Security event status marking method, system, device, equipment and storage medium

By obtaining the number of unprocessed events on the security event platform, determining the breakpoint time and marking the processed status, the problem of long-term unprocessed security events is solved, the accuracy of automatic identification and marking is improved, and the customer's work efficiency and data timeliness are improved.

CN115622741BActive Publication Date: 2025-09-26SHANGHAI ANLIZHI NETWORK SECURITY TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211146155.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-20
Publication Date
2025-09-26
Estimated Expiration
2042-09-20

AI Technical Summary

Technical Problem

In existing technologies, security incidents remain unhandled or unmarked for a long time, resulting in errors in risk asset identification and meaningless statistical reports. Insufficient application of automated linkage and lack of customer trust lead to a high proportion of unhandled security incidents in actual environments.

Method used

By obtaining the number of unprocessed security events on the security event platform, the breakpoint time is determined and the events are marked as processed starting from that moment. The number of occurrences corresponding to the breakpoint time is less than the number threshold and there are no valid attack events.

Benefits of technology

In cases of insufficient automation or distrust, processed security incidents can be automatically identified and marked to reduce the burden on operations personnel, improve processing efficiency, and maintain the timeliness and validity of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115622741B_ABST
    Figure CN115622741B_ABST
Patent Text Reader

Abstract

The present application relates to a method, system, device, equipment and storage medium for marking the status of security events. The method comprises: obtaining the number of occurrences of unprocessed security events on the security event platform at different times; based on the number of occurrences, determining the breakpoint time corresponding to the unprocessed security event from different times, starting from the breakpoint time, when it is determined that there is no valid attack event, marking the status of the unprocessed event as processed. In the case of insufficient automation or distrust, the embodiment of the present application automatically identifies security events that have actually been processed and automatically marks them as processed, thereby reducing the manual manpower of the operating personnel, further improving the work efficiency of customers in handling security issues, and keeping the security event management platform data timely and effective.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, system, device, equipment and storage medium for marking the status of a security event. Background Art

[0002] As a centralized network security operations center, the security incident management platform is responsible for monitoring the security status of the entire network. Security incidents, as a core component, encompass the entire lifecycle of security incidents, supporting the company's ongoing network security operations. Within the network security incident management platform, each security incident describes an attack or anomalous behavior. Continuous handling of security incidents is required, ensuring that the status of security incidents continues through a closed-loop process.

[0003] The security incident management platform identifies risky assets based on the status of incidents and compiles relevant reports. This requires customer operations personnel to continuously and closed-loop track the status of security incidents. In actual field operations, we've found that many customers lack the ability to maintain continuous operations, leaving security incidents unaddressed for extended periods. Even when security incidents are addressed on-site, they're not flagged on the security incident management platform. This causes security incidents to remain in an incorrect state for extended periods, leading to inaccuracies in risk asset identification and meaningless statistical reports.

[0004] The current feature that automatically marks security incidents is a coordinated response. In actual deployments, the security incident management platform and devices are linked, and after fully automated response, security incidents are automatically marked. However, in actual use, automated coordination is very rare, and many customers rarely implement it. This is partly due to the lack of coordination requirements at some locations and partly due to concerns about unforeseen issues. As a result, a significant number of security incidents in actual customer environments remain unhandled. Summary of the Invention

[0005] The present application provides a method, system, device, equipment and storage medium for marking the status of security events, which are used to solve the problem in the prior art that security events cannot be processed and marked for a long time due to insufficient automation or lack of trust.

[0006] In a first aspect, an embodiment of the present application provides a method for marking a security event status, including:

[0007] Obtain the number of unprocessed security events occurring at different times on the security event platform;

[0008] Based on the number of occurrences, determining a breakpoint moment corresponding to the unhandled security event from the different moments, the number of occurrences corresponding to the breakpoint moment being less than a number threshold;

[0009] Starting from the breakpoint moment, when it is determined that there is no valid attack event, the status of the unprocessed event is marked as processed; the valid attack event is an attack event launched by the host related to the unprocessed event on other hosts.

[0010] Optionally, before determining the breakpoint time corresponding to the unhandled security event from the different time points based on the number of occurrences, the method further includes:

[0011] Based on the number of occurrences, obtain M moments at which the number of occurrences of the unhandled security event is less than the number threshold;

[0012] Determine whether the number of the M moments is not less than a number threshold.

[0013] Optionally, determining that the valid attack event does not exist includes:

[0014] Obtaining the event type of the unhandled security event;

[0015] Obtaining an event type determination strategy that matches the event type;

[0016] A strategy is determined according to the event type to determine whether the valid attack event does not exist.

[0017] Optionally, the event type includes at least one of the following:

[0018] Scan for intrusions;

[0019] Horizontal expansion class;

[0020] Remote control external connection type;

[0021] Destruction type.

[0022] Optionally, obtaining the number of occurrences of unprocessed security events on the security event platform at different times includes:

[0023] Obtaining unprocessed security events occurring at each moment on the security event platform;

[0024] Based on the security event identifier, the number of occurrences of the unprocessed security events at different moments is obtained from the unprocessed security events occurring at each moment.

[0025] Optionally, the security event identifier includes at least one of the following:

[0026] Source IP address;

[0027] Source port;

[0028] Destination IP address;

[0029] Destination port.

[0030] In a second aspect, an embodiment of the present application provides a security event status marking system, including:

[0031] Security event platforms and hosts;

[0032] The security event platform is used to obtain the number of occurrences of unprocessed security events on the security event platform at different times;

[0033] Based on the number of occurrences, determining a breakpoint moment corresponding to the unhandled security event from the different moments, the number of occurrences corresponding to the breakpoint moment being less than a number threshold;

[0034] Starting from the breakpoint moment, when it is determined that there is no valid attack event, the status of the unprocessed event is marked as processed; the valid attack event is an attack event launched by the host related to the unprocessed event on other hosts.

[0035] In a third aspect, an embodiment of the present application provides a device for marking a security event status, including:

[0036] An acquisition module is used to obtain the number of occurrences of unprocessed security events on the security event platform at different times;

[0037] a determination module, configured to determine, based on the number of occurrences, a breakpoint moment corresponding to the unhandled security event from the different moments, the number of occurrences corresponding to the breakpoint moment being less than a number threshold;

[0038] The marking module is used to mark the status of the unprocessed event as processed when it is determined that there is no valid attack event starting from the breakpoint moment; the valid attack event is an attack event launched by the host related to the unprocessed event on other hosts.

[0039] In a fourth aspect, an embodiment of the present application provides an electronic device, including:

[0040] A processor, a memory, and a communication bus, wherein the processor and the memory communicate with each other via the communication bus;

[0041] The memory is used to store computer programs;

[0042] The processor is used to execute the program stored in the memory to implement the method for marking the security event status described in the first aspect.

[0043] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program for implementing the method for marking the security event status described in the first aspect.

[0044] The above technical solution provided by the embodiment of the present application has the following advantages over the prior art: the method provided by the embodiment of the present application obtains the number of occurrences of unprocessed security events on the security event platform at different times; based on the number of occurrences, the breakpoint moment corresponding to the unprocessed security event is determined from different times, and starting from the breakpoint moment, when it is determined that there is no valid attack event, the status of the unprocessed event is marked as processed. In the case of insufficient automation or distrust, the embodiment of the present application automatically identifies security events that have actually been processed and automatically marks them as processed, which reduces the manual manpower of operators, further improves the work efficiency of customers in handling security issues, and keeps the data of the security event management platform timely and effective. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0047] Figure 1 A flowchart of a method for marking a security event status in an embodiment of the present application;

[0048] Figure 2 A schematic diagram of the structure of a marking system for a security event status in an embodiment of the present application;

[0049] Figure 3 This is a schematic structural diagram of a device for marking a security event status in an embodiment of the present application;

[0050] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0051] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0052] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0053] A flow chart of a method for marking a security event status according to an embodiment of the present application is shown as follows: Figure 1 As shown, the method may include the following steps:

[0054] Step 101: Obtain the number of occurrences of unprocessed security events at different times on the security event platform.

[0055] It should be understood that the different moments are pre-set detection moments for unprocessed security events on the security event platform.

[0056] It should be understood that the number of unprocessed security events occurring at different times can be obtained by obtaining the unprocessed security events occurring at each moment on the security event platform and, based on the security event identifier, counting the unprocessed security events occurring at each moment.

[0057] It should be understood that the security event identifier is used to identify each unprocessed security event on the security event platform.

[0058] It should be understood that the security event identifier includes at least one of the following: source IP address; source port number; destination IP address; and destination port number. The source IP address is the source IP address where the security event occurred; the source port number is the source port number where the security event occurred; the destination IP address is the destination IP address where the security event occurred; and the destination port number is the destination port number where the security event occurred.

[0059] In the specific implementation, please refer to Table 1, which shows the unprocessed security events on the security event platform obtained at the current detection time T0.

[0060] Table 1

[0061]

[0062] In the specific implementation, please refer to Table 2, which shows the unprocessed security events on the security event platform obtained at the next detection time Ti.

[0063] Table 2

[0064]

[0065] In the specific implementation, please refer to Table 3. Based on the unprocessed security events that occur at each moment, a list of the number of occurrences of any security event on the security event platform in the time series is obtained, and then the number of occurrences of unprocessed security events at different moments is statistically obtained.

[0066] Table 3

[0067] Time T Number of events T0 10 T1 8 Ti 12 …… ……

[0068] It should be understood that the number of occurrences of unprocessed security events at different times can be obtained through a list of the number of occurrences of security events in a time series.

[0069] Among them, in the entities with attributes of security events in Table 1 and Table 2, the source IP is the source IP address where the security event occurs; the source port is the source port where the security event occurs; the destination IP is the destination IP address where the security event occurs; the destination port is the destination port where the security event occurs; the event name is a brief description of the security event; the event description is a specific description of the security event; the confidence level is the credibility of the security event, which can be specifically divided into compromised, highly suspicious or low suspicious; the level is the level of the impact of the event, which can be specifically divided into serious, high risk or low risk; the first occurrence of the event is the time when the security event is first detected; the latest occurrence time is the time when the security event is most recently detected; the status is the status of the security event, which can be specifically divided into unprocessed and processed; the focus is the host with risks that need to be paid attention to by the security event; the number of occurrences is the cumulative number of times the security event occurs from the first occurrence time to the latest occurrence time. This embodiment does not limit the specific security event attributes.

[0070] It should be understood that security events with an unhandled status include: real security events and false security events. Among them, false security events are false alarm security events discovered after investigation, which do not exist or have not yet been effectively verified.

[0071] It should be understood that before obtaining the number of occurrences of unprocessed security events on the security event platform at different times, it is necessary to check whether there are any non-real security events among the unprocessed security events. If there are non-real security events, the status of the non-real security events will be marked as ignored, and the unprocessed security events on the security event platform will be updated.

[0072] In an embodiment of the present application, by screening out non-real security events among the unprocessed security events before obtaining the number of occurrences of unprocessed security events on the security event platform at different times, the time for obtaining the number of occurrences of unprocessed security events on the security event platform at different times is reduced, and real security events among the unprocessed security events are identified more accurately.

[0073] Step 102: Determine the breakpoint time corresponding to the unhandled security event from different time points based on the number of occurrences.

[0074] It should be understood that the number of occurrences corresponding to the breakpoint moment is less than the number threshold; wherein the number threshold can be set according to actual conditions, for example, the number threshold can be set to 0.

[0075] In the specific implementation, a time series table of the occurrence counts of each unprocessed security event on the security event platform can be obtained. Through the time series table of the occurrence counts corresponding to each unprocessed security event, the occurrence counts of each unprocessed security event can be scanned in order of events. For example, if the number threshold is set to 1, when the occurrence count of an unprocessed security event is less than 1, that is, the occurrence count of the security event is 0, the occurrence count of the unprocessed security event is marked as 0, and the corresponding detection time is the breakpoint time corresponding to the unprocessed security event.

[0076] It should be understood that based on the number of occurrences, before determining the breakpoint moment corresponding to the unhandled security event from different moments, based on the number of occurrences, M moments at which the number of occurrences of the unhandled security event is less than the number threshold are obtained; and it is determined that the number of M moments is not less than the number threshold.

[0077] The number threshold can be set according to actual conditions and is not specifically limited in this embodiment.

[0078] It should be understood that before determining whether an unprocessed security event on the security event platform is a failure event, it is first determined whether the unprocessed security event is a potential failure event.

[0079] It should be understood that a failure event is an event that can be automatically marked as handled.

[0080] For ease of understanding, an example is given here. The default setting number threshold is 10 and the number of times is 1. When it is found from the time series table of the occurrence of unhandled security events that there are 10 consecutive moments with the number of occurrences being 0, the unhandled security event is determined to be a potential failure event.

[0081] In an embodiment of the present application, before determining the breakpoint moment corresponding to the unprocessed security from different moments, the M moments at which the number of occurrences of the unprocessed security events is less than the number threshold are obtained through a time series table of the number of occurrences of the unprocessed security events, and it is determined that the number of M moments is not less than the number threshold, and then the potential failure events in the unprocessed security events are determined. Through this embodiment, the potential failure events that meet the necessary conditions of the failure events are pre-screened, which provides a more accurate matching of unprocessed events for the subsequent marking of the unprocessed events as processed events, and reduces the amount of calculation.

[0082] Step 103: Starting from the breakpoint, when it is determined that there is no valid attack event, the status of the unprocessed event is marked as processed.

[0083] In a specific embodiment, the absence of a valid attack event can be determined by first obtaining the event type of the unprocessed security event and obtaining an event type determination strategy that matches the event type; and determining the absence of a valid attack event according to the event type determination strategy.

[0084] It should be understood that a valid attack event is an attack event initiated by a host related to an unprocessed event against other hosts.

[0085] It should be understood that the event type includes at least one of a scanning intrusion type, a horizontal expansion type, a remote control outreach type, and / or a destruction type.

[0086] It should be understood that a scanning intrusion security incident is an attack on a host that begins with a scanning intrusion. For example, a brute force login account cracking attack. Once this type of attack is successful, similar attacks on the host will not occur again, but other hacking activities may continue.

[0087] It should be understood that a horizontal expansion type of security incident is a poisoned host that, in the hope of expanding its effectiveness, will try to spread to nearby hosts. This type of behavior will continue until the virus is cleared. However, after successfully spreading to a host, the same incident will not continue to occur, but perhaps the action will continue.

[0088] It should be understood that remote control outbound security incidents involve a poisoned host, which to a large extent needs to connect to the hacker's remote control terminal to perform activities such as receiving and responding to commands. This type of behavior will continue to occur until the virus is cleared.

[0089] It should be understood that a destructive security incident is a poisoned host that will cause some system damage or data leakage. This type of behavior will continue until the virus is cleared. However, after successfully spreading to a host, the same incident will not continue to occur, and subsequent actions will continue.

[0090] It should be understood that the event type of unprocessed security events can be automatically identified by pre-setting the conditions for various types of security events on the security event platform; it can also be identified by users through classification of the content of the attributes of unprocessed security events on the security event platform.

[0091] In specific implementation, security events of the horizontal expansion, remote control outbound connection, and destruction categories correspond to one determination strategy, while the scanning intrusion category corresponds to another different determination strategy. Specifically, the determination strategy for security events of the horizontal expansion, remote control outbound connection, and destruction categories scans the host that initiated the event from the breakpoint of the unhandled security event to see if there are valid attack events launched against other hosts. If there are no valid attack events on the host that initiated the event, the event is identified as a failed event. The determination strategy for security events of the scanning intrusion category continues to scan the host that was invaded from the end moment to see if there are valid attack events launched against other hosts. If there are no valid attack events on the invaded host, the event is identified as a failed event.

[0092] It should be understood that the determination strategy corresponding to the event type of the unprocessed security event can be pre-set in the security event platform and automatically identified after the event type of the unprocessed security event is obtained.

[0093] In an embodiment of the present application, the number of occurrences of unprocessed security events on the security event platform at different times is obtained; based on the number of occurrences, the breakpoint time corresponding to the unprocessed security event is determined from different times, and starting from the breakpoint time, when it is determined that there is no valid attack event, the status of the unprocessed event is marked as processed. In the case of insufficient automation or distrust, the embodiment of the present application automatically identifies security events that have actually been processed and automatically marks them as processed, which reduces the manual manpower of operators, further improves the work efficiency of customers in handling security issues, and keeps the security event management platform data timely and effective.

[0094] In a specific embodiment, in a scenario where terminal behavior logs can be collected, it is possible to determine based on the terminal's file operations and / or antivirus behavior that the user has processed the unprocessed security events on the security event platform, and then identify the corresponding processed security events as non-processed, and mark the status of this security event as processed.

[0095] Based on the same concept, the embodiment of the present application provides a system for determining a security event status mark, such as Figure 2 As shown, the system mainly includes:

[0096] Security event platform 201 and host 202;

[0097] The security event platform 201 is used to obtain the number of occurrences of unprocessed security events on the security event platform at different times; based on the number of occurrences, the breakpoint time corresponding to the unprocessed security event is determined from different times, and the number of occurrences corresponding to the breakpoint time is less than the number threshold; starting from the breakpoint time, when it is determined that there is no valid attack event, the status of the unprocessed event is marked as processed; the valid attack event is an attack event launched by the host 202 related to the unprocessed event on other hosts.

[0098] Based on the same concept, an embodiment of the present application provides a device for marking a security event status. The specific implementation of the device can be found in the description of the method embodiment part, and the repeated parts will not be repeated. Figure 3 As shown, the device mainly includes:

[0099] An acquisition module 301 is used to acquire the number of occurrences of unprocessed security events at different times on the security event platform;

[0100] A determination module 302 is configured to determine a breakpoint time corresponding to an unhandled security event from different time points based on the number of occurrences, where the number of occurrences corresponding to the breakpoint time is less than a number threshold;

[0101] The marking module 303 is used to mark the status of the unprocessed event as processed when it is determined that there is no valid attack event starting from the breakpoint moment; the valid attack event is an attack event launched by the host related to the unprocessed event on other hosts.

[0102] In a specific embodiment, the device is further used to:

[0103] Based on the number of occurrences, before determining the breakpoint moment corresponding to the unhandled security event from the different moments, based on the number of occurrences, obtain M moments in which the number of occurrences of the unhandled security event is less than the number threshold; determine that the number of M moments is not less than the number threshold.

[0104] In a specific embodiment, the marking module 303 is used to:

[0105] Obtaining the event type of the unprocessed security event; obtaining an event type determination strategy that matches the event type; and determining that no valid attack event exists based on the event type determination strategy. In a specific embodiment, the event type includes at least one of the following: scanning intrusion type; horizontal expansion type; remote control outreach type; and sabotage type.

[0106] In a specific embodiment, the acquisition module 301 is used to:

[0107] Obtain the unprocessed security events that occur at each moment on the security event platform; based on the security event identifier, obtain the number of occurrences of the unprocessed security events at different moments from the unprocessed security events that occur at each moment.

[0108] In a specific embodiment, the security event identifier includes at least one of the following: source IP; source port; destination IP; destination port.

[0109] Based on the same concept, an electronic device is also provided in the embodiment of the present application, such as Figure 4 As shown, the electronic device mainly includes: a processor 401, a memory 402 and a communication bus 403, wherein the processor 401 and the memory 402 communicate with each other via the communication bus 403. The memory 402 stores a program that can be executed by the processor 401, and the processor 401 executes the program stored in the memory 402 to implement the following steps:

[0110] Obtain the number of occurrences of unprocessed security events on the security event platform at different times; based on the number of occurrences, determine the breakpoint time corresponding to the unprocessed security event from different times, and the number of occurrences corresponding to the breakpoint time is less than the number threshold; starting from the breakpoint time, when it is determined that there is no valid attack event, mark the status of the unprocessed event as processed; a valid attack event is an attack event launched by a host related to the unprocessed event on other hosts.

[0111] The communication bus 403 mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The communication bus 403 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0112] The memory 402 may include a random access memory (RAM) or a non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor 401.

[0113] The above-mentioned processor 401 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc., and can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0114] In another embodiment of the present application, a computer-readable storage medium is provided, which stores a computer program. When the computer program runs on a computer, the computer executes a method for marking a security event status described in the above embodiment.

[0115] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions are transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape, etc.), an optical medium (e.g., a DVD) or a semiconductor medium (e.g., a solid-state hard disk), etc.

[0116] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0117] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is intended to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A method for marking a security event status, characterized in that: include: Obtain the number of unprocessed security events occurring at different times on the security event platform; Based on the number of occurrences, determining a breakpoint moment corresponding to the unhandled security event from the different moments, the number of occurrences corresponding to the breakpoint moment being less than a number threshold; Starting from the breakpoint, when it is determined that there is no valid attack event, marking the status of the unprocessed security event as processed; The valid attack event is an attack event launched by a host related to the unprocessed security event against other hosts; Among them, it is determined that there are no valid attack events, including: Obtaining the event type of the unhandled security event; Obtaining an event type determination strategy that matches the event type; A strategy is determined according to the event type to determine whether the valid attack event does not exist.

2. The method according to claim 1, characterized in that Before determining the breakpoint time corresponding to the unhandled security event from the different time points based on the number of occurrences, the method further includes: Based on the number of occurrences, obtain M moments at which the number of occurrences of the unhandled security event is less than the number threshold; Determine whether the number of the M moments is not less than a number threshold.

3. The method according to claim 1, characterized in that The event type includes at least one of the following: Scan for intrusions; Horizontal expansion class; Remote control external connection type; Destruction type.

4. The method according to claim 1, wherein The acquisition of the number of occurrences of unprocessed security events on the security event platform at different times includes: Obtaining unprocessed security events occurring at each moment on the security event platform; Based on the security event identifier, the number of occurrences of the unprocessed security events at different moments is obtained from the unprocessed security events occurring at each moment.

5. The method according to claim 4, characterized in that The security event identifier includes at least one of the following: Source IP address; Source port; Destination IP address; Destination port.

6. A security event status marking system, characterized in that: include: Security event platforms and hosts; The security event platform is used to obtain the number of occurrences of unprocessed security events on the security event platform at different times; Based on the number of occurrences, determining a breakpoint moment corresponding to the unhandled security event from the different moments, the number of occurrences corresponding to the breakpoint moment being less than a number threshold; Starting from the breakpoint, when it is determined that there is no valid attack event, marking the status of the unprocessed security event as processed; The valid attack event is an attack event launched by a host related to the unhandled security event against other hosts; wherein, determining that there is no valid attack event includes: obtaining the event type of the unhandled security event; obtaining an event type determination strategy that matches the event type; and determining that there is no valid attack event according to the event type determination strategy.

7. A device for marking a security event status, characterized in that: include: An acquisition module is used to obtain the number of occurrences of unprocessed security events on the security event platform at different times; a determination module, configured to determine, based on the number of occurrences, a breakpoint moment corresponding to the unhandled security event from the different moments, the number of occurrences corresponding to the breakpoint moment being less than a number threshold; a marking module, configured to mark the status of the unprocessed security event as processed starting from the breakpoint moment when it is determined that there is no valid attack event; The valid attack event is an attack event launched by a host related to the unhandled security event against other hosts; wherein, determining that there is no valid attack event includes: obtaining the event type of the unhandled security event; obtaining an event type determination strategy that matches the event type; and determining that there is no valid attack event according to the event type determination strategy.

8. An electronic device, characterized in that: include: A processor, a memory, and a communication bus, wherein the processor and the memory communicate with each other via the communication bus; The memory is used to store computer programs; The processor is used to execute the program stored in the memory to implement the security event status marking method described in any one of claims 1-5.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method for marking the security event status according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Attack result judgment method and device, electronic equipment and storage medium

    CN114417349A

  • Method and apparatus for detecting SSH login attacks

    US20110185419A1