A method, device, electronic device and storage medium for determining a compromised host
By using preset outlier detection algorithm in security event detection combined with network behavior characteristic data, the problem of false alarm detection of security event detection is solved, and the accuracy of the lost host is improved.
Patent Information
- Application Number
- CN202111245887.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-10-26
AI Technical Summary
The prior art is prone to false alarms during the security incident detection process, resulting in inaccurate determination of the lost host.
By obtaining the network behavior characteristic data of each host to be detected in the target group, the outlier detection result is determined using preset outlier detection algorithms (such as the isolated forest algorithm and the box graph algorithm), and combined with the event detection result, the lost host is determined.
It effectively reduces the impact of security incident misjudgment on the determination of the lost host and improves the accuracy of the lost host.
Smart Images

Figure CN113987476B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of security technologies, and in particular, to a method, apparatus, electronic device, and storage medium for determining a compromised host. Background Art
[0002] A security event refers to any event that attempts to change the security state of an information system (such as changing access control measures, changing security levels, changing user passwords, etc.). During the process of a user accessing the network through a host, a security management platform can detect the access behavior of the host to determine whether a security event has occurred on the host. When a security event is detected on the host, the host will be determined as a compromised host, and thus security protection, such as issuing an alarm, etc., will be performed on the compromised host.
[0003] In the related art, since false alarms may occur during the security event detection process, this will lead to deviations in the determined compromised hosts, affecting the accuracy of the determined compromised hosts. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a method, apparatus, electronic device, and storage medium for determining a compromised host, so as to reduce the impact of misjudgment of security events on the determination of compromised hosts and improve the accuracy of the determined compromised hosts. The specific technical solutions are as follows:
[0005] The embodiments of the present application provide a method for determining a compromised host, the method comprising:
[0006] Obtain the network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, the hosts to be detected included in the target group are determined according to a preset group division index; each of the hosts to be detected has the same index value of the preset group division index;
[0007] Use a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among the network behavior characteristic data;
[0008] Obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event has occurred on the host to be detected within the preset time period;
[0009] Determine the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected.
[0010] Optionally, the network behavior characteristic data includes at least one of the following: uplink traffic, downlink traffic, number of sessions, number of Internet Protocol (IP) accesses, and number of access regions.
[0011] Optionally, the step of determining the outlier detection result of each host to be detected by using a preset outlier detection algorithm includes:
[0012] Using the Isolation Forest algorithm, determine the first outliers in the network behavior characteristic data of the hosts to be detected;
[0013] Using the box plot algorithm, determine the second outliers in the network behavior characteristic data of the hosts to be detected;
[0014] Determine the target hosts in the target group as outlier hosts, where the target hosts are the hosts to be detected corresponding to each network behavior characteristic data in the intersection of the first outliers and the second outliers;
[0015] Determine each host to be detected in the target group except the target hosts as non-outlier hosts.
[0016] Optionally, the step of determining the first outliers in the network behavior characteristic data of the hosts to be detected by using the Isolation Forest algorithm includes:
[0017] According to the network behavior characteristic data of each host to be detected, construct a preset number of isolation trees to obtain an Isolation Forest model;
[0018] Using the Isolation Forest model, calculate the anomaly scores of the network behavior characteristic data of each host to be detected;
[0019] Determine the network behavior characteristic data with the anomaly scores greater than the first anomaly threshold as the first outliers.
[0020] Optionally, the step of determining the second outliers in the network behavior characteristic data of the hosts to be detected by using the box plot algorithm includes:
[0021] For each behavior category in the network behavior characteristic data, compare the network behavior characteristic data of each host to be detected in this behavior category with the second anomaly threshold corresponding to this behavior category; the second anomaly threshold corresponding to each behavior category is: determined according to the quartiles of the network behavior characteristic data of the hosts to be detected in the target group in this behavior category;
[0022] If the network behavior characteristic data of a host to be detected in any behavior category is greater than the second anomaly threshold corresponding to this behavior category, then determine the network behavior characteristic data of this host to be detected as the second outliers.
[0023] Optionally, the step of determining the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected includes:
[0024] For each host to be detected in the target group, if the outlier detection result indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result indicates that a security event has occurred on the host to be detected within the preset time period, it is determined that the host to be detected is a compromised host.
[0025] Optionally, before determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected, it further includes:
[0026] Obtain the outlier detection results and event detection results of each host to be detected in the target group within a plurality of consecutive preset time periods;
[0027] The step of determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected includes:
[0028] For each host to be detected in the target group, within each preset time period, if the outlier detection result corresponding to the preset time period indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result of the preset time period indicates that a security event has occurred on the host to be detected, then the host to be detected is determined as an alternative host within the preset time period;
[0029] If the number of times the host to be detected is determined as an alternative host within the multiple preset time periods is greater than a preset number threshold, it is determined that the host to be detected is a compromised host.
[0030] An embodiment of the present application further provides a compromised host determination device, and the device includes:
[0031] A first acquisition module, configured to acquire the network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, each host to be detected included in the target group is determined according to a preset group division index; each host to be detected has the same index value of the preset group division index;
[0032] A first determination module, configured to use a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among the network behavior characteristic data;
[0033] A second acquisition module, configured to acquire the event detection result of each host to be detected; the event detection result is used to indicate whether a security event has occurred on the host to be detected within the preset time period;
[0034] A second determination module, configured to determine compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected.
[0035] Optionally, the network behavior feature data includes at least one of the following: uplink traffic, downlink traffic, number of sessions, number of accessed IPs, and number of accessed regions.
[0036] Optionally, the first determination module is specifically configured to use the Isolation Forest algorithm to determine the first outliers in the network behavior feature data of each host to be detected;
[0037] Use the box plot algorithm to determine the second outliers in the network behavior feature data of each host to be detected;
[0038] Determine the target hosts in the target group as outlier hosts, where the target hosts are the hosts to be detected corresponding to each network behavior feature data in the intersection of the first outliers and the second outliers;
[0039] Determine each host to be detected in the target group other than the target hosts as non-outlier hosts.
[0040] Optionally, the first determination module is specifically configured to construct a preset number of isolation trees based on the network behavior feature data of each host to be detected to obtain an Isolation Forest model; use the Isolation Forest model to calculate the anomaly scores of the network behavior feature data of each host to be detected; and determine the network behavior feature data with the anomaly scores greater than the first anomaly threshold as the first outliers.
[0041] Optionally, the first determination module is specifically configured to, for each behavior category in the network behavior feature data, compare the network behavior feature data of each host to be detected in this behavior category with the second anomaly threshold corresponding to this behavior category; the second anomaly threshold corresponding to each behavior category is determined according to the quartiles of the network behavior feature data of each host to be detected in the target group in this behavior category; if the network behavior feature data of a host to be detected in any behavior category is greater than the second anomaly threshold corresponding to this behavior category, then determine the network behavior feature data of this host to be detected as the second outliers.
[0042] Optionally, the second determination module is specifically configured to, for each host to be detected in the target group, if the outlier detection result indicates that the network behavior feature data of this host to be detected is an outlier, and the event detection result indicates that this host to be detected has a security event within the preset duration, then determine that this host to be detected is a compromised host.
[0043] Optionally, the device further includes:
[0044] A third acquisition module, configured to acquire the outlier detection results and event detection results of each host to be detected in the target group within a plurality of consecutive preset time periods before determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected;
[0045] The second determination module is specifically configured to, for each host to be detected in the target group, within each preset time period, if the outlier detection result corresponding to the preset time period indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result of the preset time period indicates that the host to be detected has a security event, then determine the host to be detected as an alternative host within the preset time period;
[0046] If the number of times the host to be detected is determined as an alternative host within the plurality of preset time periods is greater than a preset number threshold, then determine that the host to be detected is a compromised host.
[0047] An embodiment of the present application further provides an electronic device, including a processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to: implement the steps of the compromised host determination method described in any one of the above.
[0048] An embodiment of the present application further provides a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to: implement the steps of the compromised host determination method described in any one of the above.
[0049] An embodiment of the present application further provides a computer program product including instructions, which when running on a computer, causes the computer to execute the compromised host determination method described in any one of the above.
[0050] In the technical solution provided by the embodiment of the present application, by acquiring the network behavior characteristic data of each host to be detected in the target group, using a preset outlier detection algorithm to determine the outlier detection results of each host to be detected, and thus determining the compromised hosts in the target group according to the outlier detection results and event detection results of each host to be detected within a preset time period.
[0051] Compared with the related art, in the process of determining compromised hosts, in addition to considering whether a host has a security event, it also comprehensively considers whether the network behavior characteristic data of the host is an outlier in its target group, that is, it also considers the deviation of the network behavior characteristics of the host from the network behavior characteristics of other hosts in its group, thereby effectively reducing the impact of misjudgment of security events on the determination of compromised hosts and improving the accuracy of the determined compromised hosts.
[0052] Of course, it is not necessary for any product or method implementing the present application to achieve all of the above-described advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0054] Figure 1 The first flowchart of the method for determining a compromised host provided by an embodiment of the present application;
[0055] Figure 2 The second flowchart of the method for determining a compromised host provided by an embodiment of the present application;
[0056] Figure 3 The third flowchart of the method for determining a compromised host provided by an embodiment of the present application;
[0057] Figure 4 The fourth flowchart of the method for determining a compromised host provided by an embodiment of the present application;
[0058] Figure 5 A schematic diagram of a box plot provided by an embodiment of the present application;
[0059] Figure 6 The fifth flowchart of the method for determining a compromised host provided by an embodiment of the present application;
[0060] Figure 7 The sixth flowchart of the method for determining a compromised host provided by an embodiment of the present application;
[0061] Figure 8 A schematic diagram of the number of times a host is compromised and the probability of compromise within multiple preset time periods provided by an embodiment of the present application;
[0062] Figure 9-a The first structural schematic diagram of the device for determining a compromised host provided by an embodiment of the present application;
[0063] Figure 9-b The second structural schematic diagram of the device for determining a compromised host provided by an embodiment of the present application;
[0064] Figure 10 A structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0065] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0066] In the related art, when determining a compromised host, a security management platform such as threat awareness, security information and event management (SIEM), security operations center (SOC), etc. can be used to generate security events. When the security management platform generates a security event for a certain host, the host will be determined as a compromised host. However, there are often misjudgments in the detected security events.
[0067] For example, a user can manually trigger the local scanning function of a host. At this time, the host will scan the data stored locally. Due to the triggering of this scanning function, the security management platform can determine that this scanning has triggered a security event. Although there is a misjudgment in the security event, the host will still be determined as a compromised host, affecting the accuracy of the determined compromised host.
[0068] To solve the problems in the related art, an embodiment of the present application provides a method for determining a compromised host. As Figure 1 shown, Figure 1 is the first flowchart of the method for determining a compromised host provided by the embodiment of the present application. The method includes the following steps.
[0069] Step S101: Obtain the network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, each host to be detected included in the target group is determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0070] Step S102: Use a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among the network behavior characteristic data.
[0071] Step S103: Obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event has occurred for the host to be detected within a preset time period.
[0072] Step S104: Determine the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected.
[0073] By Figure 1The method shown determines the off - group detection results of each host to be detected in a target group by obtaining the network behavior characteristic data of each host to be detected in the target group and using a preset outlier detection algorithm. Then, based on the off - group detection results and event detection results of each host to be detected within a preset time period, the compromised hosts in the target group are determined.
[0074] Compared with the related technology, in the process of determining compromised hosts, in addition to considering whether a security event has occurred on the host, it also comprehensively considers whether the network behavior characteristic data of the host is an outlier in its target group, that is, it also considers the deviation of the network behavior characteristics of the host from the network behavior characteristics of other hosts in its group. Thus, it effectively reduces the impact of misjudgment of security events on the determination of compromised hosts and improves the accuracy of the determined compromised hosts.
[0075] The embodiments of the present application will be described below through specific examples. For ease of description, an electronic device is used as the execution subject for illustration below. The electronic device can be any detection device and does not play any limiting role.
[0076] Regarding the above - mentioned step S101, that is, obtaining the network behavior characteristic data of each host to be detected in a target group within a preset time period; among them, the hosts to be detected included in the target group are determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0077] In the embodiments of the present application, the electronic device can divide multiple hosts to be detected into multiple groups according to a preset group division index. Each group includes hosts to be detected that have the same index value of the preset group division index.
[0078] The above - mentioned preset group division index can be based on the characteristic information of the users using the hosts and the characteristic information of the hosts. For example, the preset group division index can be the department where the user of the host is located, the area where the host is located, etc.
[0079] For ease of understanding, take the group division of all hosts in a certain company as an example.
[0080] When the above - mentioned preset group index is the department where the user of the host is located, the electronic device can determine the department where the user of each host is located according to the personnel organization structure of the company, and thus divide the hosts corresponding to the users in the same department into the same group to obtain multiple groups. For example, a finance personnel group, a R & D personnel group, a testing personnel group, an auditing personnel group, etc.
[0081] When the above - mentioned preset group index is the area where the host is located, such as the floor, the electronic device can divide the hosts on the same floor into the same group to obtain multiple groups. For example, a first - floor host group, a second - floor host group, etc.
[0082] In the embodiments of the present application, according to different above-mentioned preset group division indicators, the same indicator values of each host to be detected in each group obtained by division are also different. Herein, the division method of the above groups is not specifically limited.
[0083] After the electronic device divides multiple hosts to be detected into groups, at least one group can be obtained. Moreover, each group includes one or more hosts to be detected. Herein, the number of groups obtained by division and the number of hosts to be detected included in each group are not specifically limited.
[0084] The above target group can be any one of the groups after group division.
[0085] In an optional embodiment, in order to reduce the influence of the difference between different hosts when accessing the network on the accuracy of the outliers determined later, the number of hosts to be detected included in the above target group can be greater than a preset quantity threshold.
[0086] The above preset quantity threshold can be set according to the user's experience. For example, the above preset quantity threshold can be 10. That is, the number of hosts to be detected included in the target group is at least 10. Herein, the above preset quantity threshold is not specifically limited.
[0087] For each host to be detected in the above target group, the electronic device can obtain the log information of the host to be detected within a preset duration, and extract the network behavior feature data of the host to be detected from the obtained log information.
[0088] In an optional embodiment, the above network behavior feature data includes at least one of the following: uplink traffic, downlink traffic, number of sessions, number of accessed IPs, and number of accessed regions.
[0089] When the above network behavior feature data includes the above uplink traffic, the electronic device can calculate the sum value of the uplink traffic of each log of the host to be detected within the preset duration according to the log information of the host to be detected within the preset duration, and use it as the uplink traffic of the host to be detected.
[0090] When the above network behavior feature data includes the above downlink traffic, the electronic device can calculate the sum value of the downlink traffic of each log of the host to be detected within the preset duration according to the log information of the host to be detected within the preset duration, and use it as the downlink traffic of the host to be detected.
[0091] When the above network behavior feature data includes the above number of sessions, the electronic device can count the sum value of the session logs of the host to be detected within the preset duration according to the log information of the host to be detected within the preset duration, and use it as the number of sessions of the host to be detected.
[0092] When the above network behavior characteristic data includes the above number of accessed IPs, the electronic device may, according to the log information of the host to be detected within a preset time period, obtain the destination IPs accessed by the host to be detected within the preset time period, and perform duplicate removal processing on the obtained destination IPs. The electronic device counts the number of remaining target IPs after the duplicate removal processing as the number of accessed IPs of the host to be detected.
[0093] When the above network behavior characteristic data includes the above number of accessed regions, the electronic device may, according to the log information of the host to be detected within a preset time period, obtain the country where the destination IP accessed by the host to be detected within the preset time period is located, and perform duplicate removal processing on the obtained countries. The electronic device counts the number of remaining countries after the duplicate removal as the number of accessed regions of the host to be detected.
[0094] In the embodiments of the present application, the above network behavior characteristic data may further include the number of Domain Name Server (DNS) requests, the number of Uniform Resource Location (URL) requests, etc. Here, no specific limitation is made on the above network behavior characteristic data.
[0095] The above preset time period can be set according to user requirements. For example, the preset time period can be 1 hour, such as 10:00 - 11:00, etc. Here, no specific limitation is made on the above preset time period.
[0096] Regarding the above step S102, that is, using a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among all the network behavior characteristic data.
[0097] In this step, the electronic device may perform outlier detection on the network behavior characteristic data of each host to be detected in the target group within a preset time period by using a preset outlier detection algorithm to obtain the outlier detection result of each host to be detected.
[0098] In an optional embodiment, regarding the outlier detection result of the above host to be detected, the outlier detection result may indicate that the network behavior characteristic data of the host to be detected is an outlier among all the network behavior characteristic data included in the target group. At this time, the electronic device may determine the host to be detected as an outlier host.
[0099] In another alternative embodiment, for the outlier detection result of the to-be-detected host mentioned above, the outlier detection result may indicate that the network behavior characteristic data of the to-be-detected host is not an outlier among all the network behavior characteristic data included in the target group. At this time, the electronic device may determine that the to-be-detected host is not an outlier host, that is, a non-outlier host.
[0100] The above-mentioned preset outlier detection algorithms include, but are not limited to, the Isolation Forest algorithm, the Box Plot algorithm, the Support Vector Machine (SVM) outlier detection algorithm, and the 3-sigma anomaly detection algorithm. Here, no specific limitation is imposed on the above-mentioned preset outlier detection algorithms.
[0101] Regarding the above step S103, that is, obtaining the event detection result of each to-be-detected host; the event detection result is used to indicate whether a security event has occurred for the to-be-detected host within a preset time period.
[0102] In this step, the above-mentioned security management platform may perform real-time security event detection on each to-be-detected host, so as to determine whether a security event has occurred for each to-be-detected host, and obtain the event detection result of each to-be-detected host. The electronic device may obtain the event detection result of each to-be-detected host within the above-mentioned preset time period from the security management platform.
[0103] The above-mentioned event detection result may be obtained by detecting and analyzing the to-be-detected host through detection methods such as correlation analysis and User and Entity Behavior Analytics (UEBA) detection. Here, no specific limitation is imposed on the determination method of the above-mentioned event detection result.
[0104] In the embodiment of the present application, the above step S103 may be executed before / after the execution of the above step S101 or step S102, or may be executed simultaneously with step S101 or step S102. Here, no specific limitation is imposed on the execution order of the above step S103 and step S101 or step S102.
[0105] Regarding the above step S104, that is, determining the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each to-be-detected host.
[0106] In this step, for each to-be-detected host in the above-mentioned target group, the electronic device may determine which to-be-detected hosts are compromised hosts according to the outlier detection result and the event detection result of the to-be-detected host. The determination method for the to-be-detected host to be a compromised host can be seen in the following description, and no specific description is given here.
[0107] In an alternative embodiment, step S102 above, that is, using a preset outlier detection algorithm to determine the outlier detection result of each host to be detected, can be specifically expressed as:
[0108] The electronic device uses the Isolation Forest algorithm to determine the outliers in the network behavior characteristic data of each host to be detected according to the network behavior characteristic data of each host to be detected in the target group, and determines the outlier detection result of each host to be detected in the target group based on the outlier. The method for determining the outlier can be seen in the following description and will not be specifically described here.
[0109] In another alternative embodiment, step S102 above, that is, using a preset outlier detection algorithm to determine the outlier detection result of each host to be detected, can be specifically expressed as:
[0110] The electronic device uses the box plot algorithm to determine the outliers in the network behavior characteristic data of each host to be detected according to the network behavior characteristic data of each host to be detected in the target group, and determines the outlier detection result of each host to be detected in the target group based on the outlier. The method for determining the outlier can be seen in the following description and will not be specifically described here.
[0111] In yet another alternative embodiment, in order to further improve the accuracy of the determined outlier detection result, according to the method Figure 1 shown above, the embodiment of the present application also provides a method for determining a compromised host. As Figure 2 shown, Figure 2 FIG. 2 is a second flowchart of the method for determining a compromised host provided by the embodiment of the present application. The method includes the following steps.
[0112] Step S201, obtain the network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, the hosts to be detected included in the target group are determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0113] The above step S201 is the same as the above step S101.
[0114] Step S202, use the Isolation Forest algorithm to determine the first outliers in the network behavior characteristic data of each host to be detected.
[0115] The method for determining the above first outliers can be seen in the following description and will not be specifically described here.
[0116] Step S203, use the box plot algorithm to determine the second outliers in the network behavior characteristic data of each host to be detected.
[0117] The method for determining the above second outliers can be seen in the following description and will not be specifically described here.
[0118] In the embodiments of the present application, the execution order of the above step S202 and step S203 is not specifically limited.
[0119] Step S204, determining the target host in the target group as an outlier host, where the target host is the host to be detected corresponding to each network behavior feature data in the intersection of the first outlier point and the second outlier point.
[0120] In this step, after determining the above first outlier point and second outlier point, the electronic device can determine the network behavior feature data included in the intersection of the first outlier point and the second outlier point, and determine the host to be detected corresponding to the network behavior feature data as an outlier host.
[0121] For ease of understanding, let the network behavior feature data included in the first outlier point be data 1 - data 3 respectively, and the network behavior feature data included in the second outlier point be data 2 - data 4 respectively. Among them, data 1 - data 4 are the network behavior feature data corresponding to hosts 1 - 4 respectively.
[0122] According to the network behavior feature data included in the first outlier point and the second outlier point, the electronic device can determine that the network behavior feature data included in the intersection of the first outlier point and the second outlier point are data 2 and data 3. At this time, the electronic device can determine host 2 corresponding to data 2, and host 3 corresponding to data 3 as the target hosts in the target group. That is, the electronic device can determine that host 2 and host 3 in the target group are outlier hosts.
[0123] Step S205, determining each host to be detected in the target group except the target host as a non - outlier host.
[0124] In this step, after determining the target host in the target group as an outlier host, the electronic device can determine each host to be detected in the target group except the target host as a non - outlier host.
[0125] Still taking the above host 2 and host 3 as an example, after the electronic device determines that host 2 and host 3 are outlier hosts in the target group, it can determine that the other hosts in the target group except host 2 and host 3 are not outlier hosts, that is, non - outlier hosts. That is, the above host 1 and host 4 are both non - outlier hosts.
[0126] The above step S202 - step S205 are refinements of the above step S102.
[0127] In the embodiments of the present application, after determining the first outlier and the second outlier, each network behavior feature data in the intersection of the first outlier and the second outlier is used to determine the host to be detected (i.e., the above-mentioned target host) corresponding thereto as an outlier host in the target group. This effectively synthesizes the outlier detection results determined by different preset outlier detection algorithms, effectively improves the accuracy of the determined outlier hosts, thereby improving the accuracy of the determined non-outlier hosts. This effectively improves the accuracy of the outlier detection results, and thus improves the accuracy of the compromised hosts determined based on the outlier detection results.
[0128] Step S206: Obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event has occurred on the host to be detected within a preset time period.
[0129] Step S207: Determine the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected.
[0130] The above Step S206 - Step S207 is the same as the above Step S103 - Step S104.
[0131] In Figure 2 the shown embodiment, only taking the synthesis of the outlier detection results determined by the isolation forest algorithm and the box plot algorithm as an example, the determination of the outlier hosts and non-outlier hosts in the target group is described. In addition to this, the electronic device can also synthesize at least two outlier detection results among the outlier detection results corresponding to the isolation forest algorithm, the box plot algorithm, the SVM outlier detection algorithm, and the 3sigma anomaly detection algorithm to determine the outlier hosts and non-outlier hosts in the target group. The specific determination method can refer to Figure 2 the shown method and will not be specifically described here.
[0132] In an optional embodiment, according to Figure 2 the shown method, the embodiments of the present application also provide a method for determining compromised hosts. As Figure 3 shown, Figure 3 is the third process schematic diagram of the method for determining compromised hosts provided by the embodiments of the present application. The method includes the following steps.
[0133] Step S301: Obtain the network behavior feature data of each host to be detected in the target group within a preset time period; wherein, the hosts to be detected included in the target group are determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0134] The above Step S301 is the same as the above Step S201.
[0135] Step S302: Based on the network behavior characteristic data of each host to be detected, construct a preset number of isolation trees to obtain an isolation forest model.
[0136] In an embodiment of the present application, the electronic device may randomly construct a preset number of isolation trees according to the network behavior characteristic data of each host to be detected and the behavior categories included in the network behavior characteristic data, so as to obtain an isolation forest model.
[0137] For ease of understanding, the construction of an isolation tree will be described with reference to Table 1.
[0138] Table 1
[0139] Host Upstream traffic Downstream traffic Host A A1 A2 Host B B1 B2 Host C C1 C2
[0140] According to Table 1, the target group includes the 3 hosts to be detected shown in Table 1, namely Host A, Host B, and Host C. The behavior categories included in the network behavior characteristic data of each host to be detected include: uplink traffic and downlink traffic.
[0141] When constructing the root node of the isolation tree, the electronic device may randomly select the network behavior characteristic data corresponding to a behavior category to fill the root node. For example, if uplink traffic is selected, the data filled in the root node is A1, A2, and A3 in Table 1.
[0142] When constructing the leaf nodes (i.e., the left child node and the right child node) of the root node of the isolation tree, the electronic device randomly generates a cut-off data, such as P1, and compares it with each network behavior characteristic data in the root node to obtain a comparison result. For example, A1 < P1, B1 < P1, C1 > P1. At this time, the electronic device may fill A1 and B1 into the left child node of the root node, and fill C1 into the right child node of the root node. And so on, further determine the two leaf nodes corresponding to the left child node of the root node, thereby obtaining an isolation tree A. Each isolation tree in the above isolation forest model can be constructed in the same way as isolation tree A, and no specific description will be made here.
[0143] In an optional embodiment, when constructing each isolation tree in the above isolation forest model, the electronic device may end the construction process of the isolation tree and obtain an isolation tree when each leaf node in each layer only includes the network behavior characteristic data of one host to be detected.
[0144] In another alternative embodiment, when constructing each isolation tree in the above isolation forest model, the electronic device can also determine whether to end the construction process of the isolation tree according to the height of the currently constructed isolation tree, so as to obtain an isolation tree. For example, when the height of the isolation tree is 5 (that is, the isolation tree includes a root node and four layers of leaf nodes), the electronic device can end the construction process of the isolation tree to obtain an isolation tree.
[0145] In the embodiments of the present application, the conditions for ending the construction process of each isolation tree are not specifically limited.
[0146] In the embodiments of the present application, the larger the above preset quantity, the more isolation trees included in the isolation forest model, and the higher the accuracy of the outliers determined based on the isolation forest model. However, the computational complexity of the outlier determination process is greater. Therefore, in order to balance the accuracy of the determined outliers and the computational complexity of the outlier determination process, the above preset quantity can be determined according to user requirements or user experience. For example, the preset quantity can be 100. Here, the above preset quantity is not specifically limited.
[0147] Step S303: Use the isolation forest model to calculate the anomaly score of the network behavior feature data of each host to be detected.
[0148] In this step, after constructing the above isolation forest model, for each host to be detected in the target group, the electronic device can input the network behavior feature data of the host to be detected into the isolation forest model to obtain the anomaly score output by the isolation forest model. That is, the anomaly score of the host to be detected.
[0149] In the embodiments of the present application, the value range of the above anomaly score can be between 0 and 1. The larger the anomaly score of the host to be detected, the higher the probability that the network behavior feature data of the host to be detected is an outlier; the smaller the anomaly score of the host to be detected, the lower the probability that the network behavior feature data of the host to be detected is an outlier.
[0150] After determining the anomaly scores of the network behavior feature data of each host to be detected in the target group, the electronic device can compare the anomaly scores of the network behavior feature data of the host to be detected with the first anomaly threshold to obtain a comparison result. The comparison result specifically includes the following two situations.
[0151] Situation 1: The anomaly score of the network behavior feature data of the host to be detected is greater than the first anomaly threshold.
[0152] Situation 2: The anomaly score of the network behavior feature data of the host to be detected is less than or equal to the first anomaly threshold.
[0153] The above first anomaly threshold can be set according to user requirements or experience, etc. For example, the above first anomaly threshold can be 0.8. Here, no specific limitation is imposed on the above first anomaly threshold.
[0154] Step S304: Determine the network behavior feature data with an anomaly score greater than the first anomaly threshold as the first outlier.
[0155] In this step, for each host to be detected in the target group, when the comparison result between the anomaly score of the network behavior feature data of the host to be detected and the first anomaly threshold is the above-mentioned situation one, that is, the anomaly score of the network behavior feature data of the host to be detected is greater than the first anomaly threshold, the electronic device can determine that the network behavior feature data of the host to be detected is an outlier, denoted as the first outlier.
[0156] In an optional embodiment, for each host to be detected in the target group, when the comparison result between the anomaly score of the network behavior feature data of the host to be detected and the first anomaly threshold is the above-mentioned situation two, that is, the anomaly score of the network behavior feature data of the host to be detected is less than or equal to the first anomaly threshold, the electronic device can determine that the network behavior feature data of the host to be detected is not an outlier, that is, a non-outlier.
[0157] Through the above steps S302 - S304, the electronic device can accurately determine the data to be detected in the target group whose feature data belongs to the first outlier.
[0158] The above steps S302 - S304 are refinements of the above step S202.
[0159] Step S305: Use the box plot algorithm to determine the second outliers in the network behavior feature data of each host to be detected.
[0160] Step S306: Determine the target hosts in the target group as outlier hosts, where the target hosts are the hosts to be detected corresponding to each network behavior feature data in the intersection of the first outliers and the second outliers.
[0161] Step S307: Determine each host to be detected in the target group other than the target hosts as non-outlier hosts.
[0162] Step S308: Obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event occurs in the host to be detected within a preset duration.
[0163] Step S309: Determine the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected.
[0164] The above steps S305 - S309 are the same as the above steps S203 - S207.
[0165] In an optional embodiment, according to Figure 2 the method shown, an embodiment of the present application further provides a method for determining a compromised host. As Figure 4 shown, Figure 4 FIG. 4 is a fourth flowchart of the method for determining a compromised host provided by an embodiment of the present application. The method includes the following steps.
[0166] Step S401, obtain the network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, each host to be detected included in the target group is determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0167] Step S402, use the isolation forest algorithm to determine the first outliers in the network behavior characteristic data of each host to be detected.
[0168] The above steps S401 - S402 are the same as the above steps S201 - S202.
[0169] Step S403, for each behavior category in the network behavior characteristic data, compare the network behavior characteristic data of each host to be detected in this behavior category with the second anomaly threshold corresponding to this behavior category; the second anomaly threshold corresponding to each behavior category is: determined according to the quartiles of the network behavior characteristic data of each host to be detected in the target group in this behavior category.
[0170] In this step, for each host to be detected in the target group, the electronic device can respectively compare the network behavior characteristic data corresponding to each behavior category of this host to be detected with the second anomaly threshold corresponding to this behavior category to obtain a comparison result. The comparison result includes at least the following two cases.
[0171] Case 1, the network behavior characteristic data corresponding to each behavior category of this host to be detected are all less than or equal to the second anomaly threshold corresponding to this behavior category.
[0172] Case 2, the network behavior characteristic data corresponding to at least one behavior category of this host to be detected are greater than the second anomaly threshold corresponding to this behavior category.
[0173] In the embodiment of the present application, the above quartiles include the upper quartile and the lower quartile.
[0174] In an optional embodiment, the above second anomaly threshold is the sum value of the upper quartile of the network behavior characteristic data of all hosts to be detected in the target group and 1.5 times the interquartile range.
[0175] For ease of understanding, taking a certain behavior category, such as the above-mentioned uplink traffic, as an example, in combination with Figure 5 the above-mentioned second anomaly threshold will be described. Figure 5 This is a schematic diagram of the box plot provided by the embodiment of the present application.
[0176] The electronic device can sort the uplink traffic of each host to be detected in the target group in descending order of data to obtain a Figure 5 box plot as shown. Among them, Max is the largest uplink traffic, and Min is the smallest uplink traffic.
[0177] The electronic device divides all the uplink traffic into four equal parts. At this time, three equal points will be generated, that is, Figure 5 Q1, M, and Q2 as shown. Among them, M is the median of all uplink traffic, Q1 is the lower quartile of all uplink traffic, and Q2 is the upper quartile of all uplink traffic.
[0178] The second anomaly threshold corresponding to the above-mentioned uplink traffic can be expressed as: Q2 + 1.5 * (Q2 - Q1). Among them, Q2 - Q1 is the interquartile range.
[0179] In the embodiment of the present application, according to the differences in the network behavior characteristic data corresponding to each behavior category of each host to be detected in the target group, the second anomaly threshold corresponding to each behavior category is also different. Here, the second anomaly threshold corresponding to each behavior category is not specifically limited.
[0180] Step S404, if the network behavior characteristic data of the host to be detected in any behavior category is greater than the second anomaly threshold corresponding to this behavior category, then the network behavior characteristic data of this host to be detected is determined as the second outlier.
[0181] In this step, for each host to be detected in the above-mentioned target group, when the comparison result between the network behavior characteristic data corresponding to the behavior category of this host to be detected and the second anomaly threshold corresponding to this behavior category satisfies the above-mentioned situation two, that is, the network behavior characteristic data corresponding to at least one behavior category of this host to be detected is greater than the second anomaly threshold corresponding to this behavior category, the electronic device can determine the network behavior characteristic data of this host to be detected as an outlier, denoted as the second outlier.
[0182] Through the above steps S403 - step S404, the electronic device can use the box plot algorithm to accurately determine the host to be detected in the target group whose network behavior characteristic data belongs to the second outlier.
[0183] The above steps S403 - step S404 are refinements of the above step S203.
[0184] In an optional embodiment, for each host to be detected in the above target group, when the comparison result between the network behavior feature data corresponding to the behavior category of the host to be detected and the second anomaly threshold corresponding to the behavior category satisfies the above situation one, that is, the network feature data corresponding to each behavior category of the host to be detected is less than or equal to the second anomaly threshold corresponding to each behavior category, the electronic device may determine the network behavior feature data of the host to be detected as a non-outlier.
[0185] Step S405: Determine the target host in the target group as an outlier host, where the target host is the host to be detected corresponding to each network behavior feature data in the intersection of the first outlier points and the second outlier points.
[0186] Step S406: Determine each host to be detected in the target group other than the target host as a non-outlier host.
[0187] Step S407: Obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event occurs for the host to be detected within a preset duration.
[0188] Step S408: Determine the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected.
[0189] The above steps S405 - S408 are the same as the above steps S204 - S207.
[0190] In an optional embodiment, according to Figure 1 the method shown, an embodiment of the present application further provides a method for determining compromised hosts. As Figure 6 shown, Figure 6 This is the fifth flowchart of the method for determining compromised hosts provided by the embodiment of the present application. The method includes the following steps.
[0191] Step S601: Obtain the network behavior feature data of each host to be detected in the target group within a preset duration; wherein, the hosts to be detected included in the target group are determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0192] Step S602: Use a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior feature data of the host to be detected is an outlier among the network behavior feature data.
[0193] Step S603: Obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event occurs for the host to be detected within a preset duration.
[0194] The above steps S601 - S603 are the same as the above steps S101 - S103.
[0195] Step S604: For each host to be detected in the target group, if the outlier detection result indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result indicates that a security event has occurred on the host to be detected within a preset duration, then determine that the host to be detected is a compromised host.
[0196] In the embodiment of the present application, after the electronic device obtains the outlier detection result and the event detection result of each host to be detected in the target group within a preset duration, for each host to be detected in the target group, it can be determined whether the outlier detection result of the host to be detected indicates that the network behavior characteristic data of the host to be detected within the preset duration is an outlier, and determine whether the event detection result of the host to be detected indicates that a security event has occurred on the host to be detected within the preset duration, as shown in Table 2 specifically.
[0197] Table 2
[0198] Situation Event detection result Outlier detection result 1 A security event occurs Outlier 2 No security event occurs Non-outlier 3 A security event occurs Non-outlier 4 No security event occurs Outlier
[0199] For each host to be detected in the target group, when the event detection result of the host to be detected within the preset duration indicates that a security event has occurred, and the outlier detection result indicates that its network behavior characteristic data is an outlier, that is, it meets Case 1 shown in Table 2, the electronic device can determine the host to be detected as a compromised host.
[0200] The above steps S603 - S604 are refinements of the above step S104.
[0201] In an optional embodiment, for each host to be detected in the target group, if the outlier detection result indicates that the network behavior characteristic data of the host to be detected is not an outlier, or the event detection result indicates that no security event has occurred on the host to be detected within the preset duration, then determine that the host to be detected is not a compromised host.
[0202] Specifically, for each host to be detected in the target group, when the event detection result of the host to be detected within the preset duration indicates that no security event has occurred, or the outlier detection result indicates that its network behavior characteristic data is not an outlier, that is, when it meets any one of Case 2, Case 3, and Case 4 shown in Table 2, the electronic device can determine that the host to be detected is not a compromised host.
[0203] In another alternative embodiment, considering that there may be misjudgments in security events, this may lead to errors in the event detection results of each host to be detected. For example, a compromised host may be determined to have not experienced a security event, or an uncompromised host may be determined to have experienced a security event. Therefore, for each host to be detected in the above target group, if the outlier detection result indicates that the network behavior characteristic data of the host to be detected is not an outlier, or the event detection result indicates that the host to be detected has not experienced a security event within a preset duration, the electronic device may not process the host to be detected. That is, the electronic device will not determine the host to be detected as a compromised host.
[0204] In an alternative embodiment, for the host to be detected whose network behavior characteristic data indicated by the above outlier detection result is not an outlier, or for which the event detection result indicates that no security event has occurred, in order to further determine whether the host to be detected is a compromised host, the electronic device may perform further detection on the host to be detected, such as detecting whether the host has been maliciously attacked, etc. Here, the detection method for the host to be detected is not specifically limited.
[0205] Through the above step S603 - step S604, the electronic device can accurately determine the compromised hosts in the target group according to the event detection results and outlier detection results of each host to be detected in the target group within a preset duration, reducing the impact of misjudgments of security events on the determination of compromised hosts and improving the accuracy of the determined compromised hosts.
[0206] In an alternative embodiment, according to Figure 1 the method shown, the embodiments of the present application also provide a method for determining compromised hosts. As Figure 7 shown, Figure 7 is the sixth process schematic diagram of the method for determining compromised hosts provided by the embodiments of the present application. The method includes the following steps.
[0207] Step S701, obtain the network behavior characteristic data of each host to be detected in the target group within a preset duration; wherein, each host to be detected included in the target group is determined according to a preset group division index; each host to be detected has the same index value of the preset group division index.
[0208] Step S702, use a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among the network behavior characteristic data.
[0209] Step S703, obtain the event detection result of each host to be detected; the event detection result is used to indicate whether a security event has occurred for the host to be detected within a preset duration.
[0210] The above steps S701 - S703 are the same as the above steps SS101 - S103.
[0211] Step S704: Obtain the outlier detection results and event detection results of each host to be detected in the target group within multiple consecutive preset time periods.
[0212] In this step, the electronic device can repeatedly execute the above steps S701 - S703 to obtain the outlier detection results and event detection results of each host to be detected in the target group within multiple consecutive preset time periods.
[0213] For example, the electronic device can obtain the outlier detection results and event detection results of each host to be detected in the target group during the period from 9:00 to 18:00 every hour.
[0214] In the embodiments of this application, considering the limitations of the outlier detection results and event detection results of the host to be detected within a single preset time period, the electronic device determines the compromised hosts in the target group by obtaining the outlier detection results and event detection results of the host to be detected within multiple consecutive preset time periods.
[0215] Step S705: For each host to be detected in the target group, within each preset time period, if the outlier detection result corresponding to this preset time period indicates that the network behavior characteristic data of this host to be detected is an outlier, and the event detection result of this preset time period indicates that this host to be detected has a security event, then determine this host to be detected as an alternative host within this preset time period.
[0216] In this step, for each host to be detected in the target group, when the outlier detection result of this host to be detected within a certain preset time period indicates that the network behavior characteristic data of this host to be detected is an outlier, and moreover, the event detection result within this preset time period indicates that this host to be detected has had a security event, the electronic device can determine that this host to be detected has been compromised once. At this time, the electronic device can determine this host to be detected as an alternative host within this preset time period.
[0217] Step S706: For each host to be detected in each target group, if the number of times this host to be detected is determined as an alternative host within multiple preset time periods is greater than the preset number threshold, then determine this host to be detected as a compromised host.
[0218] In this step, for each host to be detected in the target group, when the number of times this host to be detected is determined as an alternative host within the above - mentioned multiple consecutive preset time periods is greater than the preset number threshold, that is, the number of times this host to be detected has been compromised within the above - mentioned multiple consecutive preset time periods is greater than the preset number threshold, the electronic device can determine this host to be detected as a compromised host.
[0219] In the embodiments of the present application, by obtaining the event detection results and outlier detection results of each host to be detected in the target group within a plurality of consecutive preset time periods, the accuracy of the determined compromised host can be further improved.
[0220] For ease of understanding, through multiple experiments, a curve as Figure 8 shown is obtained. Figure 8 This is a schematic diagram of the number of compromised hosts and the compromise probability of a host within a plurality of preset time periods provided by the embodiments of the present application.
[0221] In Figure 8 the shown curve, the horizontal axis represents the number of times a host is compromised, that is, the number of times the above-mentioned host to be detected is determined as an alternative host, and the vertical axis represents the compromise probability of the host. In Figure 8 the shown curve, as the number of times a host is compromised increases, the compromise probability of the host will also increase. Therefore, when the number of times a host is compromised within a plurality of preset time periods is larger, the higher the accuracy rate of determining the host as a compromised host, and the higher the accuracy of the determined compromised host.
[0222] For example, in Figure 8 , when the number of times a host is compromised is 1, the compromise probability of the host is 55%. That is, when the number of times a host is compromised within a plurality of preset time periods is 1, the accuracy rate of determining the host as a compromised host can reach 55%. And when the number of times a host is compromised is 20, the compromise probability of the host is 100%. That is, when the number of times a host is compromised within a plurality of preset time periods is 20, the accuracy rate of determining the host as a compromised host can reach 100%.
[0223] In an alternative embodiment, the above-mentioned preset number threshold can be set according to user requirements. For example, the above-mentioned preset number threshold can be 20. Here, no specific limitation is made on the above-mentioned preset number threshold.
[0224] Based on the same inventive concept, according to the compromised host determination method provided by the embodiments of the present application, the embodiments of the present application also provide a compromised host determination device. As Figure 9-a shown, Figure 9-a this is the first structural schematic diagram of the compromised host determination device provided by the embodiments of the present application. The device includes the following modules.
[0225] A first acquisition module 901, configured to acquire the network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, each host to be detected included in the target group is determined according to a preset group division index; each host to be detected has the same index value of the preset group division index;
[0226] The first determination module 902 is configured to determine the outlier detection result of each host to be detected by using a preset outlier detection algorithm; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among the network behavior characteristic data.
[0227] The second acquisition module 903 is configured to acquire the event detection result of each host to be detected; the event detection result is used to indicate whether a security event occurs for the host to be detected within a preset duration.
[0228] The second determination module 904 is configured to determine the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected.
[0229] Optionally, the above network behavior characteristic data includes at least one of the following: uplink traffic, downlink traffic, number of sessions, number of accessed IPs, and number of accessed regions.
[0230] Optionally, the first determination module 902 may be specifically configured to use the Isolation Forest algorithm to determine the first outliers in the network behavior characteristic data of each host to be detected.
[0231] Use the box plot algorithm to determine the second outliers in the network behavior characteristic data of each host to be detected.
[0232] Determine the target hosts in the target group as outlier hosts, where the target hosts are the hosts to be detected corresponding to each network behavior characteristic data in the intersection of the first outliers and the second outliers.
[0233] Determine each host to be detected in the target group except the target hosts as non-outlier hosts.
[0234] Optionally, the first determination module 902 may be specifically configured to construct a preset number of isolation trees based on the network behavior characteristic data of each host to be detected to obtain an Isolation Forest model; use the Isolation Forest model to calculate the anomaly score of the network behavior characteristic data of each host to be detected; determine the network behavior characteristic data with the anomaly score greater than the first anomaly threshold as the first outliers.
[0235] Optionally, the first determination module 902 may be specifically configured to, for each behavior category in the network behavior characteristic data, compare the network behavior characteristic data of each host to be detected in this behavior category with the second anomaly threshold corresponding to this behavior category; the second anomaly threshold corresponding to each behavior category is determined according to the quartiles of the network behavior characteristic data of each host to be detected in the target group in this behavior category; if the network behavior characteristic data of a host to be detected in any behavior category is greater than the second anomaly threshold corresponding to this behavior category, then determine the network behavior characteristic data of this host to be detected as the second outliers.
[0236] Optionally, the second determination module 904 may specifically be configured to, for each host to be detected in the target group, if the outlier detection result indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result indicates that the host to be detected has a security event within a preset time period, determine that the host to be detected is a compromised host;
[0237] If the outlier detection result indicates that the network behavior characteristic data of the host to be detected is not an outlier, or the event detection result indicates that the host to be detected has no security event within a preset time period, determine that the host to be detected is not a compromised host.
[0238] Optionally, as Figure 9-b shown, the compromised host determination device may further include:
[0239] A third acquisition module 905, configured to acquire the outlier detection results and event detection results of each host to be detected in the target group within a plurality of consecutive preset time periods before determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected;
[0240] The second determination module 904 may specifically be configured to, for each host to be detected in the target group, within each preset time period, if the outlier detection result corresponding to the preset time period indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result of the preset time period indicates that the host to be detected has a security event, determine the host to be detected as an alternative host within the preset time period;
[0241] If the number of times the host to be detected is determined as an alternative host within a plurality of preset time periods is greater than a preset number threshold, determine that the host to be detected is a compromised host;
[0242] If the number of times the host to be detected is determined as an alternative host within a plurality of preset time periods is not greater than the preset number threshold, determine that the host to be detected is not a compromised host.
[0243] Through the device provided by the embodiments of the present application, by acquiring the network behavior characteristic data of each host to be detected in the target group, using a preset outlier detection algorithm to determine the outlier detection result of each host to be detected, and thus determining the compromised hosts in the target group according to the outlier detection results and event detection results of each host to be detected within a preset time period.
[0244] Compared with the related art, in the process of determining a compromised host, in addition to considering whether a security incident has occurred on the host, the network behavior characteristic data of the host is also comprehensively considered to be an outlier in its target group, that is, the deviation of the network behavior characteristics of the host from the network behavior characteristics of other hosts in its group is also considered, thereby effectively reducing the impact of misjudgment of security incidents on the determination of compromised hosts and improving the accuracy of the determined compromised hosts.
[0245] Based on the same inventive concept, according to the compromised host determination method provided in the embodiment of the present application above, the embodiment of the present application also provides an electronic device, such as Figure 10 shown, including a processor 1001 and a machine-readable storage medium 1002, and the machine-readable storage medium 1002 stores machine-executable instructions that can be executed by the processor 1001. The processor 1001 is prompted by the machine-executable instructions to implement the above Figures 1-4 and Figures 6-7 shown in any step.
[0246] In an optional embodiment, as Figure 10 shown, the electronic device may further include: a communication interface 1003 and a communication bus 1004; wherein, the processor 1001, the machine-readable storage medium 1002, and the communication interface 1003 complete communication with each other through the communication bus 1004, and the communication interface 1003 is used for communication between the above electronic device and other devices.
[0247] Based on the same inventive concept, according to the compromised host determination method provided in the embodiment of the present application above, the embodiment of the present application also provides a machine-readable storage medium, and the machine-readable storage medium stores machine-executable instructions that can be executed by a processor. The processor is prompted by the machine-executable instructions to implement the above Figures 1-4 and Figures 6-7 shown in any step.
[0248] Based on the same inventive concept, according to the compromised host determination method provided in the embodiment of the present application above, the embodiment of the present application also provides a computer program product containing instructions, and when it runs on a computer, it causes the computer to execute the above Figures 1-4 and Figures 6-7 shown in any step.
[0249] The above communication bus may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.
[0250] The above-mentioned machine-readable storage medium may include RAM (Random Access Memory), or may also include NVM (Non-Volatile Memory), such as at least one disk memory. Additionally, the machine-readable storage medium may also be at least one storage device located away from the aforementioned processor.
[0251] The above-mentioned processor may be a general-purpose processor, including a CPU (Central Processing Unit), an NP (Network Processor), etc.; it may also be a DSP (Digital Signal Processing), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0252] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "including", "comprising", or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device including the element.
[0253] Each embodiment in this specification is described in a related manner. For the same or similar parts between the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for embodiments such as the compromised host determination device, electronic device, machine-readable storage medium, and computer program product embodiments, since they are basically similar to the compromised host determination method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the compromised host determination method embodiments for the relevant content.
[0254] The above are only the preferred embodiments of the present application and are not intended to limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application are all included in the protection scope of the present application.
Claims
1. A method for determining a compromised host, characterized in that The method includes: Obtaining network behavior characteristic data of each host to be detected in the target group within a preset time period; wherein, the hosts to be detected included in the target group are determined according to a preset group division index; each host to be detected has the same index value of the preset group division index; Using a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of this host to be detected is an outlier among the network behavior characteristic data; Obtaining the event detection result of each host to be detected; the event detection result is used to indicate whether a security event has occurred for the host to be detected within the preset time period; Determining the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected; The step of using a preset outlier detection algorithm to determine the outlier detection result of each host to be detected includes: Using the Isolation Forest algorithm to determine the first outliers in the network behavior characteristic data of the hosts to be detected; Using the box plot algorithm to determine the second outliers in the network behavior characteristic data of the hosts to be detected; Determining the target hosts in the target group as outlier hosts, where the target hosts are the hosts to be detected corresponding to each network behavior characteristic data in the intersection of the first outliers and the second outliers; Determining each host to be detected in the target group other than the target hosts as non-outlier hosts; The step of using the Isolation Forest algorithm to determine the first outliers in the network behavior characteristic data of the hosts to be detected includes: Constructing a preset number of isolation trees according to the network behavior characteristic data of each host to be detected to obtain an Isolation Forest model; Using the Isolation Forest model to calculate the anomaly score of the network behavior characteristic data of each host to be detected; Determining the network behavior characteristic data with the anomaly score greater than the first anomaly threshold as the first outliers; The step of using the box plot algorithm to determine the second outliers in the network behavior characteristic data of the hosts to be detected includes: For each behavior category in the network behavior characteristic data, comparing the network behavior characteristic data of each host to be detected in this behavior category with the second anomaly threshold corresponding to this behavior category; the second anomaly threshold corresponding to each behavior category is: determined according to the quartiles of the network behavior characteristic data of the hosts to be detected in the target group in this behavior category; If the network behavior characteristic data of a host to be detected in any behavior category is greater than the second anomaly threshold corresponding to this behavior category, then determining the network behavior characteristic data of this host to be detected as the second outliers.
2. The method according to claim 1, wherein The network behavior characteristic data includes at least one of the following: uplink traffic, downlink traffic, number of sessions, number of Internet Protocol (IP) addresses accessed, and number of access regions.
3. The method according to claim 1, wherein The step of determining the compromised hosts in the target group according to the outlier detection result and the event detection result corresponding to each host to be detected includes: For each host to be detected in the target group, if the outlier detection result indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result indicates that the host to be detected has a security event within the preset duration, then it is determined that the host to be detected is a compromised host.
4. The method according to claim 1, wherein Before determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected, it further includes: Obtaining the outlier detection results and event detection results of each host to be detected in the target group within a plurality of consecutive preset durations; The step of determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected includes: For each host to be detected in the target group, within each preset duration, if the outlier detection result corresponding to the preset duration indicates that the network behavior characteristic data of the host to be detected is an outlier, and the event detection result of the preset duration indicates that the host to be detected has a security event, then the host to be detected is determined as an alternative host within the preset duration; If the number of times the host to be detected is determined as an alternative host within the plurality of preset durations is greater than the preset number threshold, then it is determined that the host to be detected is a compromised host.
5. A compromised host determination device, characterized in that The device includes: A first acquisition module, configured to acquire the network behavior characteristic data of each host to be detected in the target group within a preset duration; wherein, the hosts to be detected included in the target group are determined according to a preset group division index; each of the hosts to be detected has the same index value of the preset group division index; A first determination module, configured to use a preset outlier detection algorithm to determine the outlier detection result of each host to be detected; the outlier detection result of each host to be detected indicates whether the network behavior characteristic data of the host to be detected is an outlier among the network behavior characteristic data; A second acquisition module, configured to acquire the event detection result of each host to be detected; the event detection result is used to indicate whether the host to be detected has a security event within the preset duration; A second determination module, configured to determine the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected; The first determination module is specifically configured to use the Isolation Forest algorithm to determine the first outliers in the network behavior characteristic data of the hosts to be detected; Use the box plot algorithm to determine the second outliers in the network behavior characteristic data of the hosts to be detected; Determine the target hosts in the target group as outlier hosts, where the target hosts are the hosts to be detected corresponding to each network behavior characteristic data in the intersection of the first outliers and the second outliers; Determine each host to be detected in the target group except the target hosts as non-outlier hosts; The first determination module is specifically configured to construct a preset number of isolation trees based on the network behavior characteristic data of each host to be detected, so as to obtain an isolation forest model; use the isolation forest model to calculate the anomaly score of the network behavior characteristic data of each host to be detected; determine the network behavior characteristic data with the anomaly score greater than the first anomaly threshold as the first outlier; The first determination module is specifically configured to, for each behavior category in the network behavior characteristic data, compare the network behavior characteristic data of each host to be detected in this behavior category with the second anomaly threshold corresponding to this behavior category; the second anomaly threshold corresponding to each behavior category is: determined according to the quartiles of the network behavior characteristic data of each host to be detected in the target group in this behavior category; if the network behavior characteristic data of a host to be detected in any behavior category is greater than the second anomaly threshold corresponding to this behavior category, then determine the network behavior characteristic data of this host to be detected as the second outlier.
6. The device according to claim 5, characterized in that, The network behavior characteristic data includes at least one of the following: uplink traffic, downlink traffic, number of sessions, number of Internet Protocol (IP) addresses accessed, and number of access regions.
7. The device according to claim 5, characterized in that, The second determination module is specifically configured to, for each host to be detected in the target group, if the outlier detection result indicates that the network behavior characteristic data of this host to be detected is an outlier, and the event detection result indicates that this host to be detected has a security event within the preset duration, then determine that this host to be detected is a compromised host.
8. The device according to claim 5, characterized in that The device further includes: A third acquisition module, configured to acquire the outlier detection results and event detection results of each host to be detected in the target group within a plurality of consecutive preset durations before determining the compromised hosts in the target group according to the outlier detection results and event detection results corresponding to each host to be detected; The second determination module is specifically configured to, for each host to be detected in the target group, within each preset duration, if the outlier detection result corresponding to this preset duration indicates that the network behavior characteristic data of this host to be detected is an outlier, and the event detection result of this preset duration indicates that this host to be detected has a security event, then determine this host to be detected as an alternative host within this preset duration; If the number of times the host to be detected is determined as an alternative host within the plurality of preset durations is greater than the preset number threshold, then determine that this host to be detected is a compromised host.
9. An electronic device, characterized in that, It includes a processor and a machine-readable storage medium, and the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to: implement the method steps according to any one of claims 1-4.
10. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to: implement the method steps according to any one of claims 1-4.
Citation Information
Patent Citations
Network traffic anomaly detection method and device
CN109067725A
A method and a device for identifying abnormal single machines in a cluster
CN109947625A
Host security threat degree alarm method, device and equipment and storage medium
CN112181781A