Attack path visualization restoration method, device, equipment and medium
By collecting and saving security events in the SOC system and using search conditions to generate animations to show the correlation of security events, the problem of the inability to display and interactively analyze in existing technologies is solved, and more flexible and accurate attack path visualization is achieved.
Patent Information
- Application Number
- CN202211025738.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-25
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-08-25
AI Technical Summary
Existing SOC systems cannot effectively display the correlation between security events when displaying attack paths, and cannot perform interactive analysis.
By collecting original security events and saving them to a preset database, tracing the source using search conditions, generating reference attack path animations, and setting up a user search interface to generate target attack path animations, the correlation display and interactive analysis between security events can be achieved.
It realizes the display of correlation between security events in a visual interface and allows users to interact with the interface, improving the flexibility and accuracy of attack path analysis.
Smart Images

Figure CN115396199B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of intranet information security technology, and in particular to an attack path visualization restoration method, device, equipment and medium. Background Art
[0002] Cyber attacks are becoming increasingly complex. To address these issues, various detection tools are installed on intranet information systems to detect attack behaviors, such as firewalls and intrusion detection tools deployed at key points, and antivirus systems deployed on hosts. In order to conduct a comprehensive analysis of various detection results, a security operations center (SOC) is also deployed. It can assist managers in event analysis, risk analysis, early warning management, and emergency response, providing security managers with decision-making support for risk assessment and emergency response.
[0003] Currently, SOC mainly has two display methods. One method analyzes and displays the security events reported by each security device, thus ignoring the analysis of the correlation between different security events. The other method restores the attack path of the security audit event based on the occurrence time, source address, and destination address of the security event, and then displays it statically in the form of a link image. However, because the link image cannot be interactive, it is impossible to further analyze the information on the link image, and the analysis method is inflexible.
[0004] In summary, how to display the correlation between security events in the attack path visualization interface and enable interaction with the visualization interface are problems to be solved in this field. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a method, apparatus, device, and medium for visualizing and restoring attack paths, which can display the correlation between security events in a visual interface of the attack path and enable interaction with the visual interface. The specific scheme is as follows:
[0006] In a first aspect, the present application discloses a method for visually restoring an attack path, comprising:
[0007] Collecting original security events returned by the target security device and saving the original security events into a preset database;
[0008] Obtain target search conditions through a preset search condition interface, and trace back from the preset database based on the target search conditions to obtain a target security event list;
[0009] A reference attack path animation is obtained using the occurrence time information, source address and destination address in the target security event list, and a user search interface is set to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0010] Optionally, tracing the target security event list from the preset database based on the target search condition includes:
[0011] Determine whether the current tracing level is greater than the target tracing level in the target search condition; if not, based on the target search condition, use the current tracing address to perform tracing to obtain a current security event list including the current security event, and then extract the source address and destination address corresponding to the current security event, so as to obtain the next tracing address based on the source address and destination address corresponding to the current security event and obtain the next tracing level based on the current tracing level;
[0012] Determine whether the next tracing level is greater than the target tracing level; if not, use the next tracing level and the next tracing address as the current tracing level and the current tracing address, respectively; then jump back to the step of tracing based on the target search condition and using the current tracing address to obtain a current security event list containing the current security event, until the next tracing level is greater than the target tracing level, and determine the current security event list as the target security event list;
[0013] Accordingly, before determining whether the current tracing level is greater than the target tracing level in the target search condition, the process further includes:
[0014] A target search condition including an initial tracing address and a target tracing level is obtained through a preset search condition interface, and the initial tracing level is set so that the initial tracing address and the initial tracing level are used as the current tracing address and the current tracing level respectively.
[0015] Optionally, the step of tracing the source using the current tracing address to obtain a current security event list including the current security event, and then extracting the source address and destination address corresponding to the current security event, includes:
[0016] Using the current tracing address to perform tracing to obtain the current security event, and obtaining identification information of the current security event, and then determining whether the current security event has been saved in the previous security event list based on the identification information;
[0017] If it has been saved, the previous security event list will be used as the current security event list, and the source address and destination address corresponding to the current security event will be extracted; if it has not been saved, the current security event will be saved to the previous security event list to obtain the current security event list, and the source address and destination address corresponding to the current security event will be extracted.
[0018] Optionally, obtaining a reference attack path animation by using the occurrence time information, source address, and destination address in the target security event list includes:
[0019] Extracting the occurrence time information, source address, and destination address from the target security event list, and determining whether any one or more of the asset type information, asset name, and responsible person information corresponding to the source address and the destination address has been saved in the asset ledger table of the preset security operation platform;
[0020] If it has been saved, any one or more of the asset type information, asset name and responsible person information corresponding to the source address and the destination address is obtained, and a reference attack path animation is obtained based on the occurrence time information, the source address, the destination address and the asset information; if it has not been saved, a reference attack path animation is obtained based on the occurrence time information, the source address and the destination address.
[0021] Optionally, after tracing the target security event list from the preset database based on the target search condition, the method further includes:
[0022] Counting the number of security events in the target security event list and the number of nodes associated with the security events, and creating an event overview scatter animation based on the number of events and the number of nodes;
[0023] The security events in the target security event list are obtained based on a preset time sequence, and any one or more of the event information including the number of occurrences, attack stages, attack directions, source addresses, destination addresses, occurrence time information, event names, and the address of the device that reported the security events are determined, and an event information bar animation is created based on the event information.
[0024] Optionally, obtaining the security events in the target security event list based on a preset time sequence and determining any one or more event information of the number of occurrences, attack stage, attack direction, source address, destination address, occurrence time information, event name, and address of a device that reports the security event includes:
[0025] Obtaining the current security event in the target security event list based on a preset time sequence, and determining any one or more event information of the number of occurrences, occurrence time information, source address, destination address, event name, and address of a device reporting the security event of the current security event, and then querying the preset event model table for an attack stage corresponding to the event name of the current security event;
[0026] Based on the preset intranet identification information segment management table, it is determined whether the source address and destination address of the current security event are intranet addresses, and based on the determination result, the attack direction corresponding to the source address to the destination address of the current security event is calculated.
[0027] Optionally, obtaining the current security event in the target security event list based on a preset time sequence and determining any one or more event information of the number of occurrences, occurrence time information, source address, destination address, event name, and address of a device that reports the security event of the current security event includes:
[0028] Obtaining the current security event in the target security event list based on a preset time sequence, determining the occurrence time information, source address, destination address, and event name of the current security event, and determining whether the current security event is the first security event in the target security event list based on the occurrence time of the current security event;
[0029] If so, it is determined that the number of occurrences of the current security event is 1.
[0030] Optionally, after determining whether the current security event is the first security event in the target security event list based on the occurrence time of the current security event, the method further includes:
[0031] If not, determine whether the source address, destination address, and event name of the current security event are consistent with the source address, destination address, and event name of the previous security event;
[0032] If they are consistent, the number of occurrences of the previous security event is updated to obtain the number of occurrences of the current security event; if they are inconsistent, the number of occurrences of the current security event is determined to be 1.
[0033] In a second aspect, the present application discloses a device for visually restoring an attack path, comprising:
[0034] An event collection module is used to collect original security events returned by target security devices;
[0035] An event saving module, used to save the original security event into a preset database;
[0036] An event list acquisition module is used to obtain a target search condition through a preset search condition interface, and to trace the target security event list from the preset database based on the target search condition;
[0037] The animation generation module is used to use the occurrence time information, source address and destination address in the target security event list to obtain a reference attack path animation, and set a user search interface to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0038] In a third aspect, the present application discloses an electronic device, comprising:
[0039] Memory, used to store computer programs;
[0040] A processor is used to execute the computer program to implement the steps of the aforementioned disclosed attack path visualization restoration method.
[0041] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed attack path visualization restoration method are implemented.
[0042] It can be seen that the present application first collects the original security events returned by the target security device and saves the original security events into a preset database; obtains the target search conditions through the preset search condition interface, and traces the source from the preset database based on the target search conditions to obtain a target security event list; obtains a reference attack path animation using the occurrence time information, source address and destination address in the target security event list, and sets a user search interface so as to generate a target attack path animation based on the user search conditions and the reference attack path animation obtained through the user search interface. It can be seen that the present application first saves the original security events returned by the target security device into a preset database, and because it traces the source from the preset database based on the target search conditions, it is possible to obtain a target security event list that reflects the correlation between security events; obtains a reference attack path animation that can be dynamically displayed based on the occurrence time information, source address and destination address in the target security event list; obtains the user search conditions through the set user search interface, and further analyzes the reference attack path animation based on the target user search conditions to obtain the target attack path animation, thereby achieving the purpose of the target user being able to interact with the visual interface. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0044] Figure 1 This is a flow chart of a method for visualizing and restoring an attack path disclosed in this application;
[0045] Figure 2 This is a flowchart of a specific attack path visualization restoration method disclosed in this application;
[0046] Figure 3 This is a flowchart of a specific reference attack path animation acquisition method disclosed in this application;
[0047] Figure 4 This is a flowchart of a specific attack path visualization restoration method disclosed in this application;
[0048] Figure 5 This is a flowchart of a specific attack path visualization restoration method disclosed in this application;
[0049] Figure 6 This is a schematic diagram of the structure of an attack path visualization restoration device disclosed in this application;
[0050] Figure 7 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0051] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0052] Currently, SOC mainly has two display methods. One method analyzes and displays the security events reported by each security device, thus ignoring the analysis of the correlation between different security events. The other method restores the attack path of the security audit event based on the occurrence time, source address, and destination address of the security event, and then displays it statically in the form of a link image. However, because the link image cannot be interactive, it is impossible to further analyze the information on the link image, and the analysis method is inflexible.
[0053] To this end, this application provides a corresponding attack path visualization restoration solution, which can display the correlation between security events in the attack path visualization interface and can interact with the visualization interface.
[0054] See also Figure 1 As shown, the embodiment of the present application discloses a method for visually restoring an attack path, including:
[0055] Step S11: collecting original security events returned by the target security device, and saving the original security events into a preset database.
[0056] In this embodiment, a security operations platform is used for network security operations and supervision. The security operations platform can help target users achieve overall security situation control, prevent security risks, handle security incidents, and adjust security policies. It can also assist target users in tracing the source of security threats and provide decision support. The collection subsystem collects all original security event logs collected by target security devices and stores them as original security events in a pre-set distributed document database ES (Elasticsearch).
[0057] Step S12: obtaining target search conditions through a preset search condition interface, and tracing the target security event list from the preset database based on the target search conditions.
[0058] In this embodiment, tracing the source from the preset database based on the target search condition to obtain a target security event list specifically includes: judging whether the current tracing level is greater than the target tracing level in the target search condition; if not, tracing the source based on the target search condition and using the current tracing address to obtain a current security event list including the current security event; then extracting the source address and destination address corresponding to the current security event, so as to obtain the next tracing address based on the source address and destination address corresponding to the current security event and the next tracing level based on the current tracing level; judging whether the next tracing level is greater than the target tracing level; if not, using the next tracing level and the next tracing address as the current tracing level and the current tracing address respectively, and then jumping back to the step of tracing the source based on the target search condition and using the current tracing address to obtain a current security event list including the current security event, until the next tracing level is greater than the target tracing level, and determining the current security event list as the target security event list. Accordingly, before determining whether the current traceability level is greater than the target traceability level in the target search condition, the method further includes: obtaining a target search condition including an initial traceability address and a target traceability level through a preset search condition interface, and setting an initial traceability level so that the initial traceability address and the initial traceability level are used as the current traceability address and the current traceability level, respectively. For example, if the target traceability level in the target search condition is level 3 and the current traceability level is level 2, then it is determined that the current traceability level is not greater than the target traceability level, and based on the target search condition, the current traceability address is used for tracing to obtain a current security event list containing the current security event, wherein the target search condition can be the target traceability level and the time range; if the current traceability level is level 3, then it is determined that the current traceability level is not greater than the target traceability level, and then based on the target search condition, the current traceability address is used for tracing to obtain a current security event list containing the current security event, and it is understandable that the next traceability level is level 4, so the current security event list is determined as the target security event list. It should be noted that after the target security event list is determined, a new initial tracing level and a new initial tracing address can be set, and tracing can be performed again with the new initial tracing address and the new initial tracing level to obtain a new target security event list.
[0059] In this embodiment, the method of tracing the source using the current tracing address to obtain a current security event list containing the current security event, and then extracting the source address and destination address corresponding to the current security event, specifically includes: tracing the source using the current tracing address to obtain the current security event, and obtaining the identification information of the current security event, and then judging whether the current security event has been saved in the previous security event list based on the identification information; if it has been saved, using the previous security event list as the current security event list, and extracting the source address and destination address corresponding to the current security event; if it has not been saved, saving the current security event to the previous security event list to obtain the current security event list, and extracting the source address and destination address corresponding to the current security event. Judging whether the current security event has been saved in the previous security event list based on the identification information, and if it has been saved, using the previous security event list as the current security event list, and extracting the source address and destination address corresponding to the current security event, it can be understood that the same security event is not saved repeatedly to save the storage space occupied by the security event list.
[0060] Step S13: Utilize the occurrence time information, source address and destination address in the target security event list to obtain a reference attack path animation, and set a user search interface to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0061] In this embodiment, it can be understood that the reference attack path animation obtained may include the occurrence time information, source address and destination address information in the target security event list, and may also include the attack path and attack path node drawn through the occurrence time information, source address and destination address in the target security event list; when setting the user search interface, the user search interface can be set in the attack path node, attack path, or in the time display bar corresponding to the occurrence time information. When the user search interface is set in the attack path node, the filtering conditions set by the target user can be obtained through the user search interface, and then the attack path nodes that are not related to the filtering conditions can be shielded, or the attack paths that are not related to the filtering conditions can be shielded; when the user search interface is set in the time display bar corresponding to the occurrence time information, the time range set by the target user can be obtained through the user search interface, and a target attack path animation corresponding to the time range set by the target user can be generated. It should be noted that when the target user is detected clicking on the attack path node and the attack path line with the left button of the mouse, the target security event list related to the attack path node and the attack path can be automatically filtered out. When the target user is detected clicking on the attack path node with the right button of the mouse, the prompt information interface of "Start analysis with the attack path node as the initial IP" can be displayed, and when the start analysis command is obtained through the prompt information interface, the analysis will begin.
[0062] It can be seen that the present application first collects the original security events returned by the target security device and saves the original security events into a preset database; obtains the target search conditions through the preset search condition interface, and traces the source from the preset database based on the target search conditions to obtain a target security event list; obtains a reference attack path animation using the occurrence time information, source address and destination address in the target security event list, and sets a user search interface so as to generate a target attack path animation based on the user search conditions and the reference attack path animation obtained through the user search interface. It can be seen that the present application first saves the original security events returned by the target security device into a preset database, and because it traces the source from the preset database based on the target search conditions, it is possible to obtain a target security event list that reflects the correlation between security events; obtains a reference attack path animation that can be dynamically displayed based on the occurrence time information, source address and destination address in the target security event list; obtains the user search conditions through the set user search interface, and further analyzes the reference attack path animation based on the target user search conditions to obtain the target attack path animation, thereby achieving the purpose of the target user being able to interact with the visual interface.
[0063] See also Figure 2 As shown, the embodiment of the present application discloses a specific attack path visualization restoration method, including:
[0064] Step S21: collecting original security events returned by the target security device, and saving the original security events into a preset database.
[0065] In this embodiment, original security events returned by a target security device are collected, where the target security device may be any one or more of a firewall, an intrusion detection system (IDS), an APT (Advanced Packaging Tool) detection, and an antivirus system.
[0066] Step S22: Obtain target search conditions through a preset search condition interface, and perform source tracing from the preset database based on the target search conditions to obtain a target security event list.
[0067] In this embodiment, for example, when the security event with event identification information (eventID) of 10 in the preset database is taken as the initial security event and traced, the initial security event is taken as the current security event, and its corresponding source address 10.131.110.10 is used as the current traceability address. The target traceability level is level 3, and the default time range can be within 24 hours from the current time. Then, tracing is started to obtain the target security event list.
[0068] Step S23: Utilize the occurrence time information, source address, and destination address in the target security event list to obtain a reference attack path animation, and set a user search interface to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0069] In this embodiment, the reference attack path animation is obtained by utilizing the occurrence time information, source address and destination address in the target security event list, specifically including: extracting the occurrence time information, source address and destination address from the target security event list, and judging whether the asset type information, asset name and responsible person information corresponding to the source address and the destination address have been saved in the asset ledger table of the preset security operation platform; if saved, obtaining the asset type information, asset name and responsible person information corresponding to the source address and the destination address, and obtaining the reference attack path animation based on the occurrence time information, the source address, the destination address and the asset information; if not saved, obtaining the reference attack path animation based on the occurrence time information, the source address and the destination address. It can be understood that, if Figure 3A specific reference attack path animation acquisition method flowchart is shown. If it is determined that the asset ledger table of the preset security operation platform has saved any one or more of the asset type information, asset name and responsible person information corresponding to the source address and destination address, then the occurrence time information, source address, destination address and asset information are displayed below the attack path node in the reference attack path animation. The corresponding time axis can also be displayed based on the occurrence time information. If it is determined that the asset ledger table of the preset security operation platform has not saved any one or more of the asset type information, asset name and responsible person information corresponding to the source address and destination address, then the occurrence time information, source address and destination address are displayed in the reference attack path animation. When the asset type information is terminal, the responsible person information is displayed, and if the asset type information is non-terminal, the asset name is displayed.
[0070] In this embodiment, when the target user is detected dragging the timeline corresponding to the occurrence time information in the reference attack path animation or the target attack path animation to any time node, the reference attack path animation or the target attack path animation displays the corresponding number of events and the number of nodes associated with the security event as the time node changes, and displays the status of the corresponding attack path as the time node changes. For example, the reference attack path animation or the target attack path animation displays the corresponding number of events in the form of a bar graph as the time node changes, and the higher the number, the higher the bar. It can be understood that when the timeline is dragged to the target time node, the target attack path animation starts playing from the target time node. For example, if the target time node is 10:20 on October 9, 2021, the target attack path animation starts playing from 10:20 on October 9, 2021.
[0071] Step S24: Counting the number of security events in the target security event list and the number of nodes associated with the security events, and creating an event overview scatter animation based on the number of events and the number of nodes.
[0072] In this embodiment, when it is monitored that a user clicks on a scatter point in the event overview scatter point animation, the event represented by the scatter point will be filtered out. For example, when the scatter point of "Scan Detection" is clicked, the attack path corresponding to "Scan Detection" in the reference attack path animation or the target attack path animation will be displayed in a highlighted form. It can be understood that the event overview scatter point animation corresponds to the reference attack path animation or the target attack path animation. For example, when the reference attack path animation or the target attack path animation is played as the animation interface at the time node of 10:20 on October 9, 2021, the event overview scatter point animation will also play the animation interface at the time node of 10:20 on October 9, 2021.
[0073] It can be seen that this application collects original security events and traces their sources to construct a target security event list that can reflect the logical relationship between different security events, and uses the target security event list to create a reference attack path animation to dynamically display the logical relationship and occurrence time between different original security events, which is more intuitive and convenient. It also uses the number of security events in the target security event list and the number of nodes associated with the security events to create an event overview scatter animation, which more clearly reflects the number of events corresponding to the current time node and the number of nodes associated with the security events.
[0074] See also Figure 4 As shown, the embodiment of the present application discloses a specific attack path visualization restoration method, including:
[0075] Step S31: collecting original security events returned by the target security device, and saving the original security events into a preset database.
[0076] Step S32: obtaining target search conditions through a preset search condition interface, and tracing the target security event list from the preset database based on the target search conditions.
[0077] Step S33: Utilize the occurrence time information, source address, and destination address in the target security event list to obtain a reference attack path animation, and set a user search interface to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0078] In this embodiment, it should be noted that when the user search conditions are not obtained through the user search interface, the reference attack path animation is displayed in the preset attack path animation display position of the interface; when the user search conditions are obtained through the user search interface, the target attack path animation is generated based on the user search conditions and the reference attack path animation. It can be understood that the user search conditions can be set in the target attack path animation so that when it is monitored that the user enters the user search conditions through the user search interface, a new target attack path animation is generated again based on the user search conditions and the target attack path animation.
[0079] Step S34: Obtain the security events in the target security event list based on a preset time sequence, and determine any one or more of the event information including the number of occurrences, attack stages, attack directions, source addresses, destination addresses, occurrence time information, event names, and the device address for reporting the security events, and create an event information bar animation based on the event information.
[0080] In this embodiment, the security events in the target security event list are obtained based on a preset time sequence, and any one or more event information including the number of occurrences, attack stage, attack direction, source address, destination address, occurrence time information, event name, and the device address for reporting the security event is determined. Specifically, it includes: obtaining the current security event in the target security event list based on a preset time sequence, and determining any one or more event information including the number of occurrences, occurrence time information, source address, destination address, event name, and the device address for reporting the security event, and then querying the attack stage corresponding to the event name of the current security event from the preset event model table; judging whether the source address and destination address of the current security event are intranet addresses based on the preset intranet identification information segment management table, and calculating the attack direction corresponding to the source address to the destination address of the current security event based on the judgment result. Among them, the attack stage is, for example, information collection, target reconnaissance, and vulnerability exploitation. The attack direction is the attack direction from the source address to the destination address. For example, when the source address and the destination address are both intranet addresses, the attack direction is inside->inside. If the source address is an intranet address and the destination address is not an intranet address, the attack direction is inside->outside. If the source address is not an intranet address and the destination address is an intranet address, the attack direction is outside->inside. It can be understood that after calculating the attack direction, the attack direction information can be displayed by referring to the attack path animation or the target attack path animation, for example, with a preset arrow pattern pointing from the source address to the destination address.
[0081] In this embodiment, the current security event in the target security event list is obtained based on a preset time sequence, and any one or more event information of the number of occurrences, occurrence time information, source address, destination address, event name and the address of the device that reports the security event is determined. Specifically, it includes: obtaining the current security event in the target security event list based on a preset time sequence, determining the occurrence time information, source address, destination address and event name of the current security event, and judging whether the current security event is the first security event in the target security event list based on the occurrence time of the current security event; if so, judging that the number of occurrences of the current security event is 1.
[0082] In this embodiment, after determining whether the current security event is the first security event in the target security event list based on the occurrence time of the current security event, it also includes: if not, determining whether the source address, destination address and event name of the current security event are consistent with the source address, destination address and event name of the previous security event; if they are consistent, updating the number of occurrences of the previous security event to obtain the number of occurrences of the current security event; if they are inconsistent, determining that the number of occurrences of the current security event is 1.
[0083] It is understandable that the event information bar animation corresponds to the reference attack path animation or the target attack path animation. For example, when the reference attack path animation or the target attack path animation is played, the event information bar animation is also played accordingly. For example, when the reference attack path animation or the target attack path animation is played to the time node of 10:20 on October 9, 2021, the event information bar animation is also played to the time node of 10:20 on October 9, 2021. It should be noted that the preset pause interface and the preset continue interface can be displayed during the playback process. When the pause command is obtained through the preset pause interface, the current interface is stopped for playback. When the preset continue interface obtains the continue playback command, the relevant animation of the current interface continues to play. After the event information bar animation is finished playing, the event information bar animation can display security event information in reverse chronological order.
[0084] It can be seen that this application creates reference attack path animation, target attack path animation and event information bar animation based on the target security event list. Therefore, it can play the attack path animation of the security event on the interface, and can also play event information corresponding to the security event, so that users can intuitively understand the information related to the security event.
[0085] Below Figure 5 The technical solution of this application is described using the flowchart of a specific attack path visualization restoration method as an example. The original security events returned by the target security device are collected and saved in a preset database. The target search conditions are obtained through a preset search condition interface, and based on the target search conditions, the target security events are traced from the preset database to obtain a list of target security events.
[0086] The occurrence time information, source address and destination address in the target security event list are used to obtain a reference attack path animation, and a user search interface is set to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0087] Count the number of security events in the target security event list and the number of nodes associated with the security events, and create an event overview scatter animation based on the number of events and nodes.
[0088] Obtain security events in the target security event list based on a preset time sequence, and determine any one or more of the event information including the number of occurrences, attack stages, attack directions, source addresses, destination addresses, occurrence time information, event names, and device addresses that reported security events, and create event information bar animations based on the event information.
[0089] It should be noted that the reference attack path animation or target attack path animation, the event overview scatter point animation and the event information bar animation are played in a corresponding relationship. For example, when the reference attack path animation or the target attack path animation is played to the time node 10:20 on October 9, 2021, the event overview scatter point animation and the event information bar animation can also be played to the time node 10:20 on October 9, 2021. When the reference attack path animation or the target attack path animation is finished, the event overview scatter point animation and the event information bar animation are also finished, and the event overview scatter point animation can display the scatter points corresponding to the event name of each security event. When it is detected that the user clicks on a scatter point in the event overview scatter point animation, the attack path corresponding to the scatter point will be highlighted in the reference attack path animation or the target attack path animation, and the event information bar animation displays relevant information of the security event corresponding to the scatter point.
[0090] See also Figure 6 As shown, the embodiment of the present application discloses an attack path visualization restoration device, comprising:
[0091] An event collection module 11 is used to collect original security events returned by target security devices;
[0092] An event saving module 12 is used to save the original security event into a preset database;
[0093] An event list acquisition module 13 is configured to acquire a target search condition through a preset search condition interface, and perform source tracing from the preset database based on the target search condition to obtain a target security event list;
[0094] The animation generation module 14 is used to obtain a reference attack path animation using the occurrence time information, source address and destination address in the target security event list, and set a user search interface to generate a target attack path animation based on the user search conditions obtained through the user search interface and the reference attack path animation.
[0095] It can be seen that the present application first collects the original security events returned by the target security device and saves the original security events into a preset database; obtains the target search conditions through the preset search condition interface, and traces the source from the preset database based on the target search conditions to obtain a target security event list; obtains a reference attack path animation using the occurrence time information, source address and destination address in the target security event list, and sets a user search interface so as to generate a target attack path animation based on the user search conditions and the reference attack path animation obtained through the user search interface. It can be seen that the present application first saves the original security events returned by the target security device into a preset database, and because it traces the source from the preset database based on the target search conditions, it is possible to obtain a target security event list that reflects the correlation between security events; obtains a reference attack path animation that can be dynamically displayed based on the occurrence time information, source address and destination address in the target security event list; obtains the user search conditions through the set user search interface, and further analyzes the reference attack path animation based on the target user search conditions to obtain the target attack path animation, thereby achieving the purpose of the target user being able to interact with the visual interface.
[0096] Figure 7 FIG. 2 is a block diagram of an electronic device 200 according to an exemplary embodiment. Figure 7 As shown, the electronic device 200 may include: a processor 201 , a memory 202 . The electronic device 200 may also include one or more of a multimedia component 203 , an input / output (I / O) interface 704 , and a communication component 705 .
[0097] The processor 201 is used to control the overall operation of the electronic device 200 to complete all or part of the steps in the above-mentioned attack path visualization and restoration method. The memory 202 is used to store various types of data to support the operation of the electronic device 200. This data may include, for example, instructions for any application or method operating on the electronic device 200, as well as application-related data, such as contact information, sent and received messages, pictures, audio, video, etc. The memory 202 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The multimedia component 203 may include a screen and an audio component. The screen may be, for example, a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signal may be further stored in the memory 202 or sent through the communication component 205. The audio component also includes at least one speaker for outputting audio signals. The I / O interface 204 provides an interface between the processor 201 and other interface modules. The above-mentioned other interface modules may be a keyboard, a mouse, buttons, etc. These buttons may be virtual buttons or physical buttons. The communication component 205 is used for wired or wireless communication between the electronic device 200 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G or 4G, or a combination of one or more of them, so the corresponding communication component 205 may include: a Wi-Fi module, a Bluetooth module, an NFC module.
[0098] In an exemplary embodiment, the electronic device 200 can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to execute the above-mentioned attack path visualization restoration method.
[0099] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided. When executed by a processor, the program instructions implement the steps of the above-mentioned attack path visualization restoration method. For example, the computer-readable storage medium may be the aforementioned memory 202 including the program instructions. The program instructions may be executed by the processor 201 of the electronic device 200 to perform the above-mentioned attack path visualization restoration method.
[0100] In addition, the various embodiments of the present disclosure may be arbitrarily combined, and as long as they do not violate the concept of the present disclosure, they should also be regarded as the contents disclosed by the present disclosure.
[0101] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0102] The above is a detailed introduction to the attack path visualization and restoration method, device, equipment and medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method and core ideas of the present invention. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A method for visualizing and restoring an attack path, characterized in that: include: Collecting original security events returned by the target security device and saving the original security events into a preset database; Obtain target search conditions through a preset search condition interface, and trace back from the preset database based on the target search conditions to obtain a target security event list; Obtaining a reference attack path animation using the occurrence time information, source address, and destination address in the target security event list, and providing a user search interface to generate a target attack path animation based on user search conditions obtained through the user search interface and the reference attack path animation; The tracing back from the preset database based on the target search condition to obtain a target security event list includes: Determine whether the current tracing level is greater than the target tracing level in the target search condition; if not, based on the target search condition, use the current tracing address to perform tracing to obtain a current security event list including the current security event, and then extract the source address and destination address corresponding to the current security event, so as to obtain the next tracing address based on the source address and destination address corresponding to the current security event and obtain the next tracing level based on the current tracing level; Determine whether the next tracing level is greater than the target tracing level. If not, use the next tracing level and the next tracing address as the current tracing level and the current tracing address respectively, and then jump back to the step of tracing based on the target search condition and using the current tracing address to obtain a current security event list containing the current security event, until the next tracing level is greater than the target tracing level, and the current security event list is determined as the target security event list.
2. The attack path visualization restoration method according to claim 1, characterized in that: Before determining whether the current tracing level is greater than the target tracing level in the target search condition, the method further includes: A target search condition including an initial tracing address and a target tracing level is obtained through a preset search condition interface, and the initial tracing level is set so that the initial tracing address and the initial tracing level are used as the current tracing address and the current tracing level respectively.
3. The attack path visualization restoration method according to claim 2, characterized in that: The method of tracing the source using the current tracing address to obtain a current security event list including the current security event, and then extracting the source address and destination address corresponding to the current security event, includes: Using the current tracing address to perform tracing to obtain the current security event, and obtaining identification information of the current security event, and then determining whether the current security event has been saved in the previous security event list based on the identification information; If it has been saved, the previous security event list will be used as the current security event list, and the source address and destination address corresponding to the current security event will be extracted; if it has not been saved, the current security event will be saved to the previous security event list to obtain the current security event list, and the source address and destination address corresponding to the current security event will be extracted.
4. The attack path visualization restoration method according to claim 1, characterized in that: The step of obtaining a reference attack path animation by utilizing the occurrence time information, source address, and destination address in the target security event list includes: Extracting the occurrence time information, source address, and destination address from the target security event list, and determining whether any one or more of the asset type information, asset name, and responsible person information corresponding to the source address and the destination address has been saved in the asset ledger table of the preset security operation platform; If it has been saved, any one or more of the asset type information, asset name and responsible person information corresponding to the source address and the destination address is obtained, and a reference attack path animation is obtained based on the occurrence time information, the source address, the destination address and the asset information; if it has not been saved, a reference attack path animation is obtained based on the occurrence time information, the source address and the destination address.
5. The attack path visualization restoration method according to any one of claims 1 to 4, characterized in that: After tracing the source from the preset database based on the target search condition to obtain a target security event list, the method further includes: Counting the number of security events in the target security event list and the number of nodes associated with the security events, and creating an event overview scatter animation based on the number of events and the number of nodes; The security events in the target security event list are obtained based on a preset time sequence, and any one or more of the event information including the number of occurrences, attack stages, attack directions, source addresses, destination addresses, occurrence time information, event names, and the address of the device that reported the security events are determined, and an event information bar animation is created based on the event information.
6. The attack path visualization restoration method according to claim 5, characterized in that: The obtaining of the security events in the target security event list based on a preset time sequence and determining any one or more event information of the number of occurrences, attack stage, attack direction, source address, destination address, occurrence time information, event name, and address of a device that reported the security event includes: Obtaining the current security event in the target security event list based on a preset time sequence, and determining any one or more event information of the number of occurrences, occurrence time information, source address, destination address, event name, and address of a device reporting the security event of the current security event, and then querying the preset event model table for an attack stage corresponding to the event name of the current security event; Based on the preset intranet identification information segment management table, it is determined whether the source address and destination address of the current security event are intranet addresses, and based on the determination result, the attack direction corresponding to the source address to the destination address of the current security event is calculated.
7. The attack path visualization restoration method according to claim 6, characterized in that: The step of obtaining the current security event in the target security event list based on a preset time sequence and determining any one or more event information of the number of occurrences, occurrence time information, source address, destination address, event name, and address of a device that reports the security event of the current security event includes: Obtaining the current security event in the target security event list based on a preset time sequence, determining the occurrence time information, source address, destination address, and event name of the current security event, and determining whether the current security event is the first security event in the target security event list based on the occurrence time of the current security event; If so, it is determined that the number of occurrences of the current security event is 1.
8. The attack path visualization restoration method according to claim 7, characterized in that: After determining whether the current security event is the first security event in the target security event list based on the occurrence time of the current security event, the method further includes: If not, determine whether the source address, destination address, and event name of the current security event are consistent with the source address, destination address, and event name of the previous security event; If they are consistent, the number of occurrences of the previous security event is updated to obtain the number of occurrences of the current security event; if they are inconsistent, the number of occurrences of the current security event is determined to be 1.
9. A device for visualizing and restoring an attack path, characterized in that: include: An event collection module is used to collect original security events returned by target security devices; An event saving module, used to save the original security event into a preset database; An event list acquisition module is used to obtain a target search condition through a preset search condition interface, and to trace the target security event list from the preset database based on the target search condition; An animation generation module, configured to obtain a reference attack path animation using the occurrence time information, source address, and destination address in the target security event list, and to provide a user search interface to generate a target attack path animation based on user search conditions obtained through the user search interface and the reference attack path animation; The event list acquisition module is specifically used to: Determine whether the current tracing level is greater than the target tracing level in the target search condition; if not, based on the target search condition, use the current tracing address to perform tracing to obtain a current security event list including the current security event, and then extract the source address and destination address corresponding to the current security event, so as to obtain the next tracing address based on the source address and destination address corresponding to the current security event and obtain the next tracing level based on the current tracing level; Determine whether the next tracing level is greater than the target tracing level. If not, use the next tracing level and the next tracing address as the current tracing level and the current tracing address respectively, and then jump back to the step of tracing based on the target search condition and using the current tracing address to obtain a current security event list containing the current security event, until the next tracing level is greater than the target tracing level, and the current security event list is determined as the target security event list.
10. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the steps of the attack path visualization restoration method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the steps of the attack path visualization restoration method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Network attack display method and device
CN110971579A