Service Access Method, System, Electronic Device and Storage Medium of SOAR Platform
By generating and installing APP package files, the problem of low service expansion efficiency of SOAR platform when facing different security devices and programming languages is solved, and the unified service access and efficiency improvement is achieved.
Patent Information
- Application Number
- CN202111300594.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-04
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-11-04
AI Technical Summary
When facing different security devices and programming languages, the SOAR platform causes developers to need high learning costs to expand services, resulting in low service scaling efficiency.
By obtaining the parameter information of the target service, integrating the APP information description file, generating a code template file based on the programming language information, inputting the docking logic, and generating the APP package file, and installing it to the SOAR platform.
It realizes unified service access for different types of programming languages, reduces the learning costs of developers, and improves the efficiency of SOAR platform service expansion.
Smart Images

Figure CN113961179B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a service access method, system, electronic device, and storage medium for a SOAR platform. Background Art
[0002] SOAR (Security Orchestration, Automation and Response) is a series of functions used to protect IT (Internet Technology) systems from threats. It includes three major functions: case and workflow management, task automation, and centralized management of access, query, and sharing of threat intelligence. The SOAR platform can monitor threat intelligence sources and initiate automatic responses to mitigate security threats.
[0003] With the increasing complexity of the network environment, research on network protection is constantly being practiced. The iteration of various programming languages (such as JAVA, Python, Golang, Ruby, etc.) is also getting faster and faster. The security orchestration based on the SOAR platform relies on various security devices or tools. However, there are differences among various security devices or tools. It is necessary to formulate a unified encapsulation interface and a unified docking standard for the different security devices or various tools, and one should not be limited to the use of a single programming language.
[0004] However, since different developers' proficiency in different programming languages is necessarily different, in the face of the differences in security devices and programming languages, developers need to incur a high learning cost to expand various services of the SOAR platform. This results in a long time consumed and low efficiency in service expansion when expanding the services of the SOAR platform.
[0005] Currently, no effective solution has been proposed for the problem of low service expansion efficiency of the SOAR platform in related technologies. Summary of the Invention
[0006] Embodiments of this application provide a service access method, system, electronic device, and storage medium for a SOAR platform to at least solve the problem of low service expansion efficiency of the SOAR platform in related technologies.
[0007] In a first aspect, an embodiment of the present application provides a service access method for a SOAR platform. The method includes: obtaining parameter information of a target service; integrating the parameter information to generate an APP information description file corresponding to the parameter information; generating a code template file corresponding to the programming language information according to the programming language information in the APP information description file, where, after inputting preset docking logic and / or action logic, the code template file is used to generate an APP package file corresponding to the target service; obtaining the APP package file and first import configuration information corresponding to the APP package file; and installing and storing the APP package file in the SOAR platform according to the first import configuration information.
[0008] In some embodiments, generating a code template file corresponding to the programming language information includes: using the Freemarker engine to generate a code template file corresponding to the programming language information according to the APP information description file, where the APP information description file is in JSON format.
[0009] In some embodiments, the method further includes: starting the APP package file in the SOAR platform according to the programming language information corresponding to the APP package file; and registering the APP package file in a preset registration center when the APP package file is successfully started.
[0010] In some embodiments, the method further includes: obtaining request parameters corresponding to the APP package file, and using the registration center to obtain a call interface address of the APP package file; calling the target service corresponding to the APP package file according to the call interface address, and sending the request parameters to a security device corresponding to the target service; and sending response parameters generated by the security device in response to the request parameters to the SOAR platform.
[0011] In some embodiments, the method further includes: uninstalling the APP package file stored in the SOAR platform, and deleting registration information related to the APP package file in the registration center.
[0012] In some embodiments, the method further includes: obtaining an update file corresponding to the APP package file and second import configuration information corresponding to the update file; and updating the APP package file stored in the SOAR platform according to the second import configuration information and the update file.
[0013] In some embodiments, the parameter information includes at least one of the following: APP information, device parameter information, programming language information, APP request method information, APP function action information.
[0014] In a second aspect, an embodiment of the present application further provides a service access system for a SOAR platform. The system is communicatively connected to the SOAR platform and is configured to execute the service access method for the SOAR platform as described in the first aspect above.
[0015] In a third aspect, an embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the service access method for the SOAR platform as described in the first aspect above.
[0016] In a fourth aspect, an embodiment of the present application further provides a storage medium in which a computer program is stored. When the computer program is executed by a processor, it implements the service access method for the SOAR platform as described in the first aspect above.
[0017] Compared with the related art, the service access method, system, electronic device, and storage medium for the SOAR platform provided by the embodiments of the present application solve the problem of low service expansion efficiency of the SOAR platform in the related art by obtaining parameter information of a target service; integrating the parameter information to generate an APP information description file corresponding to the parameter information; generating a code template file corresponding to the programming language information according to the programming language information in the APP information description file, where, after inputting preset docking logic and / or action logic, the code template file is used to generate an APP package file corresponding to the target service; obtaining the APP package file and first import configuration information corresponding to the APP package file; and installing and storing the APP package file in the SOAR platform according to the first import configuration information, achieving the technical effect of improving the service expansion efficiency of the SOAR platform.
[0018] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more comprehensible. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0020] Figure 1 is a flowchart of the service access method for the SOAR platform according to an embodiment of the present application;
[0021] Figure 2 is a block diagram of the service access system for the SOAR platform according to an embodiment of the present application;
[0022] Figure 3 It is a schematic structural diagram of an electronic device according to an embodiment of the present application. Detailed implementation manners
[0023] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be described and explained below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments provided in the present application without making creative efforts fall within the scope of protection of the present application. In addition, it can also be understood that although the efforts made in such a development process may be complex and time-consuming, for those of ordinary skill in the art related to the content disclosed in the present application, some design, manufacturing or production changes made on the basis of the technical content disclosed in the present application are only conventional technical means and should not be understood that the content disclosed in the present application is insufficient.
[0024] Referring to "embodiment" in the present application means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those of ordinary skill in the art explicitly and implicitly understand that the embodiments described in the present application may be combined with other embodiments without conflict.
[0025] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the ordinary meanings understood by those with ordinary skills in the technical field to which this application belongs. The words such as "a", "an", "one kind", "the" and the like involved in this application do not indicate a quantity limitation and may represent a singular or plural number. The terms "include", "comprise", "have" and any variations thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may further include steps or units not listed, or may further include other steps or units inherent to these processes, methods, products or devices. The words such as "connect", "be connected", "couple" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "multiple" involved in this application means greater than or equal to two. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. The terms "first", "second", "third" and the like involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.
[0026] This embodiment provides a service access method for a SOAR platform. Figure 1 It is a flowchart of the service access method for the SOAR platform according to the embodiment of this application, as Figure 1 shown, and this method includes:
[0027] Step S101, obtain the parameter information of the target service.
[0028] In this embodiment, the parameter information of the target service can be input by developers through the SOAR platform. The parameter information may include the basic information overview of the security device or tool corresponding to the target service to be accessed, such as APP information, device information, programming language, etc.
[0029] In the above embodiment, the device information may include device manufacturer information, device model information, and device-related parameter information. The device-related parameter information may include username, password information, and request parameter information. For example, when the use of a security device requires information such as a username and password, corresponding fields for the relevant username and password need to be defined when obtaining the parameter information of the target service to prepare for the use of this security device; the request parameter information may be the request body parameter information required when calling the interface of this security device, etc.
[0030] Step S102, integrate the parameter information to generate an APP information description file corresponding to the parameter information.
[0031] In this embodiment, the APP information description file includes multiple abstract parameters and the parameter values corresponding to each abstract parameter, and defines the parameter information of the target reset in the structure of JSON (JavaScript Object Notation, simply referred to as JSON) format, which may include APP information, device parameter information, programming language information, APP request method information, and APP function action information.
[0032] Step S103: Generate a code template file corresponding to the programming language information according to the programming language information in the APP information description file. After inputting the preset docking logic and / or action logic, the code template file is used to generate an APP package file corresponding to the target service.
[0033] In this embodiment, according to the programming language information in the APP information description file, a code template file corresponding to the programming language information can be generated. For example, according to the APP function action information included in the APP information description file, a standard action code that conforms to the action standard of the SOAR platform can be automatically generated, and the standard action code does not include the code logic of specific business implementation. The code template file can be directly compiled and run and conforms to the project standard directory of various programming languages.
[0034] In the above embodiment, developers can determine the linkage function or service action of the security device corresponding to the target service according to actual needs, and then input the docking logic corresponding to the security device linkage function and / or the action logic corresponding to the service action of the security device into the code template file for compilation and modification. Adjust the configuration file required for import according to the import standard of the SOAR platform, and after completing the writing of the code template file, package it into an APP package file that conforms to the import standard of the SOAR platform.
[0035] Step S104: Obtain the APP package file and the first import configuration information corresponding to the APP package file.
[0036] In this embodiment, the first import configuration information is the configuration parameter information required to import the APP package file into the SOAR platform adjusted according to the import standard of the SOAR platform. By parsing the first import configuration information, the installation of the APP package file in the SOAR platform can be realized.
[0037] Step S105: Install the APP package file and store it in the SOAR platform according to the first import configuration information.
[0038] In this embodiment, after the APP package file is installed and stored in the SOAR platform, the target service corresponding to the APP package file can be displayed on the front-end interface of the SOAR platform for users to select and use.
[0039] Through the above steps S101 to S105, by obtaining the parameter information of the target service; integrating the parameter information to generate an APP information description file corresponding to the parameter information; generating a code template file corresponding to the programming language information according to the programming language information in the APP information description file, wherein, after inputting the preset docking logic and / or action logic, the code template file is used to generate an APP package file corresponding to the target service; obtaining the APP package file and the first import configuration information corresponding to the APP package file; installing and storing the APP package file in the SOAR platform according to the first import configuration information. According to the programming language information in the APP information description file, a code template file corresponding to the programming language information can be generated. When services with different types of programming language requirements need to be connected to the SOAR platform, through this application, code template files corresponding to different types of programming languages can be automatically generated. After inputting the logic into the code template file, an APP package file corresponding to the target service can be generated, and APP package files of different types of programming languages can be uniformly connected to the SOAR platform, reducing the learning cost of developers learning different types of programming languages, providing linkage service support for the SOAR platform, and achieving the technical effects of service function expansion and service unified management of the SOAR platform. Through this application, the problem of low service expansion efficiency of the SOAR platform in the related technology is solved, and the technical effect of improving the service expansion efficiency of the SOAR platform is achieved.
[0040] In some of these embodiments, generating a code template file corresponding to the programming language information includes: using the Freemarker engine to generate a code template file corresponding to the programming language information according to the APP information description file, wherein the APP information description file is in JSON format.
[0041] In this embodiment, the Freemarker engine is a template engine developed using the JAVA language and is a general tool for generating text based on templates. The Velocity template engine or other custom template engines can also be selected to process the APP information description file to generate the corresponding code template file.
[0042] In the above embodiments, the Freemarker engine may first obtain a code generation template corresponding to the programming language information in the APP information description file. The code generation template includes common content and differential content. The Freemarker engine may extract the information in the APP information description file that matches the differential content in the code generation template, and replace the differential content in the code generation template with this information, thereby obtaining a code template file corresponding to both the programming language information and the APP information description file.
[0043] In some of these embodiments, the method further implements the following steps:
[0044] Step 1, start the APP package file in the SOAR platform according to the programming language information corresponding to the APP package file.
[0045] Step 2, when the APP package file is successfully started, register the APP package file to a preset registration center.
[0046] In this embodiment, the NACOS (Dynamic Naming and Configuration Service, abbreviated as NACOS) can be used to provide the registration center. The registration center stores the configuration information and network information registered by the microservice system, provides the service discovery function. Developers can interface with the security devices or open-source tool interfaces according to different programming languages, provide the APP package file on the SOAR platform, import the APP package file into the SOAR platform and start the APP package file. After successful startup, it is uniformly registered to the registration center, and the APP package file can be scheduled from the registration center for the security orchestration and action management functions of the SOAR platform.
[0047] In some of these embodiments, the method further implements the following steps:
[0048] Step 1, obtain the request parameters corresponding to the APP package file, and use the registration center to obtain the call interface address of the APP package file.
[0049] Step 2, according to the call interface address, call the target service corresponding to the APP package file, and send the request parameters to the security device corresponding to the target service.
[0050] Step 3, send the response parameters generated by the security device in response to the request parameters to the SOAR platform.
[0051] In this embodiment, a gateway can be used to implement communication between the security device and the SOAR platform. For example, Spring Cloud Gateway can be adopted to provide the gateway service. When the target service corresponding to the APP package file needs to be invoked, through a series of filtering and processing by the gateway, the SOAR platform can use standard interfaces (Rest API or gRPC) to invoke the target service corresponding to the APP package file according to the invocation interface address of the APP package file, and call different underlying security devices or tools through the APP package file to perform relevant security operations.
[0052] In the above embodiment, the APP package file can encapsulate the processing request parameters and use the request parameters to request the real security device or tool, and receive the response parameters (corresponding result information of failure or success) of the security device or tool, and perform parsing, standardization processing, etc. on the response parameters so that the response parameters can conform to the standards of the SOAR platform.
[0053] In some of these embodiments, the method further includes the following steps:
[0054] Step 1, obtain the update file corresponding to the APP package file and the second import configuration information corresponding to the update file.
[0055] Step 2, update the APP package file stored in the SOAR platform according to the second import configuration information and the update file.
[0056] In this embodiment, the method further includes: uninstalling the APP package file stored in the SOAR platform, and deleting the registration information related to the APP package file in the registration center.
[0057] In this embodiment, when the APP package file needs to be updated and upgraded, the update file corresponding to the APP package file and the second import configuration information corresponding to the update file can be obtained, and the APP package file stored in the SOAR platform can be updated according to the second import configuration information and the update file; when the APP package file needs to be deleted, the APP package file stored in the SOAR platform can be uninstalled according to the first import configuration information to achieve plug-and-play statelessness and dependency-free.
[0058] This embodiment provides a service access system for the SOAR platform 21. Figure 2It is a structural block diagram of a service access system of the SOAR platform 21 according to an embodiment of the present application. As shown in the figure, the system 20 is communicatively connected to the SOAR platform 21. The system 20 is configured to obtain parameter information of a target service; integrate the parameter information to generate an APP information description file corresponding to the parameter information; generate a code template file corresponding to the programming language information according to the programming language information in the APP information description file. Among them, after inputting preset docking logic and / or action logic, the code template file is used to generate an APP package file corresponding to the target service; obtain the APP package file and the first import configuration information corresponding to the APP package file; according to the first import configuration information, install and store the APP package file in the SOAR platform 21.
[0059] In some embodiments, the system 20 is further configured to use the Freemarker engine to generate a code template file corresponding to the programming language information according to the APP information description file, where the APP information description file is in JSON format.
[0060] In some embodiments, the system 20 is further communicatively connected to the registration center 22. The system 20 is further configured to start the APP package file in the SOAR platform 21 according to the programming language information corresponding to the APP package file; when the APP package file is successfully started, register the APP package file to a preset registration center 22.
[0061] In some embodiments, the system 20 is further configured to obtain request parameters corresponding to the APP package file, and use the registration center 22 to obtain the call interface address of the APP package file; according to the call interface address, call the target service corresponding to the APP package file, and send the request parameters to the security device corresponding to the target service; send the response parameters generated by the security device in response to the request parameters to the SOAR platform 21.
[0062] In some embodiments, the system 20 is further configured to perform an uninstallation process on the APP package file stored in the SOAR platform 21, and delete the registration information related to the APP package file in the registration center 22.
[0063] In some embodiments, the system 20 is further configured to obtain an update file corresponding to the APP package file and a second import configuration information corresponding to the update file; perform an update process on the APP package file stored in the SOAR platform 21 according to the second import configuration information and the update file.
[0064] In some embodiments, the parameter information includes at least one of the following: APP information, device parameter information, programming language information, APP request method information, APP function action information.
[0065] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and alternative embodiments, and will not be elaborated here.
[0066] This embodiment also provides an electronic device. Figure 3 It is a schematic diagram of the hardware structure of the electronic device according to the embodiment of the present application. As Figure 3 shown, the electronic device includes a memory 304 and a processor 302. A computer program is stored in the memory 304, and the processor 302 is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0067] Specifically, the above-mentioned processor 302 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured with one or more integrated circuits implementing the embodiments of the present application.
[0068] Among them, the memory 304 may include a mass memory for data or instructions. By way of example and not limitation, the memory 304 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 304 may include removable or non-removable (or fixed) media. Where appropriate, the memory 304 may be internal or external to the service access system of the SOAR platform. In a particular embodiment, the memory 304 is non-volatile memory. In a particular embodiment, the memory 304 includes a read-only memory (ROM) and a random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. Where appropriate, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0069] The memory 304 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 302.
[0070] By reading and executing the computer program instructions stored in the memory 304, the processor 302 implements the service access method of any one of the SOAR platforms in the above embodiments.
[0071] Optionally, the above electronic device may further include a transmission device 306 and an input / output device 308. Among them, the transmission device 306 is connected to the above processor 302, and the input / output device 308 is connected to the above processor 302.
[0072] Optionally, in this embodiment, the above processor 302 may be set to execute the following steps through a computer program:
[0073] S1, obtain the parameter information of the target service.
[0074] S2, integrate the parameter information to generate an APP information description file corresponding to the parameter information.
[0075] S3, generate a code template file corresponding to the programming language information according to the programming language information in the APP information description file. Among them, after inputting the preset docking logic and / or action logic, the code template file is used to generate an APP package file corresponding to the target service.
[0076] S4, obtain the APP package file and the first import configuration information corresponding to the APP package file.
[0077] S5, install and store the APP package file in the SOAR platform according to the first import configuration information.
[0078] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be repeated here.
[0079] In addition, in combination with the service access method of the SOAR platform in the above embodiments, an embodiment of the present application can be implemented by providing a storage medium. A computer program is stored on the storage medium; when the computer program is executed by a processor, the service access method of any one of the above embodiments is implemented.
[0080] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0081] The above embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several variations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A service access method for a SOAR platform, characterized in that The method includes: Obtaining parameter information of a target service; wherein, the parameter information includes basic information of a security device or tool corresponding to the target service to be accessed; Integrating the parameter information to generate an APP information description file corresponding to the parameter information; Generating a code template file corresponding to the programming language information according to the programming language information in the APP information description file, wherein, after inputting a preset docking logic corresponding to the security device linkage function and / or an action logic corresponding to the service action of the security device into the code template file, the code template file is used to generate an APP package file corresponding to the target service; Obtaining the APP package file and first import configuration information corresponding to the APP package file; wherein, the first import configuration information is configuration parameter information required to import the APP package file into the SOAR platform adjusted according to the import standard of the SOAR platform; Installing and storing the APP package file in the SOAR platform according to the first import configuration information.
2. The service access method of the SOAR platform according to claim 1, wherein, Generating a code template file corresponding to the programming language information includes: Using the Freemarker engine to generate a code template file corresponding to the programming language information according to the APP information description file, wherein the APP information description file is in JSON format.
3. The service access method of the SOAR platform according to claim 1, wherein The method further includes: Starting the APP package file in the SOAR platform according to the programming language information corresponding to the APP package file; When the APP package file is successfully started, registering the APP package file in a preset registration center.
4. The service access method of the SOAR platform according to claim 3, characterized in that The method further includes: Obtaining request parameters corresponding to the APP package file and using the registration center to obtain the call interface address of the APP package file; Invoking the target service corresponding to the APP package file according to the call interface address and sending the request parameters to the security device corresponding to the target service; Sending response parameters generated by the security device in response to the request parameters to the SOAR platform.
5. The service access method of the SOAR platform according to claim 3, wherein The method further includes: Performing an uninstallation process on the APP package file stored in the SOAR platform and deleting registration information related to the APP package file in the registration center.
6. The service access method of the SOAR platform according to claim 1, wherein The method further includes: Obtaining an update file corresponding to the APP package file and second import configuration information corresponding to the update file; wherein, the second import configuration information is configuration parameter information required to import the update file corresponding to the APP package file into the SOAR platform adjusted according to the import standard of the SOAR platform; Performing an update process on the APP package file stored in the SOAR platform according to the second import configuration information and the update file.
7. The service access method of the SOAR platform according to claim 1, wherein The parameter information includes at least one of the following: APP information, device parameter information, programming language information, APP request mode information, APP function action information.
8. A service access system for a SOAR platform, characterized in that, The system is communicatively connected to the SOAR platform, and the system is used to execute the service access method of the SOAR platform described in any one of claims 1 to 7.
9. An electronic device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to run the computer program to execute the service access method of the SOAR platform described in any one of claims 1 to 7.
10. A storage medium, characterized in that, A computer program is stored in the storage medium, wherein the computer program, when executed by a processor, implements the service access method of the SOAR platform described in any one of claims 1 to 7.
Citation Information
Patent Citations
Code generation method and device
CN111324343A
Service code generation method and device, electronic equipment and readable storage medium
CN113515271A