Threat event processing method and device
By identifying and aggregating threat events from the same attack node and generating security events, the problem of low processing efficiency in existing technologies is solved, and efficient and accurate threat event processing is achieved.
Patent Information
- Application Number
- CN201911406184.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-12-31
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2039-12-31
AI Technical Summary
The existing technology is inefficient in processing threat events on terminals and networks and cannot match actual threat events, resulting in poor protection effects.
By identifying threat events from the same attack node and performing aggregation processing, security events are generated, and threat events are aggregated and processed using rule models or machine learning models.
Significantly reduce the number of events to be processed, improve processing efficiency and accuracy, and achieve rapid and accurate protection against threat events.
Smart Images

Figure CN113132306B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security technology, and in particular to a threat event processing method and device. Background Art
[0002] Computer and internet technologies have advanced rapidly. However, security threats targeting devices and networks (such as enterprise and user networks) continue to emerge. To ensure device and network security, after detecting a threat, each detected threat is typically addressed individually.
[0003] However, during the implementation process, the inventors discovered that the existing technology has the following defects: the existing technology uses a method of processing each threat event one by one, and its processing efficiency is very low. Especially when the number of threat events is large, it is impossible to achieve rapid protection of terminals and networks; and the existing technology uses a method of processing a threat event based on the information of a single threat event, so that the processing method for each threat event cannot match the actual threat event, thereby reducing the processing efficiency of threat events, which is not conducive to the effective protection of terminals and networks. Summary of the Invention
[0004] In view of the above problems, the present invention is proposed to provide a threat event processing method and apparatus that overcome the above problems or at least partially solve the above problems.
[0005] According to one aspect of the present invention, a method for handling a threat event is provided, comprising:
[0006] Get threat event information for multiple threat events:
[0007] identifying threat events corresponding to the same attack node based on threat event information of the multiple threat events;
[0008] Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0009] According to another aspect of the present invention, there is provided a threat event processing apparatus, comprising:
[0010] The threat event acquisition module is suitable for obtaining threat event information of multiple threat events:
[0011] an identification module, adapted to identify threat events corresponding to the same attack node based on threat event information of the multiple threat events;
[0012] The aggregation module is adapted to aggregate the multiple threat events based on the identification results to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0013] According to another aspect of the present invention, there is provided a computing device comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus;
[0014] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute operations corresponding to the above-mentioned threat event processing method.
[0015] According to another aspect of the present invention, a computer storage medium is provided, wherein the storage medium stores at least one executable instruction, and the executable instruction enables a processor to execute operations corresponding to the above-mentioned threat event processing method.
[0016] According to the threat event processing method and device provided by the present invention, threat event information of multiple threat events is obtained: based on the threat event information of multiple threat events, threat events corresponding to the same attack node are identified; based on the identification results, multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events; a security event is formed by the aggregation of several threat events. This solution can aggregate a large number of threat events into a small number of security events by aggregating threat events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy; further, this solution specifically aggregates threat events based on attack nodes, thereby aggregating several threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events.
[0017] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0019] Figure 1A schematic diagram showing a flow chart of a threat event processing method provided by an embodiment of the present invention;
[0020] Figure 2 A schematic diagram showing a flow chart of a threat event processing method provided by another embodiment of the present invention;
[0021] Figure 3 A schematic diagram showing a flow chart of a threat event processing method provided by another embodiment of the present invention;
[0022] Figure 4 A schematic diagram showing the structure of a threat event processing device provided by an embodiment of the present invention is shown;
[0023] Figure 5 A schematic structural diagram of a computing device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0024] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.
[0025] Figure 1 A flowchart illustrating a threat event handling method provided by one embodiment of the present invention is shown. The threat event handling method provided by this embodiment can be applied to a variety of security protection platforms (such as security protection platforms for enterprise networks or security protection platforms for user personal networks, etc.). Furthermore, the threat event handling method provided by this embodiment can be executed by a computing device with corresponding computing capabilities, and this embodiment does not limit the specific type of computing device.
[0026] like Figure 1 As shown, the method includes:
[0027] Step S110: Acquire threat event information of multiple threat events.
[0028] In the actual implementation process, threat events in the object to be protected (the object to be protected may be an enterprise network, etc.) are first detected. Optionally, in order to facilitate the rapid detection of threat events and thereby improve the overall execution efficiency of the method, this embodiment may adopt corresponding threat detection rules to detect threat events. Among them, this embodiment does not limit the specific type and content of the threat detection rules, and those skilled in the art may select corresponding threat detection rules according to actual business needs. Moreover, this embodiment does not limit the specific type of threat events, for example, the threat event may be a threat event directed at the terminal, or a threat event directed at the network side; it may also be a threat event directed at a certain type of information or application (such as a threat event directed at emails, files, and / or text messages, etc.).
[0029] Furthermore, after detecting a threat event, to facilitate subsequent aggregation processing of the threat event, this embodiment can further obtain threat event information for multiple threat events. Optionally, the threat event information can specifically include: asset information (such as specific business information, personnel information, etc.), terminal process information, intelligence information (such as intelligence interface information, etc.), and risk level information.
[0030] Step S120: identifying threat events corresponding to the same attack node according to threat event information of multiple threat events.
[0031] Different from the prior art method of processing each detected threat event one by one, this embodiment performs aggregate processing on multiple threat events based on various attack nodes.
[0032] In the process of aggregating multiple threat events based on various attack nodes, threat events corresponding to the same attack node are first identified based on the threat event information of the multiple threat events. The attack node in this embodiment is specifically a node that most attack behaviors must pass through. Optionally, the attack node includes at least one of the following nodes: a port scanning node, a vulnerability scanning node, a vulnerability attack node, a Trojan horse implantation node, a password cracking node, a key information tampering node, and a high-risk event node, etc. In this embodiment, the specific attack node type is not limited, and those skilled in the art can set the corresponding attack node according to actual business conditions. For example, if threat event A and threat event B are both scanning events targeting high-risk port X, then it is determined that threat event A and threat event B correspond to the same attack node.
[0033] Step S130: Based on the identification result, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0034] Since threat events corresponding to the same attack node have the same attack characteristics, this step further aggregates multiple threat events based on the identification result obtained in step S120. By aggregating several threat events, corresponding security events are formed, so that several threat events can be processed by processing one security event, thereby significantly reducing the number of events to be processed and improving processing efficiency. Moreover, when processing a security event, the processing method of the security event can be determined based on the threat event information of several threat events corresponding to the security event, so that the security event can be analyzed comprehensively, which is conducive to improving processing accuracy.
[0035] As can be seen, in this embodiment, threat event information of multiple threat events is obtained, and further, based on the threat event information of the multiple threat events, threat events corresponding to the same attack node are identified; based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events; wherein, a security event is formed by the aggregation of multiple threat events. By aggregating threat events, this embodiment can aggregate a large number of threat events into a small number of security events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy; further, in this embodiment, threat events are aggregated specifically based on attack nodes, thereby aggregating multiple threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events.
[0036] Figure 2 FIG2 shows a flowchart of a method for handling threat events according to another embodiment of the present invention. Figure 1 Further optimization of the method shown.
[0037] like Figure 2 As shown, the method includes:
[0038] Step S210: Acquire threat event information of multiple threat events.
[0039] Step S220: Based on the pre-generated rule model, according to the threat event information of multiple threat events, identify the threat events corresponding to the same attack node, and based on the identification results, aggregate the multiple threat events to generate at least one security event corresponding to the multiple threat events.
[0040] In this embodiment, a corresponding rule model is pre-generated to facilitate the aggregation of threat events. This rule model includes at least one identification rule and at least one aggregation rule. The identification rule is used to identify threat events corresponding to the same attack node, while the aggregation rule is used to aggregate multiple threat events based on the identification results. The identification rules and / or aggregation rules included in the rule model can be combined to aggregate multiple threat events into a single security event.
[0041] Since the identification rules and aggregation rules in the rule model of this embodiment can be dynamically added, deleted or changed according to actual business needs, it is ensured that the identification rules and aggregation rules in the rule model can meet the aggregation processing requirements of different threat events, thereby improving the scope of application of this method; and it is possible to generate matching rule models for different objects to be protected, thereby realizing customization of the rule model and having high scalability.
[0042] Specifically, this embodiment accurately aggregates multiple threat events into one security event by combining one or more of the following methods:
[0043] Implementation Method 1: Based on threat event information from multiple threat events, threat events corresponding to the same attack node are identified. For any attack node, the threat events corresponding to that attack node are aggregated to generate a security event corresponding to that attack node. In this implementation method, threat events corresponding to the same attack node are directly aggregated into a single security event, thereby assigning each security event to a single attack node. This security event allows for comprehensive and customized attack information about the attack node, facilitating specialized processing for each attack node. In the actual implementation process, an attack node can correspond to one or more identification rules. When an attack node can correspond to one identification rule, the threat event information of the threat event is matched with the identification rule to determine whether the threat event corresponds to the attack node. When an attack node can correspond to multiple identification rules, the threat event information of the threat event is matched with the multiple identification rules respectively. Based on the matching results and the relationship between the multiple identification rules, it is comprehensively determined whether the threat event corresponds to the attack node. After the threat event corresponding to the attack node is determined, the aggregation rule corresponding to the attack node is further used to aggregate the threat event corresponding to the attack node to generate a corresponding security event.
[0044] Implementation method 2: Based on the threat event information of multiple threat events, identify threat events corresponding to the same attack node; obtain multiple related attack nodes; aggregate the threat events corresponding to the multiple attack nodes to generate security events corresponding to the multiple attack nodes. The multiple related attack nodes correspond to the same attack scenario. In this embodiment, the threat events corresponding to the same attack scenario are aggregated to generate security events that match each attack scenario. This implementation method enables the generated security events to fully reflect the attack characteristics of the corresponding attack scenario, facilitating specialized analysis and processing of different attack scenarios. In the specific implementation process, the attack nodes involved in different attack scenarios can be pre-determined. For example, in attack scenario P targeting terminal USER1, it generally involves an early high-risk port scanning node (attack node A), a mid-term high-risk port attack node (attack node B), and a late-stage log cleaning node (attack node C). The threat events corresponding to attack node A, attack node B and attack node C can be determined respectively according to the identification rules corresponding to attack node A, attack node B and attack node C, and then the security events corresponding to the attack scenario P can be obtained by aggregation processing through the aggregation rules corresponding to the attack scenario P.
[0045] Step S230: Generate alarm information corresponding to the security event, and send the alarm information to a processing node that matches the security event.
[0046] To facilitate rapid processing of security events, this embodiment further generates alert information corresponding to the security event after generating the security event. Because the processing of steps S210 and S220 can aggregate large-scale threat events into small-scale security events, the number of alert information corresponding to the security events generated in this step is significantly reduced.
[0047] Furthermore, according to a pre-stored mapping table of security events and processing nodes, the alarm information can be sent to a processing node that matches the security event, so that the processing node can quickly process the security event.
[0048] Thus, it can be seen that this embodiment can aggregate a large number of threat events into a small number of security events through the aggregation processing of threat events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy. Furthermore, this embodiment specifically aggregates threat events based on attack nodes, thereby aggregating several threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events. In addition, this embodiment adopts a rule model to achieve aggregation of threat events, which expands the scope of application of this method, facilitates customized protection of the protection object, and has high scalability. Moreover, this embodiment can generate security events that can reflect the characteristics of the attack node and security events that reflect the characteristics of the attack scenario based on business needs, facilitate specialized processing for each attack node and attack scenario, thereby improving processing accuracy. In addition, this embodiment also generates alarm information corresponding to the security event and sends the alarm information to the processing node that matches the security event, which is conducive to the rapid processing of security events, thereby achieving timely protection of the protection object.
[0049] Figure 3 FIG2 shows a flowchart of a method for handling a threat event according to another embodiment of the present invention. Figure 1 Further optimization of the method shown.
[0050] like Figure 3 As shown, the method includes:
[0051] Step S310: Acquire threat event information of multiple threat events.
[0052] Step S320: Based on the pre-trained machine learning model, according to the threat event information of multiple threat events, identify the threat events corresponding to the same attack node, and based on the identification results, aggregate the multiple threat events to generate at least one security event corresponding to the multiple threat events.
[0053] In this embodiment, a machine learning model is pre-generated and trained using threat event information from historical threat events. This embodiment does not limit the specific structure of the machine learning model. For example, the machine learning model may include an input layer, at least one fully connected layer, and an output layer.
[0054] In the process of training a machine learning model using historical data (specifically, threat event information of historical threat events), the acquired threat event information of historical threat events may be pre-cleaned to remove invalid data from the historical data (e.g., stop words, etc.); further, feature extraction is performed on the cleaned historical data, and the extracted data features are converted into corresponding feature vectors. The generated feature vectors are labeled with the attack node identifier or security event identifier to which they belong, and then further input into the generated machine learning model for model training. When the loss function or other evaluation function in the machine learning model is less than a preset threshold, the training is terminated and the trained machine learning model is output.
[0055] During the execution of this step, the threat event information of multiple threat events can be converted into corresponding input vectors and input into the trained machine learning model. In one embodiment, the attack nodes corresponding to each threat event output by the machine learning model can be received; then, for any attack node, the threat events corresponding to the attack node are aggregated to generate a security event corresponding to the attack node; or multiple attack nodes with correlation are obtained, and the threat events corresponding to the multiple attack nodes are aggregated to generate security events corresponding to the multiple attack nodes; in another embodiment, the security events corresponding to each threat event output by the machine learning model can be directly received, so as to aggregate the threat events corresponding to the same security event.
[0056] In this embodiment, by utilizing a machine learning model, threat events can be automatically aggregated, with high processing efficiency and high aggregation accuracy.
[0057] Step S330: Generate alarm information corresponding to the security event, and send the alarm information to a processing node that matches the security event.
[0058] It can be seen that this embodiment can aggregate a large number of threat events into a small number of security events through the aggregation processing of threat events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy; further, this embodiment specifically aggregates threat events based on attack nodes, thereby aggregating several threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events; in addition, this embodiment adopts a machine learning model to realize the aggregation of threat events, thereby improving the aggregation accuracy and aggregation efficiency of threat events; and this embodiment can generate security events that can reflect the characteristics of attack nodes and security events that reflect the characteristics of attack scenarios based on business needs, which facilitates specialized processing for each attack node and attack scenario, thereby improving processing accuracy; in addition, this embodiment also generates alarm information corresponding to the security event and sends the alarm information to the processing node that matches the security event, which is conducive to the rapid processing of security events, thereby achieving timely protection of the protected object.
[0059] Figure 4 FIG. 1 shows a schematic diagram of the structure of a threat event processing device provided by an embodiment of the present invention. Figure 4 As shown, the device includes: a threat event acquisition module 41, an identification module 42, and an aggregation module 43.
[0060] The threat event acquisition module 41 is adapted to acquire threat event information of multiple threat events:
[0061] an identification module 42 adapted to identify threat events corresponding to the same attack node based on threat event information of the plurality of threat events;
[0062] The aggregation module 43 is adapted to aggregate the multiple threat events based on the identification results to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0063] Optionally, the aggregation module is further adapted to: for any attack node, aggregate the threat events corresponding to the attack node to generate a security event corresponding to the attack node.
[0064] Optionally, the aggregation module is further adapted to: obtain a plurality of attack nodes having correlation;
[0065] The threat events corresponding to the multiple attack nodes are aggregated to generate security events corresponding to the multiple attack nodes.
[0066] Optionally, the multiple associated attack nodes correspond to the same attack scenario.
[0067] Optionally, the identification module is further adapted to: identify threat events corresponding to the same attack node based on threat event information of the multiple threat events based on a pre-generated rule model;
[0068] The aggregation module is further adapted to: perform aggregation processing on the multiple threat events based on a pre-generated rule model and an identification result, so as to generate at least one security event corresponding to the multiple threat events.
[0069] Optionally, the identification module is further adapted to: identify threat events corresponding to the same attack node based on threat event information of the multiple threat events based on a pre-trained machine learning model;
[0070] The aggregation module is further adapted to: perform aggregation processing on the multiple threat events based on a pre-trained machine learning model and an identification result to generate at least one security event corresponding to the multiple threat events.
[0071] Optionally, the threat event information includes at least one of the following information:
[0072] Asset information, terminal process information, intelligence information, and risk level information.
[0073] Optionally, the attack node includes at least one of the following nodes:
[0074] Port scanning node, vulnerability scanning node, vulnerability attack node, Trojan horse implantation node, password cracking node, key information tampering node, and high-risk event node.
[0075] Optionally, the device further includes: an alarm module, adapted to generate alarm information corresponding to the security event after generating at least one security event corresponding to the multiple threat events.
[0076] Optionally, the device further includes: a sending module, adapted to send the alarm information corresponding to the security event to a processing node matching the security event after the alarm information corresponding to the security event is generated.
[0077] The specific implementation process of each module in this embodiment can refer to the description of the corresponding part in the method embodiment, and this embodiment will not be repeated here.
[0078] It can be seen that this solution can aggregate a large number of threat events into a small number of security events through the aggregation processing of threat events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy; further, this solution specifically aggregates threat events based on attack nodes, thereby aggregating several threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events.
[0079] According to one embodiment of the present invention, a non-volatile computer storage medium is provided. The computer storage medium stores at least one executable instruction. The computer executable instruction can execute the threat event processing method in any of the above method embodiments.
[0080] It can be seen that this solution can aggregate a large number of threat events into a small number of security events through the aggregation processing of threat events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy; further, this solution specifically aggregates threat events based on attack nodes, thereby aggregating several threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events.
[0081] Figure 5 A schematic structural diagram of a computing device provided according to an embodiment of the present invention is shown. The specific embodiment of the present invention does not limit the specific implementation of the computing device.
[0082] like Figure 5 As shown, the computing device may include: a processor (processor) 502 , a communications interface (Communications Interface) 504 , a memory (memory) 506 , and a communication bus 508 .
[0083] Processor 502, communication interface 504, and memory 506 communicate with each other via communication bus 508. Communication interface 504 is used to communicate with other devices, such as clients or other server network elements. Processor 502 is used to execute program 510, which may specifically perform the steps described in the above method embodiments.
[0084] Specifically, the program 510 may include program codes, which include computer operation instructions.
[0085] Processor 502 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The one or more processors included in a computing device may be processors of the same type, such as one or more CPUs, or processors of different types, such as one or more CPUs and one or more ASICs.
[0086] The memory 506 is used to store the program 510. The memory 406 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0087] The program 510 may be specifically configured to enable the processor 502 to perform the following operations:
[0088] Get threat event information for multiple threat events:
[0089] identifying threat events corresponding to the same attack node based on threat event information of the multiple threat events;
[0090] Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0091] In an optional implementation, the program 510 may be specifically configured to cause the processor 502 to perform the following operations:
[0092] For any attack node, the threat events corresponding to the attack node are aggregated to generate a security event corresponding to the attack node.
[0093] In an optional implementation, the program 510 may be specifically configured to cause the processor 502 to perform the following operations:
[0094] Obtain multiple attack nodes with correlation;
[0095] The threat events corresponding to the multiple attack nodes are aggregated to generate security events corresponding to the multiple attack nodes.
[0096] In an optional implementation, the multiple associated attack nodes correspond to the same attack scenario.
[0097] In an optional implementation, the program 510 may be specifically configured to cause the processor 502 to perform the following operations:
[0098] Based on a pre-generated rule model, threat events corresponding to the same attack node are identified according to the threat event information of the multiple threat events, and based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events.
[0099] In an optional implementation, the program 510 may be specifically configured to cause the processor 502 to perform the following operations:
[0100] Based on a pre-trained machine learning model, threat events corresponding to the same attack node are identified according to the threat event information of the multiple threat events. Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events.
[0101] In an optional implementation, the threat event information includes at least one of the following information:
[0102] Asset information, terminal process information, intelligence information, and risk level information.
[0103] In an optional embodiment, the attacking node includes at least one of the following nodes:
[0104] Port scanning node, vulnerability scanning node, vulnerability attack node, Trojan horse implantation node, password cracking node, key information tampering node, and high-risk event node.
[0105] In an optional implementation, the program 510 may be specifically configured to cause the processor 502 to perform the following operations:
[0106] After generating at least one security event corresponding to the multiple threat events, generating alarm information corresponding to the security event.
[0107] In an optional implementation, the program 510 may be specifically configured to cause the processor 502 to perform the following operations:
[0108] After generating the alarm information corresponding to the security event, the alarm information is sent to a processing node that matches the security event.
[0109] It can be seen that this solution can aggregate a large number of threat events into a small number of security events through the aggregation processing of threat events, thereby significantly reducing the number of events to be processed, improving processing efficiency, and facilitating the effective processing of security events and improving processing accuracy; further, this solution specifically aggregates threat events based on attack nodes, thereby aggregating several threat events with the same attack characteristics into one security event, thereby improving aggregation accuracy and further improving the processing accuracy of threat events.
[0110] The algorithm or demonstration provided herein are not inherently relevant to any particular computer, virtual system or other equipment. Various general-purpose systems may also be used together with the teachings based on this. According to the above description, it is apparent that the structure required for constructing this type of system. In addition, the embodiment of the present invention is not directed to any specific programming language yet. It should be understood that various programming languages can be utilized to realize the content of the present invention described herein, and the above description of specific languages is for the purpose of disclosing the best mode of the present invention.
[0111] In the description provided herein, numerous specific details are described. However, it is understood that embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.
[0112] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the invention, various features of the embodiments of the invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Accordingly, the claims that follow the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the invention.
[0113] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition may be divided into multiple submodules or subunits or subcomponents. All features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed herein may be combined in any combination, except that at least some of such features and / or processes or units are mutually exclusive. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.
[0114] Furthermore, those skilled in the art will appreciate that although some embodiments herein include certain features included in other embodiments but not other features, combinations of features from different embodiments are intended to be within the scope of the present invention and to form different embodiments. For example, in the claims below, any of the claimed embodiments may be used in any combination.
[0115] The various component embodiments of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components according to an embodiment of the present invention. The present invention can also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for executing a part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
[0116] It should be noted that the above embodiments illustrate rather than limit the invention, and that alternative embodiments may be devised by a person skilled in the art without departing from the scope of the appended claims. In the claims, any reference signs placed between brackets should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising several different elements and by means of appropriately programmed computers. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names. The steps in the above embodiments should not be understood as limiting the order of execution unless otherwise specified.
[0117] The present invention discloses: A1. A method for handling threat events, comprising:
[0118] Get threat event information for multiple threat events:
[0119] identifying threat events corresponding to the same attack node based on threat event information of the multiple threat events;
[0120] Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0121] A2. The method according to A1, wherein, based on the identification results, aggregating the multiple threat events to generate at least one security event corresponding to the multiple threat events further comprises:
[0122] For any attack node, the threat events corresponding to the attack node are aggregated to generate a security event corresponding to the attack node.
[0123] A3. The method according to A1, wherein, based on the identification results, aggregating the multiple threat events to generate at least one security event corresponding to the multiple threat events further comprises:
[0124] Obtain multiple attack nodes with correlation;
[0125] The threat events corresponding to the multiple attack nodes are aggregated to generate security events corresponding to the multiple attack nodes.
[0126] A4. The method according to A3, wherein the multiple associated attack nodes correspond to the same attack scenario.
[0127] A5. The method according to any one of A1 to A4, wherein identifying threat events corresponding to a common attack node based on threat event information of the multiple threat events, and aggregating the multiple threat events based on the identification results to generate at least one security event corresponding to the multiple threat events further comprises:
[0128] Based on a pre-generated rule model, threat events corresponding to the same attack node are identified according to the threat event information of the multiple threat events, and based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events.
[0129] A6. The method according to any one of A1 to A4, wherein identifying threat events corresponding to a common attack node based on threat event information of the multiple threat events, and aggregating the multiple threat events based on the identification results to generate at least one security event corresponding to the multiple threat events further comprises:
[0130] Based on a pre-trained machine learning model, threat events corresponding to the same attack node are identified according to the threat event information of the multiple threat events. Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events.
[0131] A7. The method according to any one of A1 to A6, wherein the threat event information includes at least one of the following:
[0132] Asset information, terminal process information, intelligence information, and risk level information.
[0133] A8. The method according to any one of A1 to A7, wherein the attacking node comprises at least one of the following nodes:
[0134] Port scanning node, vulnerability scanning node, vulnerability attack node, Trojan horse implantation node, password cracking node, key information tampering node, and high-risk event node.
[0135] A9. The method according to any one of A1 to A8, wherein, after generating at least one security event corresponding to the plurality of threat events, the method further comprises:
[0136] Generate alarm information corresponding to the security event.
[0137] A10. The method according to A9, wherein, after generating the alarm information corresponding to the security event, the method further comprises:
[0138] The alarm information is sent to a processing node that matches the security event.
[0139] The present invention also discloses: B11. A threat event processing device, comprising:
[0140] The threat event acquisition module is suitable for obtaining threat event information of multiple threat events:
[0141] an identification module, adapted to identify threat events corresponding to the same attack node based on threat event information of the multiple threat events;
[0142] The aggregation module is adapted to aggregate the multiple threat events based on the identification results to generate at least one security event corresponding to the multiple threat events; wherein one security event is aggregated from several threat events.
[0143] B12. The apparatus according to B11, wherein the aggregation module is further adapted to:
[0144] For any attack node, the threat events corresponding to the attack node are aggregated to generate a security event corresponding to the attack node.
[0145] B13. The apparatus according to B11, wherein the aggregation module is further adapted to:
[0146] Obtain multiple attack nodes with correlation;
[0147] The threat events corresponding to the multiple attack nodes are aggregated to generate security events corresponding to the multiple attack nodes.
[0148] B14. The apparatus according to B13, wherein the plurality of associated attack nodes correspond to the same attack scenario.
[0149] B15. The apparatus according to any one of B11 to B14, wherein the identification module is further adapted to: identify threat events corresponding to the same attack node based on threat event information of the plurality of threat events based on a pre-generated rule model;
[0150] The aggregation module is further adapted to: perform aggregation processing on the multiple threat events based on a pre-generated rule model and an identification result, so as to generate at least one security event corresponding to the multiple threat events.
[0151] B16. The apparatus according to any one of B11 to B14, wherein the identification module is further adapted to: identify threat events corresponding to the same attack node based on threat event information of the plurality of threat events based on a pre-trained machine learning model;
[0152] The aggregation module is further adapted to: perform aggregation processing on the multiple threat events based on a pre-trained machine learning model and an identification result to generate at least one security event corresponding to the multiple threat events.
[0153] B17. The apparatus according to any one of B11 to B16, wherein the threat event information includes at least one of the following:
[0154] Asset information, terminal process information, intelligence information, and risk level information.
[0155] B18. The apparatus according to any one of B11 to B17, wherein the attacking node comprises at least one of the following nodes:
[0156] Port scanning node, vulnerability scanning node, vulnerability attack node, Trojan horse implantation node, password cracking node, key information tampering node, and high-risk event node.
[0157] B19. The apparatus according to any one of B11 to B18, further comprising:
[0158] The alarm module is adapted to generate alarm information corresponding to the security event after generating at least one security event corresponding to the multiple threat events.
[0159] B20. The apparatus according to B19, further comprising:
[0160] The sending module is adapted to send the alarm information corresponding to the security event to a processing node matching the security event after the alarm information corresponding to the security event is generated.
[0161] The present invention also discloses: C21. A computing device, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other via the communication bus;
[0162] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the threat event processing method described in any one of A1-A10.
[0163] The present invention also discloses: D22. A computer storage medium, wherein the storage medium stores at least one executable instruction, wherein the executable instruction enables a processor to execute an operation corresponding to the threat event processing method described in any one of A1-A10.
Claims
1. A method for handling a threat event, comprising: Obtain threat event information for multiple threat events; identifying, based on threat event information of the plurality of threat events, threat events corresponding to a same attack node, wherein the attack node is a node that the attack behavior must pass through, and the attack nodes involved in different attack scenarios are predetermined; Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events, including: obtaining multiple attack nodes with correlation; aggregating the threat events corresponding to the multiple attack nodes to generate security events corresponding to the multiple attack nodes; wherein a security event is aggregated from multiple threat events, and the multiple attack nodes with correlation correspond to the same attack scenario; Generates alarm information corresponding to the security event and sends the alarm information to the processing node matching the security event; Among them, based on the identification results, aggregating the multiple threat events to generate at least one security event corresponding to the multiple threat events further includes: for any attack node, aggregating the threat events corresponding to the attack node to generate a security event corresponding to the attack node.
2. The method according to claim 1, wherein The identifying, based on the threat event information of the multiple threat events, threat events corresponding to the same attack node, and aggregating the multiple threat events based on the identification result to generate at least one security event corresponding to the multiple threat events further includes: Based on a pre-generated rule model, threat events corresponding to the same attack node are identified according to the threat event information of the multiple threat events, and based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events.
3. The method according to claim 1, wherein The identifying, based on the threat event information of the multiple threat events, threat events corresponding to the same attack node, and aggregating the multiple threat events based on the identification result to generate at least one security event corresponding to the multiple threat events further includes: Based on a pre-trained machine learning model, threat events corresponding to the same attack node are identified according to the threat event information of the multiple threat events. Based on the identification results, the multiple threat events are aggregated to generate at least one security event corresponding to the multiple threat events.
4. The method according to any one of claims 1 to 3, wherein The threat event information includes at least one of the following information: Asset information, terminal process information, intelligence information, and risk level information.
5. The method according to claim 1, wherein The attacking node includes at least one of the following nodes: Port scanning node, vulnerability scanning node, vulnerability attack node, Trojan horse implantation node, password cracking node, key information tampering node, and high-risk event node.
6. A threat event processing device, comprising: A threat event acquisition module, adapted to acquire threat event information of multiple threat events; an identification module adapted to identify threat events corresponding to a same attack node based on threat event information of the plurality of threat events, wherein the attack node is a node that the attack behavior must pass through, and the attack nodes involved in different attack scenarios are predetermined; an aggregation module, adapted to aggregate the multiple threat events based on the identification results to generate at least one security event corresponding to the multiple threat events, comprising: obtaining multiple associated attack nodes; aggregating the threat events corresponding to the multiple attack nodes to generate a security event corresponding to the multiple attack nodes; wherein a security event is aggregated from multiple threat events, and the multiple associated attack nodes correspond to the same attack scenario; Generates alarm information corresponding to the security event and sends the alarm information to the processing node matching the security event; Wherein, the aggregation module is further adapted to: For any attack node, the threat events corresponding to the attack node are aggregated to generate a security event corresponding to the attack node.
7. The device according to claim 6, wherein The identification module is further adapted to: identify threat events corresponding to the same attack node based on threat event information of the plurality of threat events based on a pre-generated rule model; The aggregation module is further adapted to: perform aggregation processing on the multiple threat events based on a pre-generated rule model and an identification result, so as to generate at least one security event corresponding to the multiple threat events.
8. The device according to claim 6, wherein The identification module is further adapted to: identify threat events corresponding to the same attack node based on threat event information of the plurality of threat events based on a pre-trained machine learning model; The aggregation module is further adapted to: perform aggregation processing on the multiple threat events based on a pre-trained machine learning model and an identification result to generate at least one security event corresponding to the multiple threat events.
9. The device according to any one of claims 6 to 8, wherein: The threat event information includes at least one of the following information: Asset information, terminal process information, intelligence information, and risk level information.
10. The device according to claim 6, wherein The attacking node includes at least one of the following nodes: Port scanning node, vulnerability scanning node, vulnerability attack node, Trojan horse implantation node, password cracking node, key information tampering node, and high-risk event node.
11. A computing device comprising: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform an operation corresponding to the threat event processing method according to any one of claims 1 to 5.
12. A computer storage medium, wherein the storage medium stores at least one executable instruction, wherein the executable instruction causes a processor to execute operations corresponding to the threat event processing method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Security event handling method and device
CN104753861A
Multi-step attack detection method based on multi-source abnormal event correlation analysis
CN106790186A