Problem Handling Method, Device, and Storage Medium
By using security attack knowledge base and network environment information to generate personalized security problem solving measures, the problem that cannot provide personalized processing suggestions in the existing technology is solved, and the efficiency of solving security problems is improved.
Patent Information
- Application Number
- CN202110581660.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-26
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-05-26
AI Technical Summary
Existing security problem solutions cannot provide personalized solutions to specific security problems, making it difficult for users to effectively solve security problems in computer systems.
By obtaining data from the security attack knowledge base, identifying the target security issues and their network environment information, and generating personalized solutions based on this information and outputting them to the user interface.
It realizes personalized solutions for specific security issues, improving users' efficiency and effectiveness in handling security issues.
Smart Images

Figure CN114676313B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a problem handling method, apparatus, and storage medium. Background Art
[0002] Security issues refer to the defects existing in a computer system. Attackers can often launch attacks on the computer system through the security issues existing in the computer system. For example, they can monitor, steal, and tamper with the data in the computer. Therefore, in order to defend against attackers launching attacks on the computer system through security issues, it is very necessary to solve the security issues existing in the computer system. However, in the existing methods for solving security issues, users are usually given some simple handling suggestions so that users can solve the security issues according to these handling suggestions. Generally speaking, the handling suggestions given to users are universal and cannot obtain personalized handling suggestions for a specific security issue. Summary of the Invention
[0003] Embodiments of this application provide a problem handling method, apparatus, and storage medium, which can obtain personalized solutions to security issues.
[0004] On the one hand, embodiments of this application provide a problem handling method, including:
[0005] Obtain a security attack knowledge base, where the security attack knowledge base includes multiple techniques and example data under each technique; any one of the multiple techniques refers to an attack method triggered by a security issue, and the example data under any one of the techniques at least includes: mitigation measures for the any one of the techniques;
[0006] If a target security issue is detected, then search for a target technique matching the target security issue in the security attack knowledge base, and obtain target example data under the target technique;
[0007] Identify the environmental information of the target network environment where the target security issue is located, and generate a solution to the target security issue based on the environmental information and the mitigation measures in the target example data;
[0008] Output the solution to the target security issue in a user interface.
[0009] On the one hand, embodiments of this application provide a problem handling apparatus, including:
[0010] An acquisition unit for acquiring a security attack knowledge base, where the security attack knowledge base includes multiple techniques and example data under each technique; any one of the multiple techniques refers to an attack method triggered by a security problem, and the example data under any one of the techniques at least includes: mitigation measures for the any one of the techniques.
[0011] A processing unit for, if a target security problem is detected, searching in the security attack knowledge base for a target technique that matches the target security problem, and acquiring target example data under the target technique.
[0012] The processing unit is further configured to identify environment information of a target network environment where the target security problem is located, and generate a solution measure for the target security problem based on the environment information and the mitigation measures in the target example data.
[0013] An output unit for outputting the solution measure for the target security problem in a user interface.
[0014] On the one hand, an embodiment of the present application provides a problem processing device, characterized in that the problem processing device includes an input interface and an output interface, and further includes:
[0015] A processor adapted to implement one or more instructions; and,
[0016] A computer storage medium storing one or more instructions, the one or more instructions being adapted to be loaded and executed by the processor to perform the above problem processing method.
[0017] On the one hand, an embodiment of the present application provides a computer storage medium, characterized in that computer program instructions are stored in the computer storage medium, and when the computer program instructions are executed by a processor, they are used to perform the above problem processing method.
[0018] On the one hand, an embodiment of the present application provides a computer program product or a computer program, the computer program product or the computer program includes computer instructions, the computer instructions are stored in a computer-readable storage medium; a processor of a problem processing device reads the computer instructions from the computer-readable storage medium, the processor executes the computer instructions, and when the computer instructions are executed by the processor, they are used to perform the above problem processing method.
[0019] In the embodiments of the present application, if a target security problem is detected, a target technology that matches the target security problem is searched for in the security attack knowledge base, and target example data under the target technology is obtained; then, the environmental information of the target network environment where the target security problem is located is identified, and a solution to the target security problem is generated based on the environmental information and the mitigation measures in the target example data; then, the solution to the target security problem is output in the user interface. The target example data can be searched for and obtained from the security attack knowledge base, and the target example data includes mitigation measures for the target technology; and personalized solutions that are adapted to the target network environment can also be generated according to the target network environment where the target security problem is located, so that the user can solve the target security problem according to the personalized solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to these drawings.
[0021] Figure 1a is a schematic structural diagram of a problem processing system provided by an embodiment of the present application;
[0022] Figure 1b is a schematic diagram of a data sharing system provided by an embodiment of the present application;
[0023] Figure 1c is a schematic diagram of the architecture of a blockchain provided by an embodiment of the present application;
[0024] Figure 1d is a schematic diagram of the process of generating a blockchain provided by an embodiment of the present application;
[0025] Figure 2 is a schematic diagram of the process of a problem processing method provided by an embodiment of the present application;
[0026] Figure 3 is a schematic diagram of identifying the target problem category to which a target security problem belongs provided by an embodiment of the present application;
[0027] Figure 4 is a schematic diagram of the process of another problem processing method provided by an embodiment of the present application;
[0028] Figure 5 is a schematic diagram of the process of another problem processing method provided by an embodiment of the present application;
[0029] Figure 6It is a schematic flowchart of another problem handling method provided by an embodiment of the present application;
[0030] Figure 7 It is a schematic structural diagram of a problem handling device provided by an embodiment of the present application;
[0031] Figure 8 It is a schematic structural diagram of a problem handling device provided by an embodiment of the present application. Detailed implementation manners
[0032] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0033] An embodiment of the present application provides a problem handling solution. After detecting a target security problem, target example data is found from a security attack knowledge base, and the target example data includes mitigation measures; the environmental information of the target network environment where the target security problem is located is identified, and based on the environmental information and the mitigation measures in the target example data, a solution to the target security problem is generated; the solution to the target security problem is output in the user interface.
[0034] Based on the above problem handling solution, an embodiment of the present application provides a problem handling system. Refer to Figure 1a It is a schematic structural diagram of a problem handling system provided by an embodiment of the present application. Figure 1a The problem handling system shown may include a problem handling device 101 and a server 102. Among them, the problem handling device 101 may include any one or more of a smart phone, a tablet computer, a notebook computer, a desktop computer, an intelligent vehicle, and an intelligent wearable device. The server 102 may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. The problem handling device 101 and the server 102 may be directly or indirectly communicatively connected through a wired or wireless communication method, and the present application does not limit this here.
[0035] In one embodiment, the problem processing device 101 can obtain a security attack knowledge base from the server 102 and store the security attack knowledge base in the memory of the problem processing device 101. After detecting a target security problem, the problem processing device 101 searches for target example data from the security attack knowledge base. The target example data includes mitigation measures, and then generates a solution measure for the target security problem and outputs it in the user interface of the problem processing device 101, so that the user can solve the target security problem according to the solution measure of the target security problem. In one embodiment, the problem processing device 101 can also be a device running a security problem platform for centralized discovery and processing of security problems, such as a Security Operations Center (SOC) or a Security Information and Event Management (SIEM) platform. Further, the problem processing device 101 can not only process the security problems existing in itself to obtain the solution measures for the security problems, but also process the security problems existing in one or more devices managed by the problem processing device 101 to obtain the solution measures for the security problems existing in each device.
[0036] In one embodiment, a security problem refers to a defect existing in a system. According to the problem category, security problems can be classified into security vulnerabilities in the security vulnerability category and security events (or security alerts) in the security event category. Among them, security vulnerabilities already exist in the system itself, including but not limited to system-level vulnerabilities, software-level vulnerabilities, and vulnerabilities caused by configuration errors, etc. Generally speaking, security vulnerabilities are mainly inherent in the system and will not change much with human use. A security event refers to a newly discovered or newly generated defect in the system through different security devices, security software, and algorithm engines. Generally speaking, security events will be generated or changed due to human factors such as the launch of new services and internal daily use. An attacker can often use a certain attack method to launch an attack on the device through the security problems existing in the device, where the attack method can be called a technique.
[0037] In one embodiment, the security attack knowledge base includes multiple techniques and example data under each technique. Any one of the multiple techniques refers to an attack method triggered by a security issue, that is, an attack method that can attack a device with the security issue through the security issue. The example data under any one of the techniques at least includes: mitigation measures for any one of the techniques. Further, the example data under any one of the techniques may further include: attack instance information, such as attacker information, software information, and attack method information, etc., that is, it can indicate which attackers used what software and what attack methods to conduct attacks. Further, the various techniques included in the security attack knowledge base can be classified to obtain one or more technique sets, such that one technique set includes one or more techniques. Optionally, the security attack knowledge base can be an Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) knowledge base, a Kill-Chain knowledge base, or a custom security attack knowledge base.
[0038] In one embodiment, the embodiment of the present application further provides a data sharing system, as shown in Figure 1b Figure. The data sharing system 110 refers to a system used for data sharing between nodes. The data sharing system may include multiple nodes 111, and the multiple nodes 111 may refer to each client in the data sharing system (such as the above-mentioned problem processing device 101 and the devices managed by the problem processing device 101). Each node 111 can receive input information during normal operation and maintain the shared data in the data sharing system based on the received input information. To ensure information intercommunication in the data sharing system, there may be information connections between each node in the data sharing system, and the nodes can transmit information through the above-mentioned information connections. For example, when any node in the data sharing system receives input information, other nodes in the data sharing system obtain the input information according to the consensus algorithm, store the input information as data in the shared data, so that the data stored on all nodes in the data sharing system is consistent.
[0039] For each node in the data sharing system, it has a corresponding node identifier, and each node in the data sharing system can store the node identifiers of other nodes in the data sharing system, so that subsequently, according to the node identifiers of other nodes, the generated blocks can be broadcast to other nodes in the data sharing system. Each node can maintain a node identifier list as shown in the following table, and store the node name and the node identifier correspondingly in this node identifier list. Among them, the node identifier can be an IP (Internet Protocol) address and any other information that can be used to identify the node. Only the IP address is taken as an example in Table 1 for illustration.
[0040] Table 1
[0041] Node Name Node Identifier Node 1 117.114.151.XXX Node 2 117.116.189.XXX … … Node N XX.XX.XX.XX
[0042] Each node in the data sharing system stores an identical blockchain. The blockchain consists of multiple blocks. See Figure 1c , the blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores the input information feature value, version number, timestamp, and difficulty value. The block body stores the input information; the next block of the genesis block takes the genesis block as the parent block. The next block also includes a block header and a block body. The block header stores the input information feature value of the current block, the block header feature value of the parent block, version number, timestamp, and difficulty value, and so on. In this way, the block data stored in each block in the blockchain is associated with the block data stored in the parent block, ensuring the security of the input information in the block.
[0043] When generating each block in the blockchain, see Figure 1d , when the node where the blockchain is located receives the input information, it verifies the input information. After the verification is completed, it stores the input information in the memory pool and updates the hash tree used to record the input information; then, it updates the timestamp to the time when the input information is received, and tries different random numbers, and performs eigenvalue calculations multiple times, so that the calculated eigenvalue can satisfy the following formula:
[0044] SHA256(SHA256(version+prev_hash+merkle_root+ntime+nbits+x))<TARGET
[0045] Among them, SHA256 is the eigenvalue algorithm used to calculate the eigenvalue; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash is the block header eigenvalue of the parent block of the current block; merkle_root is the eigenvalue of the input information; ntime is the update time for updating the timestamp; nbits is the current difficulty, which is a fixed value within a certain period of time and is determined again after exceeding the fixed time period; x is a random number; TARGET is the eigenvalue threshold, and this eigenvalue threshold can be determined according to nbits.
[0046] In this way, when a random number that satisfies the above formula is calculated, the information can be stored correspondingly, generating a block header and a block body to obtain the current block. Subsequently, the node where the blockchain is located sends the newly generated block to other nodes in the data sharing system where it is located according to the node identifiers of other nodes in the data sharing system. Other nodes verify the newly generated block and add the newly generated block to the blockchain they store after the verification is completed.
[0047] Based on the above problem processing system and data sharing system, an embodiment of the present application provides a problem processing method. Refer to Figure 2 , which is a schematic flowchart of a problem processing method provided by an embodiment of the present application. Figure 2 The problem processing method shown can be executed by a problem processing device. Figure 2 The problem processing method shown may include the following steps:
[0048] S201, obtain a security attack knowledge base.
[0049] In one embodiment, the security attack knowledge base includes multiple technologies and example data under each technology; any one of the multiple technologies refers to an attack method triggered by a security problem, and the example data under any one technology at least includes: mitigation measures for any one technology. Among them, the attack method triggered by a security problem means that this attack method can be triggered by a security problem, that is, an attacker can use this attack method to launch an attack on a device with this security problem through the security problem. For example, if an attack method can be triggered by security problem A, and security problem A exists in devices 1, 2, and 3, then the attacker can use this attack method to launch an attack on device 1 through the security problem A existing in device 1, can also launch an attack on device 2 through the security problem A existing in device 2, and can also launch an attack on device 3 through the security problem A existing in device 3.
[0050] S202, if a target security problem is detected, then find a target technology that matches the target security problem from the security attack knowledge base, and obtain the target example data under the target technology.
[0051] Among them, the target technology that matches the target security problem refers to the technology that can be triggered by the target security problem, that is, the technology that can attack the target device with the target security problem through the target security problem; the target example data under the target technology includes mitigation measures for the target technology, and the mitigation measures can be used to mitigate the target technology; since the target technology can be triggered by the target security problem, the mitigation measures for the target technology can also be used to solve the target security problem, so that the attacker cannot use the target technology to attack the target device.
[0052] In one embodiment, the problem processing device can detect itself to check whether there is a security problem in the problem processing device. If there is a security problem in the problem processing device, the target security problem is any security problem existing in the problem processing device. In an application scenario, the problem processing device can also detect one or more devices managed by the problem processing device to check whether there is a security problem in the one or more devices managed by the problem processing device. If there is a security problem in the multiple devices, the target security problem is any security problem existing in the multiple devices. If the problem processing device detects the target security problem, it can obtain the problem data corresponding to the target security problem, and the problem data includes relevant information about the target security problem.
[0053] Optionally, the security processing device can also obtain the problem data corresponding to the security problem from different data sources. Then, the target security problem is any security problem corresponding to the problem data obtained by the security processing device. For example, the security processing device can obtain the problem data corresponding to the security problem from a third-party security device or third-party security software that can detect the security problem; it can also directly obtain the problem data corresponding to the security problem from a database storing the problem data corresponding to the security problem.
[0054] In one embodiment, if the problem processing device detects the target security problem, it will identify the target problem category to which the target security problem belongs according to the problem data corresponding to the target security problem; and then adopt the technology search strategy corresponding to the target problem category to search for the target technology that matches the target security problem in the security attack knowledge base, and obtain the target example data under the target technology. Among them, the problem data corresponding to the target security problem can include data for identifying the target problem category to which the target security problem belongs.
[0055] In one embodiment, the problem data of the target security problem may include first field data for clearly identifying the target problem category to which the target security problem belongs. That is, the first field data clearly identifies that the target security problem belongs to the security vulnerability category or the security incident category. Then, the problem processing device can identify the target problem category to which the target security problem belongs according to the first field data. Among them, it is necessary to pre-configure the problem data in different data sources so that the problem processing device can identify the problem data obtained from different data sources. For example, if the configured data source is the problem data of a third-party security device, the first field data is the field data of a fixed length at the beginning of the problem data; if the configured data source is the problem data of a third-party security software, the first field data is the field data of a fixed length at the end of the problem data; then, if the problem data corresponding to the target security problem comes from a third-party security device, the problem processing device will determine the target problem category to which the target security problem belongs through the field data of a fixed length at the beginning of the problem data corresponding to the target security problem. If the problem data corresponding to the target security problem comes from a third-party security software, the problem processing device will determine the target problem category to which the target security problem belongs through the field data of a fixed length at the end of the problem data corresponding to the target security problem.
[0056] In one embodiment, the problem data of the target security problem may include vulnerability number data; if the problem data corresponding to the target security problem includes vulnerability number data, then the problem processing device can identify the target problem category to which the target security problem belongs as the security vulnerability category according to the vulnerability number data. Optionally, the vulnerability number data may be a Common Vulnerabilities & Exposures number (CVE number), a China National Vulnerability Database of Information Security number (CNNVD number), etc.
[0057] In one embodiment, the problem data corresponding to the target security problem may include a security vulnerability website link. If the problem data corresponding to the target security problem includes a vulnerability website link, then the problem processing device can identify the target problem category to which the target security problem belongs as the security vulnerability category according to the vulnerability website link. Among them, the vulnerability website link may be a link to a vulnerability library website, a link to a patch website, etc., for example, it may be a link to the CVE vulnerability library website.
[0058] Further, as Figure 3As shown in the figure, it is a schematic diagram of identifying the target problem category to which a target security problem belongs provided by an embodiment of the present application. If a problem processing device detects a target security problem, it will search the problem data corresponding to the target security problem to find out whether the problem data includes first field data; if it includes the first field data, it will identify the target problem category to which the target security problem belongs according to the first field data. If it does not include the first field data, it will search the problem data to find out whether the problem data includes vulnerability number data; if it includes the vulnerability number data, it will identify the target problem category to which the target security problem belongs as the security vulnerability category. If it does not include the vulnerability number data, it will search the problem data to find out whether the problem data includes one or more vulnerability website links; if it includes the vulnerability website links, it will identify the target problem category to which the target security problem belongs as the security vulnerability category. If it does not include the vulnerability website links, it will identify the target problem category to which the target security problem belongs as the security event category.
[0059] Further, after the problem processing device identifies the target problem category to which the target security problem belongs, it will adopt the technical search strategy corresponding to the target problem category to search for the target technology that matches the target security problem in the security attack knowledge base, and obtain the target example data under the target technology. The specific implementation process will be introduced in the subsequent embodiments.
[0060] S203. Identify the environmental information of the target network environment where the target security problem is located, and generate a solution to the target security problem based on the environmental information and the mitigation measures in the target example data.
[0061] In one embodiment, after the problem processing device obtains the target example data, it will specifically identify the environmental information of the target network environment where the target security problem is located according to the target problem category to which the target security problem belongs, and then generate a solution to the target security problem based on the environmental information and the mitigation measures in the target example data. The specific implementation process will be introduced in the subsequent embodiments. Among them, since the solution to the target security problem is generated based on the environmental information of the target network environment where the target security problem is located, based on the solution to the target security problem, the user can solve the target security problem in the target network environment where the target security problem is located, so that the attacker cannot use the target technology to attack the target device.
[0062] S204. Output the solution to the target security problem in the user interface.
[0063] In an embodiment of the present application, if a target security problem is detected, a target technology that matches the target security problem is searched for in the security attack knowledge base, and target example data under the target technology is obtained; then, environmental information of the target network environment in which the target security problem is located is identified, and a solution measure for the target security problem is generated based on the environmental information and the mitigation measures in the target example data; then, the solution measure for the target security problem is output in the user interface. The target example data can be searched for from the security attack knowledge base, and the target example data includes mitigation measures for the target technology; and personalized solution measures adapted to the target network environment can also be generated according to the target network environment in which the target security problem is located, so that the user can solve the target security problem according to the personalized solution measures.
[0064] Based on the above system embodiment and method embodiment, the embodiment of the present application provides another problem processing method. Refer to Figure 4 , which is a schematic flowchart of another problem processing method provided by the embodiment of the present application. Figure 4 The problem processing method shown can be executed by a problem processing device. Figure 4 The problem processing method shown may include the following steps:
[0065] S401, obtain a security attack knowledge base.
[0066] S402, if a target security problem is detected, identify the target problem category to which the target security problem belongs according to the problem data corresponding to the target security problem.
[0067] Among them, the relevant processes of steps S401 to S402 have been described in the above steps S201 to S202 and will not be elaborated here.
[0068] S403, if the target problem category is a security vulnerability category, use the technology search strategy corresponding to the security vulnerability category to search for a target technology that matches the target security problem in the security attack knowledge base, and obtain target example data under the target technology.
[0069] In a specific implementation, if the target problem category to which the target security problem belongs is a security vulnerability category, the target vulnerability component corresponding to the target security problem is determined, and the corresponding relationship between each technology set and the vulnerability component is obtained; according to the corresponding relationship, the technology set corresponding to the target vulnerability component is searched in the security attack knowledge base as the target technology set; the system environment conditions required for each technology in the target technology set to be triggered by the security problem, and the target system environment in which the target security problem is located are obtained; according to the target system environment and the system environment conditions required for each technology in the target technology set, the target technology that matches the target security problem is determined in the target technology set; wherein, the system environment conditions required for the target technology are adapted to the target system environment.
[0070] In an embodiment, the corresponding relationship between each technology set and the vulnerability component can be represented by the corresponding relationship between each technology set and the vulnerability component identifier. Then, the problem processing device can determine the target vulnerability component identifier corresponding to the target security problem, and then according to the corresponding relationship between each technology set and the vulnerability component identifier, search for the technology set corresponding to the target vulnerability component in the security attack knowledge base as the target technology set. Optionally, the corresponding relationship between each technology set and the vulnerability component can be pre-configured in the technology configuration table. Then, after the problem processing device determines the target vulnerability component corresponding to the target security problem, it can search for the technology set corresponding to the target vulnerability component in the technology configuration table as the target technology set. This method is generally applicable when the target security vulnerability is a cross-operating system type security vulnerability.
[0071] Further, the problem processing device can obtain the system environment conditions required for each technology in the target technology set when triggered by a security problem, as well as the target system environment in which the target security problem is located; determine the target technology that matches the target security problem in the target technology set according to the target system environment and the system environment conditions required for each technology in the target technology set; wherein, the system environment conditions required for the target technology are adapted to the target system environment. Among them, the target system environment in which the target security problem is located can be characterized by the system environment of the target device where the target security problem exists. For example, if the target system environment in which the target security problem is located is System Environment 2, if the target technology set includes Technology 1, Technology 2, and Technology 3; if the system environment conditions required for Technology 1 are indicated as System Environment 1, if the system environment conditions required for Technology 2 are indicated as System Environment 2, if the system environment conditions required for Technology 3 are indicated as System Environment 3; then the target technology that matches the target security problem is Technology 2, and this Technology 2 can be triggered by the target security problem, that is, an attacker can use Technology 2 to launch an attack on the target device through the target security problem existing in the target device. Another example, if the target security problem is the privilege escalation vulnerability of the su command, which is unique to the Linux system, then it can be known that the target system environment in which the target security problem (i.e., the privilege escalation vulnerability of the su command) is located is the system environment of the Linux system; and there is a target technology set named Command and Scripting Interpreter in the security attack knowledge base, and this target technology set includes various technologies that can be triggered under different system environment conditions, but only the technology named "UnixShell" has system environment conditions that are adapted to the target system environment, which is the system environment of the Linux system, so the technology named "Unix Shell" is the target technology that matches the target security problem.
[0072] S404. Identify the environmental information of the target network environment in which the target security problem is located, and generate a solution to the target security problem based on the environmental information and the mitigation measures in the target example data.
[0073] In one embodiment, if the target security issue is a target security vulnerability, the environmental information includes network location information and environmental device information. The network location information is used to indicate the network location where the target security vulnerability is located, and the environmental device information is used to indicate the devices existing in the target network environment. Among them, the network location information is specifically used to indicate whether the network location where the target security vulnerability is located is directly exposed to the public network, or is reachable by the public network, or is only located in the internal network. Among them, it can be judged by identifying the configuration information or network information of the target device with the target security vulnerability. That is to say, if the target device is directly exposed to the public network, then the network location where the target security vulnerability in the target device is located is directly exposed to the public network; if the target device is reachable by the public network, then the network location where the target security vulnerability in the target device is located is reachable by the public network; if the target device is only located in the internal network, then the network location where the target security vulnerability in the target device is located is only located in the internal network.
[0074] Furthermore, the problem processing device can also identify the exploitation method of the target security vulnerability, and generate a solution measure for the target security vulnerability based on the exploitation method of the target security vulnerability, the environmental information, and the mitigation measures in the target sample data.
[0075] In specific implementation, if the exploitation method of the target security vulnerability is a remote exploitation method, then the problem processing device can determine the defense device required to solve the target security vulnerability according to the network location indicated by the network location information; if the devices indicated by the environmental device information include defense devices, generate an environmental solution measure for the target security vulnerability, and the environmental solution measure is used to indicate that the target security vulnerability is solved based on the defense device; add the environmental solution measure and the mitigation measures in the target sample data to the solution measures for the target security vulnerability. Among them, if the network location indicated by the network location information is directly exposed to the public network, then the defense device can be a firewall and a traffic blocking device; if the network location indicated by the network location information is reachable by the public network or is only located in the internal network, then the defense device can be a firewall and a traffic threat detection device. Among them, the traffic blocking device refers to a device used to block data packets in the traffic or disconnect a specific network connection, and the traffic threat detection device refers to a device used to detect security threat data in the traffic and give an alarm after detecting that there is security threat data in the traffic. Furthermore, if the target sample data also includes: software information of the target software used by the target technology, then the problem processing device can generate attack prompt information according to the software information included in the target sample data; and add the attack prompt information to the solution measures for the target security vulnerability.
[0076] In one embodiment, if the network location where the target security vulnerability is located is directly exposed to the public network, the problem handling device determines that the defense devices required to solve the target security vulnerability are a firewall and a traffic blocking device; if the devices indicated by the environmental device information include a firewall and a traffic blocking device, an environmental solution measure for the target security vulnerability is generated. The environmental solution measure is used to indicate the solution of the target security vulnerability based on the defense devices, that is, to prompt the user that the target security vulnerability can be solved through the firewall and the traffic blocking device. For example, the environmental solution measure can be "You can use the firewall and the traffic blocking device to defend against attacks on the target security vulnerability"; the problem handling device can also generate an attack prompt message according to the software information included in the target sample data. For example, the attack prompt message can be "Attackers often attack through a certain type of software or a certain type of attack method. Please refer to the corresponding examples when writing relevant defense rules or strategies"; finally, the problem handling device adds the obtained environmental solution measure, the mitigation measure in the target sample data, and the attack prompt message to the solution measure of the target security vulnerability, so that the user can solve the target security vulnerability according to the solution measure of the target security vulnerability. For example, defense rules or strategies for the target security vulnerability can be written, and the target security vulnerability can be repaired, etc.
[0077] In one embodiment, if the network location indicated by the network location information is a specified network location, a technology that matches the target device with the target security vulnerability is searched as a reference technology from the specified technology set in the security attack knowledge base, and the reference sample data under the reference technology is obtained; the mitigation measure in the reference sample data is used as a reference mitigation measure and added to the solution measure of the target security vulnerability. Among them, the specified network location is reachable by the public network or is only located in the internal network; the specified technology set is the technology set named Persistence in the security attack knowledge base; the reference technology is a technology in the specified technology set that can be triggered by the target security vulnerability, that is, a technology that can attack the target device with the target security vulnerability through the target security vulnerability.
[0078] In one embodiment, if the network location where the target security vulnerability is located is publicly reachable or only located in the internal network, the problem handling device determines that the defense devices required to resolve the target security vulnerability are a firewall and a traffic threat detection device; if the devices indicated by the environmental device information include a firewall and a traffic threat detection device, an environmental solution measure for the target security vulnerability is generated. The environmental solution measure is used to indicate the resolution of the target security vulnerability based on the defense devices, that is, to prompt the user that the target security vulnerability can be resolved through the firewall and the traffic threat detection device. For example, the environmental solution measure can be "You can defend against attacks on the target security vulnerability through the firewall and the traffic threat detection device"; the problem handling device can also generate an attack prompt message according to the software information included in the target example data. For example, the attack prompt message can be "Attackers often attack through a certain type of software or a certain type of attack method. Please refer to the corresponding examples when writing relevant defense rules or strategies"; the problem handling device can also search for a technology matching the target device with the target security vulnerability as a reference technology and obtain reference example data under the reference technology; finally, the problem handling device adds the environmental solution measure, the mitigation measure in the target example data, the attack prompt message, and the mitigation measure in the reference example data as a reference mitigation measure to the solution measure of the target security vulnerability so that the user can resolve the target security vulnerability according to the solution measure of the target security vulnerability. For example, defense rules or strategies for the target security vulnerability can be written, and the target security vulnerability can be repaired, etc.
[0079] In one embodiment, if the exploitation method of the target security vulnerability is a local exploitation method, monitoring prompt information about the exploitation tool for the target security vulnerability is generated and added to the solution measures for the target security vulnerability; the monitoring prompt information is used to prompt that in the defense device corresponding to the target security vulnerability, it is necessary to monitor whether the exploitation tool for the target security vulnerability is spread through the network. In a specific implementation, if the exploitation method of the target security vulnerability is a local exploitation method, the defense devices determined to be required to solve the target security vulnerability are a firewall and a traffic detection device; if the devices indicated by the environmental device information include a firewall and a traffic detection device, monitoring prompt information is generated. For example, the monitoring prompt information may be "You can monitor whether the exploitation tool for the target security vulnerability is spread through the network on the firewall and the traffic detection device." Further, when the exploitation method of the target security vulnerability is a local exploitation method, the target technology set obtained by the problem handling device is the technology sets named Execution, Persistence, Privilege Escalation, and Defense Evasion in the security attack knowledge base. The reason for selecting the above several technology sets as the target technology set is that users may not pay attention to the target security vulnerability because the exploitation method of the target security vulnerability is a local exploitation method and cannot be exploited remotely. Then, once the target security vulnerability is exploited, it may mean that the internal network has been invaded; therefore, all the technology sets that may be involved when the exploitation method of the target security problem is a local exploitation method are used as the target technology set.
[0080] S405, output the solution measures for the target security problem in the user interface.
[0081] In the embodiment of the present application, if the problem handling device detects a target security vulnerability, it can search for a target technology that matches the target security vulnerability from the security attack knowledge base according to the technology search strategy corresponding to the security vulnerability category, and obtain target example data under the target technology; and can accurately generate solution measures for the target security vulnerability based on the exploitation method of the target security vulnerability and based on whether the network location where the target security vulnerability is located is directly exposed to the public network, or is reachable from the public network, or is only located in the internal network. The generated solution measures for the target security vulnerability are adapted to the target security vulnerability.
[0082] Based on the above system embodiment and method embodiment, the embodiment of the present application provides another problem handling method. Refer to Figure 5 , which is a schematic flowchart of another problem handling method provided by the embodiment of the present application. Figure 5 The problem handling method shown can be executed by the problem handling device. Figure 5 The problem handling method shown may include the following steps:
[0083] S501, Obtain a security attack knowledge base.
[0084] S502, If a target security problem is detected, then according to the problem data corresponding to the target security problem, identify the target problem category to which the target security problem belongs.
[0085] Among them, the relevant processes of steps S501 to S502 have been described in the above steps S201 to S202, and will not be elaborated here.
[0086] S503, If the target problem category is a security event category, then adopt the technical search strategy corresponding to the security event category, search in the security attack knowledge base for the target technology that matches the target security problem, and obtain the target example data under the target technology.
[0087] In specific implementation, if the target problem category to which the target security problem belongs is a security event category, then obtain the target problem attributes of the target security problem and an attribute mapping table, where the attribute mapping table includes multiple problem attributes and the technology sets corresponding to each problem attribute; search in the attribute mapping table for the technology set corresponding to the target problem attributes as the target technology set; perform technology filtering processing on the target technology set according to the operating systems involved in each technology in the target technology set and the system characteristics involved in the target security problem; use each technology in the filtered target technology set as the target technology that matches the target security problem. Among them, the system characteristics involved in the target security problem can be characterized by the system characteristics of the target device where the target security problem exists. For example, if the system characteristics involved in the target security problem are the system characteristics of system 4, if the target technology set includes technology 4, technology 5, and technology 6; if the operating system involved in technology 4 is system 4, if the operating system involved in technology 5 is system 5, if the operating system involved in technology 6 is system 6; then the target technology that matches the target security problem is technology 4, and this technology 4 can be triggered by the target security problem, that is, an attacker can use technology 4 to launch an attack on the target device through the target security problem existing in the target device. Another example is that if the system characteristics involved in the target security problem are the system characteristics of the Linux system, and the target technology set is a technology set named Command and Scripting Interpreter, and the different technologies included in this target technology set involve different operating systems, then the problem processing device will perform technology filtering processing on the target technology set to obtain a target technology named "Unix Shell" because the operating system involved in this technology named "Unix Shell" is the system indicated by the system characteristics involved in the target security problem, that is, the Linux system.
[0088] In one embodiment, the target problem attributes of the target security problem may include a target event category and a target problem identifier, where the target problem identifier may be the name of the target security problem. When the target problem attributes include the target event category, the attribute mapping table is a category mapping table including a plurality of event categories and the technology sets corresponding to each event category. Then, the problem processing device obtains the target problem attributes of the target security problem and the attribute mapping table; searching for the technology set corresponding to the target problem attributes in the attribute mapping table as the target technology set may include: extracting the target event category of the target security problem and obtaining the category mapping table; searching for the technology set corresponding to the target event category in the category mapping table as the target technology set. When the target problem attributes include the target problem identifier, the attribute mapping table is an identifier mapping table including a plurality of problem identifiers and the technology sets corresponding to each problem identifier; then, the problem processing device obtains the target problem attributes of the target security problem and the attribute mapping table; searching for the technology set corresponding to the target problem attributes in the attribute mapping table as the target technology set may include: obtaining the target problem identifier of the target security problem and the identifier mapping table; searching for the technology set corresponding to the target problem identifier in the identifier mapping table as the target technology set.
[0089] In one embodiment, the problem processing device may first determine the target technology set from the category mapping table according to the target event category of the target security problem. If the extraction of the target event category fails, or the search for the target technology set in the category mapping table fails, the target technology set may be determined from the identifier mapping table according to the target problem identifier of the target security problem.
[0090] S504, identify the environmental information of the target network environment where the target security problem is located, and generate a solution to the target security problem based on the environmental information and the mitigation measures in the target example data.
[0091] In one embodiment, if the target security problem is a target security event, then the environmental information includes environmental device information, and the environmental device information is used to indicate the devices existing in the target network environment. The problem processing device identifies the environmental information of the target network environment where the target security problem is located, and generates a solution to the target security problem based on the environmental information and the mitigation measures in the target example data, which may include: determining the security devices involved in the mitigation measures in the target example data; if the devices indicated by the environmental device information include security devices, then generating a solution to the target security event based on the device information of the security devices. Among them, the solution to the target security event is used to prompt: solve the target security event through the security devices indicated by the device information, and the security devices include at least one of security equipment and security software.
[0092] In a specific implementation, the problem handling device first obtains a device mapping table, which includes multiple technologies and the security devices corresponding to each technology; then, the problem handling device can determine the security device corresponding to the target technology from the device mapping table according to the target technology corresponding to the target security problem, and the security device corresponding to the target technology is the security device involved in the mitigation measure in the target example data; if the devices indicated by the environmental device information include security devices, then a solution measure for the target security event is generated based on the device information of the security device. For example, if the target security event is "a suspicious command is found on the terminal", the obtained target technology is the target technology named Unix Shell in the target technology set named Command and Scripting Interpreter; if the security device determined from the device mapping table is a Host-based Intrusion Detection System (HIDS), that is, the command can be monitored or disabled and mitigated through the HIDS; then, the solution measure for the generated target security event can be "you can monitor or disable the suspicious command through the HIDS".
[0093] S505, output the solution measure for the target security problem in the user interface.
[0094] In the embodiments of the present application, if the problem handling device detects a target security event, it can search for a target technology that matches the target security event from the security attack knowledge base according to the technology search strategy corresponding to the security event category, and obtain the target example data under the target technology; and can accurately generate a solution measure for the target security event based on the environmental device information in the environmental information of the target security event, and the generated solution measure for the target security event is adapted to the target security event.
[0095] Based on the above system embodiments and method embodiments, the embodiments of the present application provide another problem handling method. Refer to Figure 6 , which is a schematic flowchart of another problem handling method provided by the embodiments of the present application. Figure 6 The problem handling method shown can be executed by a problem handling device. Figure 6 The problem handling method shown may include the following steps:
[0096] S601, obtain a security attack knowledge base.
[0097] S602, if a target security problem is detected, determine one or more historical security problems that the target device with the target security problem has had.
[0098] Wherein, the one or more security problems are those that the target device has had before the target security problem exists.
[0099] S603. If there is no associated historical security issue in one or more historical security issues that is the same as the target security issue, then search the security attack knowledge base for a target technology that matches the target security issue, and obtain target example data under the target technology.
[0100] S604. Identify the environmental information of the target network environment where the target security issue is located, and generate a solution measure for the target security issue based on the environmental information and the mitigation measures in the target example data.
[0101] S605. Output the solution measure for the target security issue in the user interface.
[0102] Among them, the relevant processes of steps S603 to S605 have been disclosed in the method embodiments corresponding to Figure 2 , Figure 4 and Figure 5 and will not be elaborated here.
[0103] In one embodiment, after the problem processing device identifies the target problem category to which the target security issue belongs, it can also perform a victim surface analysis on the target security issue according to the analysis strategy corresponding to the target problem category, obtain target victim surface data corresponding to the target security issue, and output the target victim surface data together when outputting the solution measure for the target security issue, so that the user can understand the victim surface situation of the target security issue.
[0104] In one embodiment, if the target problem category of the target security issue is a security vulnerability category and the target security issue is a target security vulnerability, the problem processing device can perform a victim surface analysis on the target security vulnerability according to the exploitation method of the target security vulnerability, the network location information corresponding to the target security vulnerability, and the type of the target security vulnerability, and obtain target victim surface data corresponding to the target security vulnerability. Among them, the type of the target security vulnerability indicates that the target security vulnerability is a vulnerability at the system level, a vulnerability at the software level, or a vulnerability caused by a configuration error; the obtained target victim surface data corresponding to the target security vulnerability can reflect the victim surface situation of the target device with the target security vulnerability. For example, if the exploitation method of the target security vulnerability is a remote exploitation method, then the victim surface data can reflect the impact of the target security vulnerability on the ports or services in the target device. Generally speaking, if device 1 with the target security vulnerability is directly exposed to the public network and device 2 with the target security vulnerability is only located in the internal network, then the impact of the target security vulnerability on the ports or services in device 1 is greater than the impact on the ports or services in device 2.
[0105] In one embodiment, if the target problem category of the target security problem is a security event category and the target security problem is a target security event, the problem handling device analyzes the number of devices involved in the target security problem to obtain the target affected surface data corresponding to the target security event. Among them, the affected surface data corresponding to the target security event can reflect the number of devices affected by the target security event and the device information of the affected devices. Among them, the device information of the devices affected by the target security event may include: device identification of the device, IP address (Internet Protocol Address) corresponding to the device, administrator device corresponding to the device, and other information.
[0106] For example, if the target security event is security event B and security event B exists in device 3, device 4, and device 5, the attacker uses device 7 to launch attacks on device 4 through security event B existing in device 4, on device 5 through security event B existing in device 5, and on device 6 through security event B existing in device 6. In this case, although device 4, device 5, device 6, and device 7 are all related to security event B, only device 4, device 5, and device 6 are considered as the devices affected by security event B. Then, the number of devices affected by security event B is obtained as 3. Optionally, the number of devices affected by the target security event can be obtained by counting the device identification of the devices affected by the target security event, or the IP address corresponding to the device, or the account name corresponding to the device.
[0107] In one embodiment, the target affected surface data corresponding to the target security problem can be stored. Further, a solution feedback message can be generated through a solution feedback operation detected in the user interface and the solution feedback message can be stored. The solution feedback message is used to indicate whether the user has resolved the target security problem based on the solution measure for the target security problem. Optionally, a solution feedback option can be set in the user interface, and a solution feedback message can be generated through a selection operation detected in the user interface for the solution feedback option. For example, the solution feedback option can be a "confirm" option and a "cancel" option. If the "confirm" option is selected, the solution feedback message is used to indicate that the user has resolved the target security problem based on the solution measure for the target security problem. If the "cancel" option is selected, the solution feedback message is used to indicate that the user has not resolved the target security problem based on the solution measure for the target security problem.
[0108] S606, if there is an associated historical security problem identical to the target security problem among one or more historical security problems, perform consistency detection on the target affected surface data generated by the target security problem and the reference affected surface data generated by the associated historical security problem.
[0109] S607, if the target victim surface data is consistent with the reference victim surface data, then output a measure prompt message.
[0110] Among them, the measure prompt message indicates: adopt other solution measures different from the solution measures of the associated historical security problem to solve the target security problem. For example, if the target security problem cannot be solved on the target device, such as the system in the target device is very old and solving the target security problem may affect the online service, then at this time, the user will be prompted to suggest adopting other solution measures according to the actual situation, such as adding security devices, etc. Optionally, the target victim surface data can also be output to enable the user to understand the victim surface situation of the target device with the target security problem.
[0111] In one embodiment, before outputting the measure prompt message, the solution feedback information corresponding to the associated historical security problem can be identified. If the solution feedback information corresponding to the associated historical security problem indicates that the user has solved the target security problem based on the solution measure of the target security problem, then output the measure prompt message; if the solution feedback information corresponding to the associated historical security problem indicates that the user has not solved the target security problem based on the solution measure of the target security problem, then output the solution measure of the associated historical security problem and the reference victim surface data.
[0112] S608, if the target victim surface data is inconsistent with the reference victim surface data, then generate a measure adjustment suggestion based on the solution measure of the target security problem and the solution measure of the associated historical security problem; and output the measure adjustment suggestion, the target victim surface data, and the reference victim surface data.
[0113] In one embodiment, the measure adjustment suggestion can be the part of the solution measure of the target security problem that is different from the solution measure of the associated historical security problem; it can also be the solution measure of the target security problem. Outputting the target victim surface data and the reference victim surface data enables the user to better understand the difference in the victim surface data.
[0114] In one embodiment, before outputting the measure adjustment suggestion, the solution feedback information corresponding to the associated historical security problem can be identified. If the solution feedback information corresponding to the associated historical security problem indicates that the user has solved the target security problem based on the solution measure of the target security problem, then the output measure adjustment suggestion can be the part of the solution measure of the target security problem that is different from the solution measure of the associated historical security problem; if the solution feedback information corresponding to the associated historical security problem indicates that the user has not solved the target security problem based on the solution measure of the target security problem, then the output measure adjustment suggestion can be the solution measure of the target security problem.
[0115] In an embodiment of the present application, if a problem handling device detects a target security problem, it can perform a victim surface analysis on the target security problem according to an analysis strategy corresponding to the target problem category to which the target security problem belongs, and obtain target victim surface data corresponding to the target security problem, so that the user can understand the victim surface situation of the target security problem. Before the target device has a target security problem, if there has been an associated historical security problem in the target device that is the same as the target security problem, then the problem handling device can also perform a consistency check on the target victim surface data generated by the target security problem and the reference victim surface data generated by the associated historical security problem. When the target victim surface data is consistent with the reference victim surface data, a measure prompt message is output. When the target victim surface data is inconsistent with the reference victim surface data, a measure adjustment suggestion, the target victim surface data, and the reference victim surface data are output, so that the user can solve the target security problem differently in different situations, and outputting the target victim surface data and the reference victim surface data can enable the user to better understand the difference in the victim surface data. For example, it can be understood whether the victim surface caused by the target security problem has increased compared to the associated historical security problem.
[0116] Based on the above system embodiment and method embodiment, an embodiment of the present application provides a problem handling device. Refer to Figure 7 , which is a schematic structural diagram of a problem handling device provided by an embodiment of the present application. The problem handling device may include an acquisition unit 701, a processing unit 702, and an output unit 704. Figure 7 The problem handling device shown can operate the following units:
[0117] The acquisition unit 701 is configured to acquire a security attack knowledge base, where the security attack knowledge base includes multiple technologies and example data under each technology; any one of the multiple technologies refers to an attack method triggered by a security problem, and the example data under any one of the technologies at least includes: mitigation measures for the any one of the technologies;
[0118] The processing unit 702 is configured to, if a target security problem is detected, search for a target technology that matches the target security problem in the security attack knowledge base, and obtain target example data under the target technology;
[0119] The processing unit 702 is further configured to identify environmental information of a target network environment in which the target security problem is located, and generate a solution measure for the target security problem based on the environmental information and the mitigation measures in the target example data;
[0120] The output unit 703 is configured to output the solution measure for the target security problem in a user interface.
[0121] In one embodiment, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more technologies; when the processing unit 702 searches for a target technology that matches the target security problem in the security attack knowledge base, the following operations are specifically performed:
[0122] According to the problem data corresponding to the target security problem, identify the target problem category to which the target security problem belongs;
[0123] If the target problem category is a security vulnerability category, determine the target vulnerability component corresponding to the target security problem, and obtain the corresponding relationship between each technology set and the vulnerability component;
[0124] According to the corresponding relationship, search for the technology set corresponding to the target vulnerability component in the security attack knowledge base as the target technology set;
[0125] Obtain the system environment conditions required for each technology in the target technology set to be triggered by a security problem, and the target system environment in which the target security problem is located;
[0126] According to the target system environment and the system environment conditions required for each technology in the target technology set, determine the target technology that matches the target security problem in the target technology set; wherein, the system environment conditions required for the target technology are adapted to the target system environment.
[0127] In one embodiment, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more technologies; when the processing unit 702 searches for a target technology that matches the target security problem in the security attack knowledge base, the following operations are specifically performed:
[0128] If the target problem category to which the target security problem belongs is a security event category, obtain the target problem attribute of the target security problem and an attribute mapping table, where the attribute mapping table includes multiple problem attributes and the technology sets corresponding to each problem attribute;
[0129] Search for the technology set corresponding to the target problem attribute in the attribute mapping table as the target technology set;
[0130] According to the operating systems involved in each technology in the target technology set and the system characteristics involved in the target security problem, perform technology filtering processing on the target technology set;
[0131] Use each technology in the filtered target technology set as the target technology that matches the target security problem.
[0132] In one embodiment, the target security issue is a target security vulnerability; the environmental information includes network location information and environmental device information, where the network location information is used to indicate the network location where the target security vulnerability is located, and the environmental device information is used to indicate the devices existing in the target network environment;
[0133] When the processing unit 702 generates a solution measure for the target security issue based on the environmental information and the mitigation measures in the target example data, it specifically performs the following operations:
[0134] Determine the defense devices required to solve the target security vulnerability according to the network location indicated by the network location information;
[0135] If the devices indicated by the environmental device information include the defense devices, generate an environmental solution measure for the target security vulnerability, where the environmental solution measure is used to indicate solving the target security vulnerability based on the defense devices;
[0136] Add the environmental solution measure and the mitigation measures in the target example data to the solution measures for the target security vulnerability.
[0137] In one embodiment, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more technologies; the processing unit 702 is further configured to:
[0138] If the network location indicated by the network location information is a specified network location, search for a technology that matches the target device with the target security vulnerability in the specified technology set in the security attack knowledge base as a reference technology, and obtain reference example data under the reference technology;
[0139] Add the mitigation measures in the reference example data as reference mitigation measures to the solution measures for the target security vulnerability.
[0140] In one embodiment, the processing unit 702 is further configured to:
[0141] If the target example data further includes: software information of the target software used by the target technology, generate attack prompt information according to the software information included in the target example data; and add the attack prompt information to the solution measures for the target security vulnerability;
[0142] If the exploitation method of the target security vulnerability is a local exploitation method, monitoring prompt information about the exploitation tool for the target security vulnerability is generated and added to the solution measures for the target security vulnerability; the monitoring prompt information is used to prompt that in the defense device corresponding to the target security vulnerability, whether the exploitation tool for the target security vulnerability is spread through the network is monitored.
[0143] In one embodiment, the target security problem is a target security event; the environmental information includes environmental device information, and the environmental device information is used to indicate the devices existing in the target network environment.
[0144] When generating the solution measures for the target security problem based on the environmental information and the mitigation measures in the target example data, the processing unit 702 specifically performs the following operations:
[0145] Determine the security devices involved in the mitigation measures in the target example data, where the security devices include at least one of security equipment and security software.
[0146] If the devices indicated by the environmental device information include the security devices, generate the solution measures for the target security event based on the device information of the security devices, and the solution measures for the target security event are used to prompt that the target security event is solved through the security devices indicated by the device information.
[0147] In one embodiment, the target security problem exists in a target device. If there were one or more historical security problems before the target device had the target security problem, the solution measures for the target security problem are output when there is no associated historical security problem in the one or more historical security problems that is the same as the target security problem.
[0148] The processing unit 702 is further configured to, if the associated historical security problem exists in the one or more historical security problems, perform a consistency detection on the target victim surface data corresponding to the target security problem and the reference victim surface data corresponding to the associated historical security problem.
[0149] The output unit 703 is further configured to, if the target victim surface data is consistent with the reference victim surface data, output measure prompt information, and the measure prompt information indicates that other solution measures different from the solution measures for the associated historical security problem are used to solve the target security problem.
[0150] The processing unit 702 is further configured to generate a measure adjustment suggestion based on the solution measures for the target security problem and the solution measures for the associated historical security problems if the target victim surface data is inconsistent with the reference victim surface data; the output unit 703 is further configured to output the measure adjustment suggestion, the target victim surface data, and the reference victim surface data.
[0151] According to an embodiment of the present application, Figure 2 , Figure 4 , Figure 5 and Figure 6 each step involved in the problem handling method shown can be executed by Figure 7 each unit in the problem handling device shown. For example, Figure 2 the step S201 shown can be executed by Figure 7 the acquisition unit 701 in the problem handling device shown, Figure 2 the steps S202 to S203 shown can be executed by Figure 7 the processing unit 702 in the problem handling device shown, Figure 2 the step S204 shown can be executed by Figure 7 the output unit 703 in the problem handling device shown; and again, Figure 4 the step S401 shown can be executed by Figure 7 the acquisition unit 701 in the problem handling device shown, Figure 4 the steps S402 to S404 shown can be executed by Figure 7 the processing unit 702 in the problem handling device shown, Figure 4 the step S405 shown can be executed by Figure 7 the output unit 703 in the problem handling device shown; and again, Figure 5 the step S501 shown can be executed by Figure 7 the acquisition unit 701 in the problem handling device shown, Figure 5 the steps S502 to S504 shown can be executed by Figure 7 the processing unit 702 in the problem handling device shown, Figure 5 the step S505 shown can be executed by Figure 7 the output unit 703 in the problem handling device shown; and again, Figure 6 the step S601 shown can be executed by Figure 7 the acquisition unit 701 in the problem handling device shown, Figure 6 the steps S602 to S604, and the step S606 shown can be executed by Figure 7 the processing unit 702 in the problem handling device shown, Figure 6 the steps S605 and S607 shown can be executed byFigure 7 is executed by the output unit 703 in the problem processing device shown Figure 6 The step S608 shown can be performed by Figure 7 the processing unit 702 and the output unit 703 in the problem processing device shown.
[0152] According to another embodiment of the present application, Figure 7 each unit in the problem processing device shown can be separately or all combined into one or several other units to form, or a certain (some) unit among them can be further split into multiple smaller units with functional division to form, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above units are divided based on logical functions. In practical applications, the function of one unit can also be realized by multiple units, or the functions of multiple units can be realized by one unit. In other embodiments of the present application, the problem processing device divided based on logical functions can also include other units. In practical applications, these functions can also be assisted by other units and can be realized by the cooperation of multiple units.
[0153] According to another embodiment of the present application, it can be achieved by running a computer program (including program code) capable of executing the respective steps involved in the corresponding methods shown in Figure 2 , Figure 4 , Figure 5 and Figure 6 on a general computing device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM), to construct the problem processing device shown in Figure 7 and to implement the problem processing method of the embodiments of the present application. The computer program can be recorded on a computer-readable storage medium, for example, and loaded into the above computing device through the computer-readable storage medium and run therein.
[0154] In the embodiments of the present application, if the processing unit 702 detects a target security problem, it searches for a target technology that matches the target security problem from the security attack knowledge base and obtains target example data under the target technology; then it identifies the environmental information of the target network environment where the target security problem is located, and generates a solution to the target security problem based on the environmental information and the mitigation measures in the target example data; the output unit 703 outputs the solution to the target security problem in the user interface. The target example data can be found from the security attack knowledge base, and the target example data includes mitigation measures for the target technology; and personalized solutions adapted to the target network environment can also be generated according to the target network environment where the target security problem is located, so that the user can solve the target security problem according to the personalized solution.
[0155] Based on the above method embodiments and device embodiments, the present application further provides a problem processing device. Refer to Figure 8 , which is a schematic structural diagram of a problem processing device provided by an embodiment of the present application. Figure 8 The problem processing device shown may at least include a processor 801, an input interface 802, an output interface 803, and a computer storage medium 804. Among them, the processor 801, the input interface 802, the output interface 803, and the computer storage medium 804 may be connected by a bus or other means.
[0156] The computer storage medium 804 can be stored in the memory of the problem processing device. The computer storage medium 804 is used to store a computer program, and the computer program includes program instructions. The processor 801 is used to execute the program instructions stored in the computer storage medium 804. The processor 801 (or CPU (Central Processing Unit, central processing unit)) is the computing core and control core of the problem processing device, and is adapted to implement one or more instructions, specifically adapted to load and execute one or more instructions to implement the above problem processing method flow or corresponding functions.
[0157] The embodiment of the present application further provides a computer storage medium (Memory). The computer storage medium is a memory device in the problem processing device and is used to store programs and data. It can be understood that the computer storage medium here can include both the built-in storage medium in the terminal and, of course, the extended storage medium supported by the terminal. The computer storage medium provides a storage space, and the operating system of the terminal is stored in this storage space. And, one or more instructions suitable for being loaded and executed by the processor 801 are stored in this storage space. These instructions can be one or more computer programs (including program code). It should be noted that the computer storage medium here can be a high-speed random access memory (random access memory, RAM) memory, or a non-volatile memory (non-volatile memory), such as at least one disk memory; optionally, it can also be at least one computer storage medium located far from the aforementioned processor.
[0158] In one embodiment, one or more instructions stored in the computer storage medium can be loaded and executed by the processor 801 to implement the above related Figure 2 , Figure 4 , Figure 5 and Figure 6The corresponding steps of the method in the problem handling method embodiment. In a specific implementation, one or more instructions in the computer storage medium are loaded and executed by the processor 801, the input interface 802, and the output interface 803 to perform the following steps:
[0159] The input interface 802 is used to obtain a security attack knowledge base, and the security attack knowledge base includes multiple techniques and example data under each technique; any one of the multiple techniques refers to an attack method triggered by a security problem, and the example data under any one of the techniques at least includes: mitigation measures for the any one of the techniques;
[0160] The processor 801 is used to, if a target security problem is detected, search for a target technique that matches the target security problem in the security attack knowledge base, and obtain target example data under the target technique;
[0161] The processor 801 is further used to identify the environmental information of the target network environment where the target security problem is located, and generate a solution measure for the target security problem based on the environmental information and the mitigation measures in the target example data;
[0162] The output interface 803 is used to output the solution measure for the target security problem in the user interface.
[0163] In one embodiment, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more techniques; when the processor 801 searches for a target technique that matches the target security problem in the security attack knowledge base, the following operations are specifically performed:
[0164] According to the problem data corresponding to the target security problem, identify the target problem category to which the target security problem belongs;
[0165] If the target problem category is a security vulnerability category, determine the target vulnerability component corresponding to the target security problem, and obtain the correspondence between each technology set and the vulnerability component;
[0166] Search for a technology set corresponding to the target vulnerability component in the security attack knowledge base according to the correspondence as the target technology set;
[0167] Obtain the system environment conditions required when each technique in the target technology set is triggered by a security problem, and the target system environment where the target security problem is located;
[0168] Based on the system environment conditions required by each technology in the target system environment and the target technology set, determine a target technology in the target technology set that matches the target security problem; wherein, the system environment conditions required by the target technology are adapted to the target system environment.
[0169] In one embodiment, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more technologies; when the processor 801 searches for a target technology that matches the target security problem from the security attack knowledge base, the following specific operations are performed:
[0170] If the target problem category to which the target security problem belongs is a security event category, obtain the target problem attributes of the target security problem and an attribute mapping table, where the attribute mapping table includes multiple problem attributes and the technology sets corresponding to each problem attribute;
[0171] Search for the technology set corresponding to the target problem attributes from the attribute mapping table as the target technology set;
[0172] Perform technology filtering processing on the target technology set according to the operating systems involved in each technology in the target technology set and the system characteristics involved in the target security problem;
[0173] Use each technology in the filtered target technology set as the target technology that matches the target security problem.
[0174] In one embodiment, the target security problem is a target security vulnerability; the environment information includes network location information and environmental device information, the network location information is used to indicate the network location where the target security vulnerability is located, and the environmental device information is used to indicate the devices existing in the target network environment;
[0175] When the processor 801 generates a solution to the target security problem based on the environment information and the mitigation measures in the target example data, the following specific operations are performed:
[0176] Determine the defense device required to solve the target security vulnerability according to the network location indicated by the network location information;
[0177] If the devices indicated by the environmental device information include the defense device, generate an environmental solution to the target security vulnerability, and the environmental solution is used to indicate that the target security vulnerability is solved based on the defense device;
[0178] Add the environmental solution and the mitigation measures in the target example data to the solution to the target security vulnerability.
[0179] In one embodiment, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more technologies; the processor 801 is further configured to:
[0180] If the network location indicated by the network location information is a specified network location, search for a technology that matches the target device with the target security vulnerability from the specified technology set in the security attack knowledge base as a reference technology, and obtain reference example data under the reference technology;
[0181] Use the mitigation measures in the reference example data as reference mitigation measures and add them to the solutions for the target security vulnerability.
[0182] In one embodiment, the processor 801 is further configured to:
[0183] If the target example data further includes: software information of the target software used by the target technology, generate attack prompt information according to the software information included in the target example data; and add the attack prompt information to the solutions for the target security vulnerability;
[0184] If the exploitation method of the target security vulnerability is a local exploitation method, generate monitoring prompt information about the exploitation tool for the target security vulnerability, and add the monitoring prompt information to the solutions for the target security vulnerability; the monitoring prompt information is used to prompt: in the defense device corresponding to the target security vulnerability, monitor whether the exploitation tool for the target security vulnerability is spread through the network.
[0185] In one embodiment, the target security problem is a target security event; the environment information includes environment device information, and the environment device information is used to indicate the devices existing in the target network environment;
[0186] When generating the solutions for the target security problem based on the environment information and the mitigation measures in the target example data, the processor 801 specifically performs the following operations:
[0187] Determine the security devices involved in the mitigation measures in the target example data, and the security devices include at least one of security equipment and security software;
[0188] If the devices indicated by the environment device information include the security devices, generate the solutions for the target security event based on the device information of the security devices, and the solutions for the target security event are used to prompt: solve the target security event through the security devices indicated by the device information.
[0189] In one embodiment, the target security problem exists in the target device. If there were one or more historical security problems before the target security problem exists in the target device, the solution measure for the target security problem is output when there is no associated historical security problem identical to the target security problem among the one or more historical security problems;
[0190] The processor 801 is further configured to, if the associated historical security problem exists among the one or more historical security problems, perform consistency detection on the target victim surface data corresponding to the target security problem and the reference victim surface data corresponding to the associated historical security problem;
[0191] The output interface 803 is further configured to, if the target victim surface data is consistent with the reference victim surface data, output a measure prompt message, where the measure prompt message indicates: use other solution measures different from the solution measure for the associated historical security problem to solve the target security problem;
[0192] The processor 801 is further configured to, if the target victim surface data is inconsistent with the reference victim surface data, generate a measure adjustment suggestion based on the solution measure for the target security problem and the solution measure for the associated historical security problem; the output interface 803 is further configured to output the measure adjustment suggestion, the target victim surface data, and the reference victim surface data.
[0193] An embodiment of the present application provides a computer program product or a computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of the problem processing device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the problem processing device executes the method embodiments as described above Figure 2 、 Figure 4 、 Figure 5 or Figure 6 shown. Among them, the computer-readable storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0194] As described above, the above are only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A problem handling method, characterized in that, it includes: Obtain a security attack knowledge base, where the security attack knowledge base includes multiple techniques and example data under each technique; Any one of the multiple techniques refers to an attack method triggered by a security problem, and the example data under any one of the techniques at least includes: mitigation measures for the any one of the techniques; If a target security problem is detected, search the security attack knowledge base for a target technique that matches the target security problem, and obtain target example data under the target technique; Identify the environmental information of the target network environment where the target security problem is located, and generate a solution measure for the target security problem based on the environmental information and the mitigation measures in the target example data; Output the solution measure for the target security problem in the user interface.
2. The method according to claim 1, characterized in that, the security attack knowledge base includes one or more technique sets, and one technique set includes one or more techniques; the searching for a target technique that matches the target security problem from the security attack knowledge base includes: According to the problem data corresponding to the target security problem, identify the target problem category to which the target security problem belongs; If the target problem category is a security vulnerability category, determine the target vulnerability component corresponding to the target security problem, and obtain the correspondence between each technique set and the vulnerability component; Search the security attack knowledge base for a technique set corresponding to the target vulnerability component according to the correspondence as the target technique set; Obtain the system environment conditions required for each technique in the target technique set to be triggered by a security problem, and the target system environment where the target security problem is located; Determine a target technique that matches the target security problem in the target technique set according to the target system environment and the system environment conditions required for each technique in the target technique set; wherein, the system environment conditions required for the target technique are adapted to the target system environment.
3. The method according to claim 1, characterized in that, the security attack knowledge base includes one or more technique sets, and one technique set includes one or more techniques; the searching for a target technique that matches the target security problem from the security attack knowledge base further includes: If the target problem category to which the target security problem belongs is a security event category, obtain the target problem attribute of the target security problem and an attribute mapping table, where the attribute mapping table includes multiple problem attributes and the technique sets corresponding to each problem attribute; Search the attribute mapping table for a technique set corresponding to the target problem attribute as the target technique set; Perform a technical filtering process on the target technique set according to the operating systems involved in each technique in the target technique set and the system characteristics involved in the target security problem; Use each technique in the filtered target technique set as a target technique that matches the target security problem.
4. The method according to claim 1, characterized in that, The target security problem is a target security vulnerability; the environmental information includes network location information and environmental device information, where the network location information is used to indicate the network location where the target security vulnerability is located, and the environmental device information is used to indicate the devices existing in the target network environment; Generating a solution measure for the target security problem based on the environmental information and the mitigation measures in the target example data includes: Determining a defense device required to solve the target security vulnerability according to the network location indicated by the network location information; If the devices indicated by the environmental device information include the defense device, generating an environmental solution measure for the target security vulnerability, where the environmental solution measure is used to indicate solving the target security vulnerability based on the defense device; Adding the environmental solution measure and the mitigation measures in the target example data to the solution measures for the target security vulnerability.
5. The method according to claim 4, wherein, the security attack knowledge base includes one or more technology sets, and one technology set includes one or more technologies; the method further includes: If the network location indicated by the network location information is a specified network location, searching for a technology matching the target device with the target security vulnerability from the specified technology set in the security attack knowledge base as a reference technology, and obtaining reference example data under the reference technology; Adding the mitigation measures in the reference example data as reference mitigation measures to the solution measures for the target security vulnerability.
6. The method according to claim 4 or 5, wherein, the method further includes: If the target example data further includes: software information of the target software used by the target technology, generating attack prompt information according to the software information included in the target example data; and adding the attack prompt information to the solution measures for the target security vulnerability; If the exploitation method of the target security vulnerability is a local exploitation method, generating monitoring prompt information about the exploitation tool of the target security vulnerability, and adding the monitoring prompt information to the solution measures for the target security vulnerability; the monitoring prompt information is used to prompt: in the defense device corresponding to the target security vulnerability, monitoring whether the exploitation tool of the target security vulnerability is spread through the network.
7. The method according to claim 1, wherein, the target security problem is a target security event; the environmental information includes environmental device information, and the environmental device information is used to indicate the devices existing in the target network environment; Generating a solution measure for the target security problem based on the environmental information and the mitigation measures in the target example data includes: Determining the security devices involved in the mitigation measures in the target example data, where the security devices include at least one of security equipment and security software; If the device indicated by the environmental device information includes the security device, generate a solution measure for the target security event based on the device information of the security device, where the solution measure for the target security event is used to prompt: solve the target security event through the security device indicated by the device information.
8. The method according to claim 1, wherein, the target security problem exists in a target device. If there was one or more historical security problems before the target device had the target security problem, the solution measure for the target security problem is output when there is no associated historical security problem in the one or more historical security problems that is the same as the target security problem; the method further includes: if there is the associated historical security problem in the one or more historical security problems, perform a consistency check on the target victim surface data corresponding to the target security problem and the reference victim surface data corresponding to the associated historical security problem; if the target victim surface data is consistent with the reference victim surface data, output a measure prompt message, where the measure prompt message indicates: use other solution measures different from the solution measure for the associated historical security problem to solve the target security problem; if the target victim surface data is inconsistent with the reference victim surface data, generate a measure adjustment suggestion based on the solution measure for the target security problem and the solution measure for the associated historical security problem; and output the measure adjustment suggestion, the target victim surface data, and the reference victim surface data.
9. A problem processing device, wherein, it includes: an acquisition unit, configured to acquire a security attack knowledge base, where the security attack knowledge base includes multiple techniques and example data under each technique; any one of the multiple techniques refers to an attack method triggered by a security problem, and the example data under any one of the techniques at least includes: mitigation measures for the any one of the techniques; a processing unit, configured to, if a target security problem is detected, search for a target technique that matches the target security problem in the security attack knowledge base, and acquire target example data under the target technique; the processing unit is further configured to identify environmental information of a target network environment where the target security problem is located, and generate a solution measure for the target security problem based on the environmental information and the mitigation measures in the target example data; an output unit, configured to output the solution measure for the target security problem in a user interface.
10. A computer storage medium, wherein, computer program instructions are stored in the computer storage medium, and when the computer program instructions are executed by a processor, they are used to execute the problem processing method according to any one of claims 1-8.
11. A problem processing device, wherein, the problem processing device includes an input interface and an output interface, and further includes: a processor, adapted to implement one or more instructions; and, A computer storage medium stores one or more instructions, and the one or more instructions are adapted to be loaded and executed by the processor to perform the problem processing method according to any one of claims 1-8.
12. A computer program product, characterized in that the computer program product includes computer instructions, and when the computer instructions are executed by a processor, they are used to perform the problem processing method according to any one of claims 1-8.
Citation Information
Patent Citations
Honeynet-based risk prewarning system and method in information production environment
CN102882884A
Distributed security event associated analysis method based on knowledge graph
CN108270785A