Enterprise Industrial Control Security Brain Platform System and Operating Method

Through the enterprise industrial control security brain platform system, the log information is structured and real-time analysis and processing is solved, which solves the problem of inconsistent log information management in the enterprise network, realizes centralized control of multi-source security incidents, and improves security risk perception and response capabilities.

CN114297020BActive Publication Date: 2025-07-11JIANGSU LINYANG ENERGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111566634.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-20
Publication Date
2025-07-11
Estimated Expiration
2041-12-20

AI Technical Summary

Technical Problem

The log formats and irregular content generated by various devices in the enterprise network are not unified, resulting in difficulty in managing log information and cannot be effectively analyzed and integrated, affecting security risk perception and response capabilities.

Method used

Design an enterprise industrial control security brain platform system, including log information collection layer, intelligent analysis and processing layer, and achieve centralized control of multi-source security events through structured log information collection, real-time analysis and processing and unified management.

Benefits of technology

It improves the company's perception and response capabilities of security risks, realizes efficient utilization and unified management of log information, breaks down the barriers to differences between heterogeneous devices, and improves the agility and intelligence level of security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114297020B_ABST
    Figure CN114297020B_ABST
Patent Text Reader

Abstract

This application discloses an enterprise industrial control security brain platform system and an operation method. The system includes: a log information collection layer for collecting structured log information through a log collection script program and sending it to the intelligent analysis and processing layer; an intelligent analysis and processing layer for receiving the structured log information for real-time analysis and processing, and sending abnormal problems to the security operation layer according to the analysis and processing results; a security operation layer for configuring, managing, and monitoring the log information collection layer and the intelligent analysis and processing layer, and performing abnormal processing for abnormal problems; a system interface layer for managing the external interfaces of the platform system and docking and managing the external system interfaces. The present invention is based on the collection and processing of structured log information, and converges multi-source security event data to a unified management center to integrate information and centrally control, so as to solve the above-mentioned concerned objectives of enterprise information security construction and provide kinetic energy and management means for enterprise security operation and control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and more specifically, to an enterprise industrial control security brain platform system and an operation method thereof. Background Art

[0002] With the development of enterprise business, the requirements of enterprise industrial control security operation for business continuity are getting higher and higher, so higher requirements are put forward for the early perception and response processing stage of security risks. Therefore, the demand of enterprises for improving their own perception and processing ability of security risks becomes increasingly important.

[0003] Inside the enterprise, various software and hardware systems are running to support the enterprise's network, security, and business applications. The logs of the software and hardware systems, as the reporting and recording information of the system operation status, have long been only used as records and not as important management objects. With the continuous development of the enterprise, there are more and more hardware devices and software systems in the enterprise network, generating a large amount of various log information every day, with a very high information density. There is no way to effectively carry and consume a large amount of log information, resulting in the fact that logs have long been treated as the edge end of security management and are only traced and queried when a failure or security event occurs. A large amount of logs are continuously generated, continuously occupying disk space and continuously being ignored. In fact, when problems occur in the operation of the system or device, logs are the earliest information sources that can reflect problems. It is very necessary to make good use of log information if we want to improve the ability and speed of risk perception.

[0004] At the same time, focusing on the field of network security management, with the requirements and development of enterprise security construction, various network devices and security devices will be purchased and used in the initial stage. Most enterprise networks will have equipment products of different brands and types. How to effectively integrate various security devices, improve the overall security management level of the enterprise, and make the enterprise's security construction enter a new stage of security operation management has also become an urgent goal to be achieved in enterprise security construction.

[0005] At present, due to the different log formats and log contents generated by various devices and systems, and there is no unified standard, the vast majority are unstructured text information. It is difficult to extract effective management clues from a large amount of text logs, and it is not realistic to rely on manual inspection and analysis of a large amount of logs. Existing products or solutions in the market, such as log audit devices, only play the role of summarizing and storing logs, unable to form targeted analysis, locate and process abnormal events in the logs, and there is no unified security operation management platform to complete the analysis and management of various security events within the enterprise.

[0006] Therefore, it is necessary to develop an enterprise industrial control security brain platform system and an operation method thereof.

[0007] The information disclosed in the background section of the present invention is only intended to deepen the understanding of the general background art of the present invention, and should not be regarded as an admission or any form of implication that this information constitutes the prior art known to those skilled in the art. Summary of the Invention

[0008] The present invention provides an enterprise industrial control security brain platform system and an operation method thereof, which can collect and process structured log information, and converge multi-source security event data to a unified management center to integrate information and centrally control, so as to solve the above-mentioned concerns of enterprise information security construction, and provide kinetic energy and management means for enterprise security operation and control.

[0009] The technical solution of the present invention is as follows:

[0010] The present invention provides an enterprise industrial control security brain platform system, including a log information collection layer, an intelligent analysis and processing layer, a security operation layer, and a system interface layer:

[0011] The log information collection layer is used to collect structured log information through a log collection script program and send it to the intelligent analysis and processing layer;

[0012] The intelligent analysis and processing layer is used to receive the structured log information for real-time analysis and processing, and send abnormal problems to the security operation layer according to the analysis and processing results;

[0013] The security operation layer is used to configure, manage and monitor the log information collection layer and the intelligent analysis and processing layer, and perform abnormal processing on the abnormal problems;

[0014] The system interface layer is used for the management of the external interfaces of the platform system, as well as the docking and management of external system interfaces.

[0015] Preferably, collecting structured log information through a log collection script program includes:

[0016] Directly collect from devices or systems through an active polling sampling method to obtain the structured log information.

[0017] Preferably, collecting structured log information through a log collection script program includes:

[0018] Collect the original log information generated by devices or systems through the method of listening to the original log, and perform data cleaning, data supplementation, and formatting processing to form the structured log information.

[0019] Preferably, the security operation layer includes:

[0020] A log collection management module for managing and monitoring the collection script program.

[0021] Preferably, the security operation layer further includes:

[0022] A scheduled task management module for managing and executing scheduled tasks;

[0023] A monitoring index management module for configuring monitoring indexes.

[0024] Preferably, the security operation layer further includes:

[0025] A configuration management module for centrally storing and managing the configuration information of software and hardware required for the entire security operation environment, and recording the changes in the configuration information;

[0026] A work order management module for recording the processing process of work order task items generated by the security brain platform.

[0027] Preferably, the security operation layer further includes:

[0028] An early warning management module for defining the early warning strategies, early warning methods, and early warning information management of management indexes.

[0029] Preferably, the security operation layer further includes:

[0030] A data report module for displaying and outputting security operation management reports;

[0031] A large screen display module for large screen display in the enterprise security monitoring center.

[0032] The present invention also provides an operation method for an enterprise industrial control security brain platform system, including:

[0033] Step 1: Register a collector program in the security operation layer, generate a unique identifier ID for the collection task, and verify the collection script program;

[0034] Step 2: Define a collector program, write collection program code to formulate the log collection logic and strategy for the collection monitoring object, and add a code segment identifying its own task to the code;

[0035] Step 3: Collect structured log information through the log collection script program and send it to the intelligent analysis and processing layer;

[0036] Step 4: The intelligent analysis and processing layer realizes real-time analysis and processing of the structured log information through a big data streaming processing framework, and sends abnormal problems to the security operation layer according to the analysis and processing results;

[0037] Step 5: The security operation layer performs abnormal processing on the abnormal problems.

[0038] Preferably, the step 5 includes:

[0039] Step 501: Determine whether the expected log information has been collected within a predetermined time period. If so, execute Step 504; if not, execute Step 502;

[0040] Step 502: Determine whether there is abnormal stack information within the time period for the logs that have not been collected properly. If so, obtain the abnormal stack information and assign a unique identifier; if not, generate the result of this collection failure as an abnormal problem and assign a unique identifier;

[0041] Step 503: Check whether there is already alarm information corresponding to the unique identifier in the alarm library. If not, record the abnormal problem containing the unique identifier in the alarm library;

[0042] Step 504: Filter the time information of the log content for the log information, and filter out the log content that does not contain time information;

[0043] Step 505: Based on the log content obtained in Step 504, calculate the digital fingerprint of this log content according to the hash algorithm;

[0044] Step 506: Read the duplicate elimination policy for this type of log content. Among them, the duplicate elimination policy factors include: time interval, duplicate elimination action;

[0045] Step 507: Compare with the log fingerprint library of the same platform according to the digital fingerprint in Step 505 and the duplicate elimination policy in Step 506. If there is no log with the same digital fingerprint in the log fingerprint library within the time interval, forward the log information to the processing queue and record the current log information and digital fingerprint in the log fingerprint library; otherwise, execute the duplicate elimination action set in Step 506.

[0046] Advantages of the present invention:

[0047] The present invention forms analyzable and monitorable control index items by formatting and structuring the originally scattered and irregular logs, mines core high-value information from a large number of logs, and achieves the purpose of linking log information with business control. And perform real-time analysis and processing on the logs to realize the subversive and effective utilization of log information, thereby significantly improving the enterprise's security risk perception ability and perception speed for various control indicators. At the same time, this perception ability can be extended by adding corresponding business log collection logic and analysis and processing logic to meet the various differential security control requirements of different enterprises at different development stages.

[0048] The platform provided by the present invention can incorporate the logs of various enterprise software and hardware systems into a unified platform for management, eliminate information silos, break down the difference barriers between heterogeneous devices and systems, and manage the logs of all device systems from a unified platform entry. Compared with the original method of independently managing each scattered and isolated log information source, it has great advantages, which can further make the perception and response of security management more agile and systematic, and provide strong support for the realization of enterprise security management goals.

[0049] Through the linkage operation with external systems, the platform of the present invention improves the intelligent and automated level of enterprise security operation and maintenance, effectively provides comprehensive support for the enterprise's information security management, and escorts the realization of the enterprise's security control and business continuity goals.

[0050] Other features and advantages of the present invention will be described in detail in the following specific implementation section. Brief Description of the Drawings

[0051] By describing the exemplary embodiments of the present invention in more detail in conjunction with the drawings, the above and other objects, features, and advantages of the present invention will become more apparent. Among them, in the exemplary embodiments of the present invention, the same reference numerals generally represent the same components.

[0052] Figure 1 The schematic diagram of an enterprise industrial control security brain platform system according to an embodiment of the present invention is shown.

[0053] Figure 2 The flowchart of the steps of the operation method of the enterprise industrial control security brain platform system according to an embodiment of the present invention is shown.

[0054] Figure 3 The schematic diagram of the streaming processing of log data according to an embodiment of the present invention is shown.

[0055] Figure 4 The schematic flowchart of the real-time processing of network device load logs according to an embodiment of the present invention is shown.

[0056] Figure 5 The schematic flowchart of the real-time processing of interface network management mode logs according to an embodiment of the present invention is shown. Detailed Description of the Invention

[0057] The following will describe the preferred embodiments of the present invention in more detail. Although the following describes the preferred embodiments of the present invention, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein.

[0058] Embodiment 1

[0059] As Figure 1As shown in the figure, the industrial control security brain platform system of the enterprise includes a log information collection layer, an intelligent analysis and processing layer, a security operation layer, and a system interface layer:

[0060] The log information collection layer is used to collect structured log information through a log collection script program and send it to the intelligent analysis and processing layer;

[0061] The intelligent analysis and processing layer is used to receive the structured log information for real-time analysis and processing, and send the abnormal problems to the security operation layer according to the analysis and processing results;

[0062] The security operation layer is used to configure, manage, and monitor the log information collection layer and the intelligent analysis and processing layer, and perform abnormal processing on the abnormal management indicators reflected in the log information;

[0063] The system interface layer is used to manage the external interfaces of the platform system, as well as the docking and management of external system interfaces.

[0064] In one example, collecting structured log information through a log collection script program includes: directly collecting from devices or systems through an active polling sampling method to obtain structured log information.

[0065] Collecting structured log information through a log collection script program includes: collecting, cleaning, supplementing, and formatting the original log information generated by devices or systems through the method of listening to the original log to form structured log information.

[0066] Specifically, the industrial control security brain platform system of the enterprise includes: a log information collection layer, an intelligent analysis and processing layer, a security operation layer, and a system interface layer;

[0067] The log information collection layer mainly collects logs in two ways through a log collection script program: First, directly collect structured logs in a definable format from devices or systems through an active polling sampling method; Second, collect, clean, supplement, and format the original log information generated by devices or systems through the method of listening to the original log to form structured logs; The structured log information collected through the above two methods will be further submitted to the intelligent analysis and processing layer for further analysis and processing;

[0068] The intelligent analysis and processing layer is responsible for receiving the data transferred from the log information collection layer for real-time analysis and processing, and according to the analysis and processing results, pushing the abnormal problems to the early warning, work order and other modules of the security operation layer to drive the subsequent abnormal processing process.

[0069] The security operation layer configures, manages, and monitors the log information collection layer and the intelligent analysis and processing layer, and performs abnormal processing on the abnormal management indicators reflected in the log information, including:

[0070] The log collection management module is used to manage and monitor the collection script programs in the log information collection layer;

[0071] The scheduled task management module is used to manage the execution of scheduled tasks;

[0072] The monitoring index management module is used to configure and define various types of monitoring indexes of the enterprise;

[0073] The configuration management module is used to centrally save and manage the detailed information of software and hardware configuration items required for the entire security operation environment, and record the changes in the configuration information;

[0074] The early warning management module is used to define the early warning strategies, early warning methods and early warning information management of various management indexes, and reserve the methods for docking with external mail systems, SMS interfaces, and WeChat interfaces;

[0075] The work order management module is used to record the processing process of the work order task items generated by the security brain platform to form a management closed-loop;

[0076] The data report module is used to display and output various security operation management reports;

[0077] The large screen display module is used for the large screen display of the enterprise security monitoring center.

[0078] The system interface layer is used for the management of the external open interfaces of the platform system, as well as the docking and management of external system interfaces; the system interface layer includes business interfaces, device interfaces, etc., and the external system interfaces include SMS platforms, mail systems, WeChat platforms, external system (device) open interfaces, etc. The intelligent analysis and processing layer can, according to the external system interface call methods defined in this module, combine with the processing strategy to trigger the call of the external system interface to realize the linkage operation with the external system, so as to further realize the intelligent operation and maintenance and automated operation and maintenance capabilities for the security brain platform (ESB).

[0079] Embodiment 2

[0080] Figure 2 The flowchart showing the steps of the operation method of the enterprise industrial control security brain platform system according to an embodiment of the present invention is shown.

[0081] As Figure 2 shown, the operation method of the enterprise industrial control security brain platform system includes:

[0082] Step 1: Register the collector program in the security operation layer, generate a unique identification ID for the collection task, and verify the collection script program;

[0083] Step 2: Define the collector program, write the collection program code to formulate the log collection logic and strategy for the collection monitoring object, and add a code segment identifying its own task to the code;

[0084] Step 3: Collect structured log information through the log collection script program and send it to the intelligent analysis and processing layer;

[0085] Step 4: The intelligent analysis and processing layer realizes the real-time analysis and processing of structured log information through the big data streaming processing framework, and sends the abnormal problems to the security operation layer according to the analysis and processing results;

[0086] Step 5: The security operation layer performs exception handling for the abnormal management indicators reflected in the log information.

[0087] Specifically, the operation method of the enterprise industrial control security brain platform system includes:

[0088] Step 1: In the log collection management module of the security operation layer, register and define the collector program, generate a unique identifier ID for the collection task. The log collection script program uses this unique identifier to identify its own legitimacy with the security brain (ESB). The collection script program without a normal identifier will not be able to report log information normally through the verification of the security brain (ESB) platform. At the same time, the security brain (ESB) checks the working status of the monitoring log collection script program based on this unique identifier.

[0089] Step 2: Define the collector program, write the collection program code to formulate the log collection logic and strategy for the collection monitoring object, and add a code segment identifying its own task ID to the code.

[0090] Step 3: Configure the timed task management module of the security operation layer of the security brain (ESB) to set the timed execution frequency for the switch load log collection script in the polling sampling method, so that the collection script is executed regularly.

[0091] Step 4: Execute the collector program to start log information collection.

[0092] Step 5: Perform intelligent analysis and processing on the log content.

[0093] This embodiment will take two log collection methods in the log information collection layer in Step 2 as examples to illustrate the log collection working mechanism in detail:

[0094] (1) Active polling sampling: Use Python to access network devices to obtain information such as CPU load, memory usage, and real-time bandwidth rate, and form structured logs in the following format:

[0095] {

[0096] "Network device load": {"plant area": "Headquarters", "device type": "Switch", "device IP": "10.10.10.2", "CPU load": "30%", "memory occupancy": "40%", "real-time bandwidth": "23456Kbps", "log time": "October 21, 2021 12:01:15", "collection task ID"}

[0097] }

[0098] Push this structured log information to the intelligent analysis and processing layer for further judgment and processing.

[0099] (2) Monitor the original log: Collect, clean, and format the original log information generated by the device or system. Take the example of using Python to detect changes in the network management methods of each interface of the network firewall. Write a Python program to monitor the UPD514 port of the firewall and obtain the syslog log. The original log is in the following form:

[0100] The IPSec tunnel SA received a notification message, name: [xxx], address: [A.B.C.D / 500], status: [-], notification content: [INVALID-MESSAGE-ID], Cookie: [4e16f915dd4ff3d9 / 04875b01b7dee1da]

[0101] from module: Interface, information: Interface [ge2] has enabled the management method [HTTP]

[0101] Module: Address information, detailed information: Add an address object host entry, name: [Internal network server], type: [Contains], host: [1.2.3.4]

[0102] It can be seen that even for different types of logs of the same device, there is no unified specification rule, and important information such as device type and IP is missing. Filter and extract the interface network management method change information from the above unstructured text information through the Python log collection program, supplement the important information, and format it. Extract the key and valid information into a structured log as follows:

[0103] {

[0104] "Interface network management method": {"plant area": "Headquarters", "device type": "Switch", "device IP": "10.10.10.2", "interface": ["ge2"], "management method": "HTTP", "is enabled": true, "log time": "October 21, 2021 12:03:00", "collection task ID"}

[0105] }

[0106] Push this structured log information to the intelligent analysis and processing layer for further judgment and processing.

[0107] In step 5, the intelligent analysis and processing layer uses a big data streaming processing framework to achieve real-time analysis and processing of structured log information. As Figure 3 shown, according to the analysis and processing results, send the abnormal problems to the security operation layer;

[0108] The framework uses Kafka as the message queue to receive the log messages generated by the log collection program, accurately enqueue them for subsequent analysis and processing programs to consume in sequence. The analysis and processing section uses Storm as the streaming processing engine, writes a Storm topology program to complete the log message processing logic, and submits the cluster to run the topology. According to the two types of metric log supervision exemplified in step 2 of this embodiment, the real-time processing logic process is described as follows:

[0109] (1) Consumption of network switch load log information: First, the Storm topology program checks whether the collection task ID is registered on the platform. If it is not registered, it is ignored. If it is registered, the subsequent processing continues. The process is as follows: Parse the received log information, compare the load situation of the IP network device to which it belongs with the two data items of the historical average load of the corresponding IP device and the load threshold maintained in the configuration library. If the current load exceeds the historical average load or the load threshold, generate an operation and maintenance work order and trigger SMS and email warning notifications to the operation and maintenance personnel for processing. At the same time, write the current log into the database for persistent storage and recalculate and update the historical average load of the corresponding device. The subsequent processing feedback process is reflected in the operation and maintenance work order. The processing logic is as Figure 4 shown.

[0110] (2) Consumption of interface network management mode log information: First, the Storm topology program checks whether the collection task ID is registered on the platform. If it is not registered, it is ignored. If it is registered, the subsequent processing continues. The process is as follows: Parse the received log information, compare the current network management mode change situation of the log report IP network device with the network management mode that should be configured in the corresponding device interface definition in the configuration library. If they match, only save the log data without triggering other operations. If they do not match, generate an operation and maintenance work order and trigger SMS and email warning notifications to the operation and maintenance personnel for processing. The subsequent processing feedback process is reflected in the operation and maintenance work order. The processing logic is as Figure 5 shown.

[0111] So far, the complete control process of the above two security monitoring metrics (network device load monitoring and device interface network management method monitoring) described in step 5 has been completed, from log collection to real-time analysis, anomaly warning, generating task work orders, and work order performance evaluation. Similarly, other business security metrics concerned in the enterprise information security management process can also follow the above model, and complete custom configuration and incorporate them into the real-time control of the Security Brain (ESB) platform through processes such as defining and writing collection program scripts, writing intelligent analysis and processing programs, and submitting for operation.

[0112] In step 5, for abnormal reception, abnormal handling is performed, including:

[0113] Step 501: Determine whether the expected log information has been collected within a predetermined time period. If so, execute step 504; if not, execute step 502;

[0114] Step 502: Determine whether there is abnormal stack information within the time period for the log that has not been collected normally. If so, obtain the abnormal stack information and assign a unique identifier; if not, generate the result of this collection failure as an abnormal problem and assign a unique identifier;

[0115] Step 503: Check whether there is already alarm information with the corresponding unique identifier in the alarm library. If not, record the abnormal problem containing the unique identifier in the alarm library;

[0116] Step 504: Filter the time information of the log content for the log information, and filter out the log content that does not contain time information;

[0117] Step 505: Based on the log content obtained in step 504, calculate the digital fingerprint of this log content according to the hash algorithm;

[0118] Step 506: Read the duplicate elimination policy for this type of log content, where the duplicate elimination policy factors include: time interval, duplicate elimination action;

[0119] Step 507: Compare the digital fingerprint in step 505 with the duplicate elimination policy in step 506 against the platform log fingerprint library. If there is no log with the same digital fingerprint in the log fingerprint library within the time interval, forward the log information to the processing queue and record the current log information and digital fingerprint in the log fingerprint library; otherwise, execute the duplicate elimination action set in step 506.

[0120] The above has described the embodiments of the present invention. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes are obvious to those of ordinary skill in the art in the technical field without departing from the scope and spirit of the described embodiments.

Claims

1. A running method of an enterprise industrial control security brain platform system, characterized in that, The enterprise industrial control security brain platform system includes a log information collection layer, an intelligent analysis and processing layer, a security operation layer, and a system interface layer: The log information collection layer is used to collect structured log information through a log collection script program and send it to the intelligent analysis and processing layer; The intelligent analysis and processing layer is used to receive the structured log information for real-time analysis and processing, and send abnormal problems to the security operation layer according to the analysis and processing results; The security operation layer is used to configure, manage, and monitor the log information collection layer and the intelligent analysis and processing layer, and perform abnormal processing for the abnormal problems; The system interface layer is used for the management of the external interfaces of the platform system, as well as the docking and management of external system interfaces; The operation method includes: Step 1: Register a collector program in the security operation layer, generate a unique identifier ID for the collection task, and verify the log collection script program; Step 2: Define the collector program, write the collection program code to formulate the log collection logic and strategy for the collection monitoring object, and add a code segment identifying its own task to the code; Step 3: Collect structured log information through a log collection script program and send it to the intelligent analysis and processing layer; Step 4: The intelligent analysis and processing layer realizes the real-time analysis and processing of the structured log information through a big data streaming processing framework, and sends abnormal problems to the security operation layer according to the analysis and processing results; Step 5: The security operation layer performs abnormal processing for the abnormal problems; In Step 5, the abnormal processing for abnormal reception includes: Step 501: Judge whether the expected log information is collected within a predetermined time period. If so, execute Step 504; if not, execute Step 502; Step 502: Judge whether there is abnormal stack information in the time period for the log that is not normally collected. If so, obtain the abnormal stack information and assign a unique identifier; if not, generate the result of this collection failure as an abnormal problem and assign a unique identifier; Step 503: Check whether there is an alarm information with the corresponding unique identifier in the alarm library. If not, record the abnormal problem containing the unique identifier in the alarm library; Step 504: Filter the time information of the log content for the log information, and screen out the log content that does not contain time information; Step 505: Based on the log content obtained in Step 504, calculate the digital fingerprint of this log content according to the hash algorithm; Step 506: Read the duplicate elimination policy for this type of log content, where the duplicate elimination policy factors include: time interval, duplicate elimination action; Step 507: Compare the digital fingerprint in Step 505 with the duplicate elimination policy in Step 506 with the platform log fingerprint library. If there is no log with the same digital fingerprint in the log fingerprint library within the time interval, forward the log information to the processing queue, and record the current log information and digital fingerprint in the log fingerprint library; otherwise, execute the duplicate elimination action set in Step 506.

2. The operating method according to claim 1, characterized in that, Collecting structured log information through a log collection script program includes: directly collecting from devices or systems through an active polling sampling method to obtain the structured log information.

3. The operating method according to claim 1, characterized in that, Collecting structured log information through the log collection script program includes: collecting, cleaning, supplementing, and formatting the original log information generated by devices or systems by listening to the original logs to form the structured log information.

4. The operating method according to claim 1, characterized in that The security operation layer includes: a log collection management module for managing and monitoring the collection script program.

5. The operating method according to claim 4, characterized in that The security operation layer further includes: a scheduled task management module for managing and executing scheduled tasks; a monitoring metric management module for configuring monitoring metrics.

6. The operating method according to claim 5, characterized in that, The security operation layer further includes: a configuration management module for centrally storing and managing the configuration information of software and hardware required for the entire security operation environment, and recording the changes in the configuration information; a work order management module for recording the processing process of work order task items generated by the security brain platform.

7. The operating method according to claim 6, characterized in that, The security operation layer further includes: a warning management module for defining warning strategies, warning methods, and warning information management of management metrics.

8. The operating method according to claim 7, characterized in that, The security operation layer further includes: a data report module for displaying and outputting security operation management reports; a large screen display module for large screen display in the enterprise security monitoring center.

Citation Information

Patent Citations

  • Log treatment operation and maintenance monitoring system

    CN106371986A