Alarm information analysis method and device, electronic equipment and storage medium
By establishing a correspondence between login response messages and login status of business systems in the secure managed service platform, the high false alarm rate of weak password alarm information identification in the existing technology is solved, and accurate alarms for different business systems are realized.
Patent Information
- Application Number
- CN202111485761.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-07
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2041-12-07
AI Technical Summary
In existing technologies, when security managed service platforms identify weak password alarm information for enterprise users' business systems, the false alarm rate is high, making it difficult to accurately distinguish the login status of different business systems, resulting in insufficient accuracy of alarm information.
By acquiring weak password alarm information from the alarm system, the corresponding business system is identified, and a preset correspondence between login response messages and login status is established for each business system. This information is then imported into the alarm system to identify the login status of weak password access requests, and is accurately distinguished using Uniform Resource Locators (URLs) and login response message tags.
The system improved the accuracy of weak password alarms, reduced false alarms, and enabled accurate differentiation and targeted analysis of login status for different business systems.
Smart Images

Figure CN114417314B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to an alarm information analysis method, apparatus, electronic device, and computer storage medium. Background Technology
[0002] Office automation (OA) systems, as a type of business system, are widely used by enterprise users. These systems provide business services to users after they log in, based on user access control. However, users sometimes set weak passwords. Weak passwords have limited strength, and their vulnerability can easily lead to cybersecurity risks.
[0003] In related technologies, Managed Security Service Platforms (MSSPs) are used to manage multiple business systems of enterprise users, providing managed security services for these systems. The login response message format may differ for each business system, resulting in a wide variety of formats and increasing the difficulty of identifying the user's login status. This leads to a high false alarm rate for weak password alerts from alarm systems. Therefore, improving the accuracy of weak password alerts generated by alarm systems has become a crucial issue that urgently needs to be addressed. Summary of the Invention
[0004] This application provides an alarm information analysis method, apparatus, electronic device, and computer storage medium, which can improve the accuracy of weak password alarm information generated by the alarm system.
[0005] This application provides an alarm information analysis method, including:
[0006] Obtain weak password alarm information from the alarm system; determine the business system corresponding to each weak password alarm information;
[0007] The login status corresponding to the login reply message of each of the business systems is identified, and a preset correspondence is established for each of the business systems. The preset correspondence is used to indicate the correspondence between the login reply message and the login status.
[0008] The preset mapping relationship is imported into the alarm system, so that the alarm system can identify the login status of the weak password access request based on the preset mapping relationship of the business system to which the weak password access request belongs.
[0009] In one implementation, identifying the login status corresponding to each login response message from the business system includes:
[0010] Obtain the tag of the login response message for each of the business systems; the tag is used to mark the login status of the weak password access request corresponding to the login response message;
[0011] Based on the tags of the login response messages of each of the business systems, the login status corresponding to the login response messages of each business system is identified.
[0012] In one implementation, determining the business system corresponding to each of the weak password alarm messages includes:
[0013] Obtain the Uniform Resource Locator (URL) of the business system corresponding to the weak password alarm information;
[0014] Based on the Uniform Resource Locator, determine the business system corresponding to each of the weak password alarm messages.
[0015] This application provides a weak password detection method, including:
[0016] Determine the business system to which the weak password access request belongs; obtain the preset correspondence of the business system, the preset correspondence being used to indicate the correspondence between login response messages and login status;
[0017] Obtain the login response message from the business system, and determine the login status of the weak password access request corresponding to the login response message based on the preset correspondence.
[0018] Based on the login status of the weak password access request, determine whether to generate a weak password alarm message.
[0019] In one implementation, determining whether to generate a weak password alarm based on the login status of the weak password access request includes:
[0020] When the login status of the weak password access request of the business system belongs to the target login status, obtain the frequency information of the target login status within a preset time period.
[0021] Based on the frequency of the target login status within a preset time period, determine whether to generate a weak password alarm message.
[0022] In one implementation, determining whether to generate a weak password alarm based on the login status of the weak password access request includes:
[0023] When the login status of the weak password access request in the business system belongs to the target login status, the login reply message corresponding to the weak password access request is obtained.
[0024] Based on the login response message corresponding to the weak password access request, determine whether a weak password alarm message should be generated.
[0025] In one implementation, the method further includes:
[0026] A security log file that records login response messages from the aforementioned business system;
[0027] Determine the label of the target login response message, wherein the label of the target login response message is the label of the login response message to which the security log is to be output;
[0028] Based on the tags of the target login response message, extract the security log corresponding to the tags of the target login response message from the security log file.
[0029] An alarm information analysis device provided in this application embodiment includes:
[0030] The acquisition module is used to acquire weak password alarm information from the alarm system and determine the business system corresponding to each weak password alarm information.
[0031] The processing module is used to identify the login status corresponding to the login reply message of each of the business systems, and to establish a preset correspondence relationship for each of the business systems. The preset correspondence relationship is used to indicate the correspondence between the login reply message and the login status.
[0032] The analysis module is used to import the preset correspondence into the alarm system, so that the alarm system can identify the login status of the weak password access request based on the preset correspondence of the business system to which the weak password access request belongs.
[0033] In one implementation, the processing module is used to identify the login status corresponding to each login response message of the business system, including:
[0034] Obtain the tag of the login response message for each of the business systems; the tag is used to mark the login status of the weak password access request corresponding to the login response message;
[0035] Based on the tags of the login response messages of each of the business systems, the login status corresponding to the login response messages of each business system is identified.
[0036] In one implementation, the acquisition module is used to determine the business system corresponding to each of the weak password alarm messages, including:
[0037] Obtain the Uniform Resource Locator (URL) of the business system corresponding to the weak password alarm information;
[0038] Based on the Uniform Resource Locator, determine the business system corresponding to each of the weak password alarm messages.
[0039] This application provides a weak password detection device, comprising:
[0040] The determination module is used to determine the business system to which the weak password access request belongs; and to obtain the preset correspondence of the business system, wherein the preset correspondence is used to indicate the correspondence between the login reply message and the login status;
[0041] The identification module is used to obtain the login response message of the business system and determine the login status of the weak password access request corresponding to the login response message based on the preset correspondence.
[0042] The alarm module is used to determine whether to generate a weak password alarm message based on the login status of the weak password access request.
[0043] In one implementation, the alarm module is used to determine whether to generate a weak password alarm message based on the login status of the weak password access request, including:
[0044] When the login status of the weak password access request of the business system belongs to the target login status, obtain the frequency information of the target login status within a preset time period.
[0045] Based on the frequency of the target login status within a preset time period, determine whether to generate a weak password alarm message.
[0046] In one implementation, the alarm module is used to determine whether to generate a weak password alarm message based on the login status of the weak password access request, including:
[0047] When the login status of the weak password access request in the business system belongs to the target login status, the login reply message corresponding to the weak password access request is obtained.
[0048] Based on the login response message corresponding to the weak password access request, determine whether a weak password alarm message should be generated.
[0049] In one implementation, the alarm module is further configured to:
[0050] A security log file that records login response messages from the aforementioned business system;
[0051] Determine the label of the target login response message, wherein the label of the target login response message is the label of the login response message to which the security log is to be output;
[0052] Based on the tags of the target login response message, extract the security log corresponding to the tags of the target login response message from the security log file.
[0053] This application provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory that can run on the processor. When the processor executes the program, it implements the methods provided by one or more of the aforementioned technical solutions.
[0054] This application provides a computer storage medium storing a computer program; when the computer program is executed, it can implement the alarm information analysis method provided by one or more of the aforementioned technical solutions.
[0055] Based on the alarm information analysis method provided in this application, weak password alarm information of the alarm system is obtained; the business system corresponding to each weak password alarm information is determined; and targeted analysis is performed on the business systems with weak password alarm information in multiple business systems. The login status corresponding to the login response message of each business system is marked, and a preset correspondence is established for each business system. The preset correspondence is used to indicate the correspondence between the login response message and the login status; the preset correspondence is imported into the alarm system, so that the alarm system can identify the login status of the weak password access request based on the preset correspondence of the business system to which the weak password access request belongs. Therefore, the login status corresponding to the login response message of different business systems can be accurately distinguished, improving the accuracy of the weak password alarm information generated by the alarm system.
[0056] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this application. Attached Figure Description
[0057] Figure 1 This application provides an illustration of an alarm information analysis method.
[0058] Figure 2 A flowchart illustrating an alarm information analysis method provided in this application embodiment. Figure 1 ;
[0059] Figure 3 A schematic diagram illustrating the process of identifying login response messages from a business system, provided as an embodiment of this application;
[0060] Figure 4 A flowchart illustrating an alarm information analysis method provided in this application embodiment. Figure 2 ;
[0061] Figure 5 A flowchart illustrating a weak password detection method provided in an embodiment of this application;
[0062] Figure 6 This application provides a schematic diagram of the process for generating weak password alarm information in an embodiment of the present application. Figure 1 ;
[0063] Figure 7 This application provides a schematic diagram of the process for generating weak password alarm information in an embodiment of the present application. Figure 2 ;
[0064] Figure 8 A schematic diagram of an alarm information analysis device provided in an embodiment of this application;
[0065] Figure 9 A schematic diagram of a weak password detection device provided in an embodiment of this application;
[0066] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0067] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments provided herein are merely illustrative of the present application and are not intended to limit the present application. Furthermore, the embodiments provided below are some embodiments for implementing the present application, and not all embodiments for implementing the present application. Unless otherwise specified, the technical solutions described in the embodiments of the present application can be implemented in any combination.
[0068] In related technologies, the Burp Suite platform is used to confirm weak password alarm information. A password book is assembled based on the username and password. The browser's proxy request is intercepted at the login entry point to obtain the login request message and perform batch verification of weak password alarm information. However, the alarm system still has the problem of a high false alarm rate.
[0069] Here, the Burp Suite platform is an integrated platform for attacking web applications, containing a variety of network attack tools. The Burp Suite platform provides interfaces for network attack tools to speed up the process of attacking web applications.
[0070] In related technologies, active scanning tools are used to confirm weak password alarm information. However, active scanning tools do not have fingerprints of non-general business systems. Therefore, they cannot identify weak password alarm information in self-developed business systems of non-general business systems, and the alarm system still has a high false alarm rate.
[0071] Meanwhile, the range of usernames and passwords determines the detection capabilities of security scanning tools; when complex CAPTCHAs are present, security scanning tools cannot identify weak password alerts in business systems. Therefore, the alert system still suffers from a high false alarm rate.
[0072] In related technologies, network security devices detect passive traffic to obtain security audit logs for business systems. The Security Information and Event Management (SIEM) system provides login access to users, who then identify weak password alerts in the security audit logs.
[0073] To address the aforementioned technical problems, this application provides an alarm information analysis method, apparatus, electronic device, and storage medium. The alarm information analysis method provided in this application will be described in detail below.
[0074] Figure 1 This diagram illustrates an application scenario of an alarm information analysis method provided in an embodiment of this application. See also... Figure 1 Web system 101 is deployed on the user end, and secure managed service platform 102 is deployed on the server end. Web system 101 provides a login interface for users, who enter their account and password on the login interface to access the business system hosted in secure managed service platform 102.
[0075] In the example, the secure managed service platform 102 hosts multiple business systems, including business system 1, business system 2, business system 3, ..., business system i, ..., business system N.
[0076] In the example, multiple business systems can correspond to different enterprise users. For example, business system 1 corresponds to enterprise user 1, business system 2 corresponds to enterprise user 2, and business system i corresponds to enterprise user i.
[0077] In the example, the business system can be an office automation system, including but not limited to any of the following systems: customer relationship management system, supply chain system, financial system, work order system, enterprise resource planning system, email system, human resources system, and instant messaging system.
[0078] In this example, a network security device 103 is installed between the web system 101 and the secure managed service platform 102. The network security device 103 is used to perform security auditing on network traffic and identify network security incidents. The secure managed service platform 102 includes a SIEM system 104.
[0079] In the example, the device type of the network security device may include any of the following: network probe device, application firewall (AF) device, intrusion prevention system (IPS), endpoint detection and response (EDR) device, and situational awareness device.
[0080] In this example, the SIEM system includes multiple SIEM sensors. These sensors detect network events in network nodes, record the correlation information of these events, and obtain data records of the network events. The SIEM system periodically accesses these data records, identifies network events from multiple sources, and generates alarm information when a network event is identified as a network attack event.
[0081] Figure 2 A schematic flowchart of the alarm information analysis method provided in an embodiment of this application is shown. See also Figure 2 The alarm information analysis method provided in this application embodiment may include the following steps:
[0082] Step A201: Obtain weak password alarm information from the alarm system; determine the business system corresponding to each weak password alarm.
[0083] Here, a weak password is a password that is easy to crack and has low strength, such as "123" or "abc". Accounts with weak passwords can easily pose a security risk to the business system.
[0084] In the example, an alerting system is deployed on the secure managed service platform. The alerting system can adopt a SIEM system. As a security auditing system, the SIEM system can monitor security threats in real time and identify abnormal access behavior based on security reports and compliance management.
[0085] In the example, the security managed service platform can manage multiple business systems. When obtaining weak password alarm information from the alarm system, this application determines the business system corresponding to each weak password alarm information. Therefore, it can perform targeted analysis on business systems with weak password alarm information in multiple business systems.
[0086] In the example, the alarm system retrieves weak password alarm information from the security audit logs or security device alarms based on the weak password identifier. Here, the weak password identifier can be the username used by the account corresponding to the weak password in the business system.
[0087] For example, based on the identification information of weak passwords, the managed security service platform 102 can query the weak password alarm information of the SIEM system from the security audit logs or security device alarms collected by the SIEM system.
[0088] In the example, password information is extracted from the login request information submitted by the user to the business system, and weak password detection is performed on the password information in the login request information to determine whether the password information in the login request information is a weak password.
[0089] In the example, when the password information in the login request is identified as a weak password, the weak password identification information is recorded in the SIEM system. Therefore, weak password alarm information can be obtained from the SIEM system based on the weak password identification information.
[0090] Step A202: Identify the login status corresponding to the login reply message of each business system, and establish a preset correspondence for each business system. The preset correspondence is used to indicate the correspondence between the login reply message and the login status.
[0091] In the example, the tagging results of the user's login response messages to the business system are obtained. The tagging results include the login status corresponding to the login response messages. Based on the tagging results, the login status corresponding to the login response messages is identified, and a correspondence between login response messages and login statuses is established.
[0092] In the example, refer to Table 1 to obtain the tags of the login response messages from the business system; the tags are used to mark the login status corresponding to the login response messages. Here, the tags of the login response messages can include any of the following: login successful, username and password do not match, account expired, account locked.
[0093] Table 1 Tags of Login Response Messages
[0094]
[0095] In the example, the login response messages of the business system are marked according to the tags of the login response messages of the business system, and the marking results of the login response messages of the business system are obtained.
[0096] Step A203: Import the preset mapping relationship into the alarm system, so that the alarm system can identify the login status of the weak password access request based on the preset mapping relationship of the business system to which the weak password access request belongs.
[0097] In the example, the preset mapping relationship is imported into the SIEM system, so that the SIEM system can identify the login status of the weak password access request based on the preset mapping relationship of the business system to which the weak password access request belongs.
[0098] In the example, when the password information in the login request is identified as a weak password, it is determined that the login request to access the business system is a weak password access request.
[0099] Based on the alarm information analysis method provided in this application, weak password alarm information from the alarm system is obtained; the business system corresponding to each weak password alarm is determined; and targeted analysis is performed on business systems with weak password alarm information across multiple business systems. The login status corresponding to the login response message of each business system is marked, and a preset correspondence is established for each business system. This preset correspondence is used to indicate the correspondence between login response messages and login statuses. The preset correspondence is imported into the alarm system, enabling the alarm system to identify the login status of weak password access requests based on the preset correspondence of the business system to which the weak password access request belongs. Therefore, the login status corresponding to login response messages from different business systems can be accurately distinguished, improving the accuracy of weak password alarm information generated by the alarm system.
[0100] In practical applications, steps A201 to A203 can be implemented using a processor. The processor can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), controller, microcontroller, and microprocessor.
[0101] In one implementation, in step A202 above, the login response message for each business system is identified, see [link to relevant documentation]. Figure 3 This may include the following steps:
[0102] Step A301: Obtain the tag of the login response message for each business system; the tag is used to mark the login status of the weak password access request corresponding to the login response message.
[0103] In the example, based on user interaction, the tags assigned by the user to the login response message for the business system are obtained. That is, the user determines the tags for the login response message. Therefore, identifying the login status corresponding to the login response message can be done manually.
[0104] In the example, based on the search function provided by the SIEM system, the login response message corresponding to the weak password alarm information is obtained, and the tags of all login response messages that may show a login status are enumerated.
[0105] In practical applications, different business systems provide users with different login methods, and the corresponding login response messages differ for each method. The login response message can carry the username requesting to log in to the business system.
[0106] In the example, for the same business system, when multiple users' login response messages correspond to the same login status, the labels of the login response messages can be the same. That is, when multiple users' login response messages correspond to the same login status in the same business system, the corresponding labels of the login response messages are the same.
[0107] Step A302: Identify the login status corresponding to the login response message of each business system based on the tag of the login response message of each business system.
[0108] In the example, based on the tags of the login reply messages, the login status corresponding to the login reply messages is enumerated, and the login status corresponding to the login reply messages is identified according to the tags of the login reply messages.
[0109] It should be understood that classifying business systems and enumerating the login status corresponding to the login response messages of a specific business system can accurately distinguish the different login statuses of accounts with weak passwords, thereby improving the accuracy of weak password alarm information generated by the alarm system.
[0110] In practical applications, the data table can record the correspondence between the login response messages and login status used by each business system, and the data table can be stored in the storage server of the secure managed service platform.
[0111] In related technologies, the login response messages for weak passwords in different business systems are not significantly different, leading to inaccurate distinction of login status.
[0112] In this embodiment, the tag of the login response message of the business system is obtained; the tag is used to mark the login status corresponding to the login response message; therefore, the user can determine the tag of the login response message of the business system, and the tag of the login response message of the business system is obtained based on the interaction with the user, and the login response message of the business system is marked, thereby improving the accuracy of identifying the login status corresponding to the login response message.
[0113] In one implementation, determining the business system corresponding to each weak password alarm message in step A201 above may include the following steps:
[0114] Obtain the Uniform Resource Locator (URL) of the business system corresponding to the weak password alarm information; determine the business system corresponding to each weak password alarm information based on the URL.
[0115] In this example, the weak password alarm information is categorized based on the Uniform Resource Locator (URL) of the corresponding business system. Here, the URL of the business system corresponds to the domain name of that business system.
[0116] It should be understood that when classifying the business systems to which weak password alarm information belongs, the Uniform Resource Locator (URL) can be used as the smallest unit for classifying business systems.
[0117] In the example, the domain name of the business system corresponding to the weak password alarm information is obtained; based on the domain name of the business system, the business system corresponding to each weak password alarm information is determined.
[0118] Based on the same technical concept as the foregoing embodiments, see Figure 4 The alarm information analysis method provided in this application embodiment may include the following steps:
[0119] Step A401: Obtain alarm information for weak passwords in the SIEM system.
[0120] Step A402: Identify the business system corresponding to each weak password alarm message.
[0121] Step A403: Obtain the login response message from the business system.
[0122] Step A404: Based on the marking results of the login reply message, establish the correspondence between the login reply message and the login status.
[0123] Step A405: Identify the login status of weak password access requests from the business system based on the correspondence.
[0124] Step A406: Based on the tags of the login reply message, output the security log corresponding to the tags of the login reply message.
[0125] Based on the same technical concept as the foregoing embodiments, see Figure 5 The weak password detection method provided in this application embodiment may include the following steps:
[0126] Step A501: Determine the business system to which the weak password access request belongs; obtain the preset mapping relationship of the business system, which is used to indicate the mapping relationship between login reply messages and login status.
[0127] In the example, the domain name of the business system corresponding to the weak password access request is obtained; based on the domain name of the business system, the business system to which the weak password access request belongs is determined.
[0128] In the example, a data table records the mapping between the login response messages and login statuses used by each business system, resulting in a preset mapping relationship for each business system. This data table is pre-stored on the storage server of the secure managed service platform, and is then read to retrieve the preset mapping relationship for each business system.
[0129] Step A502: Obtain the login response message from the business system, and determine the login status of the weak password access request corresponding to the login response message based on the preset correspondence.
[0130] See the example. Figure 1 When a user enters their username and password on the login interface of Web system 101 to access the business system hosted in the secure hosting service platform 102, Web system 101 sends a page request message to the secure hosting service platform 102.
[0131] In the example, the secure managed service platform 102 sends a login request message to the business system based on the page request message. Correspondingly, the business system returns a login response message to the web system 101 via the secure managed service platform 102. Here, the login request message corresponds to a weak password access request.
[0132] The implementation process of steps A501 and A502 can be referred to steps A201 to A203 above, and will not be repeated here.
[0133] Step A503: Based on the login status of the weak password access request, determine whether to generate a weak password alarm message.
[0134] In the example, the login status of weak password access requests is determined. When the frequency of weak password access requests within a preset time period exceeds a preset value, it is determined that the account corresponding to the weak password has abnormal access behavior. In this case, a weak password alarm message is generated.
[0135] In the example, the login status corresponding to the weak password access request is "login successful". Based on the login response message corresponding to the weak password access request, it is identified that the login behavior occurred at an uncommon login location. In this case, a weak password alert message is generated.
[0136] In one implementation, in step A503 above, based on the login status of the weak password access request, it is determined whether a weak password alarm message should be generated. See [link to relevant documentation]. Figure 6 This may include the following steps:
[0137] Step A601: When the login status of a weak password access request in the business system belongs to the target login status, obtain the frequency information of the target login status within a preset time period.
[0138] In the example, weak password alarms corresponding to weak password access requests of each business system are identified. In the security managed service platform 102, the SIEM system is used to record the login status of weak password access requests of each business system and obtain the frequency information of the target login status in a preset time period.
[0139] In the example, see Table 2. The preset time period can be the most recent month. The frequency information of the login status corresponding to the weak password alarm information of the alarm system within the preset time period includes: L1, L2, L3, L4. Here, L1, L2, L3, L4 are natural numbers greater than 0.
[0140] L1 is used to indicate the cumulative number of times the login status "Login Successful" occurs within a preset time period; L2 is used to indicate the cumulative number of times the login status "Username and Password Do Not Match" occurs within a preset time period; and L3 is used to indicate the cumulative number of times the login status "Account Expired" occurs within a preset time period.
[0141] Table 2 Frequency information within the preset time period
[0142]
[0143] Step A602: Based on the frequency of the target login status within a preset time period, determine whether a weak password alarm message should be generated.
[0144] In the example, when the frequency of login status within a preset time period exceeds a preset value, it is determined that the account corresponding to the weak password has abnormal access behavior, and a weak password alarm message is generated in this case.
[0145] In one implementation, in step A503 above, based on the login status of the weak password access request, it is determined whether a weak password alarm message should be generated. See [link to relevant documentation]. Figure 7 This may include the following steps:
[0146] Step A701: When the login status of the weak password access request in the business system belongs to the target login status, obtain the login reply message corresponding to the weak password access request.
[0147] Here, the target login status can include any of the following: login successful, username and password do not match, account expired, or account locked.
[0148] In the example, when the login status corresponding to the weak password access request is "username and password do not match", the login response message corresponding to the weak password access request is retrieved.
[0149] Step A702: Determine whether a weak password alarm message is generated based on the login response message corresponding to the weak password access request.
[0150] In the example, see Table 3. The login response message may include at least one of the following fields: source IP address, destination IP address, protocol type, source port, and destination port.
[0151] Table 3 Field information in login response messages
[0152]
[0153] In the example, the login status corresponding to the weak password alarm information of the alarm system is "login successful". Based on the login reply message corresponding to the weak password alarm information of the alarm system, the source IP address of the multiple login behaviors of the account corresponding to the weak password is extracted.
[0154] In the example, the source IP address of multiple login attempts of the account corresponding to the weak password is obtained. When the source IP addresses of the multiple login attempts are distributed in different locations, it is determined that the account corresponding to the weak password has abnormal access behavior.
[0155] For example, for an account with a weak password, the source IP addresses of multiple login attempts are distributed in Shenzhen and New York. Based on the frequency information of each login location, the location "Shenzhen" is identified as a frequently used login location.
[0156] In the example, the login status corresponding to the weak password access request is "login successful". Based on the login response message corresponding to the weak password access request, when the login behavior is identified as being in an uncommon login location, a weak password alarm message is generated, and a risk warning is issued to the account corresponding to the weak password.
[0157] In one implementation, the alarm information analysis method described above may further include the following steps:
[0158] Record the security log file for login response messages of each business system; determine the tag of the target login response message from the tags of the login response messages of any business system, and the tag of the target login response message is the tag of the login response message for which the security log is to be output; extract the security log corresponding to the tag of the target login response message from the security log file according to the tag of the target login response message.
[0159] In the example, the tag of the login response message corresponding to the target login status is identified as the tag of the target login response message. Based on the retrieval function provided by the SIEM system, the security log corresponding to the tag of the target login response message is extracted from the security log file.
[0160] In the example, a preset rule is configured in the SIEM system to output the security log corresponding to the tag of the target login reply message at preset intervals. Therefore, the security log corresponding to the tag of the login reply message can be output periodically.
[0161] In this embodiment, the security log corresponding to the tag of the login reply message is output based on the tag of the login reply message. Therefore, multiple dimensions of security data can be presented to the user for correlation analysis.
[0162] Based on the same technical concept as the foregoing embodiments, see Figure 8 The alarm information analysis device provided in this application embodiment may include the following modules:
[0163] The acquisition module 801 is used to acquire weak password alarm information from the alarm system and determine the business system corresponding to each weak password alarm information.
[0164] The processing module 802 is used to identify the login status corresponding to the login reply message of each of the business systems and establish a preset correspondence relationship for each of the business systems. The preset correspondence relationship is used to indicate the correspondence relationship between the login reply message and the login status.
[0165] The analysis module 803 is used to import the preset correspondence into the alarm system, so that the alarm system can identify the login status of the weak password access request based on the preset correspondence of the business system to which the weak password access request belongs.
[0166] In one implementation, the processing module 802 is used to identify the login status corresponding to each login response message of the business system, including:
[0167] Obtain the tag of the login response message for each of the business systems; the tag is used to mark the login status of the weak password access request corresponding to the login response message;
[0168] Based on the tags of the login response messages of each of the business systems, the login status corresponding to the login response messages of each business system is identified.
[0169] In one implementation, the acquisition module 801 is used to determine the business system corresponding to each of the weak password alarm messages, including:
[0170] Obtain the Uniform Resource Locator (URL) of the business system corresponding to the weak password alarm information;
[0171] Based on the Uniform Resource Locator, determine the business system corresponding to each of the weak password alarm messages.
[0172] In practical applications, the acquisition module 801, processing module 802 and analysis module 803 can all be implemented using a processor of an electronic device. The processor can be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller and microprocessor. This application embodiment does not limit this.
[0173] Based on the same technical concept as the foregoing embodiments, see Figure 9 The weak password detection device provided in this application embodiment may include the following modules:
[0174] The determination module 901 is used to determine the business system to which the weak password access request belongs; and to obtain the preset correspondence of the business system, wherein the preset correspondence is used to indicate the correspondence between the login reply message and the login status;
[0175] The identification module 902 is used to obtain the login reply message of the business system and determine the login status of the weak password access request corresponding to the login reply message based on the preset correspondence.
[0176] The alarm module 903 is used to determine whether a weak password alarm message is generated based on the login status of the weak password access request.
[0177] In one implementation, the alarm module 903 is used to determine whether to generate a weak password alarm message based on the login status of the weak password access request, including:
[0178] When the login status of the weak password access request of the business system belongs to the target login status, obtain the frequency information of the target login status within a preset time period.
[0179] Based on the frequency of the target login status within a preset time period, determine whether to generate a weak password alarm message.
[0180] In one implementation, the alarm module 903 is used to determine whether to generate a weak password alarm message based on the login status of the weak password access request, including:
[0181] When the login status of the weak password access request of the business system belongs to the target login status, obtain the login reply message corresponding to the weak password access request of the business system.
[0182] Based on the login response message corresponding to the weak password access request from the business system, determine whether a weak password alarm message should be generated.
[0183] In one implementation, the alarm module 903 is further configured to:
[0184] A security log file that records login response messages from the aforementioned business system;
[0185] Determine the label of the target login response message, wherein the label of the target login response message is the label of the login response message to which the security log is to be output;
[0186] Based on the tags of the target login response message, extract the security log corresponding to the tags of the target login response message from the security log file.
[0187] In practical applications, the determination module 901, the identification module 902, and the alarm module 903 can all be implemented using a processor of an electronic device. The processor can be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, and microprocessor. This application embodiment does not limit this.
[0188] In some embodiments, the functions or modules of the apparatus provided in this application can be used to perform the methods described in the above method embodiments. The specific implementation can be referred to the description of the above method embodiments, and for the sake of brevity, it will not be repeated here.
[0189] Based on the same technical concept as the foregoing embodiments, see Figure 10 The electronic device 1000 provided in this application embodiment may include: a memory 1010 and a processor 1020; wherein,
[0190] Memory 1010 is used to store computer programs and data;
[0191] The processor 1020 is configured to execute a computer program stored in memory to implement any of the methods described in the foregoing embodiments.
[0192] In practical applications, memory 1010 can be volatile memory or non-volatile memory; memory 1010 can provide instructions and data to processor 1020.
[0193] Based on the same technical concept as the foregoing embodiments, this application provides a readable storage medium for storing a computer program corresponding to the above-described device control method. The computer program can be executed by the processor of an electronic device to complete the steps described in the foregoing method.
[0194] In practical applications, readable storage media include, but are not limited to, phase-change memory (PCM), programmable random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), random access memory (RAM), read-only memory (ROM), and programmable read-only memory (EPROM).
[0195] The description of the various embodiments above tends to emphasize the differences between the various embodiments. The similarities or similarities can be referred to each other. For the sake of brevity, they will not be repeated here.
[0196] The methods disclosed in the various method embodiments provided in this application can be arbitrarily combined to obtain new method embodiments without conflict.
[0197] The features disclosed in the various product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0198] The features disclosed in the various method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.
[0199] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative and exemplary. The division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components may be combined, or integrated into another system, or some features may be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed may be through some interfaces, and the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0200] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple grid units. Depending on the actual situation, some or all of the units may be selected to achieve the purpose of this embodiment.
[0201] In addition, each functional unit in the various embodiments of this application can be integrated into one processing module, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0202] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments.
[0203] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An alarm information analysis method characterized by comprising: The method comprises the following steps: In the case of hosting a plurality of business systems, obtaining weak password alarm information of an alarm system; Determine the business system corresponding to each of the weak password alarm information; Identify the login state corresponding to the login reply message of each of the business systems, and establish a preset correspondence relationship of each of the business systems, which is used to indicate the correspondence relationship between the login reply message and the login state; The preset correspondence relationship is imported into the alarm system, so that the alarm system identifies the login state of the weak password access request based on the preset correspondence relationship of the business system to which the weak password access request belongs.
2. The method of claim 1, wherein, The determination of the business system corresponding to each of the weak password alarm information comprises: Obtain the uniform resource locator of the business system corresponding to the weak password alarm information; According to the uniform resource locator, determine the business system corresponding to each of the weak password alarm information.
3. A weak password detection method, characterized by, The method comprises the following steps: In the case of hosting a plurality of business systems, determine the business system to which the weak password access request belongs; Obtain the preset correspondence relationship of the business system, which is established by identifying the login state corresponding to the login reply message of each of the business systems; the preset correspondence relationship is used to indicate the correspondence relationship between the login reply message and the login state; Obtain the login reply message of the business system, and determine the login state of the weak password access request corresponding to the login reply message based on the preset correspondence relationship; Determine whether to generate weak password alarm information based on the login state of the weak password access request.
4. The method of claim 3, wherein, The determination of the business system corresponding to each of the weak password alarm information comprises: When the login state of the weak password access request of the business system belongs to the target login state, obtain the frequency information of the target login state within a preset period; According to the frequency information of the target login state within a preset period, determine whether to generate weak password alarm information.
5. The method of claim 3, wherein, The determination of the business system corresponding to each of the weak password alarm information comprises: When the login state of the weak password access request of the business system belongs to the target login state, obtain the login reply message corresponding to the weak password access request; According to the login reply message corresponding to the weak password access request, determine whether to generate weak password alarm information.
6. The method according to any one of claims 3 to 5, characterized in that, The method further comprises: Record the security log file of the login reply message of the business system; Determine the label of the target login reply message, which is the label of the login reply message to be output as a security log; According to the label of the target login reply message, extract the security log corresponding to the label of the target login reply message in the security log file.
7. An alarm information analysis device characterized by comprising: The method comprises the following steps: An acquisition module is configured to obtain weak password alarm information of an alarm system in the case of hosting a plurality of business systems; Determine the business system corresponding to each of the weak password alarm information; The processing module is configured to identify a login state corresponding to a login reply message of each of the business systems, and establish a preset correspondence relationship of each of the business systems, the preset correspondence relationship being used to indicate a correspondence relationship between the login reply message and the login state. The analysis module is configured to import the preset correspondence relationship into the alarm system, so that the alarm system identifies the login state of the weak password access request based on the preset correspondence relationship of the business system to which the weak password access request belongs.
8. A weak password detection apparatus, characterized by comprising: The method comprises: The determining module is configured to determine a business system to which the weak password access request belongs in a case where a plurality of business systems are hosted; The preset correspondence relationship of the business system is established by identifying a login state corresponding to a login reply message of each of the business systems; and the preset correspondence relationship is used to indicate a correspondence relationship between the login reply message and the login state. The identifying module is configured to acquire the login reply message of the business system, and determine a login state of the weak password access request corresponding to the login reply message based on the preset correspondence relationship of the business system to which the weak password access request belongs. The alarm module is configured to determine whether to generate weak password alarm information based on the login state of the weak password access request.
9. An electronic device, comprising: The electronic device comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the program to implement the method of any one of claims 1 to 6.
10. A computer storage medium, the storage medium having stored thereon a computer program; characterized in that, The computer program is executed to implement the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Security risk value evaluation method based on combination of HTTP request behaviors and business processes
CN110602021A
Weak password detection method and device
CN111385272A
Gateway login method and device
CN112532663A
Recognition method and device and storage medium
CN112738006A