An alarm policy generation method and device and a storage medium

CN115712646BActive Publication Date: 2026-08-21TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110947247.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-18
Publication Date
2026-08-21
Estimated Expiration
2041-08-18

AI Technical Summary

Technical Problem

现有的检测告警是人工根据软件或硬件系统及其所承载的业务、以及告警平台的类别进行告警策略配置,策略配置和维护的人力成本极高,且生成效率低下

Benefits of technology

本申请通过获取多条安全事件的事件描述信息,事件描述信息包括安全事件的事件对象信息、事件属性信息和事件时间信息;并从配置规则库中获取包括过滤字段信息和事件聚合条件告警配置规则;然后根据过滤字段信息和事件属性信息,将配置规则库中的告警配置规则与多条安全事件进行匹配,得到了目标配置规则和对应的安全事件;以及,根据事件对象信息和事件时间信息,将对应的安全事件中的安全事件与目标配置规则的事件聚合条件进行匹配;若匹配到满足事件聚合条件的目标安全事件,基于目标配置规则生成对应的告警策略。上述技术方案通过设置配置规则库和安全数据的匹配实现了告警策略的自动生成,无需人工配置告警策略,且能够应用于不同安全平台和业务系统,进行大幅减少告警策略配置的重复性劳动,有效提高告警策略生成效率。此外,基于安全事件数据从配置规则库中确定匹配的告警配置规则,进而生成告警策略,能够提高告警策略与待分析安全事件的相关性,减少无效告警策略数量,提高告警分析效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115712646B_ABST
    Figure CN115712646B_ABST
Patent Text Reader

Abstract

The application provides an alarm policy generation method and device and a storage medium, relates to the technical field of Internet, and the method comprises the following steps: acquiring event description information of a plurality of security events, wherein the event description information comprises event object information, event attribute information and event time information of the security events; acquiring an alarm configuration rule from a configuration rule library, wherein the alarm configuration rule comprises filtering field information and event aggregation conditions; matching the alarm configuration rule in the configuration rule library with the plurality of security events according to the filtering field information and the event attribute information, obtaining a target configuration rule and corresponding security events; matching a security event in the corresponding security events with the event aggregation conditions of the target configuration rule according to the event object information and the event time information; and if a target security event meeting the event aggregation conditions is matched, generating a corresponding alarm policy based on the target configuration rule. The application can effectively improve the alarm policy generation efficiency and policy quality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to an alarm policy generation method, apparatus and storage medium. Background Technology

[0002] A security incident refers to a raw security issue discovered by different security products (including software or hardware) within their respective detection scopes (such as traffic, endpoints, or logs). Detecting and analyzing security incident data enables timely generation of alerts and appropriate alert handling to mitigate security risks.

[0003] With the widespread adoption of network technology, the number of security incidents has increased exponentially, resulting in massive and complex datasets. Consequently, alarm analysis of security incident data involves numerous alarm strategies. Current detection and alarm systems rely on manual configuration of alarm strategies based on software or hardware systems, the services they support, and the type of alarm platform. This process is extremely costly in terms of manpower for strategy configuration and maintenance, and is also inefficient. Therefore, an improved alarm strategy generation solution is needed to address these existing problems. Summary of the Invention

[0004] This application provides an alarm policy generation method and apparatus, which can effectively improve the efficiency of alarm policy generation and reduce labor costs.

[0005] On the one hand, this application provides an alarm policy generation method, the method comprising: Obtain event description information for multiple security events, wherein the event description information includes event object information, event attribute information, and event time information of the security events; Obtain alarm configuration rules from the configuration rule library. The alarm configuration rules include filter field information and event aggregation conditions. Based on the filter field information and the event attribute information, the alarm configuration rules in the configuration rule base are matched with the multiple security events to obtain the target configuration rule and the corresponding security event; Based on the event object information and the event time information, the security events in the corresponding security events are matched with the event aggregation conditions of the target configuration rules; If a target security event that meets the event aggregation conditions is matched, a corresponding alarm policy is generated based on the target configuration rules for use in the alarm analysis of the security event.

[0006] On the other hand, an alarm policy generation device is provided, the device comprising: Event information acquisition module: used to acquire event description information of multiple security events, the event description information including event object information, event attribute information and event time information of the security event; Configuration rule acquisition module: used to acquire alarm configuration rules from the configuration rule library, wherein the alarm configuration rules include filter field information and event aggregation conditions; The first matching module is used to match the alarm configuration rules in the configuration rule base with the multiple security events based on the filter field information and the event attribute information, so as to obtain the target configuration rule and the corresponding security event. The second matching module is used to match the security events in the corresponding security events with the event aggregation conditions of the target configuration rules based on the event object information and the event time information. Alarm policy generation module: If a target security event that meets the event aggregation conditions is matched, the module generates a corresponding alarm policy based on the target configuration rules for use in the alarm analysis of the security event.

[0007] On the other hand, an alarm policy generation device is provided, the device including a processor and a memory, the memory storing at least one instruction or at least one program segment, the at least one instruction or the at least one program segment being loaded and executed by the processor to implement the alarm policy generation method as described above.

[0008] On the other hand, a computer-readable storage medium is provided, wherein at least one instruction or at least one program is stored therein, the at least one instruction or the at least one program being loaded and executed by a processor to implement the alarm policy generation method as described above.

[0009] On the other hand, a server is provided, the server including a processor and a memory, the device including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the alarm policy generation method as described above.

[0010] On the other hand, a computer program product or computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the alarm policy generation method described above.

[0011] The alarm policy generation method, apparatus, device, storage medium, server, and program products provided in this application have the following technical effects: This application obtains event description information from multiple security events, including event object information, event attribute information, and event time information. It then retrieves alarm configuration rules, including filter fields and event aggregation conditions, from a configuration rule base. Based on the filter fields and event attribute information, the alarm configuration rules in the configuration rule base are matched with the multiple security events to obtain target configuration rules and corresponding security events. Furthermore, based on the event object information and event time information, the security events within the corresponding security events are matched with the event aggregation conditions of the target configuration rules. If a target security event that meets the event aggregation conditions is matched, a corresponding alarm policy is generated based on the target configuration rule. This technical solution achieves automatic alarm policy generation by setting up a configuration rule base and matching security data, eliminating the need for manual alarm policy configuration. It can be applied to different security platforms and business systems, significantly reducing repetitive work in alarm policy configuration and effectively improving alarm policy generation efficiency. Furthermore, by determining matching alarm configuration rules from the configuration rule base based on security event data and then generating alarm policies, the correlation between alarm policies and the security events to be analyzed can be improved, the number of invalid alarm policies can be reduced, and the efficiency of alarm analysis can be improved. Attached Figure Description

[0012] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a schematic diagram of an application environment provided in an embodiment of this application; Figure 2 This is a flowchart illustrating an alarm policy generation method provided in an embodiment of this application; Figure 3 This is a flowchart illustrating an alarm policy generation method provided in an embodiment of this application; Figure 4 This is a flowchart illustrating an alarm policy generation method provided in an embodiment of this application; Figure 5 This is a schematic diagram of a set of related security events provided in this embodiment; Figure 6 This is a schematic diagram of the structure of an alarm policy generation device provided in an embodiment of this application; Figure 7 This is a hardware structure block diagram of a server for an alarm policy generation method provided in an embodiment of this application. Detailed Implementation

[0014] Cloud computing refers to the delivery and usage model of IT infrastructure, meaning obtaining necessary resources in an on-demand and easily scalable manner through a network. In a broader sense, cloud computing also refers to the delivery and usage model of services, meaning obtaining necessary services in an on-demand and easily scalable manner through a network. These services can be IT and software related, internet-related, or other services. Cloud computing is a product of the development and integration of traditional computer and network technologies such as grid computing, distributed computing, parallel computing, utility computing, network storage technologies, virtualization, and load balancing.

[0015] The technical solution of this application embodiment can utilize cloud computing and cloud storage technologies to provide resource data services such as style data for alarm policy generation. Cloud storage is a new concept that extends and develops from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as a storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to aggregate a large number of storage devices (also called storage nodes) of various types in the network through application software or application interfaces to work together and jointly provide data storage and business access functions to the outside world.

[0016] Currently, the storage method in storage systems is as follows: Logical volumes are created. During creation, physical storage space is allocated to each logical volume. This physical storage space may consist of a single storage device or the disks of several storage devices. Clients store data on a logical volume, which means storing the data on the file system. The file system divides the data into many parts, each part being an object. Each object contains not only the data but also additional information such as a data identifier (ID, ID entity). The file system writes each object to the physical storage space of that logical volume and records the storage location information of each object. Therefore, when a client requests access to data, the file system can allow the client to access the data based on the storage location information of each object.

[0017] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0018] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0019] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.

[0020] SOC (Security Operations Center): It adopts a centralized management approach to uniformly manage relevant security products, collect security information of all assets within the network, and through in-depth analysis, statistics and correlation of various security events collected, promptly reflect the security status of managed assets, locate security risks, promptly discover and locate various security events, and provide timely handling methods and suggestions, assisting administrators in event analysis, risk analysis, early warning management and emergency response.

[0021] SIEM (Security Information and Event Management) is a combination of software and services, a fusion of SIM (Security Information Management) and SEM (Security Event Management). SIEM provides unified real-time detection and historical analysis of security information (including logs, alerts, etc.) generated from all IT resources (including networks, systems, and applications) within an enterprise or organization. It detects, audits, analyzes, investigates, and generates various reports on external intrusions and internal violations and misoperations, achieving the goal of IT resource compliance management while simultaneously improving the security operations, threat management, and incident response capabilities of enterprises and organizations.

[0022] Security alerts are alerts generated in security operations center platforms such as SOC / SIEM after further processing of security events or operational logs collected from different security products or devices. These alerts are derived from the analysis of security events based on alerting policies, and there is often a one-to-one relationship between security alerts and alerting policies.

[0023] Alarm policy: Alarm policy refers to the generation strategy used in security operations centers such as SOC / SIEM to convert security events, device logs, etc. into security alarms.

[0024] Please see Figure 1 , Figure 1 This is a schematic diagram of an application environment provided in an embodiment of this application, such as... Figure 1 As shown, the application environment may include at least server 01 and terminal 02. In practical applications, server 01 and terminal 02 can be directly or indirectly connected via wired or wireless communication to enable interaction between terminal 02 and server 01. This application does not impose any restrictions on this.

[0025] In this embodiment, server 01 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Specifically, the server can include physical devices, such as network communication units, processors, and memory, and software running on the physical devices, such as applications. In this embodiment, server 01 can be used to obtain event description information of multiple security events, store configuration rule bases, and provide alarm policy generation services and security event alarm analysis services.

[0026] In this embodiment, terminal 02 may include physical devices such as smartphones, desktop computers, tablets, laptops, digital assistants, augmented reality (AR) / virtual reality (VR) devices, smart TVs, smart speakers, smart wearable devices, and in-vehicle terminal devices, and may also include software running on the physical device, such as applications. Specifically, terminal 02 can be used to generate security events and send security event data, such as event records and device log data, to server 01.

[0027] In addition, it should be noted that, Figure 1 The example shown is merely an application environment for an alarm policy generation method. This application environment may include more or fewer nodes, and this application does not impose any restrictions here.

[0028] The following describes an alarm policy generation method based on the above application environment, applied to the server side. In some cases, the technical solution of this application can be applied to common security platforms such as SOC or SIEM, suitable for scenarios with fewer personnel or a large number of security incidents, such as small and medium-sized enterprises or enterprises with limited security budgets, enterprises with a large number of assets exposed to the public network, or security drills and other scenarios that pose significant challenges to enterprise security. Figure 2This is a flowchart illustrating an alarm policy generation method provided in an embodiment of this application. This specification provides method operation steps as shown in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operation steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many, and does not represent the only execution order. In actual system or server product execution, the method can be executed sequentially according to the embodiments or drawings, or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown... Figure 2 As shown, the method may include the following.

[0029] S201: Obtain event description information for multiple security events. The event description information includes the event object information, event attribute information, and event time information of the security event.

[0030] In this embodiment, a security event refers to a raw security problem discovered by different security products (including software or hardware) within a corresponding detection scope (such as traffic, terminals, or logs). Specifically, the aforementioned multiple security events can originate from the same business system or from different business systems. Specifically, the event description information can be obtained from security event data such as device log data of the multiple security events.

[0031] In some embodiments, multiple security events can be historical security events. Accordingly, based on the security event records and corresponding device log data of the historical security events, corresponding event description information is obtained to determine alarm configuration rules from the configuration rule base for generating alarm policies corresponding to these multiple security events. This is then used for alarm analysis of near-real-time security events. In some cases, event description information of multiple security events within a preset time period (such as the most recent day) can be obtained, and the generated alarm policy is used for alarm analysis of security events on that day. It should be noted that the preset time period can be set based on actual needs and is not limited to the above description; this application does not impose any restrictions.

[0032] In other embodiments, multiple security events can be near real-time security events. Accordingly, based on the security event records and corresponding device log data of the near real-time security events, corresponding event description information is obtained to determine the corresponding alarm configuration rules from the configuration rule base, and further, corresponding alarm policies and alarm results are generated. When preset conditions are met, such as the number of generated alarm policies reaching a first preset value, or the increase in the number of alarm policies within a certain period being less than or equal to a second preset value, alarm analysis is performed on subsequent security events based on the generated alarm policies. It should be noted that the preset conditions can be set based on actual needs and are not limited to the above description; this application does not impose any restrictions.

[0033] In practical applications, event object information refers to the identification information of objects related to a security event, which may include, but is not limited to: the source IP and / or destination IP of the security event, or the device identification information of the related objects. Event attribute information refers to the information that characterizes the attributes of a security event, which may include, but is not limited to: event name information and event category information (including general category and sub-category, etc.). Event time information may include, but is not limited to, the occurrence time, end time and / or duration of the security event.

[0034] By reading the event description information of multiple security events for subsequent event filtering and rule matching, there is no need to read the entire security event data (including security event records and device log data, etc.), which reduces the amount of data in the data reading, event filtering and rule matching processes and improves data processing efficiency.

[0035] S203: Retrieve alarm configuration rules from the configuration rule library. Alarm configuration rules include filter field information and event aggregation conditions.

[0036] In this embodiment, alarm configuration rules are used to indicate the rules for aggregating security events. Specifically, alarm configuration rules are compiled based on a common format to facilitate their application on different security platforms, such as SOC and SIEM. Specifically, the configuration rule base includes multiple preset alarm configuration rules, which can correspond to the same business system or different business systems.

[0037] In practical applications, alarm configuration rules include multiple configuration items. Specifically, they may include filter configuration items and event aggregation condition items. Filter configuration items include filter field information used to filter security events, and event aggregation condition items are used to indicate the conditions for aggregating security events obtained based on filter configuration items (such as filter field information).

[0038] S205: Based on the filter field information and event attribute information, match the alarm configuration rules in the configuration rule base with multiple security events to obtain the target configuration rule and the corresponding security event.

[0039] In this embodiment, the matching of the above-mentioned alarm configuration rules with security events can be achieved based on the matching results between filter field information and event attribute information. The matching methods between filter field information and event attribute information include exact matching and fuzzy matching. Exact matching means that the fields in the event attribute information are the same as the fields in the filter field information, i.e., the field values ​​are completely equal. Fuzzy matching means that the event attribute information includes some or all of the specified fields in the filter field information. For example, event attribute information includes event name, event category, and event subcategory. For instance, the event attribute information is “xss attack / NAI / VAI”; where xss attack is the event name, NAI (Network Attacks Incidents) is the event category, and VAI (Vulnerability Attacks Incidents) is the event subcategory. In some cases, the filter field information is “xss attack / NAI / VAI”, and the filter field information and event attribute information can be matched based on exact matching. In this case, the event attribute information in the security events corresponding to the target alarm rule will all be “xss attack / NAI / VAI”. In other cases, the filter field information can be a field specified in "xss attack / NAI / VAI", such as "xss attack". The filter field information and event attribute information can be matched based on fuzzy matching. In this case, the event attribute information of the security event corresponding to the target alarm rule will include "xss event".

[0040] In practical applications, the security events corresponding to the target configuration rule include at least two security events. Accordingly, if, based on the filter field information and event attribute information, the alarm configuration rule in the configuration rule base matches at least two security events among multiple security events, then the alarm configuration rule is used as the target configuration rule; if no at least two security events are matched, then step S207 below is not triggered.

[0041] In practical applications, the filter field information of each alarm configuration rule in the configuration rule base can be matched with the event attribute information of multiple security events. The alarm configuration rule that matches the security event is taken as the target configuration rule, and the security event that matches the filter field information of the target configuration rule is the corresponding security event mentioned above.

[0042] In some cases, alarm configuration rules are read one by one from the configuration rule library. Based on the filter field information of the read alarm configuration rules, the event attribute information of multiple security events is traversed and matched to obtain the target configuration rule and the corresponding security event.

[0043] In other cases, all or part of the alarm configuration rules in the configuration rule base can be read synchronously. Based on the event attribute information of the currently input security event, each read alarm configuration rule is traversed and matched to obtain the target configuration rule and the corresponding security event. For example, the alarm policy generation engine can read the required alarm configuration rules from the configuration rule base and mount them. Multiple security events are input in the form of a time-series-based security event queue. The alarm policy generation engine obtains the event description information of the security events based on this time sequence and traverses and matches their event attribute information with the filter field information of the mounted alarm configuration rules.

[0044] S207: Based on the event object information and event time information, match the security events in the corresponding security events with the event aggregation conditions of the target configuration rules.

[0045] S209: If a target security event that meets the event aggregation conditions is matched, a corresponding alarm policy is generated based on the target configuration rules for use in the alarm analysis of the security event.

[0046] In this embodiment, if a target security event that meets the event aggregation conditions of the target configuration rule is matched from the corresponding security events based on the event object information and event time information, i.e., there exists a target security event that triggers the target configuration rule, then a corresponding alarm policy is generated based on the target configuration rule. The alarm policy is used to aggregate at least two security events to generate a single alarm result. The generated alarm policy is stored in the alarm policy library for subsequent security event alarm analysis. Specifically, the target security event includes at least two security events.

[0047] This application obtains event description information from multiple security events, including event object information, event attribute information, and event time information. It then retrieves alarm configuration rules, including filter fields and event aggregation conditions, from a configuration rule base. Based on the filter fields and event attribute information, the alarm configuration rules in the configuration rule base are matched with the multiple security events to obtain target configuration rules and corresponding security events. Furthermore, based on the event object information and event time information, the security events within the corresponding security events are matched with the event aggregation conditions of the target configuration rules. If a target security event that meets the event aggregation conditions is matched, a corresponding alarm policy is generated based on the target configuration rule. This technical solution achieves automatic alarm policy generation by setting up a configuration rule base and matching security data, eliminating the need for manual alarm policy configuration. It can be applied to different security platforms and business systems, significantly reducing repetitive work in alarm policy configuration and effectively improving alarm policy generation efficiency. Furthermore, by determining matching alarm configuration rules from the configuration rule base based on security event data and then generating alarm policies, the correlation between alarm policies and the security events to be analyzed can be improved, the number of invalid alarm policies can be reduced, and the efficiency of alarm analysis can be improved.

[0048] In practical applications, generating corresponding target alarm policies based on target configuration rules may include: calling the policy generation interface to convert the configuration data of the target configuration rules into a new format to obtain the corresponding alarm policy.

[0049] It is understandable that different security platforms have different alarm policy formats. Therefore, when applying target configuration rules to different target security platforms, it is necessary to call the policy generation interface, convert the configuration data of the target configuration rules according to the policy format of the target security platform, and save it to the corresponding platform, such as converting and storing it as an alarm policy of the SOC or SIEM platform.

[0050] In some cases, before format conversion, a configuration rule detection step is also included. Specifically, this may include: calling a preset parsing syntax to parse the target configuration rule; if the parsing is successful, triggering a step to call the strategy generation interface to convert the configuration data of the target configuration rule in a new format; if the parsing is unsuccessful, generating a parsing error message to prompt the user to check the configuration rule.

[0051] Based on some or all of the above implementation methods, in this embodiment, the alarm strategy includes a merging strategy and a correlation strategy. The merging strategy is applied to scenarios where multiple security events that meet the same condition are aggregated together to generate a single alarm. The correlation strategy is applied to scenarios where related security events are aggregated together to generate a single alarm. Correspondingly, the alarm configuration rules include merging configuration rules and correlation configuration rules. The merging configuration rules are the configuration rules corresponding to the alarm strategy that aggregates security events occurring under the same condition into a single alarm result; the correlation configuration rules are the configuration rules corresponding to the alarm strategy that aggregates related security events into a single alarm result.

[0052] In practical applications, when the alarm configuration rule is a merging-type configuration rule, the event aggregation conditions include merging sub-conditions, a lower limit for the number of events to be merged, and an aggregation duration. The merging sub-conditions indicate that the security events have the same event object, and the aggregation duration indicates the time range within which security events are aggregated, which can be, for example, 1 hour or 3 hours. Accordingly, step S207 may include the following steps.

[0053] S2071: Based on the event object information and the merging sub-condition, determine the first security event with the same event object from the corresponding security events to obtain the first security event set.

[0054] Specifically, the event object information may include the source IP and destination IP, or the device identifier. Correspondingly, if the source IP and destination IP of the same event object are the same as another security event, or the device identifier is the same as another security event, then the event object is the same as another security event.

[0055] Understandably, in a merging scenario, the filter field information includes field information for a type of security event. The corresponding security events obtained through filtering are security events with the filter field information, such as security events of the same category, security events of the same subcategory, or security events with the same name. Therefore, the first security event obtained from the corresponding security events that has the same event object is one that has the filter field information and whose event objects are identical.

[0056] S2072: Based on the event time information, determine the target number of first security events that occur within the aggregation period.

[0057] Specifically, based on the event time information, the occurrence time of each first security event in the first security event set can be determined, and then the first target time period can be determined based on the occurrence time of each first security event and the aggregated duration. In some cases, the first target time period is a time period starting from the occurrence time of the first security event and having a duration equal to the aggregated duration. For example, if the first security event includes 10 first security events, with occurrence times of 1:00, 1:30, 2:10, 2:20, 2:30, 2:40, 3:30, 4:30, 5:00, and 5:30, and an aggregation duration of 2 hours, then the target time period can be a time period with a starting point of 1:00, 1:30, 2:10, 2:20, 2:30, 2:40, or 3:30, and an aggregation duration of 2 hours, namely 1:00-3:00, 1:30-3:30, 2:10-4:10, 2:20-4:20, 2:30-4:30, 2:40-4:40, or 3:30-5:30.

[0058] S2073: If the number of target events is greater than or equal to the preset minimum number, a target security event that meets the event aggregation conditions is determined to be matched.

[0059] Specifically, limiting the number of events to be merged based on a preset minimum limit can reduce the number of alarms and the false alarm rate.

[0060] For example, in a scenario using a merged alerting strategy, if host A continuously launches the same type of web attack against host B (assuming this behavior occurs throughout an hour), each time host A launches this type of web attack against host B, a security event is generated. In this scenario, these multiple security events can be aggregated into a single security alert using a merged alerting strategy (e.g., "Host A continuously launches a web attack against host B within a certain period of time"), thereby transforming a large number of security events into a manageable number of security alerts. For example, a merge configuration rule can take the form of "subject:srcip,dstip filter:name-*xss attack* time:1-10"; where "filter:name-*xss attack*" is a filter configuration item, and its filter field information is "xss attack". This item represents security events whose event names include the field "xss attack"; "subject:srcip,dstip" and "time:1-10" are event aggregation conditions. "subject:srcip,dstip" is a merge sub-condition item, representing that the condition for the same event object is that the source IP and destination IP are the same, and "time:1-10" represents that the aggregation duration is 1 hour (the merging time range is 1 hour), and the minimum number of merges is 10. The alarm policy corresponding to this merge configuration rule is: merge security events whose event names include the field "xss attack", whose source IP and destination IP are the same, and which occur more than 10 times within 1 hour.

[0061] In practical applications, when the alarm configuration rule is a correlation-based configuration rule, the event correlation sub-conditions include correlation relationship items and preset event timing. The event aggregation conditions include correlation sub-conditions, correlation event timing, and aggregation duration. The correlation sub-conditions indicate the target correlation relationship that must be satisfied between the event objects of the associated security events. The aggregation duration represents the time range within which security events are aggregated, and this time range can be the same as or different from the above-mentioned merging class. Accordingly, step S207 may include the following steps.

[0062] S2074: Based on the event object information, event time information, and associated sub-conditions, determine the second security event set from the corresponding security events that occurred within the aggregation period and have a target association relationship between the event objects.

[0063] Specifically, event object information may include source IP and destination IP, or device identifier. Correspondingly, the existence of target associations between event objects can be a target association between the source IP and destination IP of security events, or a target association between device identifiers. Target associations can be determined based on prior knowledge of event associations.

[0064] Specifically, by matching the event object information of each security event in the corresponding security event with the associated sub-conditions, security events with target association relationships between event objects can be obtained. Furthermore, the event occurrence time of each second security event in the second security event set can be determined based on the event occurrence time. Then, based on the event occurrence time, second security events occurring within the aggregate duration and with target association relationships between event objects can be identified. In some cases, similar to the first target time period, the second target time period can be determined based on the event occurrence time of each second security event and the aggregate duration; this will not be elaborated further in this application.

[0065] Understandably, in a context of association, the filtering field information includes the respective field information of each security event that satisfies the target association relationship. The corresponding security events obtained through filtering include security events related to the target association relationship that possess the filtering field information. Therefore, the second security event obtained from the corresponding security events is one that possesses the filtering field information and whose event objects have a target association relationship with each other.

[0066] For example, if host A is compromised after an attack, and the attacker then uses host A to control host B, two types of attack events will occur in this scenario: event a, where host A is attacked, and event b, where host A attacks host B. The corresponding filter fields can be the fields corresponding to the aforementioned attack events. Since the attacker attacks host A and controls host A to launch the attack, these two types of attack events can be associated through host A's IP address. Therefore, the target association relationship can be that the destination IP of event a is the same as the source IP of event b. Based on association-based configuration rules, multiple different types of events from multiple security events can be associated, greatly reducing the workload of searching for related events from a massive amount of data.

[0067] S2075: Based on event time information, determine the timing of the second security events in the second security event set.

[0068] S2076: If the timing of the second security event is consistent with the timing of the associated event, determine that a target security event that meets the event aggregation conditions has been matched.

[0069] Understandably, related security events often have a causal relationship, therefore, security events that satisfy the target correlation relationship have a sequential relationship. Therefore, it is necessary to determine whether the timing of the second security events in the second security event set is consistent with the preset timing of related events. In some cases, the timing of the second security events in each second target time period can be determined separately. If the timing of the second security event in any second target time period is consistent with the timing of related events, a target security event that meets the event aggregation condition is identified.

[0070] In some cases, event aggregation conditions may also include a lower limit on the number of associations for each type of second security event that has a target association relationship. By default, the lower limit on the number of associations for each type of second security event is 1.

[0071] For example, a specific association configuration rule's event aggregation condition could be in the form of "subject:srcip1,dstip1,srcip2,dstip2,srcip3,dstip3 relation:dstip1=srcip2,dstip2=srcip3,dstip3=srcip1 time:1 order:1>2>3"; where "subject:srcip1,dstip1,srcip2,dstip2, srcip3,dstip3 relation:dstip1=srcip2,dstip2= "srcip3,dstip3=srcip1" is a correlation sub-condition, representing the target correlation relationship between the three security events: the destination IP of event 1 is the same as the source IP of event 2, the source IP of event 3 is the same as the destination IP of event 2, and the source IP of event 1 is the same as the destination of event 3; "time:1" is the aggregation duration, corresponding to a time range of 1 hour; "order:1>2>3" is the correlation event sequence, representing the sequence of the three security events from earliest to latest as: event 1 → event 2 → event 3. Please refer to [reference needed]. Figure 5 This example can be applied to the security event scenarios shown in the figure. Event 1 is host A attacking host B, event 2 is host B attacking host C, and event 3 is host A manipulating host B to enable host B to communicate with host A.

[0072] Based on some or all of the above embodiments, please refer to the embodiments of this application. Figure 3 After step S209, the method may further include the following steps.

[0073] S211: Obtain the target alarm result corresponding to the target alarm strategy.

[0074] S213: Verify the target alarm results based on the target configuration rules to obtain the target verification results.

[0075] In practical applications, alarm data from the security platform can be periodically retrieved to check if a target alarm result corresponding to the target alarm policy exists. For example, the period could be 10 minutes. If it exists, the target alarm result is verified based on the corresponding target configuration rules. For instance, if the target configuration rule is a merge rule, it verifies whether the merged event objects meet the merge sub-conditions and whether the number of merged events meets the minimum merge limit. If the target configuration rule is an association rule, it verifies whether the event sequence of the associated security events is consistent with the associated event sequence and whether the association relationship between event objects meets the target association relationship.

[0076] Based on some or all of the above embodiments, please refer to the embodiments of this application. Figure 4 After step S209, the method may further include the following steps.

[0077] S215: Obtain statistical information on the target alarm results corresponding to the target alarm strategy within a preset time period.

[0078] S217: Optimize the target configuration rules based on statistical information to obtain updated target configuration rules.

[0079] Specifically, the preset duration can be set based on actual needs. The preset duration can be the same as or different from the aforementioned aggregation duration.

[0080] Specifically, steps S215 and S217 can be executed periodically to iteratively optimize the target configuration rules.

[0081] In practical applications, if the target configuration rule is a merge-type configuration rule, the statistical information includes the number of alarms in the target alarm result within a preset time period. Accordingly, step S217 can specifically include S2171: if the number of alarms is greater than the first alarm threshold, increase the lower limit of the merged number of the target configuration rule to obtain the updated target configuration rule.

[0082] Specifically, the lower limit of the number of merges can be adjusted incrementally. For example, the increment of the lower limit of the number of merges can be 2 during each optimization process. In this way, the lower limit of the number of merges is gradually increased to determine the optimal value of the lower limit of the number of merges, thereby ensuring that the target alarm results within a preset time period are within a certain range.

[0083] Understandably, if the number of alarms is less than the third alarm threshold, and the third alarm threshold is less than the first alarm threshold, the lower limit of the number of target configuration rules to be merged is reduced to obtain updated target configuration rules, thereby avoiding missed risk reports.

[0084] Furthermore, in some cases, the event aggregation condition also includes an upper limit on the number of merges, and the method may also include S2172: if the number of alarms is greater than the first alarm threshold, and the lower limit of the number of merges of the target configuration rule has been increased to be greater than or equal to the corresponding upper limit of the number of merges, the aggregation time of the target configuration rule is increased.

[0085] Specifically, during iterative optimization, if the lower limit of the number of merges has been adjusted to be greater than or equal to the upper limit of the number of merges, but the number of alarms in the target alarm result within the preset time is still greater than the first alarm threshold, then the aggregation time is increased to reduce the number of alarms generated within the preset time. Similarly, the aggregation time can also be adjusted incrementally. For example, the aggregation time can be increased by 1 hour each time optimization is performed.

[0086] Based on the aforementioned example "subject:srcip,dstip filter:name-*xss attack* time:1-10", when the maximum number of merges is 30, the corresponding example becomes "subject:srcip,dstip filter:name-*xss attack*time:1-10-30". When the minimum number of merges is less than 30, the target configuration rule is optimized by increasing the minimum number of merges. When the minimum number of merges reaches 30, the target configuration rule is optimized by increasing the aggregation time.

[0087] In practical applications, if the target configuration rule is an association-type configuration rule, the event aggregation conditions also include a lower limit on the number of associated security events; the statistical information includes the number of alarms in the target alarm results within a preset time period and the number of corresponding second security events. Accordingly, step S217 can specifically include the following steps.

[0088] S2173: If the number of alarms is greater than the second alarm threshold, determine the second security event with the largest number based on the number of events corresponding to the second security event.

[0089] S2174: Increase the lower limit of the number of associations corresponding to the second security event with the largest number in the target configuration rule to obtain the updated target configuration rule.

[0090] Specifically, the event aggregation conditions also include the lower limit of the number of associations for each of the various security events involved in the target configuration rules. For example... Figure 5 In the given scenario, this represents the lower limit for the number of associations for each of events 1, 2, and 3. In some cases, the initial lower limit for the number of associations for the target alarm rule can be 1 for all of them.

[0091] Specifically, the preset durations for association-type configuration rules and merging-type configuration rules can be the same or different. In the optimization scenario of association-type configuration rules, in addition to obtaining the number of alarms in the target alarm result, it is also necessary to determine the number of various types of second security events corresponding to the target configuration rule that occur within the preset duration, and then determine the second security event with the largest number of events and increase its corresponding lower limit of association quantity. Similarly, the aforementioned incremental method can also be used to adjust the lower limit of association quantity.

[0092] like Figure 5 In the scenario described, a preset duration of 3 hours is set. The number of alarms for this alarm in the past 3 hours is obtained, as well as the number of events for each of events 1, 2, and 3 in the past 3 hours. For example, if the number of events for events 1, 2, and 3 are 1, 3, and 10 respectively, if the alarm count is greater than or equal to the second alarm threshold, the lower limit of the number of associated events for event 3 in the time aggregation condition of the target configuration rule is increased. The increment can be 2 each time. That is, the corresponding alarm strategy is adjusted to: other conditions remain unchanged, and a security alarm is only issued when the number of events for event 3 is 2.

[0093] Based on some or all of the above implementation methods, in this embodiment of the application, the method further includes storing optimization records of the above optimization process. Specifically, the target configuration rules and corresponding target alarm policies before and after optimization are stored so that subsequent manual intervention or problems can be quickly located and investigated. The stored optimization records may include at least one of the following: optimization time, optimized policy name (or policy ID or other policy identifier), name of security events associated with the optimized configuration rules, corresponding quantity and their time object information, configuration rules and corresponding alarm policies before optimization, configuration rules and corresponding alarm policies after optimization, and version information of configuration rules and alarm policies.

[0094] Furthermore, the operational data involved in each step of this application can be saved and / or output to the corresponding page so that analysts can view and perform alarm analysis.

[0095] Based on the above technical solution, this application can automatically generate alarm policies based on existing security events and alarm configuration rules in the configuration rule base for subsequent security event alarm analysis. This eliminates the need for manual configuration of alarm policies across different platforms or systems, reducing the data browsing workload for analysts. It can quickly and automatically identify security events with abnormal relationships within large amounts of data, effectively improving the efficiency of alarm policy generation and corresponding alarm analysis. Furthermore, existing alarm policies can be optimized and adjusted based on alarm results to reasonably control the amount of alarm data.

[0096] This application embodiment also provides an alarm policy generation device 700, such as... Figure 6 As shown, Figure 6This illustration shows a structural diagram of an alarm policy generation device provided in an embodiment of this application. The device may include: Event Information Acquisition Module 10: Used to acquire event description information for multiple security events. The event description information includes event object information, event attribute information, and event time information of the security event. Configuration rule acquisition module 20: used to acquire alarm configuration rules from the configuration rule library. The alarm configuration rules include filter field information and event aggregation conditions. First matching module 30: Used to match alarm configuration rules in the configuration rule base with multiple security events based on filter field information and event attribute information, so as to obtain target configuration rules and corresponding security events; The second matching module 40 is used to match the security events in the corresponding security events with the event aggregation conditions of the target configuration rules based on the event object information and event time information. Alarm policy generation module 50: If a target security event that meets the event aggregation conditions is matched, it generates a corresponding alarm policy based on the target configuration rules for use in the alarm analysis of the security event.

[0097] In some embodiments, the alarm configuration rules include merging configuration rules, which are configuration rules corresponding to alarm policies that aggregate security events occurring under the same conditions into a single alarm result; the event aggregation conditions include merging sub-conditions, a lower limit for the number of events to be merged, and an aggregation duration, wherein the merging sub-conditions indicate that the security events have the same event object; the second matching module 40 may include: First security event determination unit: used to determine the first security event with the same event object from the corresponding security events based on the event object information and merging sub-conditions, and obtain the first security event set; Target event quantity determination unit: used to determine the target number of first security events that occur within the aggregation period based on event time information; First matching unit: used to determine the target security event that meets the event aggregation condition if the number of target events is greater than or equal to the preset lower limit.

[0098] In some embodiments, the alarm configuration rules include association-type configuration rules, which are configuration rules corresponding to alarm policies that aggregate associated security events into a single alarm result; the event aggregation conditions include association sub-conditions, associated event sequence, and aggregation duration, whereby the association sub-conditions indicate the target association relationship that must be satisfied between the event objects of the associated security events; the second matching module 40 may include: The second security event determination unit is used to determine, based on event object information, event time information, and associated sub-conditions, the second security event set that occurs within the aggregation period and has a target association relationship between the event objects from the corresponding security events. Event timing determination unit: used to determine the timing of the second security events in the second security event set based on event time information; The second matching unit is used to determine the target security event that meets the event aggregation conditions if the timing of the second security event is consistent with the timing of the associated event.

[0099] In some embodiments, after a target security event that meets the event aggregation conditions is matched, and a corresponding target alarm policy is generated based on the target configuration rules for use in the alarm analysis of the security event, the apparatus further includes: Alarm Result Acquisition Module: Used to acquire the target alarm results corresponding to the target alarm policy; Result verification module: Used to verify the target alarm results based on the target configuration rules and obtain the target verification result.

[0100] In some embodiments, after a target security event that meets the event aggregation conditions is matched, and a corresponding target alarm policy is generated based on the target configuration rules for use in the alarm analysis of the security event, the apparatus further includes: Statistical Information Acquisition Module: Used to acquire statistical information on the target alarm results corresponding to the target alarm strategy within a preset time period; Optimization processing module: Used to optimize the target configuration rules based on statistical information to obtain updated target configuration rules.

[0101] In some embodiments, if the target configuration rule is a merged configuration rule, the statistical information includes the number of alarms in the target alarm result within a preset time period; the optimization processing module includes a merge quantity adjustment unit: used to increase the lower limit of the merge quantity of the target configuration rule if the number of alarms is greater than the first alarm threshold, so as to obtain the updated target configuration rule.

[0102] In some embodiments, the event aggregation condition further includes an upper limit for the number of merges, and the optimization processing module further includes an aggregation duration adjustment unit: used to increase the aggregation duration of the target configuration rule if the number of alarms is greater than the first alarm threshold and the lower limit of the number of merges of the target configuration rule is increased to be greater than or equal to the corresponding upper limit of the number of merges.

[0103] In some embodiments, if the target configuration rule is an association-type configuration rule, the event aggregation condition also includes a lower limit on the number of associated security events; the statistical information includes the number of alarms in the target alarm result within a preset time period and the number of events in the corresponding second security event; the optimization processing module includes: Event Count Determination Unit: Used to determine the second security event with the largest number of events based on the corresponding second security event count if the number of alarms exceeds the second alarm threshold; Association Quantity Adjustment Unit: Used to increase the lower limit of the association quantity corresponding to the second security event with the largest quantity in the target configuration rule, so as to obtain the updated target configuration rule.

[0104] The above-described apparatus and method embodiments are based on the same implementation methods.

[0105] This application provides an alarm policy generation device, which includes a processor and a memory. The memory stores at least one instruction or at least one program segment. The at least one instruction or at least one program segment is loaded and executed by the processor to implement the alarm policy generation method provided in the above method embodiments.

[0106] Memory is used to store software programs and modules. The processor executes these stored software programs and modules to perform various functional applications and data processing. Memory can primarily consist of a program storage area and a data storage area. The program storage area stores the operating system, application programs required for functionality, etc.; the data storage area stores data created based on device usage, etc. Furthermore, memory can include high-speed random access memory (RAM) and non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory can also include a memory controller to provide the processor with access to the memory.

[0107] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, servers, or similar computing devices. Taking running on a server as an example, Figure 7 This is a hardware structure block diagram of a server for an alarm policy generation method provided in an embodiment of this application. For example... Figure 7As shown, the server 800 can vary significantly due to different configurations or performance. It may include one or more Central Processing Units (CPUs) 810 (CPUs 810 may include, but are not limited to, microprocessors (MCUs) or programmable logic devices (FPGAs), a memory 830 for storing data, and one or more storage media 820 (e.g., one or more mass storage devices) for storing application programs 823 or data 822. The memory 830 and storage media 820 may be temporary or persistent storage. The program stored in the storage media 820 may include one or more modules, each module including a series of instruction operations on the server. Furthermore, the CPU 810 may be configured to communicate with the storage media 820 and execute a series of instruction operations stored in the storage media 820 on the server 800. The server 800 may also include one or more power supplies 860, one or more wired or wireless network interfaces 850, one or more input / output interfaces 840, and / or one or more operating systems 821, such as Windows Server. TM Mac OS X TM Unix TM Linux™, FreeBSD™, etc.

[0108] The input / output interface 840 can be used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of server 800. In one example, the input / output interface 840 includes a network interface controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the input / output interface 840 may be a radio frequency (RF) module used for wireless communication with the Internet.

[0109] Those skilled in the art will understand that Figure 7 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, server 800 may also include... Figure 7 The more or fewer components shown, or having the same Figure 7 The different configurations shown.

[0110] Embodiments of this application also provide a computer-readable storage medium, which can be disposed in a server to store at least one instruction or at least one program related to implementing an alarm policy generation method in the method embodiments. The at least one instruction or the at least one program is loaded and executed by the processor to implement the alarm policy generation method provided in the above method embodiments.

[0111] Optionally, in this embodiment, the storage medium may be located at at least one of the multiple network servers in a computer network. Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0112] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various alternative implementations described above.

[0113] As can be seen from the embodiments of the alarm policy generation method, apparatus, device, server, program product, or storage medium provided in this application, this application obtains event description information of multiple security events, including event object information, event attribute information, and event time information of the security events; and obtains alarm configuration rules including filter field information and event aggregation conditions from the configuration rule base; then, based on the filter field information and event attribute information, the alarm configuration rules in the configuration rule base are matched with multiple security events to obtain target configuration rules and corresponding security events; and, based on the event object information and event time information, the security events in the corresponding security events are matched with the event aggregation conditions of the target configuration rules; if a target security event that meets the event aggregation conditions is matched, a corresponding alarm policy is generated based on the target configuration rule. The above technical solution achieves automatic generation of alarm policies by setting a configuration rule base and matching security data, eliminating the need for manual configuration of alarm policies, and can be applied to different security platforms and business systems, significantly reducing repetitive work in alarm policy configuration and effectively improving the efficiency of alarm policy generation. Furthermore, by determining matching alarm configuration rules from the configuration rule base based on security event data and then generating alarm policies, the correlation between alarm policies and the security events to be analyzed can be improved, the number of invalid alarm policies can be reduced, and the efficiency of alarm analysis can be improved.

[0114] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are also possible or may be advantageous.

[0115] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device, equipment, and storage medium embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0116] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing the relevant hardware to implement them. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0117] The above are merely preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for generating alarm strategies, characterized in that, The method includes: Obtain event description information for multiple security events, wherein the event description information includes event object information, event attribute information, and event time information of the security events; The alarm configuration rules are obtained from the configuration rule library. The alarm configuration rules include filter field information and event aggregation conditions. The configuration rule library includes multiple preset alarm configuration rules. Based on the filter field information and the event attribute information, the alarm configuration rules in the configuration rule base are matched with the multiple security events to obtain the target configuration rule and the corresponding security event; Based on the event object information and the event time information, the security events in the corresponding security events are matched with the event aggregation conditions of the target configuration rules; If a target security event that meets the event aggregation conditions is matched, the policy generation interface is called to convert the configuration data of the target configuration rule according to the policy format corresponding to the target security platform to obtain the corresponding alarm policy for alarm analysis of security events of the target security platform. Obtain statistical information of the target alarm results corresponding to the target alarm policy within a preset time period; if the target configuration rule is a merging type configuration rule, the statistical information includes the number of alarms of the target alarm results within the preset time period; if the target configuration rule is an association type configuration rule, the event aggregation condition also includes a lower limit of the number of associated security events; the statistical information includes the number of alarms of the target alarm results within the preset time period and the number of events of the corresponding second security events; If the target configuration rule is a merged configuration rule, and the number of alarms is greater than the first alarm threshold, the lower limit of the number of merges of the target configuration rule is increased in an incremental manner to obtain an updated target configuration rule; If the number of alarms is greater than the first alarm threshold, and the lower limit of the number of merged targets is increased to be greater than or equal to the corresponding upper limit of the number of merged targets, the aggregation time of the targets is increased in an incremental manner. If the number of alarms is less than the third alarm threshold, and the third alarm threshold is less than the first alarm threshold, the lower limit of the number of target configuration rules to be merged is reduced to obtain the updated target configuration rules. If the target configuration rule is an association-type configuration rule, and the number of alarms is greater than the second alarm threshold, the second security event with the largest number is determined based on the number of events of the corresponding second security event; The updated target configuration rule is obtained by increasing the lower limit of the number of associations corresponding to the second security event with the largest number in the target configuration rule.

2. The method according to claim 1, characterized in that, The alarm configuration rules include merging configuration rules, which are configuration rules corresponding to alarm strategies that aggregate security events occurring under the same conditions into a single alarm result; the event aggregation conditions include merging sub-conditions, a lower limit for the number of events to be merged, and an aggregation duration, wherein the merging sub-conditions indicate that the event objects of the security events are the same; The step of matching the security events in the corresponding security events with the event aggregation conditions of the target configuration rule based on the event object information and the event time information includes: Based on the event object information and merging sub-conditions, a first security event with the same event object is determined from the corresponding security events to obtain a first security event set; Based on the event time information, determine the target number of first security events that occur within the aggregation duration; If the number of target events is greater than or equal to a preset minimum number, a target security event that meets the event aggregation condition is determined to be matched.

3. The method according to claim 1, characterized in that, The alarm configuration rules include association class configuration rules, which are configuration rules corresponding to alarm strategies that aggregate associated security events into a single alarm result; the event aggregation conditions include association sub-conditions, associated event sequence, and aggregation duration, whereby the association sub-conditions indicate the target association relationship that must be satisfied between the event objects of the associated security events; The step of matching the security events in the corresponding security events with the event aggregation conditions of the target configuration rule based on the event object information and the event time information includes: Based on the event object information, event time information, and the associated sub-conditions, a second security event that occurred within the aggregation duration and has the target association relationship between the event objects is determined from the corresponding security events, thus obtaining a second security event set; Based on the event time information, the timing of the second security event in the second security event set is determined; If the timing of the second security event is consistent with the timing of the associated event, a target security event that meets the event aggregation conditions is determined to be matched.

4. The method according to any one of claims 1-3, characterized in that, After the method generates a corresponding target alerting policy based on the target configuration rules for alerting analysis of security events, if a target security event that meets the event aggregation conditions is matched, the method further includes: Obtain the target alarm result corresponding to the target alarm strategy; The target alarm results are verified based on the target configuration rules to obtain the target verification results.

5. An alarm strategy generation device, characterized in that, The device includes: Event information acquisition module: used to acquire event description information of multiple security events, the event description information including event object information, event attribute information and event time information of the security event; Configuration rule acquisition module: used to acquire alarm configuration rules from the configuration rule library. The alarm configuration rules include filter field information and event aggregation conditions. The configuration rule library includes multiple preset alarm configuration rules. The first matching module is used to match the alarm configuration rules in the configuration rule base with the multiple security events based on the filter field information and the event attribute information, so as to obtain the target configuration rule and the corresponding security event. The second matching module is used to match the security events in the corresponding security events with the event aggregation conditions of the target configuration rules based on the event object information and the event time information. Alarm policy generation module: If a target security event that meets the event aggregation conditions is matched, the module calls the policy generation interface, converts the configuration data of the target configuration rule according to the policy format corresponding to the target security platform, and obtains the corresponding alarm policy for alarm analysis of security events of the target security platform. Statistical Information Acquisition Module: Used to acquire statistical information of target alarm results corresponding to target alarm policies within a preset time period; if the target configuration rule is a merging-type configuration rule, the statistical information includes the number of alarms of the target alarm results within the preset time period; if the target configuration rule is an association-type configuration rule, the event aggregation condition also includes a lower limit of the number of associated security events; the statistical information includes the number of alarms of the target alarm results and the number of events of the corresponding second security events within the preset time period; The optimization processing module is configured to: if the target configuration rule is a merging-type configuration rule and the number of alarms is greater than a first alarm threshold, increase the lower limit of the merging quantity of the target configuration rule incrementally to obtain an updated target configuration rule; and if the number of alarms is less than a third alarm threshold and the third alarm threshold is less than the first alarm threshold, decrease the lower limit of the merging quantity of the target configuration rule to obtain an updated target configuration rule; if the number of alarms is greater than the first alarm threshold and the lower limit of the merging quantity of the target configuration rule is increased to be greater than or equal to the corresponding upper limit of the merging quantity, increase the aggregation time of the target configuration rule incrementally; and if the target configuration rule is an association-type configuration rule and the number of alarms is greater than a second alarm threshold, determine the second security event with the largest number based on the number of events of the corresponding second security event. The updated target configuration rule is obtained by increasing the lower limit of the number of associations corresponding to the second security event with the largest number in the target configuration rule.

6. The apparatus according to claim 5, characterized in that, The alarm configuration rules include merging configuration rules, which are configuration rules corresponding to alarm strategies that aggregate security events occurring under the same conditions into a single alarm result; the event aggregation conditions include merging sub-conditions, a lower limit for the number of events to be merged, and an aggregation duration, wherein the merging sub-conditions indicate that the event objects of the security events are the same; The second matching module includes: First security event determination unit: used to determine the first security event with the same event object from the corresponding security events based on the event object information and merging sub-conditions, and obtain the first security event set; Target event quantity determination unit: used to determine the target number of first security events that occur within the aggregation duration based on the event time information; First matching unit: used to determine if a target security event that meets the event aggregation condition is matched if the number of target events is greater than or equal to a preset lower limit.

7. The apparatus according to claim 5, characterized in that, The alarm configuration rules include association class configuration rules, which are configuration rules corresponding to alarm strategies that aggregate associated security events into a single alarm result; the event aggregation conditions include association sub-conditions, associated event sequence, and aggregation duration, whereby the association sub-conditions indicate the target association relationship that must be satisfied between the event objects of the associated security events; The second matching module includes: The second security event determination unit is used to determine, based on the event object information, event time information, and the associated sub-conditions, a second security event that occurred within the aggregation duration and has the target association relationship between the event objects from the corresponding security events, thereby obtaining a second security event set. Event timing determination unit: used to determine the timing of the second security event in the second security event set based on the event time information; The second matching unit is used to determine a target security event that meets the event aggregation conditions if the timing of the second security event is consistent with the timing of the associated event.

8. The apparatus according to any one of claims 5-7, characterized in that, The device further includes: Alarm result acquisition module: used to obtain the target alarm result corresponding to the target alarm policy after generating a corresponding target alarm policy based on the target configuration rules when a target security event that meets the event aggregation conditions is matched, for use in the alarm analysis of the security event; Result verification module: used to verify the target alarm result based on the target configuration rules, and obtain the target verification result.

9. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the alarm policy generation method as described in any one of claims 1-4.

10. An alarm policy generation device, characterized in that, The device includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the alarm policy generation method as described in any one of claims 1-4.

11. A computer program product, characterized in that, The computer program product includes computer instructions stored in a computer-readable storage medium, wherein a processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the alarm policy generation method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Event processing method and device

    CN106484595A

  • Threat event alarm method and device, alarm equipment and machine readable storage medium

    CN110545276A

  • Intelligent fault analysis method and device, equipment and storage medium

    CN112395170A