A method, apparatus and device for correlation analysis of alarm events

By generating alarm tags in a unified format and applying alarm correlation analysis rules, the problem of a large number of alarms and low accuracy in network attack events is solved, and efficient screening and accurate output of alarm events are achieved.

CN115001774BActive Publication Date: 2025-11-04QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210582262.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-26
Publication Date
2025-11-04
Estimated Expiration
2042-05-26

AI Technical Summary

Technical Problem

Existing technologies cannot effectively reduce the number of network attack alerts or improve the accuracy of alerts, making it difficult for staff to distinguish alerts that affect network security from a massive and complex number of alerts.

Method used

By generating alarm tags in a unified format and matching alarm tag groups using preset alarm correlation analysis rules, alert events that affect network security are generated, reducing the number of alarms and improving accuracy.

Benefits of technology

It effectively reduced the number of alarms, improved the accuracy of alarm events, and provided staff with reliable data for network security analysis and research.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115001774B_ABST
    Figure CN115001774B_ABST
Patent Text Reader

Abstract

The application discloses a kind of correlation analysis methods, device and equipment of warning event, the method includes: based on the matching of the obtained warning label in the preset warning correlation analysis rule to warning label group, obtain matching result;According to the matching result, determine warning label set;Based on the warning label set, generate the prompt warning event corresponding to the warning label group of the warning label group.It can be seen that, in the method, a variety of warning events are generated into uniform warning labels, and the warning correlation analysis rules suitable for the uniform format of the warning labels are set to realize the correlation analysis of the warning events generated by various security protection products, output the prompt warning events that have an impact on network security, effectively reduce the number of alarms, improve the accuracy of alarm, and provide reliable basis for the analysis and research of network security by staff.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the network security technical field, in particular to a kind of alarm event correlation analysis method, device and equipment. BACKGROUND

[0002] With the high-speed development of Internet technology, network attack events are also more and more frequent, and security manufacturers have launched various targeted security protection products to defend and discover network attacks. However, due to the emergence of different security protection products, there are many types of alarm events and a large number of alarm events, which brings great challenges to staff in distinguishing alarm events that have an impact on network security from a large number of complex alarm events for research and disposal.

[0003] Currently, some alarm whitelisting conditions are usually added by combining business-specific scenarios to reduce false positive rates, and alarm events are aggregated and suppressed by setting time windows and aggregation conditions. This method can reduce the false positive rate and alarm volume of alarm events of a single security protection product to some extent. However, for alarm events that do not hit the whitelisting conditions, the number of alarm events cannot be reduced, and although the time window and aggregation suppression method can generate only one prompt alarm event for alarm events with the same attributes within a specified time window, this does not substantially improve the accuracy of alarm events.

[0004] Therefore, there is an urgent need to provide a technical solution that can effectively improve the accuracy of alarm events, so that the final alarm prompt not only reduces the number of alarm events but also outputs prompt alarm events that have an impact on network security, improves the accuracy of alarms, and provides reliable basis for staff analysis and research on network security. SUMMARY

[0005] The embodiments of the present application provide a kind of alarm event correlation analysis method, device and equipment, which can effectively reduce the output number of alarm events and improve the accuracy of alarm event output prompt alarm event, provide reliable basis for staff analysis and research on network security alarm event, thereby improve the efficiency and accuracy of network security.

[0006] In a first aspect, the embodiments of the present application provide a kind of alarm event correlation analysis method, comprising:

[0007] obtain an alarm label group;

[0008] based on the preset alarm correlation analysis rule, the alarm label in the alarm label group is matched, and a matching result is obtained;

[0009] determine an alarm label set according to the matching result;

[0010] Based on the set of alarm tags, a prompt alarm event corresponding to the alarm tag group is generated.

[0011] Optionally, the method further comprises:

[0012] Receiving a real-time alarm event;

[0013] Determining a tag generation rule matching the identity of the real-time alarm event;

[0014] Based on the tag generation rule, an alarm tag of the real-time alarm event is generated.

[0015] Optionally, if the tag generation rule includes a persistence indication, the method further comprises:

[0016] Saving the alarm tag of the real-time alarm event to an in-memory database, the alarm tag including a tag identity, an entity name, and a tag generation time.

[0017] Optionally, if the tag type corresponding to the tag generation rule is a single alarm event tag, the generating, based on the tag generation rule, of the alarm tag of the real-time alarm event comprises:

[0018] If the real-time alarm event meets the tag generation condition corresponding to the tag generation rule, generating the alarm tag of the real-time alarm event according to the indication of the tag generation rule.

[0019] Optionally, if the tag type corresponding to the tag generation rule is an aggregated alarm event tag, the generating, based on the tag generation rule, of the alarm tag of the real-time alarm event comprises:

[0020] Based on the aggregation condition of the tag generation rule, a plurality of real-time alarm events are aggregated to obtain an aggregated alarm event;

[0021] If the aggregated alarm event meets the tag generation condition corresponding to the tag generation rule, generating the alarm tag of the aggregated alarm event as the alarm tag of the plurality of real-time alarm events according to the indication of the tag generation rule.

[0022] Optionally, the obtaining of the alarm tag group comprises:

[0023] In response to the time since the last correlation analysis reaching a preset duration, the alarm tag group is obtained.

[0024] Optionally, the obtaining of the alarm tag group comprises:

[0025] From the in-memory database, an effective historical alarm tag in a historical tag group is obtained as a tag in the alarm tag group.

[0026] Optionally, the obtaining the alarm label group comprises:

[0027] The first alarm label group is obtained from alarm labels generated by real-time alarm events participating in the current correlation analysis, and values of group fields in the first alarm label group are the same.

[0028] Optionally, the method further comprises:

[0029] According to the label identifier of the alarm label of the real-time alarm event, the alarm label of the real-time alarm event is grouped, and a grouping result of the alarm label of the real-time alarm event comprises the first alarm label group.

[0030] Optionally, the matching the alarm labels in the alarm label group based on the preset alarm correlation analysis rule to obtain a matching result comprises:

[0031] The alarm correlation analysis rule corresponding to the alarm label group type is obtained, and the alarm label group type comprises a historical label group and a real-time label group.

[0032] It is determined whether the alarm labels in the alarm label group meet the obtained alarm correlation analysis rule.

[0033] Optionally, the determining the alarm label set according to the matching result comprises:

[0034] If it is determined that the alarm labels in the alarm label group meet the obtained alarm correlation analysis rule, the alarm labels are stored in an alarm label set corresponding to the alarm label group.

[0035] Optionally, the generating the prompt alarm event corresponding to the alarm label group based on the alarm label set comprises:

[0036] If the alarm label set meets a hit condition in the obtained alarm correlation analysis rule after the matching of all the alarm labels in the alarm label group based on the preset alarm correlation analysis rule is completed, the prompt alarm event corresponding to the alarm label group is generated based on the alarm labels in the alarm label set.

[0037] Optionally, the method further comprises:

[0038] If the alarm label set does not meet the hit condition in the obtained alarm correlation analysis rule after the matching of all the alarm labels in the alarm label group based on the preset alarm correlation analysis rule is completed, the alarm label group is discarded, and the alarm label group does not correspond to any prompt alarm event.

[0039] In a second aspect, the embodiments of the present application further provide an alarm event correlation analysis device, comprising:

[0040] obtaining unit, configured to obtain an alarm label group;

[0041] matching unit, configured to match alarm labels in the alarm label group based on a preset alarm correlation analysis rule to obtain a matching result;

[0042] a first determining unit, configured to determine an alarm label set according to the matching result;

[0043] a first generating unit, configured to generate a prompt alarm event corresponding to the alarm label group based on the alarm label set.

[0044] Optionally, the apparatus further includes:

[0045] a receiving unit, configured to receive a real-time alarm event;

[0046] a second determining unit, configured to determine a label generation rule matched with an identifier of the real-time alarm event;

[0047] a second generating unit, configured to generate an alarm label of the real-time alarm event based on the label generation rule.

[0048] Optionally, if the label generation rule includes a persistence indication, the apparatus further includes:

[0049] a saving unit, configured to save the alarm label of the real-time alarm event to an in-memory database, the alarm label including a label identifier, an entity name and a label generation time.

[0050] Optionally, if a label type corresponding to the label generation rule is a single alarm event label, the second generating unit is specifically configured to:

[0051] determine that the real-time alarm event satisfies a label generation condition corresponding to the label generation rule, and then generate the alarm label of the real-time alarm event according to an indication of the label generation rule.

[0052] Optionally, if the label type corresponding to the label generation rule is an aggregated alarm event label, the second generating unit includes:

[0053] an aggregating subunit, configured to aggregate a plurality of the real-time alarm events based on an aggregation condition of the label generation rule to obtain an aggregated alarm event;

[0054] a determining subunit, configured to determine that the aggregated alarm event satisfies a label generation condition corresponding to the label generation rule, and then generate an alarm label of the aggregated alarm event as alarm labels of the plurality of the real-time alarm events according to an indication of the label generation rule.

[0055] Optionally, the obtaining unit is specifically configured to:

[0056] In response to a time distance from a last time of correlation analysis reaching a preset time length, the alarm label group is obtained.

[0057] Optionally, the obtaining unit is specifically configured to:

[0058] The valid historical alarm label in the historical label group is obtained from the in-memory database as a label in the alarm label group.

[0059] Optionally, the obtaining unit is specifically configured to:

[0060] The first alarm label group in alarm labels generated by a real-time alarm event participating in this time of correlation analysis is obtained, and values of a grouping field in the first alarm label group are the same.

[0061] Optionally, the apparatus further includes:

[0062] A grouping unit is configured to group alarm labels of the real-time alarm event according to label identifiers of the alarm labels of the real-time alarm event, and a grouping result of the alarm labels of the real-time alarm event includes the first alarm label group.

[0063] Optionally, the matching unit includes:

[0064] An obtaining subunit is configured to obtain an alarm correlation analysis rule corresponding to an alarm label group type, and the alarm label group type includes a historical label group and a real-time label group.

[0065] A judging subunit is configured to determine whether alarm labels in the alarm label group meet the obtained alarm correlation analysis rule.

[0066] Optionally, the first determining unit is specifically configured to:

[0067] If it is determined that the alarm labels in the alarm label group meet the obtained alarm correlation analysis rule, the alarm labels are stored in an alarm label set corresponding to the alarm label group.

[0068] Optionally, the first generating unit is specifically configured to:

[0069] If matching of all alarm labels in the alarm label group based on a preset alarm correlation analysis rule is completed, the alarm label set meets a hit condition in the obtained alarm correlation analysis rule, and the prompt alarm event corresponding to the alarm label group is generated based on alarm labels in the alarm label set.

[0070] Optionally, the apparatus further includes:

[0071] If all the alarm tags in the alarm tag group are matched based on the preset alarm correlation analysis rule, and the alarm tag set does not satisfy the hit condition in the obtained alarm correlation analysis rule, the alarm tag group is discarded, and the alarm tag group does not correspond to any prompt alarm event.

[0072] It should be noted that the specific implementation modes and effects of the alarm event correlation analysis device provided in the second aspect can be referred to the description of the alarm event correlation analysis method in the first aspect.

[0073] In a third aspect, the embodiments of the present application further provide an electronic device, which comprises a processor and a memory:

[0074] The memory is configured to store a computer program.

[0075] The processor is configured to execute the method provided in the first aspect according to the computer program.

[0076] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which is configured to store a computer program, and the computer program is configured to execute the method provided in the first aspect.

[0077] Therefore, the embodiments of the present application have the following beneficial effects:

[0078] The embodiments of the present application provide an alarm event correlation analysis method, in which an alarm event correlation analysis device obtains an alarm tag group, matches alarm tags in the alarm tag group based on a preset alarm correlation analysis rule, obtains a matching result, determines an alarm tag set according to the matching result, and generates a prompt alarm event corresponding to the alarm tag group based on the alarm tag set. It can be seen that in the embodiments of the present application, alarm tags in a uniform format are generated from various alarm events, the alarm correlation analysis rule suitable for the alarm tags in the uniform format is set, the correlation analysis of alarm events generated by various security protection products is realized, the prompt alarm event having an impact on network security is output, the number of alarms is effectively reduced, the accuracy of the alarm is improved, and a reliable basis is provided for the analysis and research of network security by the staff. BRIEF DESCRIPTION OF DRAWINGS

[0079] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present application, and other drawings can be obtained by those skilled in the art based on these drawings.

[0080] Figure 1 A flowchart of a correlation analysis method of an alarm event provided for an embodiment of the present application is shown in FIG. 1.

[0081] Figure 2 A schematic diagram of a label generation process provided for an embodiment of the present application is shown in FIG. 2.

[0082] Figure 3 A schematic diagram of a correlation analysis of a multi-label group provided for an embodiment of the present application is shown in FIG. 3.

[0083] Figure 4 A structural diagram of a correlation analysis system of an alarm event provided for an embodiment of the present application is shown in FIG. 4.

[0084] Figure 5 A structural diagram of a correlation analysis device of an alarm event provided for an embodiment of the present application is shown in FIG. 5.

[0085] Figure 6 A structural diagram of an electronic device provided for an embodiment of the present application is shown in FIG. 6. DETAILED DESCRIPTION

[0086] In order to make the above objectives, features and advantages of the present application more apparent, further detailed description of the embodiments of the present application will be given below in conjunction with the accompanying drawings and specific embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, and not to limit the present application. In addition, it should be noted that, for the sake of description, only the parts related to the present application are shown in the drawings, not all structures.

[0087] With the rapid development of Internet technology, the era of Internet of Everything has brought a lot of convenience to people's work and life, but network attack events also occur frequently. Security vendors have launched various targeted security protection products for different scenarios and stages to defend and discover network attacks. The alarm generated by multiple security protection products is of various types and in large quantities, and the staff needs to spend a lot of effort to determine the alarm events that have an impact on network security from the massive and complex alarm events.

[0088] Currently, in order to reduce the workload of the staff, the security vendor usually reduces the false alarm rate of the alarm event by setting some alarm whitelisting conditions, and reduces the number of alarm events by setting a time window and aggregation conditions to aggregate and suppress the alarm events (i.e. in a specified time window, only one alarm event with the same attribute is generated to notify the staff), which can reduce the false alarm rate and the number of alarm events of a single security protection product to a certain extent. However, since the formats of the alarm events generated by different security protection products are different, the set whitelisting conditions cannot be applied to the alarm events generated by all security protection products. Therefore, the method of setting alarm whitelisting conditions, time windows and aggregation conditions cannot reduce the number of alarms, and cannot substantially guarantee the accuracy of the alarm events.

[0089] Based on this, the embodiment of the present application provides a technical solution which can effectively improve the accuracy of the alarm events, so that the final alarm prompt not only reduces the number of alarm events, but also can output prompt alarm events which have an impact on network security, improves the accuracy of the alarm, and provides a reliable basis for the analysis and research of the staff on network security. Specifically, in the alarm event correlation analysis method provided by the embodiment of the present application, the alarm event correlation analysis device obtains an alarm tag group, matches the alarm tags in the alarm tag group based on a preset alarm correlation analysis rule, and obtains a matching result; determines an alarm tag set according to the matching result; and generates a prompt alarm event corresponding to the alarm tag group based on the alarm tag set.

[0090] As can be seen, in the embodiment of the present application, the alarm tags with a unified format are generated from various alarm events, the alarm correlation analysis rule suitable for the alarm tags with the unified format is set, the correlation analysis of the alarm events generated by various security protection products is realized, the prompt alarm events which have an impact on network security are output, the number of alarms is effectively reduced, the accuracy of the alarm is improved, and a reliable basis is provided for the analysis and research of the staff on network security.

[0091] It should be noted that the subject implementing the alarm event correlation analysis method can be the alarm event correlation analysis device provided by the embodiment of the present application, and the device can be carried in an electronic device or a functional module of the electronic device. The electronic device in the embodiment of the present application can be any device capable of implementing the alarm event correlation analysis method in the embodiment of the present application.

[0092] In order to facilitate the understanding of the specific implementation of the alarm event correlation analysis method provided by the embodiment of the present application, the following will be described with reference to the accompanying drawings.

[0093] Figure 1A flowchart of a method for correlation analysis of alarm events is provided in the embodiments of the present application. The method is applied to a device for correlation analysis of alarm events. As shown in Figure 1 The method can include the following S101-S104:

[0094] S101, obtaining an alarm tag group.

[0095] In order to make the alarm events generated by different security protection products have a unified format, before S101, the embodiments of the present application can further include a process of generating a tag for an alarm event. As an example, the process of generating a tag for an alarm event can include: receiving a real-time alarm event; determining a tag generation rule matching the identification of the real-time alarm event; and generating an alarm tag of the real-time alarm event based on the tag generation rule.

[0096] In order to meet the needs of some scenarios (for example, the need to analyze the impact of abnormal login on network security), the tag generation rule includes an indication of whether to persist, which can be preset based on security analysis needs. In one case, if the tag generation rule includes a persistence indication, after generating an alarm tag of a real-time alarm event in the method, the alarm tag of the real-time alarm event can also be saved to an in-memory database, and the alarm tag includes a tag identification, an entity name and a tag generation time.

[0097] As an example, the process of generating an alarm tag provided by the embodiments of the present application can include Figure 2 As shown in

[0098] S11, obtaining a tag generation rule from a database;

[0099] S12, receiving a real-time alarm event;

[0100] S13, determining whether there is a tag generation rule matching the alarm identification of the real-time alarm event, if yes, executing S14, and if no, exiting the process of generating an alarm tag;

[0101] S14, generating an alarm tag of the real-time alarm event for the real-time alarm event according to the tag generation rule matching the alarm identification of the real-time alarm event;

[0102] S15, determining whether the tag generation rule matching the alarm identification of the real-time alarm event includes a persistence indication, if yes, executing S16, and if no, executing S17;

[0103] S16, saving the alarm tag of the real-time alarm event to an in-memory database, the alarm tag including a tag identification, an entity name and a tag generation time;

[0104] S17, sending the alarm label of the real-time alarm event to an alarm correlation analysis module.

[0105] In the method for generating an alarm label provided by the embodiments of the present application, the preconfigured contents include but are not limited to: (1) a label name, used for recording the alarm label name generated by an alarm event; (2) an identification of an alarm event (also referred to as an alarm ID), which can be a serial number of the alarm event, used for uniquely identifying the alarm event, and the user can preset the correspondence between the alarm ID range and the type of the alarm event, and can determine the type of the alarm event based on the alarm ID of the real-time alarm event after receiving the real-time alarm event; (3) a label note, used for recording the description information of the alarm label; (4) an indication of whether the label is persistent, used for indicating whether the generated alarm label needs to save the key information (such as the label identification, the entity name, and the label generation time) to the in-memory database for persistence; (5) a label generation rule, used for recording the logical condition for generating the corresponding alarm label by the alarm event; and (6) a label type, which can include a single alarm event label and an aggregated alarm event label. The single alarm event label refers to that one alarm label is generated for each alarm event that meets the label generation rule, and the aggregated alarm event label refers to that one alarm label is generated for the multiple alarm events that meet the label generation rule after the multiple alarm events are aggregated according to the specified aggregation condition.

[0106] For S11, specifically, when the flow of generating an alarm label is started, the label generation module that executes the method for generating an alarm label loads the configured label generation rule from the database into the memory of the label generation module. The label generation rule in the database can be configured and managed by the rule configuration module and stored in the database synchronously. The functions of the modules can be referred to the related descriptions of Figure 4 .

[0107] For S13, if the matched label generation rule is empty, that is, the label generation rule corresponding to the alarm event is not matched, the flow is directly exited, and if the matched label generation rule is not empty, the next step S14 of the label generation flow is performed.

[0108] For S14, when the alarm label is generated, the corresponding label generation process can be performed according to the label type. In one case, if the label type corresponding to the label generation rule is a single alarm event label, then the S14 includes: determining that the real-time alarm event satisfies the label generation condition corresponding to the label generation rule, and then generating the alarm label of the real-time alarm event according to the indication of the label generation rule. In another case, if the label type corresponding to the label generation rule is an aggregated alarm event label, then the S14 includes: aggregating a plurality of real-time alarm events based on the aggregation condition of the label generation rule to obtain an aggregated alarm event; determining that the aggregated alarm event satisfies the label generation condition corresponding to the label generation rule, and then generating the alarm label of the aggregated alarm event as the alarm label of the plurality of real-time alarm events according to the indication of the label generation rule.

[0109] After the alarm label of the real-time alarm event is generated, the alarm label can be sent to the alarm correlation analysis module for subsequent analysis and processing. In addition, for the alarm label configured by the label generation rule to be persisted, the label ID, entity name, label generation time, and other information of the alarm label can also be written into the in-memory database (i.e., the aforementioned memory database).

[0110] It should be noted that the method for generating an alarm label provided in the embodiments of the present application can be implemented independently as an embodiment to generate an alarm label with a unified format for a variety of alarm event generation formats. The alarm label with a unified format is the basis for unified rule processing and analysis of alarm events generated by multiple security protection products, that is, the method for generating an alarm label provided in the embodiments of the present application is a prerequisite for realizing the correlation analysis and other analysis and processing of the alarm label.

[0111] In some implementations, after the embodiment shown in Figure 2 After the embodiment shown in

[0112] As an example, S101 may, for example, include: in response to a distance from a last time of correlation analysis reaching a preset time length, obtaining the alarm label group. If the alarm label group is a historical label group, obtaining the alarm label group in S101 may include: obtaining valid historical alarm labels in the historical label group from a memory database as labels in the alarm label group. If the alarm label group is an alarm label group corresponding to a real-time alarm event, obtaining the alarm label group in S101 may include: obtaining a first alarm label group in alarm labels generated by the real-time alarm event participating in this time of correlation analysis, the values of the grouping fields in the first alarm label group being the same. Before S101, the method may further include: grouping alarm labels of the real-time alarm event according to label identifiers of the alarm labels of the real-time alarm event, the grouping result of the alarm labels of the real-time alarm event including the first alarm label group, in order to improve the efficiency of alarm correlation analysis.

[0113] S102, based on a preset alarm correlation analysis rule, matching alarm labels in the alarm label group to obtain a matching result.

[0114] As an example, S102 may, for example, include: obtaining an alarm correlation analysis rule corresponding to an alarm label group type, the alarm label group type including a historical label group and a real-time label group; and determining whether alarm labels in the alarm label group conform to the obtained alarm correlation analysis rule.

[0115] S103, determining an alarm label set according to the matching result.

[0116] As an example, S103 may, for example, include: if it is determined that the alarm labels in the alarm label group conform to the obtained alarm correlation analysis rule, storing the alarm labels in an alarm label set corresponding to the alarm label group. Conversely, if it is determined that the alarm labels in the alarm label group do not conform to the obtained alarm correlation analysis rule, discarding the alarm labels and not generating a prompt alarm event according to the alarm label group.

[0117] S104, generating a prompt alarm event corresponding to the alarm label group based on the alarm label set.

[0118] As an example, S104 may, for example, include: if the alarm label set satisfies a hit condition in the obtained alarm correlation analysis rule after matching all alarm labels in the alarm label group based on a preset alarm correlation analysis rule, generating the prompt alarm event corresponding to the alarm label group based on alarm labels in the alarm label set.

[0119] In some implementations, the method can further include: if all alarm tags in the alarm tag group are matched based on the preset alarm correlation analysis rule, the alarm tag set does not satisfy the hit condition in the obtained alarm correlation analysis rule, the alarm tag group is discarded, and the alarm tag group does not correspond to any prompt alarm event.

[0120] In order to make the embodiments of the present application clearer, the following will combine the above-mentioned technical problems Figure 3 The implementation of S101-S104 is exemplarily described.

[0121] In a specific implementation, the alarm correlation analysis process provided by the embodiments of the present application can be as shown in Figure 3 may include:

[0122] S21, receiving an alarm tag generated by a real-time alarm event.

[0123] S22, grouping the alarm tags according to the tag ID.

[0124] S22 is an optional step performed to improve the matching efficiency of the alarm correlation analysis. If S22 is not performed, the alarm tag group below can be understood as all alarm tags received in S21 participating in the alarm correlation analysis process this time.

[0125] S23, judging whether the current time is away from the time of the last correlation analysis by a preset time length. If yes, S24 is performed, otherwise, S21 is returned.

[0126] The preset time length can be obtained by configuring the rule calculation time, for example, the preset time length can be equal to the rule calculation time.

[0127] S24, judging whether there is a historical tag group. If yes, S25 is performed, otherwise, S26 is performed.

[0128] The historical tag group can include the alarm tags saved in the memory database, that is, the alarm tags saved in the memory database based on the persistence indication after the alarm tags are generated.

[0129] It should be noted that the network attack event is usually based on the alarm tag group corresponding to the real-time alarm event for alarm, but for the data security type or APT (Advanced Persistent Threat) analysis and the like, the historical tag group and the real-time alarm tag group can be used for correlation analysis.

[0130] S25, for the historical label, obtaining the valid historical alarm label in the historical label group from the memory database as the label in the alarm label group in S101, performing correlation analysis according to the alarm correlation analysis rule corresponding to the historical label group, obtaining the historical label set, and executing S27.

[0131] S26, for the i-th alarm label group corresponding to the alarm label generated by the real-time alarm event, performing correlation analysis according to the alarm correlation analysis rule corresponding to the i-th alarm label group corresponding to the real-time alarm event, obtaining the real-time label set, and executing S27.

[0132] It should be noted that in the i-th alarm label group, the value of i is an integer from 1 to N, and N is the number of grouping of the alarm label generated by the real-time alarm event. I can start from 1 and increase, and the i-th alarm label group starts from 1 and increases. The first time S26 is executed, i=1, the second time S26 is executed, i=2, and so on, until i=N.

[0133] S27, judging whether the historical label set or the real-time label set satisfies the preconfigured alarm condition, if yes, executing S28, otherwise, executing S26;

[0134] S28, judging whether i is equal to N, if yes, determining that all label groups have completed alarm correlation analysis, then executing S29, otherwise, executing S26.

[0135] S29, generating the prompt alarm event corresponding to the alarm label group according to the historical label set and the real-time label set, and sending the prompt alarm event to the alarm module for alarm.

[0136] In the method for alarm correlation analysis provided by the embodiments of the present application, the contents that need to be pre-configured include but are not limited to: in the first aspect, the configuration of alarm rules: (1) rule calculation time, used to record the period of performing the alarm correlation analysis, every rule calculation time, the process of performing the alarm correlation analysis provided by the embodiments of the present application is triggered to perform the alarm correlation analysis provided by the embodiments of the present application on the alarm tags of the received real-time alarm events. (2) grouping calculation attribute, used to record the matching condition of the alarm events for tag grouping, for example, the grouping calculation attribute can be an Internet Protocol (IP) address, the alarm tags corresponding to different IP addresses or different IP address ranges are assigned to different alarm tag groups, which can be understood as a coarse-grained screening of the alarm tags. (3) tag group configuration, the tag groups can be divided into two categories: one category is a historical tag group, which refers to the alarm tags that occur in the historical time range set by the user, usually the alarm tags of the in-memory database; the other category is a real-time tag group, which refers to the alarm tags generated in real time by the received real-time alarm events. In the second aspect, the configuration of the historical tag group: (1) tag range, i.e. the list of tag names and the valid time of each tag; (2) must-hit tags, used to indicate the alarm tags that must be hit in the alarm correlation analysis process, the must-hit tags must be from the tags set in the tag range; (3) the number of tags that must be hit, used to limit the number of tags that must be hit in the final indication of the alarm tags that the current tag group can participate in. In the third aspect, the configuration of the alarm tag group corresponding to the alarm tags generated by the real-time alarm events: (1) tag range, i.e. the list of tag names; (2) must-hit tags, used to indicate the alarm tags that must be hit in the alarm correlation analysis process, the must-hit tags must be from the tags set in the tag range; (3) the number of tags that must be hit, used to limit the number of tags that must be hit in the final indication of the alarm tags that the current tag group can participate in.

[0137] In the alarm correlation analysis on the historical tag group in S25, the alarm tags can be taken out one by one from the tag range of the historical tag group, and the following operations can be performed: the historical alarm tags are queried from the in-memory database according to the tag name and the value of the configured grouping calculation attribute, if the queried historical alarm tags are empty, the next alarm tag is taken out from the tag range list for querying; if not, the difference between the tag generation time of the historical alarm tag and the current time is calculated to determine whether it is within the valid time range of the historical alarm tag, if yes, the historical alarm tag is considered valid, and the historical alarm tag is put into the alarm tag set corresponding to the historical tag group.

[0138] The alarm correlation analysis on the i-th alarm label group in S26 can include: taking alarm labels from the label range of the i-th alarm label group one by one, and performing the following operation: according to the label ID and the value of the grouping attribute, matching alarm labels that meet the alarm correlation analysis rule corresponding to the real-time label group from real-time alarm label groups, and adding the matched alarm labels to the alarm label set that meets the i-th alarm label group. It should be noted that the group number of the real-time alarm label group can be random, or can be determined based on the order of label generation or grouping; the order of obtaining the alarm label group can be random, or can be obtained in a preset order, and the embodiments of the application do not limit the specific manner as long as the alarm label group can be traversed.

[0139] It can be seen that by the method provided in the embodiments of the application, the alarm event correlation analysis device obtains an alarm label group, matches alarm labels in the alarm label group based on a preset alarm correlation analysis rule to obtain a matching result, determines an alarm label set according to the matching result, and generates a prompt alarm event corresponding to the alarm label group based on the alarm label set. In this way, a variety of alarm events are generated into alarm labels of a unified format, the alarm correlation analysis rule suitable for the alarm labels of the unified format is set, the correlation analysis of alarm events generated by various security protection products is realized, the prompt alarm event that has an impact on network security is output, the number of alarms is effectively reduced, the accuracy of the alarm is improved, and a reliable basis is provided for the analysis and research of network security by the staff.

[0140] Figure 4 For the architecture diagram of the system for implementing the method provided in the embodiments of the application, as shown in Figure 4 The system can include a rule configuration module 401, a database 402, an alarm label generation module 403, an alarm correlation analysis module 404, a memory database 405, and an alarm module 406. Among them:

[0141] The rule configuration module 401 is configured to manage the label generation rule of the alarm event, the alarm correlation analysis rule of the alarm label group, and the like.

[0142] The database 402 is configured to store the rules managed by the rule configuration module 401, and realize the interaction with the alarm label generation module 403 and the alarm correlation analysis module 404.

[0143] The alarm label generation module 403 is configured to generate corresponding alarm labels for alarm events generated by various security products according to the label generation rule set by the rule configuration module 401.

[0144] The alarm correlation analysis module 404 (also referred to as a multi-label group rule real-time analysis module) is configured to perform correlation matching on alarm labels according to alarm correlation analysis rules of alarm label groups set by the rule configuration module 401, and generate corresponding prompt alarm events based on corresponding alarm labels of alarm label groups that meet the alarm correlation analysis rules, and send the corresponding prompt alarm events to the alarm module 406.

[0145] The alarm module 406 is configured to receive the prompt alarm events generated by the alarm correlation analysis module 404 and perform alarm notification.

[0146] It can be seen that the embodiments of the present application consider that a complete network attack behavior from occurrence to performance to completion is often captured by different security protection products at different time periods and generates different alarm events, and it is very difficult to determine whether the attack behavior is a real attack only from the alarm events of a security protection product, because many normal entity behaviors can also trigger the alarm of a security protection product, and a large number of false positives can cause the staff to be tired of the alarm, resulting in a real attack alarm being ignored. Therefore, the method for performing correlation analysis on alarm events in the network security field proposed in the embodiments of the present application retains the advantages brought by the white-listing condition limitation and alarm aggregation by generating alarm labels, and realizes the ordered correlation of alarm events of different security protection products based on the multi-label group rule matching mode, thereby effectively reducing the reporting quantity of alarm events and improving the accuracy of the alarm.

[0147] The embodiments of the present application will be described below with reference to an actual scene embodiment.

[0148] For the scene of an attacker attacking a service that provides a file storage function to the outside, it is assumed that the security protection products involved include a firewall for border protection, a traffic anomaly detection product, and a server protection product.

[0149] The attack process can include: (1) the attacker uploads a lightweight Trojan to the target server through the file upload service provided by the service; (2) the preview function of the service triggers the execution of the Trojan; (3) the server triggers the download of a more functional Trojan from the attacker's self-built server address and executes the newly downloaded Trojan; (4) the new Trojan can establish a control connection channel with the attacker and modify the server's self-starting item to ensure that the Trojan program can automatically start after the server restarts.

[0150] The configuration item of the alarm event generating the alarm label can include: (1) the attack alarm label generated by the firewall: suspected file upload attack, suspected XSS attack, suspected SQL injection attack; (2) the malicious attack traffic alarm label generated by the traffic anomaly detection product: suspected command control traffic; (3) the corresponding alarm label of the alarm configuration generated by the server protection product: suspected malicious program modification startup item, suspected execution of malicious command, suspected download of malicious file, suspected malicious connection, etc.

[0151] The configuration item of the multi-label group rule can include:

[0152] For real-time alarm label groups, alarm label group one: label range: suspected file upload attack, suspected XSS attack, suspected SQL injection attack; must hit label: suspected file upload attack; at least hit label number: 2. Alarm label group two: label range: suspected malicious program modification startup item, suspected execution of malicious command, suspected download of malicious file, suspected malicious connection; must hit label: suspected malicious connection; must hit label number: 2.

[0153] Grouping calculation attribute (also referred to as grouping field): target IP address (i.e. IP address of the server)

[0154] Rule calculation time: 30 minutes.

[0155] Correspondingly, the embodiment of the application also provides an alarm event correlation analysis device 500, as shown in the figure, the device 500 can include: Figure 5

[0156] The obtaining unit 501 is configured to obtain an alarm label group.

[0157] The matching unit 502 is configured to match the alarm labels in the alarm label group based on a preset alarm correlation analysis rule to obtain a matching result.

[0158] The first determination unit 503 is configured to determine an alarm label set according to the matching result.

[0159] The first generation unit 504 is configured to generate a prompt alarm event corresponding to the alarm label group based on the alarm label set.

[0160] Optionally, the device 500 further includes:

[0161] The receiving unit is configured to receive a real-time alarm event.

[0162] The second determination unit is configured to determine a label generation rule matched with the identifier of the real-time alarm event.

[0163] ​The second generating unit is configured to generate the alarm label of the real-time alarm event based on the label generation rule.

[0164] Optionally, if the label generation rule comprises a persistence indication, the apparatus 500 further comprises:

[0165] The saving unit is configured to save the alarm label of the real-time alarm event to an in-memory database, the alarm label comprising a label identifier, an entity name, and a label generation time.

[0166] Optionally, if the label type corresponding to the label generation rule is a single-alarm-event label, the second generating unit is specifically configured to:

[0167] determine that the real-time alarm event satisfies the label generation condition corresponding to the label generation rule, and generate the alarm label of the real-time alarm event according to the indication of the label generation rule.

[0168] Optionally, if the label type corresponding to the label generation rule is an aggregated-alarm-event label, the second generating unit comprises:

[0169] The aggregation subunit is configured to aggregate a plurality of real-time alarm events based on an aggregation condition of the label generation rule to obtain an aggregated alarm event.

[0170] The determination subunit is configured to determine that the aggregated alarm event satisfies the label generation condition corresponding to the label generation rule, and generate the alarm label of the aggregated alarm event as the alarm label of the plurality of real-time alarm events according to the indication of the label generation rule.

[0171] Optionally, the obtaining unit 501 is specifically configured to:

[0172] obtain the alarm label group in response to a time distance from a last correlation analysis reaching a preset time length.

[0173] Optionally, the obtaining unit 501 is specifically configured to:

[0174] obtain, from an in-memory database, an effective historical alarm label in a historical label group as a label in the alarm label group.

[0175] Optionally, the obtaining unit 501 is specifically configured to:

[0176] obtain a first alarm label group in alarm labels generated by real-time alarm events participating in this correlation analysis, the values of the grouping fields in the first alarm label group being the same.

[0177] Optionally, the apparatus 500 further comprises:

[0178] grouping units, configured to group the alarm tags of the real-time alarm events according to the tag identifiers of the alarm tags of the real-time alarm events, wherein the grouping result of the alarm tags of the real-time alarm events comprises the first alarm tag group.

[0179] Optionally, the matching unit 502 comprises:

[0180] obtaining sub-units, configured to obtain alarm correlation analysis rules corresponding to alarm tag group types, wherein the alarm tag group types comprise historical tag groups and real-time tag groups;

[0181] determining sub-units, configured to determine whether the alarm tags in the alarm tag group meet the obtained alarm correlation analysis rules.

[0182] Optionally, the first determining unit 503 is specifically configured to:

[0183] If it is determined that the alarm tags in the alarm tag group meet the obtained alarm correlation analysis rules, the alarm tags are stored in the alarm tag set corresponding to the alarm tag group.

[0184] Optionally, the first generating unit 504 is specifically configured to:

[0185] If the matching of all the alarm tags in the alarm tag group based on the preset alarm correlation analysis rules is completed, and the alarm tag set meets the hit condition in the obtained alarm correlation analysis rules, the prompt alarm event corresponding to the alarm tag group is generated based on the alarm tags in the alarm tag set.

[0186] Optionally, the apparatus 500 further comprises:

[0187] If the matching of all the alarm tags in the alarm tag group based on the preset alarm correlation analysis rules is completed, and the alarm tag set does not meet the hit condition in the obtained alarm correlation analysis rules, the alarm tag group is discarded, and the alarm tag group does not correspond to any prompt alarm event.

[0188] It should be noted that the specific implementation manners and effects of the alarm event correlation analysis apparatus 500 can be referred to the descriptions of the related alarm event correlation analysis method embodiments shown in Figure 1 .

[0189] In addition, the embodiments of the present application further provide an electronic device 600, as shown in Figure 6 , the electronic device 600 comprises a processor 601 and a memory 602:

[0190] The memory 602 is configured to store a computer program.

[0191] The processor 601 is configured to execute the method provided by the embodiments of the present application according to the computer program.

[0192] In addition, the embodiments of the present application further provide a computer readable storage medium, which is used to store a computer program, and the computer program is used to execute the method provided by the embodiments of the present application.

[0193] From the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the above-mentioned embodiment methods can be implemented by means of software plus a general hardware platform. Based on such an understanding, the technical solutions of the present application can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network communication device such as a router) execute the methods described in the various embodiments or some parts of the embodiments.

[0194] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, the system embodiments and the device embodiments are basically similar to the method embodiments, so they are described more simply. The relevant parts can be referred to the part of the method embodiments. The above-described device and system embodiments are only illustrative, and the modules described as separate components can or can not be physically separated, and the components shown as modules can or can not be physical modules, i.e. they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiments according to actual needs. Those skilled in the art can understand and implement without creative labor.

[0195] The above is only the preferred embodiment of the present application, and is not used to limit the protection scope of the present application. It should be pointed out that, for those skilled in the art, without departing from the present application, a number of improvements and refinements can be made, and these improvements and refinements should be regarded as the protection scope of the present application.

Claims

1. A correlation analysis method for alarm events, characterized in that, include: Obtain alarm label groups; Based on preset alarm association analysis rules, the alarm tags in the alarm tag group are matched to obtain the matching results; Based on the matching results, determine the alarm tag set; Based on the alarm tag set, generate the corresponding prompt alarm event for the alarm tag group; The step of matching alarm tags in the alarm tag group based on preset alarm association analysis rules to obtain matching results includes: obtaining alarm association analysis rules corresponding to the alarm tag group type, wherein the alarm tag group type includes historical tag groups and real-time tag groups; determining whether the alarm tags in the alarm tag group conform to the obtained alarm association analysis rules; wherein the historical tag group includes valid historical alarm tags in the historical tag group obtained from the memory database, and the real-time tag group includes the first alarm tag group among the alarm tags generated by the real-time alarm events participating in this association analysis, wherein the grouping field values ​​in the first alarm tag group are the same, and the first alarm tag group belongs to the grouping result of the alarm tags of the real-time alarm event, wherein the grouping result is obtained by grouping the alarm tags of the real-time alarm event according to the tag identifier of the alarm tags of the real-time alarm event.

2. The method according to claim 1, characterized in that, The method further includes: Receive real-time alarm events; Determine the tag generation rules that match the identifier of the real-time alarm event; Based on the tag generation rules, alarm tags for the real-time alarm events are generated.

3. The method according to claim 2, characterized in that, If the tag generation rule includes a persistence instruction, then the method further includes: The alarm tags of the real-time alarm events are saved to an in-memory database. The alarm tags include tag identifier, entity name, and tag generation time.

4. The method according to claim 2, characterized in that, If the tag type corresponding to the tag generation rule is a single alarm event tag, then generating the alarm tag for the real-time alarm event based on the tag generation rule includes: If the real-time alarm event is determined to meet the tag generation conditions corresponding to the tag generation rule, then an alarm tag for the real-time alarm event is generated according to the instructions of the tag generation rule.

5. The method according to claim 2, characterized in that, If the tag type corresponding to the tag generation rule is an aggregated alarm event tag, then generating the alarm tag for the real-time alarm event based on the tag generation rule includes: Based on the aggregation conditions of the tag generation rules, multiple real-time alarm events are aggregated to obtain aggregated alarm events; If the aggregated alarm event is determined to meet the tag generation conditions corresponding to the tag generation rule, then, according to the instructions of the tag generation rule, the alarm tag of the aggregated alarm event is generated as the alarm tag of the multiple real-time alarm events.

6. The method according to claim 1, characterized in that, The obtained alarm tag group includes: The alarm tag group is obtained when the time since the last correlation analysis reaches a preset duration.

7. The method according to any one of claims 1-6, characterized in that, The step of determining the alarm tag set based on the matching result includes: If it is determined that the alarm tags in the alarm tag group conform to the obtained alarm association analysis rules, then the alarm tags are stored in the alarm tag set corresponding to the alarm tag group.

8. The method according to claim 7, characterized in that, The step of generating a notification alarm event corresponding to the alarm tag group based on the alarm tag set includes: If all alarm tags in the alarm tag group are matched according to the preset alarm association analysis rules, and the alarm tag set satisfies the hit condition in the obtained alarm association analysis rules, then the prompt alarm event corresponding to the alarm tag group is generated based on the alarm tags in the alarm tag set.

9. The method according to claim 8, characterized in that, The method further includes: If, after matching all alarm tags in the alarm tag group according to the preset alarm association analysis rules, the alarm tag set does not meet the hit conditions in the obtained alarm association analysis rules, then the alarm tag group is discarded, and the alarm tag group does not correspond to any prompt alarm event.

10. A correlation analysis device for alarm events, characterized in that, include: The acquisition unit is used to acquire alarm tag groups; The matching unit is used to match alarm tags in the alarm tag group based on preset alarm association analysis rules to obtain matching results; The first determining unit is used to determine the alarm tag set based on the matching result; The first generation unit is used to generate a prompt alarm event corresponding to the alarm tag group based on the alarm tag set; Specifically, the matching unit is used to: obtain alarm association analysis rules corresponding to alarm tag group types, wherein the alarm tag group types include historical tag groups and real-time tag groups; determine whether the alarm tags in the alarm tag group conform to the obtained alarm association analysis rules; wherein the historical tag group includes valid historical alarm tags from historical tag groups obtained from the memory database, and the real-time tag group includes a first alarm tag group from the alarm tags generated by the real-time alarm events participating in this association analysis, wherein the values ​​of the grouping fields in the first alarm tag group are the same, and the first alarm tag group belongs to the grouping result of the alarm tags of the real-time alarm event, wherein the grouping result is obtained by grouping the alarm tags of the real-time alarm event according to the tag identifier of the alarm tags of the real-time alarm event.

11. An electronic device, characterized in that, The electronic device includes a processor and a memory: The memory is used to store computer programs; The processor is configured to perform the method according to any one of claims 1-9 according to the computer program.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program for performing the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Data processing method and system

    CN108021809A

  • Warning information filter method and device

    CN108073611A

  • Management and control alarm method and device

    CN112182367A