Attack data processing method, device, electronic device and computer storage device

By analyzing the correlation between multiple alert data and building an alert relationship network, the problem of difficulty in effectively analyzing and handling network attacks in the existing technology is solved, and a more comprehensive and accurate analysis of network attack behavior is achieved.

CN115022079BActive Publication Date: 2025-06-27QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210795166.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-07
Publication Date
2025-06-27
Estimated Expiration
2042-07-07

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively analyze and deal with multi-step, long-term, and hidden attack behaviors in cyber attacks, resulting in a lack of auxiliary tools for computer system security analysis.

Method used

By analyzing the correlation between multiple alert data, an alarm relationship network is built to determine the attack data. The specific steps include: determining the correlation between the alarm data, building an alarm relationship network, and extracting similar alarm sets from it to determine a single-step attack.

Benefits of technology

A more comprehensive and accurate analysis of cyber attack behavior is achieved, and the relationship between various alarm data can be more clearly expressed, thereby improving the security analysis capabilities of computer systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115022079B_ABST
    Figure CN115022079B_ABST
Patent Text Reader

Abstract

The present application provides a method, an apparatus, an electronic device, and a computer storage device for processing attack data. Among them, the method includes: determining the relevance between each of the multiple pieces of alert data among the multiple pieces of alert data obtained; determining an alert relationship network according to the relevance between each of the pieces of alert data; and determining attack data according to the alert relationship network. It is possible to realize the association between various types of alert data and analyze the attack situation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of system security technology. Specifically, it relates to a method, device, electronic device, and computer storage device for processing attack data. Background Art

[0002] With the rapid development of the Internet, various services can be realized online. However, there may be various attacks on the current network, which have changed from the original system permissions to multi-step, long-term, and concealed attacks to gradually obtain target system information and ultimately achieve purposes such as stealing confidential data and disrupting online services. Therefore, network security directly affects the security of various services realized online. Currently, for various attacks on the network, usually only a corresponding reminder is given when the existence of the attack can be detected. But it cannot provide any assistance for the security analysis of computer systems. Summary of the Invention

[0003] The purpose of this application is to provide a method, device, electronic device, and computer storage device for processing attack data to improve the deficiencies in the analysis of existing attacks in computers.

[0004] In a first aspect, an embodiment of this application provides a method for processing attack data, including: determining the correlation between each piece of alarm data among the obtained multiple pieces of alarm data; determining an alarm relationship network according to the correlation between each piece of alarm data; and determining attack data according to the alarm relationship network.

[0005] Optionally, the determining the correlation between each piece of alarm data among the obtained multiple pieces of alarm data includes: for a first alarm data and a second alarm data among the multiple pieces of alarm data, determining the correlation between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data; where the first alarm data and the second alarm data are any two pieces of alarm data among the multiple pieces of alarm data.

[0006] Optionally, the determining the correlation between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data includes: if the alarm category of the first alarm data is a host alarm, determining whether the alarm category of the second alarm data is the host alarm; if the alarm category of the second alarm data is the host alarm, determining that the correlation between the first alarm data and the second alarm data is a first value.

[0007] Optionally, determining the relevance between the first alarm data and the second alarm data based on the first alarm category of the first alarm data and the second alarm category of the second alarm data further includes: if the alarm category of the second alarm data is a network alarm, determining whether the source of the first alarm data and the source of the second alarm data are the same host; if the source of the first alarm data and the source of the second alarm data are the same host, determining that the relevance between the first alarm data and the second alarm data is a first value.

[0008] Optionally, determining the relevance between the first alarm data and the second alarm data based on the first alarm category of the first alarm data and the second alarm category of the second alarm data includes: if the alarm categories of both the first alarm data and the second alarm data are network alarms, determining the relevance between the first alarm data and the second alarm data based on the first field of the first alarm data and the second field of the second alarm data.

[0009] Optionally, the first field includes a first IP field and a first port field, and the second field includes a second IP field and a second port field; determining the relevance between the first alarm data and the second alarm data based on the first field of the first alarm data and the second field of the second alarm data includes: determining an IP relationship value based on the first IP field and the second IP field; determining a port relationship value based on the first port field and the second port field; determining the relevance between the first alarm data and the second alarm data based on the IP relationship value and the port relationship value.

[0010] Optionally, determining the port relationship value based on the first port field and the second port field includes: if the first port field and the second port field are the same port, determining that the port relationship value is a first value; if the first port field and the second port field are not the same port, determining whether the first port field and the second port field are two ports of the same service, and if so, determining that the port relationship value is a third value; if the first port field and the second port field are not the same port, and the first port field and the second port field are not two ports of the same service, and if so, determining that the port relationship value is a second value.

[0011] Optionally, determining the IP relationship value according to the first IP field and the second IP field includes: if both the first IP field and the second IP field are private network IPs, determining the ratio of the common field of the first IP field and the second IP field to a specified value as the IP relationship value between the first IP field and the second IP field; if at least one of the first IP field and the second IP field is a public network IP, determining the IP relationship value as a second value.

[0012] Optionally, the IP relationship value includes a first IP relationship value and a second IP relationship value; the first IP field includes a first source IP field and a first destination IP field, and the second IP field includes a second source IP field and a second destination IP field; determining the IP relationship value according to the first IP field and the second IP field includes: determining the first IP relationship value according to the first source IP field and the second source IP field; determining the second IP relationship value according to the first destination IP field and the second destination IP field.

[0013] Optionally, determining the relevance between the first alert data and the second alert data according to the IP relationship value and the port relationship value includes: performing a weighted calculation on the first IP relationship value, the second IP relationship value, and the port relationship value to obtain the relevance between the first alert data and the second alert data; wherein, the weighted weights of the first IP relationship value, the second IP relationship value, and the port relationship value are preset weights.

[0014] Optionally, the alert relationship network includes multiple nodes and at least one relationship edge. Any one node corresponds to one piece of alert data, and any one relationship edge is used to connect two nodes, and the relevance between the two pieces of alert data corresponding to the two connected nodes satisfies a preset condition.

[0015] Optionally, determining the attack data according to the alert relationship network includes: based on the relationship edges connected to each node in the alert relationship network, extracting multiple similar alert sets from the alert relationship network to determine multiple single-step attacks according to the multiple similar alert sets, where each similar alert set includes multiple pieces of similar alert data, and each single-step attack corresponds to a similar alert set.

[0016] Optionally, the method further includes: obtaining the alert hint fields in each piece of similar alert data in any single-step attack; determining the target alert hint field of the single-step attack from the alert hint fields in each piece of similar alert data, and the target alert hint field is used as a hint message when the single-step attack occurs.

[0017] Optionally, one or more intrusion sources and one or more intrusion targets are recorded in the similar alarm set corresponding to the single-step attack; the method further includes: determining an intrusion source set and an intrusion target set corresponding to each single-step attack according to the similar alarm set corresponding to each single-step attack; determining an association degree value between each single-step attack according to the intrusion source set and the intrusion target set corresponding to each single-step attack; and constructing an attack relationship network according to the association degree value between each single-step attack.

[0018] Optionally, the multiple single-step attacks include a first single-step attack and a second single-step attack, the first single-step attack includes a first intrusion source set and a first intrusion target set, and the second single-step attack includes a second intrusion source set and a second intrusion target set; the determining an association degree value between each single-step attack according to the intrusion source set and the intrusion target set corresponding to each single-step attack includes: determining a first association value according to the first intrusion source set and the second intrusion source set; determining a second association value according to the first intrusion target set and the second intrusion target set; determining a third association value according to the first intrusion source set and the second intrusion target set; determining a fourth association value according to the first intrusion target set and the second intrusion source set; and determining an association degree value between the first single-step attack and the second single-step attack according to the first association value, the second association value, the third association value, and the fourth association value.

[0019] Optionally, the determining an association degree value between the first single-step attack and the second single-step attack according to the first association value, the second association value, the third association value, and the fourth association value includes: selecting the maximum value among the first association value, the second association value, the third association value, and the fourth association value as the association degree value between the first single-step attack and the second single-step attack; or performing weighted summation on the first association value, the second association value, the third association value, and the fourth association value to obtain the association degree value between the first single-step attack and the second single-step attack.

[0020] Optionally, the determining a correlation degree between each piece of alarm data in the obtained multiple pieces of alarm data includes: for each piece of alarm data, extracting a specified field in the alarm data to determine target alarm data in a target format; and determining a correlation degree between each piece of alarm data in the multiple pieces of target alarm data according to the multiple pieces of target alarm data.

[0021] Optionally, extracting specified fields in the alarm data to determine target alarm data in a target format includes: extracting an alarm type field, a source IP field, a source port field, a target IP field, and a target port field in the alarm data; and constructing the target alarm data in the target format according to the alarm type field, the source IP field, the source port field, the target IP field, and the target port field.

[0022] In a second aspect, an embodiment of the present application provides an attack data processing device, including: a relevance determination module, configured to determine the relevance between each piece of alarm data in the obtained multiple pieces of alarm data; a relationship determination module, configured to determine an alarm relationship network according to the relevance between each piece of alarm data; and an attack determination module, configured to determine attack data according to the alarm relationship network.

[0023] In a third aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory, where the memory stores machine-readable instructions executable by the processor, and when the electronic device runs, the machine-readable instructions are executed by the processor to perform the steps of the above-mentioned attack data processing method.

[0024] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, it performs the steps of the above-mentioned attack data processing method.

[0025] The embodiments of the present application at least include the following beneficial effects: By analyzing each piece of alarm data, the relevance of each piece of alarm data is determined, and an alarm relationship network is constructed based on this; through this alarm relationship network, the relationship between each piece of alarm can be represented more clearly, and the attack-related situation can be analyzed more comprehensively. Description of the Drawings

[0026] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.

[0027] Figure 1 It is a schematic diagram of the operating environment of the attack data processing method provided by the embodiment of the present application;

[0028] Figure 2 It is a block diagram of the electronic device provided by the embodiment of the present application;

[0029] Figure 3Flowchart of the attack data processing method provided by an embodiment of this application;

[0030] Figure 4 Schematic diagram of an alarm relationship network provided by an embodiment of this application;

[0031] Figure 5 Partial optional flowchart of step 210 of the attack data processing method provided by an embodiment of this application;

[0032] Figure 6 Optional flowchart of step 216 of the attack data processing method provided by an embodiment of this application;

[0033] Figure 7 Another partial optional flowchart of step 210 of the attack data processing method provided by an embodiment of this application;

[0034] Figure 8 Schematic diagram of the functional modules of the attack data processing method device provided by an embodiment of this application. Detailed implementation manners

[0035] Next, the technical solutions in the embodiments of this application will be described with reference to the accompanying drawings in the embodiments of this application.

[0036] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0037] In modern network environment attacks, it is no longer just about obtaining system permissions. More likely, there may be multi-step, long-term, and covert attacks to gradually obtain system information, and ultimately may achieve purposes such as stealing confidential data and disrupting online services. If such attacks are not analyzed and prevented, it may lead to significant security risks in various services on the network, and the information of users may no longer be secret.

[0038] The inventors have studied and understood that there may be some viruses on the network that use vulnerabilities in the SMB protocol to spread in the network, encrypt files after infecting Windows hosts and extort money, causing serious harm. Advanced persistent threat (APT) is a new type of attack behavior with a time span of several months to several years and strong concealment. During the penetration process, 0day vulnerabilities are often used, and it is difficult for IDS (intrusion detection system) to detect. This is mainly because IDS only focuses on single-step attacks and does not consider the complete penetration process of the attacker into the system; secondly, the situation of false alarms generated by IDS is relatively frequent, which is easy to mislead the analysis; finally, when the scale of the information system is large, the massive alarms generated by various IDSs cannot be processed manually.

[0039] Based on the above research, the present application provides an attack data processing method that can analyze the occurring attack behaviors from a large amount of alarm data. The data processing method provided by the present application will be described below through some embodiments.

[0040] To facilitate the understanding of this embodiment, first, the operating environment for implementing an attack data processing method disclosed in the embodiments of the present application will be introduced.

[0041] The operating environment of this attack data processing method can be an attack data analysis system. As Figure 1 shown, this attack data analysis system may include an electronic device 110 for processing various alarm data, and a terminal device 120 for collecting various alarm data.

[0042] The electronic device 110 and the terminal device 120 can be a network server, a database server, etc., or can be a personal computer (PC), a tablet computer, a smart phone, a personal digital assistant (PDA), etc.

[0043] Among them, an IDS that is used to instantaneously monitor network transmissions and issue alarms or take proactive response measures when suspicious transmissions are found can be run in the terminal device 120.

[0044] Exemplarily, the IDS can be an NIDS (Network intrusion detection system) or an HIDS (Host-based Intrusion Detection System). Of course, an NIDS and an NIDS can also be run in the terminal device 120.

[0045] Among them, the NIDS is used to obtain all network alert data in the internal subnet. The HIDS is used to obtain all host alert data for which the HIDS functions.

[0046] The electronic device 110 can receive all the original alert data collected by the terminal device 120 and execute the attack data processing method according to some embodiments of the present application based on all the original alert data.

[0047] As Figure 2 shown, it is a block diagram of the electronic device. The electronic device 110 may include a memory 111 and a processor 113. Those of ordinary skill in the art can understand that Figure 2 the structure shown is only illustrative and does not limit the structure of the electronic device 110. For example, the electronic device 110 may further include more or fewer components than Figure 2 shown, or have a different configuration from Figure 2 shown.

[0048] The above-mentioned memory 111 and the processor 113 are electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines. The above-mentioned processor 113 is used to execute the executable module stored in the memory.

[0049] Among them, the memory 111 can be, but is not limited to, a random access memory (Random Access Memory, abbreviated as RAM), a read-only memory (Read Only Memory, abbreviated as ROM), a programmable read-only memory (Programmable Read-Only Memory, abbreviated as PROM), an erasable programmable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), an electrically erasable programmable read-only memory (Electric Erasable Programmable Read-Only Memory, abbreviated as EEPROM), etc. Among them, the memory 111 is used to store a program. After receiving the execution instruction, the processor 113 executes the program. The method executed by the electronic device 110 defined by the process disclosed in any embodiment of the embodiments of the present application can be applied to the processor 113 or implemented by the processor 113.

[0050] The above-mentioned processor 113 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor 113 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0051] The electronic device 110 in this embodiment can be used to execute each step in the various methods provided in the embodiments of the present application. The implementation process of the attack data processing method will be described in detail through several embodiments below.

[0052] Please refer to Figure 3 , which is a flowchart of the attack data processing method provided in the embodiments of the present application. The following will elaborate in detail on Figure 3 the specific process shown.

[0053] Step 210, based on the obtained multiple alert data, determine the correlation between each piece of alert data among the multiple alert data.

[0054] Among them, the correlation between any two pieces of alert data can be used to represent the relationship between the two pieces of alert data. For example, the greater the correlation, the closer the relationship between the two pieces of alert data can be represented.

[0055] In some embodiments, the correlation between each piece of alert data can be represented by a numerical value. This numerical value can be calculated based on the information contained in the alert data.

[0056] Exemplarily, the sources of the multiple alert data can be report data obtained in scenarios such as network monitoring and detection of host behaviors.

[0057] Step 220, based on the correlation between each piece of alert data, determine an alert relationship network.

[0058] Exemplarily, it can be determined whether to establish an association relationship based on the magnitude of the correlation between each piece of alert data. For example, when the correlation meets a preset condition, an association relationship can be established between two pieces of alert data.

[0059] The preset condition can be that the relevance is a specified value, or the relevance is greater than a set threshold, etc. Specifically, the preset condition here can be set according to the actual situation.

[0060] Optionally, the preset condition can be that the relevance is a first value, or the preset condition can also be that the determined value of the relevance is greater than the relationship threshold. Therefore, if the relevance of any two pieces of alarm data is determined to be the first value, taking the two pieces of alarm data as nodes, a relationship edge is constructed between the two nodes; or if the determined value of the relevance of any two pieces of alarm data is greater than the relationship threshold, taking the two pieces of alarm data as two nodes in the alarm relationship network, and a relationship edge is constructed between the two nodes.

[0061] Exemplarily, the first value can be 1. Of course, the first value can also be set to other values according to requirements.

[0062] If the presentation method of the alarm relationship network is different, the presentation method of the association relationship is also different.

[0063] Exemplarily, if the alarm relationship network is presented in the form of a relationship network graph, then the association relationship can be presented by each edge in the relationship network graph.

[0064] Exemplarily, the alarm relationship network includes multiple nodes and at least one relationship edge. Any one node corresponds to one piece of alarm data, and any one relationship edge is used to connect two nodes, and the relevance of the two pieces of alarm data corresponding to the two connected nodes satisfies the preset condition.

[0065] Take Figure 4 as an example. Figure 4 shows a relationship network graph including ten pieces of alarm data Ad1, Ad2, Ad3,..., Ad8, Ad9, Ad10. Figure 4 The example shown includes 10 pieces of alarm data. Each piece of alarm data can form a node in the relationship network graph. The edge formed by two nodes can represent the association relationship between the two nodes, and the value on the edge can be the relevance between the alarm data. For example, wij represents the relevance between the i-th piece of alarm data and the j-th piece of alarm data. It can be seen from the figure that not all nodes are connected by edges. Figure 4 In the example shown, no connected edge is formed between the alarm data Ad1 and the alarm data Ad4, which can indicate that the relevance between the alarm data Ad1 and the alarm data Ad4 does not meet the preset condition.

[0066] It can be known that Figure 4 is just an example. In actual situations, the alarm data included in the alarm relationship network graph can be much more than Figure 4 the example shown. For example, in actual situations, the relationship network graph may contain 100 pieces, 1000 pieces of alarm data, or even more alarm data.

[0067] Exemplarily, the alarm relationship network is presented in the form of a table, and can also be in any other data form that can represent the relationship of alarm data.

[0068] Step 230, determine the attack data according to the alarm relationship network.

[0069] Among them, the intrusion targets caused by a single-step attack can be one or more, and the intrusion sources initiating a single-step attack can also be one or more. Based on this, multiple similar alarm sets can be extracted according to the association relationship between the alarm data in the alarm relationship network, so as to determine multiple single-step attacks according to the multiple similar alarm sets. A similar alarm set can include multiple similar alarm data, and one similar alarm set corresponds to one single-step attack.

[0070] Among them, one similar alarm set can be determined as one single-step attack. It can also be understood that when a single-step attack occurs, the alarm data in a similar alarm set may be generated.

[0071] Among them, if two alarm data are similar alarm data to each other, it can indicate that the correlation degree between the two alarm data satisfies a preset condition, or the two alarm data have an association relationship in the alarm relationship network, forming a relationship edge, etc.

[0072] Exemplarily, multiple similar alarm sets can be extracted from the alarm relationship network based on the relationship edges connected to each node in the alarm relationship network.

[0073] Among them, the intersection between any two alarm data sets can be empty, and the intersection between any two alarm data sets can also be non-empty.

[0074] In one implementation, the minimum number of alarm data required to be included in a similar alarm set can be preset. For example, the required number of alarm data to be included can be k. For example, first determine the first node with the most connected relationship edges; then select the second node from the nodes having a connection relationship with the first node; then select the third node from the nodes having a connection relationship with both the first node and the second node, or the nodes having a connection relationship with the first node or the second node, and so on, at least k nodes can be selected, and the alarm data corresponding to at least k nodes can form a similar alarm set. Then, the nodes that have already formed a similar alarm set are removed from the alarm relationship network, and other similar alarm sets are screened out.

[0075] Optionally, when screening nodes each time, the node with the most relationship edges connected to the selected nodes and the most relationship edges connected to itself can be screened out.

[0076] In another implementation, a community discovery algorithm can be used to extract the similar alarm sets in the alarm relationship network.

[0077] Optionally, the community discovery algorithm can be CPM (Clique Percolation Method). Using this clique percolation algorithm, similar alert sets in the alert relationship network are extracted.

[0078] In one instance, the discovery of a single-step attack in the alert relationship network can be achieved through the following process:

[0079] Input: Alert relationship network graph Galert

[0080] Output: Family of similar alert sets C, where each element Ci in the family of similar alert sets is a set of internal nodes in Galert, which can represent a similar alert set and also represent a single-step attack C ← {}

[0081] cliques ← Set of complete subgraphs in Galert containing k nodes

[0082] {Initialize an undirected unweighted graph Gclique with nodes as cliques}

[0083] for all pairs of nodes u, v in Gclique do

[0084] if u, v have at least k - 1 same nodes in Galert then

[0085] Add an edge (u, v) to Gclique

[0086] end if

[0087] end for

[0088] res ← Set of connected components in Gclique

[0089] for all r ∈ res do

[0090] alerts ← Set of alerts contained in Galert for each element in r

[0091] Add the alerts set to the family of similar alert sets C

[0092] end for

[0093] The family of similar alert sets C can also represent multiple similar alert sets. Each element Ci in the family of similar alert sets is a set of internal nodes in Galert, which can represent a similar alert set and also represent a single-step attack. This family of similar alert sets C can be used to represent the family of single-step attacks C.

[0094] In the above steps, the correlation of each piece of alarm data can be analyzed to determine the correlation of each piece of alarm data, and an alarm relationship network can be constructed based on this; through this alarm relationship network, the relationship between each piece of alarm data can be represented more clearly, and the attack-related situations can be analyzed more comprehensively.

[0095] Each piece of alarm data may include an alarm type field, a source IP field, a source port field, a destination IP field, and a destination port field.

[0096] Among them, the alarm type field is used to characterize the category to which the alarm data belongs. For example, if the category to which the alarm data belongs is a network alarm, the alerttype field is network; if the category to which the alarm data belongs is a host alarm, the alerttype field is host.

[0097] If the category to which the alarm data belongs is a network alarm, the source IP field srcip is the intrusion source IP; if the category to which the alarm data belongs is a host alarm, the source IP field srcip is the host IP where the anomaly occurs.

[0098] If the category to which the alarm data belongs is a network alarm, the source port field srcport is the port used by the intrusion source; if the category to which the alarm data belongs is a host alarm, the source port field srcport is 0.

[0099] If the category to which the alarm data belongs is a network alarm, the destination IP field dstip is the intrusion target IP; if the category to which the alarm data belongs is a host alarm, the destination IP field dstip is the host IP where the anomaly occurs.

[0100] If the category to which the alarm data belongs is a network alarm, the destination port field dstport is the port of the intrusion target; if the category to which the alarm data belongs is a host alarm, the destination port field dstport is 0.

[0101] In addition to the above information, an alarm data may also include an alarm prompt field msg, and this alarm prompt field msg may be the warning message provided by the IDS. If the IDS does not provide this field, the alarm prompt content may be set to any other default value, or this field is set to be missing.

[0102] Since the hosts involved in different categories of alarm data are different, when determining the relevance between two alarm data, it is possible to start from the category of the alarm data. Exemplarily, based on the information contained in each alarm data, for example, the relevance between each alarm data can be determined according to the alarm category of the alarm data. For the first alarm data and the second alarm data among the multiple alarm data, step 210 can be implemented as: determining the relevance between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data.

[0103] Wherein, the first alarm data and the second alarm data are any two alarm data among the multiple alarm data.

[0104] Through the above method, the relevance between any two alarm data among the multiple alarm data can be determined.

[0105] In one implementation, as Figure 5 shown, step 210 may include the following steps 211 to 216.

[0106] Step 211, determine whether the alarm category of the first alarm data is a host alarm.

[0107] If the alarm category of the first alarm data is a host alarm, then execute step 212; if the alarm category of the first alarm data is a network alarm, then execute step 212.

[0108] Step 212, determine whether the alarm category of the second alarm data is the host alarm.

[0109] If the alarm category of the second alarm data is a host alarm, then execute step 213; if the alarm category of the second alarm data is a network alarm, then execute step 214.

[0110] Step 213, determine that the relevance between the first alarm data and the second alarm data is the first value.

[0111] Optionally, when the occurrence sources of the first alarm data and the second alarm data are the same host, further determine that the relevance between the first alarm data and the second alarm data is the first value. Wherein, if the alarm categories of the first alarm data and the second alarm data are both host alarms, the occurrence source is also the intrusion source, and can also represent the host where the abnormality occurs. The source IP field of the first alarm data can be compared with the source IP field of the second alarm data to determine whether the occurrence sources of the first alarm data and the second alarm data are the same host.

[0112] Step 214, determine whether the occurrence source of the first alarm data and the occurrence source of the second alarm data are the same host.

[0113] The first alarm data is a host alarm, and the source of the first alarm data may be an intrusion source, that is, a host where an abnormality occurs. The second alarm data is a network alarm, and the source of the first alarm data may be an intrusion source or an intrusion target, that is, a host where an attack is initiated or a host that is attacked abnormally.

[0114] Therefore, the source IP field of the first alarm data may be compared with the source IP field and the target IP field of the second alarm data to determine whether the first alarm data and the second alarm data are generated from the same host.

[0115] If the source of the first alarm data and the source of the second alarm data are the same host, step 215 is executed.

[0116] Step 215: Determine that the correlation between the first alarm data and the second alarm data is a first value.

[0117] Step 216: If the alarm categories of the first alarm data and the second alarm data are both network alarms, determine the correlation between the first alarm data and the second alarm data according to the first field of the first alarm data and the second field of the second alarm data.

[0118] Exemplarily, the first field includes a first IP field and a first port field, and the second field includes a second IP field and a second port field.

[0119] like Figure 6 As shown, step 216 may include steps 2161 to 2163.

[0120] Step 2161, determining an IP relationship value based on the first IP field and the second IP field.

[0121] If both the first IP field and the second IP field are intranet IPs, the ratio of the common field of the first IP field and the second IP field to the specified value is determined as the IP relationship value of the first IP field and the second IP field. For example, the longest common prefix of the two IP fields in binary representation can be determined first, and the ratio of the longest common prefix length to the specified value is used as the IP relationship value of the two IPs. In one example, the specified value can be 32.

[0122] If at least one of the first IP field and the second IP field is a public IP, determine that the IP relationship value is the second value. That is, if any one of the IP fields is a public IP, it can be determined that the IP relationship value between the first IP field and the second IP field is the second value. The second value can be 0. Of course, the second value can also be set to other values according to requirements. Exemplarily, the second value can be a value smaller than the first value.

[0123] Since there may be multiple hosts involved in network alerts, alerts involving multiple hosts cannot determine the relevance of two alert data only by whether the hosts are the same. To make the determined relevance between each alert data more accurate, the above implementation method for determining relevance starts from the essence of network alerts. It is learned that the relevance in network alerts is mainly reflected in the source and destination of the transmitted data, that is, in the IP and port involved in the network alert. Therefore, calculating the relevance of two alert data from the information in two dimensions of IP and port can better characterize the relevant properties of the two alert data.

[0124] Considering that there are source IP and destination IP in network alerts, and the source IP and destination IP can respectively represent the hosts involved in the network alert, therefore, the relationship values between the IPs owned by the two alert data can be calculated respectively.

[0125] Exemplarily, the IP relationship value includes a first IP relationship value and a second IP relationship value; the first IP field includes a first source IP field and a first destination IP field, and the second IP field includes a second source IP field and a second destination IP field.

[0126] Step 2161 may include: determining a first IP relationship value according to the first source IP field and the second source IP field; determining a second IP relationship value according to the first destination IP field and the second destination IP field.

[0127] Step 2162, determine a port relationship value according to the first port field and the second port field.

[0128] Exemplarily, if the first port field and the second port field are the same port, determine that the port relationship value is the first value; if the first port field and the second port field are not the same port, determine whether the first port field and the second port field are two ports of the same service. If so, determine that the port relationship value is the third value; if the first port field and the second port field are not the same port, and the first port field and the second port field are not two ports of the same service, if so, determine that the port relationship value is the second value.

[0129] Optionally, there may be a pre-defined mapping table of services and ports in advance. For example, the web service corresponds to ports 20, 663, 6060, etc., and the ftp service corresponds to ports 21 and 23.

[0130] If two ports are the same, the port relationship value is determined to be the first value. For example, the first value can be 1. If two ports are different but belong to the same service in the service-port mapping table, the port relationship value is determined to be the third value, and the third value can be 0.5; in other cases, the port relationship value is determined to be the second value. Of course, according to actual needs, the third value can also be set to other values. Among them, the third value is a value between the first value and the second value, that is, the third value is larger than the second value and smaller than the first value.

[0131] Among them, if the ports where network alarms occur are the same port, it is more likely to indicate that there is a greater correlation between two alarm data; secondly, if two ports are different but belong to the same service, therefore, the two alarm data may be correlated; thirdly, if two ports are neither the same nor belong to the same service, the probability of correlation between the two alarm data is smaller. Therefore, based on the analysis of three correlation levels, the port relationship values for the three correlation levels are determined to be three different values, which can better reflect the difference in the correlation of two alarm data through the values.

[0132] Step 2163, determine the correlation degree between the first alarm data and the second alarm data according to the IP relationship value and the port relationship value.

[0133] Optionally, the first IP relationship value, the second IP relationship value, and the port relationship value can be weighted and calculated to obtain the correlation degree between the first alarm data and the second alarm data.

[0134] Among them, the weighting weights of the first IP relationship value, the second IP relationship value, and the port relationship value are pre-set weights. For example, the weights of the first IP relationship value, the second IP relationship value, and the port relationship value can be the same value, for example, all 1 / 3. For another example, the weights of the first IP relationship value, the second IP relationship value, and the port relationship value can also be different values, and specifically, the weights of the first IP relationship value, the second IP relationship value, and the port relationship value can be set as needed.

[0135] In one example, the calculation of the correlation degree between each alarm data can be implemented through the following process:

[0136] Input: Multiple alarm data A

[0137] Output: Alarm relationship network graph Galert

[0138] Take all the alarm data in A as the point set of G. Initially, there are no edges in the graph

[0139] For all pairs of points u, v in Galert do

[0140] If v is a host alarm then

[0141] Swap u and v

[0142] End if

[0143] If both u and v are host alarms then

[0144] If u.srcip = v.srcip then

[0145] Add a relationship edge (u, v, 1) to Galert

[0146] End if

[0147] Else if u is a host alarm and v is a network alarm then

[0148] If u.srcip = v.srcip ∨ u.srcip = v.dstip then

[0149] Add a relationship edge (u, v, 1) to Galert

[0150] End if

[0151] Else {both u and v are network alarms}

[0152] sim srcip ← IPSIM(u.srcip, v.srcip) {intrusion source IP relationship value}

[0153] sim dstip ← IPSIM(u.dstip, v.dstip) {intrusion target IP relationship value}

[0154] sim dstport ← PORTSIM(u.dstport, v.dstport) {target port relationship value}

[0155] score = w srcip · sim srcip + w dstip · sim dstip + w dstport · sim dstport

[0156] If score > τ then

[0157] Add a relationship edge (u, v, score) to Galert

[0158] end if

[0159] end if

[0160] end for

[0161] Among them, through the above process, the alarm relationship network graph Galert, the correlation score between each alarm data, the target port relationship value dstport, the intrusion target IP relationship value dstip, and the intrusion source IP relationship value srcip can be determined.

[0162] The above u and v represent any two alarm data, w srcip, w dstip, and w dstport respectively represent the weights of the target port relationship value, the intrusion target IP relationship value, and the intrusion source IP relationship value, and τ represents the relationship threshold. The value of the relationship threshold τ can be set as needed. For example, the relationship threshold τ is set to values such as 1, 0.9, 0.7, 1.2, etc.

[0163] Through the above method, the information that may be included in the alarm data can be fully considered, and based on various types of information, the correlation between two alarm data can be judged, so that the correlation can better represent the association between the two alarm data.

[0164] On the basis of discovering a single-step attack, in order to make the alarm message of the alarm better represent the current abnormality of the computer, the alarm data existing in the single-step attack can be analyzed to determine a more accurate alarm prompt message. Therefore, after step 230, it may further include: obtaining the alarm prompt fields in each similar alarm data in any single-step attack; determining the target alarm prompt field of the single-step attack from the alarm prompt fields in each similar alarm data.

[0165] The target alarm prompt field is used as the prompt message when the single-step attack occurs.

[0166] Exemplarily, the alarm prompt fields in all the alarm data in the single-step attack can be obtained, the occurrence times of various alarm prompt fields are determined, and if the occurrence times of any one alarm prompt field exceed the specified ratio, then the alarm prompt field is used as the target alarm prompt field of the single-step attack. The specified ratio can be 40%, 50%, 55%, etc.

[0167] Through the above method, the abnormality existing in the single-step attack can be determined more accurately, so that the prompt message can more accurately achieve the purpose of prompting.

[0168] Based on the discovery of single-step attacks, in order to more fully understand the relationships between various single-step attacks, it is also possible to analyze each single-step attack to determine the relationships between them. After step 230, the attack data processing method may further include the following steps.

[0169] Step 240, determine the intrusion source set and intrusion target set corresponding to each single-step attack according to the similar alarm sets corresponding to each single-step attack.

[0170] Exemplarily, single-step attacks may include several categories such as one-to-one, one-to-many, many-to-one, and many-to-many. One-to-one means a single intrusion source and a single intrusion target. For example, attacks such as SQL (Structured Query Language) injection. One-to-many means a single intrusion source and multiple intrusion targets. For example, subnet scanning. Many-to-one means multiple intrusion sources and a single intrusion target. For example, DDoS (Distributed denial of service attack). Many-to-many means multiple intrusion sources and multiple intrusion targets. For example, worm propagation.

[0171] When the single-step attack is one-to-one, the intrusion source set includes a single intrusion source, and the intrusion target set includes a single intrusion target. When the single-step attack is one-to-many, the intrusion source set includes a single intrusion source, and the intrusion target set includes multiple intrusion targets. When the single-step attack is many-to-one, the intrusion source set includes multiple intrusion sources, and the intrusion target set includes a single intrusion target. When the single-step attack is many-to-many, the intrusion source set includes multiple intrusion sources, and the intrusion target set includes multiple intrusion targets.

[0172] Among them, the intrusion sources and intrusion targets corresponding to a single-step attack can be presented through the information recorded in the similar alarm set corresponding to the single-step attack. Exemplarily, the source IP field in the similar alarm set corresponding to a single-step attack can be used to represent the intrusion source, and the target IP field in the similar alarm set can be used to represent the intrusion target.

[0173] In one instance, it can be implemented through the following process:

[0174] Input: Single-step attack family C

[0175] Output: Single-step attack tags

[0176] tags ← {}

[0177] for all Ci ∈ C do

[0178] A ← the number of intrusion source IPs in Ci

[0179] T ← the number of intrusion target IPs in Ci

[0180] V ← the number of all distinct IPs involved in Ci

[0181]

[0182]

[0183]

[0184]

[0185] t ← the classification corresponding to the maximum value among δOtO, δOtM, δMtO, δMtM

[0186] tags[Ci] ← t

[0187] end for

[0188] In the above process, δOtO, δOtM, δMtO, δMtM represent the possible values corresponding to four categories, and OtO, OtM, MtO, MtM represent the four categories of one - to - one, one - to - many, many - to - one, and many - to - many respectively.

[0189] The maximum value among δOtO, δOtM, δMtO, δMtM can be selected as the single - step attack label tags, and the single - step attack label tags represent the category to which the single - step attack belongs. Each element Ci in the single - step attack family C represents a single - step attack.

[0190] Step 250, determine the degree of association value between each single - step attack according to the intrusion source set and the intrusion target set corresponding to each single - step attack.

[0191] Optionally, for the degree of association value between any two single - step attacks, it can be determined according to the repetition rate of the intrusion source set and the intrusion target set corresponding to the single - step attacks. For example, the intersection of the intrusion source sets and the intrusion target sets of two single - step attacks can be calculated, and the ratio of it to the union of the intrusion source sets and the intrusion target sets of the two single - step attacks can be used to determine the degree of association value between the two single - step attacks.

[0192] Taking the first single-step attack and the second single-step attack as examples, the union of the intrusion source set of the first single-step attack and the intrusion target set can be calculated first to obtain the first intrusion set; the union of the intrusion source set of the second single-step attack and the intrusion target set can be calculated to obtain the second intrusion set; the intersection of the first intrusion set and the second intrusion set can be determined, and the union of the first intrusion set and the second intrusion set can be determined; then the ratio of the intersection to the union can be calculated, and this ratio can be determined as the correlation degree value between the first single-step attack and the second single-step attack.

[0193] Taking the first single-step attack and the second single-step attack as examples, the ratio of the intersection to the union of the intrusion source set of the first single-step attack and the intrusion source set of the second single-step attack can be calculated first to obtain the first ratio; then, the ratio of the intersection to the union of the intrusion target set of the first single-step attack and the intrusion target set of the second single-step attack can be calculated to obtain the second ratio; the correlation degree value between the first single-step attack and the second single-step attack can be obtained according to the first ratio and the second ratio.

[0194] Of course, on the basis of the determination of the above correlation degree value, the comparative analysis of the intrusion source set of the first single-step attack and the intrusion target set of the second single-step attack, and the comparative analysis of the intrusion source set of the second single-step attack and the intrusion target set of the first single-step attack can also be combined to determine the correlation degree value between the first single-step attack and the second single-step attack.

[0195] Exemplarily, the intrusion source set can be represented by the source IP set, and the intrusion target set can be represented by the target IP set. The correlation degree value between each single-step attack can be determined according to the source IP set and the target IP set.

[0196] For any two single-step attacks among multiple single-step attacks, for example, the two single-step attacks are: the first single-step attack and the second single-step attack. The first single-step attack includes a first intrusion source set and a first intrusion target set, and the second single-step attack includes a second intrusion source set and a second intrusion target set.

[0197] Exemplarily, the first intrusion source set of the first single-step attack can be represented by the first source IP set, the first intrusion target set of the first single-step attack can be represented by the first target IP set, the second intrusion source set of the second single-step attack can be represented by the second source IP set, and the second intrusion target set of the second single-step attack can be represented by the second target IP set.

[0198] Step 250 may include: determining a first correlation value according to the first intrusion source set and the second intrusion source set; determining a second correlation value according to the first intrusion target set and the second intrusion target set; determining a third correlation value according to the first intrusion source set and the second intrusion target set; determining a fourth correlation value according to the first intrusion target set and the second intrusion source set; and determining a correlation degree value between the first single-step attack and the second single-step attack according to the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value.

[0199] Then, a first correlation value may be determined according to the first source IP set and the second source IP set; a second correlation value may be determined according to the first target IP set and the second target IP set; a third correlation value may be determined according to the first source IP set and the second target IP set; and a fourth correlation value may be determined according to the first target IP set and the second source IP set.

[0200] In one implementation, the maximum value among the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value may be selected as the correlation degree value between the first single-step attack and the second single-step attack.

[0201] In another implementation, weighted summation is performed on the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value to obtain the correlation degree value between the first single-step attack and the second single-step attack.

[0202] Considering that the occurrence of a single-step attack may lead to the occurrence of further single-step attacks. At this time, the intrusion target of the previous single-step attack may be the intrusion source of the subsequent single-step attack; it is also possible that multiple single-step attacks occur at once. At this time, the intrusion sources of the multiple single-step attacks are the same; there may also be some attacks in order to achieve a better attack effect. Therefore, through multiple single-step attacks, the purpose of the attack is achieved. At this time, the intrusion targets of the multiple single-step attacks are the same. Based on the above analysis, the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value can represent the correlation degree between single-step attacks to different degrees. Therefore, when determining the correlation degree value between the first single-step attack and the second single-step attack, the influence of the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value can be fully considered, so that the finally determined correlation degree value can better characterize the correlation degree between the first single-step attack and the second single-step attack.

[0203] Considering that the influence of the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value on the correlation degree between single-step attacks may be different in different scenarios. Therefore, when calculating the correlation degree value between single-step attacks based on the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value, the weights of each correlation value can be set as needed.

[0204] Optionally, step 250 may further include: determining the association degree value between each single-step attack according to the intrusion source set and the intrusion target set corresponding to each single-step attack, and the category of each single-step attack.

[0205] Step 260, construct an attack relationship network according to the association degree value between each single-step attack.

[0206] Exemplarily, when the association degree value between two single-step attacks is greater than the association threshold, an association relationship can be created for the two single-step attacks. In the attack relationship network, the association relationship between the two single-step attacks can be represented by an edge.

[0207] Exemplarily, the attack relationship network may include multiple nodes and one or more edges. Each node represents a single-step attack, and an edge can connect two nodes.

[0208] Among them, whether two nodes need to be connected by an edge can be determined according to the association degree value of the two single-step attacks represented by the two nodes. For example, when the association degree value of the two single-step attacks is greater than the association threshold, an edge between the two nodes can be constructed; if the association degree value of the two single-step attacks is not greater than the threshold, an edge between the two nodes may not be constructed.

[0209] In one example, the following process can be used to construct an attack relationship network based on the association degree value of single-step attacks:

[0210] Input: Single-step attack family C, single-step attack labels tags

[0211] Output: Attack relationship network Gattack

[0212] {Initialize the attack relationship network, and the point set represents the elements in the single-step attack family C}

[0213] for all point pairs u, v in Gattack do

[0214] Sim AA←ATTACKIPSETSIM (u represents the intrusion source IP set, v represents the intrusion source IP set)

[0215] Sim TT←ATTACKIPSETSIM (u represents the intrusion target IP set, v represents the intrusion target IP set)

[0216] Sim AT←ATTACKIPSETSIM (u represents the intrusion source IP set, v represents the intrusion target IP set)

[0217] Sim TA←ATTACKIPSETSIM (u represents the intrusion target IP set, v represents the intrusion source IP set)

[0218] maxsim ← max{Sim AA, Sim TT, Sim AT, Sim TA}

[0219] if maxsim > σ then

[0220] Add an edge (u, v, maxsim) to Gattack

[0221] end if

[0222] end for

[0223] Among them, SimAA is used to represent the correlation value between two intrusion source sets; SimTT is used to represent the correlation value between two intrusion target sets; SimAT is used to represent the correlation value between an intrusion source set and an intrusion target set; SimTA is used to represent the correlation value between an intrusion target set and an intrusion source set; σ represents the correlation threshold for measuring the similarity degree of two IP sets; maxsim represents the correlation degree value between two single-step attacks. The value of the correlation threshold σ can be set as needed, and the embodiments of the present application are not limited to the value of this threshold σ.

[0224] ATTACKIPSETSIM is used to measure the similarity degree between two IP sets (X and Y), and the similarity degree can be used as the correlation value of the two IP sets. The specific process is as follows: If the roles of X and Y in their respective single-step attacks are both one or both many, then return (X ∩ Y) / (X ∪ Y); otherwise, assume that the role of X in the two IP sets is one and the role of Y in the two IP sets is many, then return (X ∩ Y) / X. Conversely, assume that the role of X in the two IP sets is many and the role of Y in the two IP sets is one, then return (X ∩ Y) / Y.

[0225] Among them, the above-mentioned role of one or many means one or many mentioned in various categories in a single-step attack. For example, if the type of one of the single-step attacks is one-to-many, then the role of the source IP set in this single-step attack is one, and the role of the target IP set in this single-step attack is many.

[0226] After the process of constructing the attack relationship network is completed, each node in the obtained attack relationship network Gattack can represent a single-step attack. If there is an edge between nodes, it can indicate that the single-step attacks are related, and the weight value of this edge is the correlation degree value, which can be used to represent the correlation degree between two nodes.

[0227] Through the above implementation method, it is possible to determine the internal correlation existing between each single-step attack based on the single-step attack, and it is possible to better determine the occurrence situation of each attack.

[0228] Since the original alert data may vary in terms of sources, the fields it contains can be completely different, and the distribution of each field can also be completely different. Moreover, it is possible that different alert data can contain complete fields, while some alert data only contains partial fields. Therefore, if direct analysis is performed on the original alert data, it may cause certain difficulties in determining subsequent single-step attacks. Therefore, in order to improve the efficiency of determining single-step attacks, it is also possible to preprocess the obtained original alert data in advance to improve the efficiency of subsequent calculations. Therefore, as Figure 7 shown, step 210 may include step 217 and step 218.

[0229] Step 217, for each piece of alert data, extract the specified fields in the alert data to determine the target alert data in the target format.

[0230] Step 218, based on multiple pieces of the target alert data, determine the correlation between each piece of alert data among the multiple pieces of the target alert data.

[0231] Among them, for the implementation process of step 218, reference can be made to the previous description of step 210 or steps 211 to 216, which will not be elaborated here.

[0232] Steps 217 and 218 in this embodiment do not mean that they need to be executed after step 216. Steps 217 and 218 can be independent of the steps included in the previously introduced step 210.

[0233] Of course, step 218 can also be implemented as the steps of the previous steps 211 to 216. At this time, step 217 can be executed before step 211. The alert data processed by steps 211 to 216 can be the target alert data in the target format obtained in this step 217.

[0234] The information in the alert data can include: alert type, source IP, source port, target IP, and target port, etc. The above-mentioned specified fields can be fields that can represent information such as alert type, source IP, source port, target IP, and target port.

[0235] The implementation method of step 217 can be as follows: the alert type field, source IP field, source port field, target IP field, and target port field in the alert data; based on the alert type field, the source IP field, the source port field, the target IP field, and the target port field, construct the target alert data in the target format.

[0236] The alarm data can be sourced from detection data obtained based on NIDS or HIDS, or detection reports determined based on honeypot technology, or software fault reports, etc. Therefore, the original alarm data can be standardized for subsequent analysis.

[0237] Optionally, for alarm data with specified fields, the specified fields in the alarm data can be extracted. Alarm data without specified fields can be discarded to reduce interference from useless data on calculations.

[0238] In one implementation, if an alarm data belongs to plain text format alarm data, then specified fields are extracted from the warning information in this plain text format to obtain an alarm data in a target format.

[0239] In another implementation, if the alarm data belongs to structured alarm data, for example, in formats such as json, XML, etc., it means that the content of each field has been marked in the alarm data. Then, from this structured warning data, the specified fields can be filtered out to obtain the alarm data in the target format.

[0240] In an example, an original alarm data is a host alarm detected by a host intrusion detection system. Then the alarm data in the target format can include: an alarm type field, a source IP field, a source port field, a target IP field, and a target port field. Among them, the alarm type field is "host", used to indicate that this alarm data belongs to a host alarm. In this example, both the source IP field and the target IP field are used to carry the IP of the host where the anomaly occurs, and both the source port number field and the target port field are used to carry a preset value, and the preset value can be 0.

[0241] In another example, an original alarm data is a network alarm detected by a network intrusion detection system. Then the alarm data in the target format can include: an alarm type field, a source IP field, a source port field, a target IP field, and a target port field. Among them, the alarm type field is "network", used to indicate that this alarm data belongs to a network alarm. In this example, the source IP field is used to carry the IP of the intrusion source, the source port field is used to carry the port used by the intrusion source, the target IP field is used to carry the IP of the intrusion target, and the target port field is used to carry the port of the intrusion target that is attacked.

[0242] In an example, the process of alarm data conversion can be described by the following flow.

[0243] Input: The original alarm data R, where Ri is structured alarm data or plain text alarm data

[0244] Output: Normalized alert data A in the target format, where each alert data Ai has the same and non-empty fields

[0245] A←{}

[0246] for all Ri∈R do

[0247] If Ri is plain text format alarm data then

[0248] Ri←EXTRACTVALUE(Ri)

[0249] end if

[0250] Ri←FIELDFILTER(Ri)

[0251] If there is no missing field in Ri then

[0252] Add Ri to A

[0253] end if

[0254] end for

[0255] In the above process, EXTRACTVALUE is a process that can extract a specified field from a text. Targeted processing can be used for texts in different formats, such as ssh logs or mysql logs. The processing method for texts in different formats can be determined based on the program that generates the alarm data of the plain text class. The alarm data determined by different programs carries different information, and the location of different information in the text is also different. Therefore, the logic of the alarm data can be determined based on different programs to determine the method of extracting the specified field. For example, alarms can be read from nginx log files, snort, and logs that come with the application. For each alarm text format, a corresponding method should be used to extract it.

[0256] The FIELDFILTER process in the above process processes structured alarm data, which may include more fields than those required for calculation. Therefore, the fields of interest can be filtered out from the structured alarm data.

[0257] In the embodiment of the present application, abnormal behavior occurring on the host is considered, which often indicates that the attacker has obtained some permissions in the host and attempts to obtain more permissions in the system where the host is located. Based on this, in the embodiment of the present application, the abnormality occurring in the host itself is also regarded as an attack by the host to the host itself. Through this involvement, the host alarm abnormality can be regarded as a kind of attack behavior, based on which an attack relationship network can be constructed, and ultimately the analysis of various types of warning data can be realized.

[0258] Based on the same application concept, an attack data processing device corresponding to the attack data processing method is further provided in the embodiments of the present application. Since the principle of problem-solving of the device in the embodiments of the present application is similar to that of the aforementioned attack data processing method embodiments, the implementation of the device in this embodiment can refer to the description in the embodiments of the above method, and the repeated parts will not be elaborated.

[0259] Please refer to Figure 8 , which is a schematic diagram of the functional modules of the attack data processing device provided in the embodiments of the present application. Each module in the attack data processing device in this embodiment is used to execute each step in the above method embodiments. The attack data processing device includes: a relevance determination module 310, a relationship determination module 320, and an attack determination module 330; the content of each module is as follows:

[0260] The relevance determination module 310 is used to determine the relevance between each piece of alarm data among the obtained multiple pieces of alarm data.

[0261] The relationship determination module 320 is used to determine an alarm relationship network according to the relevance between each piece of alarm data.

[0262] The attack determination module 330 is used to determine attack data according to the alarm relationship network.

[0263] In a possible implementation manner, the relevance determination module 310 is used to, for the first alarm data and the second alarm data among the multiple pieces of alarm data, determine the relevance between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data; wherein, the first alarm data and the second alarm data are any two pieces of alarm data among the multiple pieces of alarm data.

[0264] In a possible implementation manner, the relevance determination module 310 includes: a first judgment unit and a value determination unit:

[0265] The first judgment unit is used to, if the alarm category of the first alarm data is a host alarm, judge whether the alarm category of the second alarm data is the host alarm.

[0266] The first value determination unit is used to, if the alarm category of the second alarm data is the host alarm, determine that the relevance between the first alarm data and the second alarm data is a first value.

[0267] In a possible implementation manner, the relevance determination module 310 includes: a second judgment unit and a second value determination unit:

[0268] A second judgment unit, configured to determine whether the source of the first alarm data is the same host as the source of the second alarm data if the alarm category of the second alarm data is a network alarm;

[0269] A second value determination unit, configured to determine that the relevance between the first alarm data and the second alarm data is a first value if the source of the first alarm data is the same host as the source of the second alarm data.

[0270] In a possible implementation manner, the relevance determination module 310 includes: a third value determination unit, configured to determine the relevance between the first alarm data and the second alarm data according to a first field of the first alarm data and a second field of the second alarm data if the alarm categories of the first alarm data and the second alarm data are both network alarms. In a possible implementation manner, the first field includes a first IP field and a first port field, and the second field includes a second IP field and a second port field; the above-mentioned third value determination unit may be configured to determine an IP relationship value according to the first IP field and the second IP field; determine a port relationship value according to the first port field and the second port field; and determine the relevance between the first alarm data and the second alarm data according to the IP relationship value and the port relationship value.

[0271] In a possible implementation manner, the above-mentioned third value determination unit may also be configured to: determine that the port relationship value is a first value if the first port field and the second port field are the same port; determine whether the first port field and the second port field are two ports of the same service if the first port field and the second port field are not the same port, and if so, determine that the port relationship value is a third value; determine that the port relationship value is a second value if the first port field and the second port field are not the same port and the first port field and the second port field are not two ports of the same service.

[0272] In a possible implementation manner, the above-mentioned third value determination unit may also be configured to: determine the ratio of the common field of the first IP field and the second IP field to a specified value as the IP relationship value between the first IP field and the second IP field if both the first IP field and the second IP field are internal network IPs; determine that the IP relationship value is a second value if at least one of the first IP field and the second IP field is a public network IP.

[0273] In a possible implementation manner, the IP relationship value includes a first IP relationship value and a second IP relationship value; the first IP field includes a first source IP field and a first destination IP field, and the second IP field includes a second source IP field and a second destination IP field;

[0274] The above-mentioned third numerical value determination unit can also be used to determine a first IP relationship value according to the first source IP field and the second source IP field; and determine a second IP relationship value according to the first target IP field and the second target IP field.

[0275] In a possible implementation manner, the third numerical value determination unit can also be used to perform a weighted calculation on the first IP relationship value, the second IP relationship value, and the port relationship value to obtain the correlation degree between the first alarm data and the second alarm data; wherein, the weighted weights of the first IP relationship value, the second IP relationship value, and the port relationship value are preset weights.

[0276] In a possible implementation manner, the alarm relationship network includes multiple nodes and at least one relationship edge. Any one node corresponds to one piece of alarm data, and any one relationship edge is used to connect two nodes, and the correlation degree between the two pieces of alarm data corresponding to the two connected nodes satisfies a preset condition.

[0277] In a possible implementation manner, the attack determination module 330 is configured to extract multiple similar alarm sets from the alarm relationship network based on the relationship edges connected to each node in the alarm relationship network, so as to determine multiple single-step attacks according to the multiple similar alarm sets, where each similar alarm set includes multiple pieces of similar alarm data, and each single-step attack corresponds to one similar alarm set.

[0278] In a possible implementation manner, the attack data processing device provided in this embodiment may further include: a prompt module, configured to obtain the alarm prompt fields in each piece of similar alarm data in any single-step attack; and determine a target alarm prompt field for the single-step attack from the alarm prompt fields in each piece of similar alarm data, where the target alarm prompt field is used as a prompt message when the single-step attack occurs.

[0279] In a possible implementation manner, one or more intrusion sources and one or more intrusion targets are recorded in the similar alarm set corresponding to the single-step attack; the attack data processing device provided in this embodiment may further include a relationship network construction module, configured to determine an intrusion source set and an intrusion target set corresponding to each single-step attack according to the similar alarm sets corresponding to each single-step attack; determine an association degree value between each single-step attack according to the intrusion source set and the intrusion target set corresponding to each single-step attack; and construct an attack relationship network according to the association degree value between each single-step attack.

[0280] In a possible implementation manner, the multiple single-step attacks include a first single-step attack and a second single-step attack. The first single-step attack includes a first intrusion source set and a first intrusion target set, and the second single-step attack includes a second intrusion source set and a second intrusion target set;

[0281] The relationship network construction module is used to determine a first correlation value according to the first intrusion source set and the second intrusion source set; determine a second correlation value according to the first intrusion target set and the second intrusion target set; determine a third correlation value according to the first intrusion source set and the second intrusion target set; determine a fourth correlation value according to the first intrusion target set and the second intrusion source set; and determine the correlation degree value between the first single-step attack and the second single-step attack according to the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value.

[0282] In a possible implementation manner, the relationship network construction module may further be used to: select the maximum value among the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value as the correlation degree value between the first single-step attack and the second single-step attack; or perform weighted summation on the first correlation value, the second correlation value, the third correlation value, and the fourth correlation value to obtain the correlation degree value between the first single-step attack and the second single-step attack.

[0283] In a possible implementation manner, the relevance determination module 310 is used to extract the specified fields in each piece of alert data to determine the target alert data in the target format; and determine the relevance between each piece of alert data in the multiple pieces of target alert data according to the multiple pieces of target alert data.

[0284] In a possible implementation manner, the relevance determination module 310 is used to extract the alert type field, source IP field, source port field, target IP field, and target port field in the alert data; and construct the target alert data in the target format according to the alert type field, the source IP field, the source port field, the target IP field, and the target port field.

[0285] In addition, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the steps of the attack data processing method described in the above method embodiment.

[0286] The computer program product of the attack data processing method provided by the embodiment of the present application includes a computer-readable storage medium storing program code, and the instructions included in the program code can be used to execute the steps of the attack data processing method described in the above method embodiment. For details, please refer to the above method embodiment and will not be elaborated here.

[0287] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0288] In addition, the functional modules in each embodiment of the present application may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.

[0289] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs. It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or device. Without more limitations, the elements defined by the statement "including..." do not exclude the existence of additional identical elements in the process, method, article or device including the said elements.

[0290] The above are only the preferred embodiments of this application and are not used to limit this application. For those skilled in the art, this application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0291] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or replacements, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.

Claims

1. A method for processing attack data, characterized in that, Including: Determine the relevance between each piece of alarm data among the multiple pieces of alarm data obtained; Determine an alarm relationship network according to the relevance between each piece of alarm data; wherein, the alarm relationship network includes multiple nodes and at least one relationship edge, any one node corresponds to a piece of alarm data, and any one relationship edge is used to connect two nodes, and the relevance between the two pieces of alarm data corresponding to the two connected nodes meets a preset condition; Determine attack data according to the alarm relationship network, including: based on the relationship edges connected to each node in the alarm relationship network, extract multiple similar alarm sets from the alarm relationship network, so as to determine multiple single-step attacks according to the multiple similar alarm sets, wherein each similar alarm set includes multiple pieces of similar alarm data, and each single-step attack corresponds to a similar alarm set.

2. The method according to claim 1, characterized in that, The step of determining the relevance between each piece of alarm data among the multiple pieces of alarm data obtained includes: For the first alarm data and the second alarm data among the multiple pieces of alarm data, determine the relevance between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data; Wherein, the first alarm data and the second alarm data are any two pieces of alarm data among the multiple pieces of alarm data.

3. The method according to claim 2, wherein The step of determining the relevance between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data includes: If the alarm category of the first alarm data is a host alarm, determine whether the alarm category of the second alarm data is the host alarm; If the alarm category of the second alarm data is the host alarm, determine that the relevance between the first alarm data and the second alarm data is a first value.

4. The method according to claim 3, characterized in that, The step of determining the relevance between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data further includes: If the alarm category of the second alarm data is a network alarm, determine whether the source of occurrence of the first alarm data and the source of occurrence of the second alarm data are the same host; If the source of occurrence of the first alarm data and the source of occurrence of the second alarm data are the same host, determine that the relevance between the first alarm data and the second alarm data is a first value.

5. The method according to claim 2, wherein The step of determining the relevance between the first alarm data and the second alarm data according to the first alarm category of the first alarm data and the second alarm category of the second alarm data includes: If the alarm categories of the first alarm data and the second alarm data are both network alarms, determine the relevance between the first alarm data and the second alarm data according to the first field of the first alarm data and the second field of the second alarm data.

6. The method according to claim 5, wherein The first field includes a first IP field and a first port field, and the second field includes a second IP field and a second port field; Determining the relevance between the first alert data and the second alert data according to the first field of the first alert data and the second field of the second alert data includes: Determining an IP relationship value according to the first IP field and the second IP field; Determining a port relationship value according to the first port field and the second port field; Determining the relevance between the first alert data and the second alert data according to the IP relationship value and the port relationship value.

7. The method according to claim 6, wherein Determining the port relationship value according to the first port field and the second port field includes: If the first port field and the second port field are the same port, determining that the port relationship value is a first value; If the first port field and the second port field are not the same port, determining whether the first port field and the second port field are two ports of the same service. If so, determining that the port relationship value is a third value; If the first port field and the second port field are not the same port, and the first port field and the second port field are not two ports of the same service, if so, determining that the port relationship value is a second value.

8. The method according to claim 6, wherein Determining the IP relationship value according to the first IP field and the second IP field includes: If both the first IP field and the second IP field are internal network IPs, determining the ratio of the common field of the first IP field and the second IP field to a specified value as the IP relationship value between the first IP field and the second IP field; If at least one of the first IP field and the second IP field is a public network IP, determining that the IP relationship value is a second value.

9. The method according to claim 8, wherein The IP relationship value includes a first IP relationship value and a second IP relationship value; the first IP field includes a first source IP field and a first destination IP field, and the second IP field includes a second source IP field and a second destination IP field; Determining the IP relationship value according to the first IP field and the second IP field includes: Determining a first IP relationship value according to the first source IP field and the second source IP field; Determining a second IP relationship value according to the first destination IP field and the second destination IP field.

10. The method according to claim 9, wherein Determining the relevance between the first alert data and the second alert data according to the IP relationship value and the port relationship value includes: Performing a weighted calculation on the first IP relationship value, the second IP relationship value, and the port relationship value to obtain the relevance between the first alert data and the second alert data; Wherein, the weighting weights of the first IP relationship value, the second IP relationship value, and the port relationship value are preset weights.

11. The method according to claim 1, characterized in that, The method further includes: Obtaining the alert prompt fields in each piece of similar alert data in any single-step attack; Determining a target alert prompt field for the single-step attack from the alert prompt fields in each piece of similar alert data, and the target alert prompt field is used as a prompt message when the single-step attack occurs.

12. The method according to claim 1, characterized in that, The similar alarm set corresponding to the single-step attack records one or more intrusion sources and one or more intrusion targets; the method further includes: Determining an intrusion source set and an intrusion target set corresponding to each single-step attack according to the similar alarm sets corresponding to the single-step attacks; Determining an association degree value between each single-step attack according to the intrusion source set and the intrusion target set corresponding to each single-step attack; Constructing an attack relationship network according to the association degree values between each single-step attack.

13. The method according to claim 12, wherein The multiple single-step attacks include a first single-step attack and a second single-step attack. The first single-step attack includes a first intrusion source set and a first intrusion target set, and the second single-step attack includes a second intrusion source set and a second intrusion target set; The determining an association degree value between each single-step attack according to the intrusion source set and the intrusion target set corresponding to each single-step attack includes: Determining a first association value according to the first intrusion source set and the second intrusion source set; Determining a second association value according to the first intrusion target set and the second intrusion target set; Determining a third association value according to the first intrusion source set and the second intrusion target set; Determining a fourth association value according to the first intrusion target set and the second intrusion source set; Determining an association degree value between the first single-step attack and the second single-step attack according to the first association value, the second association value, the third association value, and the fourth association value.

14. The method according to claim 13, wherein The determining an association degree value between the first single-step attack and the second single-step attack according to the first association value, the second association value, the third association value, and the fourth association value includes: Selecting the maximum value among the first association value, the second association value, the third association value, and the fourth association value as the association degree value between the first single-step attack and the second single-step attack; or Performing weighted summation on the first association value, the second association value, the third association value, and the fourth association value to obtain the association degree value between the first single-step attack and the second single-step attack.

15. The method according to claim 1, characterized in that The determining a correlation degree between each of the multiple pieces of alarm data according to the obtained multiple pieces of alarm data includes: For each piece of alarm data, extracting a specified field in the alarm data to determine target alarm data in a target format; Determining a correlation degree between each of the multiple pieces of target alarm data according to the multiple pieces of target alarm data.

16. The method according to claim 15, characterized in that, The extracting a specified field in the alarm data to determine target alarm data in a target format includes: Extracting an alarm type field, a source IP field, a source port field, a target IP field, and a target port field in the alarm data; Constructing target alarm data in a target format according to the alarm type field, the source IP field, the source port field, the target IP field, and the target port field.

17. An attack data processing device, characterized in that, Including: A correlation degree determination module, configured to determine a correlation degree between each of the multiple pieces of alarm data according to the obtained multiple pieces of alarm data; A relationship determination module determines an alarm relationship network according to the relevance among the respective alarm data; wherein, the alarm relationship network includes a plurality of nodes and at least one relationship edge, any one node corresponds to one alarm data, any one relationship edge is used to connect two nodes, and the relevance of the two alarm data corresponding to the two connected nodes meets a preset condition; An attack determination module is configured to determine attack data according to the alarm relationship network; The attack determination module is further configured to extract a plurality of similar alarm sets from the alarm relationship network based on the relationship edges connected to the respective nodes in the alarm relationship network, so as to determine a plurality of single-step attacks according to the plurality of similar alarm sets, wherein each similar alarm set includes a plurality of similar alarm data, and each single-step attack corresponds to a similar alarm set.

18. An electronic device, characterized in that, Comprising: A processor and a memory, where the memory stores machine-readable instructions executable by the processor, and when the electronic device runs, the machine-readable instructions are executed by the processor to perform the steps of the attack data processing method according to any one of claims 1 to 16.

19. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by a processor, it performs the steps of the attack data processing method according to any one of claims 1 to 16.

Citation Information

Patent Citations

  • Network attack prediction model construction method based on uncertainty perception attack graph

    CN110012037A