strategy type of the attack activity.

[0035] For example, the dominant interaction mode can be one of the following: scanning and probing mode, credential abuse mode, privilege escalation mode, lateral movement mode, or data transfer mode. Specifically, the scanning and probing mode is characterized by a single source entity initiating probing requests to multiple target entities within a short period, with the corresponding dynamic correlation exhibiting low intensity but high frequency. The credential abuse mode is characterized by multiple identity authentication-related alerts appearing consecutively within a short period. The privilege escalation mode is characterized by the same asset or account undergoing permission changes, sensitive operations, or system control behaviors in consecutive events. The lateral movement mode is characterized by the same attacking entity establishing connections between multiple assets, with the corresponding dynamic correlation continuously increasing in consecutive events. The data transfer mode is characterized by continuous data transfer behavior from internal assets to external entities.

[0036] The blocking probability determination module 20 is used to determine the alarm association link based on the dynamic intelligence sequence, and to determine the local information blocking probability according to the information coherence between adjacent intelligence frames in the alarm association link and the change frequency of the dominant interaction mode.

[0037] The alarm association link here refers to the link structure formed by strongly correlated subsequences of intelligence frames selected from a dynamic intelligence sequence, used to reflect the propagation path of the same attack behavior over time. For example, a dynamic intelligence sequence may contain multiple intelligence frames arranged in chronological order, with alarm information corresponding to different intelligence frames coming from different assets and different attack events. The alarm association link includes a portion selected from these frames that meet the correlation conditions in terms of entity, semantics, and time. These intelligence frames are smoothly connected in time to form an attack behavior chain, which is the alarm association link.

[0038] Local information congestion probability describes the degree of obstruction in information transmission within the alarm association chain. The causes of this obstruction typically include an excessive number of alarm events, frequent recurrence of triggers, and insufficient processing capacity of the handling channel. In other words, local information congestion probability can, to some extent, indicate whether the resource quota of the handling channel is sufficient and whether the alarm aggregation rules are appropriate.

[0039] The compensation factor determination module 30 is used to generate compensation factors based on the alarm handling channel information in the alarm event handling receipt and based on network interaction characteristics.

[0040] A response receipt is a record of the processing results returned by the security handling system after responding to and handling the security risks triggered by an alarm, that is, after performing alarm handling operations. It is used to describe whether the handling action was successful and the execution time, etc.

[0041] Common alarm handling operations include account control (e.g., freezing abnormal accounts, resetting passwords, or forcing re-authentication), network connection control (e.g., blocking abnormal connections, banning external IP addresses, or closing abnormal ports), terminal isolation (e.g., isolating infected terminals from the network or restricting their access permissions), process handling (e.g., terminating malicious processes or preventing the execution of malicious scripts), and alarm merging or closure, such as merging or closing repeatedly triggered alarms.

[0042] Handling receipts are typically stored in the form of structured records. For example, a handling receipt usually includes the following fields: event identifier, which indicates the corresponding alarm event number; handling operation type, which indicates the handling action performed, such as account freezing, connection blocking, or terminal isolation; handling start time, which is the time when the handling operation begins; handling completion time, which is the time when the handling operation ends; handling result status, which indicates whether the handling was successful, such as success or failure; and handling execution node, which indicates the system or device node that performed the handling operation.

[0043] For example, a certain handling receipt record can be represented as follows: the event identifier is ALERT-10234, the handling operation type is blocking external connection, the handling start time is 2025-06-15 10:25:03, the handling completion time is 2025-06-15 10:25:07, the handling result status is successful, and the handling execution node is firewall node FW-01.

[0044] Network interaction characteristics can be determined based on network topology spatial interaction data and are used to describe the interaction structure between assets.

[0045] In this embodiment, the compensation factor generated based on alarm handling channel information and network interaction characteristics is essentially a compensation adjustment amount generated to address differences in alarm handling efficiency, used to adjust the performance deviation of the corresponding alarm handling channel.

[0046] The allocation processing module 40 is used to adjust the resource quota and alarm aggregation judgment threshold of the alarm handling channel according to the compensation factor within each preset allocation cycle.

[0047] Resource quotas limit the number of alarms that the alarm handling channel can process per unit of time. For example, resource quotas include concurrent processing limits, task queue capacity, and computing resource allocation ratios. When resource quotas are increased, the handling channel can process more alarm events simultaneously, thereby reducing the waiting time of alarm events in the chain and lowering the probability of information blockage.

[0048] Alarm aggregation decision thresholds are used to control the merging and suppression rules of alarm events before they enter the processing channel; in other words, they are used to adjust the alarm event aggregation rules of the alarm aggregation engine. For example, alarm aggregation decision thresholds include similarity thresholds, time window thresholds, and repetitive trigger suppression thresholds. When the alarm aggregation decision threshold is increased, repetitive or similar alarm events will be merged into fewer alarm records, thereby reducing the number of events entering the processing channel and thus reducing the probability of information blockage.

[0049] That is, in this embodiment of the application, according to the adjustment information corresponding to the compensation factor, the allocation processing module 40 adjusts the alarm processing load from two aspects: improving processing capacity and reducing input scale, so as to dynamically adjust the probability of local information blocking.

[0050] As can be seen, the embodiments of this application construct an adjustment mechanism that includes multi-source threat data collection, associated link blockage assessment, and closed-loop optimization of resource quotas and aggregation rules. This enables the resource configuration of the handling channel and the corresponding alarm aggregation rules to be adaptively adjusted according to the threat form and handling pressure, thereby avoiding critical threat intelligence from being overwhelmed by repeated alarms or suppressed by false aggregation.

[0051] In other words, the data alarm system in this application embodiment can achieve highly correlated fusion of network threat intelligence under multi-source heterogeneous conditions and adaptive reduction of redundant alarms. Without losing key alarm information, it can improve the alarm signal-to-noise ratio and processing throughput, reduce the risk of false suppression and missed detection, shorten the average response time of key threats, and help improve security operation efficiency and protection accuracy.

[0052] In some possible implementations, the dynamic intelligence sequence includes multiple intelligence frames arranged in chronological order, each intelligence frame including a structured alarm event in the same time slice and the context associated with the alarm event.

[0053] Structured alarm events refer to data records generated by security devices or security analysis systems, possessing a fixed field structure, and capable of being directly parsed by programs. Structured alarm events typically exist in the form of key-value pairs, log field sets, or tables. Their data structure is predefined in the device or system rule base, and can be represented, for example, as a data table record containing multiple fields or a standardized log record.

[0054] Structured alarm events can originate from alarm logs generated by intrusion detection devices, endpoint detection and response systems, perimeter protection devices, or security orchestration platforms. For example, a structured alarm record can be represented by the following set of fields: event timestamp is 2025-05-12 10:32:15, observation source identifier is IDS-01, asset identifier is HOST-A102, source entity identifier is 192.168.10.25, destination entity identifier is 10.10.2.15, protocol port information is TCP-445, alarm type is abnormal login attempt, severity level is high, attack stage is credential abuse stage, and object entity identifier is domain account ADMIN-01.

[0055] Context (i.e., unstructured attack context) refers to textual or semi-structured security records associated with structured alert events but lacking a fixed field structure. Its content typically originates from security device log text, attack behavior descriptions, terminal command records, action ticket records, or threat intelligence descriptions. This type of data usually exists in the form of natural language text, command line snippets, or log fragments. While it can reflect detailed information about attack behavior, its field structure is not pre-fixed, thus requiring parsing through entity extraction and behavior recognition.

[0056] For example, in a security operations scenario, an unstructured attack context record can be a work order record text in a security orchestration and handling platform, such as: "Host-A102 was detected continuously making abnormal connections to the external address 10.10.2.15, suspected of lateral movement behavior." It can also be a command-line log fragment output by the endpoint detection and response system, such as: "powershell.exe -enaW52b2tlLWRvd25sb2FkZXI," used to describe the endpoint executing suspicious script download behavior.

[0057] In this application's embodiments, the context refers to security data derived from security log text, attack behavior descriptions, or handling records, excluding human-computer interaction data from ordinary users, such as voice input, mouse operation trajectories, or keyboard keystroke records. Unless human-computer interaction data is recorded by the security system as an attack behavior log or audit log and used as evidence of a security incident, it is not included in the processing scope of the unstructured attack context described in this application.

[0058] To merge multi-source alarm events with context and prevent the same attack chain from being split into fragmented events, the system also includes a data preprocessing module 50.

[0059] For example, Figure 2This is a schematic diagram of another data alarm system provided in this application embodiment. The data preprocessing module 50 is used to acquire the alarm event and the context based on different observation sources, and merge the alarm event and the context of the same time slice to form the intelligence frame.

[0060] As mentioned above, structured alert events are alert records with fixed fields, such as event timestamp, observation source identifier, asset identifier, session identifier, alert type, severity level, attack stage, and object entity. Context (i.e., unstructured attack context) is a textual or semi-structured record; for example, the context may contain attack description fragments, command line fragments, domain name or file hash fragments, ticket record fragments, and handling instructions fragments.

[0061] The data preprocessing module 50 can perform a unified extraction operation on each acquired input record, such as extracting fields like event timestamp, observation source identifier, asset identifier, and session identifier. The event timestamp is taken from the occurrence time field in the alarm record or the observation time field in the log record. The observation source identifier is generated by the security data acquisition bus based on the data source access point and remains globally unique. This observation source identifier corresponds to the data source type or source entity of the alarm information, such as intrusion detection devices, endpoint detection and response systems, perimeter protection devices, domain name resolution log systems, proxy access systems, and security orchestration and handling platforms. The asset identifier is determined by a unique asset number provided by the asset management database. When the input record only contains a hostname, terminal identifier, or address identifier, it can be mapped to a unique asset number according to a pre-configured asset mapping table. The session identifier can be generated by session resolution rules. The session resolution rules construct a session key based on the connection tuple and process identifier. When the input source does not provide a connection tuple, the time-adjacent event cluster identifier under the same asset identifier can be used as the session identifier.

[0062] To avoid correlation deviations caused by time drift, the data preprocessing module 50 can also maintain time drift correction parameters for each observation source identifier using a unified time reference clock as the global alignment reference. For example, the unified time reference clock is provided by a trusted time source and periodically calibrated at the access node. The time drift correction parameters include a time offset parameter and a drift rate parameter. These parameters can be determined by statistically analyzing the historical time synchronization records and arrival time differences for each observation source identifier. The event timestamps of the input records are corrected for drift using a preset time drift correction period as the update period, and the corrected timestamps are used as the alignment timestamps.

[0063] After time alignment, multiple input records arriving within the same aligned timestamp neighborhood are arranged according to the ascending order of the aligned timestamps. If the aligned timestamps are the same, they are sorted by the order of arrival.

[0064] Input records within the same time slice are merged to form an intelligence frame corresponding to that time slice. The time slice is determined by a time slice start time parameter and a time slice length parameter; the time slice length parameter can be a pre-configured fixed value.

[0065] The data preprocessing module 50 can also assign a corresponding intelligence frame identifier to each intelligence frame in each time slice. The intelligence frame identifier includes the observation source identifier, the time slice start time parameter, and the time slice length parameter, and the intelligence frame identifier corresponding to each intelligence frame is unique.

[0066] It is understood that an intelligence frame can include multiple alarm events from different observation sources, as well as multiple contexts associated with these alarm events. In this embodiment, using the intelligence frame identifier as an index, multiple structured alarm events and unstructured attack contexts with different observation source identifiers, the same asset identifier, and the same session identifier within the same time slice are bound to the same intelligence frame. That is, the aligned timestamps of multiple alarm events all fall within the time slice range corresponding to the intelligence frame. The sequence of multiple intelligence frames arranged chronologically is the dynamic intelligence sequence.

[0067] In addition, in order to address the significant differences in field specifications and data quality between multi-source alarms and contexts in related technologies, in this embodiment, the data preprocessing module 50 can also perform unified processing of structured alarm field standards for structured alarm events, perform structured organization of unstructured attack contexts, and generate quality labels for each intelligence frame.

[0068] Among them, the unified processing of structured alarm field definitions for structured alarm events can be accomplished based on a pre-configured field mapping table.

[0069] The field mapping table provides a mapping relationship for alarm types, severity levels, attack stages, and object entities under different rule systems and provides a unified set of fields. The unified set of fields may include alarm type flag field, severity level flag field, attack stage flag field, object entity identifier field, source entity identifier field, destination entity identifier field, protocol type field, and port field.

[0070] For example, the field mapping table includes alarm type mapping items, severity level mapping items, attack stage mapping items, and object entity resolution items, which are used to determine the alarm type flag field, severity level flag field, attack stage flag field, and object entity identifier field, respectively. The object entity identifier field records a unified identifier for objects such as domain names, addresses, accounts, processes, or files related to the alarm. When the original data source corresponding to the alarm event does not provide the relevant field content, it can be determined based on network traffic probe records or access path records, and the relevant field content is written into the intelligence frame metadata.

[0071] The unstructured attack context is structured and organized, including three types of operations: entity extraction, behavior extraction, and evidence extraction.

[0072] For example, entity extraction can identify information such as asset names, account names, domain names, addresses, file hashes, and process names from text based on an entity dictionary and entity pattern rules, forming a contextual entity item set. Behavior item extraction can identify behaviors such as scanning, login, downloading, execution, privilege escalation, and lateral movement based on a behavior pattern library, forming a contextual behavior item set. Evidence item extraction can identify command line fragments, network request fragments, alarm rule hit fragments, and handling record fragments based on evidence type rules, forming a contextual evidence item set. The contextual entity item set, contextual behavior item set, and contextual evidence item set are then written into a contextual field set, and the contextual field set is bound to the corresponding intelligence frame identifier.

[0073] Based on this, it is possible to perform retrieval, association, and review operations on structured alarm events and unstructured attack contexts under the same unified field definition.

[0074] For each intelligence frame, quality labels are generated, including source credibility labeling, integrity labeling, and timeliness labeling. The generated quality labels are used to describe the usability of the data records in subsequent correlation analysis, so as to identify, filter, or downweight anomalous data when generating dynamic intelligence sequences.

[0075] Based on the access authentication status, data signature verification results, and historical false alarm rate statistics of the observation source identifier, the source trust label can be determined. The access authentication status is determined by the authentication result of the access link; the data signature verification result is determined by the signature verification module verifying the signature field of structured alarm events or log messages; and the historical false alarm rate statistics are calculated by the number of false alarms and the total number of alarms for that observation source identifier within a pre-configured statistical period. Here, the historical false alarm rate refers to the discrete trust level mapped from the calculation results.

[0076] Integrity labeling can be determined based on the number and proportion of missing key fields in a unified field set. The number of missing key fields is determined by a field-by-field check by the missing field detection module, and the missing proportion refers to the discrete integrity level mapped from the ratio of the number of missing key fields to the total number of key fields.

[0077] The timeliness rating can be determined based on the acquisition delay and time slice alignment error. The acquisition delay is the time difference between the acquisition arrival time and the alignment timestamp, and the time slice alignment error is the discrete timeliness level mapped from the difference between the alignment timestamp and the time slice start time parameter.

[0078] For example, in some possible implementations, the system has preset data quality rules, which include at least time consistency detection rules, field integrity detection rules, duplicate record detection rules, and source credibility assessment rules. The time consistency detection rules determine whether the deviation between the event timestamp and the collection time exceeds a preset time offset threshold. The field integrity detection rules detect whether key fields (such as asset identifiers, source entity identifiers, or alarm type fields) are missing. The duplicate record detection rules identify alarm records with completely identical field content within a preset time window. The source credibility assessment rules generate a source credibility identifier based on the data source device type or data interface credibility level.

[0079] After performing timestamp alignment, field normalization, and data quality labeling, the data preprocessing module 50 can also create indexes for dynamic intelligence sequences. For example, the indexes include indexes by asset identifier, by session identifier, and by observation source identifier, thereby enabling the rapid identification of required information during subsequent analysis and processing based on dynamic intelligence sequences.

[0080] In some possible implementations, the pattern recognition module 10 is also used to determine the dynamic correlation sequence, and then identify the dominant interaction pattern based on the dynamic correlation sequence.

[0081] For example, the pattern recognition module 10 first obtains the event feature vector corresponding to the alarm event based on preset structured rules. Then, based on a preset semantic encoding model, it obtains the context semantic embedding vector corresponding to the context.

[0082] The event feature vector can be obtained through the following steps.

[0083] For the dynamic intelligence sequence, the pattern recognition module 10 sequentially reads the corresponding structured alarm fields according to the intelligence frame identifier. Then, according to the pre-configured unified fields, it sequentially generates an event feature vector from the read structured alarm fields.

[0084] For example, the unified fields can be configured to include alarm type flags, rule trigger identifiers, source entities, destination entities, protocol port information, attack phase flags, and asset importance flags, with the order of these information being fixed. Specifically, the alarm type flag is determined by mapping alarm types in the unified field set to discrete codes using an alarm type encoding table; the rule trigger identifier is determined by mapping rule identifiers to discrete codes using a rule trigger encoding table; and the source and destination entities are resolved to unified entity identifiers by entity normalization rules, resolving addresses, accounts, processes, or domain names to their respective locations. Protocol port information is determined by encoding the protocol type field and port field according to pre-configured port encoding rules. The attack phase flag is determined by mapping the attack phase field to discrete codes using an attack phase encoding table. The asset importance flag is determined by mapping the asset classification field corresponding to the asset identifier in the asset management database. The dimensions of the event feature vector, the value range of each field, and the version number of each encoding table are all fixed as configuration parameters in the configuration and written to the intelligence frame metadata along with the intelligence frame identifier to ensure consistency in subsequent traceability.

[0085] The context semantic embedding vector can be obtained in the following way.

[0086] The semantic encoding model includes a word segmentation and embedding module, which performs word segmentation based on a pre-defined dictionary and rule-based joint segmentation strategy to obtain a set of context entity items and a set of context behavior items from the context field set. The entity tagging module of the semantic encoding model determines the corresponding entity identifiers and behavior tags based on the context entity item set and the context behavior item set. Based on pre-configured sequence organization rules, the semantic encoding model encodes the context entity item set and the context behavior item set into a semantic representation sequence. This semantic representation sequence consists of entity type tags, entity identifiers, behavior tags, and evidence fragment tags concatenated in a fixed order. Pre-configured separator tags can be inserted between different types of fragments to maintain clear boundaries. The encoder module of the semantic encoding model includes a multi-layer stacked structure, with the corresponding number of layers remaining constant. This multi-layer stacked structure is used to encode the semantic representation sequence. The vector output module of the semantic encoding model includes an embedding dimension parameter, used to aggregate the encoding results into a fixed-length context semantic embedding vector.

[0087] Those skilled in the art should understand that, in the embodiments of this application, an entity refers to an object unit that has a stable identifier in the network environment and is able to participate in network interaction activities, and behavior refers to the specific operation or interaction action performed by the entity in the network environment.

[0088] In some possible implementations, the semantic encoding model is trained offline using training corpus consisting of historical threat intelligence text and handling work order text before deployment. The training objective is to output more closely related embedding vectors for context fragments within the same alarm association link and more distant embedding vectors for fragments in different links. After training, the model version number is fixed.

[0089] In some possible implementations, the context semantic embedding vector, semantic encoding model version number, and embedding dimension parameters corresponding to each context are also written into the intelligence frame metadata to ensure that the semantic representation of the same intelligence frame is consistent in different running cycles.

[0090] In some possible implementations, after obtaining the event feature vector and context semantic embedding vector corresponding to each intelligence frame, the event feature vector of the current intelligence frame and the context semantic embedding vector of the adjacent intelligence frames can be used to form a candidate pair. In a candidate pair, the corresponding alarm event and context have the same asset identifier, and the intelligence frame identifiers are adjacent in the dynamic intelligence sequence.

[0091] In a dynamic intelligence sequence, adjacent intelligence frames are identified when the alarm event and its context originate from two consecutive intelligence frames in chronological order. For example, the system merges intelligence frames according to fixed time slices. When the time slice sequence is T1, T2, T3, the corresponding intelligence frames are F1, F2, F3. That is, intelligence frames F1 and F2, and F2 and F3 are adjacent intelligence frames. When constructing candidate pairings, only event feature vectors from adjacent intelligence frames are allowed to be paired with context semantic embedding vectors. Based on this, the temporal continuity of the associated data can be guaranteed, thereby avoiding the incorrect association of irrelevant records spanning long time intervals.

[0092] A candidate pair is configured to correspond to a pair identifier, which includes the identifiers of the two corresponding intelligence frames. For example, in a candidate pair, the event feature vector comes from intelligence frame F1 (identified as F1), and the context semantic embedding vector comes from intelligence frame F2 (identified as F2). The pair identifier corresponding to the candidate pair P1 (identified as P1) is (F1, F2), and so on.

[0093] In some possible implementations, session identifiers can play an auxiliary filtering role when constructing candidate pairs. For example, under the same asset identifier, if both the event record and the context record contain session identifiers, the consistency of their session identifiers is compared first. If the session identifiers are consistent, a candidate pair can be directly constructed. If the session identifier is missing or inconsistent, a candidate pair can still be formed under the condition that the asset identifiers are consistent and the intelligence frame identifiers are adjacent. By introducing the session identifier as an auxiliary condition, the pairing accuracy can be further improved when there are multiple concurrent network connections or multiple session activities, reducing the possibility of different session behaviors being mistakenly associated with the same attack chain.

[0094] After the candidate pairings are constructed, in some possible implementations, the pattern recognition module 10 performs entity consistency determination, semantic consistency determination and temporal proximity determination on each candidate pairing in turn to determine the corresponding association level.

[0095] For example, based on the source entity identifier, destination entity identifier, and key object entity identifier, entity consistency is determined for the candidate pairs. The key object entity identifier is determined by the normalization of object entities in the structured alarm fields. Entity consistency describes whether there is a relationship between object entities involved in different alarm events, such as whether the source entity identifier, destination entity identifier, asset identifier, or account identifier is the same or has a topological relationship.

[0096] Understandably, in network security systems, different security devices or log sources often represent the same object differently. For example, the same file, domain name, or process may have different path formats, capitalization, or additional parameters. Normalization here refers to converting object entities from different log sources and with different representation formats into entity identifiers of a unified format. This ensures that subsequent matching can correctly identify them as the same object, avoiding the problem of the same object being mistakenly identified as different entities due to different representation methods.

[0097] When the entity consistency determination result meets the first preset condition, that is, when the entity matching results corresponding to the two vectors in the candidate pair meet the matching threshold defined by the entity consistency condition parameter, the candidate pair is semantically consistent based on entity semantic similarity. Semantic consistency is used to describe whether the attack behaviors of different alarm events are semantically similar, such as whether information such as attack type, command line as feature, and attack stage label belong to the same attack stage or have similar behavioral patterns.

[0098] In the semantic consistency determination process, the similarity between the semantic representations of the entities corresponding to the context semantic embedding vector and the event feature vector can be calculated first, and the similarity value can be determined. Then, according to the semantic embedding similarity interval mapping table, the similarity value is mapped to the corresponding consistency level.

[0099] For example, similarity values ​​can be determined based on cosine similarity calculation. As mentioned earlier, event feature vectors typically contain multiple fields, such as object entity identifiers, alarm type markers, and attack phase markers. These fields are themselves discrete identifiers or category codes and cannot be directly used to calculate similarity with the contextual semantic embedding vector. Therefore, it is necessary to map these discrete features to a vector space of the same dimension as the semantic embedding vector through an event embedding table.

[0100] In this embodiment, the object entity identifier, alarm type marker, and attack stage marker in the event feature vector can be mapped to the same embedding space to form an event embedding vector. This event embedding vector can be determined by querying the event embedding table according to the encoding index. The event embedding table and the semantic encoding model use the same embedding dimension parameter. Based on this event embedding vector, the semantic representation of the event can be determined.

[0101] For example, firstly, the object entity identifier, alarm type marker, and attack stage marker are read from the event feature vector, and these identifiers are used as encoding indices input into the event embedding table. The event embedding table pre-stores the corresponding embedding vector for each encoding index; the object entity embedding vector, alarm type embedding vector, and attack stage embedding vector can be obtained by looking up the table. Then, these embedding vectors are synthesized according to preset combination rules, such as by concatenation or weighted synthesis, to generate an event embedding vector of uniform dimension.

[0102] The event embedding vector and the context semantic embedding vector reside in the same embedding space and have the same embedding dimension parameter. Therefore, the semantic similarity value can be directly determined through cosine similarity calculation. The event embedding table and the semantic encoding model use a unified embedding dimension and are managed with version numbers, ensuring consistency in the vector space across different model versions and avoiding similarity calculation deviations caused by changes in embedding dimension or encoding rules.

[0103] The similarity values ​​are mapped to the corresponding consistency levels, that is, the calculated continuous numerical similarity results are converted into discrete consistency levels according to the pre-defined interval rules.

[0104] For example, a similarity value ranging from 0 to 1 is obtained by using cosine similarity calculation. According to a pre-configured semantic embedding similarity interval mapping table, when the similarity value is in the range of 0.80 to 1.00, the corresponding consistency level is highly consistent; when the similarity value is in the range of 0.50 to 0.80, the corresponding consistency level is moderately consistent; when the similarity value is in the range of 0.20 to 0.50, the corresponding consistency level is weakly consistent; and when the similarity value is below 0.20, the corresponding consistency level is inconsistent.

[0105] This interval mapping method can transform semantic similarity calculation results into a consistency level identifier that can be directly used in rule judgment. In subsequent attack chain analysis or interaction pattern recognition, it is not necessary to repeatedly process specific values. Instead, logical judgment can be directly performed based on the consistency level, which helps to improve the stability of judgment and computational efficiency.

[0106] When the semantic consistency determination result meets the second preset condition, that is, when the consistency level meets the consistency level threshold defined by the semantic consistency condition parameter, the candidate pair is subjected to time proximity determination. For example, the difference between the aligned timestamps of the two records of the candidate pair under a unified time base is compared item by item with the time proximity threshold parameter to determine the time proximity determination result. Time proximity is used to describe the degree of proximity of different alarm events in time, and it is determined whether they belong to the same attack activity cycle by calculating the time interval between the event timestamps.

[0107] The association level can be determined based on the entity consistency determination result, the semantic consistency determination result, and the temporal proximity determination result.

[0108] In this embodiment of the application, the association level can be determined by a discrete level label based on a pre-configured association level coding table, and arranged according to the time sequence of the intelligence frame identifier to form the dynamic association degree sequence.

[0109] Based on the association level, a dynamic association validity marker can also be determined. This marker consists of two values: valid and invalid. When the results of entity consistency, semantic consistency, and temporal proximity determinations all meet their respective requirements, the dynamic association validity marker for the candidate pair is valid. When any one of these determinations fails to meet its corresponding requirement, the dynamic association validity marker for the candidate pair is invalid.

[0110] The dynamic correlation sequence, dynamic correlation validity marker, pairing identifier, and alignment lookup table are written together into the intelligence frame metadata, which can serve as the basis for subsequent alarm correlation link maintenance. The alignment lookup table records the alignment relationship between the event feature vector and the context semantic embedding vector in the entity identifier dimension. Here, alignment refers to the correspondence between entities in the event feature vector (source entity identifier, destination entity identifier, key object entity identifier) ​​and entities in the context entity item set corresponding to the context semantic embedding vector within the same candidate pair.

[0111] In some possible implementations, the pattern recognition module 10 identifies the dominant interaction pattern of the current attack by the following steps: First, based on the intelligence frames within the time range corresponding to the first preset sliding time window, a transfer sequence for the corresponding association level is determined. The transfer sequence is used to indicate the change in the association level of adjacent intelligence frames. Secondly, based on the transition sequence, multiple corresponding interaction modes are determined by querying a preset pattern dictionary; Finally, the dominant interaction mode is determined based on the frequency of occurrence and continuous duration of the multiple interaction modes.

[0112] For example, the first preset sliding time window includes a corresponding sliding time window length parameter and a sliding step parameter. The window is slid according to the sliding step parameter, the current window boundary is adjusted, and the corresponding association level transfer sequence is extracted within the intelligence frame interval covered by the window.

[0113] The transition sequence here can be understood as a structured representation of the original association level change sequence. For example, within the intelligence frame interval covered by the window, the dynamic association degree sequence formed by arranging the association levels of multiple candidate pairs in chronological order is L1, L2, L3, L3. When the sliding window covers this intelligence frame interval, the association level change sequence obtained within the sliding time window is L1-L2, L2-L3, L3-L3. This change sequence describes the change path of the association level over time and can be used to characterize the evolution trend of attack behavior relationships, such as continuous enhancement, stable maintenance, or sudden decline. Therefore, to facilitate pattern recognition, the change sequence can be structured, for example, converting each step of change into a change direction label, such as increase, maintenance, or decrease. For example, the above change sequence can be structured as: increase-increase-maintain.

[0114] The system's pre-configured pattern dictionary can predefine several patterns. For example, rise-rise-hold can be defined as a progressively enhanced interaction pattern, hold-hold-hold as a stable interaction pattern, rise-fall-rise as a fluctuating interaction pattern, fall-fall-hold as a decaying interaction pattern, and so on.

[0115] Once the system obtains the association level transition sequence within a certain time window, it uses its corresponding structured expression pattern as the key to search for the corresponding interaction pattern in the pattern dictionary.

[0116] For example, interaction patterns can be marked using interaction pattern identifiers. Interaction pattern identifiers are used to characterize the dominant interaction form of the attack intent. Within the same sliding time window, the number of occurrences and continuous duration of each interaction pattern identifier are counted. Here, the number of occurrences is the number of times the interaction pattern identifier is mapped and hit within the window, and the continuous duration is the longest duration for which the interaction pattern identifier is continuously hit within the window.

[0117] Based on the determination rule of prioritizing the frequency of occurrence and secondarily prioritizing the continuous duration, the dominant interaction mode identifier (i.e., determining the dominant interaction mode) is determined, and the dominant interaction mode identifier is bound to the corresponding sliding time window identifier and the corresponding alarm association link.

[0118] For example, Figure 3 This is a flowchart illustrating the steps for identifying a dominant interaction mode according to an embodiment of this application, including: Step S31: Obtain dynamic intelligence sequences; Steps S32-S33: Based on the dynamic intelligence sequence, obtain the structured alarm fields, generate the event feature vector, and obtain the unstructured context and generate the context semantic embedding vector. Step S34: Construct candidate pairings based on the event feature vectors and context semantic embedding vectors of adjacent intelligence frames; Step S35: Perform hierarchical judgment, that is, perform entity consistency judgment, semantic consistency judgment and temporal proximity judgment on candidate pairs in sequence to determine the association level; Step S36: Arrange the association levels according to the time sequence corresponding to the intelligence frames to form a dynamic association degree sequence; Step S37: Based on the sliding time window, statistically analyze the correlation level transition sequence; Step S38: Determine the corresponding dominant interaction mode based on the pattern dictionary.

[0119] As can be understood from the foregoing, in the embodiments of this application, the alarm association link can be constructed by pairing identifier and intelligence frame temporal adjacency relationship, and the alarm association link records its start intelligence frame identifier and end intelligence frame identifier with link identifier.

[0120] The dominant interaction mode identifier is written into the alarm association link metadata, which allows the blocking probability determination module 20 to detect the information continuity between adjacent intelligence frames in the alarm association link and calculate the local information blocking probability level.

[0121] In some possible implementations, information coherence is detected, also known as coupling adequacy detection, including entity continuity detection, attack phase consistency detection, and semantic drift detection.

[0122] Entity continuity detection is performed based on the source entity identifier, destination entity identifier, and key object entity identifier corresponding to adjacent intelligence frames. The source and destination entity identifiers are taken from the event feature vector field, while the key object entity identifier is taken from the object entity identifier field. The key object entity identifier is determined by the object entity normalization of the event feature vector.

[0123] Entity continuity detection determines entity continuity by comparing the entity identifier field in adjacent event records. Adjacent events are considered continuous if they share the same entity identifier, have a network topology reachability relationship, or have an account inheritance relationship. If there is no direct or topological relationship between the entity identifiers of adjacent events, they are considered discontinuous.

[0124] Entity continuity detection results reflect the degree of continuity of entity paths as attack activities propagate between network assets. Determining whether entities appear consecutively in entity continuity detection aims to identify the trajectory characteristics of attack behavior propagation or continuation between network entities. When source entities, destination entities, or critical target entities appear consecutively in adjacent intelligence frames, it indicates that related attack behaviors are continuously occurring on the same entity or the same entity path, suggesting that the entity may be at a critical node in the attack chain. For example, if an attacker continuously uses the same host for lateral movement or performs multiple operations under the same account identity, consecutive appearance can convey information about the continuity of attack behavior at the entity level. When entities are interrupted or replaced in adjacent intelligence frames, it indicates that the attack behavior may have undergone a phase transition, attack path shift, or attack target change. For example, if an attacker moves from one host to another or switches from one account to another identity, entity discontinuity can reflect changes in the attack path or a break in the attack chain.

[0125] In this embodiment, an entity continuity detection window parameter can be pre-set, which represents the maximum allowable break span. Based on this window parameter, the system backtracks within the alarm-associated link to check if the same entity identifier reappears within the continuity window. If the continuity condition is met, it is recorded as continuous; otherwise, it is recorded as discontinuous. The number of discontinuities and their duration are recorded. The number of discontinuities refers to the cumulative number of discontinuity determinations during the link scan, and the duration of discontinuity refers to the time span from the first discontinuous intelligence frame to the next intelligence frame meeting the continuity condition, calculated using an aligned timestamp under a unified time base.

[0126] The source entity identifier, destination entity identifier, and key object entity identifier of two adjacent frames in the alarm association link are compared item by item. The source entity continuity record, destination entity continuity record, and key object entity continuity record are summarized to form the entity continuity detection record. The entity continuity detection record can be written into the alarm association link metadata.

[0127] Phase consistency detection (also known as attack phase consistency detection) is performed based on the attack phase markers corresponding to adjacent intelligence frames and a preset attack phase progression rule table.

[0128] As explained above, each alert event can be tagged with an attack phase upon generation. These attack phase tags include at least one of the following: scanning and probing phase, authentication phase, privilege escalation phase, lateral movement phase, or data transfer phase. Attack phase consistency detection compares the attack phase tags and phase transition relationships of adjacent events to determine if they meet phase evolution rules. For example, the phase evolution rule might be: the scanning and probing phase is followed by the authentication phase, and the authentication phase is followed by the privilege escalation phase. When the phase transition relationship between adjacent events conforms to the preset phase evolution rules, it is considered a phase-consistent state; otherwise, it is considered a phase-inconsistent state.

[0129] For example, the intelligence frame metadata contains a pre-configured attack phase encoding table and corresponding version numbers. Based on this attack phase encoding table, the corresponding discrete phase encoding, i.e., the attack phase marker, can be determined according to the attack phase field mapping in the unified field set corresponding to the event feature vector. The blocking probability determination module 20 contains a pre-configured attack phase progression rule table, which pre-defines allowed phase transition relationships and disallowed phase jump relationships.

[0130] In attack phase consistency detection, the attack phase markers of adjacent intelligence frames are progressively checked according to the link sequence. That is, the change in attack phase marker from the current frame to the next frame is used as input, and the transition result is queried in the rule table. When the transition result belongs to an allowed phase transition relationship, it is recorded as attack phase consistent. When the transition result belongs to an disallowed phase jump relationship, it is recorded as attack phase inconsistent, and the number of phase jumps and jump positions are recorded. The number of phase jumps refers to the cumulative number of times an attack phase is determined to be inconsistent within the alarm-related link, and the jump position refers to the corresponding intelligence frame identifier pair. The attack phase consistency detection record formed by summarizing the detection results of multiple intelligence frames in the alarm-related link can be written into the alarm-related link metadata.

[0131] Semantic drift detection is used to determine whether the semantics of events in an alarm association chain have changed significantly. Semantic drift detection determines the degree of semantic change by calculating the semantic distance or similarity between the semantic embedding vectors of adjacent events. When the semantic distance is less than a preset semantic drift threshold, it is determined to be a semantically stable state; when the semantic distance exceeds the semantic drift threshold, it is determined to be a semantically drifting state.

[0132] Semantic drift detection is used to identify whether an attack has involved a strategy shift or a change in the target.

[0133] For example, in this embodiment of the application, semantic drift detection is performed based on the contextual semantic embedding vectors of adjacent intelligence frames and a preset semantic embedding similarity interval mapping table. The semantic embedding similarity interval mapping table is used to divide the semantic embedding similarity values ​​into multiple intervals and assign a drift level label to each interval, such as high drift level, medium drift level, low drift level, etc.

[0134] The similarity value is determined by calculating the cosine similarity of the contextual semantic embedding vectors of two adjacent frames. Based on this, the drift level corresponding to the interval in which the similarity value falls is marked as the drift level. When recording the drift level, the corresponding drift duration can also be recorded. The drift duration refers to the time span during which the data continuously falls into the high drift level interval in the link scan. The time span is calculated using aligned timestamps under a unified time base.

[0135] In this embodiment, the aforementioned entity continuity detection records, attack phase consistency detection records, and semantic drift detection records are summarized to form the information coherence detection result, also known as the coupling sufficiency detection record. This coupling sufficiency detection record includes the coupling status of the alarm association link in the entity, phase, and semantic dimensions. A high coupling state is determined when all three dimensions meet the continuity or consistency condition; a medium coupling state is determined when some dimensions do not meet the condition; and a low coupling state is determined when multiple dimensions experience interruptions or drift.

[0136] Based on the dominant interaction mode identifier determined above, the blocking probability determination module 20 can also determine the frequency of change of the dominant interaction mode identifier within the sliding time window. Specifically, the number of window advances can be determined based on the sliding step parameters and the statistical period; the frequency of change can then be determined based on the number of window advances and the number of changes in the dominant interaction mode identifier of adjacent sliding time windows.

[0137] The blocking probability determination module 20 is also pre-configured with a mapping table. By taking the change frequency and information coherence detection results as input, it can determine multiple combination intervals and the corresponding local information blocking probability.

[0138] In this embodiment, the probability of local information blocking is represented by discrete level labels (i.e., local information blocking probability levels). By using discrete level labels instead of continuous probability values, the sensitivity to fluctuations can be reduced, which is beneficial for subsequent adjustment strategy judgment. The local information blocking probability level can also be linked to the corresponding alarm-related link and the corresponding intelligence frame interval as an index, which is beneficial for subsequent dynamic closed-loop control processing of the system.

[0139] Figure 4 This is a schematic diagram of the structure of another data alarm system provided in the embodiments of this application.

[0140] like Figure 4 As shown, to improve overall alarm processing efficiency and reduce system oscillation risk, in some possible implementations, the system further includes an alarm efficiency determination module 60, used to determine the intent response sparse region based on the network interaction characteristics. Furthermore, the compensation factor determination module 30 can generate a corresponding compensation factor based on the combination relationship between the intent response sparse region and the processing channel, so that the system can make targeted configuration adjustments for the intent response sparse region.

[0141] The intent response sparse region here represents an area in the network topology with low interaction frequency and insufficient potential threat identification capability. That is, this region is more likely to have problems such as missing alarm correlation information or decreased processing efficiency, and requires more dynamic allocation of processing resources and alarm aggregation rules.

[0142] In other words, low interaction frequency usually means fewer associated attack paths and weaker contextual information propagation capabilities within the area. When an attack spans multiple assets or stages, relevant intelligence may not form a continuous link within the area, leading to reduced dynamic correlation or increased repeated alarm triggering. In such cases, if alarms are still handled using a globally unified strategy, local information blockage or redundant alarm accumulation can easily occur.

[0143] For areas with high interaction frequency, since their intelligence association links are usually more complete and dynamic association is more stable, alarm information can naturally form a continuous attack chain. Therefore, there is no need to frequently adjust resources and aggregation thresholds; maintaining the default configuration is sufficient.

[0144] Therefore, in some possible implementations of this application, a dynamic correlation sequence is extracted first from the intelligence frame interval corresponding to the sparse region of intent response. This sequence is then combined with the alarm repetition triggering characteristics within that interval to construct a fluctuation assessment input vector, calculate the alarm efficiency fluctuation coefficient, and adjust the resource quota parameters and alarm aggregation judgment threshold parameters accordingly. In this way, targeted allocation can be performed in areas with weak information propagation capabilities or high alarm redundancy, improving alarm processing efficiency and reducing redundant alarms in those areas. This strategy of focusing on sparse regions and maintaining stable high-interaction regions avoids system oscillations caused by global parameter tuning while improving overall alarm processing efficiency.

[0145] It is understandable that, due to differences in asset types, alarm density, and processing resource allocation across different network regions, the processing time for the same type of alarm often varies across different network regions. In this embodiment, a correspondence is established between different regions and their corresponding processing response delays, thereby determining the alarm processing efficiency of different network regions and making targeted adjustments.

[0146] For example, if the response latency of a certain sparse region is significantly higher than that of other regions, it indicates that there is a deficiency in the resource allocation or alarm aggregation rules of that region. Therefore, the resource quota parameters and alarm aggregation judgment threshold parameters can be adjusted based on the compensation factor, thereby optimizing the resource allocation of the alarm processing channel and reducing redundant alarm triggering in subsequent steps.

[0147] To determine the sparse region of intent response, for example, the alarm efficiency determination module 60 first constructs an interaction graph based on network interaction characteristics.

[0148] For example, firstly, network topology spatial interaction data is acquired. This data includes at least communication connection records, access path records, and lateral movement association records. Communication connection records are determined by network traffic probes or border devices, and their corresponding fields include at least source entity identifier, destination entity identifier, protocol port information, and alignment timestamp. Access path records are determined by proxy access or application gateways, and their corresponding fields include at least account identifier, asset identifier, access target identifier, access result identifier, and alignment timestamp. Lateral movement association records are determined by terminal detection and response or domain controller auditing, and their corresponding fields include at least source asset identifier, destination asset identifier, account identifier, process identifier, object entity identifier, and alignment timestamp. By performing unified identifier normalization processing on the above interaction data, an interaction graph can be established using asset identifiers, account identifiers, process identifiers, and domain identifiers as node identifiers.

[0149] In the interaction graph, nodes represent corresponding entity objects, and edges represent interaction relationships under the constraints of aligned timestamps. Edge types include at least communication connection edges, access path edges, and lateral movement edges. Edge attributes include edge type flags, trigger count counters, and the most recent trigger timestamp. The aligned timestamps and protocol port information used in the interaction graph adopt a unified time base aligned field caliber and maintain a consistent mapping relationship with the asset identifier and session identifier in the intelligence frame metadata.

[0150] For example, Figure 5 This is a schematic diagram of an interaction graph topology provided in an embodiment of this application.

[0151] In this interaction diagram, nodes 1 through 5 represent server A, server B, server C, server D, and external IP, respectively. Edges 1 through 4 represent network interactions between entities, namely, scanning between external IP and server A, lateral access between server A and server B, interconnection between server A and server C, and permission exploitation between server B and server D.

[0152] After the interaction graph is constructed, it can be partitioned according to security domain boundaries, subnet boundaries, and service domain boundaries, and nodes can be assigned to corresponding partitions, each with a partition identifier. Within the system, security domain configuration tables, network address planning tables, and service asset grouping tables can be pre-configured. Security domain boundaries are determined by the pre-configured security domain configuration tables, subnet boundaries by the network address planning tables, and service domain boundaries by the service asset grouping tables. All of these configuration tables are fixed with version numbers and associated with intelligence frame identifiers, ensuring the traceability of results for each partition.

[0153] In the above classification criteria, security domain boundaries reflect security policy isolation relationships, such as intranet zones, DMZ zones, and extranet zones. Subnet boundaries reflect network address divisions, such as different IP network segments. Business domain boundaries reflect the affiliation of business systems or applications, such as database zones, application zones, and office zones. Each node (asset identifier, account identifier, etc.) possesses all three types of attributes. Based on preset priorities or combination rules (e.g., security domain first, subnet second, and finally refined to business domain), each node is assigned to a corresponding partition, and each partition corresponds to a unique partition identifier.

[0154] Based on the above partitioning method, while ensuring that the partitions have security isolation significance, they can also reflect the network structure and business attributes. This allows the statistically obtained interaction frequency to have both security semantics and network and business interpretability.

[0155] Then, for each partition, the interaction frequency of each partition is determined according to the window length parameter and step parameter of the second preset sliding time window. The interaction frequency includes the increment of the number of edges within the partition, the number of times the cross-partition edge is triggered, and the number of times the path is traversed.

[0156] The increment of the number of edges within a partition refers to the difference between the number of edges within a partition in the current sliding time window and the number of edges within a partition in the previous sliding time window. The number of cross-partition edge triggers refers to the cumulative number of times edges whose two endpoints belong to different partitions are triggered within the current sliding time window. The number of path traversals refers to the cumulative number of times access path edges and lateral movement edges are recorded as traversing a certain partition within the current sliding time window.

[0157] Each partition type has a corresponding threshold configuration item, including a corresponding preset low-frequency judgment threshold. The interaction frequency of each partition is compared with the preset low-frequency judgment threshold. When the interaction frequency is lower than the preset low-frequency judgment threshold and the duration reaches the preset duration threshold, the partition is identified as an intent response sparse region. Furthermore, a corresponding sparse region identifier can be generated. The sparse region identifier includes the partition identifier, the starting timestamp of the sliding time window, and the sliding time window length parameter. The sparse region identifier remains unique and is bound to the intelligence frame range covered by the sliding time window. Writing the sparse region identifier into the intelligence frame metadata also facilitates subsequent targeted dynamic adjustments.

[0158] During the process of determining the sparse region of intent response based on the second preset sliding time window, the alarm efficiency determination module 60 also determines the alarm re-triggering characteristics of each partition within the same sliding time window. That is, based on the window length parameter and step parameter of the second preset sliding time window, the re-triggering density, re-triggering duration, and the number of assets covered by re-triggering are determined. Furthermore, the corresponding alarm efficiency fluctuation coefficient level can be determined.

[0159] The repetitive trigger density refers to the ratio of the number of structured alarm triggers corresponding to the same aggregation key within the current sliding time window to the sliding time window length parameter. The aggregation key consists of the source entity identifier, destination entity identifier, attack phase marker, rule trigger identifier, and asset identifier. In this embodiment, this ratio is mapped to discrete density levels; that is, the repetitive trigger density is represented by discrete density levels, such as high density level, medium density level, and low density level. The repetitive trigger duration refers to the time span during which the repetitive trigger density remains at a high density level across multiple consecutive sliding time windows. The time span is determined by the start and end timestamps of the window under a unified time base. The number of assets covered by repetitive triggers refers to the number of different asset identifiers covered by repetitive trigger alarms within the current sliding time window.

[0160] As mentioned above, both the dynamic correlation sequence and the sparse region identifier are bound to the intelligence frame metadata. The corresponding intelligence frame interval can be located based on the sparse region identifier, and the dynamic correlation sequence corresponding to that interval can be obtained. Based on the dynamic correlation sequence and the alarm repetition triggering characteristic, a fluctuation assessment input vector can be constructed.

[0161] The dynamic correlation sequence includes dynamic correlation validity marker information and correlation level information. Alarm re-triggering characteristics include re-triggering density level, re-triggering duration, and the number of assets covered by re-triggering. Based on the ratio of the number of valid pairs marked as dynamic correlation validity to the total number of pairs within the intelligence frame interval corresponding to the current sparse region identifier, the validity ratio of the dynamic correlation sequence can be determined. In this embodiment, this validity ratio can be mapped to a discrete ratio interval. On the other hand, based on the cumulative number of times the correlation level rises or falls between adjacent intelligence frames within the corresponding intelligence frame interval, the correlation level fluctuation amplitude can be determined, and this correlation level fluctuation amplitude can also be mapped to a discrete amplitude interval.

[0162] The volatility assessment input vector is a vector that includes information on the effectiveness ratio, correlation level volatility, recurring trigger density level, recurring trigger duration, and the number of assets covered by recurring triggers.

[0163] The system's pre-configured interval mapping table can convert the fluctuation assessment input vector into an alarm efficiency fluctuation coefficient. To facilitate online deployment, in this embodiment, the value of the alarm efficiency fluctuation coefficient is discretized into alarm efficiency fluctuation coefficient levels according to the interval mapping table. This alarm efficiency fluctuation coefficient level is written into the intelligence frame metadata using a level tag format, and is simultaneously bound to the corresponding sparse region identifier and the corresponding sliding time window identifier for subsequent querying.

[0164] For example, in an enterprise office network scenario, after a terminal device receives a phishing email, it triggers a suspicious script execution alarm in the terminal detection and response system. At the same time, the intrusion detection device continuously triggers external connection alarms, proxy access generates abnormal download records, and the security operations platform also receives multiple duplicate alarms with the same rule trigger identifier.

[0165] Based on the data alarm system provided in this application embodiment, structured alarm events and unstructured attack contexts can first be aligned to the same intelligence frame, generating a dynamic intelligence sequence. Then, based on the corresponding event feature vectors and context semantic embedding vectors, a dynamic correlation sequence can be constructed, and the corresponding dominant interaction pattern can be identified. The phase progression characteristics of the dominant interaction pattern are: external download, credential abuse, and lateral movement. Next, entity continuity detection and attack phase consistency detection are performed along the alarm correlation link. If it is detected that the attack phase markers of adjacent intelligence frames in the alarm correlation link are continuously progressive and repeatedly triggered densely, then the probability level of local information blocking is determined to be increased. By constructing an interaction graph and partitioning and statistically analyzing the interaction frequency, it can be determined that the cross-partition interaction from the subnet where the terminal device is located to the subnet where the file server is located is low-frequency and continuous, thus identifying the corresponding partition as an intent response sparse region. Within this sparse region, the density of repeated triggers and the number of covered assets are high, and the alarm efficiency fluctuation coefficient level is marked as high fluctuation.

[0166] Based on this, in subsequent processing steps, the system can aggregate and suppress duplicate alarms under the same aggregation key, and prioritize retaining aggregated alarm records that are valid with stage progression markers and dynamic correlation validity markers, thereby reducing the interference of redundant alarms on analysis and decision-making without losing the main attack chain.

[0167] In some possible implementations, the compensation factor determination module 30, when used to generate the compensation factor, is specifically used for: Based on the alarm event handling receipt, a response delay sample table is constructed with the combination of the intent response sparse region and the handling channel as the index key; Based on the response delay sample, the predicted response delay level and delay sensitivity level corresponding to the index key are determined by querying the preset response delay level range table and sensitivity level range table mapping. Based on the alarm efficiency fluctuation coefficient, the predicted response delay level, and the delay sensitivity level, the compensation factor corresponding to the index key is determined by querying a preset adjustment rule table. Each rule in the adjustment rule table includes the scope of application for sparse area identifiers and the scope of application for disposal channel identifiers.

[0168] As mentioned above, the handling receipt is automatically sent back by the alarm handling channel after the handling action is completed, or it is submitted by the safety operations personnel when the handling work order is closed.

[0169] In this embodiment, the handling receipt is validated and a handling record is constructed. The handling record is a data record that provides a structured description of the alarm handling process. The handling record consistently includes the following fields: alarm identifier, sparse area identifier, handling channel identifier, start time, completion time, and handling result. The alarm identifier is determined by the unique number of the structured alarm event and is consistent with the original alarm identifier list in the aggregated alarm record. The sparse area identifier is pre-bound to the intelligence frame metadata, and its value is the interaction graph partition number or network asset partition number, such as the subnet partition number, server area number, or terminal area number, used to indicate the area to which the alarm event belongs in the network topology. The handling channel identifier is a unique identifier generated by the handling action type and execution combination, such as the automated handling channel number or the manual handling channel number, used to distinguish different alarm handling processes. The start time is the timestamp of the handling channel accepting the alarm or the aggregated alarm record. The completion time is the timestamp of the handling channel completing the handling and generating the receipt. The handling result field is a pre-configured enumeration value of the handling result, such as handling success status, handling failure status, or handling cancellation status, used to describe whether the handling action was completed and its execution result.

[0170] In this embodiment, a unified time base correction is performed on the start and finish times, and the response delay is calculated based on the correction result. The response delay is the time difference between the finish time and the start time. The time difference is expressed in seconds under the unified time base. If the processing receipt is missing a start or finish time, the processing record is marked as unusable and not used for subsequent processing to ensure data quality consistency.

[0171] The response delay corresponding to each obtained processing receipt is used as a sample. A response delay sample table is constructed using the combination of sparse region identifier and processing channel identifier as the index key. Each index key corresponds to a set of response delay samples. The sample table records the number of samples in each set, the sample time coverage range, and the distribution of processing results.

[0172] To facilitate mapping processing, this embodiment discretizes the response delay into a predicted response delay level and simultaneously outputs the delay sensitivity level.

[0173] The predicted response latency level is determined by a pre-configured response latency level interval table. This table divides the numerical range of response latency into multiple non-overlapping level intervals and assigns a level label to each interval. The median of all response latency samples under each index key is used as the representative latency value, and the corresponding response latency level can be determined based on this representative latency value. For example, if the representative latency value is less than T1, it is mapped to a low latency level. If the representative latency value is between T1 and T2, it is mapped to a medium latency level. If the representative latency value is greater than T2, it is mapped to a high latency level. In this embodiment, the representative latency value is determined using the median rule, which helps to reduce the impact of outlier samples on the level output.

[0174] The latency sensitivity level is used to characterize the degree of fluctuation in response latency under the same combination of sparse region identifier and processing channel identifier. For example, based on the interquartile range rule, the difference between the upper quartile and the lower quartile of the response latency samples in the latency sample table is calculated as a dispersion index. Based on this dispersion index, the samples are classified and then mapped to a latency sensitivity level according to a pre-configured sensitivity level interval table.

[0175] In some possible implementations, the above response latency level range table and sensitivity level range table are both saved as part of the configuration file and have corresponding version numbers. The version numbers are written into the mapping model metadata to ensure that the rule definitions are traceable.

[0176] In other words, by inputting the above index key into the mapping model, the predicted response latency level and latency sensitivity level can be output. For example, the mapping model can be implemented using either a table-driven mapping method or a lightweight classification model.

[0177] Taking the table-driven mapping method as an example, at the end of each allocation cycle, the representative delay value and dispersion index corresponding to the delay sample table are updated by index key, and the predicted response delay level and delay sensitivity level corresponding to the index key are updated accordingly.

[0178] The security operation strategy can be pre-configured and loaded into the adjustment rule table during initialization. Each rule in the adjustment rule table includes the applicable sparse area identifier range and the applicable disposal channel identifier range to ensure that different types of sparse areas and different disposal channels can adopt differentiated allocation strategies.

[0179] Based on this adjustment rule table, a two-dimensional matrix structure is constructed using sparse region identifiers as row indices and processing channel identifiers as column indices. Each index key, at its corresponding coordinate in the two-dimensional matrix, determines a corresponding compensation factor based on the alarm efficiency fluctuation coefficient, the predicted response delay level, and the delay sensitivity level, thus forming a compensation factor matrix. This compensation factor matrix can be written to the online allocation parameter storage area. Furthermore, it can record the matrix version number, rule table version number, and mapping model version number, and archive the version numbers along with the allocation cycle identifier for subsequent dynamic adjustments.

[0180] Each matrix element (i.e., each compensation factor) includes a resource quota adjustment instruction field and an aggregation threshold adjustment instruction field. The resource quota adjustment instruction field includes adjustment levels for concurrency quota, queue quota, and computing power quota, used to indicate the adjustment direction of these parameters during resource quota adjustment. The aggregation threshold adjustment instruction field includes adjustment levels for similarity judgment threshold, time window threshold, and suppression threshold, used to indicate the adjustment direction of these parameters during alarm aggregation processing.

[0181] In this embodiment of the application, each adjustment gear position adopts a discrete gear position mark. The set of values ​​for the gear position mark is determined by a pre-configured gear position set table. For example, the gear position set table includes at least three types of gear position marks: up gear position, down gear position, and hold gear position. Each type of gear position mark has a corresponding single-cycle change allowable range.

[0182] For example, if a sparse region experiences a high predicted response latency level on a particular processing channel, it indicates insufficient processing capacity on that channel. In this case, a compensation factor is used to instruct an increase in resource quotas, such as increasing concurrency limits or queue capacity. If the latency level is low but the alarm repetition density is high, the compensation factor is used to instruct an increase in the alarm aggregation threshold to reduce redundant alarms. If the latency sensitivity level is high, the adjustment range per cycle will also be limited to avoid system oscillations.

[0183] That is, in this embodiment of the application, the adjustment rule table is used to determine the adjustment levels of the concurrency quota, queue quota, computing power quota, similarity judgment threshold, time window threshold, and suppression threshold based on the corresponding levels of the predicted response delay level, delay sensitivity level, and alarm efficiency fluctuation coefficient level.

[0184] For example, the state of a certain sparse region in the current allocation cycle is as follows: the predicted response latency level is high latency, the latency sensitivity level is medium sensitivity, and the alarm efficiency fluctuation coefficient level is high volatility. According to the adjustment rule table, the compensation factors are in the following tiers: the resource quota adjustment tier is increased by two tiers, and the aggregation threshold adjustment tier is increased by one tier. An increase of two tiers indicates a significant increase in the concurrency quota parameter, queue quota parameter, or computing power quota parameter within this cycle, for example, by increasing it by two preset steps. An increase of one tier indicates a smaller adjustment to the alarm aggregation-related thresholds, for example, increasing the similarity judgment threshold or shortening the aggregation time window by one step.

[0185] Alternatively, the state of a certain sparse region within the current allocation cycle is: predicted response latency level is low latency, latency sensitivity level is low sensitivity, and alarm efficiency fluctuation coefficient level is low fluctuation. According to the adjustment rule table, the compensation factor is that the resource quota adjustment level is maintained, and the aggregation threshold adjustment level is lowered by one level. The maintained level means that the resource parameters remain unchanged, while the lowered level means that the alarm aggregation judgment threshold is slightly reduced to enhance alarm merging capabilities.

[0186] In this embodiment, the system can uniformly convert multi-dimensional state information into discrete adjustment gear instructions, thereby maintaining a stable and controllable adjustment process when performing resource allocation and threshold adjustment.

[0187] In some possible implementations, the dispensing processing module 40 is further configured to: Based on the compensation factor, adjust the resource quota parameters and aggregation threshold parameters corresponding to the alarm handling channel; Within each preset allocation cycle, the dynamic correlation sequence and the local information blocking probability are re-determined based on the adjusted parameters; If the dynamic correlation sequence indicates that the dynamic correlation of the intelligence frame sequence remains valid within the current allocation cycle, and the local information blocking probability is within a preset controlled range, the current parameter is archived as an effective configuration and enters the next allocation cycle; otherwise, the current parameter is rolled back until the parameter is archived as an effective configuration.

[0188] For example, when the compensation factor corresponding to a sparse response region indicates that the alarm handling channel in that region has a high response latency and a large fluctuation coefficient in alarm efficiency, the similarity judgment threshold and time window threshold in the alarm aggregation judgment threshold parameter set can be increased. Based on this, alarm events generated within a similar time period and with similar behavioral characteristics will be merged into the same alarm record. At the same time, increasing the repeated trigger suppression threshold can reduce repeated alarms entering the handling channel, thereby reducing the degree of information congestion in the handling link and decreasing the probability of local information blockage. If the alarm handling efficiency in a certain region is high and the response latency is low, the aggregation judgment threshold can be appropriately reduced, allowing more fine-grained alarm events to be retained, thereby maintaining the continuity and correlation strength of the dynamic correlation sequence.

[0189] By adaptively adjusting the threshold parameter set in the above manner, the number of duplicate alarms can be reduced while maintaining the effective correlation between alarm events. This stabilizes the processing load of the alarm handling channel in different network regions, achieving a synergistic balance between redundant alarm reduction and the effectiveness of correlation analysis.

[0190] After parameter adjustment, a verification operation is required. The allocation cycle here is determined by the allocation cycle duration parameter, that is, an allocation calculation and parameter distribution are triggered according to the allocation cycle duration parameter.

[0191] In this embodiment of the application, an alarm handling channel set containing multiple handling channel identifiers can be pre-established based on the handling channel identifier, and each handling channel identifier corresponds to an executable handling queue.

[0192] On one hand, each processing channel identifier is associated with a resource quota parameter set, which includes concurrency quota parameters, queue quota parameters, and computing power quota parameters. The concurrency quota parameter limits the maximum number of alarms that the processing channel can process in parallel within the same allocation cycle. The queue quota parameter limits the maximum number of alarms that the processing channel's queue can hold. The computing power quota parameter limits the amount of computing resources that the processing channel can occupy, measured in a uniform computing power unit. The concurrency quota parameter, queue quota parameter, and computing power quota parameter each have corresponding parameter value ranges and single-cycle adjustment step size limits. The parameter value range limits the minimum and maximum parameter values, while the single-cycle adjustment step size limits the maximum change in each upward or downward adjustment, preventing resource jitter during the allocation process.

[0193] On the other hand, for each processing channel identifier, before an alarm event enters the processing channel, the alarm aggregation engine aggregates and suppresses alarm events according to alarm aggregation rules. In this embodiment, in addition to the resource quota parameter set, an alarm aggregation judgment threshold parameter set is pre-established to adjust the alarm aggregation rules. The parameters corresponding to both the resource quota parameter set and the alarm aggregation judgment threshold parameter set can be written to the parameter configuration storage area as the initial effective configuration.

[0194] The alarm aggregation judgment threshold parameter set includes similarity judgment threshold parameters, time window threshold parameters, and suppression threshold parameters. The similarity judgment threshold parameter determines the passing boundary for alarm similarity judgment under the same aggregation key; the time window threshold parameter determines the length boundary of the sliding time window covered by the aggregation operation; and the suppression threshold parameter determines the trigger boundary for duplicate trigger records to enter the suppression list. The similarity judgment threshold parameter, time window threshold parameter, and suppression threshold parameter each have corresponding parameter value ranges and upper limits for single-cycle adjustment steps.

[0195] For example, during the process of aggregating and suppressing alarm events according to alarm aggregation rules, the alarm aggregation engine first generates an aggregation key for each structured alarm event and writes the aggregation key into the alarm metadata. The aggregation key includes the source entity identifier, destination entity identifier, attack phase marker, rule trigger identifier, and asset identifier. Then, within a sliding time window, alarm events are grouped by the aggregation key. For each group, the similarity judgment threshold parameter and time window threshold parameter are read, and the merging boundary is determined according to the threshold conditions to generate an aggregated alarm record. Next, for each group, the suppression threshold parameter is read, the repetitive trigger density and repetitive trigger duration are calculated, and repetitive trigger records exceeding the interval corresponding to the suppression threshold parameter are written into the suppression list, and the suppression reason is marked in the aggregated alarm record. Then, for each aggregated alarm record, the dynamic correlation validity marker and attack phase marker change record are read. When the dynamic correlation validity marker is valid and the attack phase marker undergoes progressive change, a phase progression marker is generated, and the aggregated alarm record is maintained as a continuous link event. Finally, an evidence chain index is created for each aggregated alarm record. The evidence chain index includes a list of original alarm identifiers, a list of corresponding context fragment identifiers, and a dominant interaction mode identifier.

[0196] At the beginning of each allocation cycle, the alarm efficiency fluctuation coefficient level and corresponding compensation factor of each sparse region identifier within the current allocation cycle are extracted according to the time window covered by the current allocation cycle. Based on this, the set of sparse region identifiers that need to be allocated and the corresponding adjustment strategy can be determined.

[0197] Based on the compensation factor corresponding to the combination of each sparse region identifier and each processing channel identifier, the resource quota adjustment level and aggregation threshold adjustment level are determined, namely, the concurrency quota adjustment level, queue quota adjustment level, computing power quota adjustment level, similarity judgment threshold adjustment level, time window threshold adjustment level, and suppression threshold adjustment level. The parameters are adjusted according to the adjustment direction indicated by the adjustment level. For example, taking an upward adjustment level as an example, the corresponding parameter is adjusted upward according to the upper limit of the single-cycle adjustment step size, while controlling the parameter not to exceed the maximum value within the parameter value range. When the level is a downward adjustment level, the corresponding parameter is adjusted downward according to the upper limit of the single-cycle adjustment step size, while controlling the parameter not to fall below the minimum value within the parameter value range. When the level is a hold level, the parameter value remains unchanged.

[0198] The concurrency and queue quota parameters for each processing channel are synchronously sent to the processing queue scheduler, while the computing power quota parameters are sent to the resource controller. The resource controller limits the computing resource usage of that processing channel within the allocation cycle based on the computing power quota parameters. Similarity threshold parameters, time window threshold parameters, and suppression threshold parameters are sent to the alarm aggregation engine. The alarm aggregation engine performs aggregation and suppression judgments on alarms under the same aggregation key based on the updated threshold parameters, thus ensuring that resource allocation and aggregation rules take effect collaboratively within the same allocation cycle.

[0199] Within each preset allocation cycle, a verification operation is performed based on the adjusted parameters, and the local information blocking probability level is recalculated. That is, as mentioned earlier, entity continuity detection, attack phase consistency detection, and semantic drift detection are performed along the alarm association link. Combined with the frequency of changes in the dominant interaction mode, the local information blocking probability level is determined according to a preset mapping table. Furthermore, based on the intelligence frame metadata, dynamic correlation validity markers are simultaneously acquired. Within the intelligence frame interval covered by the current allocation cycle, the dynamic correlation validity ratio is calculated. The dynamic correlation validity ratio refers to the ratio of the number of pairs marked as valid to the total number of pairs. In some possible implementations, when the dynamic correlation validity ratio is greater than or equal to a preset validity ratio threshold parameter, the dynamic correlation is considered to remain valid.

[0200] The system also has a pre-configured, fixed controlled interval, which indicates the set of allowed blocking probability levels. The acquired local information blocking probability level is compared with the pre-configured controlled interval. If the local information blocking probability level falls within the pre-configured controlled interval and the dynamic correlation remains valid, the resource quota parameter set and alarm aggregation judgment threshold parameter set of the current allocation cycle are archived as effective configurations. The allocation cycle identifier, sparse area identifier, handling channel identifier, alarm efficiency fluctuation coefficient level, compensation factor matrix element identifier, and parameter adjustment level are recorded as the basis for subsequent closed-loop updates and audits.

[0201] Understandably, while increasing the aggregation threshold to reduce the number of alarms can lower the probability of blocking, excessive aggregation may lead to the incorrect merging of alarms from different attack stages. This disrupts the correlation between events, reduces dynamic correlation, and prevents the correct identification of attack chains. Therefore, it is necessary to simultaneously check the effectiveness of dynamic correlation to ensure that the correlation structure between alarm events remains intact.

[0202] If the system only ensures the effectiveness of dynamic correlation without controlling the probability of blocking, the number of alarm events may continue to grow, causing blockages in the processing channel, resulting in increased alarm processing delays and affecting security response efficiency. Therefore, it is also necessary to ensure that the alarm processing link remains in a bearable state through controlled blocking probability conditions.

[0203] In this embodiment of the application, the two factors of controlled blocking probability and effective dynamic correlation are used as the triggering conditions for the effective configuration. This can ensure that the number of repeated alarms is reduced without destroying the correlation structure of the attack behavior, thereby achieving redundant alarm reduction while maintaining the ability to identify attack links.

[0204] When the probability level of local information blockage does not fall within the preset controlled range or the condition for maintaining the effectiveness of dynamic correlation is not met, the rollback level adjustment is executed according to the preset rollback rules and re-verified to ensure stable convergence of the allocation process.

[0205] In this embodiment, the preset rollback rule prioritizes the suppression threshold parameter and the time window threshold parameter for rollback. The rollback level is adjusted according to the rollback rule. Specifically, for the suppression threshold parameter and the time window threshold parameter, the parameter value from the previous allocation cycle is used as the rollback baseline, and the upper limit of the adjustment step is set for each cycle. The adjusted parameter value moves towards the baseline value until the controlled interval and validity conditions are met. During the rollback process, the concurrency quota parameter, queue quota parameter, and computing power quota parameter remain unchanged, or the resource stability sub-rule in the rollback rule maintains the current level, avoiding simultaneous drastic fluctuations in both resources and thresholds when the blocking risk is high.

[0206] After the rollback, the probability level of local information blocking is recalculated and the effectiveness ratio of dynamic correlation is recalculated until the conditions for effectiveness are met. Then, the rolled-back parameter combination is archived as the effective configuration and enters the next allocation cycle.

[0207] Through the aforementioned gear allocation, controlled verification, and rollback convergence mechanism driven by the allocation cycle, in a real-world safe operation environment, it is possible to reduce interference from redundant alarm triggering while maintaining the effective transmission of alarm correlation links, keeping the blocking probability within a controlled range and maintaining the effectiveness of dynamic correlation at an available level, thereby achieving an engineering-implementable closed loop for redundant alarm reduction.

[0208] For example, in data center operations and maintenance scenarios, perimeter protection devices and intrusion detection devices generate a large number of scanning and login failure alarms targeting management interfaces in a short period of time. Some of these are genuine external brute-force attack attempts, while others are repeated alarms triggered by maintenance script inspections. Genuine brute-force attack alarms are handled by automatically blocking channels, while scanning alarms are handled by manually analyzing the channels.

[0209] According to the alarm system provided in the embodiments of this application, the system can first read the handling receipt to construct the handling record, calculate the response delay, and then merge the response delay according to the sparse area identifier and the handling channel identifier to form a delay sample table. Based on the mapping model, the response delay level and the delay sensitivity level can be predicted.

[0210] Subsequently, based on the alarm efficiency fluctuation coefficient level of the sparse region, a compensation factor is generated according to a preset adjustment rule table. For example, the compensation factor indicates that the concurrency quota parameter and computing power quota parameter of the automatically blocked channel should be adjusted upwards, while the queue quota parameter of the manually judged channel should be adjusted downwards or kept at the same level. At the same time, the suppression threshold parameter and time window threshold parameter are adjusted to a level more suitable for aggregating repeated scan alarms.

[0211] After the compensation factor is issued and allocated, the local information blocking probability level is recalculated and the dynamic correlation effectiveness ratio is statistically analyzed. When the local information blocking probability level falls within the preset controlled range and the dynamic correlation effectiveness ratio meets the preset effectiveness ratio threshold parameter, the periodic parameter is archived as the effective configuration. When any condition is not met, the suppression threshold parameter and time window threshold parameter are rolled back according to the rollback rules and re-verified. Thus, in actual operation, stable convergence of processing resources and aggregation thresholds is achieved, reducing the consumption of processing resources by repeated alarms and improving the timeliness of response to critical brute-force attack alarms.

[0212] This application also provides a data alarm processing method, such as... Figure 6 As shown, Figure 6 This is a flowchart illustrating a data alarm processing method provided in an embodiment of this application. The method can run on the terminal device side or on the server side.

[0213] The method includes the following steps S100 to S400: Step S100: Generate a dynamic intelligence sequence with spatiotemporal correlation based on alarm information from different sources, and identify the dominant interaction mode of the current attack based on the dynamic correlation sequence of the dynamic intelligence sequence.

[0214] Step S200: Determine the alarm association link based on the dynamic intelligence sequence, and determine the local information blocking probability according to the information coherence between adjacent intelligence frames in the alarm association link and the change frequency of the dominant interaction mode.

[0215] Step S300: Generate a compensation factor based on the alarm handling channel information in the alarm event handling receipt and based on network interaction characteristics.

[0216] Step S400: Within each preset allocation cycle, adjust the resource quota and alarm aggregation judgment threshold of the alarm handling channel according to the compensation factor.

[0217] To avoid system oscillations caused by global parameter tuning and to improve overall alarm processing efficiency, some possible implementations adopt a strategy of focusing on allocating sparse regions and maintaining high-interaction regions stably.

[0218] For example, Figure 7 This is a flowchart of another data alarm processing method provided in an embodiment of this application. The method includes the following steps S71 to S76: S71: Real-time collection and integration of multi-source heterogeneous threat data, unified time benchmark alignment, unified field caliber and quality labeling for structured alarms and unstructured contexts, generating dynamic intelligence sequences with spatiotemporal correlations; S72: Extract event feature vectors and context semantic embedding vectors, generate dynamic correlation degree according to hierarchical judgment method, and determine the correlation level based on entity consistency, semantic consistency and temporal proximity in turn, and identify the attack intent-driven interaction mode according to the dynamic correlation degree sequence within the sliding time window. S73: Perform coupling sufficiency detection along the alarm association link. Coupling sufficiency detection includes entity continuity detection, attack phase consistency detection and semantic drift detection. Combined with the change frequency of the dominant interaction mode, the detection results are converted into local information blocking probability levels according to preset mapping rules. S74: Collect network topology space interaction data to construct an interaction graph, count the interaction frequency by partition and locate low-frequency interaction areas as sparse areas of intent response, and generate alarm efficiency fluctuation coefficient by combining dynamic correlation and repeated triggering characteristics. S75: Based on the handling receipt, establish a mapping between the sparse area and the alarm handling channel response delay, and generate a compensation factor matrix to indicate the adjustment direction of resource quota parameters and aggregation threshold parameters; S76: Based on the alarm efficiency fluctuation coefficient and compensation factor matrix, dynamically adjust the resource quota parameter set and alarm aggregation judgment threshold parameter set of each alarm processing channel to control the blocking probability and maintain the dynamic correlation, thereby reducing redundant alarms.

[0219] In this embodiment of the application, by constructing a closed-loop optimization mechanism that integrates multi-source threat data collection and alignment, dual-vector fusion of alarm events and context, and linkage between associated link blocking assessment and resource threshold allocation, it is possible to achieve highly consistent fusion of network threat intelligence under multi-source heterogeneous conditions and adaptive reduction of redundant alarms.

[0220] By performing unified time base alignment, field standardization, and quality labeling on structured alerts and unstructured attack contexts, a dynamic intelligence sequence with spatiotemporal correlation is formed, which helps to reduce correlation bias caused by inconsistent data standards from different sources and out-of-order arrival.

[0221] Building upon this foundation, a dynamic correlation degree is generated based on hierarchical judgments of entity consistency, semantic consistency, and temporal proximity, identifying attack intent-driven interaction patterns. This allows alarm aggregation to no longer rely solely on static rules but instead align with the progressive characteristics of the attack chain. Furthermore, coupling sufficiency detection is performed along the alarm correlation chain, quantifying the probability of local information blockage. Combined with low-frequency areas of network topology interaction, sparse regions of intent response are located, generating an alarm efficiency fluctuation coefficient to indicate changes in redundancy and handling pressure. Subsequently, a mapping between sparse regions and handling channel response delays is established based on handling receipts, and a compensation factor matrix is ​​constructed. The resource quotas and aggregation thresholds of the handling channels are dynamically adjusted and subjected to controlled verification and backoff convergence. This significantly improves the alarm signal-to-noise ratio and handling throughput without losing critical evidence chains, reduces the risk of false suppression and missed detections, shortens the average response time of critical threats, and enhances the stability and engineering efficiency of security operations.

[0222] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the methods described in the above embodiments.

[0223] For the method embodiments and computer program product embodiments, since they basically correspond to the system embodiments, the relevant parts can be referred to in the description of the system embodiments. Furthermore, the system embodiments described above are illustrative; the modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, i.e., they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0224] Figure 8 This is a hardware schematic diagram of an electronic device provided in an embodiment of this application.

[0225] For example, device 800 can be a mobile phone, computer, server, digital broadcasting terminal, messaging device, game console, tablet device, medical device, fitness equipment, personal digital assistant, etc.

[0226] Device 800 may include one or more of the following components: processing component 801, memory 802, power supply component 803, multimedia component 804, audio component 805, input / output (I / O) interface 806, sensor component 807, and communication component 808.

[0227] Processing component 801 typically controls the overall operation of device 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 801 may include one or more processors 809 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 801 may include one or more modules to facilitate interaction between processing component 801 and other components. For example, processing component 801 may include a multimedia module to facilitate interaction between multimedia component 804 and processing component 801.

[0228] Memory 802 is configured to store various types of data to support the operation of device 800. Examples of this data include instructions for any application or method operating on device 800, contact data, phonebook data, messages, pictures, videos, etc. Memory 802 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0229] Power supply component 803 provides power to various components of device 800. Power supply component 803 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to device 800.

[0230] Multimedia component 804 includes a screen that provides an output interface between the device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, swipe, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 804 includes a front-facing camera and / or a rear-facing camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0231] Audio component 805 is configured to output and / or input audio signals. For example, audio component 805 includes a microphone (MIC) configured to receive external audio signals when device 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 802 or transmitted via communication component 808. In some embodiments, audio component 805 also includes a speaker for outputting audio signals.

[0232] Input / output (I / O) interface 806 provides an interface between processing component 801 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, start buttons, and lock buttons.

[0233] Sensor assembly 807 includes one or more sensors for providing status assessments of various aspects of device 800. For example, sensor assembly 807 can detect the on / off state of device 800, the relative positioning of components such as the display and keypad of device 800, changes in the position of device 800 or a component of device 800, the presence or absence of user contact with device 800, the orientation or acceleration / deceleration of device 800, and temperature changes of device 800. Sensor assembly 807 may also include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 807 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 807 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.

[0234] Communication component 808 is configured to facilitate wired or wireless communication between device 800 and other devices. Device 800 can access wireless networks based on communication standards, such as WiFi, 2G or 3G, 4G or 5G, or combinations thereof. In one exemplary embodiment, communication component 808 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 808 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0235] In an exemplary embodiment, device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described in any of the above embodiments.

[0236] In an exemplary embodiment, this application also provides a non-transitory computer-readable storage medium including instructions, such as a memory 802 including instructions, which can be executed by a processor 809 of a device 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

Claims

1. A data alarm system, characterized in that, include: The pattern recognition module is used to generate a dynamic intelligence sequence with spatiotemporal correlation based on alarm information from different sources, and to identify the dominant interaction pattern of the current attack based on the dynamic correlation sequence of the dynamic intelligence sequence; the dynamic correlation sequence includes correlation levels arranged in chronological order, and the correlation level is determined based on candidate pairings composed of alarm events of the current intelligence frame and the context of adjacent intelligence frames. The blocking probability determination module is used to determine the alarm association link based on the dynamic intelligence sequence, and to determine the local information blocking probability based on the information coherence between adjacent intelligence frames in the alarm association link and the change frequency of the dominant interaction mode. The compensation factor determination module is used to: construct a response delay sample table based on alarm event handling receipts, with the combination of intent response sparsity region and handling channel as the index key; determine the predicted response delay level and delay sensitivity level corresponding to the index key according to the response delay sample; and generate the compensation factor corresponding to the index key according to the predicted response delay level and delay sensitivity level; wherein, the intent response sparsity region is determined based on network interaction characteristics. The allocation and processing module is used to adjust the resource quota and alarm aggregation judgment threshold of the alarm handling channel according to the compensation factor within each preset allocation cycle, so that the probability of local information blocking is within a preset controlled range.

2. The system according to claim 1, characterized in that, The dynamic intelligence sequence includes multiple intelligence frames arranged in chronological order, each intelligence frame including a structured alarm event in the same time slice and the context associated with the alarm event; The system also includes a data preprocessing module, which is used to acquire the alarm events and the context based on different observation sources, and merge the alarm events and the context of the same time slice to form the intelligence frame.

3. The system according to claim 2, characterized in that, The candidate pairing includes the event feature vector corresponding to the alarm event and the context semantic embedding vector corresponding to the context; The pattern recognition module is also used for: Based on preset structured rules, the event feature vector corresponding to the alarm event is obtained; Based on a preset semantic encoding model, obtain the context semantic embedding vector corresponding to the context.

4. The system according to claim 2, characterized in that, When the pattern recognition module is used to determine the association level, it is specifically used for: Based on the source entity identifier, destination entity identifier, and key object entity identifier, the candidate pairings are judged for entity consistency. If the entity consistency determination result meets the first preset condition, the candidate pairing is semantically consistent based on the entity semantic similarity. If the semantic consistency determination result meets the second preset condition, the temporal proximity determination is performed on the candidate pairing; The association level is determined based on the entity consistency determination result, the semantic consistency determination result, and the temporal proximity determination result.

5. The system according to claim 1, characterized in that, When identifying the dominant interaction pattern of the current attack, the pattern recognition module is specifically used for: Based on the intelligence frames within the time range corresponding to the first preset sliding time window, a transfer sequence for the corresponding association level is determined. The transfer sequence is used to indicate the change in the association level of adjacent intelligence frames. Based on the transition sequence, multiple corresponding interaction modes are determined by querying a preset pattern dictionary; The dominant interaction mode is determined based on the frequency of occurrence and continuous duration of the multiple interaction modes.

6. The system according to claim 1, characterized in that, The blocking probability determination module is also used to detect the information coherence between adjacent intelligence frames in the alarm association link, specifically for: Based on the source entity identifier, destination entity identifier, and key object entity identifier corresponding to adjacent intelligence frames, entity continuity detection is performed on adjacent intelligence frames. Based on the attack phase markers corresponding to adjacent intelligence frames, the attack phase consistency of adjacent intelligence frames is checked by querying a preset attack phase progression rule table. By querying a pre-defined semantic embedding similarity interval mapping table, semantic drift detection is performed on the context of adjacent intelligence frames.

7. The system according to claim 1, characterized in that, The system also includes an alarm efficiency determination module, used to determine the intent response sparse region based on the network interaction characteristics; The compensation factor determination module is further configured to generate a corresponding compensation factor based on the combination relationship between the response sparsity region and the processing channel.

8. The system according to claim 7, characterized in that, When determining the sparse region of the intent response, the alarm efficiency determination module is specifically used for: An interaction graph is constructed based on the aforementioned network interaction features; Based on the preset security domain configuration table, network address planning table, and business asset grouping table, the interaction graph is divided into multiple partitions; The interaction frequency of each partition is determined based on the window length parameter and step parameter of the second preset sliding time window; the interaction frequency includes the increment of the number of edges within the partition, the number of times the cross-partition edge is triggered, and the number of times the path is traversed; Based on the preset threshold configuration, determine whether the partition is an intention response sparse region.

9. The system according to claim 8, characterized in that, The alarm efficiency determination module is also used for: Based on the window length parameter and step parameter of the second preset sliding time window, the alarm repetition triggering characteristics of each partition are determined; the alarm repetition triggering characteristics include repetition triggering density, repetition triggering duration and the number of assets covered by repetition triggering; Based on a preset fluctuation range mapping table, the corresponding alarm efficiency fluctuation coefficient is determined according to the alarm repetitive triggering characteristics and the dynamic correlation sequence of the corresponding time. The compensation factor determination module is further configured to determine the compensation factor based on the alarm efficiency fluctuation coefficient.

10. The system according to claim 9, characterized in that, The compensation factor determination module, when used to generate the compensation factor, is specifically used for: Based on the alarm event handling receipt, a response delay sample table is constructed with the combination of the intent response sparse region and the handling channel as the index key; Based on the response delay sample, the predicted response delay level and delay sensitivity level corresponding to the index key are determined by querying the preset response delay level range table and sensitivity level range table mapping. Based on the alarm efficiency fluctuation coefficient, the predicted response delay level, and the delay sensitivity level, the compensation factor corresponding to the index key is determined by querying a preset adjustment rule table. Each rule in the adjustment rule table includes the scope of application for sparse area identifiers and the scope of application for disposal channel identifiers.

11. The system according to claim 1, characterized in that, The blending and processing module is also used for: Based on the compensation factor, adjust the resource quota parameters and aggregation threshold parameters corresponding to the alarm handling channel; Within each preset allocation cycle, the dynamic correlation sequence and the local information blocking probability are re-determined based on the adjusted parameters; If the dynamic correlation sequence indicates that the dynamic correlation of the intelligence frame sequence remains valid within the current allocation cycle, and the local information blocking probability is within a preset controlled range, the current parameter is archived as an effective configuration and enters the next allocation cycle; otherwise, the current parameter is rolled back until the parameter is archived as an effective configuration.

12. The system according to claim 11, characterized in that, The dynamic correlation sequence includes multiple dynamic correlation validity markers arranged in chronological order; The dynamic correlation degree remains effective, including: within the current allocation cycle, the proportion of the dynamic correlation degree marked as effective is greater than or equal to a preset proportion threshold.

13. The system according to claim 11, characterized in that, The aggregation threshold parameters include time window threshold parameters and suppression threshold parameters; When the allocation processing module is used to roll back the current parameters, it is specifically used for: According to the preset rollback rules, and in accordance with the preset single-cycle adjustment step size upper limit, the time window threshold parameter and the suppression threshold parameter are adjusted from the current value to the value of the previous adjustment cycle.

14. A data alarm processing method, characterized in that, include: A dynamic intelligence sequence with spatiotemporal correlation is generated based on alarm information from different sources, and the dominant interaction mode of the current attack is identified based on the dynamic correlation sequence of the dynamic intelligence sequence. The dynamic correlation sequence includes correlation levels arranged in chronological order, and the correlation level is determined based on candidate pairings composed of alarm events of the current intelligence frame and the context of adjacent intelligence frames. Based on the dynamic intelligence sequence, an alarm association link is determined, and based on the information coherence between adjacent intelligence frames in the alarm association link and the change frequency of the dominant interaction mode, the probability of local information blocking is determined. Based on alarm event handling receipts, a response latency sample table is constructed with the combination of intent response sparse region and handling channel as the index key; according to the response latency sample, the predicted response latency level and latency sensitivity level corresponding to the index key are determined; according to the predicted response latency level and latency sensitivity level, the compensation factor corresponding to the index key is generated; wherein, the intent response sparse region is determined based on network interaction characteristics; Within each preset allocation cycle, the resource quota and alarm aggregation judgment threshold of the alarm handling channel are adjusted according to the compensation factor so that the probability of local information blockage is within a preset controlled range.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in claim 14.

16. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method of claim 14.

17. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in claim 14.

Citation Information

Patent Citations

  • Operation and maintenance alarm intelligent filtering and grading processing method based on adaptive algorithm

    CN121560596A

  • Alarm correlation analysis method and device and storage medium

    CN121664614A